Edit: this is a quote posted by Dark-Jack on his site but we can't link to it as they illegally host copyrighted material.
Quote: “Hi
First of all, I am from Japan, so please excuse my enlish :-|
Im TyraMis. If you are new to the PSP scene, you probably don’t know me so I will explain I was big in the old days of the PSP scene when cracking the pre-IPL of the 1000/2000 mobos was first discovered
First of all I’d like to congratulate you on your homebrew launcher that you are making for use with the medal of honors exploit.
However, I ask that you’d please not release the MOHH HEN, for 2 reasons.
1 – Sony will patch the kernel bug before GO! is released
2 – I have a better exploit anyways, so I would like to keep your kernel mdoe bug available so I can make this happen (I will explain in a moment) again on the GO, like I did with a 88 version 3.
Ok, so what did I do? I found a way, using a user and kernel vulnerability combined, to bypass the VERY first signature check at the beginning of boot and run a little code, to find out where the pre-IPL is stored
Then I coded a little app using the MOHH exploit to take advantage of the kernel and EEPROM exploit I made to dump the pre-IPL, knowing now that it is mapped at 0
Quote: “Hi
First of all, I am from Japan, so please excuse my enlish :-|
Im TyraMis. If you are new to the PSP scene, you probably don’t know me so I will explain I was big in the old days of the PSP scene when cracking the pre-IPL of the 1000/2000 mobos was first discovered
First of all I’d like to congratulate you on your homebrew launcher that you are making for use with the medal of honors exploit.
However, I ask that you’d please not release the MOHH HEN, for 2 reasons.
1 – Sony will patch the kernel bug before GO! is released
2 – I have a better exploit anyways, so I would like to keep your kernel mdoe bug available so I can make this happen (I will explain in a moment) again on the GO, like I did with a 88 version 3.
Ok, so what did I do? I found a way, using a user and kernel vulnerability combined, to bypass the VERY first signature check at the beginning of boot and run a little code, to find out where the pre-IPL is stored
Then I coded a little app using the MOHH exploit to take advantage of the kernel and EEPROM exploit I made to dump the pre-IPL, knowing now that it is mapped at 0