Hacking PS4 5.xx Rest mode Kernel exploit revealed

  • Thread starter Thread starter crossholo
  • Start date Start date
  • Views Views 68,949
  • Replies Replies 139
  • Likes Likes 20

Will you update your ps4?


  • Total voters
    286

crossholo

Well-Known Member
Newcomer
Joined
May 26, 2017
Messages
45
Reaction score
56
Trophies
0
Age
28
XP
985
Country
Italy
Exploit revealed by @vpikhur

He made a presentation at the Recon Brussels hacking conference showing the exploit and a demo video.
Apparently his exploit uses a vulnerability on sys_kldload.
He also relased the presentation slides later in the day here.

Quoted by wololo.net

According to the developer:
The custom Southbridge silicon, responsive for background downloads while main SoC is off, didn’t help to secure Playstation 4. We explain how a chain of exploits combined with hardware attacks will allow code to run in the context of the secure bootloader, extract private keys, and sign a custom kernel.

According to the hacker, the sys_kldload exploit still exists in firmware 5.00, potentially more recent firmwares as well.
The important point of the video above is that the hack persists after boot, demonstrating what is probably the very first custom firmware on the PS4
Sony changed their keys in 5.05, but apparently not the signing process.
The kernel bootloader contains the keys for Rest Mode kernel, which is why it was interesting to get access to it.
How the exploit works is shown in this video.



WHEN ETA??!?!?")=£)/

EDIT 1: Webkit Exploit released! here. It works up to 5.50 beta 3. (tried up to 5.05 myself)

Instructions with localhost
  1. Download install Node.js (LTS version): https://nodejs.org/en/

  2. In your start menu there should be a new program called "Node.js command prompt". Open that.

  3. The default directory will open to c:\Users\"YOUR_USER_NAME"\

  4. Download the zip from git hub and place it in your user directory mentioned in 3.

  5. Rename the folder something easy like "ps4" then run the command "cd ps4" without quotes

  6. Now run command "npm install" without quotes

  7. run command (without quotes): "npm start"

  8. Configure your ps4 DNS to point to the IP address of your computer

  9. Run a connection test to trigger a captive portal (I.E. like a screen you get when first logging into a coffee shop wifi or airport wifi. Basically any public wifi)

  10. FUCKIN PROFIT (I think)
If you do not want to bother doing all this, go to this page on your ps4 browser. Also try multiple times until it says Success.
 
Last edited by crossholo,
Now this is getting interesting
5a7a654f565e80291574c86894dddba8.jpg



Sent from my iPhone using Tapatalk
 
It probably won't be on the latest firmware still but more exclusives will be open for piracy since we don't have a spoofer yet.
 
This has been known for 2 years so who knows if it will ever get a release.
quoted by wololo:
it appears the hacker is leveraging (and revealing) a not publicly known kernel exploit on the PS4, leveraging a vulnerability in sys_kldload. There is probably enough in the presentation for people to take this information some step further.
 
I guess it's time to hunt down a cheap used Pro (and activate it for Remote Play later on) before 5.50 comes out.
 
Last edited by Axido,
As I said a while back, once ps5 is announced you'll hear of a hack on the latest firmware for ps4 too.

It actually makes a lot of sense on a lot of levels to do it this way as the game has changed so much since I last played it.
 
So do you think this exploit requieres some hardware 'soldering'? Or only through web access like what we have now.
 
noob question. what does it take for PS4 hacking to be like PS3 or something where once you jailbreaked your PS4, you can just wait a little while for the jailbreak on the latest update? are we close to that? or will it always be like Vita, where the jailbreak on new firmware may never come or long long wait?
 
Yes, this is nice. I think mine is on 5.03.

How to disable updates for PS4? I'd like to know right now because ofcourse the PS4 will connect to the internet as soon as it's turned on.
 

Site & Scene News

Popular threads in this forum