PSP-Hacks.com

Join the Dashhacks Fan Club on FacebookFollow Dashhacks on TwitterDashhacks YouTube ChannelPSP-Hacks RSS Feed

Hack your Sony PSP

Forums | Tutorials | Custom Firmwares | PSP Themes | Search


 

POC: GripShift SaveGame Exploit Found; Works on PSP-3000!

greg | January 3, 2009

Every so often some claims are made and videos surface, most completely fabricated, but this time — we have the real deal. Discovered by MaTiAz and proven successful by both MaTiAz and FreePlay is a user-mode buffer overflow exploit. The vulnerability lies within the GripShift save game loading routine. Check it –

It’s a step in the right direction all right.

Let me quote MaTiAz –

GripShift has a buffer overflow vulnerability when loading savegames. The savegame contains the profile name which can be easily used to overwrite $ra. The savegame file is pretty big (25kB) so you have lots of space to put your code there. I wrote a simple blob of code to paint the framebuffer completely white (to just indicate that arbitrary code is running). The return address is located at offset 0xA9 in the file. In this poc it points to 0×08E4CD50 (which is only a few bytes after the return address), and the code starts at 0xCC in the file.

It was tested on 4.01M33-2 with US version of GripShift (ULUS10040), and psplink.prx, usbhostfs.prx and deemerh.prx loaded (also without psplink and usbhostfs). The decrypted savegame (sorry, couldn’t [be bothered to] get Shine’s savegame tool working so it’s in plaintext form) is in the SDDATA.BIN form which Hellcat’s Savegame-Deemer produces (thanks to him, if the program didn’t exist I wouldn’t have bothered with this). Just copy the ULUS10040SAVE00 directory to /PSP/SAVEPLAIN/ and run the game. EDIT: yeah, don’t forget to have Savegame-Deemer working, duh.

Download:

GripShift SaveGame Exploit (POC)
(both MaTiAz and FreePlay’s included)

Savegame Deemer
(to decrypt and use the unencrypted GripShift savegame)

- source: lan.st

Share This With...
  • Facebook
  • Digg
  • Twitter
  • RSS
  • Slashdot
  • Technorati
  • del.icio.us
  • Reddit
  • Blogosphere News
  • HackerNews
  • StumbleUpon
  • Google Bookmarks
  • email
Comments (63)

Tagged: :: :: :: ::

RSS feed | Trackback URI

63 Comments »

Comment by Dirkovat se musi furt!
2009-01-03 19:56:52

This is great news! Congrats to all!!!

 
Comment by Amrish
2009-01-03 20:05:35

pretty interesting. well done guys, lets see where this leads…..

 
Comment by jkp
2009-01-03 20:10:25

intriguing…
*runs off to gamestop*

 
Comment by rebman
2009-01-03 20:33:36

Wow, I posted this in the forum here, and I don’t even get any thanks or notice from you guys??

Come on.

Comment by Thankful person
2009-01-03 20:36:55

Thanks Rebman, for sharing this info!

 
Comment by psp hopeful
2009-01-04 07:12:42

Yeah, Thanks a lot!!

 
Comment by Kenneth
2009-01-04 17:11:57

We don’t read the forum that much.

 
 
Comment by Scotch
2009-01-03 20:43:00

very interesting news!
The scene hasn’t been resurrected by a gamesave exploit in quite a while. I’ll be following this…

 
Comment by JAY
2009-01-03 20:55:24

Just brought a UK & US gripshift for $20 hoping for hack in very near future before the price rockets up ;)

Looking good keep the hard work up.

Comment by EOH01
2009-01-04 06:39:07

I see the sales of Grip Shift going through the roof. :)

Great find… Keep it up dudes.

 
 
Comment by asdfg
2009-01-03 20:58:02

Good job, i wonder what this will lead to. I wonder if its gonna be as popular as GTA:Lcs and Lumines on Ebay…lol

 
Comment by Alex
2009-01-03 20:58:54

Wow, im excited now, this is like how to put the homebrew channel on your Wii, you get the wii game The Legend of Zelda: Twllight Princess and put the hack which is hidden as a saved Zelda Twllight Princess saved game, so when you try to play the disc you load up that saved game file and when it loads it it activates that hack. The same thing might happen hear with the psp. (Sorry I know Wii has nothing to do with this site but yea anyway I wanted to show the similaraties.)

Comment by XIYL
2009-01-04 03:47:46

Well If were doing that its like the Xbox with 007 or Mech Assault, that’s how I got XBMC installed as the Dash on mine and all my friends Xbox’s.

Comment by cuttsy
2009-01-04 07:41:27

original xboxs are so awsome

 
 
Comment by asdfg
2009-01-04 08:03:33

Yea, Fyi, the orginal Xbox did a very similar thing as the Wii, and the PSP used to have a exploit in a game too, it was in GTA:LCS, homebrew could be run from it, then later on custom firmware was introduced, and then there was a homebrew to upgrade to a custom firmware through gta:lcs. Lumines was another game for psp, that did downgrading. It is like the Wii

 
Comment by Anonymoos
2009-01-04 22:48:12

holy shi- *runs off to buy twilight*

——————-
cool, 3000 will be hacked soon

 
 
Comment by YAY
2009-01-03 21:33:35

FUK YEA
GETTING CLOSER TO HACKIN THE PSP-3000

 
Comment by Brett
2009-01-03 23:35:29

Fuck yeah

Comment by gregerson316
2009-01-04 05:50:30

Fuck Yeah!!!

Comment by Znupi
2009-01-04 19:21:45

Yeah Fuck!!!

Comment by HyperHacker
2009-01-04 22:45:39

Fuck? Yeah.

Comment by Hell Of Blood
2009-01-21 19:42:54

Fuck Yeah!!!
(So Many Fuck Yeahs!!)

(Comments wont nest below this level)
 
 
 
 
 
Comment by dustin
2009-01-03 23:35:44

“…It was tested on 4.01M33-2 with US version of GripShift…”

he said it worked on M33. has anyone tried on the official firmware?

Comment by lainlives
2009-01-03 23:39:29

umm yes, as its being tested on a psp-3000 in the video…

Comment by Playboy
2009-01-05 08:21:36

rofl lainlives xD

 
Comment by LastmanOut
2009-01-05 23:54:03

Then it’s incorrect on the original post to say he tested it on a psp-3000 with custom firmware 4.01M33-2, it should say he tested it on a psp-3000 with official firmware.

 
 
 
Comment by Brett
2009-01-03 23:38:39

Should I buy Gripshift?

Comment by gregerson316
2009-01-04 05:52:06

If you have a 3000 and want any hope of hacking it soon, then yes. Id do it before Sony pulls it off the shelves and ebay sells it for at least $50 a pop.

 
 
Comment by SinWarrior
2009-01-03 23:50:52

@_@ the description has too many tech terms….

 
Comment by lone tiger
2009-01-04 00:00:01

sooo anyone have a hacked CFW psp 3000 they can sell me? cause i dont want to go thru the trouble of buying gripshift and then find out i did something wrong and bricked a 3000. should i just wait for the 4000? cause all the 3000 is a 2000 wit anti glare screen. and will they ever fix the lines on the screen?

Comment by asdfg
2009-01-04 08:05:19

Its prob the psp screen that is causing the line. but idk if fixed, 3000 aint hacked yet… and 3000 has built in mic.

 
 
Comment by Woody
2009-01-04 00:38:53

Looking forward to it….ill keep my 3000 virgin though….allways good to have a 2nd psp….the fix the lines issue is overblown….ive had 3 psps…and the 3000 is the best BY FAR looking screen sony has ever out into the psp….great work guys…!!

 
Comment by Zachspod
2009-01-04 02:16:17

YES so close for psp3000 now we have an exploit and now hopefully dax will decrypt the new screencode on psp3000 and itl be like whean we used gta on psp1000

 
Comment by SECRET INFORMER
2009-01-04 02:29:52

DAX HAS been workin on it nd we might get da news within 2 dayz dat diz exploit colud take us to cfw path or not…..he haz started workin on it……

 
Comment by igotapencil
2009-01-04 02:43:03

Alright a break through!!!!!!!!!

 
Comment by killer7
2009-01-04 03:34:51

I don’t get it!!

did the psp 3000 got hacked and CFW works on it now?

Comment by Zachspod
2009-01-04 04:05:09

no it just has this exploit THIS ONE ONLY it does not have cfw it states it was tested on a cfw psp (1000 or 2000)

 
Comment by gregerson316
2009-01-04 05:56:26

Someone just has found a hole in the savegame file to where it is possible to write code on it. Its not a guarantee but very possible to hack it or at least make eboot loaders to load homebrew. Back in the day this is what we did, and there were homebrew apps that ran ISO’s too.

Comment by SinWarrior
2009-01-04 07:33:46

“back to the days” seems to be where we need to search for answers :)

 
Comment by asdfg
2009-01-04 08:08:08

Back in teh days is cool, now wehave Pandora, and a shit load of ppl is hacking it eaisly… its still cool though i guess. It seemed more exciting back then. With the firmware emulators and firmware spoofs, battery icon is customizable… Emulators were available n in much development. Now everything kinda died, n psp iso is what most ppl do on it.

 
 
 
Comment by rjomha
2009-01-04 03:53:05

^my question exactly^

 
Comment by luther
2009-01-04 05:25:32

well they said they could get he keys to make the Pandora work if they found another way to exploit a 3000 and looks like they just did.

Comment by DSpider
2009-01-04 09:41:33

That’s right. So let’s just see what happens instead of desperately trying to buy a mediocre game.

 
Comment by HyperHacker
2009-01-04 22:47:38

But will this exploit be enough, or do they need kernel access?

 
 
Comment by EOH01
2009-01-04 06:59:39

This is a bit like the Twighlight hack for the WII. Gets you in the back door and then you need something else to make it useful. :) Glad the PSP homebrew scene is so healthy. :D

You guys all rock…

Comment by asdfg
2009-01-04 08:09:29

This is also like the GTA: lcs and Lumines hack for the PSP…back in the days. Hope this works though.

 
 
Comment by DrFred
2009-01-04 11:35:59

This is just a user mode exploit though, unless they find a way to make it kernel (I’m sure they will eventually), then it’ll still be a long time before it’s hacked completely.

 
Comment by PA1N
2009-01-04 12:53:24

BACK IN THE DAYS LIKE ONLY 2 YEAR AGO LOL GOOD WORK

 
Comment by addict.insane
2009-01-04 14:20:38

Now we wait DA to dump the pre ipl and game over for ta88v3. Don’t buy the game. Cuz if there will be a hack, it will be with pandora battery.

 
Comment by uberusmaximus
2009-01-04 15:41:25

omg yes!!!!

 
Comment by bright alex
2009-01-04 16:27:13

just wait and see

 
Comment by luther
2009-01-04 18:29:30

true its userland but they can now start working on the new keys needed for a pandora to work again.they said it could be done if a gamesave hack or another way in was found.

 
Comment by green
2009-01-04 20:50:10

i actually wont buy gripshift im gonna wait and see what pandora can do because pandora has bound to break that wall with the new motherboard plus pandora = awesome

 
Comment by Rin
2009-01-04 21:20:58

yeah i just picked up 5 copy’s of gripshift looking for more

Comment by Mavrick
2009-01-04 22:14:03

You are dumb, do you think you can sell them on ebay for 100’s? Seriously, GripShift is at ever game store.

 
Comment by AlexandraTheGreat
2009-01-05 05:40:31

Those noobs like you goona purchase all of the cheap copies of GripShift leaving the homebrew developers like DaX with expensive materials to work on. :(

Comment by Playboy
2009-01-05 08:23:32

hahaha, good point mate! xD

 
 
 
Comment by Chinaman
2009-01-04 22:00:21

5 copies? Trying to merchant now…=P

 
Comment by MysterySword
2009-01-05 16:37:16

Only thing about this, is that if the PSP-3000 bricks, there’s still no way to use Pandora…
Nice exploit, though

Comment by LastmanOut
2009-01-06 00:04:12

Well that’s part of the inherent risk you take. If I recall correctly I think there used to be a disclaimer before some firmwares were installed to say if it bricks don’t come crying.

 
 
Comment by Rin
2009-01-05 19:39:35

they were only 7 bucks each at gamestop why not

 
Comment by cheses100
2009-01-07 21:21:10

I have a question, could it be posible to make a program that simply tells the psp to run another program that modifies the firmware or would you still need keral mode for te psp to run the program that your proram tells it to run?

 
Comment by rodge1205
2009-01-08 06:07:14

,,,soon psp 3000 will hack!!!,,,

,,,another bad attempt to stop hacking,,

 
<< Login :: Register >>
Name (required)
E-mail (required - never shown publicly)
URI
Your Comment (smaller size | larger size)


Affiliates



Video Games






PSP Hacks Archives