EurAsiayour console hacking resource
Select topic
  Create an account Home  ·  Your Account  ·  Online Shop  ·  Forums  ·  Downloads  ·  Wiki  
Main Menu
· Home
· Downloads
· FAQ
· Forums
· Info Pages
· Members List
· Online Shop
· PDA - AvantGo
· Private Messages
· Search Stories
· Statistics
· Stories Archive
· Submit Story
· Top 10
· Topics
· Upload
· WAP
· Web Links
· Wiki
· Your Account

Online Shop
Credit Card

EurAsia Online Shop
enter

new products
· RROD Kit Bulk Version
· RROD Repair Kit Pro II
· 360 Xtractor 2
· 360 Xtractor Vampire
· Wiikey Fusion
· xenoGC 2.0
· NWP Chip v2 Kit
· NWP Chip Kit
· R4i DSi LL
· USB Gecko
· DriveKey modchip Wii
· Access Pro Tool Kit v2
· 360 Xtractor 1
· 360 Xtractor Spear
· WiiKey 2 modchip
· d2lite modchip wii
· yaosm 3.2 drivechip wii
· d2pro 6-wire modchip Wii
· d2prog USB programmer
· SD Card Adapter

complete price list

Who's Online
There are currently 156 guest(s) and 39 member(s) online.

carlosapj - chibimoni - coronado - cuervo - d3lta - Dante_317 - dataSA - djmanps2 - dranik - exelzor - Flupper - happyxbox - heydricas - jack316 - jbs - jester124 - kevinaska - Lutzero - modfreak - momiji - mundo_x_games - payst - plimpy - powery - RetroHelix - roadkill - ruger1234 - samylan - sinner - sk8er_4_life_ez - skel28 - slashdown - SlimShady - smith164 - systemD - tecnor - tricky1 - windepot - wumse

Welcome honored guest. You can register for free by clicking here.

Hot Wikis
· Xecuter LT Fakir
· PS3 YLOD Fix
· NSMB Modchip Tutorial
· PS3 Glitch Hack
· Xbox360NoDvdRom
· Ps3FactoryRestore
· DumpNewLiteOn
· Free60JtagHack
· WiiMenu4Guide
· Ps3HddDecrypt
· WiiKey2EjectFix
· SaveMiiFree
· RemoveOct23Update
· LiteOnDvdKeySpoof
· WiiHwDiagram
· Ps3OsRels
· PandoraNoHomebrewPsp
· GcOsMultiGameWiiHowTo
· Xbox360LinuxBurn
· Xbox360Elite
· Xbox360EraserFix
· Ps3PalMoboShots
· Xbox360Kernel
· RevoDevKit
· Ps3DevKitPictures
· Xbox360DisasmXtreme
· Xbox360XeDk
· HeatGunPoll
· Ps2HdlPatchTutorial
· Ps2VersionTable
· XboxErrorCodes
· XboxVersionTable
· GameCubeLaserTweak
· ModchipSolderingGuide
· DsFirmwareVersions
· DsFlashMeTutorial
· DsM3SimplyIdiotGuide
· PspUmdIsoHaxorLinux

RSS Feed
News & Downloads & Wiki

IRC
#eur
EFnet

WAP
http://wap.eurasia.nu

Respected Sites
· consolereview.net
· dextrose-forum.com
· [CRAZY NATION]
· Home of the Hitmen
· pouet.net
· LoveMHz / XeLove
· Console-News.me
· WiiBrew.org
· psx-scene.com
· WiiNewz
· GameCube Linux
· Xbox Linux
· Xbox-Scene.com
· XboxHacker.Net
· xbins.org
· Doom9.net
· bunnie's blog
· debugmo.de
· Dark-AleX.org
· GX-Mod.com
· ElOtroLado.net
· MODCONTROL.COM
· PS2DEV network
· uCON64
· GBADEV.ORG
· GBAtemp.net
· PocketHeaven.com
· PDRoms
· GameSX.com
· ASSEMbler
· phrack.org
· Woz.org
· Captain Crunch

Support...

Pirate Party

OpenCores
Folding@home
Electronic Frontier Foundation
Amnesty International

Nectarine Radio

Demovibes Radio
Linux
Mozilla

Total Page Views
We received
40149118
page views since June 2002

GripShift savegame exploit released
Posted on Monday, January 05, 2009 @ 05:11:47 GMT

psp [source: MaTiAz @ lan.st] So, happy new year. I think presenting a new usermode exploit on the PSP is a good way to start 2009. ;) GripShift has a buffer overflow vulnerability when loading savegames. The savegame contains the profile name which can be easily used to overwrite . The savegame file is pretty big (25kB) so you have lots of space to put your code there. I wrote a simple blob of code to paint the framebuffer completely white (to just indicate that arbitrary code is running :)). The return address is located at offset 0xA9 in the file. In this poc it points to 0x08E4CD50 (which is only a few bytes after the return address), and the code starts at 0xCC in the file.

It was tested on 4.01M33-2 with US version of GripShift (ULUS10040), and psplink.prx, usbhostfs.prx and deemerh.prx loaded (also without psplink and usbhostfs). The decrypted savegame (sorry, couldn't [be bothered to] get Shine's savegame tool working so it's in plaintext form) is in the SDDATA.BIN form which Hellcat's Savegame-Deemer produces (thanks to him, if the program didn't exist I wouldn't have bothered with this. :)). Just copy the ULUS10040SAVE00 directory to /PSP/SAVEPLAIN/ and run the game. :) EDIT: yeah, don't forget to have Savegame-Deemer working, duh.

Credits go to those who deserve them.


Note: This has been confirmed working on PSP-3000 by FreePlay.

 
Login
Nickname

Password

Don't have an account yet? You can create one. As registered user you have advantages like access to our download section, member forums, private messages, post stories with your name and more.

Related Links
· More about psp
· News by Robert


Most read story about psp:
One wire Pandora magic...


Story Rating
Average Score: 0
Votes: 0

Please take a second and vote for this story:

Bad
Regular
Good
Very Good
Excellent



Options

Printer Friendly Page  Printer Friendly Page


"Login" | Login/Create an Account | 0 comments
Threshold
The comments are owned by the poster. We aren't responsible for their content.
 
All trademarks and copyrights on this page are owned by their respective owners.
Comments and forum messages are owned by the Poster.