PS4 Kernel Exploit Leaked

The Holy Grail of PS4 hacking, discovered by CTurt some time ago but never released, has been leaked today. Known as the BADIRET exploit, it gives full access to the PS4 hardware. It was designed to work for firmware version 1.76 originally, but sources say it -may- work up to 2.01 with a different entrypoint.

(If I have my facts straight, the common webkit exploit was patched after 1.76, but the BADIRET exploit was not patched until after 2.01)

Currently, not much can be done with this, although Team fail0verflow does have an interesting Linux loader that is open source and seems to be fairly functional at this time, the only thing they don't supply is the hack (BADIRET) to load it with.

On a side note, be prepared to drop some MAJOR cash on one of these old firmware PS4's. Maybe you will have some luck here:

https://gbatemp.net/categories/trading-area.157/

gKlf796.png


Kodi.tv running on my PS4? Yes ma'am!

:arrow: Source

(Editor's Note: I have a 1.71 PS4 that I will update and personally test this on once I get back from my mini-vacation!)
 

stanleyopar2000

RIP Yuzu. "It is always morally correct..."
Member
Joined
Jun 22, 2007
Messages
4,804
Trophies
2
Location
C-137
Website
www.youtube.com
XP
3,662
Country
United States
This is amazing... Too bad I've spent too much money in the PSN to risk a ban =/

My modded Wii + rooted FireKodi TV can do everything I want anyway

This does pique my interest to what emulators will come for it eventually
 
Last edited by stanleyopar2000,

Foxi4

Endless Trash
Global Moderator
Joined
Sep 13, 2009
Messages
30,825
Trophies
3
Location
Gaming Grotto
XP
29,841
Country
Poland
I like how people underestimate the "slow-ass netbook-grade APU" (it's not by the way, there isn't a single octacore Jaguar APU out there, off-the-shelf models are up to quadcore) of the PS4 when it already runs PS2 games via the built-in PS2 Classics overlay, just like the PS3 did (in software mode, mind you - not all PS3's had PS2 hardware on-board - most didn't). It absolutely does have enough horsepower for the job, and I need zero evidence to prove that since it already literally does that. I'd also love someone to point out one, just one netbook that runs on unified GDDR5 memory via HSA - hint, they don't exist. I'm so sick and tired of people treating current gens as low-end PC's - they're custom hardware based on off-the-shelf components, just like every other console in history. If the PS4 is a netbook then the Wii U is an old PPC-based Mac, it might as well be.
 

Vappy

Well-Known Member
Member
Joined
May 23, 2012
Messages
1,508
Trophies
2
XP
2,613
Country
Kind of fails to mention that both CTurt and kr105 have said that the leaked code isn't actually in a functioning state. Going to need some more work done before it's usable.
 
  • Like
Reactions: cearp

lefthandsword

Well-Known Member
Member
Joined
Apr 6, 2015
Messages
352
Trophies
0
Age
26
Location
root
XP
478
Country
Hong Kong
Kind of fails to mention that both CTurt and kr105 have said that the leaked code isn't actually in a functioning state. Going to need some more work done before it's usable.
But they already documented the exploits well enough for someone to implement it (no code were released either when memchunkhax2/A9LH were revealed but the community implemented them by themselves) before their private payloads were leaked, but no one bothered because it only works on very old FW.

But considering how easy you could clone PSN licenses to multiple consoles, a hardmod NOR downgrade method could be a possibility.
 
Last edited by lefthandsword,

Relys

^(Software | Hardware) Exploit? Development.$
Member
Joined
Jan 5, 2007
Messages
878
Trophies
1
XP
1,239
Country
United States
I will be trying this out when I get home. Expect videos and modding tools soon. :)

I want to focus on SteamOS support with the intention of bringing the PlayStation VR to an open platform. :)

It looks like this is the raw exploit. It's missing IDT restoration and return back to userland for use with the Linux bootloader.

Need a lot of post exploitation stuff like breaking out of chroot jail (on Cturt's blog), allowing kernel peek/poke, etc.

All of this shouldn't be too hard though now that we have kernel code exec! :)
 
Last edited by Relys,

Xenon Hacks

Well-Known Member
Member
Joined
Nov 13, 2014
Messages
7,414
Trophies
1
Age
30
XP
4,687
Country
United States
I will be trying this out when I get home. Expect videos and modding tools soon. :)

I want to focus on SteamOS support with the intention of bringing the PlayStation VR to an open platform. :)

It looks like this is the raw exploit. It's missing IDT restoration and return back to userland for use with the Linux bootloader.

Need a lot of post exploitation stuff like breaking out of chroot jail (on Cturt's blog), allowing kernel peek/poke, etc.

All of this shouldn't be too hard though now that we have kernel code exec! :)
Will firmwares pre 1.76 be viable for this?
 

Giga_Gaia

Well-Known Member
Member
Joined
Sep 12, 2006
Messages
1,429
Trophies
1
Age
38
XP
1,222
Country
Canada
Wake me up when there is a CFW you can install over 3.00+ firmwares that lets you pirate games.

^This. This is kinda useless unless it works on latest firmware. At least the PS3 was hacked on the latest firmware at the time. They still haven't cracked 3.56 or above, but at least when it happened, 3.55 was the latest and everyone was on it.

This is useless because this firmware is so old only someone with no Internet would be on it. So wake me up when someone find something important, which means something on latest firmware.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    HiradeGirl @ HiradeGirl: Have a nice day. Life. Week. Month. year.