Tutorial  Updated

PS5 Exploit Guide

Latest OFW: 7.20 (19/04/23)
Highest PS5 OFW hackable: 4.51 (highest for Znulls new method)
Highest for Mast1c0re native code exec: 6.00 (unreleased)
Highest for Mast1c0re PS2 classics: 6.50 (relies on offsets)

First BD-J + Kernel access exploit provided by Sleirsgoevy (29/9/22)

Note: Though there are three USERLAND exploits and one KERNEL exploit, there are no public HYPERVISOR exploits available to complete the exploit chain, so there is no chance of HEN, and therefore no PS4/PS5 backup loading yet.

(Note: a hypervisor exploit is rumoured to be held in private that works on <2.50 firmware).

• 4.51 OFW for BD-JB entry point.
• 3.00/3.20/3.21/4.02/4.03/4.50/4.51 OFW for webkit entry point
• No firmware requirement for Mast1c0re PS2 classics entry point

NOTE: NEVER TURN ON IDU MODE

NOTE 2: Always stay on the lowest FW possible, if you are on 3.00-4.03 etc, don’t be tempted to update to 4.51 yet, stay as low as possible for now.

If you get stuck in a boot loop at the PS logo, this means the SNVS is corrupted (if hash check fails on boot this causes a “soft brick”).

DONT WORRY it’s not “bricked”, just reinstall your current firmwares RECOVERY PUP in safe mode!

USB: PS5 > UPDATE > PS5UPDATE.PUP

WEBKIT EXPLOIT:
Webkit > Kernel exploit chain for 3.00-4.51 via SpectreDev & ChendoChap:
https://github.com/Cryptogenic/PS5-4.03-Kernel-Exploit

https://github.com/ChendoChap/PS5-IPV6-Kernel-Exploit/tree/wip_branch

BD-JB EXPLOIT:
BD-JB > Kernel exploit chain for 4.51 via Sleirsgoevy:
https://github.com/sleirsgoevy/bd-jb/commit/159253464afde59c3007a706210bec65b91f38f3

PS2 CLASSICS EXPLOIT:
PS2 Classics > Userland > ?? via CTurt:
(Implementation by McCaulay)

Note: this is currently limited to swapping the loaded PS2 iso, or loading PS2 elf homebrew on PS5 (or PS4) for emulators or basic PS2 brew.

Mast1c0re PS2 exploit for PS2 homebrew:
https://cturt.github.io/mast1c0re.html

Mast1c0re part 2:
https://cturt.github.io/mast1c0re-2.html

Mast1c0re payload framework:
https://github.com/McCaulay/mast1c0re

Okrager save game exploit generator for Okage:
https://github.com/McCaulay/okrager

Mast1c0re payloader TCP Client GUI for PS5 6.50:
https://github.com/Master-s/PS4-PS5-Mast1c0re-Payloader/releases

TCP network ISO loader:
https://github.com/McCaulay/mast1c0re-ps2-network-elf-loader/releases

ExFat USB ISO loader:
(Coming soon)

PS5 version display payload by SiSTR0 (compiled by Logic-68):
https://github.com/logic-68/Portage_PS5Version_Mast1c0re/releases/tag/V1.0.0

Console/exploit information and updates:

PS5 FIRMWARE REPO:

https://darthsternie.net/ps5-firmwares/

PS5 SDK REPO:
https://github.com/PS5Dev

With debug setting you can install LEGIT PS5 game update pkg’s from:
https://prosperopatches.com/

You can also install free/demo PKGS (legit pkgs) via debug pkg installer, providing you have all the files/json/licences required.

https://github.com/TheOfficialFloW/Presentations/blob/master/2022-hardwear-io-bd-jb.pdf

https://github.com/sleirsgoevy/bd-jb

https://github.com/psxdev/bd-jb (NOTE: File listing working up to 5.10)

4.03 PAYLOADS:
RET.BIN (Hello world payload by Zeco): https://www17.zippyshare.com/v/awY1gGiJ/file.html

FTP.BIN (by Zeco)
https://www102.zippyshare.com/v/244hmTgp/file.html

4.5X PAYLOADS:
(Coming soon)

/System mount payload elf for BD-J:
https://gbatemp.net/download/remount-system-with-write-permissions.37807/

https://github.com/john-tornblom/ps5-payload-sdk

https://github.com/john-tornblom/bdj-sdk/actions/workflows/bdjb.yml
 
Last edited by KiiWii,

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,257
Trophies
3
XP
28,409
Country
United States
I think I'm going to take off until this evening. I've extended my brain too much over the past two days. btw, I got the amy mod to work on android for sonic mania. this new build with mods seems to work for those who had trouble, but afaik, the amy mod doesn't work without plus, so I can't upload it.
 

KiiWii

Editorial Team
OP
Editorial Team
Joined
Nov 17, 2008
Messages
15,112
Trophies
3
Website
defaultdnb.github.io
XP
22,521
Country
United Kingdom
FYI: PSVR2 can be updated offline.

The headset update is within the 7.00 update and so once you have updated via USB for example; plugging in the headset then prompts for the update.

I believe the format is MUP, within the PUP.
 
  • Like
Reactions: godreborn

Hayato213

..
Member
Joined
Dec 26, 2015
Messages
16,239
Trophies
1
Location
Aionios
XP
14,742
Country
United States
btw, speaking of controllers, do you know if it's possible to sync wirelessly? one thing I've never understand, up till now, about the ps5, is why you can't sync without plugging in the controller, yet a brooks adapter, nvidia shield, etc. can do so. that's pretty fucked up.

I think it has to do with how it get sync the first time, brook adapter still require you to sync with it the first time pairing it with the console you are using.
 

thekarter104

Well-Known Member
Member
Joined
Mar 28, 2013
Messages
1,932
Trophies
1
XP
2,647
Country
United States
Ah, I have to update. Still have a PSPlus Code lying around somewhere that I need to use before it goes to waste.

Glad I already own Okage shadow king, so I'm good.
 
Last edited by thekarter104,

smf

Well-Known Member
Member
Joined
Feb 23, 2009
Messages
6,414
Trophies
2
XP
5,371
Country
United Kingdom
@schatzi24 I think it’s a mount point trick.

I’m not 100% sure tbh.
From what I can tell from using google translate on his posts, it uses the 4.03 hyper visor exploit in a similar way to the original psjailbreak. The console requires an original disc in the internal drive, which is why it uses a usb bluray reader. With as you say a mount point trick.

I'm pretty convinced that anyone on >4.03 is going to be out of luck.
 

KiiWii

Editorial Team
OP
Editorial Team
Joined
Nov 17, 2008
Messages
15,112
Trophies
3
Website
defaultdnb.github.io
XP
22,521
Country
United Kingdom
From what I can tell from using google translate on his posts, it uses the 4.03 hyper visor exploit in a similar way to the original psjailbreak. The console requires an original disc in the internal drive, which is why it uses a usb bluray reader. With as you say a mount point trick.

I'm pretty convinced that anyone on >4.03 is going to be out of luck.
Hyper visor exploit?
 
  • Like
Reactions: schatzi24

KiiWii

Editorial Team
OP
Editorial Team
Joined
Nov 17, 2008
Messages
15,112
Trophies
3
Website
defaultdnb.github.io
XP
22,521
Country
United Kingdom
Well I might be wrong, The exploit was allegedly fixed "around 4.00", 4.03 is around 4.00.

Until it's released, I'm being pessimistic.

Firmware downgrade might be eventually possible.
Hmm I don’t think that any hyper visor exploit was made public though… I also thought it only applied to <2.50?
 
General chit-chat
Help Users
    tankioo @ tankioo: ok