Hacking PS4 5.xx Rest mode Kernel exploit revealed

Will you update your ps4?


  • Total voters
    286

crossholo

Well-Known Member
OP
Newcomer
Joined
May 26, 2017
Messages
45
Trophies
0
Age
26
XP
963
Country
Italy
Exploit revealed by @vpikhur

He made a presentation at the Recon Brussels hacking conference showing the exploit and a demo video.
Apparently his exploit uses a vulnerability on sys_kldload.
He also relased the presentation slides later in the day here.

Quoted by wololo.net

According to the developer:
The custom Southbridge silicon, responsive for background downloads while main SoC is off, didn’t help to secure Playstation 4. We explain how a chain of exploits combined with hardware attacks will allow code to run in the context of the secure bootloader, extract private keys, and sign a custom kernel.

According to the hacker, the sys_kldload exploit still exists in firmware 5.00, potentially more recent firmwares as well.
The important point of the video above is that the hack persists after boot, demonstrating what is probably the very first custom firmware on the PS4
Sony changed their keys in 5.05, but apparently not the signing process.
The kernel bootloader contains the keys for Rest Mode kernel, which is why it was interesting to get access to it.
How the exploit works is shown in this video.



WHEN ETA??!?!?")=£)/

EDIT 1: Webkit Exploit released! here. It works up to 5.50 beta 3. (tried up to 5.05 myself)

Instructions with localhost
  1. Download install Node.js (LTS version): https://nodejs.org/en/

  2. In your start menu there should be a new program called "Node.js command prompt". Open that.

  3. The default directory will open to c:\Users\"YOUR_USER_NAME"\

  4. Download the zip from git hub and place it in your user directory mentioned in 3.

  5. Rename the folder something easy like "ps4" then run the command "cd ps4" without quotes

  6. Now run command "npm install" without quotes

  7. run command (without quotes): "npm start"

  8. Configure your ps4 DNS to point to the IP address of your computer

  9. Run a connection test to trigger a captive portal (I.E. like a screen you get when first logging into a coffee shop wifi or airport wifi. Basically any public wifi)

  10. FUCKIN PROFIT (I think)
If you do not want to bother doing all this, go to this page on your ps4 browser. Also try multiple times until it says Success.
 
Last edited by crossholo,

ManuelKoegler

Well-Known Member
Member
Joined
Nov 5, 2015
Messages
397
Trophies
0
Age
29
XP
685
Country
Netherlands
Now this is getting interesting
5a7a654f565e80291574c86894dddba8.jpg



Sent from my iPhone using Tapatalk
 
D

Deleted User

Guest
It probably won't be on the latest firmware still but more exclusives will be open for piracy since we don't have a spoofer yet.
 

crossholo

Well-Known Member
OP
Newcomer
Joined
May 26, 2017
Messages
45
Trophies
0
Age
26
XP
963
Country
Italy
This has been known for 2 years so who knows if it will ever get a release.
quoted by wololo:
it appears the hacker is leveraging (and revealing) a not publicly known kernel exploit on the PS4, leveraging a vulnerability in sys_kldload. There is probably enough in the presentation for people to take this information some step further.
 

Axido

Maker of TRASLApp
Member
Joined
Feb 12, 2014
Messages
1,304
Trophies
2
Age
32
XP
4,314
Country
Germany
I guess it's time to hunt down a cheap used Pro (and activate it for Remote Play later on) before 5.50 comes out.
 
Last edited by Axido,

Deleted member 42501

Well-Known Member
Member
Joined
Jun 16, 2006
Messages
1,724
Trophies
2
XP
4,259
As I said a while back, once ps5 is announced you'll hear of a hack on the latest firmware for ps4 too.

It actually makes a lot of sense on a lot of levels to do it this way as the game has changed so much since I last played it.
 

depaul

Well-Known Member
Member
Joined
May 21, 2014
Messages
1,294
Trophies
0
XP
2,973
Country
France
So do you think this exploit requieres some hardware 'soldering'? Or only through web access like what we have now.
 

askara

Well-Known Member
Member
Joined
Feb 12, 2013
Messages
238
Trophies
1
XP
935
Country
noob question. what does it take for PS4 hacking to be like PS3 or something where once you jailbreaked your PS4, you can just wait a little while for the jailbreak on the latest update? are we close to that? or will it always be like Vita, where the jailbreak on new firmware may never come or long long wait?
 

thekarter104

Well-Known Member
Member
Joined
Mar 28, 2013
Messages
1,987
Trophies
1
XP
3,019
Country
United States
Yes, this is nice. I think mine is on 5.03.

How to disable updates for PS4? I'd like to know right now because ofcourse the PS4 will connect to the internet as soon as it's turned on.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • K3Nv2 @ K3Nv2:
    I'll reformat and have a 3tb raid0 m. 2 at least
    +1
  • K3Nv2 @ K3Nv2:
    Lmao that sold out fast
    +1
  • Veho @ Veho:
    Yeet the cat.
    +1
  • K3Nv2 @ K3Nv2:
    Good idea
    +1
  • The Real Jdbye @ The Real Jdbye:
    i thought everybody knew cocktails are like 75% ice
  • Veho @ Veho:
    Yeah but not like this.
  • Veho @ Veho:
    It's not like they're complaining that their Slurpee is 99% ice or something, but if the cocktail calls for "shot of vodka, shot of vermouth, shot of gin, shot of Campari, three shots of juice, squirt of lemon" and ends up being a thimbleful of booze, that's a problem.
  • The Real Jdbye @ The Real Jdbye:
    the funny thing is cocktails in norway are only allowed to have 1 20ml shot of booze
  • The Real Jdbye @ The Real Jdbye:
    so..... yeah
  • The Real Jdbye @ The Real Jdbye:
    we're used to only having a thimbleful of booze
  • Veho @ Veho:
    Booo.
  • The Real Jdbye @ The Real Jdbye:
    same thing if you want whisky on the rocks or something, you can't get a double
  • The Real Jdbye @ The Real Jdbye:
    but you could buy as many shots of whisky (or anything else) as you want and ask for a glass of ice and pour them in
  • The Real Jdbye @ The Real Jdbye:
    it's dumb
  • Veho @ Veho:
    Maybe.
  • Veho @ Veho:
    There was a comparison of the number of Ibuprofen poisonings before and after they limited the maximum dosage per box or per pill (i'll look that up). No limit on the number of boxes you can still buy as many as you want, so people argued it was pointless.
  • Veho @ Veho:
    But the number of (accidental) poisonings dropped because drinking an entire package of ibuprofen pills went from "I need a new liver" to "I need a new box of Ibuprofen".
  • Veho @ Veho:
    Here we have ketoprofen that used to be prescription-only because of the risk of toxic dosages, but then they halved the dose per pill and sell them in bottles of six pills apiece instead of twenty and it doesn't need a prescription any more. Yes you can buy more than one bottle but people simply don't.
  • Psionic Roshambo @ Psionic Roshambo:
    Usually accidentally overdose of ibuprofen here is from people taking like cold medicine then ibuprofen for a headache and the combination is over what they need
    Veho @ Veho: https://imgur.com/gallery/QQkYnQu