Join Us and become a Member for a Verified Badge to access private areas with the latest PS4 PKGs.
Status
Not open for further replies.
Another Festivus miracle... proceeding the PS4 9.00 Payloads, Caturday arrived early for the PS4Scene as ChendoChap (BTC: bc1qswmgpt7akstzrsudefjj88e7caxgmqfaxt59rf) just released the PS4 9.00 Jailbreak Exploit dubbed POOBS4 following @sleirsgoevy's PS4 9.00 Webkit Exploit for use in PlayStation 4 Jailbreaking consoles up to PS4 9.00 OFW as @SpecterDev confirmed it was patched in 9.03 PS4 OFW... to reiterate, this means if you update your PlayStation 4 console software above 9.00 you will NOT be able to jailbreak it at this time! 🎄 :kitty:

Also released in conjunction with today's pOOBs4 PS4 9.00 Kernel Exploit and PS4 Payloads for 9.00 Firmware are a Mira ELF / Loader for enabling homebrew (ELF: port 9021, Loader: port 9020) via SpecterDev and a GoldHEN 9.00 PS4 Payload via _AlAzif to run the latest PS4 PKG Games (Part II). :tree: :santa:

Download: pOOBs4-main.zip (22.6 KB - includes exfathax.img) / GIT / 9.00 Host Live Demo / 9.00 Host GIT / Mira 9.00.zip (116 KB - includes Mira_Orbis_MIRA_PLATFORM_ORBIS_BSD_900.elf and MiraLoader_Orbis_MIRA_PLATFORM_ORBIS_BSD_900.bin) / payloads (3.50.9.00).zip (223.66 KB) / goldhen_2.0b_900.bin (224 KB - Fixed) / ps4-dumper-vtx-900.bin / Al Azif's DNS Exploit Menu IPs / PS4JB pOOBs4 for 9.00 with GoldHEN Autoload / 9.00_kernel.bin (20.08 MB) / USBHack.zip (6.23 KB - includes USBHack.img - a better? image file for USB drives to replace exfathax.img) per mrdude, to quote:

Here you go people, I have created a better image file for your usb drives to replace exfathax.img. This is better for the following reasons:

With exfathax.img there is an error dispalyed on the ps4 because the exfat file system doesn't exist and the ps4 can see that there is an error in the usb file system. I have created a new image which fixes this error and has a very tiny exfat partition only a few bytes, but stil shows up on pc without the need to format error. This also stops the usb error message showing up on the ps4. This should make booting into the hack easier.

To use - just use win32diskimager to write to the image to your usb drive. You can also create a partition on the existing space on your usb drive and use that on the ps4 for installing pkg files.

I tried to post this on poobs4 github but there's no way to post on that page, so I'll release here and someone can pass it on.

Spoiler: Depreciated

:alert: Those interested in exploiting their 9.00 or below PlayStation 4 console can either use @Al Azif's DNS IPs above or host it yourself following the previous guides linked below, keeping in mind our stance on clone hosts remains the same on the forums here... spam them and get banned.
⚠️ Below is pOOBs4's README.md... this requires a specially formatted USB device (ExFAT Bug also affects PS5 🥳) so read it VERY CAREFULLY to ensure developers including Al Azif aren't inundated with questions already covered... @RF0oDxM0Dz reports stability is similar to 5.05 and "better than 6.72 and 7.xx" with @Al Azif stating the success rate from feedback is "already is a world of difference from 6.72, 7.02, and 7.5X" so without further ado:

PS4 9.00 Kernel Exploit

Summary


In this project you will find an implementation that tries to make use of a filesystem bug for the PlayStation 4 on firmware 9.00. The bug was found while diffing the 9.00 and 9.03 kernels. It will require a drive with a modified exfat filesystem. Successfully triggering it will allow you to run arbitrary code as kernel, to allow jailbreaking and kernel-level modifications to the system. will launch the usual payload launcher (on port 9020).

Patches Included

The following patches are applied to the kernel:
  1. Allow RWX (read-write-execute) memory mapping (mmap / mprotect)
  2. Syscall instruction allowed anywhere
  3. Dynamic Resolving (sys_dynlib_dlsym) allowed from any process
  4. Custom system call #11 (kexec()) to execute arbitrary code in kernel mode
  5. Allow unprivileged users to call setuid(0) successfully. Works as a status check, doubles as a privilege escalation.
  6. (sys_dynlib_load_prx) patch
  7. Disable delayed panics from sysVeri
Short how-to

This exploit is unlike previous ones where they were based purely in software. Triggering the vulnerability requires plugging in a specially formatted USB device at just the right time. In the repository you'll find a .img file. You can write this .img to a USB using something like Win32DiskImager.

Note: This will wipe the USB drive, ensure you select the correct drive and that you're OK with that before doing this

POOBS4 PS4 9.00 Jailbreak Exploit via ChendoChap with Updated Payloads! 2.png

When running the exploit on the PS4, wait until it reaches an alert with "Insert USB now. do not close the dialog until notification pops, remove usb after closing it.". As the dialog states, insert the USB, and wait until the "disk format not supported" notification appears, then close out of the alert with "OK".

It may take a minute for the exploit to run, and the spinning animation on the page might freeze - this is fine, let it continue until an error shows or it succeeds and displays "Awaiting payload".

Notes
  • You need to insert the USB when the alert pops up, then let it sit there for a bit until the ps4 storage notifications shows up.
  • Unplug the USB before a (re)boot cycle or you'll risk corrupting the kernel heap at boot.
  • The browser might tempt you into closing the page prematurely, don't.
  • The loading circle might freeze while the webkit exploit is triggering, this means nothing.
  • This bug works on certain PS5 firmwares, however there's no known strategy for exploiting it at the moment. Using this bug against the PS5 blind wouldn't be advised.
Contributors
Special Thanks
🌀 Twitter Tweets
Spoiler: PS4 Alternative USB Flash Drive Method by SMD

:idea: Finally, if you haven't done so yet check out both the Downloading PS4 PKG Games That Are Base64 Encoded or Torrents Guide and PS4 Fake PKG (FPKG) Sharing Guide to become Verified via the 'floating' Discord Channel and get your Blue Verified Badge for the latest PS4 Game PKGs! 🏴‍☠️
POOBS4 PS4 9.00 Jailbreak Exploit via ChendoChap with Updated Payloads!.png
 

Comments

@kingpinrules Thank You for clarification but there is not need to run backported games on 9.00. If any problems he needs to re-download the games and running them as normal w/o any backport. As I said, 100 Ps4 owners will have a different results either running the games or running the jailbreak.
 
I want to thank the devs for this it has been a good jb process and works almost every time. My only problem is dumping games and not working properly and only taking a few seconds and to say it’s finished
 
@nikeymikey
I have a JB'ed Playstation 4 Slim on 6.72 and backporting is cumbersome yes. Though I've always managed to install content, not once I have bumped into an unsolvable issue. So far 7 fails out of 60 tries. I also have another recently JB'ed Ps4 Pro on 9.00. I have it just to play more recent games (EE Village, TLOUP II) I don't play online multiplayer games, so I JB'ed it.

So far the only thing that I've been uncapable of installing is the Bloodborne GOTY 720p 60 Fps Patch. The JB has gave me one kernel panic, and has soft-failed to open the usb insert window like seven times the second try and I managed to launch it afterwards by just closing and reopening the web browser. The first kernel panic may have been prompted by a precocious removal of the usb out of excitement lol, from then on, it hasn't failed once out of four tries, but I wont update my 6.72 console yet.

I'm going to wait until Elden Ring is released which i suspect will be released on a higher firmware, if so I will update my pro to play that game and then maybe I consider updating the slim.

I've found that recent games aren't getting too much optimization for Pro consoles (now that's upsetting) so the difference on non 4K displays aren't that noticeable besides framerate improvements that have become more and more scarce with the Ps5 entering the scene. Though I prefer to play on my Pro whenever I can, and the SsD does make load times quicker.

Anyway thank you Sir for your suggestion. Cheers to you all, have great holydays!
 
Biggest issue I had was a dodgy bluray ribbon causing the flash to fail. 100% success rate on the exploit so far. Amazing work.

Now just need ps4debug.bin to be updated and we're golden.
 
Status
Not open for further replies.
Back
Top