Original PlayStation 2 security chip SPC970 has been reverse engineered
Developer DiscoStarslayer has dumped the firmware of the SPC970 MechaCon chip in the fat PlayStation 2, the console's last unmapped component. An EEPROM buffer overflow exploit extracted the 256KB image; the dumps and 22 firmware images are now on GitHub.
- Exploit uses a zero block count to underflow the counter and overflow EEPROM writes into RAM
- Full 256KB dump takes about 1,000 passes, each wearing down the EEPROM
- 22 firmware images cover fat PS2s from the 2000 SCPH-15000 to 2002 39000-series
- Dumps also cover Namco System 246 and 256 arcade boards using the same chip
Read next
Gadgets