Post Reply 
Geohot's PS3 Exploit
Author Message
RIKKU
Storm Trooper

Posts: 2,380.2478
Threads: 288
Joined: 12th Aug 2007
Reputation: -2.68834
E-Pigs: 69.6099
Offline
Post: #17
RE: Geohot's PS3 Exploit
Joomla12 Wrote:
[Image: geohot-113-iphone-unlock.jpg]



Geohot Wrote:Here's your silver platter
In the interest of openness, I've decided to release the exploit. Hopefully, this will ignite the PS3 scene, and you will organize and figure out how to use this to do practical things, like the iPhone when jailbreaks were first released. I have a life to get back to and can't keep working on this all day and night.

Please document your findings on the psDevWiki. They have been a great resource so far, and with the power this exploit gives, opens tons of new stuff to document. I'd like to see the missing HV calls filled in, nice memory maps, the boot chain better documented, and progress on a 3D GPU driver. And of course, the search for a software exploit.

This is the coveted PS3 exploit, gives full memory access and therefore ring 0 access from OtherOS. Enjoy your hypervisor dumps. This is known to work with version 2.4.2 only, but I imagine it works on all current versions. Maybe later I'll write up how it works :)

Good luck!
Posted by George Hotz at 6:10 PM


Geohot Wrote:!!EXPLOIT IS FOR RESEARCH PURPOSES ONLY!!

Usage Instructions:

Compile and run the kernel module.

When the "PRESS THE BUTTON IN THE MIDDLE OF THIS" comes on, pulse the line circled in the picture low for ~40ns.
Try this multiple times, I rigged an FPGA button to send the pulse.
Sometimes it kernel panics, sometimes it lv1 panics, but sometimes you get the exploit!!
If the module exits, you are now exploited.

This adds two new HV calls,
u64 lv1_peek(16)(u64 address)
void lv1_poke(20)(u64 address, u64 data)
which allow any access to real memory.

The PS3 is hacked, its your job to figure out something useful to do with it.

http://geohotps3.blogspot.com/
~geohot

Someone just leaked this to me so I thought that I'd share.

Edit: It seems that it's actually hosted on his site.

Download- HERE


- Source: [HERE]
arhhh i love this guy <3
27/01/2010 12:14 AM
Find all posts by this user Quote this message in a reply
Post Reply 


Messages In This Thread
Geohot's PS3 Exploit - Joom - 26/01/2010, 05:01 PM
RE: Geohot's PS3 Exploit - ProperBritish - 26/01/2010, 05:14 PM
RE: Geohot's PS3 Exploit - Grey Ghost - 27/01/2010, 02:01 AM
RE: Geohot's PS3 Exploit - 1-R - 26/01/2010, 05:20 PM
RE: Geohot's PS3 Exploit - Joom - 26/01/2010, 05:21 PM
RE: Geohot's PS3 Exploit - YoYoBallz - 26/01/2010, 05:48 PM
RE: Geohot's PS3 Exploit - Joom - 26/01/2010, 05:59 PM
RE: Geohot's PS3 Exploit - Kana - 26/01/2010, 06:09 PM
RE: Geohot's PS3 Exploit - YoYoBallz - 26/01/2010, 06:13 PM
RE: Geohot's PS3 Exploit - xero1 - 26/01/2010, 06:14 PM
RE: Geohot's PS3 Exploit - Joom - 26/01/2010, 06:15 PM
RE: Geohot's PS3 Exploit - Anger - 26/01/2010, 06:30 PM
RE: Geohot's PS3 Exploit - SchmilK - 26/01/2010, 08:24 PM
RE: Geohot's PS3 Exploit - Syfe - 26/01/2010, 09:28 PM
RE: Geohot's PS3 Exploit - Mr. Shizzy - 26/01/2010, 11:09 PM
RE: Geohot's PS3 Exploit - 1-R - 26/01/2010, 11:11 PM
RE: Geohot's PS3 Exploit - feinicks - 26/01/2010, 11:40 PM
RE: Geohot's PS3 Exploit - SchmilK - 27/01/2010, 04:03 AM
RE: Geohot's PS3 Exploit - RIKKU - 27/01/2010 12:14 AM
RE: Geohot's PS3 Exploit - krystabegnalie - 27/01/2010, 01:43 AM
RE: Geohot's PS3 Exploit - RIKKU - 27/01/2010, 04:19 AM
RE: Geohot's PS3 Exploit - ProperBritish - 27/01/2010, 06:46 AM
RE: Geohot's PS3 Exploit - RIKKU - 27/01/2010, 07:21 AM
RE: Geohot's PS3 Exploit - ProperBritish - 27/01/2010, 12:42 PM
RE: Geohot's PS3 Exploit - Kchan - 27/01/2010, 11:29 AM
RE: Geohot's PS3 Exploit - hecaitomix - 27/01/2010, 11:53 AM
RE: Geohot's PS3 Exploit - YoYoBallz - 27/01/2010, 11:57 AM

Forum Jump:


User(s) browsing this thread: 2 Guest(s)

 Quick Theme: