Hacking thefl0w tweated/hinted 6.20 kexploit maybe coming soon.

peteruk

Well-Known Member
Member
Joined
Jun 26, 2015
Messages
3,005
Trophies
2
XP
7,369
Country
United Kingdom
I know there are about 5 people working independently to achieve the same goal, for various reasons.

It’s just a matter of time before something gives.

But that length of time is indeterminate.

I have a feeling it would speed up if there was a bounty.


In your opinion will these 5 people be working on 6.20 or will those of us on the latest (7 whatever) be looked after too
 
  • Like
Reactions: kop365

KiiWii

Editorial Team
Editorial Team
Joined
Nov 17, 2008
Messages
16,735
Trophies
3
Website
defaultdnb.github.io
XP
27,372
Country
United Kingdom
In your opinion will these 5 people be working on 6.20 or will those of us on the latest (7 whatever) be looked after too

It ranges: 5.50/6.20/7.00 seem to be the main versions.

Some are also working on firmware agnostic vectors to bring new solutions.

I would bet on 5.5x before anything else, 6.2x if we are lucky, 7.xx when several higher versions exist to prevent online haxxing.
 

MostlyUnharmful

Well-Known Member
Member
Joined
Feb 8, 2018
Messages
410
Trophies
0
Age
42
XP
1,446
Country
Italy
Some are also working on firmware agnostic vectors to bring new solutions.

If I was really really bored, I would test RowHammer for PS4's GDDR5. ^__^;

Unfortunately, I think I've read somewhere that Javascript doesn't offer precise timers anymore — to avoid fingerprinting for privacy reasons — so WebKit exploit would still be necessary...
 
  • Like
Reactions: KiiWii

KiiWii

Editorial Team
Editorial Team
Joined
Nov 17, 2008
Messages
16,735
Trophies
3
Website
defaultdnb.github.io
XP
27,372
Country
United Kingdom
If I was really really bored, I would test RowHammer for PS4's GDDR5. ^__^;

Unfortunately, I think I've read somewhere that Javascript doesn't offer precise timers anymore — to avoid fingerprinting for privacy reasons — so WebKit exploit would still be necessary...
Interesting, I’ve just been reading up on this, we must be able to write our own timers for better granularity? Idk.

https://gbatemp.net/threads/would-it-be-possible-to-rowhammer-a-ps4.383646/

No one ever answered.

There was also nethammer, and throwhammer, but not sure how useful they could be either. If they rely on JIT it would be a pretty solid: nope.
 
  • Like
Reactions: peteruk

MostlyUnharmful

Well-Known Member
Member
Joined
Feb 8, 2018
Messages
410
Trophies
0
Age
42
XP
1,446
Country
Italy
There was also nethammer, and throwhammer, but not sure how useful they could be either. If they rely on JIT it would be a pretty solid: nope.

Get it to work straight from the browser would be asking too much in my opinion, but I wouldn't mind to use it to escalate privileges...
 
  • Like
Reactions: KiiWii

KiiWii

Editorial Team
Editorial Team
Joined
Nov 17, 2008
Messages
16,735
Trophies
3
Website
defaultdnb.github.io
XP
27,372
Country
United Kingdom
Get it to work straight from the browser would be asking too much in my opinion, but I wouldn't mind to use it to escalate privileges...
That’s all we have publicly right now :(

Potentially we also have older Webmaf apps, and I have heard of a zero day USB based attack, which also hasn’t been patched yet.
 

jammybudga777

Well-Known Member
Member
Joined
Aug 23, 2013
Messages
2,284
Trophies
1
Age
37
XP
2,193
Country
I know there are about 5 people working independently to achieve the same goal, for various reasons.

It’s just a matter of time before something gives.

But that length of time is indeterminate.

I have a feeling it would speed up if there was a bounty.
i personally think the flow is waiting for his paypal too get some attention then we might see a release
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    K3Nv2 @ K3Nv2: https://www.kohls.com/product/prd-6512692/arcade-1-up-infinity-50-games-game-board.jsp?pfm=bdrecs...