Advertising (This ad goes away for registered users. You can Login or Register)

PSVita Webkit exploit for 2.60 PoC

Open discussions on programming specifically for the PS Vita.
Forum rules
Forum rule Nº 15 is strictly enforced in this subforum.
Locked
reprep
Posts: 1074
Joined: Tue Dec 17, 2013 4:38 pm

PSVita Webkit exploit for 2.60 PoC

Post by reprep »

Right to the point.

https://bitbucket.org/DaveeFTW/psvita-260-webkit
Advertising
chihuahua
Posts: 479
Joined: Fri Aug 22, 2014 4:39 pm
Location: England

Re: PSVita Webkit exploit for 2.60 PoC

Post by chihuahua »

the 2.60 part worries me.
Advertising
2 x Vita TV PVE-1000 - 3.18/3.18
4 x Vita 1000 - 1.80/3.18/3.18/3.18 kiosk
1 x Vita 2000 - 3.18
PS3 Slim 320gb OFW
PS3 Phat 40gb CFW 4.55 Rogero
PS4 White 500gb
reprep
Posts: 1074
Joined: Tue Dec 17, 2013 4:38 pm

Re: PSVita Webkit exploit for 2.60 PoC

Post by reprep »

chihuahua wrote:the 2.60 part worries me.
Don't worry, quoted from DaveeFTW "This is a PoC of webkit exploit running on psvita. The PoC will work on firmware 2.60 only, but should be simple to adapt to new firmwares."
MadZiontist
Posts: 557
Joined: Sun Mar 18, 2012 3:14 am
Location: Detroit Rap City

Re: PSVita Webkit exploit for 2.60 PoC

Post by MadZiontist »

Very nice.
PSP Star Wars 2001 TA-085v1 32GB 6.60 ME-2.3
PSV 1001 3G 64GB 3.60 HENkaku Enso
PSTV 64GB
xyz
Posts: 61
Joined: Thu Jan 20, 2011 7:06 pm

Re: PSVita Webkit exploit for 2.60 PoC

Post by xyz »

Nice one. This should work on firmwares 2.00-3.18 (not sure about 3.20) that use webkit 536.26. It doesn't work on FWs < 2.00 because webkit is too old and doesn't have shift/unshift optimizations that trigger the exploit and on >=3.30 because it's too new and this is fixed. And while we're at it, anybody managed to get new webkit source code from Sony?
yifanlu
Guru
Posts: 760
Joined: Sun Mar 11, 2012 6:42 am
Contact:

Re: PSVita Webkit exploit for 2.60 PoC

Post by yifanlu »

Hmm seeing roptool was created 2013-07-14, I'm guessing somebody has been pretty busy ;)
gnubaver
Posts: 16
Joined: Sun Jun 29, 2014 6:19 pm

Re: PSVita Webkit exploit for 2.60 PoC

Post by gnubaver »

So does this mean a Webkit exploit for 2.0-3.18 is ready to go?
yifanlu
Guru
Posts: 760
Joined: Sun Mar 11, 2012 6:42 am
Contact:

Re: PSVita Webkit exploit for 2.60 PoC

Post by yifanlu »

As soon as people find gadgets for each fw version, sure. But end of the day, it will only benefit hackers looking to find a kernel exploit and although some people are more optimistic, I don't think homebrew will come from rop.
gnubaver
Posts: 16
Joined: Sun Jun 29, 2014 6:19 pm

Re: PSVita Webkit exploit for 2.60 PoC

Post by gnubaver »

yifanlu wrote:As soon as people find gadgets for each fw version, sure. But end of the day, it will only benefit hackers looking to find a kernel exploit and although some people are more optimistic, I don't think homebrew will come from rop.
What could we expect from ROP? I'm a total newbie when it comes to Vita. I'm pretty new to this, The PSP on the other hand.

Will we see highly illegal stuff? (I'm sure you know what i mean, without the need to discuss this further)
yifanlu
Guru
Posts: 760
Joined: Sun Mar 11, 2012 6:42 am
Contact:

Re: PSVita Webkit exploit for 2.60 PoC

Post by yifanlu »

My hope is that people will pick up this hack and use it to dump WebKit and start attacking the kernel. With only this, you can't do much and definitely can't load any pirated games (or even homebrew code). It's also likely that whatever kernel exploit comes out would require a userland component which this would provide.
Locked

Return to “Programming and Security”