Tutorial  Updated

PS5 Exploit Guide

PS5 HACK STATUS:

Recommended FW: 4.51 for etaHEN or HV exploit.
Highest Hypervisor exploit: 1.00-4.51 (FlatZ confirmed)
Highest Public Hypervisor exploit: 1.xx-2.50/2.70 (byepervisor by Specter dev)
Highest public kernel exploit: 5.50 UMTX
Highest private kernel exploit:
*7.61 UMTX*
KEX offsets found: 1.00-5.50
Highest webkit entry point: 5.XX
Mast1C0re entrypoint: 7.61 (for PS2 backups)
Highest BD-JB entrypoint: 7.61
Highest Lua entrypoint: 7.61
Homebrew Enabler: etaHEN (3.XX-4.5X) latest
HERE
PS5 backup loading: Itemzflow for 3.XX-4.5X HERE
PS4 backup loading: FPKG Enabler 2.XX-4.5X (rest mode & backports work, can crash).
PS5debug released:
HERE
PS5 trainers/cheats: Work
PS5 dumper: 3.XX-4.5X works with most games, use Itemzflow
(Dumps need rebuilding/cracking to avoid crashing)

UART:
HERE
Full chain exploit: 1.00-2.70 (byepervisor)
PSN access: NEVER
Latest OFW: 10.20 (23/10/24)
Latest beta OFW: 10.00 b2 (25/07/24)
OFW Updates:
HERE
Legit PKG Updates: HERE

https://github.com/PS5Dev/PS5-UMTX-Jailbreak/releases/tag/v1.2

UMTX 1.2 exploit works on 1.00-5.xx with WebKit:
https://zecoxao.github.io/umtx/ or https://es7in1.site/ (payloads not working on 5.xx yet)

UMTX 6.xx-7.61 will require a new webkit exploit for digital consoles

PS5 Itemzflow compatibility list:

Recommended hosts:
AL-AZIF WEB HOST:
DNS 1: 165.227.83.145
DNS 2: 192.241.221.79

https://cthugha.thegate.network/
https://ithaqua.thegate.network/

NOMADIC20000 HOST:
DNS 1: 62.210.38.117

(Leave DNS 2 blank)
http://es7in1.site/
https://zecoxao.github.io/ps5jb/

https://ps5jb.pages.dev/
https://sleirsgoevy.github.io/ps4jb2/ps5-403/index.html

PS5 game updates: https://psxpatches.com/

Summarised OFW/Model guide: HERE

1.XX-7.61 game compatibility list: HERE

Update OFW manually via USB by getting the firmware file from HERE and installing from <USB>:/PS5/UPDATE/PS5UPDATE.PUP

SYSTEM UPDATES:
7.61 SYS MD5: d5eca8b171a8d7df7ba225167f77e645 (ready for exploit)
6.50 SYS MD5: 98db854ba47a75dff0cb09355bca9025 (ready for exploit)
5.50 SYS MD5: edb3513ec531b2bd28f3a0b52a82a54f (exploited)
4.51 SYS MD5: 1330b7bf63bf5c93d809b1eb1f4e1f01 (exploited)
4.03 SYS MD5: 3716e4e6e0d223cd94cd4a8e5bd4fb94 (exploited)

RECOVERY UPDATES (wipes all data):

7.61 REC MD5: 932f24e934723050fe49561b67e95226 (ready for exploit)
6.50 REC MD5: 4305223c12bd6dda9b944c0ee49c94c0 (ready for exploit)
5.50 REC MD5: c939ac8b37e07bbc129816a61002d30a (exploited)
4.51 REC MD5: da78ca268da90a963d89b0f45db0f061 (exploited)
4.03 REC MD5: e6dcc800d8d1dcada4f2bcd6e7ff162c (exploited)


PS5 OFW 1.xx runs PS4 games up to 7.50
PS5 OFW 2.xx runs PS4 games up to 8.00
PS5 OFW 3.xx runs PS4 games up to 8.50
PS5 OFW 4.xx runs PS4 games up to 9.00

PS4 backported FPKGs work perfectly on PS5.

To determine your OFW version:
Go to settings > system > console information.

Version string info:
Year.Half (1st/2nd half of the year)-Major Version No.Minor Version No.Extended info-Further Info.Retail/Debug

21.02-04.03.00.00-00.00.00.0.1

First BD-J + Kernel access exploit provided by Sleirsgoevy (29/9/22)


Note: There are several USERLAND exploits, a couple of KERNEL exploits, and there is now a public HYPERVISOR exploits available for 1.xx-2.70 to complete the full exploit chain (23/10/24).

Recently Flatz confirmed he has developed his own HV exploit (1.xx-4.51 which is kept private) which was chained from a PS4 save game, and has successfully dumped PlayStation Secure Processor (27/07/23).


As of August 4th 2022: We can now install PS4/PS5 PKG games and updates (and by extension FPKGs) however official PKGs cannot be run unless you legitimately owned them previously digitally and have a licence for them on your current console, or if you own the disc (for update pkgs).

As of October 6th PS4 FPKG can be played on 4.03 OFW thanks to Sliersgoevy FPKG enabler!

Payload: https://gbatemp.net/download/4-03-fpkg-enabler-hen.38248/

As of October 21st PS4 FPKG can be played on 4.50 thanks to cheburek3000 porting offsets.

Payload: https://gbatemp.net/download/4-50-fpkg-enabler-hen.38279/

As of October 25th theflow0 fixes BD-J path traversal and native code execution for 7.61
https://x.com/theflow0/status/1717088032031982066?s=46&t=PIYQV4jmWEyCbVfx3Nx26g

As of November 4th ktuff is fixed for 4.51:

Payload: https://gbatemp.net/download/fpkg-enabler-4-51-hen.38306/

Nov 7th PS5 backups loaded via Itemzflow by Lightningmodz and Echostretch. Fully decrypted dumps require system files bundled into them in order to run without crashing with Libhijacker (no hen required), details here: https://gbatemp.net/threads/ps5-exploit-guide.613891/page-109#post-10290677

As of November 30th ps5debug has been released by SiSTR0: https://github.com/GoldHEN/ps5debug
Mirror: https://gbatemp.net/download/ps5debug.38333/

Dec 1st: first PS5 trainer (Dark Souls) is completed ready for the imminent release of REAPER Multi Trainer II by CTN.

Dec 25th: PS5 back up loading via ITEMZFLOW now released: https://pkg-zone.com/details/ITEM00001

As of Jan 2nd 2024 Sleirsgoevy has ported K-Stuff offsets for 3.xx firmwares.

As of Jan 4th 2024 LM had added 3.XX Kstuff to Itemzflow meaning 3.XX-4.51 is now supported for PS4/PS5 backups and dumping.


Oct 8th 2024: BD-JB + Kernel works on 7.61 thanks to user Hammer.
1: Never enable IDU mode.
If you do you will need to enter staff mode by holding L1 + L2 and tapping this combo: circle, cross, square, triangle, right D-Pad. Release L1 + L2 and you can access settings to exit IDU.

2: Try to stay on the lowest FW possible and wait it out for hacks on that firmware.

3: PS5 FPKGs cannot work as a hack for the a53 processor does not publicly exist to enable PS5 content as FPKG/PKG.

4: Installing legit game PKGs you do not own will not work, even if spoofed.

5: If you get stuck in a boot loop at the PS logo, this means the SNVS is corrupted (if hash check fails on boot this causes a “soft brick”).

It’s not “bricked”, just reinstall your current firmware RECOVERY PUP in safe mode!

USB: PS5 > UPDATE > PS5UPDATE.PUP

WEBKIT EXPLOIT:
Webkit > Kernel exploit chain for 3.00-4.51 via SpectreDev & ChendoChap:
https://github.com/Cryptogenic/PS5-4.03-Kernel-Exploit

https://github.com/ChendoChap/PS5-IPV6-Kernel-Exploit/tree/wip_branch

4.03 only: https://sleirsgoevy.github.io/ps4jb2/ps5-403/index.html

BD-JB EXPLOIT:
BD-JB > Kernel exploit chain for 4.51 via Sleirsgoevy:
https://github.com/sleirsgoevy/bd-jb/commit/159253464afde59c3007a706210bec65b91f38f3

PS2 CLASSICS EXPLOIT:
PS2 Classics > Userland via CTurt:
(Implementation by McCaulay)

Note: this is currently limited to swapping the loaded PS2 iso, or loading PS2 elf homebrew on PS5 (or PS4) for emulators or basic PS2 brew.

Mast1c0re PS2 exploit for PS2 homebrew:
https://cturt.github.io/mast1c0re.html

Mast1c0re part 2:
https://cturt.github.io/mast1c0re-2.html

Mast1c0re payload framework:
https://github.com/McCaulay/mast1c0re

Okrager save game exploit generator for Okage:
https://github.com/McCaulay/okrager

Mast1c0re payloader TCP Client GUI for PS5 6.50:
https://github.com/Master-s/PS4-PS5-Mast1c0re-Payloader/releases

TCP network ISO loader:
https://github.com/McCaulay/mast1c0re-ps2-network-elf-loader/releases

ExFat USB ISO loader:
https://github.com/McCaulay/mast1c0re-ps2-usb-game-loader/releases

4.03 PAYLOADS:
PS5 self dumper (Sleirsgoevy):
https://github.com/sleirsgoevy/ps4jb-payloads/tree/bd-jb/ps5-self-dumper

PS4 FPKG Enabler (Sleirsgoevy):
https://gbatemp.net/download/4-03-fpkg-enabler-hen.38248/

4.5X PAYLOADS:
(Coming soon)

MISC PAYLOADS + TOOLS:
PS5 version display payload by SiSTR0 (compiled by Logic-68):
https://github.com/logic-68/Portage_PS5Version_Mast1c0re/releases/tag/V1.0.0

Libhijacker (by Astrelsky):
https://github.com/astrelsky/libhijacker

60 FPS patches for Libhijacker (by illusion0001):
https://github.com/illusion0001/libhijacker
Console/exploit information:

PS5 SDK REPO:

https://github.com/PS5Dev

PS5 factory mode PUP installation path:
/usb/PROSPERO/UPDATE/PROSPEROUPDATE.PUP

You can install free/demo PKGS (legit pkgs) via debug pkg installer, providing you have all the files/json/licences required.

(Astro’s Playroom has no licences and can be installed and played from official pkgs and update up to 1.60)
 
Last edited by KiiWii,

Wolf85

Well-Known Member
Newcomer
Joined
Feb 29, 2016
Messages
75
Trophies
0
Age
39
XP
339
Country
United States
Might not be that bad. I just cant imagine a disc less future and consoles that can't be jailbroken. I went and bought physical copy of Star wars fallen order for £6. It's £60 on PSN despite being an old game now!!
Sony might have you believe that the ps5 pro recent discount was black Friday related but I'm sure it's more about consumers rejecting the absurd £700 launch price. Same with future PS6, in the end, the market will dictate whether an expensive console can exist or not.
First time that I'm Starting to feel like an old man yelling at clouds. So much about society that doesn't make sense outside of forums like these 😔
The money scam has never made sense once in over twelve thousand years, but greedy humans keep using it to enslave the rest of us...
 

C_2_T

Member
Newcomer
Joined
Nov 13, 2024
Messages
18
Trophies
0
Age
43
XP
39
Country
United States
He talked about being made redundant while looking after family. Good news is they will now continue developing for the scene thanks to donations and recouping other monies. Because there are so few developers working on ps5 scene, if one person leaves or retires then it has big consequences. So I'm glad Zeco is doing a bit better now :)
I can understand his position. I'm also unemployed. it's been a hard time for me personally, so I can empathize. he does need to spend more time on himself. the scene will still be there later.
 

ccfman2004

Well-Known Member
Member
Joined
Mar 5, 2008
Messages
2,962
Trophies
2
XP
3,743
Country
United States
I can understand his position. I'm also unemployed. it's been a hard time for me personally, so I can empathize. he does need to spend more time on himself. the scene will still be there later.
I wish I understood more of how these people find exploits in hardware so I could add anything I would find. But alas, this is far beyond what I understand. If I had extra funds, I'd throw some their way as these guys absolutely rock. I wish more people would be nice to these extraordinarily talented folks rather than be WEN, WEN, WEN. We've lost too many good people due to that mentality.
 

C_2_T

Member
Newcomer
Joined
Nov 13, 2024
Messages
18
Trophies
0
Age
43
XP
39
Country
United States
I wish I understood more of how these people find exploits in hardware so I could add anything I would find. But alas, this is far beyond what I understand. If I had extra funds, I'd throw some their way as these guys absolutely rock. I wish more people would be nice to these extraordinarily talented folks rather than be WEN, WEN, WEN. We've lost too many good people due to that mentality.
thanks. I wasn't sure if anyone agreed with me. I agree that a lot of people don't truly appreciate how much time these people invest to find exploits, develop homebrew, dump games, etc. with each new generation, it seems there are fewer and fewer people who care. not only is it harder to hack these systems, but more people expect you to deliver in a timely fashion, which is sad. I'm legit myself. I don't care if people pirate though. I just don't want the latest hacked, especially after what happened with the ps3. that was a disaster, because sony was totally unprepared. I also don't want pirates to have the same amenities a legit person would have while also not buying games, for those who only pirate. that's always been concern of mine. I simply don't think it's fair, and I think if I were pirating, I'd feel the same way. legit users don't deserve it. they've done nothing wrong.
 

FateNightroad

Well-Known Member
Member
Joined
Jul 19, 2023
Messages
145
Trophies
0
Age
37
XP
426
Country
Canada
I also don't want pirates to have the same amenities a legit person would have while also not buying games, for those who only pirate. that's always been concern of mine. I simply don't think it's fair, and I think if I were pirating, I'd feel the same way. legit users don't deserve it. they've done nothing wrong.
I haven't seen "legit" users being treated any different from others. What do you mean?
 

C_2_T

Member
Newcomer
Joined
Nov 13, 2024
Messages
18
Trophies
0
Age
43
XP
39
Country
United States
I haven't seen "legit" users being treated any different from others. What do you mean?
I mean I don't think pirates should be able to use cloud or sync trophies or whatever. do you know what happened after the ps3 was hacked on the latest firmware? cheaters, people causing legit users to be banned by hacking their accounts, adding money to wallets, etc. that's completely unfair. like I and the other person were talking, a lot of people who pirate don't even donate to devs who make this possible to begin with. it's not like they're breaking the bank either, just $5. I just got a smart tv THIS YEAR, when a lot of these people have the means to donate but don't. I've donated over $100, and I barely get $600/month for all expenses, so there's no excuse for not giving a shit. those sorts of people don't deserve free games. they offer nothing in return. that is a fact.
 

ccfman2004

Well-Known Member
Member
Joined
Mar 5, 2008
Messages
2,962
Trophies
2
XP
3,743
Country
United States
I mean I don't think pirates should be able to use cloud or sync trophies or whatever. do you know what happened after the ps3 was hacked on the latest firmware? cheaters, people causing legit users to be banned by hacking their accounts, adding money to wallets, etc. that's completely unfair. like I and the other person were talking, a lot of people who pirate don't even donate to devs who make this possible to begin with. it's not like they're breaking the bank either, just $5. I just got a smart tv THIS YEAR, when a lot of these people have the means to donate but don't. I've donated over $100, and I barely get $600/month for all expenses, so there's no excuse for not giving a shit. those sorts of people don't deserve free games. they offer nothing in return. that is a fact.
Nobody on exploitable firmware can connect to PSN at least nothing that's public to let us do so. For the PS3, Sony was heavy handed with ban hammers to people who connected to PSN with a PS3 in jailbreak mode.

But with the PS4 and PS5, exploits are reported to Sony and patched before said exploit has the chance of being made public so unless Sony royally screws something up with firmware checks and accidentally makes it possible for people to connect to PSN while on an exploitable firmware, I don't we have to worry about cheaters online.
 
  • Like
Reactions: FateNightroad

FateNightroad

Well-Known Member
Member
Joined
Jul 19, 2023
Messages
145
Trophies
0
Age
37
XP
426
Country
Canada
I mean I don't think pirates should be able to use cloud or sync trophies or whatever. do you know what happened after the ps3 was hacked on the latest firmware? cheaters, people causing legit users to be banned by hacking their accounts, adding money to wallets, etc. that's completely unfair.
You aren't able to use cloud or sync trophies or whatever on the PS4 or PS5 because there's no custom firmware like on the PS3. So, perhaps it was unfair back at that specific era, but not currently as far as I know.
 

Mc_Kuc

Active Member
Newcomer
Joined
Mar 6, 2024
Messages
25
Trophies
0
Age
31
XP
169
Country
Austria
Hello, i just want to let you know that i will return my PS5 Pro next week because for me personally it is not worth it. The FW is 9.05 and if somebody can not find one on 9.05 but wants to have a PS5 Pro on the lowest FW possible, you can contact me. I am from Austria and would give it away for the same price i paid for it (+shipping if needed). I am struggling a bit to send it back knowing that it will be updated to 10.20 or higher 😄.
 

Attachments

  • Screenshot_20241116_232542_Amazon Shopping.jpg
    Screenshot_20241116_232542_Amazon Shopping.jpg
    31.7 KB · Views: 1

AlphaBravo

Well-Known Member
Member
Joined
Oct 9, 2018
Messages
136
Trophies
0
Age
42
XP
600
Country
United Kingdom
At one point I saw some eBay being listings for £600. I agree with you but I'd say the Pro is not worth it at the moment. Maybe in 3-6 months. Sony and third parties urgently need to clarify what's games are getting pro patches because there is a lot of confusion on this subject. Some games got patches but then didn't use PSSR. Others like Allan wake 2 and Star wars Survivor have artefacts or frame rate issues.
The Ps5 Pro has potential but it was rushed to market and it annoying that older games require individual patches rather than naturally improving like a pc game does when you simply upgrade it's ram or GPU.
 
Last edited by AlphaBravo,
  • Like
Reactions: qamartheone

iguanoPT

Active Member
Newcomer
Joined
Jan 10, 2024
Messages
37
Trophies
1
Age
39
XP
378
Country
Portugal
Right, but when the PS6 comes out. How many people will buy it, when it could drop considerably in price in a week?

Deflation is the worst thing you can ever do.
With FOMO as high as it is and the helping hand of scalpers... I don't think people will remember anything, sadly😂
 

KiiWii

Editorial Team
OP
Editorial Team
Joined
Nov 17, 2008
Messages
17,175
Trophies
3
Website
defaultdnb.github.io
XP
29,507
Country
United Kingdom
Can you explain why this is interesting for this thread ? Is there some reference to kernel crashes or something?
It’s interesting to note issues with a console that may be jailbreakable one day.

I have the Pro and have found a few issues here and there in some games, which is going to happen but overall the compatibility is great and the upscaling is incredible.
 
  • Like
Reactions: Randqalan

AlphaBravo

Well-Known Member
Member
Joined
Oct 9, 2018
Messages
136
Trophies
0
Age
42
XP
600
Country
United Kingdom
Was
It’s interesting to note issues with a console that may be jailbreakable one day.

I have the Pro and have found a few issues here and there in some games, which is going to happen but overall the compatibility is great and the upscaling is incredible.

If ps5 pro was jailbroken at launch, pretty sure that scene developers would flicked a couple of switches, changed a line of code and most of these problems would have been fixed by now 😉
 

ccfman2004

Well-Known Member
Member
Joined
Mar 5, 2008
Messages
2,962
Trophies
2
XP
3,743
Country
United States
Sometimes I think Sony is purposely either adding some of those game bugs in or not fixing them before launch just to see if any hackers jailbreak it right after launch so they can fix that silently while also stating they are fixing those game issues to get people to update. That could just be my internal conspiracy theory generator acting up.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Veho @ Veho: Well, onion maybe.