Symbian OS | Pocket PC | Smartphone | Android | BlackBerry | Apple iPhone OS | Java | Mobile Gaming | Linux | Palm | Win CE | Tablet  
     

Free Mobile Software, Themes, Games, Apps for PDA and Smartphones

     
Search by Device
My Device

  
Last Viewed Apps
Analog Clock Screen Lock
Child Memory
AnyTitle Deleter DB
Sensible soccer skills
Chicken invaders 4
Animated Barca
Midnight pool 2
DuckDuckGo (SSL) - Firefox Addon
Kobe Bryant
Smok With Tone
Search by Category
Business & Profession
Databases
Dictionary & Translator
Entertainment
Finance
Games
Healthcare & Medicine
Internet & Communications
Multimedia & Graphics
Organisation & Productivity
Programming & Development
Reading
Science & Education
System Utilities
Antivirus
Archivers & Compression
Backup & Memory
Barcode Scanner
Battery
Data Storage & Encryption
Display & Flashlight
Emulators & Shells
File management
Hacks & Tweaks
Installer
Interface
Keyboard Extensions & Lock
Localization
Password Managers
Profiles
Registry
Remote connection & Consoles
Screensavers
Screenshots
Search
Security
Synchronization
System management
Task Managers & Launchers
Tests & Benchmarks
Text Editors
More
Themes & Wallpapers & Skins
Travel & Navigation
Search by Platform
Android
Apple iPhone OS
iPad
iPhone
iPod Touch
BlackBerry
Java
Linux
Maemo Nokia Internet Tablet
MeeGO
Sharp Zaurus
Mobile Gaming
Nintendo DS
Playstation 3
Playstation Portable
Wii
Xbox 360
Palm OS
Symbian OS
Series 60
Series 80
Series 90
UIQ
Tablet PC
Windows CE.NET
Windows Mobile Pocket PC
Windows Mobile Smartphone
     


Achivx Partner
 
 
GripShift savegame exploit POC




GripShift savegame exploit POC
Version: 2

Platforms: PSP, Mobile Gaming


Categories: System Utilities

Upload date: 20 Oct 11

Developer:

License: Freeware

Downloads: 12

File Size: 491 Kb
Download Free GripShift savegame exploit POC 



Rating: 1.0/5 (Total votes: 1)




  GripShift savegame exploit POC

Aah, yes, new exploit, old game. It's so cool to actually see this beauty working - and on a PSP-3000 no less! The PSP scene was buzzing the other day when MaTiAz found an exploit (read: buffer overflow!) in the three year old game, GripShift.

MaTiAz says that they've yet to find any further use for this, but it's still a new exploit. It could lead to further hacks, and for now, it's merely a proof of concept. Be that as it may, this is a great start, and a rather sweet find! Here's MaTiAz explaining the exploit:

GripShift has a buffer overflow vulnerability when loading savegames. The savegame contains the profile name which can be easily used to overwrite $ra. The savegame file is pretty big (25kB) so you have lots of space to put your code there. I wrote a simple blob of code to paint the framebuffer completely white (to just indicate that arbitrary code is running ). The return address is located at offset 0xA9 in the file. In this poc it points to 0x08E4CD50 (which is only a few bytes after the return address), and the code starts at 0xCC in the file.


It was tested on 4.01M33-2 with US version of GripShift (ULUS10040), and psplink.prx, usbhostfs.prx and deemerh.prx loaded (also without psplink and usbhostfs). The decrypted savegame (sorry, couldn't [be bothered to] get Shine's savegame tool working so it's in plaintext form) is in the SDDATA.BIN form which Hellcat's Savegame-Deemer produces (thanks to him, if the program didn't exist I wouldn't have bothered with this. ). Just copy the ULUS10040SAVE00 directory to /PSP/SAVEPLAIN/ and run the game. EDIT: yeah, don't forget to have Savegame-Deemer working, duh.
 
Like it? Share with your friends!

If you got an error while installing Themes, Software or Games, please, read FAQ.
 
Similar Software:

Devhook 0.44Devhook 0.44
Devhook 0.44 The PSP 'scene' is having some of its best times lately, what with the recent deluge of downgraders, and one of the most awesome homebrew, Devhook. And guess what? Booster has just raised the bar with his latest incarnation of Devhook. Apparently, the latest release supports 2.71 reboot. Or in other words, 2.71 Emulation
PSP Pandora DeluxePSP Pandora Deluxe
PSP Pandora Deluxe Changelog: v2.3 (2008-10-11) - Fixed problem with 1.50 Kernel Addon selection. - Added the following Support Tools: Hellcat's Recovery Flasher 1.32 (Pandora) AutoStartPRX 5 (XMB) CPU-Modulator 0.20 (XMB) CW Cheat 0.2
PSP Slim and Lite USB plug-inPSP Slim and Lite USB plug-in
PSP Slim and Lite USB plug-in Noobz! has released the PSP Slim USB charger which, as the name implies, allows users to charge their PSP Slim and Lite via a USB cable. This new hombrew works for the 3.60 and 3.71 M33 CFW, and should allow you to charge your unit with either a normal USB charger or by just plugging the unit into the computer and switching it on
Custom Firmware EnablerCustom Firmware Enabler
Custom Firmware Enabler Changelog: - Fixed a bug with the game for the network infrastructure (if you fail to function properly it is necessary to return to change the version.txt in this version, simply reescribelo in the menu) - Improved system for updating network. - Improved system distorts the direction of Mac - Improved system plugins (yes, again ..
PBPSpoofPBPSpoof
Having trouble running some of your homebrews due to compatibility issues on your Sony PSP's firmware version? You may want to take a look at this new application released by developer PEB , dubbed PBPSpoof v1
PSP Hardware Alarm Interface IPSP Hardware Alarm Interface I
PSP Hardware Alarm Interface I Developer Mr305 visited the QJ.NET Forums earlier to announce the release of PSP Hardware Alarm Interface I v1.3.359. This homebrew application is basically an alarm that will activate even if the PSP's in sleep or Powered Off (standby) mode
FX_ThreadMan 0.5FX_ThreadMan 0.5
FX_ThreadMan 0.5  from NoEffex: Well, the abbreviation pretty much covers it. In doing digging into various things I wrote this up and found it quite useful in tracking down various things. readme says: Stick it into seplugins, and game.txt. If you dunno how, you shouldn't be using this
PSN PKG Decryptor & Extractor Bumped to 1.74a: Better EBOOT and PKG GenerationPSN PKG Decryptor & Extractor Bumped to 1.74a: Better EBOOT and PKG Generation
PSN PKG Decryptor & Extractor Bumped to 1.74a: Better EBOOT and PKG Generation - Have any Sony PSN files that need decrypting? Leecherman's latest download allows for better PSOne, UMD, and game update DRM stripping
PrxEncrypterPrxEncrypter
PrxEncrypter After KGSWS put online the first signed homebrew, developer bbtgp has released a new tool that allows users to sign/encrypt simple homebrews, without going through the HBL or HEN. Developer's note: "based off the first homebrew ever signed and various code snippets on this thread. Its signs a simple hello world just fine.
Pandora Installer for 3.xx Kernels Second RevisionPandora Installer for 3.xx Kernels Second Revision
Pandora Installer for 3.xx Kernels Second Revision Homebrew developer Hellcat has come out with the second version of the Pandora Installer for 3.xx kernels. This application allows users to run a base Pandora setup for any kernel 3.71 and below. This application also works on both the PSP Slim and Lite and the original PSP
 

Comments on GripShift savegame exploit POC:

Comments not found

Name:


Comment:


Enter text from image below:

Turn on images!

 
 

If you noted an error or download link is broken, please, report it via this page or use comments.
 

Please, select device to check if GripShift savegame exploit POC supports it
 
 
© Pantich 2009 - 2025 All rights reserved.