PS4 Kernel Exploit Leaked

The Holy Grail of PS4 hacking, discovered by CTurt some time ago but never released, has been leaked today. Known as the BADIRET exploit, it gives full access to the PS4 hardware. It was designed to work for firmware version 1.76 originally, but sources say it -may- work up to 2.01 with a different entrypoint.

(If I have my facts straight, the common webkit exploit was patched after 1.76, but the BADIRET exploit was not patched until after 2.01)

Currently, not much can be done with this, although Team fail0verflow does have an interesting Linux loader that is open source and seems to be fairly functional at this time, the only thing they don't supply is the hack (BADIRET) to load it with.

On a side note, be prepared to drop some MAJOR cash on one of these old firmware PS4's. Maybe you will have some luck here:

https://gbatemp.net/categories/trading-area.157/

gKlf796.png


Kodi.tv running on my PS4? Yes ma'am!

:arrow: Source

(Editor's Note: I have a 1.71 PS4 that I will update and personally test this on once I get back from my mini-vacation!)
 
The ps4 can run full blown linux. That means retro emulators with multiple bluetooth and usb based support, ultra portable for taking to friends houses too!
I can already see this thing running dolphin and PCSX2 :)
 
Get hyped, time to buy a PS4, and pirate all those great exclusives, like, um, Bloodborne!
 
This is amazing... Too bad I've spent too much money in the PSN to risk a ban =/

My modded Wii + rooted FireKodi TV can do everything I want anyway

This does pique my interest to what emulators will come for it eventually
 
Last edited by NostalgicMillennial,
If you buy a new ps4 in the store, what firmware version will it be on?
 
what is kodi TV? is it fun to watch?

Open source Media player. Available on Windows, mac, Linux, Android and with hacks. Roku...Apple TV etc With the right addons it can be a swashbucklers' dream. Yaaarrr....
 
I like how people underestimate the "slow-ass netbook-grade APU" (it's not by the way, there isn't a single octacore Jaguar APU out there, off-the-shelf models are up to quadcore) of the PS4 when it already runs PS2 games via the built-in PS2 Classics overlay, just like the PS3 did (in software mode, mind you - not all PS3's had PS2 hardware on-board - most didn't). It absolutely does have enough horsepower for the job, and I need zero evidence to prove that since it already literally does that. I'd also love someone to point out one, just one netbook that runs on unified GDDR5 memory via HSA - hint, they don't exist. I'm so sick and tired of people treating current gens as low-end PC's - they're custom hardware based on off-the-shelf components, just like every other console in history. If the PS4 is a netbook then the Wii U is an old PPC-based Mac, it might as well be.
 
Kind of fails to mention that both CTurt and kr105 have said that the leaked code isn't actually in a functioning state. Going to need some more work done before it's usable.
 
  • Like
Reactions: cearp
Kind of fails to mention that both CTurt and kr105 have said that the leaked code isn't actually in a functioning state. Going to need some more work done before it's usable.
But they already documented the exploits well enough for someone to implement it (no code were released either when memchunkhax2/A9LH were revealed but the community implemented them by themselves) before their private payloads were leaked, but no one bothered because it only works on very old FW.

But considering how easy you could clone PSN licenses to multiple consoles, a hardmod NOR downgrade method could be a possibility.
 
Last edited by lefthandsword,
I will be trying this out when I get home. Expect videos and modding tools soon. :)

I want to focus on SteamOS support with the intention of bringing the PlayStation VR to an open platform. :)

It looks like this is the raw exploit. It's missing IDT restoration and return back to userland for use with the Linux bootloader.

Need a lot of post exploitation stuff like breaking out of chroot jail (on Cturt's blog), allowing kernel peek/poke, etc.

All of this shouldn't be too hard though now that we have kernel code exec! :)
 
Last edited by Relys,
I will be trying this out when I get home. Expect videos and modding tools soon. :)

I want to focus on SteamOS support with the intention of bringing the PlayStation VR to an open platform. :)

It looks like this is the raw exploit. It's missing IDT restoration and return back to userland for use with the Linux bootloader.

Need a lot of post exploitation stuff like breaking out of chroot jail (on Cturt's blog), allowing kernel peek/poke, etc.

All of this shouldn't be too hard though now that we have kernel code exec! :)
Will firmwares pre 1.76 be viable for this?
 
Wake me up when there is a CFW you can install over 3.00+ firmwares that lets you pirate games.

^This. This is kinda useless unless it works on latest firmware. At least the PS3 was hacked on the latest firmware at the time. They still haven't cracked 3.56 or above, but at least when it happened, 3.55 was the latest and everyone was on it.

This is useless because this firmware is so old only someone with no Internet would be on it. So wake me up when someone find something important, which means something on latest firmware.
 

Site & Scene News

Popular threads in this forum