PDA

View Full Version : Geohot attempting to hack the ps3



shak360
12-29-2009, 05:58 AM
A Real Challenge
The PS3 has been on the market for over three years now, and it is yet to be hacked. It's time for that to change.

I spent three weeks in Boston working software only, but now I'm home and have hardware. My end goal is to enable unsigned code execution, making every unit into a test and opening up a third party development community, either through software or hardware(with a mod chip). The PS3 is a prime example of how security should be done, very open docs wise, and the thing even runs Linux. But it isn't unbreakable :-)


Cell SPI
The Cell processor has an SPI port which is used to configure the chip on startup. Well documented here. It also allows hypervisor level MMIO registers to be accessed. In the PS3, the south bridge sets up the cell, and the traces connecting them are on the bottom layer of the board. Cut them and stick an FPGA between.

Quick theoretical attack. Set an SPU's user memory region to overlap with the current HTAB. Change the HTAB to allow read/write to the hypervisor! If that works it's full compromise of the PPU.

would have posted a picture but wouldn't let me

twoboys
12-30-2009, 05:42 PM
Hmmm, interesting.

I'm keeping a close eye on this as well.

About time someone tried a good hardware attack. Wish I had the ability to try it, lol

Nocuddle
12-30-2009, 08:21 PM
no link, no blink.

ThreeDog
12-30-2009, 08:26 PM
Looks promising. Maybe its time to stash a unit to prevent the urge to update?

Links:
http://geohotps3.blogspot.com/ follow his blog here.
http://twitter.com/geohot Twitter :)
http://www.ps3news.com/PS3-Hacks/apple-iphone-unlocker-geohot-begins-hacking-sonys-ps3/ at your own risk....
http://www.ps3news.com/PS3-Hacks/geohot-resumes-sony-ps3-hacking-opens-ps3-hacks-blog/ at your own risk....


I'm not really looking for a software hole, hardware isn't patchable and the console world is used to the idea already. Dumping the HV will really just be cool, cause I've done a couple weeks work with it and I want to see the other side.

Other OS boots sans HD, the HD encryption problem will be solved either by reading/modifying the HV or the 7th SPU.

As far as piracy goes, I'm not going to hack any DRM.

And I don't think this'll make CNN