DaNtE_PSL Wrote:Hi Guys, i'm Dante From PSL, sorry for my bad english i'm italian; i'm here for talk about this exploit, andrea1234567890 is a member of us forum, he is a serious guy, and we are investigating about this exploit, but i want to make known some thing, frist of all the composition of this exploit, is an HYBRID of two thing: tiff ChickHen and one of mallixos.The expoit are now in alpha phase and is very unstable, andrea can't repply now because he's ill he have fever thks for the attenction
Hey Dante, sorry, I don't speak Italian, so I'll go with english:
1)Malloxis is a tool. His "exploit" is Jeerum's bmp file renamed as a tiff. The guy has no clue what he's doing. The fact that he was the origin of the laughing man tiff through luck doesn't mean he's a hacker. He's trying to do it again, but renaming a bmp as a tiff only shows a huge lack of knowledge.
2)The BMP creates a buffer overflow that is not exploitable. I've discussed it there:
http://wololo.net/wagic/2009/10/18/why- ... mp-images/ . And most other devs I know agreed with my conclusion. I'd be happy if someone can prove me wrong though.
3)Combining 2 exploits doesn't make an exploit. You clearly have NO idea what you're talking about, and whoever andrea1234567890 is, he's playing with you.
4) Please note that Jeerum's BMP has been out for almost 6 months now. Most devs of the scene now about it. If it was exploitable, it would probably have been done by now...
en Français:
1)Malloxis est un abruti. Son"exploit" n'est rien de plus que le fichier BMP de Jeerum renommé en tiff. Il ne comprend rien à rien. Ce n'est pas parce qu'il était à l'origine du laughing man (qu'il a créé par chance) que ça fait de lui un hacker. Il essaie de reproduire son exploit, mais renommer un bmp en tiff prouve simplement qu'il ne comprend rien à ce qu'il fait.
2)Le BMP de Jeerum génère effectivement un buffer overflow, mais il n'est pas exploitable. J'explique ici pourquoi:
http://wololo.net/wagic/2009/10/18/why- ... mp-images/ . La plupart des devs que je connais sont arrivés à la même conclusion que moi, mais je serai évidemment ravi qu'on me prouve le contraire.
3) La combinaison de 2 hacks ne fait pas un hack. Pour dire ça, il faut vraiment ne RIEN comprendre à ce qu'on fait, je ne sais pas qui est andrea1234567890, mais il se fout de ta gueule.
4)Le BMP de Jeerum est dispo sur le net depuis plusieurs mois. Si il permettait de hacker la console, je pense que ça aurait été fait depuis longtemps.