PSP Hacks - Forums
Go Back   PSP Hacks - Forums > PSP Community > Hacks, Cracks & Mods

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 10-06-2008, 04:34 PM
Ryu's Avatar
Ryu Ryu is offline
Moderator
PSP Titan
 
Join Date: Mar 2006
Location: Dologany
Posts: 11,650
Ryu is on a distinguished road
Default Why TA88v3 cannot be hacked "yet"

http://www.dark-alex.org/forum/viewt...hp?f=44&t=1194
Quote:
Originally Posted by Dark_AleX
This is an explanation of the security that was added in TA88v3, and which will be likely in PSP3000.

When the PSP boots, the boot code (aka pre-ipl or ipl loader) loads the ipl from either the nand or memory stick. The IPL is splitted into pieces of 0x1000 bytes.

First 0xA0 bytes of each block is a header for the kirk hardware command 1. It contains keys,
the size of the cipher data, and two hashes, one for part the header itself, and another one for the body. The 0xF60 remaining bytes are the ciphered body, which will decrypt to 0xF60 plain bytes... if the hashes, which are checked by kirk hardware itself, are OK. (Note: ciphered body can actually be less than 0xF60, in this case, remaining bytes are ignored... before TA88v3) Fir

The security of kirk hashes was destroyed by a timing attack, and the IPL became unprotected.
What has Sony added to fix this?

The answer can be found in 4.00+ slim ipl's. They decreased the size of the ciphered body to 0xF40 to leave 0x20 bytes at the end of each block (at offset 0xFE0).
As stated before, these remaining bytes are ignored... in pre-ipl's of psp's prior to TA88v3, and in fact, they can be randomized and ipl will still boot in those psp's. In newest pre-ipl's, these 0x20 bytes have a meaning.

The first 0x10 bytes is an unknown hash calculated from the decrypted block. It is deduced that is calculated from the decrypted block and not the ciphered one due to the fact that 4.01 and 4.05 have a lot of ipl blocks in common, which, when decrypted, are similar, but they are totally different in its encrypted form. In these two ipl's, this hash is same, as seen in the picture:



The second 0x10 bytes seem also to be dependent of the decrypted body (maybe dependent of the previous 0x10 bytes too?). In the picture it can be seen that they are different in 4.01 and 4.05, but they can actually be interchanged, you can move those 0x10 bytes from the same block in 4.05 ipl to the 4.01 ipl and it will still boot; however it cannot be randomized.

This protection also destroys any possibility of downgrading below 4.00, as these new cpu's won't be able to boot previous firmwares ipl's.

Summary: basically, all security of newest psp cpu's rely on the secrecy of the calculation of those 0x20 bytes. If pre-ipl were dumped somehow, the security would go down TOTALLY.

Graphic summary:
__________________
PSP 1.5 got on USA first day is was 1.5 NOW 4.01 M33-2 -> 5.00 M33(1.50 addon),PS3 60GB FW:2.50
::[ρøwєя for admin]:: & ::[dr34ds for mod]::
It a good idea to have "Hide extensions for known file types" in Folder Options(under Tool) unchecked (turn on extensions)
Reply With Quote
  #2  
Old 10-06-2008, 08:41 PM
jibbz's Avatar
jibbz jibbz is offline
Senior Member
PSP God
 
Join Date: Jan 2007
Location: The Basement - Canada
Posts: 3,258
jibbz will become famous soon enough
Default

http://sceners.org/?itemid=12
Quote:
Dark-AleX.org back online.
As you might have already seen, www.Dark-AleX.org is back online.

Thanks for the waiting.

pd. As you might also already discovered, there is NO relation with any PS3 hack.
pd2. And no, neither about 88v3 hack. (Just going before odd questions)
__________________

la la la la , oh what fun ...Whoops
Reply With Quote
  #3  
Old 10-07-2008, 12:12 AM
igotapencil's Avatar
igotapencil igotapencil is offline
PSP Veteran
 
Join Date: Mar 2007
Location: Gettin' Money
Posts: 1,050
igotapencil User Has a Beginner Reputation
Default

Alright, he is finally back.
__________________
Stay Ballin'


PSP Firmware 5.00M33-4 Get Money™
Reply With Quote
  #4  
Old 10-08-2008, 11:53 AM
Scotch's Avatar
Scotch Scotch is offline
PSP Monk
 
Join Date: Jan 2007
Location: Strawberry Fields
Posts: 2,603
Scotch User Has a Beginner Reputation
Default

Very interesting...If its that small of a problem, then hopefully its just a matter of time before 0x20 gets cracked wide open.

If the PSP3000 can be hacked, I will shit bricks, eat my hat, and go then buy one (psp3k that is)
__________________

Xbox: Blue+Silver Softmodded - 160GB HDD - XBMC
PSP: TA-079 4.01 M33, 2-1.50k. owner since May '05
WEEE!!- Got a new comp for X-mas!
Reply With Quote
Reply

 



Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 09:15 PM.


Powered by vBulletin® Version 3.7.4
Copyright ©2000 - 2009, Jelsoft Enterprises Ltd.
©