Quick Jump Daily Digest
Thank you for your interest in the Quick Jump Daily Digest. Get notified of all new content on QJ in our free Daily Digest. To subscribe, enter your email address below and click the subscribe button.
2.80 Kernel Access Exploit from Team C+D!!! |
Listed in: Hacks & Exploits, Homebrew Development Tags: eLoader, Exploit, Mathieulh, psp exploits, psp hacks, Sony, TIFF
Ó
Team C+D just came out of the blue today and posted about kernel access on 2.80 (which only previously had user-mode access from the Tiff exploit). The second I read about this release, I grabbed my sweet laptop, ran in front of my Wii-boxing father, past my dusted PSP, over my NDS and into my sweet computer chair! Just a few moments ago, the C+D team announced that they have achieved kernel access on firmware 2.80, something of which had several people stirring and furiously to test if this was indeed true. Mathieulh, a respected member of the scene, took it upon himself to confirm the validity of this statement, and he comes out of it with a positive response - it works!
This is just a "proof of concept" download, meaning that there is no downgarder yet and no kernel applications will work. However, with the scene demons pouncing on this already, it is only a matter of time before this is usable by the end-user. It currently runs through eLoader (after having compiled the eboot), so only 2.80 is supported (nothing greater). However, many have deducted from the initial testing that this may not be patched in the most recent update, 3.03 from Sony! However, as many of you know we can't run homebrew on 2.81 and beyond, so the concept and method is there, we just don't have the method of launching it!
PS: Thanks for Moca for compiling the makefile into a usable eboot for our members who have a curious mind!
Download: [2.80 Kernel Access Proof-of-Concept]
Discuss: [Forums]
| This story sucks? This story rocks! |
|
|












Comments
Reply
Reply
Reply
Reply
Reply
CANNOT WAIT FOR 1.5!!!
(second)
Reply
Reply
Reply
Reply
Mathieulh running the code
vb_master omgzMathieulh that damn tif exploit is instable as hell, takes ages to run
Steven shh
Mathieulh anyway the MS light is flashing
Mathieulh ok let's reboot the psp
Mathieul and take a look at the MSMathieulh files in there :)
Talidan WOOT
Mathieul opening with hex workshop.....
Fanjita yeah, but is it legit?
Talidan mmk
Mathieulh looks like a legit kdump
Fanjita really?Mathieulh most likely from 2.80 kernelMathieulh yeahMathieulh definitely
Fanjita well bugger mevb_master omfg
Talidan okay
* Talidan buggers Fanjita
Teggleswesome I guess
Steven A zomg i bricked
Reply
Reply
Reply
Reply
Reply
Reply
Reply
HOLY F-U-C-K!
Reply
Reply
Reply
Good job first poster for not saying first post I hope others follow your shining example
Reply
Reply
There. I FLAMED YOU. HAPPY NOW?! XD
Reply
Reply
Reply
www.freewebs.com/pspfriendly
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
this i steh best moment of my life?
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
PS You saved my PSP from bieng sold on Ebay!
Reply
my gf does it to me all the time
Reply
Reply
Reply
Reply
Reply
Reply
for the sake of those unfortunate people
Not me I love my originally jap 1.00 and now 1.50 psp
Reply
dis could lead to new custom firmware with full proof homebrew ability.
congrats to team C+D for the exploit and of course all happy 2.80 who waited patiently. yr patience will soon be paid off.
Reply
Reply
Reply
Reply
i was gunna do the same exact thing... im sooooo glad i didnt! w00t w00t!
*****ing Fanjita, i wana suck ur d1ck!
Reply
john, hoax? time will tell but i believe it's legit.
Reply
Reply
Does it work on TA-082 psp's?
Y I ask? I'm afraid of bricking :)
Reply
Reply
Reply
Reply
shweeeeet.
Reply
w00t
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
qq, what does the kmem.bin file do that the proof of consept thing makes?
Reply
Reply
Reply
Reply
heres the link
http://dl.qj.net/Deviant-Flash-for-fw2.80-PSP-Homebrew-Applications/pg/12/fid/11381/catid/151
Reply
2. LOL@ All of you who though were first, never seen so many thinkin gthat they are first. hahahaha to you all.
Reply
Reply
Reply
Reply
if u come out to australia fanjita i will buy u all the beer u can handle
Reply
nah maybe not but who cares.
so that's preety cool, im hoping for a new custom FW then!
Reply
Reply
Reply
ahahahahahahaha hahahahahah!!!! !!!!!!
yes yes yes yes!!!!!!!!!!!! !!!!!
dgs gonna come soon!!!
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
But a 2.80 SE would be better as the tiff exploit for eLoader/xLoader is quite unstable
Reply
Reply
Reply
Reply
Reply
mine refuses to make me sandwiches though >:(
Reply
Reply
Reply
While "kernel mode" is also a mode in the PSP security model, at lowest level. kernel mode is a property of the CPU. Certain instructions can only be executed properly in kernel mode; in user mode they cause an exception. Memory protection is the other part of kernel mode. The kernel and its data structures are located in kernel memory which cannot be accessed directly by user mode programs. This is basic operating system stuff and is similar on many architectures.
On top of this kernel/user mode is the more advanced security models. In UNIX for instance, everything except actual kernel code is run in user mode, even the "highest" level of access ie root access.
To allow user mode programs to make use of the kernel, controlled access is used, usually known as syscalls. A syscall takes arguments and calls the kernels interface. This interface analyzes the arguments and checks if the user mode program has proper authorization for the request. If not, it is denied, otherwise the kernel performs the operation for the user mode program.
Tyranid already demonstrated how the primitive MMU of the PSP is controlled by DDR hardware registers which makes it possible to disable protection of the kernel memory (but of course it requires kernel mode to do so!). As I already saw noted by Dark_Alex, it is possible that the exploit simple disables the kernel memory protection so that user mode programs can access that memory, without having the kernel mode CPU flag set. That does not mean that user mode programs can automatically perform syscalls that require "kernel mode", because when the kernel checks the authorization, the user mode program will still just have its normal access.
However, if one can modify the kernel memory, obviously such checks can be bypassed, and anything goes...
Reply
Oh, im sorry I shouldn't laugh, the same thing happened to me with 2.70.
Reply
But the answer is no neway
Reply
I've been waiting a long time for this, SCORE! At last I can play my precious kick-ass kernal homebrew and my MGS will work! :)
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
hello world only allows access to user mode,
This allows access to kernel+ much better
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
PS, C+D are briliant
Reply
Reply
Reply
Reply
Reply
Reply
Reply
HAX0Rs totally POWNED $ony!!
Reply
Reply
Reply
YEY!
i like mine with extra salt n butter plz!
Reply
Reply
Reply
Reply
Reply
Reply
RIGHT???
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
I hope that something can be done for the TA-082 users
Reply
Reply
Reply
Reply
Reply
yay!
1.5 here i go!
Reply
what the highest version you can downgrade from?
someone point me in the right direction?
Reply
BEST X-MAS GIVE
BEST X-MAS GIVE
BEST X-MAS GIVE I ONLY WISH THAT ,THAT HAPPENS BEFORE MY B-DAY DECEMBER 30 OHHH THX THANK YOU ARIGATO GRACIAS
Reply
Reply
I AM GAY!!
Reply
Reply
Reply
Reply
Reply
Reply
It just does one task, what does it only get half of the kernel file or something????????
Reply
Reply
Reply
Reply
Reply
You should have "baught" your PSP at a more reputable establishment, where they price their goods "proporly" !!!
HAHHAHA!
1st + Theres no way you ran a "proof of concept" kernel mode app on your 2.82 PSP
2nd + This is the anniversary of Roe vs. Wade...your momma should have taken advantage!
OH SNAP!
FACE!!!!!
Reply
I hope you aren't serious about it, if you just wait a few months I'm sure someone will find a crack in 3.0x or something and as they say the security hole they are exploiting here might not be fixed there, which means a downgrader in no-time
Reply
Reply
The only problem is, we need an exploit to load the code!
Reply
Reply
dat shytz next level!!
Good Job!
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
kernel that means 2.71 users can now just upgrade,
well of course after the great hombrewers do their
thing.
And downgrading at this point makes no since at all
cause everything 1.5 can do 2.71 can do and more,
so wouldn't 2.80 have the same effect.
Anyways don't really know don't have 1.5.
Reply
Reply
Reply
Reply
2. only a noob can brick his psp
3. I ran the eboot on my 3.01 and it just says it can't be run duh.
4. moron if you ever paid over 200$ for your psp
5. Who is the noob, cause it sounds like you tried it on a PS3...you do know the difference right.
Reply
Reply
Reply
Reply
Yay!
Reply
Reply
Reply
Reply
Reply
Reply
So my recommendation is that you make sure to read the readme properly.
Reply
sir?
Reply
Reply
downdater-
DUMP PRX
data chkuppkg.prx
font ipl_update.prx
dic lepton_update.prx
kd
vsh lflash_fatfmt.prx
libpsar.prx
suspend_cancele r.prx
testmode.prx
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
what do i do now or is this it
Reply
Reply
Whoa, never knew that could work... XD
I HATE YOU SONY, YOU FORCE US TO UPGRADE FOR NO REASON!
Reply
Reply
Reply
Reply
My psp is 2.81
I think I have to wait +(
Reply
Reply
I think I have to wait more
Reply
Reply
And now with christmas there will probably be thousands of new noobs...
Reply
Reply
Reply
Does this mean they are working on a Downgrader for the 2.81 PSP??
Someone please let me know nycreamny@aol.com
thanks for the help!!!
Reply
downgrader is everybodies waitin' for. keep up Devs!!
Reply
#### ### ### #######
##### ### ### #####
### ### ####
### ### ######
### ### ######
### ### ####
### ### ######
#### ###### #######
##### ########## ########
Reply
Reply
Reply
But yea ur ****ed but it wont take three years more like three months
Reply
Reply
this is *****
Reply
and look at:
http://www.dcemu.co.uk/vbulletin/showthread.php?t=46764
we have now Nand Flash Access on 2.80!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!!! !!!!!!!!!!!!!
Reply
Reply
Reply
Reply
Reply
Reply
Ookm did it!
Reply
Reply
Reply
I was expecting for it to take a while to do, but I went down to make a sarnie, back up and it's done!
and it's done!
thanks so much...
...downgrader to 1.50 here I come...free games here I come...
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply