Tutorial  Updated

PS5 Exploit Guide

PS5 Hack Status:


FW Ranges:
2.XX = KEX+HV: PS4/5 backups, possible keys exploit (WK: 2.50 best / 2.7X max)
3.XX = KEX+HV+Linux: PS4/5 backups, possible keys exploit (WK/BD/LUA: 3.20 best / 3.21 max)
4.XX = KEX+HV+Linux: PS4/5 backups (WK/BD/LUA (Y2/NF/YARPE 4.03+): 4.50 best / 4.51 max)
5.XX = KEX+HV+Linux: PS4/5 backups (
WK/BD/Y2/NF/LUA/YARPE: 5.50 best + max)

6.XX = KEX: PS4/5 backups (KEX+HV+Linux: 6.02 max) (WK/BD/Y2/NF/LUA/YARPE: 6.02 for Linux / 6.50 max)
7.XX = KEX: PS4/5 backups (KEX+HV+Linux: 7.61) (
WK/BD/Y2/NF/LUA/YARPE: 7.61 best + max)
8.XX-10.00 = KEX: PS4/5 backups, no HV (WK/BD/Y2/NF/LUA/YARPE)
10.01-12.70 = KEX: PS4/5 backups, no HV (
WK/BD/Y2/NF/LUA/YARPE)
13.XX = HV+KEX+WK SOON! (WK/BD (13.42)/Y2/LUA/YARPE)
14.XX = No KEX/UL only (LUA/YARPE)


NOTE 1: Recommended firmware is subjective. Staying low is always recommended.
NOTE 2: Do not update too many major versions (e.g., 4.xx to 5.xx or 7.xx to 8.xx). Remain low unless all you want is backups.
NOTE 3: P2JB can take over an hour to exploit on FW up to 12.70.


Hypervisor (HV):
Highest released HV: 7.61
Highest unreleased HV: 13.60 (SlopVisor)
*unreleased/unimplemented


Kernel (KEX):
Highest released KEX:
12.70 (P2JB)
Highest unreleased KEX: 13.60 (SlopSploit SOON)
UMTX2:
1.00-7.61 (*WK to 5.50 / BDJB to 7.61)
Lapse: 1.00-10.01
Relapse/Prolapse: 11.60-13.60 (Soon)
Poopsploit:
4.03-12.00 (*BD to 12.00)
P2JB: 9.00-12.70 (*WK: Lapse to 10.01 / P2JB to 12.70)

Userland (UL):
LUA (Artemis): 2.00-LATEST (LUA exploit, + Lapse up to 10.01)
Y2JB: 4.03-13.40 (YouTube exploit, + Lapse: 10.01 / P2JB: 12.70)
NFNH: 4.03-12.XX (Netflix exploit, + Lapse: 10.01)
YARPE: 4.03-12.XX (Ren'Py exploit, + Lapse: 10.01 / P2JB: 12.70)
BD-JB: 1.00-13.42 (BD exploit + UMTX2: 7.61 / BD-JB5 + Poops to 12.00)
Webkit: 1.00-5.50 (PSFREE +UMTX2: 5.50 / SlopKit 7.00-13.60 (P2JB: 12.70) / (Slopsploit: 13.60)
Mast1C0re: 1.00-7.61 (Depreciated for LuaC0re)
LuaC0re: 1.00-12.70 (Poops: 4.03-12.00/P2JB: 9.00-12.70)
REDIS: 1.00-5.50 (Jordy's untethered JB on boot - coming soon)

NOTE 1: A userland entry point (UL) chained to kernel exploit (KEX) is required to exploit your console.
NOTE 2: Digital consoles can now use Y2JB+Poops (4.03-12.00) / Y2JB+P2JB (9.00-12.70).
NOTE 3: All consoles will be able to use SlopKit (webkit), SplopSploit (KEX) and SlopVisor (HV) for firmwares up to 13.60 SOON.


Useful Applications:
FPKG: 3.00-11.60 with KStuff Lite / 12.XX-13.60 SOON
Kstuff Lite: 3.00-12.70
HERE
Kstuff Toggle: 3.00-12.00 HERE
PS5 App Dumper: 3.00-12.00 HERE
Dump Runner: 3.00-12.00 HERE
Dump Installer: 3.00-12.00 HERE
Backporting: Possible (backpork / Porkfolio)
PS4/PS5 DLC: Work with Kstuff Lite
Trophies: Work with Kstuff Lite
Compression: Works with Kstuff Lite
Homebrew Enabler: etaHEN (3.00-10.01) latest HERE
PS5 Backup manager: ItemzFlow Compatibility list: HERE
PS4 Backup Loading: Works (rest mode & backports work, can crash).
PS5 Debug NG: 3.XX-13.XX
HERE
PS5 Remote Play: Works HERE & HERE
PS5 Trainers/Cheats: Work

UART:
HERE
Linux: (OG: 3.00-7.61, Slim: 7.61) HERE
Kldload (wip): 3.00-6.50 HERE
PSN access: NEVER
Latest OFW: 14.00 (16/9/26)
Summarised OFW/Model guide: HERE
1.XX-7.61 compatibility list:
HERE
PS5 SDK Repo: HERE
Legit PKG Updates: HERE or HERE
OFW Updates: HERE (history HERE)

Preparing Your Console:


It is recommended to either self-host offline or block these addresses in your router to avoid accidental updates or getting an update nag. Using the DNS method is no longer failsafe, as these are not guaranteed to be running 24/7.


dau01.ps5.update.playstation.net
dbr01.ps5.update.playstation.net
dcn01.ps5.update.playstation.net
deu01.ps5.update.playstation.net
dhk01.ps5.update.playstation.net
djp01.ps5.update.playstation.net
dkr01.ps5.update.playstation.net
dmx01.ps5.update.playstation.net
dru01.ps5.update.playstation.net
dsa01.ps5.update.playstation.net
dtw01.ps5.update.playstation.net
duk01.ps5.update.playstation.net
dus01.ps5.update.playstation.net
fau01.ps5.update.playstation.net
fbr01.ps5.update.playstation.net
fcn01.ps5.update.playstation.net
feu01.ps5.update.playstation.net
fhk01.ps5.update.playstation.net
fjp01.ps5.update.playstation.net
fkr01.ps5.update.playstation.net
fmx01.ps5.update.playstation.net
fru01.ps5.update.playstation.net
fsa01.ps5.update.playstation.net
ftw01.ps5.update.playstation.net
fuk01.ps5.update.playstation.net
fus01.ps5.update.playstation.net
hau01.ps5.update.playstation.net
hbr01.ps5.update.playstation.net
hcn01.ps5.update.playstation.net
heu01.ps5.update.playstation.net
hhk01.ps5.update.playstation.net
hjp01.ps5.update.playstation.net
hkr01.ps5.update.playstation.net
hmx01.ps5.update.playstation.net
hru01.ps5.update.playstation.net
hsa01.ps5.update.playstation.net
htw01.ps5.update.playstation.net
huk01.ps5.update.playstation.net
hus01.ps5.update.playstation.net
sgst.prod.dl.playstation.net
gs2.ww.prod.dl.playstation.net

Alternative DNS IP:
62.210.38.117 - User Guide = ES7in1
or
45.56.67.85
(Leave DNS 2 blank)

To determine your OFW version:
Go to settings > system > console information.

Version string info:
Year.Half (1st/2nd half of the year)-Major Version No.Minor Version No.Extended info-Further Info.Retail/Debug

21.02-04.03.00.00-00.00.00.0.1

It is recommended to keep your console as low as possible to have access to better jailbreak stability and features. Stay as low as possible within the "Golden" firmware brackets that apply to your current firmware, see the top of this page.

(No jailbreak is ever guaranteed. No developer is obliged to release anything publicly)

WARNING:

Only update OFW manually via USB by getting the firmware file from HERE and installing from <USB>:/PS5/UPDATE/PS5UPDATE.PUP
(Updating with RECOVERY PUP will perform a factory format and will wipe your internal HDD)

PS5 factory mode PUP installation path:
/usb/PROSPERO/UPDATE/PROSPEROUPDATE.PUP

NOTE: Make a system back up before attempting any modifications.
On console: go to [Settings] > [System] > [System Software] > [Back Up and Restore] > [Back Up Your PS5]

Select Your Jailbreak:


WEBKIT:BD-JB:LUA:Y2JB:NFNH:YARPE:LuaC0re:BD-UN-JB:


  1. Information:
    Firmware 1.00-5.50 or 7.00-12.70 is required for the webkit exploit.

    Enabling web browser:
    Open [Settings] > select [Users & Accounts] > select [YouTube] > click "Link" > click "use browser" > click "terms" (bottom right) > click google apps icon (top right) > select Google Search.

    Exploiting 1.00-5.50:
    Enter https://zecoxao.github.io/luasauce/ or https://github.com/kmeps4/PSFree into google > click “Jailbreak" or wait for it to complete.

    Exploiting 7.00-8.60:

    https://soniciso1.github.io/pooP2JB/

    Exploiting 7.00-12.00 (-13.60 SOON):

    https://jordyidk.github.io/slopkit/

    https://zecoxao.github.io/slopkit2/

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  2. Important:
    You will need a BD dive paired to your Slim/Pro console or an OG Phat model . Consoles must be on 1.00-13.42 to run this exploit.


    Recommended ISO: Viktorious AIO Auto BD-JB ISO for 4.XX-7.61

    Exploiting:
    1, Burn ISO to a blank BD-R or BD-RE > Insert into console > click on the [DISC PLAYER] icon.

    2, Highlight [PIPELINE RUNNER] > click option 2 [Normaljailbreak-etaHEN-UMTX1.pipe] to auto load etaHEN ready for ItemzFlow.

    ELF Loader uses PS5 IP: port 9021 / BIN loader uses 9020 / Jar loader uses port 9025

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  3. Important:
    LUA entry point works from 2.00 to the latest OFW, but there is no KEX above 12.70 yet.
    (A compatible PS4 game is required to launch the exploit on PS5. See below)

    Your PS5 console must be activated to use save copying for PS4 games.
    1. Insert your game disc and, as soon as possible, make a save file within it.
    2. Copy the save files to USB, go to [SETTINGS] > [STORAGE] > [CONSOLE STORAGE] > [SAVE DATA] > [PS4 GAMES] > select the game save and copy to a USB drive.
    3. On PC, using a Google Drive account, make a new folder with the GAME ID of your game, and upload the savedata & savedata.bin files to that folder.
    4. Share the folder, set it to editor mode, share with anyone, and click "copy the link".
    5. Join the HTOS Discord group: HERE type "/decrypt", select "FALSE" for including SCE_SYS, paste or type in the Google Drive link, and press enter. The bot should begin mounting your save. (If it doesn't, paste in the link again.)
    6. Click "ENCRYPTED" to remove the Sony PFS layer. Download the generated files and extract the folder to your desktop (you should have 4 files in there and be named dec_savedata_CUSA[GAME ID]).
    7. Using REMOTE LUA LOADER, open the savedata folder, copy the 20 files within into your encrypted save folder on your desktop.
    8. Upload the encrypted save folder (now with 24 files in) to your Google Drive. It should be named "dec_savedata_CUSA[GAME ID]" where GAME ID is your games 5 digit number, and set it to editor mode, share with anyone, and then click "copy the link".
    9. Go back to the HTOS discord server, and type "/encrypt", hit "FALSE" for uploading individually, and "FALSE" to include SCE_SYS. Finally, hit shared_gd_link and paste in your link to the original save (4 files) folder. (If it doesn't, paste in the link again.)
    10. When this is done, paste the link to the decrypted save (24 files) folder, and the bot will encrypt the files.
    11. Resign the files by typing "/resign" followed by your account name on the console, or PSN ID associated with that account if using the latest OFW.
    12. Download the resigned files, extract the files to your USB drive and overwrite them into the savedata folder on your USB or external drive.
    13. Copy the saves back to your console [SETTINGS] > [SAVE DATA AND GAME/APP SETTINGS] > [SAVE DATA PS4] > [COPY OR DELETE FROM USB] > [COPY TO CONSOLE STORAGE] > select your game save folder from the USB drive and copy/overwrite old save data.
    14. Load LUA game again, and you should see the LUA LOADER screen.
    15. You can use "SEND_LUA.PY" to send the UMTX files to the loader.
    (NOTE: Some games require manual loading of save game)

    On firmware up to 7.61, you can now load UMTX/2 followed by etaHEN by sending the files to your console IP on PORT 9026.
    On firmware 8.00-LATEST, you can connect with the REMOTE LUA LOADER APP to send debug notifications or FTP on port 1337.

    LUA Loader: HERE or HERE

    Auto LUA Loader Fork: HERE

    Compatible LUA games:
    Aerial Life (CUSA17122)
    Aibeya (CUSA17068)
    Aikagi 2 (CUSA19556)
    Aikagi Kimi to Issho ni Pack (CUSA16229)
    Aikano Yukizora no Triangle (CUSA19370)
    Boku to Nurse no Kenshuu Nisshi (CUSA12049)
    Boku to Joi no Shinsatsu Nisshi (CUSA18107)
    Fuyu Kiss (CUSA29745)
    Hamidashi Creative (CUSA27389)
    Hamidashi Creative Demo (CUSA27390 requires the latest OFW to download from PSN)
    Haruoto Alice (CUSA14324)
    IxSHE Tell (CUSA17112)
    IxSHE Tell Demo (CUSA17126)
    Jinki Resurrection (CUSA25179)
    Jinki Resurrection Demo (CUSA25180 requires the latest OFW to download from PSN)
    Maid-san no Iru Kurashi (CUSA18106)
    Nora Princess and Stray Cat Heart HD (CUSA13303: Rename save9999.dat into nora_01.dat)
    Nora Princess and Strat Cat Heart 2 (CUSA13586)
    Raspberry Cube (CUSA16074)
    Winter Guest (CUSA11977)

    WARNING: using demos is free but can become corrupt, and you cannot upgrade your internal HDD either. If you lose the demo you can no longer use the exploit. Disc recommended.

    Incompatible LUA games:

    Dokyusei Remake Csver (CUSA47117)
    Dōkyūsei: Bangin' Summer - Home Edition Demo (CUSA47132)
    Kiss Trilogy (CUSA19341)
    Love Clear Demo (CUSA18109)
    Mikagami Sumika no Seifuku Katsudou (CUSA11481)
    Sen no Hatou, Arazone no Hime (CUSA09647)
    Tonari ni Kanojo no Iru Shiawase: Two Farce (CUSA09825)
    Tonari ni Kanojo no Iru Shiawase Summer Surprise (CUSA18998)

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  4. Requirements:
    PS5 console must be on 4.30-12.70 and previously activated through PSN or fake activated to use the YouTube app, unless you're restoring a backup.
    (Note: restoring a backup will factory reset your console).

    Information:
    If updating and older installation, download the latest download0.dat > use FTP or PS5 Explorer to place it in the user/download/PPSA01650 folder.

    Preparation:
    Download the Y2JB_backup_X.X(4.03) if you're on 4.03-12.40, or the Y2JB_backup_X.X(12.20) if you're on 12.60 or higher from HERE
    On PC: format a USB 3.0 HDD to exFAT, and copy the PS5 folder from the backup to the root, and put the latest nanodnf.efl from nanoDNS to the root too.
    On console: go to [Settings] > [System] > [System Software] > [Back up and Restore] > [Restore] > select the y2JB back up & let it install (the console will reboot when complete).
    (Note: The exploit will now be accessible under the [MEDIA] tab)

    Exploiting:
    Going to [Settings] > [Network] > [Settings] > [Set up Internet Connection] > [Set up Manually] > set up a wireless or LAN connection > change [DNS Settings] to manual > change [Primary DNS] to 127.0.0.1 > click [Done] > open the [YouTube App].
    (Note: Ignore and internet connection issue warnings)

    Firmware up to 10.01 will use Lapse Kernel Exploit. Firmware 10.20-12.70 and above will use P2JB and could take up to an hour.

    You can send payloads using netcat GUI to PS5's IP Address & port 9021.

    You can swap the download0.dat to itzPLK version for auto loading and payload manager in future (payload manager accessible through browser on 127.0.0.1:8084)

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  5. Requirements:
    PS5 console must be on 4.30-10.01 and previously activated through PSN or fake activated. You will need a 256GB external HDD (minimum).

    Preparation:
    Download balenaEtcher
    Download the latest Extended Storage or M.2 Image (select your m.2's capacity)

    EXTERNAL DRIVE METHOD (Netflix_PS5_EU_Ext.7z):
    1a, On PC: connect your 256GB (min) USB drive to your Windows/Mac/Linux PC > extract the image to your computer > open Etcher > click [Flash From File] & select the extracted image *.zip > click [Select Target] & choose the external drive > Click [Flash!] & allow it to complete.
    (Note: 256GB is the smallest drive you can use)

    2a, On console: click [Settings] > [Storage] > [USB Extended Storage] > [Games and Apps] > press X on [Netflix] > select [NETFLIX] under items to move > select [Move] > move to internal storage & allow it to complete.
    (Note: The exploit will now be accessible under the [MEDIA] tab)

    INTERNAL DRIVE METHOD (Netflix.XXXXGB.7z):
    1b, On PC: connect the M.2 to your Windows/Mac/Linux PC > extract the image to your computer > open Etcher > click [Flash From File] & select the extracted image *.zip > click [Select Target] & choose the external drive > Click [Flash!] & allow it to complete.
    (Note: 4TB will take 80 mins, 2TB 45 mins, 256GB 10 mins)

    2b, On console: Power off the console > insert the M.2 SSD > power on the console > click [Settings] > [Storage] > press X on [Netflix] > select [NETFLIX] under items to move > select [Move] > move to internal storage & allow it to complete.
    (Note: The exploit will now be accessible under the [MEDIA] tab).

    Exploiting:
    1a, for consoles 10.01 and below, on console: go to [Settings] > [Network] > [Settings] > [Set up Internet Connection] > [Set up Manually] > set up a wireless or LAN connection. Go to Proxy > change [Automatic] to [Manual] > enter Address: 172.105.156.37 & port: 42069 > click [Done] > open the [Netflix App].
    (Note: Ignore and internet connection issue warnings)

    1b, for consoles 10.20-12.70, COMING SOON.

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  6. Important:
    YARPE works from 4.30 to 12.70 (9.00 - 12.07 via P2JB)
    (A compatible PS4 game is required to launch the exploit on PS5. See below)

    Requirements:
    PS5 console must be on 4.30-10.01 to use this exploit.

    Exploiting:
    coming soon

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].

  7. Requirements:
    PS5 console must be on 4.30-12.70 to use this exploit. SWRR

    Exploiting:
    coming soon

    Debug settings will be loaded, and the package installer can be found under [SETTINGS] > [DEBUG SETTINGS].


  8. [UPDATED]
    No longer needed if using latest WebKit (to 13.60) or BD-JB (to 13.42)!


    Important:

    This method modifies the BD-J stack to allows BD-JB entry point to be re-enabled on consoles up to 13.60, for convenience only.

    Very Important:
    This method requires your console to be jailbroken by another method first to gain access to alter the files.

    https://github.com/Gezine/BD-UN-JB

    Preparation:
    Burn the ISO to a blank Blu Ray, insert it into the jailbroken console. Send the bdj_unpatch.elf to elfldr using netcat GUI to PS5's IP Address & port 9021 to unpatch BD-J.

    (NOTE: DO NOT REINSTALL/UPDATE FW, IT WILL WIPE THE PATCH AND LOSE BD-JB)


Once jailbroken it is recommended to run KSTUFF LITE and SHADOWMOUNTPLUS at minimum to get you up and running.
(ShadowMountPlus: is an automated background auto-mounter payload for jailbroken PS5 consoles. Detects, mounts, and installs game dumps from internal or external storage, with support for UFS, exFAT, PFS, and nested compressed PFS containers)

Additional Information:


Blocking Updated with nanoDNS:
Set primary DNS manually to 127.0.0.1. Send latest elf to BIN LOADER using netcat GUI to PS5's IP Address & port 9021.

PS4 GAME INFORMATION:
OFW 1.xx cannot run PS4 games.
OFW 2.xx runs PS4 games up to 8.03

OFW 3.xx runs PS4 games up to 8.52
OFW 4.xx runs PS4 games up to 9.04
OFW 5.xx runs PS4 games up to 9.60
OFW 6.xx runs PS4 games up to 10.50

OFW 7.xx runs PS4 games up to 11.00
OFW 8.xx/9.xx runs PS4 games up to 11.50
OFW 10.xx runs PS4 games up to 12.00

OFW 11.xx runs PS4 games up to 12.50
OFW 12.xx runs PS4 games up to 13.00
OFW 13.xx runs PS4 games up to 13.52
OFW 14.xx runs PS4 games up to 14.00


(Note: PS4 backported FPKGs also work perfectly on an exploited PS5 with Kstuff)


You can install free/demo PKGS (legit pkgs) via the debug pkg installer, provided you have all the files/json/licences required.
(Astro’s Playroom has no licences and can be installed and played from official pkgs and updated inline with your firmware)

Warnings:


1: Never enable IDU mode.
If you do, you will need to enter staff mode by holding L1 + L2 and tapping this combo: circle, cross, square, triangle, right D-Pad. Release L1 + L2, and you can access settings to exit IDU.

2: Try to stay on the lowest FW possible and wait for hacks on that firmware.

3: Installing legit game PKGs you do not own will never work, even if spoofed.

4: If you get stuck in a boot loop at the PS logo, the SNVS is corrupted (if the hash check fails on boot, this causes a “soft brick”). It’s not “bricked”. Simply reinstall your current firmware RECOVERY PUP in safe mode from USB: PS5 > UPDATE > PS5UPDATE.PUP.

Archived Information


 
Last edited by KiiWii,
I just been using them 4 files in that order below in my autoloader so I dont have to think about what's going on lol. Now drakmor is constantly updating so better versions with better options are probably out. I'm not changing unless a game comes out that is not compatible.

kstuff-1.12-dr-test8-1.elf

a53_ppr_install_fast_15.09-1.elf

shadowmountplus 1.7alpha13fix1-2

ps5-backpork (1)-1.elf
Am i wrong or new kstuff of Drakmor has a53_ppr inside?
 
  • Like
Reactions: peteruk
I sold my PS5 (firmware 6.50) and bought a new PS5 Pro, updating it to 13.60. Now I'll be keeping an eye on Linux-related news in the scene
Im also thinking about selling my 6.50 for a good price. I have bought almost new banned 13.40 few months ago for so cheap that i couldnt resist and now i will be able to use it 😁. Then sell my old one and get some proper cash. I basically just play games on it so i will not loose anything (maybe fpkg but im used to external drive by now). Was thinking about PRO but i have a good PC so dont need it.
 
Im also thinking about selling my 6.50 for a good price. I have bought almost new banned 13.40 few months ago for so cheap that i couldnt resist and now i will be able to use it 😁. Then sell my old one and get some proper cash. I basically just play games on it so i will not loose anything (maybe fpkg but im used to external drive by now). Was thinking about PRO but i have a good PC so dont need it.
My PS5 auction ended today; I managed to sell my PS5 (firmware 6.50) with the disc drive for a pretty high price.

Tomorrow, I’m going to buy a PS5 Pro and pair the disc drive to firmware 13.60. I’ll buy console in person at a store because I don't have much time left to handle drive pairing process for 13.60
Post automatically merged:

I'll keep it offline then and try to sell it after some time.
 
Chaps, when we have a FPKG and Drakmor releases say a new ampr-emu file... then where do we place it? Pre FPKG, I was using the native dump and it was was to replace any files into the dumps folder...?.
You don't place it anywhere. ampr_emu is not needed for fPKG games. Since we're using Sony's native package format and execution flow, we don't have to emulate ampr; we have the real thing.

This is one of the many (many) perks of fPKGs.

nanoDNS 0.4

  • IPv6 support
  • Quiet mode
  • Yandex.DNS fix (remove old nanodns.ini)
FW PS5 1.00-13.60, PS4 1.00-13.52
source: https://github.com/drakmor/nanoDNS/releases/tag/0.4
I'm a bit confused. NanoDNS 0.4 is almost two months old. Why is this being posted now?

To be fair that root key is buried in there. Theres like 8 hoops you gotta jump through to get there

And that super duper low FW to get them.

But with PUP keys you can sign FW from what I was told which need the same requirements to get afaik unless someone has another way
I'm probably missing something basic here, but why would firmware signing keys even be on the consoles? The public key needed to validate the firmware, sure. But the private key to sign firmwares should never be leaving Sony HQ. The only signing keys a console should have are for saves and the extra layer of encryption used on games copied to an external USB drive.
 
I'm a bit confused. NanoDNS 0.4 is almost two months old. Why is this being posted now?
I've already posted it a few days back.

The source code and link so version 0.4 are from august 4th. However the 2 .elf files are updated. The PS4 elf file has been updated to FW 13.52. I already checked that one on my PS4. Works fine.
The PS5 .elf file has been updated to work with FW 13.60.

1790372503322.png

Post automatically merged:

Am i wrong or new kstuff of Drakmor has a53_ppr inside?
Yup. Since kstuff-fpkg-1.13-dr-test1.elf (23-09)
Most reccent version from today is: kstuff-1.13-fpkg-dr-test4.elf
 
I've already posted it a few days back.

The source code and link so version 0.4 are from august 4th. However the 2 .elf files are updated. The PS4 elf file has been updated to FW 13.52. I already checked that one on my PS4. Works fine.
The PS5 .elf file has been updated to work with FW 13.60.

View attachment 592523
Gotcha. Thanks for the clarification!
 
At this point we're gonna have most of the important apps already updated for 13.60 support before de JB releases, but hey, I'm not complaining. Better be ready beforehand!
 
  • Like
Reactions: AlphaBravo
I Have 3 PS5 on software 11.60 that i have jailbroken using webkit userland exploit. All of them shutdown randomly and completely unstable if i download a lot of ps4 games on them, but if keep only 2 - 3 games they won't shutdown at all. What could be causing this?
I stumbled upon such post on Facebook with a lot of replies from people with the same firmware version reporting the exact same issue.
Does anyone know what this might be?
Does it affect other firmware versions as well?
Does if affect only the webkit exploit chain or others like BD-JB as well?
 
Last edited by kam821,
At this point we're gonna have most of the important apps already updated for 13.60 support before de JB releases, but hey, I'm not complaining. Better be ready beforehand!
This is a very rare time that will probably never happen again. We have an kernel and hv exploit up to the second last firmware, kstuff and a ton of other payloads have already been updated to 13.60 so hopefully things are good to go right when the new jailbreak drops.

Remember when a new jailbreak method was released it took weeks or sometimes months for kstuff and others to be updated? I think it was 11.xx or maybe 12.xx where things really changed so it took EchoStretch and friends much longer to figure it out.
 
  • Like
Reactions: AlphaBravo
I've always been skeptical about these "keys" or perhaps the interpretation of it.

There is no way in hell, a group of security engineers for a modern console would design a security model in which would be satisfied with the assumption that a user whom decides to not update their console, their launch rushed and potentially vulnerable console will eventually hold the key to the entire business and life of the console. What are they? Fucking monkeys?

Modern CPUs offer a secure context, memory and storage isolated from the normal world even at kernel level privileges, is an execution context in which you can trivially reverse engineer the binaries it executes, see what it does but the normal world can't see, access or read the secrets and its execution at runtime. But even then, I highly doubt Sony will rely on it alone to protect the games/content, a highly motivated and skilled reverse engineer will want to find their way in through a vulnerability, it has happened before, I am sure Sony would have assumed that too.

Sony's ability to have a server side secret (public/private key) can help Sony mitigate the damage and protect future content should current secrets are exposed. This makes a lot of sense in today's world than just having the console securely store a highly valuable key.

I speculate that, some people may have found a vulnerability to the PSP and have managed to extract or read firmware-specific private key(s), such key or maybe a combination of secrets are probably used by the console during game license acquisition (ie. When the user downloads a digital game they bought) or disc license verification at the time of reading/installing a disc game into the console. They may facilitate or allow to derive a common "game decryption key" that ultimately would allow to turn a .PKG or a disc encrypted by Sony into a FFPKG.

So in theory given:
1) A valid account with a digital purchased game
2) Reversing the console-server interaction during license acquisition.
3) And such private key

Someone would impersonate the requests made by the console, request a game license signed/encrypted by Sony's public key, download the encrypted game blob, derive such common game key and decrypt the game into a FFPKG without touching the console. This is a very plausible case of what they MAY potentially have access to.

Even in such a case I would argue that there is nothing stopping Sony from enforcing a firmware-specific private key(s), that is, Sony can only issue you a license to decrypt the game if the firmware private key hasn't been exposed or is recent enough. Ie. If your extracted private key is from Firmware 5 or 6, and you are requesting a game license today, it would be rejected or issue but you wouldn't be able to derive the game decryption key from it. So while it would enable piracy, it would be short lived or meaningless depending on when these keys where extracted.

This is obviously my theory, Sony's security engineers could be really a bunch of morons and have included a highly valuable key in every shipped console. BUT i extremely doubt it, and I would love to see a POC that demonstrate it, not the key, but how Sony was stupid enough to allow it to happen.

And to be clear, I don't give a damn about a POC. BUT it's worth noting that demonstrating the power of such keys if they are firmware, app or game singing keys, is fairly trivial and unlikely to bring any legal trouble to prove it. As I've suggested before they can write, package and sign a Hello World .pkg to demonstrate it, if the console can launch it after restart, then there is the proof. A jailbroken console still will be needed to install it, that throws the whole legal talk out of the window. It is not like you can get this signed app to a legitimate user on the latest firmware, since the only way to install a package is via the PlayStation Store or through your account download history.
 
  • Like
Reactions: bamboocappucino
Is anyone here daily driving Linux on PS5? I have been wanting to set it up for a while as a equivalent steam machine to play on my sofa but the amount of information I can find on how it run's is pretty limited. Seem's like there were some driver issues with some games early on but I have no idea if those are fixed now? My ideal use case is like a steam machine that I can play on my TV then play on the go on my deck.

There is a linux distro that is based on steam machine if I remember correctly ?
 
Is anyone here daily driving Linux on PS5? I have been wanting to set it up for a while as a equivalent steam machine to play on my sofa but the amount of information I can find on how it run's is pretty limited. Seem's like there were some driver issues with some games early on but I have no idea if those are fixed now? My ideal use case is like a steam machine that I can play on my TV then play on the go on my deck.

There is a linux distro that is based on steam machine if I remember correctly ?
I've been rocking ubuntu on my 3.00 ps5 for a while now

I chose ubuntu because it's the most "noob friendly" distro IMO because of how popular and documented it is.

You just run lutris for your steam games (you don't need to buy the games btw but I won't talk about that here) and any issue you have you just copy and paste the commands that chatgpt gives you in your command prompt.

Never tell chatgpt that you don't have steam installed.
 
Never tell chatgpt that you don't have steam installed.

Never tell ChatGPT (or any other for that matter) because it's AI...

Anyway, for me personally I love Linux Mint. Ubuntu is very nice too.
SteamOS is fine, but I'm not a fan of KDE. PS5 is a great Steam Machine.

Btw since you have experienced with Linux in PS5 I have always a concern about usage. How does the process when you want to use it (or not), do you just boot the normal PS5 OS fine? Do you choose a Linux Loader something inside PS5 homebrew program or does it boot into it directly?
 
Somebody wants KODI for their PS5?

Kodi for PlayStation 5 (homebrew)​

A native ps5 platform port of Kodi 22 for jailbroken PS5 consoles, built on the open-source ps5-payload-dev toolchain and ps5-opengl, and installed as a regular home-screen title via ShadowMountPlus.

Unofficial. This project is not affiliated with or endorsed by Team Kodi / the XBMC Foundation or Sony. "Kodi" and the Kodi logo are trademarks of the XBMC Foundation.
This repository contains no exploit, no Sony SDK code and no firmware files. The Sony library prototypes in overlay/xbmc/platform/ps5/sce/ are clean-room declarations of the handful of functions Kodi needs.

Hardware decoding
What's new

Native 3840×2160 rendering.
Refresh-rate switching between 59.94 and 119.88 Hz through Kodi's Adjust display refresh rate: films at 23.976/24 fps play with an even 5:1 cadence.
The real 59.94 Hz output rate and a display vsync clock for Sync playback to display.
Video frame uploads 6× faster (rectangle textures).
No more ghosted GUI text.

Install: extract into /data/homebrew/, then register with ShadowMountPlus. Recommended settings are in the README.

Known limits: 25/50 fps content stays at 59.94 Hz; HEVC 10-bit decodes in software; no internet access yet. decodes in software; no internet access yet.

Link: https://github.com/VivaLaVent/kodi-ps5/releases/tag/0.6
Post automatically merged:

New update regarding RetroArch. Dolphin emu added.

PS5 RetroArch — Alpha 3 🎮​

This release adds Dolphin (GameCube) to PS5 RetroArch, with support for up to 6× internal resolution through PS5_Vulkan. It also fixes save-state loading, frame pacing and several driver issues found while bringing Dolphin to the PS5.

✨ What's new​

  • Dolphin at up to 6× internal resolution. Lower the resolution in Quick Menu → Core Options if a game or setting is too demanding.
  • Resident Evil 4's large save state now loads without crashing. RetroArch's large buffers use a separate memory pool, leaving room for Dolphin's compiled code.
  • More even frame pacing in Wind Waker. Dolphin supplies one frame for each frame step, including repeated frames.
  • Fixed slowdown at 120 Hz. RetroArch can request five swapchain images when displaying each game frame twice. This removed a measured 4–12% speed loss in heavier settings.
  • Fixed a texture leak when reloading a core or changing video settings. Each reload had left behind two textures and 13 driver memory mappings.
  • FTP access to saves, states and configuration files. At launch, RetroArch sets directories under PPSA99169 to 0777 and files to 0666, including existing files. Files that previously returned 550 Permission denied are now accessible.
Link: https://github.com/mihawk-99/PS5_RetroArch/releases/tag/v0.3.0-alpha.3
Post automatically merged:

Twiso — PS2 ISO Launcher​

A native PlayStation 5 homebrew front-end that browses your PS2 ISOs and boots them through selectable PS2 emulator packages — all from a clean, PS5-styled UI.

Status: work in progress / experimental homebrew. Not affiliated with or endorsed by Sony. Requires a jailbroken console (see Requirements).
This repository ships no emulator runtimes and no packaged backends. It contains only the front-end, its build tooling, and documentation. You must supply your own emulator packages (see Bring your own backends).
Twiso main menu

Link: https://github.com/Swordpdf/Twiso/releases/tag/v01.00
Post automatically merged:

From our trusted developer Gezine:

Luac0re 2.4b​

Fixed PS4 14.00 socket error

Changelog 2.4
Fixed get_title_id crashing PS4

Changelog 2.3
Rewrote poops and p2jb to jit C
Now p2jb 2.0 runs under 1 hour
Deprecated GPU RW
Deprecated PS5 firmware specific offsets
Merged ufm42's kexp PS5 post JB all in one shellcode
Changed elfldr to official repo's 0.23 version

Read README for instruction
https://github.com/Gezine/Luac0re

Link: https://github.com/Gezine/Luac0re/releases/tag/2.4b
 
Last edited by HS2005,
  • Like
Reactions: schatzi24 and Inaki

Site & Scene News