Tutorial  Updated

PS5 Exploit Guide

Latest OFW: 7.20 (19/04/23)
Highest PS5 OFW hackable: 4.51 (highest for Znulls new method)
Highest for Mast1c0re native code exec: 6.00 (unreleased)
Highest for Mast1c0re PS2 classics: 6.50 (relies on offsets)

First BD-J + Kernel access exploit provided by Sleirsgoevy (29/9/22)

Note: Though there are three USERLAND exploits and one KERNEL exploit, there are no public HYPERVISOR exploits available to complete the exploit chain, so there is no chance of HEN, and therefore no PS4/PS5 backup loading yet.

(Note: a hypervisor exploit is rumoured to be held in private that works on <2.50 firmware).

• 4.51 OFW for BD-JB entry point.
• 3.00/3.20/3.21/4.02/4.03/4.50/4.51 OFW for webkit entry point
• No firmware requirement for Mast1c0re PS2 classics entry point

NOTE: NEVER TURN ON IDU MODE

NOTE 2: Always stay on the lowest FW possible, if you are on 3.00-4.03 etc, don’t be tempted to update to 4.51 yet, stay as low as possible for now.

If you get stuck in a boot loop at the PS logo, this means the SNVS is corrupted (if hash check fails on boot this causes a “soft brick”).

DONT WORRY it’s not “bricked”, just reinstall your current firmwares RECOVERY PUP in safe mode!

USB: PS5 > UPDATE > PS5UPDATE.PUP

WEBKIT EXPLOIT:
Webkit > Kernel exploit chain for 3.00-4.51 via SpectreDev & ChendoChap:
https://github.com/Cryptogenic/PS5-4.03-Kernel-Exploit

https://github.com/ChendoChap/PS5-IPV6-Kernel-Exploit/tree/wip_branch

BD-JB EXPLOIT:
BD-JB > Kernel exploit chain for 4.51 via Sleirsgoevy:
https://github.com/sleirsgoevy/bd-jb/commit/159253464afde59c3007a706210bec65b91f38f3

PS2 CLASSICS EXPLOIT:
PS2 Classics > Userland > ?? via CTurt:
(Implementation by McCaulay)

Note: this is currently limited to swapping the loaded PS2 iso, or loading PS2 elf homebrew on PS5 (or PS4) for emulators or basic PS2 brew.

Mast1c0re PS2 exploit for PS2 homebrew:
https://cturt.github.io/mast1c0re.html

Mast1c0re part 2:
https://cturt.github.io/mast1c0re-2.html

Mast1c0re payload framework:
https://github.com/McCaulay/mast1c0re

Okrager save game exploit generator for Okage:
https://github.com/McCaulay/okrager

Mast1c0re payloader TCP Client GUI for PS5 6.50:
https://github.com/Master-s/PS4-PS5-Mast1c0re-Payloader/releases

TCP network ISO loader:
https://github.com/McCaulay/mast1c0re-ps2-network-elf-loader/releases

ExFat USB ISO loader:
(Coming soon)

PS5 version display payload by SiSTR0 (compiled by Logic-68):
https://github.com/logic-68/Portage_PS5Version_Mast1c0re/releases/tag/V1.0.0

Console/exploit information and updates:

PS5 FIRMWARE REPO:

https://darthsternie.net/ps5-firmwares/

PS5 SDK REPO:
https://github.com/PS5Dev

With debug setting you can install LEGIT PS5 game update pkg’s from:
https://prosperopatches.com/

You can also install free/demo PKGS (legit pkgs) via debug pkg installer, providing you have all the files/json/licences required.

https://github.com/TheOfficialFloW/Presentations/blob/master/2022-hardwear-io-bd-jb.pdf

https://github.com/sleirsgoevy/bd-jb

https://github.com/psxdev/bd-jb (NOTE: File listing working up to 5.10)

4.03 PAYLOADS:
RET.BIN (Hello world payload by Zeco): https://www17.zippyshare.com/v/awY1gGiJ/file.html

FTP.BIN (by Zeco)
https://www102.zippyshare.com/v/244hmTgp/file.html

4.5X PAYLOADS:
(Coming soon)

/System mount payload elf for BD-J:
https://gbatemp.net/download/remount-system-with-write-permissions.37807/

https://github.com/john-tornblom/ps5-payload-sdk

https://github.com/john-tornblom/bdj-sdk/actions/workflows/bdjb.yml
 
Last edited by KiiWii,

Tomato123

Well-Known Member
Member
Joined
Feb 8, 2020
Messages
681
Trophies
1
Location
England
XP
2,082
Country
United Kingdom
Without rwx I won't torture my PS5 at this point. And with a success rate as low as 30%... My PS4 hated FW 7.02 with all the crashes and forced reboots. ;) But I will stay on 4.03 for now.
That's honestly for the best. There isn't any reason to use this as an end-user. Maybe in the future, but not right now.
 

linuxares

The inadequate, autocratic beast!
Global Moderator
Joined
Aug 5, 2007
Messages
11,082
Trophies
2
XP
14,497
Country
Sweden
Does this atleast give us the possibility to start dumping games? For preservation never the less.
I wish the Xbox X and Series also get hacked for preservation sake.
 

spoggi

Well-Known Member
Member
Joined
Jun 5, 2020
Messages
378
Trophies
0
Age
49
XP
863
Country
Denmark
Too bad there are never enough interest from people in the Xbox scene, that why the Xbox one never got hacked.
I read somewhere that is was because Microsoft threatened the hackers with jail sentence
if they tried to jailbreak the Xbox one
 

jme2712

Active Member
Newcomer
Joined
Feb 17, 2009
Messages
29
Trophies
1
XP
225
Country
United States
I read somewhere that is was because Microsoft threatened the hackers with jail sentence
if they tried to jailbreak the Xbox one
Dev mode or what ever they call it on Xbox allows HB too so no need for it to be hacked by those in the know because they mainly only support HB and not piracy
 

anibabu

New Member
Newbie
Joined
Sep 24, 2020
Messages
3
Trophies
0
Age
38
XP
92
Country
Canada
I ran the exploit using the Echo Stretch host and it kernel panicked my 4.03 PS5 as expected, but when I turn on the PS5 afterwards it goes to the "repairing console storage" page, reaches 100%, restarts and the PS logo appears on screen, after about 30 seconds it goes to a black screen with a blinking blue light on the PS5, then it stays like that for about 20 minutes and then turns off automatically, and repeats the same thing if I try turning it on again. Has anyone else experienced something like this after running the exploit?
 
  • Sad
Reactions: Tomato123

Tomato123

Well-Known Member
Member
Joined
Feb 8, 2020
Messages
681
Trophies
1
Location
England
XP
2,082
Country
United Kingdom
I ran the exploit using the Echo Stretch host and it kernel panicked my 4.03 PS5 as expected, but when I turn on the PS5 afterwards it goes to the "repairing console storage" page, reaches 100%, restarts and the PS logo appears on screen, after about 30 seconds it goes to a black screen with a blinking blue light on the PS5, then it stays like that for about 20 minutes and then turns off automatically, and repeats the same thing if I try turning it on again. Has anyone else experienced something like this after running the exploit?
This is why warnings were given out. You can try this but if it doesn't work you might have a permanent brick.
 

schatzi24

Well-Known Member
Member
Joined
Apr 25, 2018
Messages
252
Trophies
0
XP
1,686
Country
Italy
Great only 2 attempts and debug settings.
Can not install any PS4 Fpgk,only error:unsure:
 

Attachments

  • 20221004_173029.jpg
    20221004_173029.jpg
    1.6 MB · Views: 26

Prb

Well-Known Member
Member
Joined
Nov 10, 2020
Messages
1,018
Trophies
1
XP
3,709
Country
United Kingdom
Great only 2 attempts and debug settings.
Can not install any PS4 Fpgk,only error:unsure:
Even if the could install the fpkg's you still can't load them ps5 has no hen just because it has an exploit doesn't mean pirate games or even retail pkgs atm
We still need the hv to be exploited and then hen this may still be a long way off
 
  • Like
Reactions: Mentelos and KiiWii
General chit-chat
Help Users
    tankioo @ tankioo: ok