TheFlow has discovered a major exploit called bd-jb for PS3, PS4, and PS5, can be used to load game backups burned to discs

photo_2022-06-10_13-34-33.jpg

One of the PlayStation scene's most notable figures, TheFlow (Andy Nguyen), is back at it again. He's discovered a major exploit that affects not just one PlayStation console, but three. A hackerone report by TheFlow sheds light on five vulnerabilities that range in effectiveness, allowing users to load payloads that can be used to exploit the PlayStation 3, PlayStation 4, and even the PlayStation 5. The exploit is referred to as bd-jb, or the Blu-ray Disc Java Sandbox Escape, and was featured during a panel at this year's hardwear.io security conference.

Below are 5 vulnerabilities chained together that allows an attacker to gain JIT capabilities and execute arbitrary payloads. The provided payload triggers a buffer overflow that causes a kernel panic. Please consider each of the vulnerabilities individually. AFAIK, this is the first exploit chain that is being submitted to you :)

According to Nguyen's report, a UDF driver can cause an overflow on both the PS4 and the PS5. An exploit chain, aka bd-jb, can then be loaded as the payload as a burned Blu-ray disc. The hack, in summary, will allow users to burn physical discs of game backups, and then play them on their consoles. This affects PlayStation 4 consoles below OFW 9.50, and PlayStation 5 systems that are below OFW 5.0.

With these vulnerabilities, it is possible to ship pirated games on bluray discs. That is possible even without a kernel exploit as we have JIT capabilities.



TheFlow's panel that discusses the exploit in detail will be uploaded in "a few weeks". The full hackerone report and all of its technical details can be read about below.

Following the initial report, TheFlow made an update to his claims.



:arrow: Source
 

chrisrlink

Has a PhD in dueling
Member
Joined
Aug 27, 2009
Messages
5,572
Trophies
2
Location
duel acadamia
XP
5,796
Country
United States
This mf just open up Pandora's Box and this is gonna turn out to be the second coming of the "G-Hotz" saga. TheFlow better lawyer up, lol.
doubt that will happen he wouldn't disclose if Sony put him under an NDA sony's been gracious enough to allow hax after they are patched theres a reason SciresM didn't disclose fusee-geele directly to nintendo (he disclosed it to nvidia the chip maker or we'll never have that exploit EVER
 
  • Like
Reactions: urbanman2004

TomRiddle

Yare Yare Daze
Member
Joined
Nov 12, 2021
Messages
202
Trophies
0
Location
Hogwarts
XP
550
Country
Canada
Awesome but sad that Sony was able to patch it, imagine running homebrew on a playstation system while still being able to go online.

Yeah, homebrew is great but one of the biggest unfortunate disadvantages is that it's too risky for most to install cfw on PS5, let alone run backups if you still want online support.

Now don't get me wrong, it's still always possible to be careful but overall the better thing when hacking systems is to accept and be fine with the chance of loosing online support imo.
 
  • Like
Reactions: Marc_LFD

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,471
Trophies
3
XP
29,138
Country
United States
Yeah, homebrew is great but one of the biggest unfortunate disadvantages is that it's too risky for most to install cfw on PS5, let alone run backups if you still want online support.

Now don't get me wrong, it's still always possible to be careful but overall the better thing when hacking systems is to accept and be fine with the chance of loosing online support imo.
I agree. I personally don't think exploited consoles for any system should be online. it just ruins it for legit players often enough.
 

EnigmaExodus

Active Member
Newcomer
Joined
Feb 6, 2022
Messages
25
Trophies
0
Location
Earth
XP
51
Country
Belgium
So Sony didn't know one of the most basic things about Java's built in object serialization?

So many exploits revolve around that feature, it has so much power and you have to be really careful with it.
You have to remember this is coming from the same people who thought using a constant random-value for ECDSA signatures was a good idea...

https://media.ccc.de/v/27c3-4087-en-console_hacking_2010

Seemingly Sony is trying to play nice with hackers instead of DMCA/lawsuit bullshit from years past.
 
  • Like
Reactions: Marc_LFD

TomRiddle

Yare Yare Daze
Member
Joined
Nov 12, 2021
Messages
202
Trophies
0
Location
Hogwarts
XP
550
Country
Canada
I agree. I personally don't think exploited consoles for any system should be online. it just ruins it for legit players often enough.

I mean if you're specifically taking about people who abuse homebrew to cheat in online games then yeah, you have a point.

It sucks because those types of people are ruining online functionality for those who just want to hack their consoles for getting themes or whatever, so I still see why consoles ban you for putting cfw (although I mostly disagree with it).
 

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,471
Trophies
3
XP
29,138
Country
United States
I mean if you're specifically taking about people who abuse homebrew to cheat in online games then yeah, you have a point.

It sucks because those types of people are ruining online functionality for those who just want to hack their consoles for getting themes or whatever, so I still see why consoles ban you for putting cfw (although I mostly disagree with it).
well, there's that. I also don't think you should be able to sync trophies or achievements. it's unfair to have all the amenities of being legit when most do not even pay for games. it's a catch 22 really. you have to be willing to sacrifice certain aspects of the console if you're going to exploit it.
 

gudenau

Largely ignored
Member
Joined
Jul 7, 2010
Messages
3,882
Trophies
2
Location
/dev/random
Website
www.gudenau.net
XP
5,423
Country
United States
You have to remember this is coming from the same people who thought using a constant random-value for ECDSA signatures was a good idea...

https://media.ccc.de/v/27c3-4087-en-console_hacking_2010

Seemingly Sony is trying to play nice with hackers instead of DMCA/lawsuit bullshit from years past.

To be fair, there is more president for that stuff to fail now.

Plus this was submitted to a bug bounty website so it could be fixed.
 

chrisrlink

Has a PhD in dueling
Member
Joined
Aug 27, 2009
Messages
5,572
Trophies
2
Location
duel acadamia
XP
5,796
Country
United States
the worst part of hacker one anyone can submit a working exploit even if it isn't theres (good example is a former member on here that was blacklisted by a lot of devs for infiltrating teams and stealing exploit code and selling it to nintendo via hackerone
 
  • Wow
Reactions: Marc_LFD

CanIHazWarez

Well-Known Member
Member
Joined
Jan 21, 2016
Messages
371
Trophies
0
Age
32
XP
1,352
Country
United States
the worst part of hacker one anyone can submit a working exploit even if it isn't theres (good example is a former member on here that was blacklisted by a lot of devs for infiltrating teams and stealing exploit code and selling it to nintendo via hackerone
That's a problem. But also, the real worst part is that the exploits get patched :rofl:
 

Blavla

Well-Known Member
Member
Joined
Sep 20, 2020
Messages
248
Trophies
0
Age
33
XP
1,238
Country
Germany
This mf just open up Pandora's Box and this is gonna turn out to be the second coming of the "G-Hotz" saga. TheFlow better lawyer up, lol.
Why should he? He even sold that to Sony, (10K i think) he is alowed to share it after the sony patches it
 

Blavla

Well-Known Member
Member
Joined
Sep 20, 2020
Messages
248
Trophies
0
Age
33
XP
1,238
Country
Germany
yeah, sony is the one who decides whether an exploit can be disclosed to the public, so theflow0 won't be sued.
that is false. Typically, responsible disclosure guidelines allow vendors 60 to 120 business days to patch a vulnerability. Often, vendors negotiate with researchers to modify the schedule to allow more time to fix difficult flaws. After the responsible disclosure time he can do with it whatever he wants. That´s why Sony needs to patch it or ask the "researcher" for more time
 
  • Like
Reactions: Hayato213

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,471
Trophies
3
XP
29,138
Country
United States
that is false. Typically, responsible disclosure guidelines allow vendors 60 to 120 business days to patch a vulnerability. Often, vendors negotiate with researchers to modify the schedule to allow more time to fix difficult flaws
Not true. They cannot disclose exploits that are closed source.
 

Hayato213

Newcomer
Member
Joined
Dec 26, 2015
Messages
20,037
Trophies
1
XP
21,152
Country
United States
that is false. Typically, responsible disclosure guidelines allow vendors 60 to 120 business days to patch a vulnerability. Often, vendors negotiate with researchers to modify the schedule to allow more time to fix difficult flaws. After the responsible disclosure time he can do with it whatever he wants. That´s why Sony needs to patch it or ask the "researcher" for more time

Yup it says 60 - 120 days to patch it

https://www.techtarget.com/searchsecurity/definition/vulnerability-disclosure
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    I gotta raid0 these m.2s yay
  • BigOnYa @ BigOnYa:
    Do a raid10
  • K3Nv2 @ K3Nv2:
    That's tomorrow
    +1
  • Xdqwerty @ Xdqwerty:
    Yawn
  • BigOnYa @ BigOnYa:
    Damn Wal-Mart has 42" 4k TVs for only $150
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, i bet it will not fit inside your bedroom
  • BigOnYa @ BigOnYa:
    Yea here in North Korea, we are only allowed 1 19" tv per household. And the only channel we get is, MLT (Missile Launch Today)
    +1
  • K3Nv2 @ K3Nv2:
    @BigOnYa, doesn't fit in his bedroom he's American
    +1
  • BigOnYa @ BigOnYa:
    I hate ordering stuff online if I can go buy it somewhere close to me, and everywhere anymore will give you a discount only if you order it online, bs. Should be a discount if I go pick it up, not order online.
  • K3Nv2 @ K3Nv2:
    I love it for most things most stores you just shows the receipt online and they scan it
    +1
  • K3Nv2 @ K3Nv2:
    Makes it easy for incompetent restaurant staff that don't know how to hear an order
  • BigOnYa @ BigOnYa:
    Mostly for big purchases, I want it in my hands before I pay. Like a tv, I trust picking it up myself, before I'd trust it being sent thru mail/delivery. (Broken screen, etc) But yea if I can order online, then pickup at store is ok, but not all places offer that.
  • cearp @ cearp:
    > Like a tv, I trust picking it up myself, before I'd trust it being sent thru mail/delivery. (Broken screen, etc)

    Thing is, if you break it driving back to your house, it's your fault. But if the delivery driver damages it, it's not your fault.
    +1
  • K3Nv2 @ K3Nv2:
    Most people that haul big tvs have empty trucks or know enough not to set it face down
  • BigOnYa @ BigOnYa:
    Then I gotta send it back and wait another week or two. I have a pickup truck, with a extended cab, so no prob for me.
  • K3Nv2 @ K3Nv2:
    Most manufacturers pack it well enough where they aren't that dumb to let it happen
  • BigOnYa @ BigOnYa:
    They building a new Microcenter store near by me, is kinda scary. That's my favorite place, I'm like a kid in a candy store there.
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, what's a microcenter?
  • K3Nv2 @ K3Nv2:
    Cool I'll make you ship me stuff
    +1
  • K3Nv2 @ K3Nv2:
    Microcenter sells high quality microwaves
  • BigOnYa @ BigOnYa:
    Computer store basically, but they sell everything, like game systems, tvs , 3d printers, etc
    +1
  • K3Nv2 @ K3Nv2:
    I've seen i9/mobo deals for like 400
  • BigOnYa @ BigOnYa:
    Yea been itching to build a new pc, mine is like 3-4 years old, ancient in pc tech time.
  • K3Nv2 @ K3Nv2:
    That's still high tech to ancientboi
    K3Nv2 @ K3Nv2: That's still high tech to ancientboi