PS3 Firmware v3.56 contains Rootkit – Can Enable Remote PS3 Scans

#1 01 Feb 2011 @ 20:27
Quote:
PS3 firmware 3.56 may bring more to the table than meets the eye. According to a post made on the NeoGaf forums, Sony may have the ability to run code to check for ANYTHING on your PS3 without your even knowing. Upon connecting to PSN Sony can scan your PS3 for verifying correct system files to searching for homebrew.

To quote N.A:

For those who are curious about the new PS3 security, it seems Sony has implemented something in 3.56 I mentioned here a few weeks ago that is the same as Microsoft uses to detect and ban 360′s.

Mathieulh just posted about it on IRC.

Essentially Sony can now remotely execute code on the PS3 as soon as you connect. This can do whatever Sony wants it to do such as verifying system files or searching for homebrew. Sony can change the code and add new detection methods without any firmware updates and as the code executes remotely there is no reliable way to forge the replies.

Whilst it is possible to patch or remove this code from the firmware this will likely mean the end of playing CFW online (as PSN can just check before login that this is active) or at the very least mean it will be even easier for Sony to detect and ban users.

Judging from the fact that people can still connect using the proxy method it seems Sony hasn’t activated any of this yet but the functions are there in the new firmware.

IRC Logs:

Jan 27 14:44:32 <Mathieulh> 3.56 has nice new stuffs in there :P
Jan 27 14:44:43 <Mathieulh> like remote code execution upon login
Jan 27 14:44:45 <Sorrowuk> They will just release patches so people who have hacked cant go online
Jan 27 14:44:46 <Mathieulh> yummy :P
Jan 27 14:44:50 <noone> WAT
Jan 27 14:45:00 <noone> RFE built-in the fw!?
Jan 27 14:45:25 <Mathieulh> 3.56 pretty much has a built in psn rootkit
Jan 27 14:45:30 <noone> dude, that’s the only stuff i’d be afraid of
Jan 27 14:45:31 <Mathieulh> don’t tell me I haven’t warned you
Jan 27 14:45:43 <Sorrowuk> psn rootkit ?
Jan 27 14:46:05 <noone> but if we could rip-off the fw that shit would be erased
Jan 27 14:46:20 <noone> that was the only thing stopped sony to _auto_ update your fw
Jan 27 14:46:22 <Mathieulh> noone it’s not that simple
Jan 27 14:46:29 <Mathieulh> the server awaits a proper reply
Jan 27 14:46:34 <Mathieulh> and that reply isn’t in the firmware

What are your thoughts on this new “security”, will you be connecting to PSN online anyways? Let us know VIA comments below.
Source


Also for those of you who don't know, this update is disables to hard drive upgrade function, but this is thought to be a bug like it was in a previous firmware so we'll have to wait and see.
This message has been edited since its posting. Latest edit was made on 01 Feb 2011 @ 20:35


AfterDawn Advertisement
#2 01 Feb 2011 @ 22:28
I just downloaded a few hours ago the OFW update that removes the bug that prevents you from upgrading your HDD. Glad it did not take long to fix since I'm looking to upgrade the old HDD. All these free games I've been getting from PS plus finally caught up to me :)
As far as the root key its interesting stuff and I guess we will have to wait and see if people start getting banned from PSN and not just game servers like Activisions.As of now
#3 06 Feb 2011 @ 7:19
Not good news, Waninkoko is backing off the cfw 3.56.


#4 06 Feb 2011 @ 7:26
Originally posted by goyankees:
Not good news, Waninkoko is backing off the cfw 3.56.
where did you here this?
#5 07 Feb 2011 @ 7:18
It is just a rumor AFAICT, but it makes sense...if he didn't find a hole, he probably won't...and if he did find a hole, he is probably saving it for the long delayed 3.60 update.


#6 07 Feb 2011 @ 13:26
Originally posted by KillerBug:
It is just a rumor AFAICT, but it makes sense...if he didn't find a hole, he probably won't...and if he did find a hole, he is probably saving it for the long delayed 3.60 update.
that makes more sence,why do the cfw for the 3.56 when 3.60 is just around the corner



microsoft after a ban wave
This discussion thread has been automatically closed, as it hasn't received any new posts during the last 180 days. This means that you can't post replies or new questions to this discussion thread.

If you have something to add to this topic, use this page to post your question or comments to a new discussion thread.

Subscribe to AfterDawn's weekly newsletter.