Tag Archives: Geo Hot

[PS3] GeoHot Opens All HV’s SPUs / XorLoser Preps Manual

Obviously notorious George Hotz has managed to get all 7 SPUs of the Playstation 3’s CPU under his control. This means although he cannot access the CPU’s root key, he now can decrypt everything that’s going thru these SPUs like datastreams of (encrypted) commercial games.

The PPU is higher on the control chain then the SPUs. Even if checks were to be added to, for example, verify the hypervisor before decrypting the kernel, with clever memory mappings you can hide your modified hypervisor.

In the meantime another hacker going under the nick XorLoser has released a more detailed manual of how to use GeoHot’s exploitation files and how to do the glitching.

Besides that XorLoser maintains a plugin for reverser’s beloved Interactive Disassembler (IDA) that contains special PPC instructions for Xbox360 and PS3.

Congratulations to GeoHot. Kudos fly out to XorLoser.

Links

» GeoHot: On Isolated SPUs
» XorLoser: PS3 Exploit – Software
» XorLoser: PS3 Exploit – Hardware
» XorLoser: PS3 and Xbox360 IDA PlugIn
» Hex-Rays.com: IDA Pro

[PS3] GeoHot Hacks PS3’s Hypervisor Protection

Notorious iPhone hacker GeoHot has succesfully circumvented the Playstation’s security system. According to his latest blog entry, he has dumped LV0 and LV1 code, thus allowing him to (theoretically) run code on the processor, bypassing the hypervisor.

The Playstation’s hypervisor is intended to run third party software (like Yellow Dog Linux) on a virtualized level, thus maintaining system integrity and protection of the host system. Within this virtualized environment arbitrary access to certain hardware devices has been disabled, thus allowing only basic access to the graphic processing unit (GPU) for example.

GeoHot seems to have broken the chain of trust. This means he can bypass the hypervisor to directly access hardware like the GPU with his custom code. Anyway he has not released any further information or proof of his work. But hey, it is not anyone, it is GeoHot, so it seems solid.

We compiled some links for people being interested in the hypervisor protection topic.

» GeoHot: Hello hypervisor, I’m GeoHot
» WeboPedia.com: Virtualization – All About Hypervisors
» PS3News: Overview on Security architecture of the PS3
» PS2Dev Wiki: Details about hypervisor functions of the PS3 and Toshiba’s CellEB
» PS3News: A PS3 Game’s Flow of Execution; PS3’s base AIX


Massive Attack: Protection (1995)…

[iPhone] GeoHot Announces Latest Baseband Unlock

George Hotz – by now almost any iPhone user should know that guy – hacked the latest baseband firmware 05.11.07. The unlock will be named BlackSn0w, well …

That means all carrier or SIM locked iPhones around the globe running this latest firmware can be used with different SIM cards from different carriers. Thus making holidays no roaming fee horror show.

Information about the unlock procedures will be released on BlackRa1n.com on Nov 04, 2009. Until then, enjoy GeoHot’s video proof:

Kudos fly out to GeoHot. Standing work, dude. But why the hell is there always Snow, Rain, Snow, Rain. Why no sunshine, guys?

[iPod] GeoHot Jailbreaks iPod Touch Firmware 3.1

GeoHot today posted a photo of a jailbroken iPod Touch running iPhone OS 3.1. He eventually made it. As of now there is no more information available, but it is likely that this is the approach he and the Chronic Dev Team were talking about.

[iPhone] GreenPois0n to Jailbreak all iPhones and iPod Touchs

What has happened so far

Some irritation is going on in the Apple hacking community. On the one hand GeoHot today announced that there will be a tool that will allow jailbreaking all iPhones and iPod Touchs, but as he wished to perform further tests he didn’t tell anything about the procedure.

The Chronic Dev Team on the other hand who seem to have been working together with GeoHot now released the technical details about this hack. Sadly as there is no GreenPois0n tool available as of now, the technical details are most likely useless for 99,9% of all iPhone and iPod users.

Reasons are unknown why the Chronic Dev Team released the information before a tool has been finished. But it seems GeoHot is not amused by taking these steps.

Update 2009, Oct 19th: GeoHot and the Chronic Dev Team tell they have independently found the bug that allows for jailbreaking the 3.1 firmware.

Enduser compatible information

According to mFX.ch (german only) the forthcoming GreenPois0n jailbreak tool will not require to bring the iPhone into DFU mode. The GreenPois0n will be released on the PirateBay*.

External Links

» GeoHot on the universal 3.1 jailbreak
» Chronic Dev Team on 3.1. jailbreak progress
» GreenPois0n site (only dummy page atm)…
» TheiPhoneWiki with technical details

* for legal reasons here in Germany we cannot link directly to the PirateBay.