PS4 PS4 Jailbreak 7.02 is now a reality, but various things (like Mira) still need ported to 7.02

When we seen the PS4 6.72 Jailbreak go live from theflow0 's disclosure of a kernel exploit, we knew from reading his reasearch that his findings could work upto 7.02 OFW, but 6.72 OFW became the candidate because the kxploit needed an entry point as well. Thanks to Fire30's previous webkit exploit release to the public, 6.72 then having the complete puzzle that was the natural progression from the previous 5.05 Jailbreak.

Now we have seen developer sleirsgoevy release the needed webkit exploit for 7.02, so now we have the complete puzzle to begin the porting and jailbreaking of the console. Mira and various other things will need to be ported before this new PlayStation 4 Jailbreak is useful but that is the easy work compared to what has been released and is available to us, with a bit of time and patients from the community it appears that 7.02 OFW is the next PS4 jailbreak. This is not a huge jump from 6.72 but should allow for a few more games to be playable on a jailbroken and give user's a few more options when seeking a console to jailbreak. Hackers and developer's are moving up the ladder, but there is still work to be done on 7.02 before its time to consider an update and leave a more polished jailbreak, then for one that is still a work in progress.

landscape-1473282180-p1018211.JPG


Now the developer is trying to get Mira ported & working on the new jailbreak, there has been some progress.. After the dev discovered an issue he accidentally introduced, he was able to get Mira working on 7.02, but there is more test as getting it to run is only part of the war but that battle has been solved. Now, testing homebrew launching and other elements will be next. So stay tuned at the 7.02 jailbreak evolves!!!

  • via twitter
    7.02 Full Stack, let the fun begin :) https://github.com/ChendoChap/ps4-ipv6-uaf
    Many Thanks to Chendo, @Znullptr @Synacktiv, @kd_tech_@Fire30_ @theflow0, @sleirsgoevy and @SpecterDev Also, the Webkit Entrypoint still needs some love, so please be understanding at the success rate and that there is still work that needs to be done!

    PS4 7.00 - 7.02 Kernel Exploit
    .

    Summary
    In this project you will find a full implementation of the "ipv6 uaf" kernel exploit for the PlayStation 4 on 7.00 - 7.02. It will allow you to run arbitrary code as kernel, to allow jailbreaking and kernel-level modifications to the system. will launch the usual payload launcher (on port 9020). This bug was originally discovered by Fire30, and subsequently found by Andy Nguyen

    Patches Included

    The following patches are applied to the kernel:
    1. Allow RWX (read-write-execute) memory mapping (mmap / mprotect)
    2. Syscall instruction allowed anywhere
    3. Dynamic Resolving (sys_dynlib_dlsym) allowed from any process
    4. Custom system call #11 (kexec()) to execute arbitrary code in kernel mode
    5. Allow unprivileged users to call setuid(0) successfully. Works as a status check, doubles as a privilege escalation.
    6. (sys_dynlib_load_prx) patch

    Notes

    • The page will crash on successful kernel exploitation, this is normal
    • There are a few races involved with this exploit, losing one of them and attempting the exploit again might not immediately crash the system but stability will take a hit.

  • Contributors

Source Code @: github.com/ChendoChap
Twitter: twitter.com/sleirsgoevy / twitter.com/SocraticBliss

PSX-Place.com Discussion: psx-place.com

Updates:
 
Last edited:
YES!!!!!

Sorry... got a little excited just now. :)

I posted this a few days ago...

https://www.psx-place.com/posts/269808/

...and just wanted to give this thread a bump and let anyone who's interested know that I've got one on 7.02 and I'm happy to test away or lend a hand in any way possible.

If there's nothing I can do to help, then I'll just keep waiting. Keep up the great work everyone!
 
What is patched on 7.03? Why we cant execute exploit on > fw? Exist unrelesead kernel exploit? Never patched? How works web kit exploit + kernel exploit? Why we cant install cfw on ps4? Ps4 can be exploited via save game? (cyberpunk 2077 crash many time can be used?). Dlna can be used for hacking?
 
What is patched on 7.03? Why we cant execute exploit on > fw? Exist unrelesead kernel exploit? Never patched? How works web kit exploit + kernel exploit? Why we cant install cfw on ps4? Ps4 can be exploited via save game? (cyberpunk 2077 crash many time can be used?). Dlna can be used for hacking?

This is a more in-depth explanation on the current state of FW 7.02 than I could ever offer and should answer some of your questions...

Page 48-50 in particular of this will answer some of your "why" questions:

https://i.blackhat.com/eu-20/Thursd...-Exploiting-A-Webkit-0day-In-Playstation4.pdf

...and I found that presentation from this page if it helps any:

https://www.blackhat.com/eu-20/brie...xploiting-a-webkit--day-in-playstation--21212
 
blackhat is the conference that was done around the 7th through the 10th of this month. I know that the ps4 day0 exploit was on the 10th in the morning some time. unfortunately, they didn't record it, so you have to read what happened. from my memory, they only did a day0 exploit of 6.xx webkit. that's what it said on their site before the presentation anyway.
 
blackhat is the conference that was done around the 7th through the 10th of this month. I know that the ps4 day0 exploit was on the 10th in the morning some time. unfortunately, they didn't record it, so you have to read what happened. from my memory, they only did a day0 exploit of 6.xx webkit. that's what it said on their site before the presentation anyway.

When will this exploit be released?
 
When will this exploit be released?

of that, I'm not sure. it might've already been. the description for the exploit (before the presentation) mentioned it being day0 webkit exploit for 6.xx. the last sentence in the description made it sound like it had been disclosed to sony, which may be why this presentation even existed. you're allowed to disclose exploits with hackerone as long as a reasonable amount of time has passed for it to be patched.
 
Seems this 7.02 exploit is fairly good, the main issue seems to be that it takes a while to initiate, like 1min 30sec ish, but the good thing is that if it fails it does not crash. You can just cancel the out of memory error and try again.

I think I will update my 5.05 pro soon.

 
Seems this 7.02 exploit is fairly good, the main issue seems to be that it takes a while to initiate, like 1min 30sec ish, but the good thing is that if it fails it does not crash. You can just cancel the out of memory error and try again.

I think I will update my 5.05 pro soon.


Few hundred tries and only 3 KP. Rare but can still crash. Games and most apps working.
 
Stability and available ports for 7.02 has increased daily I've been testing it on my ps4 with 7.00 firmware no issues recently, acquired arbitrary rwx with successful hen launch and stable for as long as I'm using it. Very very big news and a great advancement in the ps4 scene I'm grateful for this, the devs work and the time they put into it. Happy holidays everyone.
 
Ok..soo...now more releases and updates on 6.72???.
....i should just wait till all tools and Payloads updated for 7.02
...
Hopefully Gta v mod menus get updated soon ....
 
Back
Top