Acabo de pasarme por la web de Wololo (y no esperaba encontrarme nada) y por sorpresa, he visto que hoy han lanzado el Vitasploit.
La publicación que pusieron es la siguiente
Yesterday, developer Hykem released his own set of tools to leverage the Webkit exploit on the PS Vita . (If you don’t know who Hykem is, just know that he’s been on the scene for quite some time now, and has experience on lots of Sony’s stuff). Download links at the bottom of the article
Vitasploit is an attempt at merging all the ongoing efforts (memtools_vita, JSoS Module Dumper, akai,…) and improving on them. Hykem says some of the code has been cleaned up, and made more generic (“The scripts can be used for both memory reading/writing and ROP code execution by changing a single variable.”).
Additionally, he plans to port the scripts to as many firmwares as possible (3.30+ owners, remember, we’re talking of an exploit that works up to 3.18 here. When you read “as many firmwares as possible”, it means anything at 3.18 or below!), with the ultimate goal of reverse engineering various versions of the modules, to understand what has changed, and maybe find even more vulnerabilities, or understand how the NID poisoning was implemented (that was apparently added in firmware 2.xx)
Parece ser que es un conjunto de herramientas fusionadas y optimizadas (memtools_vita, JSoS Module Dumper, akai,…) que aprovechan el exploit de Webkit de PS Vita. E incluso se puede hacer un dump de los módulos que usa la propia PS Vita.
El autor también planea algunos scripts más para hacer ingeniería inversa a algunos de los módulos.
¿No es interesante? Creo que es un paso muy grande.
Con las prisas soy bastante nefasto traduciendo y en los comentarios empiezan con opiniones interesantes. Así que os dejo el enlace:
http://wololo.net/2014/11/14/vita-native-hack-vitasploit-released-by-hykem/