Tutorial  Updated

PS5 Exploit Guide

PS5 Hack Status:


FW Ranges:
2.XX = KEX+HV: PS4/5 backups, possible keys exploit (WK: 2.50 best / 2.7X max)
3.XX = KEX+HV+Linux: PS4/5 backups, possible keys exploit (WK/BD/LUA: 3.20 best / 3.21 max)
4.XX = KEX+HV+Linux: PS4/5 backups (WK/BD/LUA (Y2/NF/YARPE 4.03+): 4.50 best / 4.51 max)
5.XX = KEX+HV+Linux: PS4/5 backups (
WK/BD/Y2/NF/LUA/YARPE: 5.50 best + max)

6.XX = KEX: PS4/5 backups (KEX+HV+Linux: 6.02 max) (WK/BD/Y2/NF/LUA/YARPE: 6.02 for Linux / 6.50 max)
7.XX = KEX: PS4/5 backups (KEX+HV+Linux: 7.61) (
WK/BD/Y2/NF/LUA/YARPE: 7.61 best + max)
8.XX-10.00 = KEX: PS4/5 backups, no HV (WK/BD/Y2/NF/LUA/YARPE)
10.01-12.70 = KEX: PS4/5 backups, no HV (
WK/BD/Y2/NF/LUA/YARPE)
13.XX = HV+KEX+WK SOON! (WK/BD (13.42)/Y2/LUA/YARPE)
14.XX = No KEX/UL only (LUA/YARPE)


NOTE 1: Recommended firmware is subjective. Staying low is always recommended.
NOTE 2: Do not update too many major versions (e.g., 4.xx to 5.xx or 7.xx to 8.xx). Remain low unless all you want is backups.
NOTE 3: P2JB can take over an hour to exploit on FW up to 12.70.


Hypervisor (HV):
Highest released HV: 7.61
Highest unreleased HV: 13.60 (SlopVisor)
*unreleased/unimplemented


Kernel (KEX):
Highest released KEX:
12.70 (P2JB)
Highest unreleased KEX: 13.60 (SlopSploit SOON)
UMTX2:
1.00-7.61 (*WK to 5.50 / BDJB to 7.61)
Lapse: 1.00-10.01
Relapse/Prolapse: 11.60-13.60 (Soon)
Poopsploit:
4.03-12.00 (*BD to 12.00)
P2JB: 9.00-12.70 (*WK: Lapse to 10.01 / P2JB to 12.70)

Userland (UL):
LUA (Artemis): 2.00-LATEST (LUA exploit, + Lapse up to 10.01)
Y2JB: 4.03-13.40 (YouTube exploit, + Lapse: 10.01 / P2JB: 12.70)
NFNH: 4.03-12.XX (Netflix exploit, + Lapse: 10.01)
YARPE: 4.03-12.XX (Ren'Py exploit, + Lapse: 10.01 / P2JB: 12.70)
BD-JB: 1.00-13.42 (BD exploit + UMTX2: 7.61 / BD-JB5 + Poops to 12.00)
Webkit: 1.00-5.50 (PSFREE +UMTX2: 5.50 / SlopKit 7.00-13.60 (P2JB: 12.70) / (Slopsploit: 13.60)
Mast1C0re: 1.00-7.61 (Depreciated for LuaC0re)
LuaC0re: 1.00-12.70 (Poops: 4.03-12.00/P2JB: 9.00-12.70)
REDIS: 1.00-5.50 (Jordy's untethered JB on boot - coming soon)

NOTE 1: A userland entry point (UL) chained to kernel exploit (KEX) is required to exploit your console.
NOTE 2: Digital consoles can now use Y2JB+Poops (4.03-12.00) / Y2JB+P2JB (9.00-12.70).
NOTE 3: All consoles will be able to use SlopKit (webkit), SplopSploit (KEX) and SlopVisor (HV) for firmwares up to 13.60 SOON.


Useful Applications:
FPKG: 3.00-11.60 with KStuff Lite / 12.XX-13.60 SOON
Kstuff Lite: 3.00-12.70
HERE
Kstuff Toggle: 3.00-12.00 HERE
PS5 App Dumper: 3.00-12.00 HERE
Dump Runner: 3.00-12.00 HERE
Dump Installer: 3.00-12.00 HERE
Backporting: Possible (backpork / Porkfolio)
PS4/PS5 DLC: Work with Kstuff Lite
Trophies: Work with Kstuff Lite
Compression: Works with Kstuff Lite
Homebrew Enabler: etaHEN (3.00-10.01) latest HERE
PS5 Backup manager: ItemzFlow Compatibility list: HERE
PS4 Backup Loading: Works (rest mode & backports work, can crash).
PS5 Debug NG: 3.XX-13.XX
HERE
PS5 Remote Play: Works HERE & HERE
PS5 Trainers/Cheats: Work

UART:
HERE
Linux: (OG: 3.00-7.61, Slim: 7.61) HERE
Kldload (wip): 3.00-6.50 HERE
PSN access: NEVER
Latest OFW: 14.00 (16/9/26)
Summarised OFW/Model guide: HERE
1.XX-7.61 compatibility list:
HERE
PS5 SDK Repo: HERE
Legit PKG Updates: HERE or HERE
OFW Updates: HERE (history HERE)

Preparing Your Console:


It is recommended to either self-host offline or block these addresses in your router to avoid accidental updates or getting an update nag. Using the DNS method is no longer failsafe, as these are not guaranteed to be running 24/7.


dau01.ps5.update.playstation.net
dbr01.ps5.update.playstation.net
dcn01.ps5.update.playstation.net
deu01.ps5.update.playstation.net
dhk01.ps5.update.playstation.net
djp01.ps5.update.playstation.net
dkr01.ps5.update.playstation.net
dmx01.ps5.update.playstation.net
dru01.ps5.update.playstation.net
dsa01.ps5.update.playstation.net
dtw01.ps5.update.playstation.net
duk01.ps5.update.playstation.net
dus01.ps5.update.playstation.net
fau01.ps5.update.playstation.net
fbr01.ps5.update.playstation.net
fcn01.ps5.update.playstation.net
feu01.ps5.update.playstation.net
fhk01.ps5.update.playstation.net
fjp01.ps5.update.playstation.net
fkr01.ps5.update.playstation.net
fmx01.ps5.update.playstation.net
fru01.ps5.update.playstation.net
fsa01.ps5.update.playstation.net
ftw01.ps5.update.playstation.net
fuk01.ps5.update.playstation.net
fus01.ps5.update.playstation.net
hau01.ps5.update.playstation.net
hbr01.ps5.update.playstation.net
hcn01.ps5.update.playstation.net
heu01.ps5.update.playstation.net
hhk01.ps5.update.playstation.net
hjp01.ps5.update.playstation.net
hkr01.ps5.update.playstation.net
hmx01.ps5.update.playstation.net
hru01.ps5.update.playstation.net
hsa01.ps5.update.playstation.net
htw01.ps5.update.playstation.net
huk01.ps5.update.playstation.net
hus01.ps5.update.playstation.net
sgst.prod.dl.playstation.net
gs2.ww.prod.dl.playstation.net

Alternative DNS IP:
62.210.38.117 - User Guide = ES7in1
or
45.56.67.85
(Leave DNS 2 blank)

To determine your OFW version:
Go to settings > system > console information.

Version string info:
Year.Half (1st/2nd half of the year)-Major Version No.Minor Version No.Extended info-Further Info.Retail/Debug

21.02-04.03.00.00-00.00.00.0.1

It is recommended to keep your console as low as possible to have access to better jailbreak stability and features. Stay as low as possible within the "Golden" firmware brackets that apply to your current firmware, see the top of this page.

(No jailbreak is ever guaranteed. No developer is obliged to release anything publicly)

WARNING:

Only update OFW manually via USB by getting the firmware file from HERE and installing from <USB>:/PS5/UPDATE/PS5UPDATE.PUP
(Updating with RECOVERY PUP will perform a factory format and will wipe your internal HDD)

PS5 factory mode PUP installation path:
/usb/PROSPERO/UPDATE/PROSPEROUPDATE.PUP

NOTE: Make a system back up before attempting any modifications.
On console: go to [Settings] > [System] > [System Software] > [Back Up and Restore] > [Back Up Your PS5]

Select Your Jailbreak:


WEBKIT:BD-JB:LUA:Y2JB:NFNH:YARPE:LuaC0re:BD-UN-JB:


  1. Information:
    Firmware 1.00-5.50 or 7.00-12.70 is required for the webkit exploit.

    Enabling web browser:
    Open [Settings] > select [Users & Accounts] > select [YouTube] > click "Link" > click "use browser" > click "terms" (bottom right) > click google apps icon (top right) > select Google Search.

    Exploiting 1.00-5.50:
    Enter https://zecoxao.github.io/luasauce/ or https://github.com/kmeps4/PSFree into google > click “Jailbreak" or wait for it to complete.

    Exploiting 7.00-8.60:

    https://soniciso1.github.io/pooP2JB/

    Exploiting 7.00-12.00 (-13.60 SOON):

    https://jordyidk.github.io/slopkit/

    https://zecoxao.github.io/slopkit2/

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  2. Important:
    You will need a BD dive paired to your Slim/Pro console or an OG Phat model . Consoles must be on 1.00-13.42 to run this exploit.


    Recommended ISO: Viktorious AIO Auto BD-JB ISO for 4.XX-7.61

    Exploiting:
    1, Burn ISO to a blank BD-R or BD-RE > Insert into console > click on the [DISC PLAYER] icon.

    2, Highlight [PIPELINE RUNNER] > click option 2 [Normaljailbreak-etaHEN-UMTX1.pipe] to auto load etaHEN ready for ItemzFlow.

    ELF Loader uses PS5 IP: port 9021 / BIN loader uses 9020 / Jar loader uses port 9025

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  3. Important:
    LUA entry point works from 2.00 to the latest OFW, but there is no KEX above 12.70 yet.
    (A compatible PS4 game is required to launch the exploit on PS5. See below)

    Your PS5 console must be activated to use save copying for PS4 games.
    1. Insert your game disc and, as soon as possible, make a save file within it.
    2. Copy the save files to USB, go to [SETTINGS] > [STORAGE] > [CONSOLE STORAGE] > [SAVE DATA] > [PS4 GAMES] > select the game save and copy to a USB drive.
    3. On PC, using a Google Drive account, make a new folder with the GAME ID of your game, and upload the savedata & savedata.bin files to that folder.
    4. Share the folder, set it to editor mode, share with anyone, and click "copy the link".
    5. Join the HTOS Discord group: HERE type "/decrypt", select "FALSE" for including SCE_SYS, paste or type in the Google Drive link, and press enter. The bot should begin mounting your save. (If it doesn't, paste in the link again.)
    6. Click "ENCRYPTED" to remove the Sony PFS layer. Download the generated files and extract the folder to your desktop (you should have 4 files in there and be named dec_savedata_CUSA[GAME ID]).
    7. Using REMOTE LUA LOADER, open the savedata folder, copy the 20 files within into your encrypted save folder on your desktop.
    8. Upload the encrypted save folder (now with 24 files in) to your Google Drive. It should be named "dec_savedata_CUSA[GAME ID]" where GAME ID is your games 5 digit number, and set it to editor mode, share with anyone, and then click "copy the link".
    9. Go back to the HTOS discord server, and type "/encrypt", hit "FALSE" for uploading individually, and "FALSE" to include SCE_SYS. Finally, hit shared_gd_link and paste in your link to the original save (4 files) folder. (If it doesn't, paste in the link again.)
    10. When this is done, paste the link to the decrypted save (24 files) folder, and the bot will encrypt the files.
    11. Resign the files by typing "/resign" followed by your account name on the console, or PSN ID associated with that account if using the latest OFW.
    12. Download the resigned files, extract the files to your USB drive and overwrite them into the savedata folder on your USB or external drive.
    13. Copy the saves back to your console [SETTINGS] > [SAVE DATA AND GAME/APP SETTINGS] > [SAVE DATA PS4] > [COPY OR DELETE FROM USB] > [COPY TO CONSOLE STORAGE] > select your game save folder from the USB drive and copy/overwrite old save data.
    14. Load LUA game again, and you should see the LUA LOADER screen.
    15. You can use "SEND_LUA.PY" to send the UMTX files to the loader.
    (NOTE: Some games require manual loading of save game)

    On firmware up to 7.61, you can now load UMTX/2 followed by etaHEN by sending the files to your console IP on PORT 9026.
    On firmware 8.00-LATEST, you can connect with the REMOTE LUA LOADER APP to send debug notifications or FTP on port 1337.

    LUA Loader: HERE or HERE

    Auto LUA Loader Fork: HERE

    Compatible LUA games:
    Aerial Life (CUSA17122)
    Aibeya (CUSA17068)
    Aikagi 2 (CUSA19556)
    Aikagi Kimi to Issho ni Pack (CUSA16229)
    Aikano Yukizora no Triangle (CUSA19370)
    Boku to Nurse no Kenshuu Nisshi (CUSA12049)
    Boku to Joi no Shinsatsu Nisshi (CUSA18107)
    Fuyu Kiss (CUSA29745)
    Hamidashi Creative (CUSA27389)
    Hamidashi Creative Demo (CUSA27390 requires the latest OFW to download from PSN)
    Haruoto Alice (CUSA14324)
    IxSHE Tell (CUSA17112)
    IxSHE Tell Demo (CUSA17126)
    Jinki Resurrection (CUSA25179)
    Jinki Resurrection Demo (CUSA25180 requires the latest OFW to download from PSN)
    Maid-san no Iru Kurashi (CUSA18106)
    Nora Princess and Stray Cat Heart HD (CUSA13303: Rename save9999.dat into nora_01.dat)
    Nora Princess and Strat Cat Heart 2 (CUSA13586)
    Raspberry Cube (CUSA16074)
    Winter Guest (CUSA11977)

    WARNING: using demos is free but can become corrupt, and you cannot upgrade your internal HDD either. If you lose the demo you can no longer use the exploit. Disc recommended.

    Incompatible LUA games:

    Dokyusei Remake Csver (CUSA47117)
    Dōkyūsei: Bangin' Summer - Home Edition Demo (CUSA47132)
    Kiss Trilogy (CUSA19341)
    Love Clear Demo (CUSA18109)
    Mikagami Sumika no Seifuku Katsudou (CUSA11481)
    Sen no Hatou, Arazone no Hime (CUSA09647)
    Tonari ni Kanojo no Iru Shiawase: Two Farce (CUSA09825)
    Tonari ni Kanojo no Iru Shiawase Summer Surprise (CUSA18998)

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  4. Requirements:
    PS5 console must be on 4.30-12.70 and previously activated through PSN or fake activated to use the YouTube app, unless you're restoring a backup.
    (Note: restoring a backup will factory reset your console).

    Information:
    If updating and older installation, download the latest download0.dat > use FTP or PS5 Explorer to place it in the user/download/PPSA01650 folder.

    Preparation:
    Download the Y2JB_backup_X.X(4.03) if you're on 4.03-12.40, or the Y2JB_backup_X.X(12.20) if you're on 12.60 or higher from HERE
    On PC: format a USB 3.0 HDD to exFAT, and copy the PS5 folder from the backup to the root, and put the latest nanodnf.efl from nanoDNS to the root too.
    On console: go to [Settings] > [System] > [System Software] > [Back up and Restore] > [Restore] > select the y2JB back up & let it install (the console will reboot when complete).
    (Note: The exploit will now be accessible under the [MEDIA] tab)

    Exploiting:
    Going to [Settings] > [Network] > [Settings] > [Set up Internet Connection] > [Set up Manually] > set up a wireless or LAN connection > change [DNS Settings] to manual > change [Primary DNS] to 127.0.0.1 > click [Done] > open the [YouTube App].
    (Note: Ignore and internet connection issue warnings)

    Firmware up to 10.01 will use Lapse Kernel Exploit. Firmware 10.20-12.70 and above will use P2JB and could take up to an hour.

    You can send payloads using netcat GUI to PS5's IP Address & port 9021.

    You can swap the download0.dat to itzPLK version for auto loading and payload manager in future (payload manager accessible through browser on 127.0.0.1:8084)

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  5. Requirements:
    PS5 console must be on 4.30-10.01 and previously activated through PSN or fake activated. You will need a 256GB external HDD (minimum).

    Preparation:
    Download balenaEtcher
    Download the latest Extended Storage or M.2 Image (select your m.2's capacity)

    EXTERNAL DRIVE METHOD (Netflix_PS5_EU_Ext.7z):
    1a, On PC: connect your 256GB (min) USB drive to your Windows/Mac/Linux PC > extract the image to your computer > open Etcher > click [Flash From File] & select the extracted image *.zip > click [Select Target] & choose the external drive > Click [Flash!] & allow it to complete.
    (Note: 256GB is the smallest drive you can use)

    2a, On console: click [Settings] > [Storage] > [USB Extended Storage] > [Games and Apps] > press X on [Netflix] > select [NETFLIX] under items to move > select [Move] > move to internal storage & allow it to complete.
    (Note: The exploit will now be accessible under the [MEDIA] tab)

    INTERNAL DRIVE METHOD (Netflix.XXXXGB.7z):
    1b, On PC: connect the M.2 to your Windows/Mac/Linux PC > extract the image to your computer > open Etcher > click [Flash From File] & select the extracted image *.zip > click [Select Target] & choose the external drive > Click [Flash!] & allow it to complete.
    (Note: 4TB will take 80 mins, 2TB 45 mins, 256GB 10 mins)

    2b, On console: Power off the console > insert the M.2 SSD > power on the console > click [Settings] > [Storage] > press X on [Netflix] > select [NETFLIX] under items to move > select [Move] > move to internal storage & allow it to complete.
    (Note: The exploit will now be accessible under the [MEDIA] tab).

    Exploiting:
    1a, for consoles 10.01 and below, on console: go to [Settings] > [Network] > [Settings] > [Set up Internet Connection] > [Set up Manually] > set up a wireless or LAN connection. Go to Proxy > change [Automatic] to [Manual] > enter Address: 172.105.156.37 & port: 42069 > click [Done] > open the [Netflix App].
    (Note: Ignore and internet connection issue warnings)

    1b, for consoles 10.20-12.70, COMING SOON.

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  6. Important:
    YARPE works from 4.30 to 12.70 (9.00 - 12.07 via P2JB)
    (A compatible PS4 game is required to launch the exploit on PS5. See below)

    Requirements:
    PS5 console must be on 4.30-10.01 to use this exploit.

    Exploiting:
    coming soon

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  7. Requirements:
    PS5 console must be on 4.30-12.70 to use this exploit. SWRR

    Exploiting:
    coming soon

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].


  8. [UPDATED]
    No longer needed if using latest WebKit (to 13.60) or BD-JB (to 13.42)!


    Important:

    This method modifies the BD-J stack to allows BD-JB entry point to be re-enabled on consoles up to 13.60, for convenience only.

    Very Important:
    This method requires your console to be jailbroken by another method first to gain access to alter the files.

    https://github.com/Gezine/BD-UN-JB

    Preparation:
    Burn the ISO to a blank Blu Ray, insert it into the jailbroken console. Send the bdj_unpatch.elf to elfldr using netcat GUI to PS5's IP Address & port 9021 to unpatch BD-J.

    (NOTE: DO NOT REINSTALL/UPDATE FW, IT WILL WIPE THE PATCH AND LOSE BD-JB)


Once jailbroken it is recommended to run KSTUFF LITE and SHADOWMOUNTPLUS at minimum to get you up and running.
(ShadowMountPlus: is an automated background auto-mounter payload for jailbroken PS5 consoles. Detects, mounts, and installs game dumps from internal or external storage, with support for UFS, exFAT, PFS, and nested compressed PFS containers)

Additional Information:


Blocking Updated with nanoDNS:
Set primary DNS manually to 127.0.0.1. Send latest elf to BIN LOADER using netcat GUI to PS5's IP Address & port 9021.

PS4 GAME INFORMATION:
OFW 1.xx cannot run PS4 games.
OFW 2.xx runs PS4 games up to 8.03

OFW 3.xx runs PS4 games up to 8.52
OFW 4.xx runs PS4 games up to 9.04
OFW 5.xx runs PS4 games up to 9.60
OFW 6.xx runs PS4 games up to 10.50

OFW 7.xx runs PS4 games up to 11.00
OFW 8.xx/9.xx runs PS4 games up to 11.50
OFW 10.xx runs PS4 games up to 12.00

OFW 11.xx runs PS4 games up to 12.50
OFW 12.xx runs PS4 games up to 13.00
OFW 13.xx runs PS4 games up to 13.52
OFW 14.xx runs PS4 games up to 14.00


(Note: PS4 backported FPKGs also work perfectly on an exploited PS5 with Kstuff)


You can install free/demo PKGS (legit pkgs) via the debug pkg installer, provided you have all the files/json/licences required.
(Astro’s Playroom has no licences and can be installed and played from official pkgs and updated inline with your firmware)

Warnings:


1: Never enable IDU mode.
If you do, you will need to enter staff mode by holding L1 + L2 and tapping this combo: circle, cross, square, triangle, right D-Pad. Release L1 + L2, and you can access settings to exit IDU.

2: Try to stay on the lowest FW possible and wait for hacks on that firmware.

3: Installing legit game PKGs you do not own will never work, even if spoofed.

4: If you get stuck in a boot loop at the PS logo, the SNVS is corrupted (if the hash check fails on boot, this causes a “soft brick”). It’s not “bricked”. Simply reinstall your current firmware RECOVERY PUP in safe mode from USB: PS5 > UPDATE > PS5UPDATE.PUP.

Archived Information


 
Last edited by KiiWii,
1790234676332.png
 

Attachments


So in theory if we're just running fpkg (no mountable game images) we could get away with just running this one payload (now that a53 is incorporated) and do without shadowmount too
It's still quite early in the day and I'm not fully awake, am i missing something ?

Edit... can't remember if his version of Kstuff supports backports or if that's what we need sm+ for... would be pretty great to have the one unified payload in my humblest of opinions
 
So in theory if we're just running fpkg (no mountable game images) we could get away with just running this one payload (now that a53 is incorporated) and do without shadowmount too
It's still quite early in the day and I'm not fully awake, am i missing something ?

Edit... can't remember if his version of Kstuff supports backports or if that's what we need sm+ for... would be pretty great to have the one unified payload in my humblest of opinions
Indeed.

Previous situation.
1. Load PPR A53 patch
2. Load kstuff

Current situation.
1. Load kstuff, because the PPR patch for A53 is integrated.

SM+ is needed for mounting games such as .ffpkg, .exfat, .ffpfs, .ffpfsc and pfs container related formats.
 
Last edited by HS2005,
Indeed.

Previous situation.
1. Load PPR A53 patch
2. Load kstuff

Current situation.
1. Load kstuff, because the PPR patch for A53 in integrated.

SM+ is only needed for mounting games such as .ffpkg, .exfat, .ffpfs, .ffpfsc, pfs container related

Thanks! I sometimes find it hard to focus and think clearly (mainly because of the daily medications) so I appreciate you helping me to see clearly

It's a great time, whilst some of the AIO payload's we were seeing from some AI assisted dev's were ridiculously bloated I believe this kind of unified payload from a very talented individual is the way forward... Less is more imho :)
 
SM+ is only needed for mounting games such as .ffpkg, .exfat, .ffpfs, .ffpfsc and pfs container related formats.
It can also be used to load external backport files over an fPKG if you ever want to swap those out or otherwise mess with them without repacking the whole dang package. But that is a going to become an increasingly niche use case for end-users as the library of available fPKGs grows.
 
Last edited by ViRGE,
  • Like
Reactions: Godoto
Thanks! I sometimes find it hard to focus and think clearly (mainly because of the daily medications) so I appreciate you helping me to see clearly

It's a great time, whilst some of the AIO payload's we were seeing from some AI assisted dev's were ridiculously bloated I believe this kind of unified payload from a very talented individual is the way forward... Less is more imho :)
Well besides any medication PS5 developments are in a rapid-pace.
When I open my discord on a daily basis I have over 200+ new messages and like 30 new+ DM's.

The rule of thumbs is the less payloads the less stress on the system. .elf files can be merged, when merged properly, due to many firmwares and all of their different nature / behaviour. This was also a pre developement: https://github.com/Soonniicc/kstuff-a53 (now offline) not needed anymore.

Anyway we will see what is (still) needed once 13.60 arrives.
Post automatically merged:

It can also be used to load external backport files if you ever want to swap those out or otherwise mess with them without repacking the whole dang fPKG. But that is a going to become an increasingly niche use case for end-users as the library of available fPKGs grows.
Yes that why I wrote and pfs container related formats because SM+ also reads and makes use of fakelib and fakelib2. Asumming you wanted to point that out.

EDIT: In addition. The M2 fix is big because a lot of people (like I) make use of a internal M2 slot.
 
Last edited by HS2005,
Anyone got zeco's fw spoof working? I had it working no problem before, but now it never shows any debug popup and freezes me out of any other homebrew without changing the fw string. my console is still on the same fw too,
 
Anyone got zeco's fw spoof working? I had it working no problem before, but now it never shows any debug popup and freezes me out of any other homebrew without changing the fw string. my console is still on the same fw too,
Nevere tried it because no need. You can check this if you want: https://github.com/illusionyy/ps5-fw-spoof/releases
Post automatically merged:

Additional update regarding elf-arsenal

v1.6.23


soniciso released this yesterday

Firmware coverage, a PKG installer that takes links, and a download queue that
stops hiding what it is doing.

Install from a link. Paste URLs one per line, or give it the address of a
page that lists them — an archive.org item, an open directory index, anything
that is just anchors — and the console reads that page and hands back the .pkg
links to pick from. Doing the fetch on the console also sidesteps the CORS
refusals a browser would hit. Links go on a queue with a single worker, since
installs serialise down there anyway; it reports per-item state and refuses
duplicates that are still pending.

Every payload is rebuilt against the current SDK, so all of them now carry the
full 3.00–13.60 dispatch. zftpd was the one that mattered: it stopped at 10.60
and was reachable from the FTP daemon switch. The firmware check that catches
this now also runs on the argv spawn path, which was skipping it.

The ShellCore PPR patch gains tables for 6.50 and 10.60, taking it to 50
of 51 firmwares — only 9.05 is missing, and no image for it exists to derive one
from. Both new tables were carried over from neighbouring firmwares rather than
read off a console; tools/verify-firmware-tables.py checks every table against
a real firmware image and all 51 pass, 561 sites, nothing failing. The same tool
verifies kmonitor's kernel offsets against decrypted kernels — 51 of 52.

The patcher now looks before it writes. Each entry replaces a specific
instruction, and nothing checked that the instruction was there; an offset that
did not describe the running build was written anyway. Anything unexpected is
skipped now, which is also what makes a derived table safe to ship.

Link: https://git.etawen.dev/soniciso/elf-arsenal/releases/tag/v1.6.23
 
Last edited by HS2005,
  • Like
Reactions: schatzi24
Still want one of these vibe coding devs to explain why we can’t get FPKG on 12.xx. A real dev would’ve explained it by now. But I guess since their Patreon donations aren’t where they’d like them to be, they won’t.

So allow me.

Apparently the reason why we don’t have it yet for 12.xx is because Sony patched the A53 in those firmwares. So whatever “exploit” they have, it’s unfortunately required to run FPKG on anything over 12.xx. The 11.60 fix was just to update some things that 11.40 changed but the “hole” was still there.

Still, I want to hear it out of the mouth of one of these devs to either confirm I’m right or to prove me wrong.

Tired of all this grandstanding and drama and shit. Takes a few minutes to explain things. But they’re too busy fighting and trolling each other to do it.

To quote CM Punk “I’m old, I’m tired, and I work with fucking children”. I’d be laughing if it wasn’t so true.

I gave it a few days to see if they could muster up the answer, now I am.

So if you’re on 12.xx firmware, you’ll have to wait for the new 13.60 exploit before you get FPKG support.
 
Still want one of these vibe coding devs to explain why we can’t get FPKG on 12.xx. A real dev would’ve explained it by now. But I guess since their Patreon donations aren’t where they’d like them to be, they won’t.

So allow me.

Apparently the reason why we don’t have it yet for 12.xx is because Sony patched the A53 in those firmwares. So whatever “exploit” they have, it’s unfortunately required to run FPKG on anything over 12.xx. The 11.60 fix was just to update some things that 11.40 changed but the “hole” was still there.

Still, I want to hear it out of the mouth of one of these devs to either confirm I’m right or to prove me wrong.

Tired of all this grandstanding and drama and shit. Takes a few minutes to explain things. But they’re too busy fighting and trolling each other to do it.

To quote CM Punk “I’m old, I’m tired, and I work with fucking children”. I’d be laughing if it wasn’t so true.

I gave it a few days to see if they could muster up the answer, now I am.

So if you’re on 12.xx firmware, you’ll have to wait for the new 13.60 exploit before you get FPKG support.
I think you over estimate greatly how many people have researched a53, let alone fpkg research it’s not an easy nut to crack there’s only a handful of people I know, ark included who would be far enough to elaborate

None of which have accounts here either.

I dumped a53 but never looked into the piracy side of things. So the only 12.x deterrent I know of is that 1 hour p2jb thing everytime you reboot

And touching a53 you will reboot. A LOT. If you even breath wrong it will kernel panic. Which makes research a bitch so maybe it’s not patched but actually not researched. Ark Sama has said half truths before
 
Anyone using onionhen, do you always get the onionhen shortcut in the top right of the xmb like in modded warfares video?
I'm on 6.02 and it seems any payload that tries to put a shortcut up there, fails to do so.
 
  • Like
Reactions: schatzi24
Still, I want to hear it out of the mouth of one of these devs to either confirm I’m right or to prove me wrong.

Tired of all this grandstanding and drama and shit. Takes a few minutes to explain things. But they’re too busy fighting and trolling each other to do it.

To quote CM Punk “I’m old, I’m tired, and I work with fucking children”. I’d be laughing if it wasn’t so true.

I gave it a few days to see if they could muster up the answer, now I am.

So if you’re on 12.xx firmware, you’ll have to wait for the new 13.60 exploit before you get FPKG support.
I apologize in advance for being blunt.

No developer is obligated to prove anything to you, let alone go to the trouble of explaining things... In my opinion, they simply want to polish a few things before the official launch of version 12/13.xx.

In any case, I’ll reiterate that developers are under no obligation to release information or provide explanations. Sometimes explaining things is a real hassle

They aren't obliged to release anything, and what they do release doesn't have to come with an explanation; anyone who wants to use it can, and anyone who doesn't is free to go wherever they like. You aren't obliged to explain everything in your life to me either.
 
Still want one of these vibe coding devs to explain why we can’t get FPKG on 12.xx. A real dev would’ve explained it by now. But I guess since their Patreon donations aren’t where they’d like them to be, they won’t.

So allow me.

Apparently the reason why we don’t have it yet for 12.xx is because Sony patched the A53 in those firmwares. So whatever “exploit” they have, it’s unfortunately required to run FPKG on anything over 12.xx. The 11.60 fix was just to update some things that 11.40 changed but the “hole” was still there.

Still, I want to hear it out of the mouth of one of these devs to either confirm I’m right or to prove me wrong.

Tired of all this grandstanding and drama and shit. Takes a few minutes to explain things. But they’re too busy fighting and trolling each other to do it.

To quote CM Punk “I’m old, I’m tired, and I work with fucking children”. I’d be laughing if it wasn’t so true.

I gave it a few days to see if they could muster up the answer, now I am.

So if you’re on 12.xx firmware, you’ll have to wait for the new 13.60 exploit before you get FPKG support.

I think you should take your concerns to Oprah, then Judge Judy and finally International Court of Justice. Truth is out there....

Dude, I was on 5.xx waiting a year to get anything from the scene. And now I'm on 6.02 with no WebKit and still having to use porn simulator as a userland.

I wish I had your problems 😂
 
  • Like
Reactions: Axido
I apologize in advance for being blunt.

No developer is obligated to prove anything to you, let alone go to the trouble of explaining things... In my opinion, they simply want to polish a few things before the official launch of version 12/13.xx.

In any case, I’ll reiterate that developers are under no obligation to release information or provide explanations. Sometimes explaining things is a real hassle

They aren't obliged to release anything, and what they do release doesn't have to come with an explanation; anyone who wants to use it can, and anyone who doesn't is free to go wherever they like. You aren't obliged to explain everything in your life to me either.
Let's say the devs reply to this person in the same way, but even then, I don't think their answer would satisfy them. Imagine if they told them that it’s simply because they don’t want to, as Stoned said above, or because the a53 is a tricky component and there’s really only progress in 11.60 and 13.xx because until the jailbreak comes out, there isn’t much that can be done. But anyway, according to them, they’re hiding something from everyone on 12.xx and will leave them out.
 
  • Like
Reactions: TheStonedModder
I apologize in advance for being blunt.

No developer is obligated to prove anything to you, let alone go to the trouble of explaining things... In my opinion, they simply want to polish a few things before the official launch of version 12/13.xx.

In any case, I’ll reiterate that developers are under no obligation to release information or provide explanations. Sometimes explaining things is a real hassle

They aren't obliged to release anything, and what they do release doesn't have to come with an explanation; anyone who wants to use it can, and anyone who doesn't is free to go wherever they like. You aren't obliged to explain everything in your life to me either.
It’s only a “hassle” if they’re just telling Claude how to code and don’t truly understand how things work or what they’re doing. A real dev does and can explain. We see it in the MiSTer community all the time. Devs breaking down how things work and why. Hell, even with systems previous to this when we had actual devs in the scene and not a bunch of vibe coding bounty hunters, we always seen explanations and videos of how things worked and how they got there.

I know kissing ass is the norm here and you people want to normalize this kind of thing, but I’m not doing it.

You wonder WHY legit devs are leaving this scene? Because it’s full of toxic vibe coders who just type a few things into Claude and use their social media pages to gain clout and attention. I been in various scenes since the Dreamcast era and I’ve never seen a scene as toxic and inexcusable as this one.

Both these vibe coders and the people that worship them. I respect people who actually put in the work. I can tell a vibe coder apart from a legit programmer and congratulations.

You failed.
Post automatically merged:

But anyway, according to them, they’re hiding something from everyone on 12.xx and will leave them out.
That’s not what I said.

I explained why it’s not possible since none of these supposed “devs” can explain why it’s not possible yet. I gave them a chance to explain, they didn’t. So I did.

I knew the answer, I was waiting for them to explain it.
 
It’s only a “hassle” if they’re just telling Claude how to code and don’t truly understand how things work or what they’re doing. A real dev does and can explain. We see it in the MiSTer community all the time. Devs breaking down how things work and why. Hell, even with systems previous to this when we had actual devs in the scene and not a bunch of vibe coding bounty hunters, we always seen explanations and videos of how things worked and how they got there.

I know kissing ass is the norm here and you people want to normalize this kind of thing, but I’m not doing it.

You wonder WHY legit devs are leaving this scene? Because it’s full of toxic vibe coders who just type a few things into Claude and use their social media pages to gain clout and attention. I been in various scenes since the Dreamcast era and I’ve never seen a scene as toxic and inexcusable as this one.

Both these vibe coders and the people that worship them. I respect people who actually put in the work. I can tell a vibe coder apart from a legit programmer and congratulations.

You failed.
Whether it's with “Claude” or without assistance, any developer in the scene would tell you the same thing in response to your insistence and assumptions. No one here is sucking up to them, Sony, or AI. Whichever side you take, at the end of the day, you’re getting the jailbreak without making any personal contribution other than disconnecting the console from the internet, so, well, it’s up to you.
 
Whether it's with “Claude” or without assistance, any developer in the scene would tell you the same thing in response to your insistence and assumptions. No one here is sucking up to them, Sony, or AI. Whichever side you take, at the end of the day, you’re getting the jailbreak without making any personal contribution other than disconnecting the console from the internet, so, well, it’s up to you.
Keep telling yourself that, level 1. You ALMOST got to my point but had to white knight your way out of it…..
Post automatically merged:

And let me spell it out so maybe you can understand better:

I’m not arguing about being entitled to a free jailbreak. Instead, I’m arguing for transparency and basic respect for the craft of programming, which is completely flying over your heads.

You’re mad because I held up a mirror to the exact toxic, clout-chasing culture that has taken over the scene. I proved that y’all care more about sucking up to "vibe coders" than actually understanding the hardware they are trying to hack.

I jailbreak my shit for three reasons: to protect the digital stuff I buy and have more control over and to understand how things operate.

I’m not one of those “FREE WAREZ” motherfuckers.

I am however one that wants explanations for people that might NOT understand so we don’t get hundreds of “etaWEN” comments.
 
Last edited by littlemisskittn,
  • Like
Reactions: schatzi24

Site & Scene News