Tutorial  Updated

PS5 Exploit Guide

Latest OFW: 7.20 (19/04/23)
Highest PS5 OFW hackable: 4.51 (highest for Znulls new method)
Highest for Mast1c0re native code exec: 6.00 (unreleased)
Highest for Mast1c0re PS2 classics: 6.50 (relies on offsets)

First BD-J + Kernel access exploit provided by Sleirsgoevy (29/9/22)

Note: Though there are three USERLAND exploits and one KERNEL exploit, there are no public HYPERVISOR exploits available to complete the exploit chain, so there is no chance of HEN, and therefore no PS4/PS5 backup loading yet.

(Note: a hypervisor exploit is rumoured to be held in private that works on <2.50 firmware).

• 4.51 OFW for BD-JB entry point.
• 3.00/3.20/3.21/4.02/4.03/4.50/4.51 OFW for webkit entry point
• No firmware requirement for Mast1c0re PS2 classics entry point

NOTE: NEVER TURN ON IDU MODE

NOTE 2: Always stay on the lowest FW possible, if you are on 3.00-4.03 etc, don’t be tempted to update to 4.51 yet, stay as low as possible for now.

If you get stuck in a boot loop at the PS logo, this means the SNVS is corrupted (if hash check fails on boot this causes a “soft brick”).

DONT WORRY it’s not “bricked”, just reinstall your current firmwares RECOVERY PUP in safe mode!

USB: PS5 > UPDATE > PS5UPDATE.PUP

WEBKIT EXPLOIT:
Webkit > Kernel exploit chain for 3.00-4.51 via SpectreDev & ChendoChap:
https://github.com/Cryptogenic/PS5-4.03-Kernel-Exploit

https://github.com/ChendoChap/PS5-IPV6-Kernel-Exploit/tree/wip_branch

BD-JB EXPLOIT:
BD-JB > Kernel exploit chain for 4.51 via Sleirsgoevy:
https://github.com/sleirsgoevy/bd-jb/commit/159253464afde59c3007a706210bec65b91f38f3

PS2 CLASSICS EXPLOIT:
PS2 Classics > Userland > ?? via CTurt:
(Implementation by McCaulay)

Note: this is currently limited to swapping the loaded PS2 iso, or loading PS2 elf homebrew on PS5 (or PS4) for emulators or basic PS2 brew.

Mast1c0re PS2 exploit for PS2 homebrew:
https://cturt.github.io/mast1c0re.html

Mast1c0re part 2:
https://cturt.github.io/mast1c0re-2.html

Mast1c0re payload framework:
https://github.com/McCaulay/mast1c0re

Okrager save game exploit generator for Okage:
https://github.com/McCaulay/okrager

Mast1c0re payloader TCP Client GUI for PS5 6.50:
https://github.com/Master-s/PS4-PS5-Mast1c0re-Payloader/releases

TCP network ISO loader:
https://github.com/McCaulay/mast1c0re-ps2-network-elf-loader/releases

ExFat USB ISO loader:
(Coming soon)

PS5 version display payload by SiSTR0 (compiled by Logic-68):
https://github.com/logic-68/Portage_PS5Version_Mast1c0re/releases/tag/V1.0.0

Console/exploit information and updates:

PS5 FIRMWARE REPO:

https://darthsternie.net/ps5-firmwares/

PS5 SDK REPO:
https://github.com/PS5Dev

With debug setting you can install LEGIT PS5 game update pkg’s from:
https://prosperopatches.com/

You can also install free/demo PKGS (legit pkgs) via debug pkg installer, providing you have all the files/json/licences required.

https://github.com/TheOfficialFloW/Presentations/blob/master/2022-hardwear-io-bd-jb.pdf

https://github.com/sleirsgoevy/bd-jb

https://github.com/psxdev/bd-jb (NOTE: File listing working up to 5.10)

4.03 PAYLOADS:
RET.BIN (Hello world payload by Zeco): https://www17.zippyshare.com/v/awY1gGiJ/file.html

FTP.BIN (by Zeco)
https://www102.zippyshare.com/v/244hmTgp/file.html

4.5X PAYLOADS:
(Coming soon)

/System mount payload elf for BD-J:
https://gbatemp.net/download/remount-system-with-write-permissions.37807/

https://github.com/john-tornblom/ps5-payload-sdk

https://github.com/john-tornblom/bdj-sdk/actions/workflows/bdjb.yml
 
Last edited by KiiWii,

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,238
Trophies
3
XP
28,395
Country
United States
you could theoretically put the pt demo on the ps5 by having it already on the ps4. all you have to do is put it on a disk, then connect it to the system. this does in fact work.
 
  • Like
Reactions: acesmokemall

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,238
Trophies
3
XP
28,395
Country
United States
@KiiWii , off topic, but I think in the final dungeon of berseria. it took me a little over a month, I think, to get a little over 60 hours. much better than the 3 years it took me to beat dragon quest xi. lol hopefully, I can keep this momentum. I'm going to try to get the rest of the trophies in berseria, as long as it doesn't require new game plus like all the tales have.
 

spoggi

Well-Known Member
Member
Joined
Jun 5, 2020
Messages
378
Trophies
0
Age
49
XP
863
Country
Denmark
Guys the ps5 horizon bundle have software version 4.xx?



Where to get your hands on a 4.03 or 4.05 PS5 console​

So, if you’re looking to buy such a console, where would you look?

Disclaimer: eBay/Amazon links below are affiliate links. If you buy through our links, you don’t pay anything additional but we get a small commission on the sale.

First of all, forget about mainstream stores such as Amazon or Walmart: PS5s sell like hotcakes, so the models they have are most likely newer firmwares by now. The exception being the Horizon Forbidden West bundle if you can get one (see below)

Are any PS5 bundles shipping with firmware 4.50 or lower?​

In the PS3/PS4 era, we would look for specific bundles that were known to run a specific firmware. There haven’t been that many bundles for the PS5: The Ratchet and Clank bundle was one of the exceptions, and if you can get your hands on a (sealed) one it is pretty much guaranteed to ship with a low firmware. We haven’t been able to find it on the usual marketplaces though, and the few claiming they have a “bundle” are actually just selling a recent PS5 with the game, which is not what we’re looking for. So we can’t easily recommend that as a feasible option.
 

smf

Well-Known Member
Member
Joined
Feb 23, 2009
Messages
6,414
Trophies
2
XP
5,369
Country
United Kingdom
Can anyone explain to me what was patched in later FW’s, and to why this exploit wouldn’t work?
The exploit was disclosed to Sony a while back so they could fix it, only then is it released for us.

So don't update as exploitable firmware is always likely to be at least a year old.
 
General chit-chat
Help Users
  • No one is chatting at the moment.
    Sonic Angel Knight @ Sonic Angel Knight: Chili dog :ninja: