QJ.NET | Videos | Forums | iPhone | MMORPG | Nintendo DS | Wii | PlayStation 3 | PSP | Xbox 360 | PC | Downloads | Contact Us
Forums | Gaming News | Videos | Downloads | Today's Posts | Mark Forums Read | Chat | FAQ | Members List | Contact

QJ.net Game Discussion - PSP, Xbox, Wii, PS3, PSP Homebrew, and PSP Guides

Go Back   QJ.net Game Discussion - PSP, Xbox, Wii, PS3, PSP Homebrew, and PSP Guides > Developers Corner > PSP Development, Hacks, and Homebrew > PSP Development Forum > Developer's Dungeon
The above video goes away if you are a member and logged in, so log in now!

libtiff vulnerability crash's 2.71 and 2.80

This is a discussion on libtiff vulnerability crash's 2.71 and 2.80 within the Developer's Dungeon forums, part of the PSP Development Forum category; So, any updates on this? I have been away for the weekend so, I dont know, if anything has been ...

Reply
 
LinkBack Thread Tools
Old 08-21-2006, 04:40 AM   #301

Rock Star
 

 
Join Date: Aug 2005
Location: CT| FW: 4.01 M33-2
Posts: 11,844
Trader Feedback: 0
Default

So, any updates on this? I have been away for the weekend so, I dont know, if anything has been progressing. Plus, this thread hasn't been updated in two days.
__________________

TeamOverload is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-21-2006, 06:00 AM   #302

 
Fanjita's Avatar
 
Join Date: Sep 2005
Location: Edinburgh, UK
Posts: 2,388
Trader Feedback: 0
Default

Perhaps because there's no news?
Fanjita is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-21-2006, 06:01 AM   #303

Rock Star
 

 
Join Date: Aug 2005
Location: CT| FW: 4.01 M33-2
Posts: 11,844
Trader Feedback: 0
Default

Quote:
Originally Posted by Fanjita
Perhaps because there's no news?
I figured that out, but with things like this, I would at least expect discussion.

Edit: I forgot this did get moved to the Developer's Dungeon, so there aren't as many people to talk about it.
__________________


Last edited by TeamOverload; 08-21-2006 at 06:01 AM.. Reason: Added something
TeamOverload is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-21-2006, 04:31 PM   #304

Suicide Silence
 

 
Join Date: Sep 2005
Location: New Jersey
Posts: 2,163
Trader Feedback: 0
Default

Thats a good thing, there should be less speculation and use this thread solely for news
__________________
Theknightinhell is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-21-2006, 05:26 PM   #305

 
Fanjita's Avatar
 
Join Date: Sep 2005
Location: Edinburgh, UK
Posts: 2,388
Trader Feedback: 0
Default

Alright, time for a brief update with the facts so far.

This exploit is definitely genuine, and usable.

It's unclear exactly which firmwares it will be usable on, but so far 2.0 and 2.01 should definitely work. 2.5 and above are significantly harder to research. 2.7+ will take longer still. The signs are that it may go up as far as 2.8, but that's not proven.

Just to put things into perspective, a combined team has spent at least 60 intensive hours working on researching this so far, and we're at the point of being able to confirm that it will work.

It will take longer still to convert it into something that is actually in a demonstrable form, such as Hello World.

Credit so far goes to NOPx86 for discovering the vulnerability and proof of concept on the PC, and Skylark and psp250 for researching it on the PSP. I've helped a bit too, but those guys have done the bulk of the work.
Fanjita is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-21-2006, 05:35 PM   #306

I'm Baaaack!
 
Access_Denied's Avatar
 
Join Date: May 2006
Location: Waukegan,Illinois
Posts: 2,186
Trader Feedback: 0
Default

If the exploit does work on 2.5+, could the eLoader be easily adapted to work with this exploit? Or will it take another couple weeks to create a whole new eLoader?
__________________
Access_Denied is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-21-2006, 05:48 PM   #307

 
Fanjita's Avatar
 
Join Date: Sep 2005
Location: Edinburgh, UK
Posts: 2,388
Trader Feedback: 0
Default

Quote:
Originally Posted by ARza
If the exploit does work on 2.5+, could the eLoader be easily adapted to work with this exploit? Or will it take another couple weeks to create a whole new eLoader?
Yes, that ought to be possible.
Fanjita is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-21-2006, 06:03 PM   #308
TheMarioKarters
Guest
 
Posts: n/a
Default

Quote:
Originally Posted by Fanjita
Alright, time for a brief update with the facts so far.

This exploit is definitely genuine, and usable.

It's unclear exactly which firmwares it will be usable on, but so far 2.0 and 2.01 should definitely work. 2.5 and above are significantly harder to research. 2.7+ will take longer still. The signs are that it may go up as far as 2.8, but that's not proven.

Just to put things into perspective, a combined team has spent at least 60 intensive hours working on researching this so far, and we're at the point of being able to confirm that it will work.

It will take longer still to convert it into something that is actually in a demonstrable form, such as Hello World.

Credit so far goes to NOPx86 for discovering the vulnerability and proof of concept on the PC, and Skylark and psp250 for researching it on the PSP. I've helped a bit too, but those guys have done the bulk of the work.
Excellent, i'll be looking out for the latest news from you guys.
 
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-21-2006, 07:40 PM   #309
 
FreePlay's Avatar
 
Join Date: Dec 2005
Location: h0000000rj
Posts: 12,858
Trader Feedback: 0
Default

Kick... ass.
__________________
[qj now fails.]
FreePlay is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-21-2006, 09:00 PM   #310

Suicide Silence
 

 
Join Date: Sep 2005
Location: New Jersey
Posts: 2,163
Trader Feedback: 0
Default

Damn skippy, kick ass. Good luck Fanjita, Skylark, and PSP250
__________________
Theknightinhell is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-21-2006, 09:20 PM   #311

Developer
 
TheEmulatorGuy's Avatar
 
Join Date: Feb 2006
Location: Tauranga, New Zealand
Posts: 355
Trader Feedback: 0
Default

I don't think we'll be seeing a kernel eLoader, since 2.0 didn't have one.
__________________
TheEmulatorGuy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-21-2006, 10:24 PM   #312

Developer
 
Join Date: Jun 2005
Location: At my house...
Posts: 885
Trader Feedback: 0
Default

But that was a different exploit. You cant base your expectations on what was set in the past with this exploit.
__________________
F.A.L.O?
Twenty 2 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-21-2006, 11:09 PM   #313

Developer
 
TheEmulatorGuy's Avatar
 
Join Date: Feb 2006
Location: Tauranga, New Zealand
Posts: 355
Trader Feedback: 0
Default

Quote:
Originally Posted by Twenty 2
But that was a different exploit. You cant base your expectations on what was set in the past with this exploit.
Uh, yes I can, because they're both buffer overflows in the TIFF format.
__________________
TheEmulatorGuy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-21-2006, 11:11 PM   #314

Developer
 
Join Date: Jul 2006
Posts: 262
Trader Feedback: 0
Default

Holy crap the exploit was confirmed. Awesome. I've got 1.5 but for some reason, I always find this type of news exciting. How exactly did they confirm it is what I'm wondering.
__________________
http://openpandora.org/
the_darkside_986 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-22-2006, 01:27 AM   #315

My name is Mud
 
Join Date: Dec 2005
Posts: 1,538
Trader Feedback: 0
Default

Quote:
Originally Posted by TheEmulatorGuy
Uh, yes I can, because they're both buffer overflows in the TIFF format.
Ya, but they're not the same exploit, are they?
__________________

hàrléyg² is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-22-2006, 03:14 AM   #316

Developer
 
TheEmulatorGuy's Avatar
 
Join Date: Feb 2006
Location: Tauranga, New Zealand
Posts: 355
Trader Feedback: 0
Default

Quote:
Originally Posted by hàrléyg²
Ya, but they're not the same exploit, are they?
Quote:
Originally Posted by Glynnder
exactly
I will eat my words if I turn out wrong, but the exploits use the same process and area. There is no direct kernel access as shown by the 2.0 exploit, so any huge difference is unlikely. Same place, same mode.

Of course, it doesn't matter, because the vulnerability that allowed kernel access through GTA will work here.
__________________
TheEmulatorGuy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-22-2006, 05:15 AM   #317
Retired QJ *****istrator
 
Abe_Froeman's Avatar
 
Join Date: Jan 2006
Real First Name: Mandatory Field Filler
Location: East Coast of US
Just Played: Mandatory Field Filler
Posts: 14,616
Trader Feedback: 0
Default

Per some members requests, I went through and cleaned out all of the spam since this thread has been moved to the Dungeon. If you have nothing to contribute to the thread or this isn't your area of expertise, just because you can post in the Dungeon doesn't mean you "need" to.
Abe_Froeman is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-22-2006, 05:24 AM   #318
 
FreePlay's Avatar
 
Join Date: Dec 2005
Location: h0000000rj
Posts: 12,858
Trader Feedback: 0
Default

Quote:
Originally Posted by TheEmulatorGuy
I will eat my words if I turn out wrong, but the exploits use the same process and area. There is no direct kernel access as shown by the 2.0 exploit, so any huge difference is unlikely. Same place, same mode.

Of course, it doesn't matter, because the vulnerability that allowed kernel access through GTA will work here.
Um... Actually, TEG, the 2.00 exploit was kernel-mode. It ran in the VSH, which has full access to kernel-mode functions. Also, the kernel-mode exploit used for the 2.5/2.6 downgrader probably doesn't exist on 2.80.
__________________
[qj now fails.]
FreePlay is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-22-2006, 07:48 AM   #319

Party at Las Noches!
 
IchigoKurosaki's Avatar
 
Join Date: Jun 2005
Location: Florida
Posts: 1,648
Trader Feedback: 0
Default

If i'm correct VSH Mode dosen't have access to Kernel Mode Function, but does have access of changing between Game Mode and Kernel/Update Mode...
__________________
.:Nobis Development Group:.
.:Personal Portfolio:.

Playstation Portable - PSP1001 - 3.90 M33-2
IchigoKurosaki is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-22-2006, 11:50 AM   #320
 
FreePlay's Avatar
 
Join Date: Dec 2005
Location: h0000000rj
Posts: 12,858
Trader Feedback: 0
Default

VSH mode definitely has kernel access. There's no doubt of that, really... I managed to mount an ISO as disc0: and read from it using nothing but syscalls under the 2.00 VSH.
__________________
[qj now fails.]
FreePlay is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-22-2006, 01:55 PM   #321

 
Fanjita's Avatar
 
Join Date: Sep 2005
Location: Edinburgh, UK
Posts: 2,388
Trader Feedback: 0
Default

Quote:
Originally Posted by FreePlay
VSH mode definitely has kernel access. There's no doubt of that, really... I managed to mount an ISO as disc0: and read from it using nothing but syscalls under the 2.00 VSH.
No.

Try reading some kmem, then you'll see that you're not in kernel mode.

The Sony APIs just allow user threads with the VSH thread attribute to do more stuff, that's all.
Fanjita is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-22-2006, 02:34 PM   #322
 
FreePlay's Avatar
 
Join Date: Dec 2005
Location: h0000000rj
Posts: 12,858
Trader Feedback: 0
Default

B'doh. I stand corrected.
__________________
[qj now fails.]
FreePlay is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-22-2006, 08:36 PM   #323

Developer
 
TheEmulatorGuy's Avatar
 
Join Date: Feb 2006
Location: Tauranga, New Zealand
Posts: 355
Trader Feedback: 0
Default

Quote:
Originally Posted by FreePlay
B'doh. I stand corrected.
Yeah, I'm not going to say anything.
__________________
TheEmulatorGuy is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-22-2006, 11:45 PM   #324
 
FreePlay's Avatar
 
Join Date: Dec 2005
Location: h0000000rj
Posts: 12,858
Trader Feedback: 0
Default

That would probably be kind of you.
__________________
[qj now fails.]
FreePlay is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-23-2006, 12:16 AM   #325

is not posting very often
 
Glynnder's Avatar
 
Join Date: Feb 2006
Location: omnipresent
Posts: 5,161
Trader Feedback: 0
Default

Thats what I was thinking, if you read earlier im sure i said something like that too.

Methinks thats why when it was vsh(?) mode unloked for the 2.60 eLoader not much happens.
Or was that not vsh
__________________
Quote:
Originally Posted by Abe
Either way, if you don't know, don't guess. Stick to answering questions about stuff you're qualified to answer, like Pokemon questions or something along those lines.
http://forums.qj.net/501501-post26.html
Glynnder is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-23-2006, 02:01 AM   #326

Party at Las Noches!
 
IchigoKurosaki's Avatar
 
Join Date: Jun 2005
Location: Florida
Posts: 1,648
Trader Feedback: 0
Default

No it was Update Mode...
__________________
.:Nobis Development Group:.
.:Personal Portfolio:.

Playstation Portable - PSP1001 - 3.90 M33-2
IchigoKurosaki is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-23-2006, 08:11 AM   #327

is not posting very often
 
Glynnder's Avatar
 
Join Date: Feb 2006
Location: omnipresent
Posts: 5,161
Trader Feedback: 0
Default

that was it, sorry!
__________________
Quote:
Originally Posted by Abe
Either way, if you don't know, don't guess. Stick to answering questions about stuff you're qualified to answer, like Pokemon questions or something along those lines.
http://forums.qj.net/501501-post26.html
Glynnder is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-23-2006, 09:55 AM   #328

Developer
 
Join Date: Jun 2005
Location: At my house...
Posts: 885
Trader Feedback: 0
Default

So why doesnt the 2.6 exploit work on 2.7?
__________________
F.A.L.O?
Twenty 2 is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-23-2006, 10:10 AM   #329

is not posting very often
 
Glynnder's Avatar
 
Join Date: Feb 2006
Location: omnipresent
Posts: 5,161
Trader Feedback: 0
Default

because Sony patched the GTA exploit
__________________
Quote:
Originally Posted by Abe
Either way, if you don't know, don't guess. Stick to answering questions about stuff you're qualified to answer, like Pokemon questions or something along those lines.
http://forums.qj.net/501501-post26.html
Glynnder is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 08-23-2006, 10:37 AM   #330

My name is Mud
 
Join Date: Dec 2005
Posts: 1,538
Trader Feedback: 0
Default

I'm thinking about closing this thread and only allowing fanjita to post news updates inside it.
I'll ask him what he thinks.
__________________

hàrléyg² is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Tags
271 , 280 , crash , libtiff , vulnerability

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -8. The time now is 03:00 AM.



Use of this Web site constitutes acceptance of the TERMS & CONDITIONS and PRIVACY POLICY
Copyright © 2009, QJ.NET. All Rights Reserved.
Contact Us