Join Us and become a Member for a Verified Badge to access private areas with the latest PS4 PKGs.
PS4 Jailbreaking       Thread starter PSXHAX       Start date Feb 3, 2024 at 4:29 PM       14      
Status
Not open for further replies.
Following his BD-JB PS5 Userland Exploit 7.61 Firmware Revision, Security Researcher theflow0 confirmed via Twitter that he'll be giving a talk on CVE-2006-4304 (Remote Vulnerabilities in SPP) affecting PS4 up to FW 11.00 and PS5 up to FW 8.20 at the Moxy Seoul Myeongdong All Offensive Security Conference which runs from May 27th-31st, 2024 covering a PlayStation 4 Kernel Remote Code Execution (RCE) Exploit enabling a jailbreak without requiring a user entry (such as a WebKit) point. :geek:

This comes proceeding the PSFree WebKit Exploit Updates, Aapo's HackerOne PlayStation Hacktivity Critical Vulnerability Report, PS4PayloadSDK 10.50-11.02 Support update and recent CVE-2006-4304 PoC... with Andy Nguyen's presentation details outlined below courtesy of TyphoonCon.com:

PlayStation 4 Kernel RCE

Date: May 30-31
, 2024

Talk Overview:


This talk will be about successful exploitation of kernel vulnerabilities in a network protocol on the PlayStation 4 which is based on FreeBSD.

I show how internals of the IPv6 protocol can be abused to achieve an information leak and to redirect control flow to get RCE with kernel privileges on the console.

The exploitation strategies may also apply to XNU as they share very similar code. Moreover, this exploit enables a jailbreak without requiring a user entry point such as a WebKit exploit.


Finally, on the PS5 Research & Development general server @Al Azif asked in Discord, "Another IPv6 one?" with @flatz replying "yes" in Discord... to which @Al Azif's response was, "Oof, brutal. Time to shut off notifications everywhere lol" as noted by hhk2003_ via Twitter.
And where there are vulns there are exploits
The PS4 (up to FW 11.00) and PS5 (up to FW 8.20) were vulnerable to CVE-2006-4304: Remote vulnerabilities in spp. I'll share details about successful exploitation at TyphoonCon.
Thanks! Yeah, I also thought this one would be in critical scope ($50'000). I tried with Hacker0x01 mediation, but Sony just didn't want to pay more (and without explanation) :confused:
And those will call me traitor, sold-out and whatnot I guess :p
Should I wait then? :p
PlayStation 4 (PS4) Kernel RCE Talk by TheFloW0 at TyphoonCon 2024.png
 

Comments

I only have two dreams:

—The first one is challenging, and I don't hold too much hope for it —a Custom Firmware (CFW). I'm still on 5.05 because I'm unwilling to let go of hope. :coldsweat:

—The second dream is a jailbreak method that consistently works without causing my PS4 to shut down randomly now and then when applied. Maybe this new method without requiring a WebKit exploit can do it? :geek:
 
@Pretinaverse No and no, sorry. You are asking too much; you are lucky guys.

Flow still working on PS4, he should move to PS5 long time ago. PS4 ends on firmware 9.00 in my opinion make no sense to use the tools to keep going. Almost all games are being backported.
 
I hope this kernel rce gonna work for 8.xx consoles too.

I have a white slim laying in my closet with a broken bd and can't repair it because the renesas chip is dead.
 
anyone holding on to ps4s on OFW above 9.00 shouldn't all together lose hope however MUCH of the ps exploit scene has moved onto the ps5, but there is a slim chance that ps4 above 9.00 may get an exploit however i wouldn't hold my breath.

either sell your unexploitable consoles to fund a purchase of an actually exploitable console or hold on to it for however long. personally i dislike the etawen? people, but there's always gonna be 'em around.

i personally guarantee there are existing exploits available on higher fws than 9.00 however it will take dedication, trial and error, and a very keen knowledge of the FBSD core components used by 50ny in its consoles.

anyone who doesn't have the knowledge can learn how to id, and code for exploit scenarios found in implemented components found via reading through source code.

I will add tho i am quite interested in what thefl0w will have to say at this expo, and am fascinated to see what information he will divulge and how it could be utilized elsewhere.

also this itself wont mean higher fws will be exploitable via this information, as useful as this may be this is not a golden bullet.
 
Status
Not open for further replies.
Back
Top