<?xml version="1.0" encoding="iso-8859-1"?>
<rss version="2.0">
<channel>
  <title>Linux Format forums</title>
  <link>http://www.linuxformat.com/forums/index.php</link>
  <description>Help, discussion, magazine feedback and more</description>
  <language>english</language>
  <copyright>(c) Copyright Tue May 21, 2013 9:20 pm by Linux Format forums</copyright>
  <managingEditor>webmaster@linuxformat.com</managingEditor>
  <webMaster>webmaster@linuxformat.com</webMaster>
  <pubDate>Tue May 21, 2013 9:20 pm</pubDate>
  <lastBuildDate>Tue May 21, 2013 9:20 pm</lastBuildDate>
  <docs>http://backend.userland.com/rss</docs>
  <generator>phpBB2 RSS Syndication Mod by Lucas</generator>
  <ttl>1</ttl>

  <image>
    <title>Linux Format forums</title>
    <url></url>
    <link>http://www.linuxformat.com/forums/</link>
    <description>Help, discussion, magazine feedback and more</description>
  </image>

                                      <item>
                                        <title>Re: PS3 has been hacked...</title>
                                        <link>http://www.linuxformat.com/forums/viewtopic.php?p=84880#84880</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://www.linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=65966'&gt;pctechie&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Thu Feb 04, 2010 11:35 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Here's how it works for technical minded people&lt;br /&gt;
&lt;/span&gt;&lt;table width=&quot;90%&quot; cellspacing=&quot;1&quot; cellpadding=&quot;3&quot; border=&quot;0&quot; align=&quot;center&quot;&gt;&lt;tr&gt; 	  &lt;td&gt;&lt;span class=&quot;genmed&quot;&gt;&lt;b&gt;Code:&lt;/b&gt;&lt;/span&gt;&lt;/td&gt;	&lt;/tr&gt;	&lt;tr&gt;	  &lt;td class=&quot;code&quot;&gt;geohot&amp;#58; well actually it's pretty simple&lt;br /&gt;
geohot&amp;#58; i allocate a piece of memory&lt;br /&gt;
geohot&amp;#58; using map_htab and write_htab, you can figure out the real address of the memory&lt;br /&gt;
geohot&amp;#58; which is a big win, and something the hv shouldn't allow&lt;br /&gt;
geohot&amp;#58; i fill the htab with tons of entries pointing to that piece of memory&lt;br /&gt;
geohot&amp;#58; and since i allocated it, i can map it read/write&lt;br /&gt;
geohot&amp;#58; then, i deallocate the memory&lt;br /&gt;
geohot&amp;#58; all those entries are set to invalid&lt;br /&gt;
geohot&amp;#58; well while it's setting entries invalid, i glitch the memory control bus&lt;br /&gt;
geohot&amp;#58; the cache writeback misses the memory &amp;#58;&amp;#41;&lt;br /&gt;
geohot&amp;#58; and i have entries allowing r/w to a piece of memory the hypervisor thinks is deallocated&lt;br /&gt;
geohot&amp;#58; then i create a virtual segment with the htab overlapping that piece of memory i have&lt;br /&gt;
geohot&amp;#58; write an entry into the virtual segment htab allowing r/w to the main segment htab&lt;br /&gt;
geohot&amp;#58; switch to virtual segment&lt;br /&gt;
geohot&amp;#58; write to main segment htab a r/w mapping of itself&lt;br /&gt;
geohot&amp;#58; switch back&lt;br /&gt;
geohot&amp;#58; PWNED&lt;br /&gt;
geohot&amp;#58; and would work if memory were encrypted or had ECC&lt;br /&gt;
geohot&amp;#58; the way i actually glitch the memory bus is really funny&lt;br /&gt;
geohot&amp;#58; i have a button on my FPGA board&lt;br /&gt;
geohot&amp;#58; that pulses low for 40ns&lt;br /&gt;
geohot&amp;#58; i set up the htab with the tons of entries&lt;br /&gt;
geohot&amp;#58; and spam press the button&lt;br /&gt;
geohot&amp;#58; right after i send the deallocate call&lt;br /&gt;
&lt;/td&gt;	&lt;/tr&gt;&lt;/table&gt;&lt;span class=&quot;postbody&quot;&gt;&lt;br /&gt;
&lt;br /&gt;
Read this &lt;a href=&quot;http://www.eurogamer.net/articles/digitalfoundry-ps3hacked-article&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot; class=&quot;postlink&quot;&gt;article&lt;/a&gt; if you are less technical minded.</description>
                                        <comments>http://www.linuxformat.com/forums/viewtopic.php?p=84880#84880</comments>
                                        <author>pctechie</author>
                                        <pubDate>Thu Feb 04, 2010 11:35 pm</pubDate>
                                        <guid isPermaLink="true">http://www.linuxformat.com/forums/viewtopic.php?p=84880#84880</guid>
                                      </item>
                                      <item>
                                        <title>PS3 has been hacked...</title>
                                        <link>http://www.linuxformat.com/forums/viewtopic.php?p=84359#84359</link>
                                        <description>&lt;br /&gt;
                                      Author: &lt;a href='http://www.linuxformat.com/forums/profile.php?mode=viewprofile&amp;u=58561'&gt;Bazza&lt;/a&gt;&lt;br /&gt;&lt;br /&gt;
                                      Posted: Tue Jan 26, 2010 6:45 pm&lt;br /&gt;&lt;br /&gt;
                                      &lt;br /&gt;&lt;br /&gt;
                                      Hi all...&lt;br /&gt;
&lt;br /&gt;
Interesting stuff...&lt;br /&gt;
&lt;br /&gt;
&lt;a href=&quot;http://geohotps3.blogspot.com/&quot; rel=&quot;nofollow&quot; target=&quot;_blank&quot;&gt;http://geohotps3.blogspot.com/&lt;/a&gt;</description>
                                        <comments>http://www.linuxformat.com/forums/viewtopic.php?p=84359#84359</comments>
                                        <author>Bazza</author>
                                        <pubDate>Tue Jan 26, 2010 6:45 pm</pubDate>
                                        <guid isPermaLink="true">http://www.linuxformat.com/forums/viewtopic.php?p=84359#84359</guid>
                                      </item></channel></rss>