Category PS4 Jailbreaking       Thread starter PSXHAX       Start date Apr 21, 2016 at 9:12 PM       10,925       10            
Following news of the PS4 Dlclose Exploit for 1.76 and more recently the Entry Point findings, today Wololo reports that PlayStation 4 developer Fire30 made available a PS4 Webkit Exploit proof-of-concept for PlayStation 4 Firmware 2.XX.

Download: PS4-2014-1303-POC-master.zip / PS4-2014-1303-POC GIT

From the ReadMe file: CVE 2014-1303 Proof Of Concept for PS4

This repository contains a poc for the CVE 2014-1303 originally disclosed by Liang Chen. It has been tested to work on system firmware 2.03, but should work for systems on a firmware < 2.50, the ROP test will however only work on 2.03.

Usage

You need to edit the dns.conf to point to the ip address of your machine, and modify your consoles dns settings to point to it as well. Then run
Code:
python fakedns.py -c dns.conf
then
Code:
python server.py
Debug output will come from this process.

Navigate to the User's Guide page on the PS4 and various information should be printed to the console. The ROP test will print what is stored in the rsp register. Continuing execution after rsp is pivoted still needs to be done.

Acknowledgements

Liang Chen
thexyz
dreadlyei

Fire30 also notes, to quote: This implementation will not work on the vita as it uses a different memory allocator. In fact I am using the same exploit that is used in https://github.com/Hykem/vitasploit for 3.36, so that is the farthest this vulnerability will go.

Thanks to CnCore for the tip in the PSXHAX.COM Shoutbox! :D

CVE-2014-1303.jpg
 

Comments

Fimo

Senior Member
Contributor
Open the webkit..
Open the ofw...
Open the hdd...
Create the cfw...
Great ......
Jailbreak...
Bingo....
You're forgeting the most important part, the kernel exploit ! max 2.03 OFW for dlclose exploit and max 2.xx for the 80% completed badiret expoit.
 

mcmrc1

Senior Member
Contributor
Verified
and i think first we need keys to create a cfw and decrypt files and so one...

without keys no cfw if iam not wrong
 

Fimo

Senior Member
Contributor
What about 2.57 ?
- Badiret patch released on FreeBSD 9 (Orbis) = 2015-08-25
- 2.57 = Jully 2015
A JB may come soon for 2.03 with the dlclose exploit with the help of FIRE30.

A POC has been posted on twitter of POC 3.50 webkit exploit (twit deleted). With a Badiret exploit, there is still hope for a 2.57 (even 3.00 ?) Jailbreak.
 
Recent Articles
PS4 Kernel Fixup Script for IDA 7.0-7.2 Released by SocraticBliss
Following his PS4 Kernel Loaders and PS4 Name 2 NID Plugin, PlayStation 4 scene dev @SocraticBliss (Twitter) made available a PS4 Kernel Fixup Python Script (ps4_kernel_fixup.py) he's currently...
PlayStation Store Black Friday 2019 PSN Sale Begins Today!
We've seen the PlayStation Black Friday & Cyber Monday 2019 hardware deals, and today Sony unveiled their Black Friday 2019 PSN discounts offering savings up to 40% off on select PlayStation Store...
PlayStation VR Game Releases for the Holiday Season and Early 2020
With a PS VR 5-Game Bundle for $199 available this holiday season and Lost Ember by Mooneye Studios arriving today, here are some upcoming PlayStation VR game releases through early 2020 that...
Sony PS4 / PS3 Blu-ray Disc Drive Internals & Security by Oct0xor at 36c3
Last year they covered Exploiting PS4 Video Apps, and at the 36th annual Chaos Communication Congress (36c3) from December 27th to the 30th 2019 in Leipzig Germany scene developer @Octopus (aka...
Top