Hacking PS4 6.70 Research

IndieDeveloper

Active Member
Newcomer
Joined
Mar 1, 2020
Messages
25
Trophies
0
Age
34
XP
77
Country
Italy
@KiiWii
You seem to me the best and very prepared. I did this thought.
An updated payload that applies the right patches to access the debug menu of system and escape sandbox should make the "0day" exploit work
 
  • Like
Reactions: KiiWii

KiiWii

Editorial Team
Editorial Team
Joined
Nov 17, 2008
Messages
16,713
Trophies
3
Website
defaultdnb.github.io
XP
27,298
Country
United Kingdom
What do you think
It’s all well and good saying “updated”, but how you gonna do dat?

First you need to find a “STABLE” web->userland->kernel exploit chain for your chosen firmware, craft ROP/gadgets, dump kernel, finally then you can use this to find the offsets to port existing payloads (debug or hen etc) to work on the firmware you have kernel access to.

It’s so simple to say, or ask for. But without relevant skill set it’s very difficult to implement.
 

IndieDeveloper

Active Member
Newcomer
Joined
Mar 1, 2020
Messages
25
Trophies
0
Age
34
XP
77
Country
Italy
It’s all well and good saying “updated”, but how you gonna do dat?

First you need to find a “STABLE” web->userland->kernel exploit chain for your chosen firmware, craft ROP/gadgets, dump kernel, finally then you can use this to find the offsets to port existing payloads (debug or hen etc) to work on the firmware you have kernel access to.

It’s so simple to say, or ask for. But without relevant skill set it’s very difficult to implement.
thank you for your opinion. I don't want to imply it's easy, absolutely not. I wanted to know your opinion on this, instead of finding a new kernel exploit since in theory I thought that the existing one should work.
To find the necessary offsets you need kernel access, The chain always breaks without a kernel exploit on chosen firmware.
What I was thinking is to take advantage of the current kernel exploit, which should also work on newer firmware ( 6.XX -7.XX ?? ). Potentially there are many webkit exploits with userland access with ready-made ROPs, the problem would be the kernel exploit.
There must be a secondary road to update payload offsets for access to the system's debug menu, otherwise you are point and head
 

KiiWii

Editorial Team
Editorial Team
Joined
Nov 17, 2008
Messages
16,713
Trophies
3
Website
defaultdnb.github.io
XP
27,298
Country
United Kingdom
thank you for your opinion. I don't want to imply it's easy, absolutely not. I wanted to know your opinion on this, instead of finding a new kernel exploit since in theory I thought that the existing one should work.
To find the necessary offsets you need kernel access, The chain always breaks without a kernel exploit on chosen firmware.
What I was thinking is to take advantage of the current kernel exploit, which should also work on newer firmware ( 6.XX -7.XX ?? ). Potentially there are many webkit exploits with userland access with ready-made ROPs, the problem would be the kernel exploit.
There must be a secondary road to update payload offsets for access to the system's debug menu, otherwise you are point and head

The current (5.05) kex won’t work on >5.50.

ROP is bespoke afaik. I don’t think there can be “pre made” ROP that will magically work on PS4s environment, even if it is FBSD based.

I have heard there is a 0day USB based exploit for dumping apps and kernel, but I don’t know how far along it is or how high it functions on.

Offsets are pretty important, otherwise you would be blindly poking around hoping to hit a needle in a haystack. We have a dumped decrypted kernel for 7.xx, but even if you did port offsets using this, we have no public exploit to implement these ported payloads, even for testing.

It’s a chicken or egg scenario.
 

IndieDeveloper

Active Member
Newcomer
Joined
Mar 1, 2020
Messages
25
Trophies
0
Age
34
XP
77
Country
Italy
The current (5.05) kex won’t work on >5.50.

ROP is bespoke afaik. I don’t think there can be “pre made” ROP that will magically work on PS4s environment, even if it is FBSD based.

I have heard there is a 0day USB based exploit for dumping apps and kernel, but I don’t know how far along it is or how high it functions on.

Offsets are pretty important, otherwise you would be blindly poking around hoping to hit a needle in a haystack. We have a dumped decrypted kernel for 7.xx, but even if you did port offsets using this, we have no public exploit to implement these ported payloads, even for testing.

It’s a chicken or egg scenario.
Very lucid explanation, some interesting information.
I will continue my research thanks @KiiWii
 
  • Like
Reactions: KiiWii

schatzi24

Well-Known Member
Member
Joined
Apr 25, 2018
Messages
502
Trophies
0
XP
2,554
Country
Italy
I will also search a PS4 with firmware 6.70 and i like the PS4 PRO Death Stranding in white and black.
Have this console a firmware under 7.02?
 

RiPPERD

Well-Known Member
Member
Joined
Oct 17, 2018
Messages
334
Trophies
0
Age
37
XP
1,298
Country
United Kingdom
well now the whole world is on lockdown... maybe something big will happen in the ps4 scene? that would be good lol
 
  • Like
Reactions: KiiWii

RY0M43CH1Z3N

Touching things and improving your world
Member
Joined
Aug 16, 2017
Messages
593
Trophies
0
Location
Your Mind
Website
github.com
XP
1,918
Country
Spain
Hi to all,

So where am i ?

i try to get the 6.70 Webkit cause since the begin i work with the 6.50 or 7.00.

Since i don't have any interrest in 6.50 cause i don't own one i let you my research i made with this .

Thanks to liveoverflow for his exelent series on it.

it seems like it was patch in the 6.70, so if you have an adress other than : "[*] 0x7ff8000000000000" it should work .


Thanks you for the support and see y'a all.

Hello, i have a 6.50 PS4 to test things if you want me to try anything.
 

RY0M43CH1Z3N

Touching things and improving your world
Member
Joined
Aug 16, 2017
Messages
593
Trophies
0
Location
Your Mind
Website
github.com
XP
1,918
Country
Spain
  • Like
Reactions: RiPPERD

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Psionic Roshambo @ Psionic Roshambo:
    Having every channel is fun lol
  • D @ diamondsofmayhem:
    Actually, finally found someone who was looking for the same thing. https://gbatemp.net/threads/lost-hyrule-warriors-legends-v1-6-0-ntr-plugin.628141/ to no avail.
  • D @ diamondsofmayhem:
    well, sorry for bugging yall with this.
  • Xdqwerty @ Xdqwerty:
    good night
  • Sicklyboy @ Sicklyboy:
    sup nerds
    +1
  • BigOnYa @ BigOnYa:
    Sup dawg, watching old rap vids so feel like I gotta talk...Real
  • BigOnYa @ BigOnYa:
    Not really just funny. I'm definitely a nerd!
  • ShinyLuxio @ ShinyLuxio:
    Hi there, it's any way to recover original LFCS if I don't have a NAND backup?
  • ShinyLuxio @ ShinyLuxio:
    Bought second hand 3DS, it seems it was "unbanned" but that was before I bought it
  • K3Nv2 @ K3Nv2:
    I got these in today for $20 stink buds they aren't that bad https://a.co/d/fOMSn8g
    +1
  • ShinyLuxio @ ShinyLuxio:
    @BigOnYa thanks but my question isn't there
  • BigOnYa @ BigOnYa:
    You ask your questions there, create a new thread if its not already answered, then eventually a 3ds genius will respond.
  • ShinyLuxio @ ShinyLuxio:
    I will, thanks
    +1
  • BigOnYa @ BigOnYa:
    No prob and btw, welcome to gbatemp! :grog:
  • BigOnYa @ BigOnYa:
    @K3Nv2 I got some cheapies at wallys, that are pretty good, already have lost a few expensive ones (one falls out and gone, can't find) while cutting grass so bought some cheap ones, and of course never lose these cheap ones. (Cheap meaning only $35, compared to air buds which I only have 1 of 2 now)
  • BigOnYa @ BigOnYa:
    They need to add air tags to they airbuds..
  • The Real Jdbye @ The Real Jdbye:
    @BigOnYa the airtags are bigger than the airpods, they won't fit
    +1
  • BigOnYa @ BigOnYa:
    Be cool tech tho. Of course they want to lose them anyways. Buy and buy again.
  • K3Nv2 @ K3Nv2:
    Apple could make a find my AirPods thing pretty easily
    +1
  • BigOnYa @ BigOnYa:
    You would think, esp using bluetooth, not GPS, like a "your getting hot-er" meter on your phone.
  • BigOnYa @ BigOnYa:
    I think they should tie up diddy, and let all the victims come and abuse him, we'll make a holiday of it every year. (jk, maybe)
  • BigOnYa @ BigOnYa:
    Crazy, the rich get away with this shit, and I can't shit without the poop police checking my asshole every time I shit, or if i have my toilet seatbelt on.
    BigOnYa @ BigOnYa: Crazy, the rich get away with this shit, and I can't shit without the poop police checking my...