PS4 (Rumor) Possible Exploit for 8.52

@Berion Ok I remember . You tried already and your case is indeed fuses.
Anyway really rubbish units ps4. Quite clean unit, thermal paste nearly after warranty period, dead bd lens already. Is going down this area.
 
In my opinion it's already patched but not released for everyone...the difference between 7.55 and 8.03 are none.they prefer sell their hack to Sony for 10k bounty and not to release for public
 
Chance of getting online with hacket ps4 ??

I would say 0. hacker one is meant to allow sony to patch the exploit before it's disclosed. well, technically, it says "within a reasonable time frame," so firmware 9.00 will likely be out. I think there's a beta of 9.00 already out. who knows if it's patched anything, but I'm sure the final release will have it patched.

btw, I think it's been confirmed that it is indeed a kernel exploit for all 8.xx firmwares. however, we need a webkit component or some way to implement it before it will be of any use. I think zecoxao mentioned a webkit component specifically, since that's what we've been using. like I mentioned on temp, it's probably going to be at least two months as a minimum before you see anything released. I haven't looked at hacker one yet to see if the exploit has even been disclosed or not. it will probably be a while (possibly a lot longer than two months) before anything is released. they had major issues getting the 7.5x exploits working, so theflow had to give them some pointers iirc. that one took a while, even after disclosure, before it was released, because it was quite unstable.
 
I would say 0. hacker one is meant to allow sony to patch the exploit before it's disclosed. well, technically, it says "within a reasonable time frame," so firmware 9.00 will likely be out. I think there's a beta of 9.00 already out. who knows if it's patched anything, but I'm sure the final release will have it patched.

btw, I think it's been confirmed that it is indeed a kernel exploit for all 8.xx firmwares. however, we need a webkit component or some way to implement it before it will be of any use. I think zecoxao mentioned a webkit component specifically, since that's what we've been using. like I mentioned on temp, it's probably going to be at least two months as a minimum before you see anything released. I haven't looked at hacker one yet to see if the exploit has even been disclosed or not. it will probably be a while (possibly a lot longer than two months) before anything is released. they had major issues getting the 7.5x exploits working, so theflow had to give them some pointers iirc. that one took a while, even after disclosure, before it was released, because it was quite unstable.
I would say 0. hacker one is meant to allow sony to patch the exploit before it's disclosed. well, technically, it says "within a reasonable time frame," so firmware 9.00 will likely be out. I think there's a beta of 9.00 already out. who knows if it's patched anything, but I'm sure the final release will have it patched.

btw, I think it's been confirmed that it is indeed a kernel exploit for all 8.xx firmwares. however, we need a webkit component or some way to implement it before it will be of any use. I think zecoxao mentioned a webkit component specifically, since that's what we've been using. like I mentioned on temp, it's probably going to be at least two months as a minimum before you see anything released. I haven't looked at hacker one yet to see if the exploit has even been disclosed or not. it will probably be a while (possibly a lot longer than two months) before anything is released. they had major issues getting the 7.5x exploits working, so theflow had to give them some pointers iirc. that one took a while, even after disclosure, before it was released, because it was quite unstable.
If you compare with PS3 xploit..you will see that on PS3 was much higher dedication..on ps4 just a few people involved and some just for bounty
 
@Berion , I don't really care about the games either. I dumped a couple more things:

upload_2021-8-22_14-33-13.png


I used orbisman to dump all of it. the idps is only the first 8 bytes or so (it can't dump all of it, not sure why). orbisman only works on 4.55 and 5.05 or it says that it does. don't know what happens with later firmware or how to dump these keys otherwise. also, I strongly suggest you dump these on a regular basis:

upload_2021-8-22_14-36-20.png


I dumped them directly from system_data/priv/mms . if you ever have to rebuild the database, these will save you as all games and dlc won't be in the database anymore. the notification.db can be deleted, and a new one will be created. as the name suggests, it's the notifications section of the home menu.
 
also, I learned this recently from a dev friend of mine, but apparently the update blocker payload doesn't work correctly on anything above 5.05. if you get a kernel panic, it's deleted from the update partition, so use the al-azif dns instead to prevent automatic downloading of a new update, if you use an online host. I'm completely offline myself, using a wifi stick (the sandisk connect), but you're much more limited on your choice of hosts if you're offline online or self-hosting.
 
another dev friend of mine said the next mira is going to use a plugin system, instead of payloads, so things may work better, less kp and less memory errors. no eta on it though.
 
no, only partial if i remember correctly. ps4 is hacked from years, i don't know why, but it's really that hard? or no one cares about making cool stuff like idps dumper/spoofer, rif decryptor or even kernel clock update for higher fw than 5.05
 
yeah, it's only partial (first 8 bytes or so). I'm not sure of the reason unless it's obfuscated or something and we don't know how to read the rest of it. you can get eap key and psid, both complete. I'm not sure what happens above 5.05 when trying to dump your keys.
 
On 1.76 you were able to dump the full idps or was it only partial also?

I read that it was full on 1.76. my system's base firmware was 3.xx iirc, so I was never able to get it. I can't be 100% it was full, but that's what I've heard. I'm not sure what sony did to it afterwards.
 
this is only a rumor at this point, but cturt has received a bounty from sony for $10K (same as theflow) for something a day or two ago. zecoxao says it's possibly a kernel exploit for 8.52, so an update from sony is likely incoming. if you're on 8.52 and want to exploit your system, do not update, because it will likely be patched. it could be a while before we know for sure or for anything to be released, so this is just a heads up.
Why you think they jump to 8.52..not 8.00 and 8.03?this was the algorithm of jailbraiking...not jailbreak a version that it.s from june
 
Why you think they jump to 8.52..not 8.00 and 8.03?this was the algorithm of jailbraiking...not jailbreak a version that it.s from june

there's no guarantee. you just have to dump the kernel to tell if the exploit works on later firmware, which apparently it does. it really depends on the webkit exploit though. 6.72 and 7.02 use the same kernel exploit but a different webkit one. originally, we only had a webkit exploit up to 6.72.
 
What is use of console ID? What's the benefit of it?

not much really. I mean you can't change it or anything or unban yourself. it just would be nice to have though. I think it's best to get all important keys, files, and make nand backup (if possible) for any system you play to exploit or hack just in case something were to happen. I can't tell you how many times I've seen posts where someone was completely unprepared when something bad happened on one of their systems. that should be the first thing you do, before installing any games even.
 
As far as i know, taking flash back up in PS4 require soldering. I don't know if you can restore this flash. You can't change console id like PS3 sen enabler so no use of PS4 id whether its full or partial. Regarding eid rootkey, i think this might help you to read PS4 hdd on PC. Is that it?
 
I think the erk on the ps3 is the eap key on the ps4. you can dump it, but I don't know if you can really do anything with it presently. it's still nice to have though. one thing I'd definitely suggest is dumping the databases from system_data/priv/mms . if you ever have to rebuild the database, they'll save you. the only alternative is to use the database fixer python script, which only works with the app.db and will make games undeleteable unless you change the canRemove from a 0 to a 1. tedious if you have a lot of games, but I think you can make a record for it to do it all at once.
 
I did a little research, and it does seem to be possible to extract content from the hdd. you do need the eap key, which you can get in a couple of ways. it should work on any ps4 afaik regardless of firmware (not sure about retrieval, but accessing, yes).
 
Back
Top