Quick Jump Daily Digest
Thank you for your interest in the Quick Jump Daily Digest. Get notified of all new content on QJ in our free Daily Digest. To subscribe, enter your email address below and click the subscribe button.
MaTiAz does it again! TIFF Hello World exploit for FW 5.03 released, hints at upcoming "awesomeness" |
Listed in: Hacks & Exploits Tags: Exploit, MaTiAz, memory stick, psp exploits, psp hacks, TIFF
Ó
In the words of MaTiAz himself, "The days of TIFF based exploits aren't long gone, at least not yet." The PSP homebrew stalwart once again brings the buzz back into the scene with the release of the third TIFF exploit for the PSP, the Hello World TIFF exploit for FW 5.03.So far, this release only works only on PSP phat, but expect a version for the slim and the brite to come out pretty soon.
Developer Note:
Just copy the files to the memory stick root, disconnect USB and go to photo menu. Don't dismiss the exploit even if it doesn't work on the first time, it's *very* unstable. You might get it working on the first time, but you might as well have to try it 20 times!
As if that's not enough, MaTiAz even throws in a hint of great things to come in a few days, saying, "P.S. Just wait a few days, there's a bit of awesomeness coming up" in his post.
Everything else you'll need is in the file's readme. Now hurry up and download!
Download: 5.03 TIFF Hello World
Thanks EXTER!
Via PSP Gen
| This story sucks? This story rocks! |
|
|












Comments
Reply
I'd worked on this a bit with him, but he's clearly taken it far beyond where it was before... nicely done, MaTiAz :) Glad to see you got things to actually run consistently.
Reply
Anyways, let's hope it's compatible with the 3000. Yay.
Reply
Reply
Reply
Very nice.
I wonder if there was word of this when they played that joke here.
Where are the ribbons?
Reply
i test it and works !!!
to cool, finali i made samething with my 3k.
Reply
Is this an exploit to what? Install custom firmware?
Phat just broke, if this works on Brite.
Hello happy me. XD
Reply
There's an infinite amount of ways to get past any firmware, and it's a lot easier when many devs all ready have access to the inner workings of the things they are making software for.
I think they just missed stuff.
Reply
http://forums.mformature.net/showthread.php?t=2242
Not PSPGEN
Reply
A few days.
I really really can't wait.
Reply
that would be soo bomb
my last psp's analog nub then screen went ka-pooy and ive been needing a new one
Reply
http://forums.mformature.net/showthread.php?t=2242
Sounds like some major posturing and then backing down.
This could be da bomb!
Reply
Reply
^^ That is why. Street smart always wins.
Reply
Reply
Wahoo!
Reply
Reply
Reply
Someone could just as easily make a software exploit that converts a battery into a pandora battery.
Also... if this exploit work the way I think it does, does that mean that they can bypass that whole confusing thingy that Dark Alex explained when he was talking about why Pandoras don't work on Brites/Later Slims?
Reply
Reply
So, if Sony was smart, they'd just remove TIFF support. Of course, that would probably make them look very bad to the end user ("What's this? An update that removes functionality?! Holy Executive Meddling, Batman!").
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
Reply
thing with TA-088v3 and TA-090v2 boards are that when pandora is inserted the pre-IPL checks are done
no TIFF or savegame exploit can bypass that
additionally i believe the trigger for pandora has changed in the TA-090v2 (0xFFFFFFFF is blacklisted, so not only do you need to find the new trigger, you need to pass pre-IPL checks as well).
this for me explains why TA-088v3 gets a green light even though pandora doesnt work and TA-090v2 doesnt do anything.
Reply
Reply
if custom firmware is installed on PSP-3000 it will brick due to pre-IPL checks
Reply
might update it to 5.03 since you've already tested 5.02 and check
Reply
ok
PSP-2000 TA-088 goes into service mode hackable
TA-088v2 goes into service mode hackable
TA-088v3 goes into service mode but not hackable (pre-IPL check)
TA-090 goes into service mode hackable
PSP-3000 TA-090v2 doesnt go into service mode not hackable, but is it pre-IPL check
i started thinking that the previous two TA-088 were hackable then they released TA-88v3 where pandora works but the memstick doesnt
maybe sony did something that even they cant revive dead TA-088v3 boards
then the latest slim board the TA-090 which is hackable again
then the PSP-3000 TA-090v2, now i'm thinkin this is hackable but oxFFFFFFFF has been blacklisted.
once the trigger for service mode is relised for the PSP-3000 the existing IPL's will work.
Reply
5.02 or 5.03
Reply
Reply
@Achooist: Well... not stupid. Lazy and sloppy, yeah.
Reply
Reply
Reply
"I've put in so many enigmas and puzzles into this laughing man tiff that it will keep the professors busy for centuries arguing over what I did to this tiff, and trying to crack my code wont solve anything i want to see if you can crack my code A man of genius makes no mistakes; his errors are volitional and are the portals of discovery.Dark Alex Your battles inspired me or have i solved much more in a matter of minutes then you all in hours How rare and wonderful is that flash of a moment when we realize we have discovered how simple things are listen The value of an idea lies in the using of it so what i tell you is not is to not think so simple like those idiots but to understand simply step outside your box and into Pandora's box but i have found i have learned how to accomplish great things with this tiff is something so simple thank you "
In other words, he's full of sh*t, and he just discovered it completely by accident.
Reply
Hello World for PSP firmware 5.03
The days of TIFF based exploits aren't long gone, at least not yet
Here's the third TIFF exploit for the PSP, enjoy.
Just copy the files to the memory stick root, disconnect USB and go to photo menu.
Don't dismiss the exploit even if it doesn't work on the first time, it's *very* unstable.
You might get it working on the first time, but you might as well have to try it 20 times!
The h.bin is loaded to 0x08800000, and the text address of paf.prx is passed in $a0 to the
binary code. You can then trick out function imports, like for example sceDisplayWaitV blankStart:
sceDisplayWaitV blankStart = (void*)(paf_add r+0x15F068);
Instructions:
1. Copy either slim.tiff or phat.tiff to /PSP/PHOTO/ folder on the memory stick, depending on
your PSP model. Do NOT copy both!
2. Copy h.bin to the root of the memory stick.
Thanks to malloxis, FreePlay, Archaemic, wololo, Cloudy, Davee and everyone else who was involved.
Have fun!
P.S. Just wait a few days, there's a bit of awesomeness coming up.
- MaTiAz
Updated with new version which works on Slims and Phats. No 3000 though. :/
that was copied from the forum i linked above. it also has version 2 of the exploit attached to the post and it isn't too hard to register to try it out. keep up the work on the exploit and it works great. i know when i tried version one on my 3000 it sometimes loaded the picture then it crashed and flashed the wlan light. did something similar on my 2000 and it crashes when i just hit photo on my 1000 like it said. good job
Reply
works on PSP-2000 (dont have a TA-088v3 so couldn't test that specific board) but it dont on PSP-3000
good work MaTiAz
you're onto something great
maybe HEN very soon
Reply
Reply
the votes should be for people who are active in the coversation
Reply
Reply
Do nothing if you do not.
What is it that you want to vote on?
Reply
did you like or dislike this comment.
why or why not.
instead of this system where people may have a great comment thats totally relevant.
and you get people downvoting him not because of their answer, but maybe they know him from around and just like downvoting him.
i think being only able to (and even forced) to vote on reply could get some really good discussions going amongst the real tech heads.
like lately ive enjoyed alot of PS34ME's comments, as he has a seemingly better knowledge on how the two systems perform, and he does it in an unbiased way.
i just think if your going to sit there and rate people's opinions down or up, you have to post a why you think that.
Reply