Quoted
Hello hypervisor, I'm geohot
I have read/write access to the entire system memory, and HV level access to the processor. In other words, I have hacked the PS3. The rest is just software. And reversing. I have a lot of reversing ahead of me, as I now have dumps of LV0 and LV1.
3 years, 2 months, 11 days...thats a pretty secure system
Took 5 weeks, 3 in Boston, 2 here, very simple hardware cleverly applied, and some not so simple software.
Shout out to George Kharrat from iPhoneMod Brasil for giving me this PS3 a year and a half ago to hack. Sorry it took me so long
As far as the Exploit goes, I'm not revealing it yet. The theory isn't really patchable, but they can make implementations much harder. Also, for obvious reasons I can't post dumps. I'm hoping to find the decryption keys and post them, but they may be embedded in hardware. Hopefully keys are setup like the iPhone's KBAG.
A lot more to come...
Quoted
In the interest of openness, I've decided to Release the Exploit. Hopefully, this will ignite the PS3 scene, and you will organize and figure out how to use this to do practical things, like the iPhone when jailbreaks were first released. I have a life to get back to and can't keep working on this all day and night.
Please document your findings on the psDevWiki. They have been a great resource so far, and with the power this Exploit gives, opens tons of new stuff to document. I'd like to see the missing HV calls filled in, nice memory maps, the boot chain better documented, and progress on a 3D GPU driver. And of course, the search for a software Exploit.
This is the coveted PS3 Exploit, gives full memory space access and therefore ring 0 access from OtherOS. Enjoy your hypervisor dumps. This is known to work with version 2.4.2 only, but I imagine it works on all current versions. Maybe later I'll write up how it works
This is a good article for what it means for the less technical.
Good luck!
This post has been edited 1 times, last edit by "Ark" (Jan 27th 2010, 3:33pm)
Hat geohot nicht auch den iPod und das iPhone das erste mal gehackt und gejailbreakt??
Hat geohot nicht auch den iPod und das iPhone das erste mal gehackt und gejailbreakt??
Nein, er hat blackra1n geschrieben, welches oft zum jailbreaken genommen wird.
Einer der ersten war er aber nicht.
Sein echter Name ist übrigens George Hots (oder Hotz, hab ich vergessen)
Der Blackra1n jailbreak ist übrigens nicht so gut wie der des Dev-Teams, da PushNotifications danach nicht mehr gehen
danacb noch appsync drauf, vlc4iphone und das proggi iphone folders (braucht für 2gb daten ca. 2minuten zum rüberspielen)
Der Ultimative Umbau-Thread
Erste Hilfe für Newbies
*Klick Me*
Quoted
46 DC EA D3 17 FE 45 D8 09 23 EB 97 E4 95 64 10 D4 CD B2 C2
![]()



Der Ultimative Umbau-Thread
Erste Hilfe für Newbies
*Klick Me*
"Took 5 weeks, 3 in Boston, 2 here, very simple hardware cleverly applied, and some not so simple software."11 Wochen ist doch gar nix für so ne Leistung![]()

Copyright © 2008-2012 by www.wii-homebrew.com