TheFlow has discovered a major exploit called bd-jb for PS3, PS4, and PS5, can be used to load game backups burned to discs

photo_2022-06-10_13-34-33.jpg

One of the PlayStation scene's most notable figures, TheFlow (Andy Nguyen), is back at it again. He's discovered a major exploit that affects not just one PlayStation console, but three. A hackerone report by TheFlow sheds light on five vulnerabilities that range in effectiveness, allowing users to load payloads that can be used to exploit the PlayStation 3, PlayStation 4, and even the PlayStation 5. The exploit is referred to as bd-jb, or the Blu-ray Disc Java Sandbox Escape, and was featured during a panel at this year's hardwear.io security conference.

Below are 5 vulnerabilities chained together that allows an attacker to gain JIT capabilities and execute arbitrary payloads. The provided payload triggers a buffer overflow that causes a kernel panic. Please consider each of the vulnerabilities individually. AFAIK, this is the first exploit chain that is being submitted to you :)

According to Nguyen's report, a UDF driver can cause an overflow on both the PS4 and the PS5. An exploit chain, aka bd-jb, can then be loaded as the payload as a burned Blu-ray disc. The hack, in summary, will allow users to burn physical discs of game backups, and then play them on their consoles. This affects PlayStation 4 consoles below OFW 9.50, and PlayStation 5 systems that are below OFW 5.0.

With these vulnerabilities, it is possible to ship pirated games on bluray discs. That is possible even without a kernel exploit as we have JIT capabilities.



TheFlow's panel that discusses the exploit in detail will be uploaded in "a few weeks". The full hackerone report and all of its technical details can be read about below.

Following the initial report, TheFlow made an update to his claims.



:arrow: Source
 

KuntilanakMerah

Well-Known Member
Member
Joined
Dec 14, 2021
Messages
203
Trophies
0
Age
26
XP
272
Country
Australia
i hope on the ps5 have the same method use disc to gain access to its root and then you can install homebrew exploit like on the ps3 hen / ps2 fmcb
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Skv0ra @ Skv0ra:
    or Nivera
  • K3Nv3 @ K3Nv3:
    Can hit 258Mph needs a days charge for half a mile
  • Skv0ra @ Skv0ra:
    How fast do those microwaves cook food?
  • Skv0ra @ Skv0ra:
    and can I refill the range in 5 min?
  • Skv0ra @ Skv0ra:
    lmao
  • Veho @ Veho:
    Drag a metal pot behind the car and the friction will boil water in a few seconds prolly.
    +1
  • K3Nv3 @ K3Nv3:
    Imagine out running the cops in a EV
    +1
  • Skv0ra @ Skv0ra:
    For, how many seconds?
  • K3Nv3 @ K3Nv3:
    Not only is my EV fast I can also use the tires for popcorn
    +1
  • Skv0ra @ Skv0ra:
    no replacement for displacement
  • K3Nv3 @ K3Nv3:
    Gta6: dead battery mission
    +1
  • Skv0ra @ Skv0ra:
    drag the car using 30 friends using ropes to the closest junk yard
  • Skv0ra @ Skv0ra:
    QWOP style
  • K3Nv3 @ K3Nv3:
    Couple neighbors went out and bought e Chevy bolt together so tempting to unplug their little charge oops I tripped
  • Veho @ Veho:
    THE FUTURE
  • Veho @ Veho:
    Is styrofoam EVs apparently.
  • K3Nv3 @ K3Nv3:
    Oh good Styrofoam won't expload it'll just melt
  • Skv0ra @ Skv0ra:
    they're already styrofoam
  • K3Nv3 @ K3Nv3:
    Those home chargers are so dumb can't even use an extension cord with them
  • Skv0ra @ Skv0ra:
    so, battery will leak invisible hot fumes and lithium that will melt the foam ALL over your meaty, baggy body
  • Skv0ra @ Skv0ra:
    i call it a GREAT solution to existence of CA
  • K3Nv3 @ K3Nv3:
    California EV made with all reused homeless people
    K3Nv3 @ K3Nv3: California EV made with all reused homeless people