Hacking What can we do ?

Ohad1th

Well-Known Member
OP
Member
Joined
Jul 23, 2015
Messages
250
Trophies
0
Age
28
XP
308
Country
Iceland
So I was just scrolling gbatemp and I saw this PS4 Hacking forum
What can we actually do as of now ?
probebly not download games lol but are there anything good we can do ? any good hacker to follow ?
new here any development on anything ? I'm currently on the latest version on my PS4
 
  • Like
Reactions: Margarine67
D

Deleted-355425

Guest
So I was just scrolling gbatemp and I saw this PS4 Hacking forum
What can we actually do as of now ?
probebly not download games lol but are there anything good we can do ? any good hacker to follow ?
new here any development on anything ? I'm currently on the latest version on my PS4

1.76 has private-ish kernel and web exploits
3.15 has web exploit.

Few in between also have web exploits.
 

spotanjo3

Well-Known Member
Member
Joined
Nov 6, 2002
Messages
11,145
Trophies
3
XP
6,215
Country
United States
Yes, mech is correct. By the way, for the more information following at:

The trust is: wololo, psx-scene, ps4hax, and ps3hax. Google those. I used them for a long time. Enjoy!
 
Last edited by spotanjo3,

CTurt

Well-Known Member
Member
Joined
May 3, 2015
Messages
73
Trophies
0
XP
317
Country
Publicly for 1.76 there is a WebKit exploit in the browser and 2 kernel exploits. The kernel exploits work a few versions above 1.76 but there is no public WebKit exploit to use them with.

If you are on 1.76 you can boot Linux right now without needing to compile or host anything yourself; it's as simple as placing 2 files on a FAT32 USB and visiting the live demo of PS4-playground.

No developers that I've ever spoken to have shown interest in running pirated games, so I wouldn't expect this to happen for a fairly long time.

For later firmwares there is little you can do unless you are a developer. You can run ROP chains in web apps which are statically compiled to outdated versions of WebKit, which is enough to test whether they are vulnerable to most kernel exploits, and you can do a few other things. These apps don't have permission to use the JIT system calls so they can't be used for full code execution unless you want to trigger a full kernel exploit with just ROP which is pretty hardcore (very difficult to do multi threading for example).

There are plenty of WebKit bugs which could be used to exploit the browser on the latest firmware for arbitrary code execution (http://webkitgtk.org/security/WSA-2016-0002.html http://webkitgtk.org/security/WSA-2016-0003.html) however the WebKit team won't publicly publish the details of these bugs, but they could be found by manually going through thousands of WebKit commits if you wanted.

Generally I wouldn't expect anything for latest firmware to be released until it has been patched though.

In terms of developers to follow, there's myself (http://twitter.com/CTurtE), who was first to publicly announce both kernel exploits, and I've published articles documenting them on my site (http://cturt.github.io/ps4-3.html and http://cturt.github.io/dlclose-overflow.html). But I don't have much interest in the PS4 at the moment. There's also kR105 (http://twitter.com/kr105rlz) who wrote most of the public Linux boot loader. Most other developers tend to prefer to work privately, so I won't add them here, but I've found wololo.net to be by far the most accurate site for PS4 hacking news which you should follow if you don't want to miss anything.

I hope this answered all of your questions.
 
Last edited by CTurt,

brickmii82

Well-Known Member
Member
Joined
Feb 21, 2015
Messages
1,442
Trophies
1
Age
41
XP
2,930
Country
United States
Publicly for 1.76 there is a WebKit exploit in the browser and 2 kernel exploits. The kernel exploits work a few versions above 1.76 but there is no public WebKit exploit to use them with.

If you are on 1.76 you can boot Linux right now without needing to compile or host anything yourself; it's as simple as placing 2 files on a FAT32 USB and visiting the live demo of PS4-playground.

No developers that I've ever spoken to have shown interest in running pirated games, so I wouldn't expect this to happen for a fairly long time.

For later firmwares there is little you can do unless you are a developer. You can run ROP chains in web apps which are statically compiled to outdated versions of WebKit, which is enough to test whether they are vulnerable to most kernel exploits, and you can do a few other things. These apps don't have permission to use the JIT system calls so they can't be used for full code execution unless you want to trigger a full kernel exploit with just ROP which is pretty hardcore (very difficult to do multi threading for example).

There are plenty of WebKit bugs which could be used to exploit the browser on the latest firmware for arbitrary code execution (http://webkitgtk.org/security/WSA-2016-0002.html http://webkitgtk.org/security/WSA-2016-0003.html) however the WebKit team won't publicly publish the details of these bugs, but they could be found by manually going through thousands of WebKit commits if you wanted.

Generally I wouldn't expect anything for latest firmware to be released until it has been patched though.

In terms of developers to follow, there's myself (http://twitter.com/CTurtE), who was first to publicly announce both kernel exploits, and I've published articles documenting them on my site (http://cturt.github.io/ps4-3.html and http://cturt.github.io/dlclose-overflow.html). But I don't have much interest in the PS4 at the moment. There's also kR105 (http://twitter.com/kr105rlz) who wrote most of the public Linux boot loader. Most other developers tend to prefer to work privately, so I won't add them here, but I've found wololo.net to be by far the most accurate site for PS4 hacking news which you should follow if you don't want to miss anything.

I hope this answered all of your questions.

Anyone else think this should be stickied FFR, til further progress is made?

@CTurt nice work sir.
 

ShinyGengar001

Active Member
Newcomer
Joined
Mar 1, 2016
Messages
40
Trophies
0
Age
32
XP
152
Country
Hey guys,

Quick question instead of updating my ps4 to go on the ps store. Can i use the app on my phone to trigger the download then go on my console for it to finish without updating. ( of course i know some games require higher ofw to play )

Cheers
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    Slower speeds for gen4
  • K3Nv2 @ K3Nv2:
    I'll reformat and have a 3tb raid0 m. 2 at least
    +1
  • K3Nv2 @ K3Nv2:
    Lmao that sold out fast
    +1
  • Veho @ Veho:
    Yeet the cat.
    +1
  • K3Nv2 @ K3Nv2:
    Good idea
    +1
  • The Real Jdbye @ The Real Jdbye:
    i thought everybody knew cocktails are like 75% ice
  • Veho @ Veho:
    Yeah but not like this.
  • Veho @ Veho:
    It's not like they're complaining that their Slurpee is 99% ice or something, but if the cocktail calls for "shot of vodka, shot of vermouth, shot of gin, shot of Campari, three shots of juice, squirt of lemon" and ends up being a thimbleful of booze, that's a problem.
  • The Real Jdbye @ The Real Jdbye:
    the funny thing is cocktails in norway are only allowed to have 1 20ml shot of booze
  • The Real Jdbye @ The Real Jdbye:
    so..... yeah
  • The Real Jdbye @ The Real Jdbye:
    we're used to only having a thimbleful of booze
  • Veho @ Veho:
    Booo.
  • The Real Jdbye @ The Real Jdbye:
    same thing if you want whisky on the rocks or something, you can't get a double
  • The Real Jdbye @ The Real Jdbye:
    but you could buy as many shots of whisky (or anything else) as you want and ask for a glass of ice and pour them in
  • The Real Jdbye @ The Real Jdbye:
    it's dumb
  • Veho @ Veho:
    Maybe.
  • Veho @ Veho:
    There was a comparison of the number of Ibuprofen poisonings before and after they limited the maximum dosage per box or per pill (i'll look that up). No limit on the number of boxes you can still buy as many as you want, so people argued it was pointless.
  • Veho @ Veho:
    But the number of (accidental) poisonings dropped because drinking an entire package of ibuprofen pills went from "I need a new liver" to "I need a new box of Ibuprofen".
  • Veho @ Veho:
    Here we have ketoprofen that used to be prescription-only because of the risk of toxic dosages, but then they halved the dose per pill and sell them in bottles of six pills apiece instead of twenty and it doesn't need a prescription any more. Yes you can buy more than one bottle but people simply don't.
  • Psionic Roshambo @ Psionic Roshambo:
    Usually accidentally overdose of ibuprofen here is from people taking like cold medicine then ibuprofen for a headache and the combination is over what they need
    Psionic Roshambo @ Psionic Roshambo: https://www.youtube.com/watch?v=1hp24nDVKvY