Things are starting to get a bit interesting in the PlayStation 4 Hacking Scene, as well known hacker qwertyoruiop a couple of days ago released a webkit exploit for 4.0x firmware (non 4.50), however this exploit needs a kexploit (kernel exploit) on the same level as something like 1.76 firmware and did not work in 4.50. So the hacker has been working on a kernel exploit as well and in 5 days the developer has not only a kernel exploit but one that works for 4.50 but with 4.50 we do not have an entry point to execute the kernel exploit, which is where the webkit exploit comes in. So 4.50 user's appear has some strong hope , .
-
- Nothing to kernel in 5 days. GG sony
- 0day, it should work on 4.50 too
- It was actually simpler than expected. iOS is more challenging from the post exploitation point of view
- 30 hours of no sleep later i am finally happy about the ps4 exploit
- So it turns out sony is doing sneaky syscall shit. updated code some further, you'll have to manually call libkernel syscall stubs
- updated ps4 rce with actually functioning fcall and syscall primitives
- updated ps4 exploit with rop code exec (for 4.06 specifically).
- updated the ps4 exploit with some more comments and it no longer alerts a JSValue, but prints a function pointer
Last edited: