Thread: How does the TIFF Exploit work?

Page 1 of 2 12 LastLast
Results 1 to 15 of 16
  1. #1 How does the TIFF Exploit work? 
    Member PSP User
    Join Date
    Sep 2010
    Posts
    51
    I want to know how the tiff exploit worked from a technical aspect, as i may or may not be onto something that could allow chickhen on firmwares higher than 5.03.

    I suspect that the exploit worked by overloading the psp's ram, causing it to have to restart in a vulnerable state. If this is not the case then please explain how it works.
    Fear the persuasion.
    Reply With Quote  
     

  2. #2  
    Texas Hellboy PSP Elite Hacker xavis's Avatar
    Join Date
    Feb 2009
    Posts
    8,073
    the TIFF sends a code to whatever kernel or user vulnerability first. then overrides, then goes to ram.

    which has been tried on all current firmware by more trusted people and has been determined as unusable.


    also, IF you do have an exploit, current chickhen won't work on higher firmwares. you'd have to make a whole new one from scratch and code it for that firmware.
    Last edited by xavis; 09-11-2010 at 03:46 AM.

    "I don't have an anger problem, I have a problem with idiots." - Hank Hill


    CXMB Guide | IRSHELL UsbHost/RemoteJoy Guide! | Hell's Bells
    Reply With Quote  
     

  3. #3  
    Senior Member PSP Elite Hacker Product F(RED)'s Avatar
    Join Date
    Dec 2007
    Posts
    2,898
    It causes a stack overflow.

    AMD Phenom II X4 945 3.0GHz | 4GB A-Data DDR2 RAM | Sparkle Nvidia GeForce 9400GT 512MB
    Intel Core i5 M430 2.27GHz | 4GB DDR3 RAM | Intel GMA HD
    Reply With Quote  
     

  4. #4  
    Member PSP User
    Join Date
    Sep 2010
    Posts
    51
    wait...if code was embedded in the tiff, isnt the same also true for a sound or video file?
    Last edited by Unkind Student; 09-11-2010 at 03:13 PM. Reason: New Theory!
    Fear the persuasion.
    Reply With Quote  
     

  5. #5  
    Texas Hellboy PSP Elite Hacker xavis's Avatar
    Join Date
    Feb 2009
    Posts
    8,073
    yes. but the important code is not in the TIFF. its in the .BIN file.

    "I don't have an anger problem, I have a problem with idiots." - Hank Hill


    CXMB Guide | IRSHELL UsbHost/RemoteJoy Guide! | Hell's Bells
    Reply With Quote  
     

  6. #6  
    Member PSP User
    Join Date
    Sep 2010
    Posts
    51
    Quote Originally Posted by xavis View Post
    yes. but the important code is not in the TIFF. its in the .BIN file.
    So how is the .BIN file associated with the Image, or any other type of media viewable by the PSP?
    Fear the persuasion.
    Reply With Quote  
     

  7. #7  
    Texas Hellboy PSP Elite Hacker xavis's Avatar
    Join Date
    Feb 2009
    Posts
    8,073
    the TIFF file when loaded tells the system to load the h.bin file which has everything in it. codes, overrides, all that good shit.

    "I don't have an anger problem, I have a problem with idiots." - Hank Hill


    CXMB Guide | IRSHELL UsbHost/RemoteJoy Guide! | Hell's Bells
    Reply With Quote  
     

  8. #8  
    Member PSP User
    Join Date
    Sep 2010
    Posts
    51
    So the tiff has a code embedded in it that tells the psp to read a certain file, regardless of a signature from sony.
    Fear the persuasion.
    Reply With Quote  
     

  9. #9  
    Texas Hellboy PSP Elite Hacker xavis's Avatar
    Join Date
    Feb 2009
    Posts
    8,073
    yes.


    filler

    "I don't have an anger problem, I have a problem with idiots." - Hank Hill


    CXMB Guide | IRSHELL UsbHost/RemoteJoy Guide! | Hell's Bells
    Reply With Quote  
     

  10. #10  
    The King Of Chinatown PSP Elite Hacker Geek's Avatar
    Join Date
    Jan 2009
    Posts
    6,557
    TIFF images are high quality and as such are often used for exploits, however, to prevent anymore TIFF exploits sony has disabled the ability to read the format on PSP




    I'm not a pirate. I am a 21st century Che liberating files from the capitalist overlords.
    How to check if you can mod your PSP

    Thanks MZ for a sleek sig!
    Reply With Quote  
     

  11. #11  
    Member PSP User
    Join Date
    Sep 2010
    Posts
    51
    Would embedding such a code be possible with a PNG of GIF format, or was it only possible with TIFF because of its high quality.
    Fear the persuasion.
    Reply With Quote  
     

  12. #12  
    Texas Hellboy PSP Elite Hacker xavis's Avatar
    Join Date
    Feb 2009
    Posts
    8,073
    theoretically it might work. but you would have to go to lan.st and ask them. they would know.

    be aware a crash is different then an exploit. so dont go in and hex the shit willy nilly.

    "I don't have an anger problem, I have a problem with idiots." - Hank Hill


    CXMB Guide | IRSHELL UsbHost/RemoteJoy Guide! | Hell's Bells
    Reply With Quote  
     

  13. #13  
    Senior Member PSP Elite Hacker DarkFoxSniper's Avatar
    Join Date
    Aug 2007
    Posts
    5,879
    LibTIFF still works and some crashes were even found but as xavis said a crash is not an exploit.

    Quote Originally Posted by iedwardsIII
    In the words of DFS, go die.

    PSP Motherboard F.A.Q. Coldboot Tutorial





    Reply With Quote  
     

  14. #14  
    Member PSP User
    Join Date
    Sep 2010
    Posts
    51
    Yeah i am aware of that, trust me, im dont know nearly enough about programming and the such in order to hex edit. I really just want to find a vulnerability that others can work with.

    Even if it is hacked we would need to figure out the proprietary software deal, so any mistakes can be easily fixed.
    Fear the persuasion.
    Reply With Quote  
     

  15. #15  
    Texas Hellboy PSP Elite Hacker xavis's Avatar
    Join Date
    Feb 2009
    Posts
    8,073
    dude a 5 year old hex edit. thats basicly how you find a crash. find out what you can do to a tiff and, test the crash on CFW with psplink(or something) then ask at lan.st.

    if they tell you that you can get full control over $ra (i believe thats it) then ya, good for you.

    not likely though.

    "I don't have an anger problem, I have a problem with idiots." - Hank Hill


    CXMB Guide | IRSHELL UsbHost/RemoteJoy Guide! | Hell's Bells
    Reply With Quote  
     

Page 1 of 2 12 LastLast

Similar Threads

  1. Weird results with tiff exploit
    By teidullie in forum PSP Software, Firmware & Plugins
    Replies: 5
    Last Post: 10-23-2009, 06:56 PM
  2. Replies: 37
    Last Post: 04-21-2009, 06:48 PM
  3. What is a TIFF exploit ?
    By sawanraykar in forum PSP Homebrew
    Replies: 4
    Last Post: 04-21-2009, 01:40 AM
  4. PSP TIFF Exploit fever(again :D)
    By DarkMaster3442 in forum PSP Discussion
    Replies: 2
    Last Post: 04-14-2009, 01:20 AM
  5. FileAssistant Ported To Tiff Exploit
    By Julie in forum PSP Software, Firmware & Plugins
    Replies: 1
    Last Post: 09-18-2006, 10:48 PM
Posting Permissions
  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •