TheFlow has discovered a major exploit called bd-jb for PS3, PS4, and PS5, can be used to load game backups burned to discs

photo_2022-06-10_13-34-33.jpg

One of the PlayStation scene's most notable figures, TheFlow (Andy Nguyen), is back at it again. He's discovered a major exploit that affects not just one PlayStation console, but three. A hackerone report by TheFlow sheds light on five vulnerabilities that range in effectiveness, allowing users to load payloads that can be used to exploit the PlayStation 3, PlayStation 4, and even the PlayStation 5. The exploit is referred to as bd-jb, or the Blu-ray Disc Java Sandbox Escape, and was featured during a panel at this year's hardwear.io security conference.

Below are 5 vulnerabilities chained together that allows an attacker to gain JIT capabilities and execute arbitrary payloads. The provided payload triggers a buffer overflow that causes a kernel panic. Please consider each of the vulnerabilities individually. AFAIK, this is the first exploit chain that is being submitted to you :)

According to Nguyen's report, a UDF driver can cause an overflow on both the PS4 and the PS5. An exploit chain, aka bd-jb, can then be loaded as the payload as a burned Blu-ray disc. The hack, in summary, will allow users to burn physical discs of game backups, and then play them on their consoles. This affects PlayStation 4 consoles below OFW 9.50, and PlayStation 5 systems that are below OFW 5.0.

With these vulnerabilities, it is possible to ship pirated games on bluray discs. That is possible even without a kernel exploit as we have JIT capabilities.



TheFlow's panel that discusses the exploit in detail will be uploaded in "a few weeks". The full hackerone report and all of its technical details can be read about below.

Following the initial report, TheFlow made an update to his claims.



:arrow: Source
 

nikeymikey

This is now a Spiderman thread.........
Member
Joined
Nov 19, 2008
Messages
1,510
Trophies
1
XP
2,447
Country
United Kingdom
  • Like
Reactions: elm

codezer0

Gaming keeps me sane
Member
Joined
Jul 14, 2009
Messages
3,576
Trophies
2
Location
The Magic School Bus
XP
4,524
Country
United States
So this works for bd games on PS3 as well?

Also, considering it's still impossible to even source a PS5, I fully expect Sony to block this exploit on those as quickly (and sneakily) as possible.
 

Marc_LFD

Well-Known Member
Member
Joined
Nov 3, 2021
Messages
5,484
Trophies
1
Age
34
XP
8,870
Country
United States
I wonder what FW my PS5 is on. I've had it for months and never taken it out of the box yet. Haha.

It's not connected to the internet so you're safe it didn't automatically update.

Most sellers selling their PS4 or PS5 think having the latest firmware is a good idea. It actually devalues if a buyer is looking for a specific FW.
 

Marc_LFD

Well-Known Member
Member
Joined
Nov 3, 2021
Messages
5,484
Trophies
1
Age
34
XP
8,870
Country
United States
If he releases the exploit. The scene will be back on fire. Backup disks market will be alive again in a lot of countries!!

I guess people will be selling backup copies of PS5 games now. Good to be back to the PS1 and PS2 days.

You fellas not thinking they'll sell on eBay, right? Because those listings would be taken down due to being piracy.

Welp Blue ray drives are either 25gb or 50gb(super expensive). What games will fit there?
PS5 may use a mix of BD25/BD50 (number indicates the amount of GBs), but it's advertised as using UHD discs which are like 100GB.

good luck finding one that isn't a scalper :creep:

Back to burning games on expensive discs and having to buy an expensive UHD Disc Burner? I wouldn't.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    SylverReZ @ SylverReZ: You could say the same for a couple or so threads that used to be popular, I guess.