FrSIRT Reports libtiff exploit as a "RAISED" Risk |
Ó
The French Security Incident Response Team has flagged the new libtiff
exploit. Apparently the exploit, which hasn't been fully implemented
yet, is already a target for Sony. With news like this, expect to see a
firmware 2.81 within the next two weeks. This is the text, as written
on the English page."Technical Description
A vulnerability has been identified in Sony PSP, which could be exploited by attackers to execute arbitrary commands. This flaw is due to an error in the Photo Viewer when handling malformed TIFF images using libTIFF, which could be exploited by attackers to compromise a vulnerable device by tricking a user into opening a malicious image."
Trends such as this have been seen before, with the 1.5 KXploit release. 3 weeks later, we were handed 1.51. And then, after the original photo exploit in 2.0, it was only two and a half weeks before 2.1 came out. And with the 2.5/2.6 downgrader came 2.7. And now a 2.8. This is sad news, but we can urge all of you: If you want to use homebrew and you think it's too late since you have 2.8 already, DO NOT UPGRADE. When a 2.81 comes out, you can bet work will continue on hacking the original 2.8.
EXTRA: The FrSIRT page has a references list, and guess who's on it? That's right, QJ. A thread in the Developers Dungeon was added to the research and reference list that contributed to the decision to raise the risk level.
Via FrSIRT
21 Jumps Custom firmware 5.50GEN-D now out
Contact Us:
The QJ.net Network |
|
| Site | Feed |
| QJ.NET | RSS |
| Nintendo DS | RSS |
| PlayStation 3 | RSS |
| PSP Updates | RSS |
| Wii | RSS |
| Xbox 360 | RSS |
| MMORPG | RSS |
| Personal Computer Games | RSS |
| iPhone - iPod Touch | RSS |
| QJ.NET Forums | RSS |
User Favorites - December
User Favorites - December
Categories
Archives
Accessories
Add-ons
Applications
Artwork
Batteries
Cheats
Deals
Emulators
Events
Featured Articles
Firmware
Flash Applications
Flash games
Game Demos
Games
Hacks & Exploits
Homebrew Applications
Homebrew Demos
Homebrew Development
Homebrew Emulators
Homebrew Games
Homebrew Themes
How-To
Humor
Imports
Interviews
Magazines
Mods
MY QJ
News
Off Topic
On Shelves This Week
Opinions & Analysis
Podcasts
Previews
PSP Go
PSP Minis
PSP Slim & Lite
QJ How-To Series
QuickJump QuickGuide
QuickJump QuickPeek
Reviews
Rumors
Scans
Screenshots
Site News
Titles
UMD Movies
Videos
Weekend Warrior
Wi-Fi
December 2009
November 2009
October 2009
September 2009
August 2009
July 2009
June 2009
May 2009
April 2009
March 2009
February 2009
January 2009
December 2008
November 2008
October 2008
September 2008
August 2008
July 2008
June 2008
May 2008
April 2008
March 2008
February 2008
January 2008
December 2007
November 2007
October 2007
September 2007
August 2007
July 2007
June 2007
May 2007
April 2007
March 2007
February 2007
January 2007
December 2006
November 2006
October 2006
September 2006
August 2006
July 2006
June 2006
May 2006
April 2006
March 2006
February 2006
January 2006
December 2005
November 2005
October 2005
September 2005
August 2005
July 2005
June 2005
May 2005
April 2005
March 2005
February 2005
January 2005
Comments [refresh]
YEP!
ok.
2.7 came before the 2.5/2.6 downgrader.
2.70 and 2.71 were out even before we first heard about updater mode or the downgrader...
This was inevitable. I mean This is the most eagrly awaited and biggest exploit found after kexploit. What more It can F**k All PSP Firmware after 2.0. Expecting that It would not be fixed soon is just foolishness. But I wonder Where is SONY Going With this. Patching patching and more Patching the more roadblocks they will create the more ppl will lose faith in such a wonderfull device. They must go the Microsoft way and must release a SDK friendly for Homebrew Now. Before DS Or Microsoft take on It with their Portables.
so fanjita, ditlew, others who helped... how do you guys like being defined as "attackers" trying to trick a device?
"malicious" isnt that when u are trying to do something bad? how is trying to make you own games malicious?
How can they say that libTiff is something that can be exploited via remote? It's not like the libTiff exploit can be run via the web browser. The PSP's browser doesn't even recognise TIF files as an image type, just another file to be downloaded to the MSD.
How can we get both badasses like Zidane, and dumbasses like these guys in France?
aww man we gt kicked in the balls wid that one, qjs fault aswell lol, frm now on we shud talk in code .. ....... ...... ...... ;; ..?'[..
those who found the exploit should have sat on it a while until 3.0 came out so sony wouldn't have fixed the hole so soon...
that wouldn't have worked because the exploit is in something that isn't PSP specific.
Meaning that other people would have patched this and $ony would have simply used that patch in 3.00
all this homebrew ***** is stupid. do something productive on a pc. enjoy the psp for what it is and quit wasting time.
FrSIRT linked to a post in the Developers Dungeon section of the QJ forums, which is restricted to approved devleopers only...
I sure wish they would have kept this exploit secret till the emulator was out, now sony will just fix it.....pretty damn dumb if you ask me.....
I love how it states the exploits as being open to "attackers" LOLOLOLOLOL!!!!
anything to make it sound like sony are doing the right thing by patching it up! ;)
Good ole' sony!
1.5 FTW!!!!!!!!!!!! !!
12: I enjoy the PSP for what it is; MINE!!! I'll do what the ***** i want on it thankyou :]
14: That wouldnt have mattered seeing as there isnt a kernel expoit yet on 2.8. unless the exploit magically reopens on 3.0 or whatever.
Tis both the cause of our pleasures and our pains!
2.71 downgrader now available, just give it up cause your limpware aint al dente
Who cares homebrew r0x
Vulnerability reported by NOPx86
wow... nice...
Well GEE, maybe if sony would release SOME DECENT SOFTWARE so i could use my PSP FOR WHAT IT IS i wouldn't have to go to the homebrew developers!!!
Besides i bought this machine i paid my damn money and if sony doesn't like that then they can take my psp and give me my money back, and if everybody else does this i'll laugh and watch sony go broke, hey, sony let's not forget the reason you're sitting on that cash is because someone bought your product. NEVER forget that.
"which could be exploited by attackers to compromise a vulnerable device by tricking a user into opening a malicious image"
oh joy, here comes a remake of the 2.0 bricker trojan. ¬¬
i bet sony bribed them
i mean, if u were really clever and wicked enough to be a terrorist to do somthing u would have found another exploit ANYWAY and downgraded and used "terroristic homebrew!" this is juz sony's weak attempt to stop d/graders and h/brew
cmon, u might find homebrew developed for terrorism or summat but this is juz ga* saying it's a way to brick ur psp or something. it's not, it's so we can enjoy what sony has been to laid back to develop
"And with the 2.5/2.6 downgrader came 2.7"
wtf
the 2.5/2.6 downgrader came out in July
firmware 2.7 came out in April
also
there was never 2.1
it was 2.01
wher ik can download it
Lol, 'vulnerability', the only vulnerability is in the monopolies annual NET profits...
STICK IT TO THE MAN!
Nice job on the reference QJ...
aaa