Hacking [Release] PS-Phive! (For PS4 FW 9.00) Exploit Host Menu

  • Thread starter Thread starter Leeful
  • Start date Start date
  • Views Views 191,243
  • Replies Replies 600
  • Likes Likes 43
It's all down to timing and the size of the code. Changing just onle little thing can screw things up. Its a very fine balance.
Thats why there is a delay in me releasing v3. I can have it running rock solid then I add just one little thing or remove just one little thing and it throws it off considerably.

After I am happy with the PS-Phive! v3 and released it I will try and make a basic GoldHEN 9v6 for people who want something simple.
Thanks for your work i hope if you have time to update PS-PHIVE for 6.72 version using PC SELFHOST with GOLDHEN
 
  • Like
Reactions: Leeful
What is ASLR? Is there any use to disable it at 9.00?
One use of having ASLR disabled is to reduce the time it takes for the webkit exploit to run.

ASLR (Address Space Layout Randomization) is used to increase the difficulty of finding and exploiting something in the memory.

For example, when ASLR is enabled the memory layout is randomized so it can take anything from 5 to 30 (or even more) seconds for the webkit exploit to to what it needs to do.

When ASLR is disabled the memory layout is not randomized so the webkit finds it much easier to do what it needs to do so it finishes a lot quicker.
 
One use of having ASLR disabled is to reduce the time it takes for the webkit exploit to run.

ASLR (Address Space Layout Randomization) is used to increase the difficulty of finding and exploiting something in the memory.

For example, when ASLR is enabled the memory layout is randomized so it can take anything from 5 to 30 (or even more) seconds for the webkit exploit to to what it needs to do.

When ASLR is disabled the memory layout is not randomized so the webkit finds it much easier to do what it needs to do so it finishes a lot quicker.
perfect, now I understand. Disabling ASLR is through a payload? I will test with myself my arduino sketch and esp32.

edit: in selfhost is the payload, I'm going to load it in my esp32 to test. Is it enough to launch it once or do you have to launch it every time you start the jailbreak?
 
Last edited by eemcmCL,
perfect, now I understand. Disabling ASLR is through a payload? I ask to be able to do tests with my arduino sketch and esp32.

edit: in selfhost is the payload, I'm going to load it in my esp32 to test. Is it enough to launch it once or do you have to launch it every time you start the jailbreak?
When ASLR is disabled it stays disabled until you reboot so you only need to run it once per boot.
I dont know it it stays disabled if you use and resume from rest mode, I have not tested that.

ASLR is automatically disabled when you load any of the later versions GoldHEN but it is not present in some older beta versions. So you can disable it with either just the payload or by loading GoldHEN.

As an exaple of disable ASLR in action you will notice that if you do not disable it the webkit times vary every time you run the webkit but after it is disabled it will always run in 3 seconds.
Sometimes it might be 10 seconds, depending on the exploit code used but you will notice the the webkit load time is always the same after ASLR is disabled.
 
  • Like
Reactions: susi91
When ASLR is disabled it stays disabled until you reboot so you only need to run it once per boot.
I dont know it it stays disabled if you use and resume from rest mode, I have not tested that.

ASLR is automatically disabled when you load any of the later versions GoldHEN but it is not present in some older beta versions. So you can disable it with either just the payload or by loading GoldHEN.

As an exaple of disable ASLR in action you will notice that if you do not disable it the webkit times vary every time you run the webkit but after it is disabled it will always run in 3 seconds.
Sometimes it might be 10 seconds, depending on the exploit code used but you will notice the the webkit load time is always the same after ASLR is disabled.

then every time you turn on the ps4 and start the jailbreak you would also have to launch the payload disable aslr (this is what I understood).

I thought that launching the payload once would disable alsr all time.

Anyway, I'll do some tests later.
 
  • Like
Reactions: Leeful
@Leeful
Hi
I really appreciate your hard work for making these hosts am just asking if it possible to make a manual method cause for some reason the auto method not working will for me i searched the internet for self hosting with the latest gh but i couldn't find one
thank you
 
Last edited by ace1112,
  • Like
Reactions: Leeful
@Leeful bro ist it true that too much payload on host occurs WebKit exploit loads slow and if has less payload WebKit exploit loads faster...
Yes, this can be an issue. It's because of the offline cache. Thats why I split the cache manifests into 2 seperate files to bypass the problem.:)
Post automatically merged:

@Leeful
Hi
I really appreciate your hard work for making these hosts am just asking if it possible to make a manual method cause for some reason the auto method not working will for me i searched the internet for self hosting with the latest gh but i couldn't find one
thank you
As with everthing, some things on the PS4 do not work as well for some people as they do for others.

One thing you could try is to change the timing when you press X after the popup notification appears.
Instead of pressing X after the notification has dissapeared, try pressing it when you first see it or 2 seconds after it appears or even wait a few seconds after it has gone.
 
Last edited by Leeful,
Yes, this can be an issue. It's because of the offline cache. Thats why I split the cache manifests into 2 seperate files to bypass the problem.:)
Post automatically merged:


As with everthing, some things on the PS4 do not work as well for some people as they do for others.

One thing you could try is to change the timing when you press X after the popup notification appears.
Instead of pressing X after the notification has dissapeared, try pressing it when you first see it or 2 seconds after it appears or even wait a few seconds after it has gone.
Great I thought so.. Genius knows all the problem and solved like Magician 👌🏆
 
  • Like
Reactions: Leeful
Just quick question , can we use DNS IP for browser jailbreak with this esp32s2 host ???

I mean without using your online host , fully non internet jailbreak like other esp32s2 host like kameleon or karo
 
Just quick question , can we use DNS IP for browser jailbreak with this esp32s2 host ???

I mean without using your online host , fully non internet jailbreak like other esp32s2 host like kameleon or karo
Its not an esp32s2 host. The esp is only used for the USBhax function.
 
disclaimer: for each host, the results will be different on each PS4... I've tried this host for several days... there was a bug when I wanted to turn off the PS4, what happened was that the PS4 didn't turn off and the indicator light kept flashing white...I waited for 10 minutes but the PS4 still doesn't turn off completely...in the end I unplugged the power cable...and this happened 2 times with the ESP method...goldhen v2.2.5b7...then when I was about to activate the Goldhen cheat manager the PS4 instead froze. .. maybe for the next ESP update it should be made separately with the payload stored on the ESP instead of just using the ESP as a substitute for a flash drive as a usbhax... and removing the notification box... the rest of this host is already very good... thank you Leeful
 
  • Like
Reactions: Leeful and ace1112
disclaimer: for each host, the results will be different on each PS4... I've tried this host for several days... there was a bug when I wanted to turn off the PS4, what happened was that the PS4 didn't turn off and the indicator light kept flashing white...I waited for 10 minutes but the PS4 still doesn't turn off completely...in the end I unplugged the power cable...and this happened 2 times with the ESP method...goldhen v2.2.5b7...then when I was about to activate the Goldhen cheat manager the PS4 instead froze. .. maybe for the next ESP update it should be made separately with the payload stored on the ESP instead of just using the ESP as a substitute for a flash drive as a usbhax... and removing the notification box... the rest of this host is already very good... thank you Leeful
The bug is in the esp not leeful's menu technically it can happen with any esp32 with or without the actual menu on the esp if it happens again try unplugging the esp and your ps4 should shutdown btw are you using the v2 esp with sleep?
 
  • Like
Reactions: laz305 and Leeful
yes...I used ESP V2 with sleep mode for 10 minutes...hopefully in V3 there will be an improvement for ESP mode...I like this host because it's stable...never had kernel panic when activating goldhen...just a bug as I explained above...
 
  • Like
Reactions: Leeful
As @Prb said, the bug is with the esp devices. If for whatever reason the esp device crashes while the PS4 is connected to it, it messes up the PS4's network causing it to hang either when you try and shut down or if you try and change your network connection.

I've noticed the same thing happen with esp8266 devices when they are connected to a PC. For some strange reason the connection just randomly disconnects and I have to manually reconnect to it.

BTW if your PS4 ever hangs or freezes whatever you are doing with it you never have to physically unplug the power cable. If you keep the power button pressed for 20-30 seconds it will always shut itself down.
 
Maybe it's a bug from ESP32 because when the ESP32 is attached to the PS4 I can't access the PS4 storage to view the savedata...it just loads it then I unplug the ESP32 and I can access the savedata on my PS4...and I just found out if I press the button for 30 seconds power can turn off ps4...😁...BTW your host is indeed better than other hosts for my ps4...thank you very much
 
  • Like
Reactions: Leeful
Hi,

I have tried the the new PS-Phive!_ESP32-S2_bin_v2.0 on my board ESP32-S2 but I cannot get it working at all (sure I'm doing something wrong...)

I can connect to the WIFI PS-Phive! , I can access to config menu and see the configuration using the PC or PS4, but
when I have open on the PS4 the browser and I'm connected online to the url: prb123.ir/ps-phive

the wektit exploit start, the message for insert usb is showed, and I have to press 'X' and then the message error 'kernal ahead is corrupted... reboot ...etc..' is showed but seems that the usb of my S2 has not been detected...

If instead of connect to my home wifi (only option), I have connected to PS-Phive! AP (offline option), and use the prb123.ir/ps-phive , then the error is that the server/url cannot be found.

I am bit lost here, can someone have idea what I'm doing wrong?
this new menu PS-Phive!_ESP32-S2_bin_v2.0 have to work online or off-line like almost all other menu for S2?
Post automatically merged:



Finally I have got this GREAT menu working!!!

The issues that I had with this menu can happen anyone, especially if you are testing different menus, GH versions, etc...

Maybe @Leeful can complete the original instructions with a few notes, especially if the menu no work at the first time (that has happened to me...)

OK, how I resolved it (below the original instructions with a minor update):

1. Download and flash the PS-Phive! ESP32-S2 bin file to your ESP32-S2 device using NodeMCU PyFlasher. (link below)

1-B. Open the PS4 Browser and go Options => Delete Cookies and Clear WebSite Data.

1-C. On the below point 2, choose the Online Host URL, so open the browser and go to the corresponding URL that actually is: prb123.ir/ps-phive

2. Install the PS-Phive! menu on your PS4 by either using the PC SelfHost files or the online host URL. (links below)

2-B. After install the menu in cache, close the browser with the circle button (only one time click) and go back to the main PS4-Menu.

3. When the PS-Phive! menu has finished installing on your PS4, plug in your ESP32-S2 and setup a new
Internet connection on your PS4: Use Wi-Fi > Easy > PS-Phive! > password: 12345678

4. After the Set Up Internet Connection is complete press back and go to View Connection Status
and make sure that it has connected and you have an IP address.

All Done. You can now go back to the browser and use the PS-Phive! menu.

5. Final Step: After the setup and with the PS-Phive! menu working fine and before shut-down your PS4, you should create a bookmark for the next time to open PS-Phive! menu by ESP32-S2 with the below url:

http://prb123.ir/ps-phive/v2/index.html

because the url used by the setup on the step 1-C will no work more with ESP32-S2 mode..


Final Note and the most important: Follow the previous instructions in the correct order and don't change or skip any step, because if you skip or change the order and after that you try to follow correct steps, even doing it correctly the second time, it maybe can no work until you reboot the PS4 and start again with the correct instructions/steps.

Btw: I have discovered all this after dozen trial and error tries.
 
Last edited by xZenithy,
  • Like
Reactions: b0li and Leeful

Site & Scene News

Popular threads in this forum