GSM Shop GSM Shop
GSM-Forum  

Welcome to the GSM-Forum forums.

You are currently viewing our boards as a guest which gives you limited access to view most discussions and access our other features.
Only registered members may post questions, contact other members or search our database of over 8 million posts.

Registration is fast, simple and absolutely free so please - Click to REGISTER!

If you have any problems with the registration process or your account login, please contact contact us .

Go Back   GSM-Forum > Non GSM/Mobile Related Forums > Game Consoles & Mp3/4 , HD players


Game Consoles & Mp3/4 , HD players Repairing and servicing Mp4, Mp3 devices, HD players.. you may also find here any threads related to Game Consoles devices like Wii, PlayStation, Xbox, Nintendo .. etc

Reply
 
LinkBack Thread Tools Display Modes
Old 11-18-2008, 22:51   #1 (permalink)
No Life Poster
 
RNC_EBM's Avatar
 
Join Date: Dec 2004
Location: PHILIPPINES
Posts: 5,294
Member: 101860
Status: Offline
Sonork: 100.1582168 100.77603
Thanks Meter: 6,036
Donate money to this user
>>> PSP: Dark_Alex - Why TA88v3 cannot be hacked "yet" <<<


Why TA88v3 cannot be hacked "yet"

Quote:
Originally Posted by Dark_AleX
This is an explanation of the security that was added in TA88v3, and which will be likely in PSP3000.

When the PSP boots, the boot code (aka pre-ipl or ipl loader) loads the ipl from either the nand or memory stick. The IPL is splitted into pieces of 0x1000 bytes.

First 0xA0 bytes of each block is a header for the kirk hardware command 1. It contains keys,
the size of the cipher data, and two hashes, one for part the header itself, and another one for the body. The 0xF60 remaining bytes are the ciphered body, which will decrypt to 0xF60 plain bytes... if the hashes, which are checked by kirk hardware itself, are OK. (Note: ciphered body can actually be less than 0xF60, in this case, remaining bytes are ignored... before TA88v3) Fir

The security of kirk hashes was destroyed by a timing attack, and the IPL became unprotected.
What has Sony added to fix this?

The answer can be found in 4.00+ slim ipl's. They decreased the size of the ciphered body to 0xF40 to leave 0x20 bytes at the end of each block (at offset 0xFE0).
As stated before, these remaining bytes are ignored... in pre-ipl's of psp's prior to TA88v3, and in fact, they can be randomized and ipl will still boot in those psp's. In newest pre-ipl's, these 0x20 bytes have a meaning.

The first 0x10 bytes is an unknown hash calculated from the decrypted block. It is deduced that is calculated from the decrypted block and not the ciphered one due to the fact that 4.01 and 4.05 have a lot of ipl blocks in common, which, when decrypted, are similar, but they are totally different in its encrypted form. In these two ipl's, this hash is same, as seen in the picture:


The second 0x10 bytes seem also to be dependent of the decrypted body (maybe dependent of the previous 0x10 bytes too?). In the picture it can be seen that they are different in 4.01 and 4.05, but they can actually be interchanged, you can move those 0x10 bytes from the same block in 4.05 ipl to the 4.01 ipl and it will still boot; however it cannot be randomized.

This protection also destroys any possibility of downgrading below 4.00, as these new cpu's won't be able to boot previous firmwares ipl's.

Summary: basically, all security of newest psp cpu's rely on the secrecy of the calculation of those 0x20 bytes. If pre-ipl were dumped somehow, the security would go down TOTALLY.

Graphic summary:

br

RNC_EBM
  Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
>>> PSP: Dark_Alex - PSX problems in 5.00 M33 <<< RNC_EBM Game Consoles & Mp3/4 , HD players 2 03-29-2010 17:33
>>> PSP: TORCH - Hold+ - Battery Saver Plugin UPDATE HERE <<< RNC_EBM Game Consoles & Mp3/4 , HD players 5 01-19-2009 22:41
>>> PSP: L/R BLight & UMD Door MOD <<< RNC_EBM Game Consoles & Mp3/4 , HD players 1 08-05-2008 12:14
>>> PSP: Lockdown v3.0 - Flash0 Based Password Protection <<< RNC_EBM Game Consoles & Mp3/4 , HD players 0 07-27-2008 13:32


All times are GMT +1. The time now is 01:42.



Powered by Searchlight © 2024 Axivo Inc.
vBulletin Optimisation provided by vB Optimise (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
- GSM Hosting Ltd. - 1999-2023 -
Page generated in 0.13890 seconds with 10 queries

SEO by vBSEO