Category PS4 Jailbreaking       Thread starter PSXHAX       Start date Mar 30, 2018 at 12:13 AM       27,457       70            
Earlier this month we saw the PS4 4.55 WebKit Exploit Write-up by PlayStation 4 developer @SpecterDev, and now he announced on Twitter that he's added the PS4 4.55 / FreeBSD BPF kernel exploit writeup to his GitHub repository crediting qwertyoruiop and stating: "The bug is present on any system running FreeBSD such that you have privileges (which we did on PS4). Could be used on other systems for root to ring0 code execution."

Below is an excerpt from it, with the full documentation available on the Github Repo for those interested in learning more about it! :geek:

To quote: Conclusion

This was a pretty cool bug to exploit and write-up. While the bug is not incredibly helpful on most other systems as it cannot be exploited from an unprivileged user, it is still valid as a method of going from root to ring0 code execution.

I thought this would be a cool bug to write-up (plus I love writing them anyway) as the attack strategy is fairly unique (using a race condition to trigger an out-of-bounds write on the stack). It's also a fairly trivial exploit to implement, and the strategy of overwriting the return pointer on the stack is an easy method for learning security researchers to understand.

It also highlights how while an attack strategy may be old, perhaps this one being the oldest there is - they can still be applied in modern exploitation with slight variations.

Credits
References
Thanks to Edark knight for the heads-up on this earlier today in the forums. (y)
PS4 4.55 BPF Race Condition Kernel Exploit Writeup by SpecterDev.jpg
 

Comments

Recent Articles
Redbox Video Game Rentals to End This Year, Game Sales by Early 2020
As GameStop reported massive financial losses and announced the closing of more stores this year, it appears Redbox is getting out of the video game rental business by the end of 2019... they'll...
Horizon: Zero Dawn Camera PS4 Hacks Demo by ManFightDragon
Proceeding his P.T. Silent Hills Demo Camera PS4 Hacks and MHW: Iceborne x Horizon Zero Dawn: The Frozen Wilds, PlayStation 4 video game hacker @manfightdragon is back with a Horizon: Zero Dawn...
Minecraft Bedrock Version on PS4 Features Cross-Play and Marketplace
Back in October we reported that PS4 Cross-Play exited the Beta stage and was available to all PlayStation 4 developers, and today Mojang officially announced that the Minecraft Bedrock Version...
Open World Co-op RPG Ashen Joins New PS4 Game Releases Next Week
Among the new PS4 video game releases next week is open world co-op action RPG Ashen by A44 and Annapurna Interactive where you play a wanderer in search of a place to call home. In Ashen you'll...
Top