Posted Sep 01, 2006 at 11:20AM by Ian S. Listed in: Hacks & Exploits Tags: downgrader, Sony, KXploit, Exploit, FrSIRT
Ó

FrSIRTThe French Security Incident Response Team has flagged the new libtiff exploit. Apparently the exploit, which hasn't been fully implemented yet, is already a target for Sony. With news like this, expect to see a firmware 2.81 within the next two weeks. This is the text, as written on the English page.

"Technical Description

A vulnerability has been identified in Sony PSP, which could be exploited by attackers to execute arbitrary commands. This flaw is due to an error in the Photo Viewer when handling malformed TIFF images using libTIFF, which could be exploited by attackers to compromise a vulnerable device by tricking a user into opening a malicious image."

Trends such as this have been seen before, with the 1.5 KXploit release. 3 weeks later, we were handed 1.51. And then, after the original photo exploit in 2.0, it was only two and a half weeks before 2.1 came out. And with the 2.5/2.6 downgrader came 2.7. And now a 2.8. This is sad news, but we can urge all of you: If you want to use homebrew and you think it's too late since you have 2.8 already, DO NOT UPGRADE. When a 2.81 comes out, you can bet work will continue on hacking the original 2.8.

EXTRA: The FrSIRT page has a references list, and guess who's on it? That's right, QJ. A thread in the Developers Dungeon was added to the research and reference list that contributed to the decision to raise the risk level.


[Via FrSIRT] Permalink  |   Email this  |   Linking Blogs   |   Digg It!

Bookmark / Find this article on:


27 Comments


Sort by:
   by milo22 (Unregistered) - 2006-09-01
 » FIRST!!

YEP!

   by gally (Unregistered) - 2006-09-01
 » emm

ok.

   by milo22 (Unregistered) - 2006-09-01
 » HELLO!!!

2.7 came before the 2.5/2.6 downgrader.

   by Mosquito - 2006-09-01
 » 2.71

2.70 and 2.71 were out even before we first heard about updater mode or the downgrader...

   by Vidhun (Unregistered) - 2006-09-01
 » Well ***** happens

This was inevitable. I mean This is the most eagrly awaited and biggest exploit found after kexploit. What more It can F**k All PSP Firmware after 2.0. Expecting that It would not be fixed soon is just foolishness. But I wonder Where is SONY Going With this. Patching patching and more Patching the more roadblocks they will create the more ppl will lose faith in such a wonderfull device. They must go the Microsoft way and must release a SDK friendly for Homebrew Now. Before DS Or Microsoft take on It with their Portables.

   by eggwonder (Unregistered) - 2006-09-01
 » lol

so fanjita, ditlew, others who helped... how do you guys like being defined as "attackers" trying to trick a device?

"malicious" isnt that when u are trying to do something bad? how is trying to make you own games malicious?

   by Warhawke (Unregistered) - 2006-09-01
 » Remote Exploitable, Not

How can they say that libTiff is something that can be exploited via remote? It's not like the libTiff exploit can be run via the web browser. The PSP's browser doesn't even recognise TIF files as an image type, just another file to be downloaded to the MSD.

   by Talbain - 2006-09-01
 » Wtf?

How can we get both badasses like Zidane, and dumbasses like these guys in France?

   by Advertising -
   by kersplatty - 2006-09-01

aww man we gt kicked in the balls wid that one, qjs fault aswell lol, frm now on we shud talk in code .. ....... ...... ...... ;; ..?'[..

   by asdf (Unregistered) - 2006-09-01
 » blah

those who found the exploit should have sat on it a while until 3.0 came out so sony wouldn't have fixed the hole so soon...

   by milo22 (Unregistered) - 2006-09-01
 » @10

that wouldn't have worked because the exploit is in something that isn't PSP specific.
Meaning that other people would have patched this and $ony would have simply used that patch in 3.00



   Re: sanu (Unregistered) - 2006-10-19
 » semia

aaa
   by Victor (Unregistered) - 2006-09-01
 » enjoy

all this homebrew ***** is stupid. do something productive on a pc. enjoy the psp for what it is and quit wasting time.

   by MasterQ - 2006-09-01
 » haha

FrSIRT linked to a post in the Developers Dungeon section of the QJ forums, which is restricted to approved devleopers only...

   by Hmm (Unregistered) - 2006-09-01
 » think ahead

I sure wish they would have kept this exploit secret till the emulator was out, now sony will just fix it.....pretty damn dumb if you ask me.....

   by SeanyP (Unregistered) - 2006-09-01
 » LMAO!

I love how it states the exploits as being open to "attackers" LOLOLOLOLOL!!!!
anything to make it sound like sony are doing the right thing by patching it up! ;)
Good ole' sony!
1.5 FTW!!!!!!!!!!!!!!

   by SeanyP (Unregistered) - 2006-09-01
 » @12 and 14

12: I enjoy the PSP for what it is; MINE!!! I'll do what the ***** i want on it thankyou :]
14: That wouldnt have mattered seeing as there isnt a kernel expoit yet on 2.8. unless the exploit magically reopens on 3.0 or whatever.

   by Advertising -
   by Nipples (Unregistered) - 2006-09-01
 » DAMN THE INTERNET.

Tis both the cause of our pleasures and our pains!

   by egrger (Unregistered) - 2006-09-01
 » GIVE IT UP SONY

2.71 downgrader now available, just give it up cause your limpware aint al dente

   by fsIRT (Unregistered) - 2006-09-01
 » fsIRT are weirdos

Who cares homebrew r0x

   by anonymous stranger - 2006-09-01
 » ok?

Vulnerability reported by NOPx86

wow... nice...

   by The Smokydoggg (Unregistered) - 2006-09-01

Well GEE, maybe if sony would release SOME DECENT SOFTWARE so i could use my PSP FOR WHAT IT IS i wouldn't have to go to the homebrew developers!!!
Besides i bought this machine i paid my damn money and if sony doesn't like that then they can take my psp and give me my money back, and if everybody else does this i'll laugh and watch sony go broke, hey, sony let's not forget the reason you're sitting on that cash is because someone bought your product. NEVER forget that.

   by o joy (Unregistered) - 2006-09-02
 » oh god, not again

"which could be exploited by attackers to compromise a vulnerable device by tricking a user into opening a malicious image"

oh joy, here comes a remake of the 2.0 bricker trojan. ¬¬

   by td (Unregistered) - 2006-09-02
 » i bet sony bribed u

i bet sony bribed them
i mean, if u were really clever and wicked enough to be a terrorist to do somthing u would have found another exploit ANYWAY and downgraded and used "terroristic homebrew!" this is juz sony's weak attempt to stop d/graders and h/brew
cmon, u might find homebrew developed for terrorism or summat but this is juz ga* saying it's a way to brick ur psp or something. it's not, it's so we can enjoy what sony has been to laid back to develop

   by me (Unregistered) - 2006-09-04
 » wtf

"And with the 2.5/2.6 downgrader came 2.7"
wtf
the 2.5/2.6 downgrader came out in July
firmware 2.7 came out in April
also
there was never 2.1
it was 2.01

   by montana (Unregistered) - 2006-09-17

wher ik can download it

   by BadKarma (Unregistered) - 2006-09-22

Lol, 'vulnerability', the only vulnerability is in the monopolies annual NET profits...

STICK IT TO THE MAN!

Nice job on the reference QJ... :D



Featured Content
QJ.NET Blog Network RSS Feeds
MyQJ Feed / PDA
MyQJ RSS / PDA
Blog of Blogs Feed / PDA
QJ.NET RSS / PDA
Gaming Consoles Feed / PDA
Nintendo DS RSS / PDA
PlayStation 3 RSS / PDA
PSP Updates RSS / PDA
Wii RSS / PDA
Xbox 360 RSS / PDA
PC Gaming Feed / PDA
Age of Conan RSS / PDA
Games for Windows RSS / PDA
MMORPG RSS / PDA
Tabula Rasa RSS / PDA
World of Warcraft RSS / PDA
Science Feed / PDA
Science RSS / PDA
Technology Feed / PDA
Apple RSS / PDA
Gadgets RSS / PDA
Mobile RSS / PDA
Photography RSS / PDA
Add QJ.NET
Add to My Yahoo!
Google Reader Subscribe with Bloglines
Add  to your Kinja digest Subscribe in NewsGator Online
Subscribe with Pluck RSS reader Add 'www.qj.net' to Newsburst from CNET News.com
Subscribe with SearchFox RSS del.icio.us www.qj.net
Add to Technorati Favorite! Add to My AOL
furl! it Stumble for Treehugger!

 Username: 
 Password:
Forgot password
New user registration



Poll
Which is the greatest handheld of all time?
Categories

Emulators
Titles
Archives