thraker
L15: Wise
- Seit
- 1 März 2009
- Beiträge
- 9.109
Im folgenden Video siehst du, wie du consolewars als Web-App auf dem Startbildschirm deines Smartphones installieren kannst.
Hinweis: This feature may not be available in some browsers.
Dann erkläre mit doch bitte, was an den drehenden Quadraten jetzt so großartig ist. Ich meine das ernst!Schön das endlich Leute Homebrew verstehen![]()
Dann erkläre mit doch bitte, was an den drehenden Quadraten jetzt so großartig ist. Ich meine das ernst!
Gut erkannt! Ich weiß nicht, was das ist. Deswegen frage ich nach. Das ist doch wirklich kein Grund mich zu beschimpfen, oder?Hast wohl kein Plan was ein Luaplayer ist oder? hehe du armes Wü... aber hauptsache Unruhe stiften^^
Gut erkannt! Ich weiß nicht, was das ist. Deswegen frage ich nach. Das ist doch wirklich kein Grund mich zu beschimpfen, oder?
But basically they talked about how the PS3 totally failed in security, by botching the pki implementation it became possible to calculate the keys needed to sign everything. PUBLIC PRIVATE KEYS, and replacing the "revoke-list" with super-large one (overflow) during the bootup NOR flash at startup, giving them full control of the PS3 system.
1000€ bist du mir schuldig. Aber zackig.
fail0verflow
we only started looking at the ps3 after otheros was killed.
fail0verflow
Note: we won't be working long-term on CFW or similar. We'll release tools and a PoC, someone else can take over. The fun part is done
marcan42
Myth #2: Sony can change keys.
No, they can't. These aren't encryption keys, they're signing keys. If they change them GAMES STOP WORKING.
marcan42
Myth #1: It took us 3-4 years to do this.
Negative, this exploit only took a few months after we started working. We weren't trying before.
marcan42
They actually CAN change keys for LV2/LV1, isolated modules, rvklists, spp, but that's useless because you can just downgrade the loaders.
marcan42
The XKCD "return 4" function that we showed is (essentially) part of the code that Sony HQ runs to sign games, it's not in the PS3 FW.
marcan42
This is also why we didn't use the term "exploit" or "bug". The PS3 signature fail is neither an exploit nor a bug (in the PS3 firmware).
marcan42
It's Sony not knowing WTF they're doing when making signatures, and thus mathematically leaking their keys.
marcan42
Clarification #3: The private keys refer to keys that Sony HQ uses. PS3s don't have these keys (but we calculated them due to the fail).
marcan42
Clarification #4: the random number isn't 4, it's more like 007eabbb79360e14df1457a4194b82f71a0dc39280 (example). But it's still constant.
marcan42
we can't modify lv1 directly yet (no lv1ldr dump) but we can pwn lv1 early in the boot process via a hacked iso module.
marcan42
we don't have the game signing key but the same epic fail applies to it. Once someone dumps appldr they can calculate it too.
Ich sehe eine PSP 2.0 auf uns zukommen![]()
Jup und die wird besser als jede Konsole auf der Welt ^^
Sony = Reallife :win: