PS3 hacked
(too old to reply)
2010-01-23 20:43:09 UTC
"Hello hypervisor, I'm geohot
I have read/write access to the entire system memory, and HV level access to
the processor. In other words, I have hacked the PS3. The rest is just
software. And reversing. I have a lot of reversing ahead of me, as I now
have dumps of LV0 and LV1.
3 years, 2 months, 11 days...thats a pretty secure system
Took 5 weeks, 3 in Boston, 2 here, very simple hardware cleverly applied,
and some not so simple software.
Shout out to George Kharrat from iPhoneMod Brasil for giving me this PS3 a
year and a half ago to hack. Sorry it took me so long :)
As far as the exploit goes, I'm not revealing it yet. The theory isn't
really patchable, but they can make implementations much harder. Also, for
obvious reasons I can't post dumps. I'm hoping to find the decryption keys
and post them, but they may be embedded in hardware. Hopefully keys are
setup like the iPhone's KBAG.
A lot more to come..."
Maybe taking Linux away wasn't a good idea.
2010-01-27 12:45:27 UTC
"In the interest of openness, I've decided to release the exploit.
Hopefully, this will ignite the PS3 scene, and you will organize and figure
out how to use this to do practical things, like the iPhone when jailbreaks
were first released. I have a life to get back to and can't keep working on
this all day and night.
This is the coveted PS3 exploit, gives full memory space access and
therefore ring 0 access from OtherOS. Enjoy your hypervisor dumps. This is
known to work with version 2.4.2 only, but I imagine it works on all current
versions. Maybe later I'll write up how it works :)"
Cue firmware update that "fixes compatibility issue on certain software" as
Sony puts it when fixing exploits on the PSP.
