Video of PSP libtiff exploit in Action

Posted Aug 24, 2006 at 12:59PM by QJ Staff Listed in: Firmware, Hacks & Exploits, News, Videos Tags: DevHook, Exploit, Fanjita, psp250, skylark, Sony
Ó




Adrian (thanks for the tip!) has sent us word of a video that shows the PSP's libtiff vulnerability in action. For those of you who haven't heard of the libtiff vulnerability before, its a vulnerability which leads to the PSP crashing which could possibly lead to an exploit allowing homebrew to be run. Although Sony were supposed to have 'patched' firmwares 2.01+ for any image browser vulnerabilities, it appears that this one slipped the net. This means that although it hasn't been confirmed, this exploit could be present in firmwares up to 2.80.

The video put together by block10 shows the libtiff vulnerability crashing a 1.50 PSP DevHook-ed up to 2.71. As QJ's Jake said a few days ago: Even if this only works on lower firmwares, it will usher in the age of GTA-less homebrew for 2.01+ PSP's, which will be a welcome change for homebrew enthusiasts. Work on this exploit is continuing, and the guys you need to thank for finding this are NOPx86 (for originally finding this vunerability) psp250, Fanjita and Skylark for working on this. Developers can discuss this in the Developers Dungeon whereas normal forum users can find the appropriate thread in our PSP Hacks Forum.

Read: [libtiff Exploit Discussion - Developer's Dungeon]
Read: [libtiff Exploit Discussion - PSP Hacks Forum]

Via block10

 
 
 

Comments [refresh]

by DOPLIC - 2006-08-24 07:54
» wow

So this means what?

by Steve - 2006-08-24 07:54
» great

first comment

great video

good news for 2.80 users

by Jigga - 2006-08-24 07:54
» Question

Sounds cool,



But how does this make the jump from being a stupid "trick" that crashes a PSP to a buffer overflow exploit that can run unsigned code?

by uzi - 2006-08-24 08:01
» useless

this is usless unless it can run code and sofar only theyve got code to run on tiff viewer on windows... not psp ..2 sept things

by ? - 2006-08-24 08:03
» wow

Where can i get a south park bootscreen like that?

by ... - 2006-08-24 08:03
» WTF. i heard screaming

as soon as i heard some yelling (or "singing") i stopped the video... screaming into the microphone = rock.

by nice - 2006-08-24 08:09
» This is great!

I have 2.71 ;(

Can't wait for something to come out of this!!!

by FOR3MAN - 2006-08-24 08:14
» Aces over Eights

Sweet mother of Jesus we're going... Back to the future! Make sure to check you psp's flux capacitor before more testing of this exploit is contiued. Also your psp needs to be struck by lightning for the right amount of juice.



j/k I kicked hombrew a ways back and although I dont really miss it, I would be excited for the oppurtunity to run some emulators one last time. Excellent work code jockeys!

by psphacker12 - 2006-08-24 08:18
» I have worked on this exploit.....

And yet PSPU gives me no credit...

http://youtube.com/watch?v=sxHXG1bSuMc

by mrbones123185 - 2006-08-24 08:20
» about that boot screen

where or how can you make the boot screens i thought you can only use the pmf files from the games

by Paul - 2006-08-24 08:23
»

No offence but that was the worst quality vid i have ever seen, you couldnt see the firmware number or anything...... but good luck with the exploit

by PSPTerminator - 2006-08-24 08:23
» I created this exploit before that guy worked on it

PSU knows better than to give me credit, I work in the shadows. All I ask is for random compliments from peopl I dont know and will never meet. That gives me wood!

gamers-core.com

by 1 - 2006-08-24 08:27
» 1

What the fack was that?! its non-sense... this wont go far..

by psphacker12 - 2006-08-24 08:29
» PSPTerminator^^^^^^^^^^^^^^^^

Me and Skeletor from PSPandMore.net worked on this exploit.................

by psphacker12 - 2006-08-24 08:39
» P.O.C. Download

Here is the proof of concept exploit that I have packaged in a .rar file as proof.



http://www.sendspace.com/file/9mmqzg

Disclaimer : Remember that you are using this program at your own risk. Thank you.

by LOL - 2006-08-24 08:42
» WT*****e!?

THAT MUSIC REALLY ROCK AND GETS THE POINT OVER. I FEEL LIKE A GIANT HOMO FOR HAVING IT EVEN TOUCH MY EARS. I AM NOW SO GAY I CAN ONLY TYPE IN CAPS, THANKS FOR YOU HOMOEROTIC ROCK VIDEO.

by FOR3MAN - 2006-08-24 08:47
» NOBODY GIVES A FLYING PHUCK

We don't care about any of you gutless unregistered fools caliming you created this first. Truth is everyone knows that Voltron created this exploit, fully assembled Voltron of course, and the the gay ass power ranger version Im talking Die Cast Metal Voltron made this hack. Now stand off, your smell would knok a vulture off a chit wagon!

by FOR3MAN - 2006-08-24 08:48
» NOBODY GIVES A FLYING PHUCK

We don't care about any of you gutless unregistered fools caliming you created this first. Truth is everyone knows that Voltron created this exploit, fully assembled Voltron of course, and the the gay ass power ranger version Im talking Die Cast Metal Voltron made this hack. Now stand off, your smell would knock a vulture off a chit wagon!

by moon! - 2006-08-24 08:48
» free us from gta

im tired of the opening music of GTA :)



go tiffexploit!

by psphacker12 - 2006-08-24 08:49
» ^^^^^

How about saying i didnt create this exploit now???

Download it here:

http://www.sendspace.com/file/9mmqzg

by Captian Jack Sparrow - 2006-08-24 08:50
» Wow

Well this is going to be a pretty nifty little tool if they get it working.



Although 2 tips next time; Turn on the light, and dont drink a fifth of vodka before you make a video.

by pspmaster - 2006-08-24 08:50
» gameboot

where do you get the south park gameboot?

by PSPTerminator - 2006-08-24 08:50
» psphacker12 !!!!!!!!!!!

Clearly you have no mind for sacasim. I was tryin gto infer to you that it's pathetic you have to come on here to get your praise. Look at everyone line up to thank you for you total load of BS. All hail you, you the man!

by jordan8930 - 2006-08-24 08:53
» ?

When the psp turned on again at the end why was it on hold?

by psphacker12 - 2006-08-24 08:53
» shut up pspterminator

I did too make this crack, you can download it from my link above. Bow before me cause I am 1337 Hacker. Screw you all Im going to post on the official sony boards where my genius will be appreciated!

by lol - 2006-08-24 08:59
» psphacker

psphacker dont lie. You know you didn't make it.

by pspuser129 - 2006-08-24 09:00
» southpark game boot

how would i get that

by SomeDude - 2006-08-24 09:03
» 2.80

It works on my 2.80 PSP.

by The Pierced Weirdo - 2006-08-24 09:18
» I call

After it "crashes" if you look up next to the clock you see the hold "key" is on. All you have to do is pause the camera and then turn the psp back on then unpause the camera or edit it in windows movie maker. I'm not doubting the fact that this exploit exists. but the video is far from convincing.

by Brawling_Mad - 2006-08-24 09:21
» gays...

wow, there must be a load of 'gangstas' in this forum, as a few people have moaned about the music in the vdieo. SORRY, DO INTELLIGENT PEOPLE OFFEND YOU!!! people need intelligence to play instruments, and they SING!!! not go 'oh, uh, yeh, dis is fiddy cent, lemme take u 2 da candy shop' tht is the most retarded of the retarded music EVER!!! jeez, stop smoking dope and GAIN AN EDUCATION MORONS!!!

by soopergooman - 2006-08-24 09:33
» ..

useeless is something alot of the unregistered commenters say.



I say come on guys, dig in deep and grab this exploit and bring it to fruition. I hope that this leads to homebrew on 2.8. i miss djsp on it.

by psphacker12 - 2006-08-24 09:35
»

hey i did make the exploit first it came to me in a dream i had there i was jacking off to ricky martin win all of the sudden it hit me i can do this..

by Zodionic - 2006-08-24 09:36
»

thats not real music either, i dont want to listen to some guy go, uh yea , uhuh, ill take you to my candy shop so you can lick my penis, mofo,

but at the same time i dont want to listen to some guy screaching down the micraphone about how much his life sucks.

in my opinion the only great music is euphoric trance and electronica. its a shame no one else seems to agree.

i dont get the point in stories being told in music, if i want to hear a story ill read a book.

by FOR3MAN - 2006-08-24 09:42
» LOL AT DEFENDING MUSIC

Why not just defend the fast you like gerbils where the sun don't shine.

I wouldn't be so quick to jump up and defend your flaming putang "rock" there. Just makes you look like more of a phag. They can't sing, they barely play their instruments, and it makes the whole hack video lose credibillity.

Were the Spin Doctors not available? Maybe you couldnt find your Hootie and the Blowfish. .. L M A O

by Landon - 2006-08-24 09:46
» Same background

I have that background he has. also, anyone think this is goin anywhere?

by adf - 2006-08-24 09:55
» adf

It doesn't crash for the last time.

Please stop saying it crashes.

It only freezes.

A crash is diffrent then a freeze.

You can boot or run code with a freeze.

But if it crashes you can run code and boot stuff.

So until I see a real crash.

Im not sure this can even be called a exploit.

If you mess around with the web browser a lot it freezes.

by xfgthdxfth - 2006-08-24 10:07
» dfgr

this crap is FAKE

by Hootie and a blowfish! - 2006-08-24 10:08
» Dont drag us down with that garbage...

I mean they are "better than the beatles" but we be way better than no-taste-is.

by To #38 - 2006-08-24 10:09
» wtf?

this exploit has been proven and fanjita is working on it, it is not fake dumb@$$

by RaiderX - 2006-08-24 10:17
» awesome, a freeze...

how can he write "CONFIRMED exploit"? its not confirmed, all they did was freeze it, nothing has come of it yet, no exploit yet, not confirmed.

by Jumpin Jehosaphat - 2006-08-24 10:37
» All you psp are belonging to us.

@31 i play an instrument and i didn't care for the music in the vid. Just because they worked hard on it dosn't mean anyone has to like it.



To the creator of the video, you should block out your MAC adress for security reasons.



And as for psphacker12 and the rest, i would just like to inform you all that it was I in fact who invented this "mess your psp picture thing", and you should donate all your base to us or i won't finish coding it.



BTW thank you to all the real developers that are working on this exploit, not that it in any way affects me.

by FreePlay - 2006-08-24 10:54
» You people are totally retarded.

Fanjita and Skylark wouldn't still be working on this is if it were fake, now would they? No. Now run along, kids.

by §åggåR - 2006-08-24 10:55
» cool

i think this is really going somewhere like the overflow.tif exploit in 2.00! great progess, this is what keeps the psp scene going!



and as a side note "To the creator of the video, you should block out your MAC adress for security reasons."



why the hell would he, is someone going to hack his psp? i can understand a computer, but goddamn, why should he block his mac address?

by teh g0nz3r - 2006-08-24 10:55
» word up

Elton John all the way.

by skee - 2006-08-24 11:03
» omg this guy is crazzy

he showed his mac address sony could hunt him down LOL

by *****er90129 - 2006-08-24 11:04
» your all *****ing morons

*****,*****,*** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****, *** **,*****,*****,

Add comment

Security code
Refresh

Add QJ.NET
Add to My Yahoo!
Google Reader Subscribe with Bloglines
Add  to your Kinja digest Subscribe in NewsGator Online
Subscribe with Pluck RSS reader Add 'www.qj.net' to Newsburst from CNET News.com
Subscribe with SearchFox RSS del.icio.us www.qj.net
Add to Technorati Favorite! Add to My AOL
furl! it Stumble for Treehugger!