TheFlow has discovered a major exploit called bd-jb for PS3, PS4, and PS5, can be used to load game backups burned to discs

photo_2022-06-10_13-34-33.jpg

One of the PlayStation scene's most notable figures, TheFlow (Andy Nguyen), is back at it again. He's discovered a major exploit that affects not just one PlayStation console, but three. A hackerone report by TheFlow sheds light on five vulnerabilities that range in effectiveness, allowing users to load payloads that can be used to exploit the PlayStation 3, PlayStation 4, and even the PlayStation 5. The exploit is referred to as bd-jb, or the Blu-ray Disc Java Sandbox Escape, and was featured during a panel at this year's hardwear.io security conference.

Below are 5 vulnerabilities chained together that allows an attacker to gain JIT capabilities and execute arbitrary payloads. The provided payload triggers a buffer overflow that causes a kernel panic. Please consider each of the vulnerabilities individually. AFAIK, this is the first exploit chain that is being submitted to you :)

According to Nguyen's report, a UDF driver can cause an overflow on both the PS4 and the PS5. An exploit chain, aka bd-jb, can then be loaded as the payload as a burned Blu-ray disc. The hack, in summary, will allow users to burn physical discs of game backups, and then play them on their consoles. This affects PlayStation 4 consoles below OFW 9.50, and PlayStation 5 systems that are below OFW 5.0.

With these vulnerabilities, it is possible to ship pirated games on bluray discs. That is possible even without a kernel exploit as we have JIT capabilities.



TheFlow's panel that discusses the exploit in detail will be uploaded in "a few weeks". The full hackerone report and all of its technical details can be read about below.

Following the initial report, TheFlow made an update to his claims.



:arrow: Source
 

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,467
Trophies
3
XP
29,204
Country
United States
yeah, the ps5 is about four firmwares higher than 4.50, 5.00, 5.01, 5.02, and 5.10 iirc. and we're up to 9.60 on the ps4.
 

gbadl

Well-Known Member
Member
Joined
Sep 13, 2009
Messages
203
Trophies
1
XP
571
Country


"I wanted to clarify: Without a kernel exploit, you won't be able to run any pirated games (which would have worked on the PS4 only anyways), because we don't have enough RAM in the bd-j process and there are some other constraints. It was only a theoretical impact."
 

diggeloid

Alex
Member
Joined
Apr 29, 2019
Messages
473
Trophies
1
Age
34
Location
gbatemp.net
XP
2,448
Country
United States
This is probably making Sony sweat, but you know what's really stupid? Dedicated security researchers like the flow would probably not be spending so much time and effort trying to exploit these consoles if Sony just opened it up and let people run homebrew straight up.
 
  • Like
Reactions: CTR640

linuxares

The inadequate, autocratic beast!
Global Moderator
Joined
Aug 5, 2007
Messages
13,430
Trophies
2
XP
18,425
Country
Sweden


"I wanted to clarify: Without a kernel exploit, you won't be able to run any pirated games (which would have worked on the PS4 only anyways), because we don't have enough RAM in the bd-j process and there are some other constraints. It was only a theoretical impact."

Everyone that kept a PS5 suddenly got sad
 

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,467
Trophies
3
XP
29,204
Country
United States
This is probably making Sony sweat, but you know what's really stupid? Dedicated security researchers like the flow would probably not be spending so much time and effort trying to exploit these consoles if Sony just opened it up and let people run homebrew straight up.
that's probably what they should do. lots of different apps on the series x. maybe they'll do that with the ps6, then no one will care about exploiting the console, and opening it up to piracy.
 

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,467
Trophies
3
XP
29,204
Country
United States
Not I. I wasn't planning on doing it anyway if it were possible. I won't give up online play and use of the PSN store for pirated discs. I've also been planning to hook my PS5 up for the first time the day the new PS Plus tiers launch in the US.:)
sony sent me a message about that. I think it goes live on the same day as those covers get released, which is a week from today.
 

alt_Human

Well-Known Member
Member
Joined
Jun 9, 2022
Messages
125
Trophies
0
Location
U.S.S. Cygnus
XP
137
Country
United States
you may be right. I just don't recall for sure, just that sony sent me a message. I'm sticking to the base tier for right now, since streaming is impossible with a data cap.

I only have the highest tier becasue I had 2 more years stacked and got in on the PS Now upgdade deal before they closed the loophole. I will have to see where everything stands in two years to see if I'll continue with Premium or not. I still have my modded PS3 so the PS3 streaming isn't a factor to me personally. Sucks you have a data cap. Aren't the PS1 and PS2 games downloadable?
 
  • Like
Reactions: godreborn

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • BigOnYa @ BigOnYa:
    Me and a buddy used to play that, is pretty fun. Graphics were pretty good also at that time, I think what 5-6 years ago. --Edit yea was 2018
  • BigOnYa @ BigOnYa:
    Surprised they never made a second one.
  • K3Nv2 @ K3Nv2:
    It takes two was their newest different theme
  • BigOnYa @ BigOnYa:
    I didn't care for that one so much, but didn't play it much either.
  • BigOnYa @ BigOnYa:
    I just played little of "Still Wakes The Deep" , just came to gamepass today, its alright, kinda creepy. I'm not usually a horror game fan, but it looks really good graphic wise, esp w 4k. I admit it made me jump a few times.
  • LNLenost @ LNLenost:
    Anyone here using the 3DS?
  • LNLenost @ LNLenost:
    do u have pretendo?
  • LNLenost @ LNLenost:
    whats ur code?
  • B @ btjunior:
    i dont have pretendo sorry
  • LNLenost @ LNLenost:
    oh ok
  • LNLenost @ LNLenost:
    well if ur console isnt modded i suggest u to mod it
  • B @ btjunior:
    also, just curius, does the freinds app still work after the shutdown?
  • LNLenost @ LNLenost:
    yes
  • B @ btjunior:
    nice
  • LNLenost @ LNLenost:
    but u cant play online games anymore :(
  • LNLenost @ LNLenost:
    i miss going in other peoples town
  • B @ btjunior:
    yeah
  • LNLenost @ LNLenost:
    i have a friend named Pineapple (@pineappleJuice hi). we played a lot the day b4 the server shutdown
  • K3Nv2 @ K3Nv2:
    I preten to know doe
  • BigOnYa @ BigOnYa:
    @LNLenost how well is the pretendo servers, you ever get kicked off games when playing online?
    +1
  • LNLenost @ LNLenost:
    @BigOnYa not always you get kicked. it happens rarely to me.
    +1
  • LNLenost @ LNLenost:
    ofc they're not great, but props to them for making this
    +1
  • LNLenost @ LNLenost:
    btw, I decided to make the nintendo support team going insane
  • LNLenost @ LNLenost:
    i told them my badges disappeared after i opened the badge arcade after the shutdown, but actually they disappeared because i opened the badge arcade w/ pretendo
    LNLenost @ LNLenost: i told them my badges disappeared after i opened the badge arcade after the shutdown, but...