Post: fail0verflow! - Sony's ECDSA code
12-29-2010, 04:08 PM #1
manster
League Champion
(adsbygoogle = window.adsbygoogle || []).push({});
Hi!
Featured News from You must login or register to view this content.
You must login or register to view this content.

You must login or register to view this content.

JAILBREAK -> DOWNGRADE -> fail0verflow


You must login or register to view this content.

You must login or register to view this content.

You must login or register to view this content.

Well the big PS3 Exploit talk is now officially over at the annual 27C3 conference. All the big names in the developer scene world was there giving a one hour talk regarding Sony's EPIC FAIL


You must login or register to view this content.

But basically they talked about how the PS3 totally failed in security, by botching the pki implementation it became possible to calculate the keys needed to sign everything. PUBLIC PRIVATE KEYS, and replacing the "revoke-list" with super-large one (overflow) during the bootup NOR flash at startup, giving them full control of the PS3 system.


The 360 console is now more of secure system then the PS3 after all these years!




This site was announcend at the conference
You must login or register to view this content. - Coming Soon
You must login or register to view this content.
check this site too
You must login or register to view this content.

Originally posted by another user

"The recent advent of these new exploits means current firmware is vulnerable, v3.55 and possibly beyond. It will be very difficult for Sony to fix the described exploits."

"we can now run unsigned code on an non-exploited PS3."

@KushanTheCat our goal is to have linux running on all existing PS3 consoles, whatever their firmware versions.

Our current PS3 goal: AsbestOS.pup

Myth #1: It took us 3-4 years to do this. Negative, this exploit only took a few months after we started working. We weren't trying before.

Myth #2: Sony can change keys. No, they can't. These aren't encryption keys, they're signing keys. If they change them GAMES STOP WORKING.

Clarification #3: The private keys refer to keys that Sony HQ uses. PS3s don't have these keys (but we calculated them due to the fail).

Clarification #4: the random number isn't 4, it's more like 007eabbb79360e14df1457a4194b82f71a0dc39280 (example). But it's still constant.

Note: we won't be working long-term on CFW or similar. We'll release tools and a PoC, someone else can take over. The fun part is done Winky Winky

Myth: Geohot -> Sony pulls OtherOS -> JB -> Fail. Fact: Slim had no OtherOS -> Geohot -> ... . Geohot started his work due to the Slim.

@You must login or register to view this content. yes, we'll release all our tools as soon as we cleaned them up in january or so.
Great news for all PS3 User's Smile




Console Hacking 2010 - Chaos Communication Congress
Screenshots:

You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.

short videos from the conference:

[ame]https://www.youtube.com/watch?v=YbUVgxw1yWc&feature=player_embedded[/ame]
[ame]https://www.youtube.com/watch?v=GPjd6gHY6A4[/ame]
[ame]https://www.youtube.com/watch?v=ClnvJe4_u0Q&feature=player_embedded[/ame]

Full Video
[ame]https://www.youtube.com/watch?v=hcbaeKA2moE[/ame]
Splitted in 3 parts:

[ame]https://www.youtube.com/watch?v=X6CA4fqAdsc&feature=player_embedded[/ame]
[ame]https://www.youtube.com/watch?v=X8ohOy8_XO4&feature=player_embedded[/ame]
[ame]https://www.youtube.com/watch?v=Eag0VyRTld8&feature=player_embedded[/ame]
Download full video here (right click -> save as):
You must login or register to view this content.


Marcan @ 27C3 Lightning Talk
[ame]https://www.youtube.com/watch?v=lGI0EnNQ5GE&feature=player_embedded[/ame]


Have fun watching


Sources:
You must login or register to view this content.
You must login or register to view this content.
You must login or register to view this content.
Last edited by manster ; 12-31-2010 at 11:43 PM.

The following 29 users say thank you to manster for this useful post:

369lo, 8======D----, bcb, Cain, CHuRCHYx, CRACKbomber, Fallen152039, Geigers, GetDeleted -_-, Hells, ihaxgames, IRiSe_GodFather, iSergeant-Adam, KimKardashian, MarioDaKid, Mark00agent, Mr. Aimbot, Mr. Star, Nicky74me, ProjectPartial, Slashey, Solid Snake, Suxh4rd2bu, That Guy_, The InvadeR, The Overdose, Uk_ViiPeR, UMD, XxLuisMaxX
01-03-2011, 01:28 AM #74
lives2game
Do a barrel roll!
Originally posted by Adam View Post
you act like it is so hard to sack ps3


if that was directed at me...i didnt mean to say that it was hard...infact im sure i didnt say that it was hard to hack it, i just said that there are those of us who dont know what we are doing....lol...everyone starts somewhere, you dont just wake up knowing how to do something...haha..i am pretty excited for this to be released, and to figure out how to hack my ps3...
01-03-2011, 11:57 AM #75
Originally posted by lives2game View Post
if that was directed at me...i didnt mean to say that it was hard...infact im sure i didnt say that it was hard to hack it, i just said that there are those of us who dont know what we are doing....lol...everyone starts somewhere, you dont just wake up knowing how to do something...haha..i am pretty excited for this to be released, and to figure out how to hack my ps3...


no it wasn't directed towards you
01-03-2011, 03:47 PM #76
Arriba
Banned
I heard fail0verflow are not working on a CFW for PS3 as they say the fun part is done, however they will be releasing tools and leaving it up to other people to do it.
01-03-2011, 09:47 PM #77
lives2game
Do a barrel roll!
Originally posted by Adam View Post
no it wasn't directed towards you



ah, well looks like i wasted my breath on that last one....anyway....i cant wait till they figure everything out and release some user friendly stuff for it
01-05-2011, 04:44 AM #78
Lydey
RyanBell RIP 20.3.11 GBNF
my arse the 360 is better in security the 360 got hacked first and it took them years to hack ps3 so i really doubt u can say 360 is better in security Smile
01-06-2011, 11:47 PM #79
bigit1029
NGU Orginal
this means they can potentially sigh any applications for us to use on our ps3's Smile
01-07-2011, 12:32 AM #80
ツSparky
Teddy <3
I laughed watchn the vids
01-07-2011, 03:58 AM #81
no doubt that these guys are geniusses lol XD
01-07-2011, 04:15 AM #82
Thanitos
Vault dweller
Originally posted by packarda12 View Post
These are really interesting photo's what a wierd chipset hes using i wonder what it does.

I cant wait for the supposive release next month.

Unsigned code ftw ! .

---------- Post added at 10:51 PM ---------- Previous post was at 10:47 PM ----------



Sony are complete idiots they thought nobody would ever get far enough to cause any real damage.

Well they were wrong.

The main thing i thought was funny was the fact that they basically called the hyper visor stupid halfway through there talk.

They said it doesn't provide any sort of security there puzzled at what Sony thought they were doing.

Oh well hopefully these newly found exploits can't be patched that will f*ck up Sony a treat. !


until the ps4 comes out with a whole overhaul and a new challenge, and all games from here on out will only work on ps4 :(

Copyright © 2024, NextGenUpdate.
All Rights Reserved.

Gray NextGenUpdate Logo