Post Reply 
Geohot's PS3 Exploit
Author Message
Joom
WOOP
Worlds End

Posts: 4,206.7320
Threads: 417
Joined: 20th Mar 2009
Reputation: 5.41709
E-Pigs: 134.1772
Offline
Post: #4
RE: Geohot's PS3 Exploit
I can't wait for the fun to begin.

Quote:geohot: well actually it’s pretty simple
geohot: i allocate a piece of memory
geohot: using map_htab and write_htab, you can figure out the real address of the memory
geohot: which is a big win, and something the hv shouldn’t allow
geohot: i fill the htab with tons of entries pointing to that piece of memory
geohot: and since i allocated it, i can map it read/write
geohot: then, i deallocate the memory
geohot: all those entries are set to invalid
geohot: well while it’s setting entries invalid, i glitch the memory control bus
geohot: the cache writeback misses the memory :)
geohot: and i have entries allowing r/w to a piece of memory the hypervisor thinks is deallocated
geohot: then i create a virtual segment with the htab overlapping that piece of memory i have
geohot: write an entry into the virtual segment htab allowing r/w to the main segment htab
geohot: switch to virtual segment
geohot: write to main segment htab a r/w mapping of itself
geohot: switch back
geohot: PWNED
geohot: and would work if memory were encrypted or had ECC
geohot: the way i actually glitch the memory bus is really funny
geohot: i have a button on my FPGA board
geohot: that pulses low for 40ns
geohot: i set up the htab with the tons of entries
geohot: and sPa/\/\ press the button
geohot: right after i send the deallocate call

[Image: ROVBdMh.png]
3DS Friend Code: 5000-6045-4964
(This post was last modified: 26/01/2010 05:45 PM by Joom.)
26/01/2010 05:21 PM
Find all posts by this user Quote this message in a reply
Post Reply 


Messages In This Thread
Geohot's PS3 Exploit - Joom - 26/01/2010, 05:01 PM
RE: Geohot's PS3 Exploit - ProperBritish - 26/01/2010, 05:14 PM
RE: Geohot's PS3 Exploit - Grey Ghost - 27/01/2010, 02:01 AM
RE: Geohot's PS3 Exploit - 1-R - 26/01/2010, 05:20 PM
RE: Geohot's PS3 Exploit - Joom - 26/01/2010 05:21 PM
RE: Geohot's PS3 Exploit - YoYoBallz - 26/01/2010, 05:48 PM
RE: Geohot's PS3 Exploit - Joom - 26/01/2010, 05:59 PM
RE: Geohot's PS3 Exploit - Kana - 26/01/2010, 06:09 PM
RE: Geohot's PS3 Exploit - YoYoBallz - 26/01/2010, 06:13 PM
RE: Geohot's PS3 Exploit - xero1 - 26/01/2010, 06:14 PM
RE: Geohot's PS3 Exploit - Joom - 26/01/2010, 06:15 PM
RE: Geohot's PS3 Exploit - Anger - 26/01/2010, 06:30 PM
RE: Geohot's PS3 Exploit - SchmilK - 26/01/2010, 08:24 PM
RE: Geohot's PS3 Exploit - Syfe - 26/01/2010, 09:28 PM
RE: Geohot's PS3 Exploit - Mr. Shizzy - 26/01/2010, 11:09 PM
RE: Geohot's PS3 Exploit - 1-R - 26/01/2010, 11:11 PM
RE: Geohot's PS3 Exploit - feinicks - 26/01/2010, 11:40 PM
RE: Geohot's PS3 Exploit - SchmilK - 27/01/2010, 04:03 AM
RE: Geohot's PS3 Exploit - RIKKU - 27/01/2010, 12:14 AM
RE: Geohot's PS3 Exploit - krystabegnalie - 27/01/2010, 01:43 AM
RE: Geohot's PS3 Exploit - RIKKU - 27/01/2010, 04:19 AM
RE: Geohot's PS3 Exploit - ProperBritish - 27/01/2010, 06:46 AM
RE: Geohot's PS3 Exploit - RIKKU - 27/01/2010, 07:21 AM
RE: Geohot's PS3 Exploit - ProperBritish - 27/01/2010, 12:42 PM
RE: Geohot's PS3 Exploit - Kchan - 27/01/2010, 11:29 AM
RE: Geohot's PS3 Exploit - hecaitomix - 27/01/2010, 11:53 AM
RE: Geohot's PS3 Exploit - YoYoBallz - 27/01/2010, 11:57 AM

Forum Jump:


User(s) browsing this thread: 6 Guest(s)

 Quick Theme: