Hacking PS4 5.xx Rest mode Kernel exploit revealed

Will you update your ps4?


  • Total voters
    286

crossholo

Well-Known Member
OP
Newcomer
Joined
May 26, 2017
Messages
45
Trophies
0
Age
26
XP
963
Country
Italy
Exploit revealed by @vpikhur

He made a presentation at the Recon Brussels hacking conference showing the exploit and a demo video.
Apparently his exploit uses a vulnerability on sys_kldload.
He also relased the presentation slides later in the day here.

Quoted by wololo.net

According to the developer:
The custom Southbridge silicon, responsive for background downloads while main SoC is off, didn’t help to secure Playstation 4. We explain how a chain of exploits combined with hardware attacks will allow code to run in the context of the secure bootloader, extract private keys, and sign a custom kernel.

According to the hacker, the sys_kldload exploit still exists in firmware 5.00, potentially more recent firmwares as well.
The important point of the video above is that the hack persists after boot, demonstrating what is probably the very first custom firmware on the PS4
Sony changed their keys in 5.05, but apparently not the signing process.
The kernel bootloader contains the keys for Rest Mode kernel, which is why it was interesting to get access to it.
How the exploit works is shown in this video.



WHEN ETA??!?!?")=£)/

EDIT 1: Webkit Exploit released! here. It works up to 5.50 beta 3. (tried up to 5.05 myself)

Instructions with localhost
  1. Download install Node.js (LTS version): https://nodejs.org/en/

  2. In your start menu there should be a new program called "Node.js command prompt". Open that.

  3. The default directory will open to c:\Users\"YOUR_USER_NAME"\

  4. Download the zip from git hub and place it in your user directory mentioned in 3.

  5. Rename the folder something easy like "ps4" then run the command "cd ps4" without quotes

  6. Now run command "npm install" without quotes

  7. run command (without quotes): "npm start"

  8. Configure your ps4 DNS to point to the IP address of your computer

  9. Run a connection test to trigger a captive portal (I.E. like a screen you get when first logging into a coffee shop wifi or airport wifi. Basically any public wifi)

  10. FUCKIN PROFIT (I think)
If you do not want to bother doing all this, go to this page on your ps4 browser. Also try multiple times until it says Success.
 
Last edited by crossholo,

ManuelKoegler

Well-Known Member
Member
Joined
Nov 5, 2015
Messages
397
Trophies
0
Age
29
XP
685
Country
Netherlands
Now this is getting interesting
5a7a654f565e80291574c86894dddba8.jpg



Sent from my iPhone using Tapatalk
 
D

Deleted User

Guest
It probably won't be on the latest firmware still but more exclusives will be open for piracy since we don't have a spoofer yet.
 

crossholo

Well-Known Member
OP
Newcomer
Joined
May 26, 2017
Messages
45
Trophies
0
Age
26
XP
963
Country
Italy
This has been known for 2 years so who knows if it will ever get a release.
quoted by wololo:
it appears the hacker is leveraging (and revealing) a not publicly known kernel exploit on the PS4, leveraging a vulnerability in sys_kldload. There is probably enough in the presentation for people to take this information some step further.
 

Axido

Maker of TRASLApp
Member
Joined
Feb 12, 2014
Messages
1,304
Trophies
2
Age
32
XP
4,299
Country
Germany
I guess it's time to hunt down a cheap used Pro (and activate it for Remote Play later on) before 5.50 comes out.
 
Last edited by Axido,

Deleted member 42501

Well-Known Member
Member
Joined
Jun 16, 2006
Messages
1,724
Trophies
2
XP
4,259
As I said a while back, once ps5 is announced you'll hear of a hack on the latest firmware for ps4 too.

It actually makes a lot of sense on a lot of levels to do it this way as the game has changed so much since I last played it.
 

depaul

Well-Known Member
Member
Joined
May 21, 2014
Messages
1,293
Trophies
0
XP
2,953
Country
France
So do you think this exploit requieres some hardware 'soldering'? Or only through web access like what we have now.
 

askara

Well-Known Member
Member
Joined
Feb 12, 2013
Messages
238
Trophies
1
XP
935
Country
noob question. what does it take for PS4 hacking to be like PS3 or something where once you jailbreaked your PS4, you can just wait a little while for the jailbreak on the latest update? are we close to that? or will it always be like Vita, where the jailbreak on new firmware may never come or long long wait?
 

thekarter104

Well-Known Member
Member
Joined
Mar 28, 2013
Messages
1,986
Trophies
1
XP
3,010
Country
United States
Yes, this is nice. I think mine is on 5.03.

How to disable updates for PS4? I'd like to know right now because ofcourse the PS4 will connect to the internet as soon as it's turned on.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    SylverReZ @ SylverReZ: @OctoAori20, Thank you. Hope you're in good spirits today like I am. :)