Tutorial  Updated

PS5 Exploit Guide

PS5 Hack Status:


FW Ranges:
2.XX = KEX+HV: PS4/5 backups, possible keys exploit (WK: 2.50 best / 2.7X max)
3.XX = KEX+HV+Linux: PS4/5 backups, possible keys exploit (WK/BD/LUA: 3.20 best / 3.21 max)
4.XX = KEX+HV+Linux: PS4/5 backups (WK/BD/LUA (Y2/NF/YARPE 4.03+): 4.50 best / 4.51 max)
5.XX = KEX+HV+Linux: PS4/5 backups (
WK/BD/Y2/NF/LUA/YARPE: 5.50 best + max)

6.XX = KEX: PS4/5 backups (KEX+HV+Linux: 6.02 max) (WK/BD/Y2/NF/LUA/YARPE: 6.02 for Linux / 6.50 max)
7.XX = KEX: PS4/5 backups (KEX+HV+Linux: 7.61) (
WK/BD/Y2/NF/LUA/YARPE: 7.61 best + max)
8.XX-10.00 = KEX: PS4/5 backups, no HV (WK/BD/Y2/NF/LUA/YARPE)
10.01-12.70 = KEX: PS4/5 backups, no HV (
WK/BD/Y2/NF/LUA/YARPE)
13.XX-13.60 = HV+KEX+WK (
WK/BD (13.42)/Y2/LUA/YARPE)
14.XX = No KEX/HV. UL ONLY (LUA/YARPE)

NOTE 1: Recommended firmware is subjective. Staying low is always recommended.
NOTE 2: Do not update too many major versions (e.g., 4.xx to 5.xx or 7.xx to 8.xx). Remain low unless all you want is backups.
NOTE 3: P2JB can take over an hour to exploit on FW up to 12.70.


Hypervisor (HV):
Highest released HV: 7.61
Highest unreleased HV: 14.10 (SlopVisor)
*unreleased/unimplemented


Kernel (KEX):
Highest released KEX:
13.60 (ReLapse)
Highest unreleased KEX: 13.60 (SlopSploit)
UMTX2:
1.00-7.61 (*WK to 5.50 / BDJB to 7.61)
Lapse: 1.00-10.01
Relapse: 7.00-13.60
Poopsploit:
4.03-12.00 (*BD to 12.00)
P2JB: 9.00-12.70 (*WK: Lapse to 10.01 / P2JB to 12.70)

Userland (UL):
Webkit: 1.00-5.50 (PSFREE +UMTX2) / 7.00-13.60 (RELAPSE) (Recommended)
LUA (Artemis): 2.00-LATEST (LUA exploit, + Lapse up to 10.01)
Y2JB: 4.03-13.40 (YouTube exploit, + Lapse: 10.01 / P2JB: 12.70)
NFNH: 4.03-12.XX (Netflix exploit, + Lapse: 10.01)
YARPE: 4.03-12.XX (Ren'Py exploit, + Lapse: 10.01 / P2JB: 12.70)
BD-JB: 1.00-13.42 (BD exploit + UMTX2: 7.61 / BD-JB5 + Poops to 12.00)
Mast1C0re: 1.00-7.61 (Depreciated for LuaC0re)
LuaC0re: 1.00-12.70 (Poops: 4.03-12.00/P2JB: 9.00-12.70)
REDIS: 1.00-5.50 (Jordy's untethered JB on boot)

NOTE 1: A userland entry point (UL) chained to kernel exploit (KEX) is required to exploit your console at bare minimum.
NOTE 2: Consoles 7.00-13.60 should now use WebKit and RELAPSE (Recommended)


Useful Applications:
FPKG: 3.00-11.60 (KStuff Lite) / 12.XX-13.60 (KStuff-NG SOON)
Kstuff Lite: 3.00-12.70
HERE
Kstuff Toggle: 3.00-12.00 HERE
PS5 App Dumper: 3.00-13.60 HERE
Dump Runner: 3.00-12.00 HERE
Dump Installer: 3.00-12.00 HERE
Backporting: Possible (backpork / Porkfolio)
PS4/PS5 DLC: Work with Kstuff Lite
Trophies: Work with Kstuff Lite
Compression: Works with Kstuff Lite
Homebrew Enabler: etaHEN (3.00-10.01) latest HERE
PS5 Backup manager: ItemzFlow Compatibility list: HERE
PS4 Backup Loading: Works (rest mode & backports work, can crash).
PS5 Debug NG: 3.XX-13.XX
HERE
PS5 Remote Play: Works HERE & HERE
PS5 Trainers/Cheats: Work

UART:
HERE
Linux: (OG: 3.00-7.61, Slim: 7.61) HERE
Kldload (wip): 3.00-6.50 HERE
PSN access: NEVER
Latest OFW: 14.10 (01/10/26)
Summarised OFW/Model guide: HERE
1.XX-7.61 compatibility list:
HERE
PS5 SDK Repo: HERE
Legit PKG Updates: HERE or HERE
OFW Updates: HERE (history HERE)

Preparing Your Console:


It is recommended to either self-host offline or block these addresses in your router to avoid accidental updates or getting an update nag. Using the DNS method is no longer failsafe, as these are not guaranteed to be running 24/7.


dau01.ps5.update.playstation.net
dbr01.ps5.update.playstation.net
dcn01.ps5.update.playstation.net
deu01.ps5.update.playstation.net
dhk01.ps5.update.playstation.net
djp01.ps5.update.playstation.net
dkr01.ps5.update.playstation.net
dmx01.ps5.update.playstation.net
dru01.ps5.update.playstation.net
dsa01.ps5.update.playstation.net
dtw01.ps5.update.playstation.net
duk01.ps5.update.playstation.net
dus01.ps5.update.playstation.net
fau01.ps5.update.playstation.net
fbr01.ps5.update.playstation.net
fcn01.ps5.update.playstation.net
feu01.ps5.update.playstation.net
fhk01.ps5.update.playstation.net
fjp01.ps5.update.playstation.net
fkr01.ps5.update.playstation.net
fmx01.ps5.update.playstation.net
fru01.ps5.update.playstation.net
fsa01.ps5.update.playstation.net
ftw01.ps5.update.playstation.net
fuk01.ps5.update.playstation.net
fus01.ps5.update.playstation.net
hau01.ps5.update.playstation.net
hbr01.ps5.update.playstation.net
hcn01.ps5.update.playstation.net
heu01.ps5.update.playstation.net
hhk01.ps5.update.playstation.net
hjp01.ps5.update.playstation.net
hkr01.ps5.update.playstation.net
hmx01.ps5.update.playstation.net
hru01.ps5.update.playstation.net
hsa01.ps5.update.playstation.net
htw01.ps5.update.playstation.net
huk01.ps5.update.playstation.net
hus01.ps5.update.playstation.net
sgst.prod.dl.playstation.net
gs2.ww.prod.dl.playstation.net

Alternative DNS IP:
62.210.38.117 - User Guide = ES7in1
or
45.56.67.85
(Leave DNS 2 blank)

To determine your OFW version:
Go to settings > system > console information.

Version string info:
Year.Half (1st/2nd half of the year)-Major Version No.Minor Version No.Extended info-Further Info.Retail/Debug

21.02-04.03.00.00-00.00.00.0.1

It is recommended to keep your console as low as possible to have access to better jailbreak stability and features. Stay as low as possible within the "Golden" firmware brackets that apply to your current firmware, see the top of this page.

(No jailbreak is ever guaranteed. No developer is obliged to release anything publicly)

WARNING:

Only update OFW manually via USB by getting the firmware file from HERE and installing from <USB>:/PS5/UPDATE/PS5UPDATE.PUP
(Updating with RECOVERY PUP will perform a factory format and will wipe your internal HDD)

PS5 factory mode PUP installation path:
/usb/PROSPERO/UPDATE/PROSPEROUPDATE.PUP

NOTE: Make a system back up before attempting any modifications.
On console: go to [Settings] > [System] > [System Software] > [Back Up and Restore] > [Back Up Your PS5]

Select Your Jailbreak:


WEBKIT:BD-JB:LUA:Y2JB:NFNH:YARPE:LuaC0re:BD-UN-JB:


  1. Information:
    Firmware 1.00-5.50 or 7.00-13.60 is required for the webkit exploit.

    Enabling web browser:
    Open [Settings] > select [Users & Accounts] > select [YouTube] > click "Link" > click "use browser" > click "terms" (bottom right) > click google apps icon (top right) > select Google Search.

    Exploiting 1.00-5.50:
    Enter https://zecoxao.github.io/luasauce/ or https://github.com/kmeps4/PSFree into google > click “Jailbreak" or wait for it to complete.

    Exploiting 7.00-13.60:

    https://ntfargo.github.io/Relapse-Exploit/

    https://zecoxao.github.io/bagagwa/

    https://soniciso1.github.io/poopicker/

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  2. Important:
    You will need a BD dive paired to your Slim/Pro console or an OG Phat model . Consoles must be on 1.00-13.42 to run this exploit.


    Recommended ISO: Viktorious AIO Auto BD-JB ISO for 4.XX-7.61

    Exploiting: 1, Burn ISO to a blank BD-R or BD-RE > Insert into console > click on the [DISC PLAYER] icon.

    2, Highlight [PIPELINE RUNNER] > click option 2 [Normaljailbreak-etaHEN-UMTX1.pipe] to auto load etaHEN ready for ItemzFlow.

    ELF Loader uses PS5 IP: port 9021 / BIN loader uses 9020 / Jar loader uses port 9025

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  3. Important:
    LUA entry point works from 2.00 to the latest OFW, but there is no KEX above 12.70 yet.
    (A compatible PS4 game is required to launch the exploit on PS5. See below)

    Your PS5 console must be activated to use save copying for PS4 games.
    1. Insert your game disc and, as soon as possible, make a save file within it.
    2. Copy the save files to USB, go to [SETTINGS] > [STORAGE] > [CONSOLE STORAGE] > [SAVE DATA] > [PS4 GAMES] > select the game save and copy to a USB drive.
    3. On PC, using a Google Drive account, make a new folder with the GAME ID of your game, and upload the savedata & savedata.bin files to that folder.
    4. Share the folder, set it to editor mode, share with anyone, and click "copy the link".
    5. Join the HTOS Discord group: HERE type "/decrypt", select "FALSE" for including SCE_SYS, paste or type in the Google Drive link, and press enter. The bot should begin mounting your save. (If it doesn't, paste in the link again.)
    6. Click "ENCRYPTED" to remove the Sony PFS layer. Download the generated files and extract the folder to your desktop (you should have 4 files in there and be named dec_savedata_CUSA[GAME ID]).
    7. Using REMOTE LUA LOADER, open the savedata folder, copy the 20 files within into your encrypted save folder on your desktop.
    8. Upload the encrypted save folder (now with 24 files in) to your Google Drive. It should be named "dec_savedata_CUSA[GAME ID]" where GAME ID is your games 5 digit number, and set it to editor mode, share with anyone, and then click "copy the link".
    9. Go back to the HTOS discord server, and type "/encrypt", hit "FALSE" for uploading individually, and "FALSE" to include SCE_SYS. Finally, hit shared_gd_link and paste in your link to the original save (4 files) folder. (If it doesn't, paste in the link again.)
    10. When this is done, paste the link to the decrypted save (24 files) folder, and the bot will encrypt the files.
    11. Resign the files by typing "/resign" followed by your account name on the console, or PSN ID associated with that account if using the latest OFW.
    12. Download the resigned files, extract the files to your USB drive and overwrite them into the savedata folder on your USB or external drive.
    13. Copy the saves back to your console [SETTINGS] > [SAVE DATA AND GAME/APP SETTINGS] > [SAVE DATA PS4] > [COPY OR DELETE FROM USB] > [COPY TO CONSOLE STORAGE] > select your game save folder from the USB drive and copy/overwrite old save data.
    14. Load LUA game again, and you should see the LUA LOADER screen.
    15. You can use "SEND_LUA.PY" to send the UMTX files to the loader.
    (NOTE: Some games require manual loading of save game)

    On firmware up to 7.61, you can now load UMTX/2 followed by etaHEN by sending the files to your console IP on PORT 9026.
    On firmware 8.00-LATEST, you can connect with the REMOTE LUA LOADER APP to send debug notifications or FTP on port 1337.

    LUA Loader: HERE or HERE

    Auto LUA Loader Fork: HERE

    Compatible LUA games:
    Aerial Life (CUSA17122)
    Aibeya (CUSA17068)
    Aikagi 2 (CUSA19556)
    Aikagi Kimi to Issho ni Pack (CUSA16229)
    Aikano Yukizora no Triangle (CUSA19370)
    Boku to Nurse no Kenshuu Nisshi (CUSA12049)
    Boku to Joi no Shinsatsu Nisshi (CUSA18107)
    Fuyu Kiss (CUSA29745)
    Hamidashi Creative (CUSA27389)
    Hamidashi Creative Demo (CUSA27390 requires the latest OFW to download from PSN)
    Haruoto Alice (CUSA14324)
    IxSHE Tell (CUSA17112)
    IxSHE Tell Demo (CUSA17126)
    Jinki Resurrection (CUSA25179)
    Jinki Resurrection Demo (CUSA25180 requires the latest OFW to download from PSN)
    Maid-san no Iru Kurashi (CUSA18106)
    Nora Princess and Stray Cat Heart HD (CUSA13303: Rename save9999.dat into nora_01.dat)
    Nora Princess and Strat Cat Heart 2 (CUSA13586)
    Raspberry Cube (CUSA16074)
    Winter Guest (CUSA11977)

    WARNING: using demos is free but can become corrupt, and you cannot upgrade your internal HDD either. If you lose the demo you can no longer use the exploit. Disc recommended.

    Incompatible LUA games:

    Dokyusei Remake Csver (CUSA47117)
    Dōkyūsei: Bangin' Summer - Home Edition Demo (CUSA47132)
    Kiss Trilogy (CUSA19341)
    Love Clear Demo (CUSA18109)
    Mikagami Sumika no Seifuku Katsudou (CUSA11481)
    Sen no Hatou, Arazone no Hime (CUSA09647)
    Tonari ni Kanojo no Iru Shiawase: Two Farce (CUSA09825)
    Tonari ni Kanojo no Iru Shiawase Summer Surprise (CUSA18998)

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  4. Requirements:
    PS5 console must be on 4.30-12.70 and previously activated through PSN or fake activated to use the YouTube app, unless you're restoring a backup.
    (Note: restoring a backup will factory reset your console).

    Information:
    If updating and older installation, download the latest download0.dat > use FTP or PS5 Explorer to place it in the user/download/PPSA01650 folder.

    Preparation:
    Download the Y2JB_backup_X.X(4.03) if you're on 4.03-12.40, or the Y2JB_backup_X.X(12.20) if you're on 12.60 or higher from HERE
    On PC: format a USB 3.0 HDD to exFAT, and copy the PS5 folder from the backup to the root, and put the latest nanodnf.efl from nanoDNS to the root too.
    On console: go to [Settings] > [System] > [System Software] > [Back up and Restore] > [Restore] > select the y2JB back up & let it install (the console will reboot when complete).
    (Note: The exploit will now be accessible under the [MEDIA] tab)

    Exploiting:
    Going to [Settings] > [Network] > [Settings] > [Set up Internet Connection] > [Set up Manually] > set up a wireless or LAN connection > change [DNS Settings] to manual > change [Primary DNS] to 127.0.0.1 > click [Done] > open the [YouTube App].
    (Note: Ignore and internet connection issue warnings)

    Firmware up to 10.01 will use Lapse Kernel Exploit. Firmware 10.20-12.70 and above will use P2JB and could take up to an hour.

    You can send payloads using netcat GUI to PS5's IP Address & port 9021.

    You can swap the download0.dat to itzPLK version for auto loading and payload manager in future (payload manager accessible through browser on 127.0.0.1:8084)

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  5. Requirements:
    PS5 console must be on 4.30-10.01 and previously activated through PSN or fake activated. You will need a 256GB external HDD (minimum).

    Preparation:
    Download balenaEtcher
    Download the latest Extended Storage or M.2 Image (select your m.2's capacity)

    EXTERNAL DRIVE METHOD (Netflix_PS5_EU_Ext.7z):
    1a, On PC: connect your 256GB (min) USB drive to your Windows/Mac/Linux PC > extract the image to your computer > open Etcher > click [Flash From File] & select the extracted image *.zip > click [Select Target] & choose the external drive > Click [Flash!] & allow it to complete.
    (Note: 256GB is the smallest drive you can use)

    2a, On console: click [Settings] > [Storage] > [USB Extended Storage] > [Games and Apps] > press X on [Netflix] > select [NETFLIX] under items to move > select [Move] > move to internal storage & allow it to complete.
    (Note: The exploit will now be accessible under the [MEDIA] tab)

    INTERNAL DRIVE METHOD (Netflix.XXXXGB.7z):
    1b, On PC: connect the M.2 to your Windows/Mac/Linux PC > extract the image to your computer > open Etcher > click [Flash From File] & select the extracted image *.zip > click [Select Target] & choose the external drive > Click [Flash!] & allow it to complete.
    (Note: 4TB will take 80 mins, 2TB 45 mins, 256GB 10 mins)

    2b, On console: Power off the console > insert the M.2 SSD > power on the console > click [Settings] > [Storage] > press X on [Netflix] > select [NETFLIX] under items to move > select [Move] > move to internal storage & allow it to complete.
    (Note: The exploit will now be accessible under the [MEDIA] tab).

    Exploiting:
    1a, for consoles 10.01 and below, on console: go to [Settings] > [Network] > [Settings] > [Set up Internet Connection] > [Set up Manually] > set up a wireless or LAN connection. Go to Proxy > change [Automatic] to [Manual] > enter Address: 172.105.156.37 & port: 42069 > click [Done] > open the [Netflix App].
    (Note: Ignore and internet connection issue warnings)

    1b, for consoles 10.20-12.70, COMING SOON.

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  6. Important:
    YARPE works from 4.30 to 12.70 (9.00 - 12.07 via P2JB)
    (A compatible PS4 game is required to launch the exploit on PS5. See below)

    Requirements:
    PS5 console must be on 4.30-10.01 to use this exploit.

    Exploiting:
    coming soon

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  7. Requirements:
    PS5 console must be on 4.30-12.70 to use this exploit. SWRR

    Exploiting:
    coming soon

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].


  8. [UPDATED]
    No longer needed if using latest WebKit (to 13.60) or BD-JB (to 13.42)!


    Important:

    This method modifies the BD-J stack to allows BD-JB entry point to be re-enabled on consoles up to 13.60, for convenience only.

    Very Important:
    This method requires your console to be jailbroken by another method first to gain access to alter the files.

    https://github.com/Gezine/BD-UN-JB

    Preparation:
    Burn the ISO to a blank Blu Ray, insert it into the jailbroken console. Send the bdj_unpatch.elf to elfldr using netcat GUI to PS5's IP Address & port 9021 to unpatch BD-J.

    (NOTE: DO NOT REINSTALL/UPDATE FW, IT WILL WIPE THE PATCH AND LOSE BD-JB)


Once jailbroken it is recommended to run KSTUFF LITE and SHADOWMOUNTPLUS at minimum to get you up and running.
(ShadowMountPlus: is an automated background auto-mounter payload for jailbroken PS5 consoles. Detects, mounts, and installs game dumps from internal or external storage, with support for UFS, exFAT, PFS, and nested compressed PFS containers)

Additional Information:


Blocking Updated with nanoDNS:
Set primary DNS manually to 127.0.0.1. Send latest elf to BIN LOADER using netcat GUI to PS5's IP Address & port 9021.

PS4 GAME INFORMATION:
OFW 1.xx cannot run PS4 games.
OFW 2.xx runs PS4 games up to 8.03

OFW 3.xx runs PS4 games up to 8.52
OFW 4.xx runs PS4 games up to 9.04
OFW 5.xx runs PS4 games up to 9.60
OFW 6.xx runs PS4 games up to 10.50

OFW 7.xx runs PS4 games up to 11.00
OFW 8.xx/9.xx runs PS4 games up to 11.50
OFW 10.xx runs PS4 games up to 12.00

OFW 11.xx runs PS4 games up to 12.50
OFW 12.xx runs PS4 games up to 13.00
OFW 13.xx runs PS4 games up to 13.52
OFW 14.xx runs PS4 games up to 14.00


(Note: PS4 backported FPKGs also work perfectly on an exploited PS5 with Kstuff)


You can install free/demo PKGS (legit pkgs) via the debug pkg installer, provided you have all the files/json/licences required.
(Astro’s Playroom has no licences and can be installed and played from official pkgs and updated inline with your firmware)

Warnings:


1: Never enable IDU mode.
If you do, you will need to enter staff mode by holding L1 + L2 and tapping this combo: circle, cross, square, triangle, right D-Pad. Release L1 + L2, and you can access settings to exit IDU.

2: Try to stay on the lowest FW possible and wait for hacks on that firmware.

3: Installing legit game PKGs you do not own will never work, even if spoofed.

4: If you get stuck in a boot loop at the PS logo, the SNVS is corrupted (if the hash check fails on boot, this causes a “soft brick”). It’s not “bricked”. Simply reinstall your current firmware RECOVERY PUP in safe mode from USB: PS5 > UPDATE > PS5UPDATE.PUP.

Archived Information


 
Last edited by KiiWii,
Karo set up a host for Relapse, guarantees more reliable launch, without it freezing halfway through or causing the browser to crash, and without black screens or crashes when loading ELF.


how do you run it tho? Where to begin with all that stuff - i've only tried webkit autoloader which is automated. yet i have no clue where to start with all the different methods like 'hosting your own' and 'sending payloads'
 
After further testing the new jailbreak here are my findings.

1.13.60 fat digital ps5 crashes are so unpredictable.
2.kstuff NG loads but games don't start up
3.Autoloader hangs on kernel base messege
4.When hangs occur the console should be shutdown completely for the jailbreak to load on the next run.
5.Always shutdown never restart to load jailbreak.
6.Payload manager autoload always crashes when loading kstuff. (loading kstuff light manually with each jailbreak is more stable)
 
I usually try to keep the payloads to a minimum but I want to understand what other people are doing.
What is etaHEN for?
Yes keep payloads to a mininum = less stress on the system in general.

Not going to write an essay about what etaHEN is and does. to be short: It's an AIO Homebrew enabler.
I need it for testing purposes. You can read more here: https://github.com/etaHEN/etaHEN
Post automatically merged:

I think you gave us/me bad versions for Y2JB youtube apps... some other sources say .253 for anything 13.40+...
Please, use the 1.009.253 ones for 13.60 also... or wait a bit till we have more info... 13.60 files fail in my 13.60
EDIT: yes, tested 1.009.253 on my fw 13.60 and it works.

Wait, wait, dont't be hasty. I only provide the g00d stuff

1790930560885.png

Post automatically merged:

Hahaha, Kstuff NG? 👀👀👀
Yes that's for testing purposes ATM.
I have some other payloads that i'm testing on another console. Makes no sense to show it and share it. I only share the "public" payloads. Would not make sense otherwise since not everybody can use them anyway.
Post automatically merged:

what is the best ps5 pkg builder right now?
People have different feelings / opinions / love & hate relations ships with some tools, but you can check these:

https://github.com/Phoenixx1202/PS5-FPKG-Builder
https://github.com/zerodaysofficial/ps5-exfat-pkg-builder-v1/releases/tag/v1.4.5
https://github.com/rdmrocha/fpkg-cli
Post automatically merged:

https://github.com/itsPLK/ps5-y2jb-autoloader/releases/tag/v1.0.0-dev-a05c279
https://github.com/edisnord/relapse-y2jb

Huge thanks to edisnord for his work on porting Relapse to Y2JB and najdek for maintaining and expanding the autoloaders.
I've managed to run it 15 times in a row on 11.60 and so far it works like a charm.
Nice. I have 0 need for it. But I'm going to test this in the upcoming dayz.
 
Last edited by HS2005,
FYI; I changed my autoload sequence a bit. Since when loading etaHEN the possibility to send .elf files is not possible. Here's my updated autoloader on FW 13.60:

View attachment 593524

These payloads load after clicking on the Webkit Autoloader v0.5.2.
etaHEN needed a bit more time so I have set this to 12 seconds. After etaHEN is loaded I load the elfldr-ps5-1360.elf file to enable sending .elf files again. Which works like a charm after everything is loaded.

Why not just load etahen first as it has it's own kstuff running? You can also change which version it runs. Wouldn't that save having to add Kstuff to the list?

Perhaps you do it for testing purposes but what about average user?
 
  • Like
Reactions: bn2soldier
Interesting project:

PS5 Vulkan Template​

Everything needed to build a PlayStation 5 homebrew powered by Vulkan, in one repository. Titles made from it render through RADV, Mesa's Vulkan driver, which my PS5_Mesa fork builds for the console with a PS5 winsys. RADV is linked into each title by PS5_Vulkan, on the platform layer of my payload SDK fork. On the console it reports Vulkan 1.4 and presents at 3840x2160, at 119.88 Hz when the TV allows it.

A one-stop repo for making your own PS5 homebrew powered by Vulkan 1.4. Point your AI agent at it and it has everything it needs to build a title with you:

  • Docs: setup, build, deploy and testing on the console
  • Agent skills: the stack, the console's rules, porting, releases
  • 16 samples proven on PS5: glTF models, PBR, shadows, deferred lighting, bloom, MSAA, compute, mesh shaders, ray queries… all at 4K / 120 fps
  • A generator: one command makes a new homebrew, ready to build and run
  • A test suite: runs your homebrew on the console and checks its picture against a PC reference
What you need: a Linux PC and a jailbroken PS5 with a homebrew setup (etaHEN, ftpsrv, klogsrv). ps5/tools/bootstrap.sh sets up the rest.

Link: https://github.com/mihawk-99/PS5_VulkanTemplate
Post automatically merged:

Why not just load etahen first as it has it's own stuff running? You can also change which version it runs. Wouldn't that save having to add Kstuff to the list?

Perhaps you do it for testing purposes but what about average user?
To be short: it conflicts. System crashing, some binaries and ofssets (on the background) not loading etc.
I do this for testing purposes (fpkg-related), but users can use the kstuff 1.11 lite version or Drakmor's version. So kstuff-1.13-fpkg-dr-test5.elf I also targeted etaHEN to use the Ng kstuff in my case via config.

For 95% of the users this is enough to load:

1790933368013.png


Next to using a cheat engine like Cheatrunner. https://github.com/notmaj0r/CheatRunner/releases/tag/v0.17.2 or other variant.

Post automatically merged:

Another video from Modded:.
Setup the New PS5 Relapse Jailbreak which can now be fully installed on the console itself and work offline with the autoloader!

 
Last edited by HS2005,
Yes keep payloads to a mininum = less stress on the system in general.

Not going to write an essay about what etaHEN is and does. to be short: It's an AIO Homebrew enabler.
I need it for testing purposes. You can read more here: https://github.com/etaHEN/etaHEN
Post automatically merged:



Wait, wait, dont't be hasty. I only provide the g00d stuff

View attachment 593575
Post automatically merged:


Yes that's for testing purposes ATM.
I have some other payloads that i'm testing on another console. Makes no sense to show it and share it. I only share the "public" payloads. Would not make sense otherwise since not everybody can use them anyway.
Post automatically merged:


People have different feelings / opinions / love & hate relations ships with some tools, but you can check these:

https://github.com/Phoenixx1202/PS5-FPKG-Builder
https://github.com/zerodaysofficial/ps5-exfat-pkg-builder-v1/releases/tag/v1.4.5
https://github.com/rdmrocha/fpkg-cli
Post automatically merged:
l

Nice. I have 0 need for it. But I'm going to test this in the upcoming dayz.
haha, yes, forgive my language, that sounds a bit overdramatic on my side ;( I apologize.
 
Seems like 14.10 is starting to be rolled out. But some good news from Jordy.


It's good and bad news. So long as HV remains unpatched in latest fw (ref Ark Sama), the longer it will take to see Fpkg working on 12.xx and 13.xx systems. I hope HV doesn't get patched for a long time. Benefits out way some of the short term limitations...
 
It's good and bad news. So long as HV remains unpatched in latest fw (ref Ark Sama), the longer it will take to see Fpkg working on 12.xx and 13.xx systems. I hope HV doesn't get patched for a long time. Benefits out way some of the short term limitations...
The benefits of it remaining unpatched for longer outweigh the downsides imo. Granted, I waited from release until now to actually do anything with my PS5 so I just have the mindset of "already waited this long, can wait a little longer".
 
Big update of ProsperoEden.

ProsperoEden is an unofficial PlayStation 5 port of Eden - an accurate, high-performance emulator. All credit for the emulator core belongs to the Eden project and its contributors. ProsperoEden is not affiliated with or endorsed by the Eden team or Sony.

This is an early alpha. Video, audio, controller input, and saves have been confirmed working. Compatibility and performance will vary between games.

ProsperoEden v1.000.040​

  • The launcher in your language. It follows the language the PS5 is set to, in 29 languages. Arabic, Chinese, Greek, Japanese, Korean and Thai are drawn with the console's own fonts. Text that runs longer in another language makes its own room instead of being cut.
  • Accessibility. Settings > Accessibility adds Larger text, High contrast and Reduce motion. Warnings carry a mark as well as a colour.
  • Save data in and out. Import a game's save from a folder or from a Ryujinx data folder, and export a copy. See "Moving save data" in the README inside the ZIP.
  • A ten-second slowdown with the AMD FSR filter is fixed. In a large open-world game, gameplay could start at 3-9 FPS for about ten seconds, and frames of about a tenth of a second kept coming afterwards. The texture cache was throwing away images the GPU had drawn, with a wait for the GPU each time, as soon as memory use passed a mark that the FSR filter's own images pushed it over. It now keeps them until graphics memory is really short.
  • Smoother heavy scenes. The renderer hands its work to the Vulkan worker in larger batches, and the emulated cores wait less on the GPU caches' locks. In the heaviest area of a test walk this removed drops to 26-28 FPS and cut the GPU thread's work by about a quarter.
  • Touchpad as Select in games. A tap of the touchpad presses the game's Select (Minus) button, and a longer press holds it. The Select + L1 and Select + R1 shortcuts never reach the game as a press.
  • A crash a few seconds into some games is fixed. The motion sensors' updates could reach a part of the controller service that was not set up yet.
  • Games' own system screens. A game's error dialog, profile picker and similar screens use Eden's built-in versions, and its error dialog now answers the game instead of leaving it waiting. The firmware's versions could end a session with an out-of-memory error.
  • More graphics memory. The PS5 gives an app one pool of memory that the CPU and the GPU share, and ProsperoEden held about 3 GiB of it without using it: its heap took 3 GiB at start and the emulated console's page table 1 GiB. Both now take memory as they need it, which gives graphics about 2.6 GiB more in the largest game tested. That game ran out of graphics memory while loading at 2x; it now runs at 2x with the AMD FSR filter at a steady 30 FPS, with about 2 GiB to spare. The texture cache also measures its memory use from what is really left of the pool, instead of a driver figure that counted every allocation twice.
  • A clearer message when a game runs out of graphics memory. If a game still needs more than there is at a high resolution, give it its own lower one: Triangle on it in the Library, then Resolution.
  • Games that accept only single Joy-Cons now get one, and L1 and R1 are its SL and SR buttons, which those games ask for on their controller screen.
  • Mods. A game's patches, replacement files and cheats load from mods/<title ID>/ next to roms/, and the game's settings list them with a switch each. .ips and text .pchtxt patches, which the emulator core could not apply, now work. The Library has one switch per game for all of its mods. See "Mods" in the README inside the ZIP.
  • 120 Hz output. Refresh rate in Settings > Video, and in each game's settings, asks the display for 120 Hz while a game runs. A display that cannot show it stays at 60 Hz, and the menu always runs at 60 Hz. After a game at 120 Hz the menu takes about five seconds to come back while the display changes rate.
  • Output resolution. Settings > Video has a new Output resolution row: 1080p (as before), 1440p or 2160p. It is the size of the picture ProsperoEden puts out, for the menu and for games. Until now a game's picture was made at 1080p and enlarged, whatever its internal resolution; at 2160p the upscaling filter scales the game straight to a 4K picture. A larger picture needs more graphics memory.
  • 3x and 4x resolution. The internal resolution now goes up to 4x. These need far more graphics memory than 2x; a game that runs out says so, and can be given its own lower resolution.
  • Patches for more frames than the display shows. A game patched to run faster than the output refreshes keeps its pace: the frames the display has no refresh for are left out.
  • Crash reports. If ProsperoEden stops because of an error, it writes crash-<date>-<time>.txt to /data/prosperoeden/logs, starts again and says on the home screen where the report is. That session's logs are kept beside it, and the five newest reports stay. A report holds what failed, where in the app's code, and what was running; it never holds the contents of memory.
  • The launcher and the OpenGL renderer use the PS5 OpenGL 4.6 SDK 1.0.0.
  • The graphics driver's shader cache moved to /data/prosperoeden/cache, so a read-only package install keeps it.
  • Experimental: block list. With an empty file named block-list.txt in /data/homebrew/PPSA99008, ProsperoEden saves which code a 64-bit game compiled and compiles it again on a spare CPU when the game next starts. In a repeat session of a large open-world game, the emulated cores then compiled 426 blocks during play instead of 138,262, and gameplay started at 30 FPS instead of 22. It is off by default until more games have run with it.
Link: https://github.com/blackbearreloaded/ProsperoEden/releases/tag/v1.000.040
Post automatically merged:

1790938512045.png


Update 26.06-14.10.00 came out yesterday. This update did not patch the HV.
 
Last edited by HS2005,
CheatRunner v0.17.2


@notmaj0r
notmaj0r released this 11 hours ago
v0.17.2
59dcb9e
CheatRunner v0.17.2

See the full changelog here: Changelog

v0.17.2​

  • Fixed: writes on FW 13.60.

Check GUIDE to setup CheatRunner.zip on Homebrew Launcher.

⚠️ Before updating to a new CheatRunner version, please follow these steps: Updating CheatRunner

Special Thanks:

💖 Supporters - those who supported the project through Ko-Fi or Buy Me a Coffee.
• primo • lal3x • jawad • anonymous • Maffioh • X-F1REBALL-X • Br0ken4life

💚 Testers - those who tested early builds of CheatRunner before release.

source: https://github.com/notmaj0r/CheatRunner/releases/tag/v0.17.2
https://fxtwitter.com/callmemaj0r/status/2105835008413843563?s=20
 
Seems like 14.10 is starting to be rolled out. But some good news from Jordy.

So why all the drama if that's the case? Doesn't that mean it wasn't patched on 14.00 either even though the whole thing was about burning the last remaining exploit, meaning no more dumps or anything past 13.60?

I know it's not as simple as the bug existing=exploit, but still, if games like lua work, and there's a hv bug, then it's not "unhackable" after 13.60 right?
 
  • Like
Reactions: AndrewM96 and Inaki
Since you need to install disc based games, is it possible to bypass the disc license check so you can play without the disc?

When you start a game without the disc or still with another game disc inside, it will say the data is corrupted. (if no jailbreak is loaded, it will literally say insert the disc.)

Would be cool to bypass disc license check.
Post automatically merged:

Is not compiled or im mistake?
Post automatically merged:




If i i try to install on an m2 that contains exfat games,it will erase them before installing?
Does it support retro achievements or am I not looking in the right place? Can't find it.
 
Last edited by thekarter104,
Since you need to install disc based games, is it possible to bypass the disc license check so you can play without the disc?

When you start a game without the disc or still with another game disc inside, it will say the data is corrupted. (if no jailbreak is loaded, it will literally say insert the disc.)

Would be cool to bypass disc license check.
I tried this a bunch of times on ps4, there's some sort of additional check I think. Probably that it needs to read the wobble from the disc directly.

On ps4 I would pull the license file and pkg from the disc, install them both, but still nothing.

To be clear I never tried on ps5, like you said with jb I got that same error with legit games that required higher fw version. Whereas on base fw it told me to install the update file. So there's something else going on with the jailbreak that bypasses those checks at least.

I still would suspect it won't work though, given that it never need on ps4. I also think it treats the game as digital once installed, even though it's a disc pkg file which is a different CUSA/PPSA from the digital version.

Maybe if someone can fake mount the disc partition, almost like a ps5 equivalent to iso loading, from an external or m.2 drive. That might work, but if it's intentionally looking for the wobble regardless then probably not, since the consoles knows if a pkg is the digital version, or the disc version.
 
It's good and bad news. So long as HV remains unpatched in latest fw (ref Ark Sama), the longer it will take to see Fpkg working on 12.xx and 13.xx systems. I hope HV doesn't get patched for a long time. Benefits out way some of the short term limitations...

Isn't FPKG related to the A53 exploit and not the HV exploit? If so, the question is if the A53 expoit is patched in 14.10.
 
  • Like
Reactions: peteruk
Hi! I'm new to this, and I'm running into a couple of issues.

The first one, and the one that worries me the most, is cooling/temperature. I'm using the WebKit autoloader, and then I just autorun kstuff and ShadowMountPlus. Backups run fine from an external NVMe SSD, but I noticed that the back of my PS5 gets quite hot after playing. I only played for about 30–40 minutes to test it, but it felt pretty hot. The SSD was also hot, although I assume that's normal.

Is this normal for the PS5 when using a jailbreak, or could I have done something wrong? I don't want to risk overheating the console.
Jailbreaking does not change the console's thermal management policies. Sony runs the PS5 hot for efficiency reasons (the hotter the temperature differential, the more heat you can move with a given volume of air). This allows them to keep the fan running at a lower speed, and thus less noise.

Now there are utilities that can change the fan policy, and Shadowmountplus is one of them. But it is not enabled by default.

The second issue is with ShadowMountPlus. I edited the config.ini file and removed the # from kstuff_game_auto_toggle=1 so that the option is enabled. However, I don't get the "kstuff paused" notification when launching a game, even with silent mode disabled.

I've been searching around, but most of what I've found are older posts and payloads. I also tried asking on X, but didn't get any replies.
kstuff toggling is an outdated feature. The modern kstuff does not have the performance penalty that earlier versions carried.
 
  • Like
Reactions: schatzi24

Site & Scene News

New Hot Discussed User Submitted