PSP Exploit sets off Panda Alarms

Posted Sep 11, 2006 at 5:41PM by QJ Staff Listed in: News Tags: downgrader, Flash Memory, Panda Software, PandaLabs, TIFF
Ó


PSPWhile homebrew development teams have been exploring the libtiff exploit to enable us to play homebrew games, others could be exploring it to brick our handhelds. According to Panda Software, these malware exploit the buffer overflow vulnerability of PSPs with firmware that can view TIFF files.

The company revealed that there is already a proof-of-concept code that demonstrates this vulnerability, and that hackers can take advantage of this flaw to wreak havoc on your PSP. Last year, their PandaLabs detected the Format.A and Tahen Trojan viruses designed to infect PSPs and delete its files, making the handheld unusable - bricked.

The most basic precaution that all PSP owners can take is to only connect to trusted and reliable sources. In addition, all downloaded files and software should be scanned with an updated anti-virus program to clear it of any threat to your PSP, says the company. But you guys always do that, right?



*NOTE* We need to clarify something about the use of anti-virus programs on PSP-specific files. They will also detect the Downgrader, X-flash, and other flash memory-loading programs as a "threat," even if they really aren't (as we all know), and may try to modify or even delete them. So be careful if you really plan on using anti-virus programs on PSP files. Or, more preferably, choose a trusted site.

Via vnunet.com

 
 
 

Comments [refresh]

by Soma - 2006-09-11 12:23
»

Whatever will I do.

by Snarg - 2006-09-11 12:23
» no duh

This is exactly why I said the 2.81 firmware was essential, and had nothing to do with the decrypter.

by Bncplix - 2006-09-11 12:24
»

2nd poster plx?

by XChr0n - 2006-09-11 12:25
»

Psht, only nubs get viruses on their PSP's.

by Gam3Guy - 2006-09-11 12:26
» hmm

Can I trust this site?

by Rayn - 2006-09-11 12:29
» then sony needs to make an Norton or something

if psp's can be hacked then it should be sony's job to make it more safe

by soopergooman - 2006-09-11 12:29
» ...

never thought of scanning before but i will now. as long as the psp can get virus's, someone should be making one or two for the ds's of the werld. why should they get left out or are they the Mac's of hhgaming.

by DOM - 2006-09-11 12:31
» SONY AND THE ALLEGED WEPONS OF MASS MEMORY DESTRUCTION

SONY PROBABLY TIPPED THEM OFF TO GET PEOPLE SCARED I BET SONY HAVE CREATED A MALICIOUS CODE AND THERE GONNA RELESE IT UNDER DRAGONUK'S USERNAME LOL SO WE BLAME HIM WHILS THEY LAUGH......



PEOPLE COMMON SENSE SAYS USE ONLY TRUSTED SOURCES AND IF IN DOUBT WAIT TILL SOME OTHER SUCKER TRYS THE EXPLOIT/PATCH/WHATEVER BEFORE YOU DO OR GET A UP CHIP AND YOU WILL HAVE NADA TO WORRY BOUT

HOLLA AT YA BOY

by gamerz275 - 2006-09-11 12:32
» oh boy

wait.. if its just a TIFF couldnt you get infected by just going on the web browser? (if you open an infected page

by 1 - 2006-09-11 12:34
» 1

BS! Only sony will do that. So we be forced to update firmware, thats crap.

by --- - 2006-09-11 12:36
» ---

SNARG, GTFO OF MY INTERNET. Only *****ing morons get viruses on their PSPs, or on their computers now that I think of it.

by Lyper - 2006-09-11 12:37
»

Agree Post 10!! LoL!! Bah its definately not good for psp homebrew, but we couldnt dodge this virus anymore, now the infection will spreak all over the world!! AHHH DESTRUCTION!!

by meh - 2006-09-11 12:38
»

@6-they fixed the tiff exploits in 2.81........so they dont need to make anything, and why the hell do you think they would care for someone that isnt using the lastest firmware?they are evil

by xdiscrackax - 2006-09-11 12:40
» look

i say get pspantivirus from dcemu a good site and download all hb from here my favorite place

by Snarg - 2006-09-11 12:42
» #13

Exactly.



You see that's why they update firmwares when exploits are found, because it is there responsibility to do so!

They would be neglegent not to. Only narrow minded self absorbed people that can't see anything from any persepective but there own don't get that. cough: post11: cough.

by DoN - 2006-09-11 12:44
» It happened to me..kinda.

Ok well i was usin dev hook and playing a game i got out of the game and soon enough my game was deleted then nxt thing my other games where getting deleted so i formatted it and put dev hook back on with the games but it happened last night so ima have to pay attention to my files...Game was cso could it be the cso's?????

by TheAgent - 2006-09-11 12:52
»

simple answer, don't use your 1.5 psp to go web-surfing

not that its very good at it anyway



Sony could of at least put together some good apps for the psp themselves and whacked them on a UMD, if home brew bothered them that much

by meh - 2006-09-11 13:04
»

@17-i never found a site that has some especific psp destroying virus....most sites that try to do something bad would probably look for a windows/system folder or something....so i assume surfing the web is save(since they cant force you to open a progam that flashes your psp,nor they can flash it directly)just assuming this stuff though...

@15-yeah it is their resposability, but that doesnt make them less evil =p

by acme - 2006-09-11 13:07
»

while we're all scanning for potential viruses the scanenrs will conveniently label our downgraders as virii, since its the exact same exploit...how nice

by double edged sword - 2006-09-11 13:10
» Like Duh...

Lets think about this for a moment. A hack is a hack. Pure and simple. What may seem as a way to get homebrew into our beloved psp's is also a way for others to f**k up our machines.



YES most certainly you are at risk (Anyone with fw less than 2.81 or 1.50 and devhook up to 2.71); I agree with (17) just don't web surf, or if you do, make sure you turn the images off. As a plus, turning off the images makes web sites load much faster on my psp anyway.

by KFC Guy - 2006-09-11 13:17
» it a threat

that happened when they make the downgrade of 2.0 and the news only stay for a couple of month and then dissapeared cause sony think that 2.+ nobody can downgrade so when $ony saw the 2.5/2.6 downgrade they make 2.71 and then 2.71 downgrade see the light they scared so bad that they make 2.81 so fast so they miss the decryption thing and now this the make bussines with panda labs so the can sell and antivirus or better make ppl upgrade the sofware!!!! HEARD THIS SONY I LOVE HOMEBREW AND I NEVER NEVER GIONG TO UPGRA TO YOUR PIECE OF $#!7 FW I RATHER USE DEV-HOOK

SO BOOSTER WHERE R U MAN!!!!!

by skate4life - 2006-09-11 13:18
» double edged sword ??

how do u TURN OFF IMAGES for web browser??

by skate4life - 2006-09-11 13:20
» double edged sword ??

how do u TURN OFF IMAGES for web browser??

by random - 2006-09-11 13:25
» this happened to me?

awhile ago.. like 4 months? ive had a prblem like this.. or soo.. i added a folder into music with some songs (game songs? ) and then in about a week i decided to delete it.. to add some games.. soo i did but wen i deleted it unhooked the usb.. then hooked it up again it automatically copied that song folder back into my psp.. and i tried deleting it directly .. and then with irshell but wateva i did wen i rehook the usb it auto copied the folder.. the onli way i got outa this was format my mem (2gig) .. soo i was wonderin if this had some to do with the topic

by sdgdfg - 2006-09-11 13:27
» fdgfdgf

homebrew firewall? just a thought

by double edged sword - 2006-09-11 13:27
» >> 22 turning off images

Using the official $ony browser you can.



Open up the browser, goto tools -> Settings -> View Settings. From here you can disable images

by Phyllo - 2006-09-11 13:27
» @22-23

RTFM tools > settings > view settings

by skate4life - 2006-09-11 13:33
» double edged sword !! advice

thx man much appricated

by killa726 - 2006-09-11 13:36
» R.I.P

In loving memory of those who died on September 11th, send this to 11 people and something good will happen tomarrow, if not, yo don't have a heart

by double edged swrod - 2006-09-11 13:43
» only protects you from net

My solution still does not protect you from the threats of malicious homebrew that takes advantage of the libtiff exploit.



However, one half of the program is solved, if there is no way for the web-browser to be scripted to turn images back on!!

by liquidtenmillion - 2006-09-11 13:49
» Geuss what you *****ING dumbasses? Sony doesn't read this.

*****ing seriously. Stop being ass*****ed-*****whipped-*****slammed morons. Sony doesn't CARE, they don't give a ***** if you like homebrew, and they don't give a rat's ass if you upgrade or not. Get over yourselves.







Also, the libtiff vulnerability is what causes the buffer overflow you *****headed idiots. Guess what? I, myself, could code a *****ing virus that takes advantage of the overflow. Just like the downgrader, I could simply *****ing delete files from the firmware. Guess we'd see who'd be laughing then huh? It'd be you *****weeds.



Jesus christ.

by peeInMyPantz - 2006-09-11 14:04
»

I only download from this site. so I think I'm safe

by PSPUser - 2006-09-11 14:08
» too funny

what a lot of BS,



1st

yes people could do bad things that could brick your psp using a tiff image but guess what (2.0-2.6) users have the eloader, as long as you use the eloader to run your HB you cant brick your psp since it dont have the access.



2nd

Just download your files (Homebrew) from here, after people have tested it and you'll be ok.

by doh - 2006-09-11 14:12
» @31

hey pal, if you had a clue what 'a virus' is you would not post such bul*****. the best you could try to code is a 'trojan horse' (look up the difference in google). but good luck in your endeavor. don't miss to let us know when the virus is ready ; )



to the rest of the alert netizens here: what dumb ass views random tiffs on his psp? tiffs have one purpose and one only - to propagate homebrew. but if you're careless enough to not check what you intentionally run on your psp's - well, tough luck.

by PARRANOYA - 2006-09-11 14:25
» the revenge of $ony

Hmmmmm.... I made a handheld....others use it for their own nefarious deeds.... so I hack my own system and screw them...thanks again $ony. They are evil enough to do this!

by carboncopy - 2006-09-11 14:40
»

This so called Libtiff exploit trojen is going to delete my files on my flash, than I'd like to have it, becuase you need kernal access and people belive 2.8 has no kernal access.

by b rad - 2006-09-11 14:41
»

i downloaded from sony connect and got some type virus called psp destrution program it lock my psp up and it wont even come on

by yeah - 2006-09-11 14:53
» well...

as long as i get everything from this site....its safe....right?

by Daddy Long Dong - 2006-09-11 15:16
» @ 37

Bull***** bro.

by bloodqc - 2006-09-11 15:38
»

We don't even know if the PSP's browser DO support .tiff files

by H4x0r - 2006-09-11 15:45
»

Couldn't we use this way to also flash the psp with custom firmwares, im not totoally on the scene of all the flash custom firmwares out there but i think that this could also be used in a good way

by Do this - 2006-09-11 15:46
» do this

go to the photo icon of your psp dont push x, push start





weird aint it

by clordio - 2006-09-11 15:52
» why?

I know this happens on pc's but why on such a hacker friendly device as the psp? Sometimes you can't always filter all the dirt out. *sigh*

by Armez - 2006-09-11 16:05
» ...

I agree with part of what 31 said. Sony could care LESS about homebrew, in fact homebrew MAKES SONY MORE MONEY b/c eloders and isos chew up alot of memory so you have to buy more memory=ka-ching...



to 21 shut up you ignorant tard...you make the people w/ a brain stem who run homebew look as dumb as you. You have no idea what you're saying.



I'm a proud 1.5 user, trashing sony THE PEOPLE WHO MADE THE ALMIGHTY PSP is simply assinine.

by hackers are sux - 2006-09-11 16:24
» hacker sux

hacker are ga.y except for the people who hack for good



the qj.net people < Good hacker



virus & trojans people

by GeC - 2006-09-11 19:35
» Exploit

The name itself sais enough. IT IS AN EXPLOID. This means it can be abused, for good and for bad. If used wrongly, and it will be sooner or later, it will crash your PSP or install a virus to infect other PSP's (with for example gamesharing).

Being able to crash your PSP makes it a critical exploid.

It's good there is an update so Sony can not be held responsible for any crashes.

by Project Dogwaffle - 2006-09-11 22:10
»

lol this is total bs caus in the libtiff exploit they dont have kernal mode which means the hacks cant get access to the flash and thats y ppl still prefer to run 1.5FW psps..... like me :)

by .j - 2006-09-11 23:02
»

ESET NOD32 AntiVirus System 4ever!

by liquidtenmillion - 2006-09-11 23:12
» Hey idiots, guess what again?

The libtiff exploit is a buffer overflow. It does indeed have kernel access. How on earth do you think the downgrader exists in the first place? The libtiff vulnerablility OBVIOUSLY has flash access, or there would be no downgrader......



Besides, you definitely could code a virus for the PSP, store it in the flash, and have it load as a module every time you boot your PSP up.



In a buffer overflow you can execute code, ANY code that you can, within certain limits. That is why you have the eboot loader, that is why you had the 2.00 downgrader, and that is why you now have the 2.01-2.71 downgrader without the use of GTA.

by Hajrush - 2006-09-11 23:48
» Kinda late, but.....

R.I.P



In loving memory of those who died on September 11th, send this to 11 people and something good will happen tomarrow, if not, yo don't have a heart

by 50... - 2006-09-11 23:51
» #50 stfu

stfu with ur *****ty chain spam *****

by doh - 2006-09-11 23:53
» @40

netFront _cannot_ show tiff files. the tiff exploit works only when you intentionally open tiff files.

by lead2gold - 2006-09-12 01:11
» i don't have to worry

i loaded my psp with Norton Antivirus 2006, and i run ad-aware homebrew once a day. I switch my sony browser over to Microsoft IE 7. Plus... Thanks to Windows Vista, the remaining 1.8 gigs of my memory card is used up. There is no room for a virus on my psp! :)



Hopefully the losers who are capable of writing viruses for the psp will skip that thought and focus more on the developement for it instead (such as DevHook .47 - Support for 2.81 firmware). Why bring down the community, when you can make it stronger!

by mEZ - 2006-09-12 01:40
» YEAH RIGHT

I don't think fanboys or hackers will create stuff just to sabotage your PSP. Perhaps to take advantage of your PSP would make more sense. The way this sounds to me, the "hackers" Panda Software is talking about are their own programmers creating stuff so that we will buy their product (their anti-virus) to scan stuff for our PSP and at the same time might as well use it for our PCs. Sneaky, sneaky!



Panda is an 'okay' AV but so damn slow and takes over your computer like a Symantec product would do. It's not even that reliable. It's just decent.



So everyone should be careful what they put in their PSP, Make sure what you download comes from a reliable source and scan it with whatever AV works for you (I personally love NOD32).

by ??? - 2006-09-12 01:41
»

Go to these sites this site and pspbrew.com.I go to pspbrew.com and I have never had a problem with them.By the way there is this site I went to called pspwallpapers .comthey gave me a huge virus and I had to completely start all over everything DO NOT GO TO PSPWALLPAPERS.COM!!!!!!IT MESSED UP MY COMPUTER!!!!but now its fine

by spardaofdemons - 2006-09-12 02:07
» Sony trying to make me update?????????

I was on the internet with my 1.5 PSP using Devhook 2.71 on this website for a bout 20 mins and then i found a update in my memory stick (2 of them)!!!!!!!!!!



Banned frrom the forums for a year so can't post there *****!

by CHUCKINGROCKSATSPACESHIPS - 2006-09-12 04:53
» Sony Don't Want To Commit A Crime Like That

Why are people thinking that Sony would make a virus or something to mess up your PSP. They would not do such a thing considering all the potential lawsuits they would endure. Remember what they did on some of their music cds that caught peoples attention and they were forced to stop. They could however make software or firmware that could legally be used as a tool to stop you or make it hard for you to use homebrew.

by ... - 2006-09-12 07:58
» hmm...

wait.. if its just a TIFF couldnt you get infected by just going on the web browser? (if you open an infected page

nice one #9

gamerz275

by Jin - 2006-09-12 08:30
» peeInMyPantz

...you're probably the biggest idiot in here next to that person who uses that chain-letter. Quote...



"*****ing seriously. Stop being ass*****ed-*****whipped-*****slammed morons. Sony doesn't CARE, they don't give a ***** if you like homebrew, and they don't give a rat's ass if you upgrade or not. Get over yourselves."



So you're a dumbass if you think Sony cares whether or not we use homebrew? What the... Words can not express what a damn retard you are for saying that. That's like saying Sony doesn't care about ISO loaders (CSO's are better. ;) ) Sony cares a lot. You can bet your ass they want every single person to upgrade to a 2.81, or to have the lower ones bricked for NOT updating. And as for Sony not reading this? This as in just this site or this as in everything about homebrew? Because otherwise every single one of their "Protects you against malicious software" updates have coincidentally came out after they were discovered using homebrew? ...*****ing idiot.

by CommunistSpaceMonkey - 2006-09-12 08:41
» The first handful of posters are borderline retarded

.

by Marq - 2006-09-12 09:41
» ...

...You're all Psycho.

by Flames21891 - 2006-09-12 12:28
» yeah, nothing to worry about

First:



no, a virus utilizing the libtiff exploit CANNOT brick your PSP through the web browser. The exploit uses an overflow in picture VIEWERS. the web browser is not really a picture viewer and, since it's an exploit pic, probably couldn't be posted directly on a website anyways.



Second:



Sony's excuse of making 2.81 because of "possible malicious software utilizing the exploit" is *****ing bull*****, they hate homebrew and we all know it. It was specifically stated that the exploit DID NOT have kernal access in 2.8. Now how does one expect to access flash in USER MODE. Sony is basicly using the following as an excuse for being Homebrew Haters:



Sony: "OMG OMG, There's a possibility that someone might make a virus in a picture file for 2.01-2.71. Nobody is intelligent enough to keep from opening a suspicious picture file. If we don't make a crappy update soon thier PSP's may be bricked!!!!!



Homebrew users: "well why don't you let us handle not opening the pics, and those of us who can't can simply upgrade to 2.8 which has no kernal access. So go work on a GOOD firmware update *for once*"



Sony: "No, all homebrew users are too stupid to handle it. Prepare for a crappy patc...I mean.......er......umm...... useful update."



Homebrew users: "Great. Can't wait for that pat...I mean....new unconventional format that nobody uses because it sucks."



Sony: "Hey, we could add that too. You should be on our development team."

by jmp - 2006-09-12 13:42
»

number 40 rock on!!!!!!

sony dont care!! so dont blame it on them and plus if you hate sony so much get rid of your psp!!

by dashti - 2006-09-12 18:30
»

evry thing are caming soon

***** this

by Daniel - 2006-09-18 04:28
» The reason why $ony hates Homebrew

As fas as I can tell, the main reason that $ony dispises the homebrew scene is because people will make malicious code that bricks the PSP causing lots more tech calls that ultimately costs $ony more money. By doing their best to prevent homebrew, they try to eliminate people from making those same programs that bricks the PSP, thus saving them money, as well as preventing potential piration caued by programs that rip the image off a UMD disk .. in short, they do this for 2 reasons, in both cases, they are watching their own back.



I got the PSP as a V 1.52 and I upgraded to try to get videos to work, but if I had known what I could do I never would have done so. As for downgrading or such, how hard would it be to copy all the contence of the PSP to some flash folder on a memstik and just replace that with a dump of a V 1.5 or even V1.0 firm? With the font hack you can get the registry, so I bet it can't be that hard to do.



Well, this is just speculation. As for exploiting on a web site, I am going to create a page specificly to see what happens if I exploit the tiff on a site, and see how the PSP works ...

by tuddy - 2006-09-25 06:26
» thats why...

Thats why I only rely on dl.qg.net, I know all the files are not viruses on there!

by gfgf - 2006-09-26 01:05
» ggg

***** all of u. 1.5 psp's can't view tiff images so 1.5's won't get the *****i virus

Add QJ.NET
Add to My Yahoo!
Google Reader Subscribe with Bloglines
Add  to your Kinja digest Subscribe in NewsGator Online
Subscribe with Pluck RSS reader Add 'www.qj.net' to Newsburst from CNET News.com
Subscribe with SearchFox RSS del.icio.us www.qj.net
Add to Technorati Favorite! Add to My AOL
furl! it Stumble for Treehugger!