Psychson icon indicating copy to clipboard operation
Psychson copied to clipboard

I think its time to move on.

Open zuhaib2002 opened this issue 9 years ago • 3 comments

The all-famous 2303 Controller is no longer easily available in the market. Does it mean that this "Flaw" has been fixed in the more common 2307? No one in 2 years have worked on Phison 2307 controllers and i doubt if someone is going to. Conclusion : BADUSB vulnerability has been fixed

zuhaib2002 avatar Sep 07 '16 07:09 zuhaib2002

"BadUSB" is not a vulnerability -- it is the ability to alter the firmware on a USB flash drive, and that most certainly has not changed on the 2307.

What prevents people from easily using this on the 2307 (and even some 2303s) is the patches, which need to be tweaked to work properly on different firmware versions. Rather than simply hard-code patch addresses, the code in this repository tries to be a tiny bit smart and look for code patterns, so that there'd be some hope of it working on other firmware versions, but it does not work well enough on the 2307 or some 2303 versions.

Studying the disassemblies and making the appropriate changes is all that's necessary -- and I've seen links on this very issue tracker (such as https://github.com/brandonlw/Psychson/issues/137 ) of people who have done exactly that, so it is certainly possible.

brandonlw avatar Sep 07 '16 07:09 brandonlw

Thank You for finding time to reply. i never said it is not possible, but no one is committed enough to work further on this and more importantly on other controllers. only if the developers who discovered this 'ability' could find time for this project and somehow tweak through the changes for 'further analysis and research'

zuhaib2002 avatar Sep 08 '16 08:09 zuhaib2002

Also i went thoroughly on the Japanese guy who sorted this out, but he is not actually providing documentation or the proper walk-through of how to do this on 2307

zuhaib2002 avatar Sep 08 '16 08:09 zuhaib2002