Hacking PS4 6.70 Research

IndieDeveloper

Active Member
Newcomer
Joined
Mar 1, 2020
Messages
25
Trophies
0
Age
34
XP
77
Country
Italy
@KiiWii
You seem to me the best and very prepared. I did this thought.
An updated payload that applies the right patches to access the debug menu of system and escape sandbox should make the "0day" exploit work
 
  • Like
Reactions: KiiWii

KiiWii

Editorial Team
Editorial Team
Joined
Nov 17, 2008
Messages
16,604
Trophies
3
Website
defaultdnb.github.io
XP
27,012
Country
United Kingdom
What do you think
It’s all well and good saying “updated”, but how you gonna do dat?

First you need to find a “STABLE” web->userland->kernel exploit chain for your chosen firmware, craft ROP/gadgets, dump kernel, finally then you can use this to find the offsets to port existing payloads (debug or hen etc) to work on the firmware you have kernel access to.

It’s so simple to say, or ask for. But without relevant skill set it’s very difficult to implement.
 

IndieDeveloper

Active Member
Newcomer
Joined
Mar 1, 2020
Messages
25
Trophies
0
Age
34
XP
77
Country
Italy
It’s all well and good saying “updated”, but how you gonna do dat?

First you need to find a “STABLE” web->userland->kernel exploit chain for your chosen firmware, craft ROP/gadgets, dump kernel, finally then you can use this to find the offsets to port existing payloads (debug or hen etc) to work on the firmware you have kernel access to.

It’s so simple to say, or ask for. But without relevant skill set it’s very difficult to implement.
thank you for your opinion. I don't want to imply it's easy, absolutely not. I wanted to know your opinion on this, instead of finding a new kernel exploit since in theory I thought that the existing one should work.
To find the necessary offsets you need kernel access, The chain always breaks without a kernel exploit on chosen firmware.
What I was thinking is to take advantage of the current kernel exploit, which should also work on newer firmware ( 6.XX -7.XX ?? ). Potentially there are many webkit exploits with userland access with ready-made ROPs, the problem would be the kernel exploit.
There must be a secondary road to update payload offsets for access to the system's debug menu, otherwise you are point and head
 

KiiWii

Editorial Team
Editorial Team
Joined
Nov 17, 2008
Messages
16,604
Trophies
3
Website
defaultdnb.github.io
XP
27,012
Country
United Kingdom
thank you for your opinion. I don't want to imply it's easy, absolutely not. I wanted to know your opinion on this, instead of finding a new kernel exploit since in theory I thought that the existing one should work.
To find the necessary offsets you need kernel access, The chain always breaks without a kernel exploit on chosen firmware.
What I was thinking is to take advantage of the current kernel exploit, which should also work on newer firmware ( 6.XX -7.XX ?? ). Potentially there are many webkit exploits with userland access with ready-made ROPs, the problem would be the kernel exploit.
There must be a secondary road to update payload offsets for access to the system's debug menu, otherwise you are point and head

The current (5.05) kex won’t work on >5.50.

ROP is bespoke afaik. I don’t think there can be “pre made” ROP that will magically work on PS4s environment, even if it is FBSD based.

I have heard there is a 0day USB based exploit for dumping apps and kernel, but I don’t know how far along it is or how high it functions on.

Offsets are pretty important, otherwise you would be blindly poking around hoping to hit a needle in a haystack. We have a dumped decrypted kernel for 7.xx, but even if you did port offsets using this, we have no public exploit to implement these ported payloads, even for testing.

It’s a chicken or egg scenario.
 

IndieDeveloper

Active Member
Newcomer
Joined
Mar 1, 2020
Messages
25
Trophies
0
Age
34
XP
77
Country
Italy
The current (5.05) kex won’t work on >5.50.

ROP is bespoke afaik. I don’t think there can be “pre made” ROP that will magically work on PS4s environment, even if it is FBSD based.

I have heard there is a 0day USB based exploit for dumping apps and kernel, but I don’t know how far along it is or how high it functions on.

Offsets are pretty important, otherwise you would be blindly poking around hoping to hit a needle in a haystack. We have a dumped decrypted kernel for 7.xx, but even if you did port offsets using this, we have no public exploit to implement these ported payloads, even for testing.

It’s a chicken or egg scenario.
Very lucid explanation, some interesting information.
I will continue my research thanks @KiiWii
 
  • Like
Reactions: KiiWii

schatzi24

Well-Known Member
Member
Joined
Apr 25, 2018
Messages
489
Trophies
0
XP
2,503
Country
Italy
I will also search a PS4 with firmware 6.70 and i like the PS4 PRO Death Stranding in white and black.
Have this console a firmware under 7.02?
 

RiPPERD

Well-Known Member
Member
Joined
Oct 17, 2018
Messages
334
Trophies
0
Age
37
XP
1,294
Country
United Kingdom
well now the whole world is on lockdown... maybe something big will happen in the ps4 scene? that would be good lol
 
  • Like
Reactions: KiiWii

RY0M43CH1Z3N

Touching things and improving your world
Member
Joined
Aug 16, 2017
Messages
593
Trophies
0
Location
Your Mind
Website
github.com
XP
1,918
Country
Spain
Hi to all,

So where am i ?

i try to get the 6.70 Webkit cause since the begin i work with the 6.50 or 7.00.

Since i don't have any interrest in 6.50 cause i don't own one i let you my research i made with this .

Thanks to liveoverflow for his exelent series on it.

it seems like it was patch in the 6.70, so if you have an adress other than : "[*] 0x7ff8000000000000" it should work .


Thanks you for the support and see y'a all.

Hello, i have a 6.50 PS4 to test things if you want me to try anything.
 

RY0M43CH1Z3N

Touching things and improving your world
Member
Joined
Aug 16, 2017
Messages
593
Trophies
0
Location
Your Mind
Website
github.com
XP
1,918
Country
Spain
  • Like
Reactions: RiPPERD

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • TwoSpikedHands @ TwoSpikedHands:
    I just found out that the EU version is better in literally every way, better sound quality, better lighting, and there's even a patch someone made to make the text look nicer
  • TwoSpikedHands @ TwoSpikedHands:
    Do I restart now using what i've learned on the EU version since it's a better overall experience? or do I continue with the US version since that is what ive been using, and if someone decides to play my hack, it would most likely be that version?
  • Sicklyboy @ Sicklyboy:
    @TwoSpikedHands, I'll preface this with the fact that I know nothing about the game, but, I think it depends on what your goals are. Are you trying to make a definitive version of the game? You may want to refocus your efforts on the EU version then. Or, are you trying to make a better US version? In which case, the only way to make a better US version is to keep on plugging away at that one ;)
  • Sicklyboy @ Sicklyboy:
    I'm not familiar with the technicalities of the differences between the two versions, but I'm wondering if at least some of those differences are things that you could port over to the US version in your patch without having to include copyrighted assets from the EU version
  • TwoSpikedHands @ TwoSpikedHands:
    @Sicklyboy I am wanting to fully change the game and bend it to my will lol. I would like to eventually have the ability to add more characters, enemies, even have a completely different story if i wanted. I already have the ability to change the tilemaps in the US version, so I can basically make my own map and warp to it in game - so I'm pretty far into it!
  • TwoSpikedHands @ TwoSpikedHands:
    I really would like to make a hack that I would enjoy playing, and maybe other people would too. swapping to the EU version would also mean my US friends could not legally play it
  • TwoSpikedHands @ TwoSpikedHands:
    I am definitely considering porting over some of the EU features without using the actual ROM itself, tbh that would probably be the best way to go about it... but i'm sad that the voice acting is so.... not good on the US version. May not be a way around that though
  • TwoSpikedHands @ TwoSpikedHands:
    I appreciate the insight!
  • The Real Jdbye @ The Real Jdbye:
    @TwoSpikedHands just switch, all the knowledge you learned still applies and most of the code and assets should be the same anyway
  • The Real Jdbye @ The Real Jdbye:
    and realistically they wouldn't

    be able to play it legally anyway since they need a ROM and they probably don't have the means to dump it themselves
  • The Real Jdbye @ The Real Jdbye:
    why the shit does the shitbox randomly insert newlines in my messages
  • Veho @ Veho:
    It does that when I edit a post.
  • Veho @ Veho:
    It inserts a newline in a random spot.
  • The Real Jdbye @ The Real Jdbye:
    never had that i don't think
  • Karma177 @ Karma177:
    do y'all think having an sd card that has a write speed of 700kb/s is a bad idea?
    trying to restore emunand rn but it's taking ages... (also when I finished the first time hekate decided to delete all my fucking files :wacko:)
  • The Real Jdbye @ The Real Jdbye:
    @Karma177 that sd card is 100% faulty so yes, its a bad idea
  • The Real Jdbye @ The Real Jdbye:
    even the slowest non-sdhc sd cards are a few MB/s
  • Karma177 @ Karma177:
    @The Real Jdbye it hasn't given me any error trying to write things on it so I don't really think it's faulty (pasted 40/50gb+ folders and no write errors)
  • DinohScene @ DinohScene:
    run h2testw on it
    +1
  • DinohScene @ DinohScene:
    when SD cards/microSD write speeds drop below a meg a sec, they're usually on the verge of dying
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Samsung SD format can sometimes fix them too
  • Purple_Heart @ Purple_Heart:
    yes looks like an faulty sd
  • Purple_Heart @ Purple_Heart:
    @Psionic Roshambo i may try that with my dead sd cards
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    It's always worth a shot
    Psionic Roshambo @ Psionic Roshambo: It's always worth a shot