PS4 (Update) A New PS4 Kernel Exploit (7.02) Released by TheFl0w (PS4 6.72 Jailbreak next canidate)

The PlayStation 4 Hacking/Homebrew Scene has been a unique journey in comparison to other PlayStation platforms even those in the firmware era (psp/vita/ps3). The PS4 itself has been a bit unique, while development has always been there it has came at a slower pace and for a limited audience on back dated firmware releases. We have seen several exploited firmware on the PlayStation 4 (PS4) we started the show off with 1.76 and then through a few exploits we eventually climbed the ladder and moved onto 5.05 firmware and currently that has been the latest firmware exploited when the console has aged to 7.5x era . So a new exploit is in the desire list for many.

Recently (back in March) well known developer theflow0 most notably for his work recently in the PS Vita scene. His works included various exploits and also some great homebrew projects like VitaShell. So when the developer decided to turned his attention to the PS4 (see our coverage here) and announced that he had a 6.20 kernel exploit and advised the public not to update your PS4 console's firmware past 6.20, it excited many, At the time many would have updated already (v7.x), its did become a much bigger window then the current 5.05 and upgrades existing exploited console's with a new exploit. So this was eager news for many waiting patiently and sadly also fuel for the twitter trolls out there in social media land.

48790761922_b9a81a53dd_o.png

Then, several weeks ago you may of heard of a new bug bounty program for PlayStation (via https://hackerone.com/playstation). When this program was announced just recently there was alot of opinions shared and various disagreements in ideology arose and that became the focus of arguments it seemed. Following some of those disputes hacker thefl0w went to twitter on June 25 with the following:


"PS4 scene, you're starting such a drama over nothing. I was actually planning to disclose something in a few weeks/months (which I will still do...) and after that, I'd like to announce my retirement, even if I was never part of that toxic and entitled "scene".

Then today thefl0w and hackerone.com (via PlayStation Bug Bounty) announced the ps4/vita hacker has claimed a $10,000 bounty for a kernel exploit on the PS4 for firmware 7.02 (patched in 7.50) (however for 7.02 support there will need to be a webkit exploit found and released to the public, but there is one released in the public that support 6.72.) Here is what theflow0 has to say about the exploit released on July 6:
via twitter (July 6)
Here you are, https://hackerone.com/reports/826026, PS4 kernel exploit for FW 7.02 and below. Vulnerability discovered on 2019-06-09. This must be chained together with a WebKit exploit, for example https://github.com/Fire30/bad_hoist for FW 6.50.
July 6
Apologies, the WebKit exploit works upto FW 6.72.

  • So, what does this mean?
    We will be moving on from 5.05 in the future as the pieces are put together by the community. with 6.72 more then likely being the focus since we have a public webkit already and the wait will be for a 7.02 webkit exploit to be found and released to the public as that is needed for entry point to use the kernel exploit..

    thefl0w entry in the PS4 scene appears to be a brief but explosive one as the developer has also decided to call his short PS4 tenure quits confirming what he said on June 25 as those feelings seemed to stemmed from various disagreements and attitude's he did not like (more details can be found on his twitter)

    To summarize, A developer got $10,000 for releasing his Exploit, an exploit that many are going to get to use and upgrades from 5.05 It does look like that bounty program is not the end of the world after all as some were suggesting,

    Stay Tuned as this is sure to mature over the next several days/weeks,
    Do not update past 6.72 and if on 5.05 currently stay until been properly prepared for public consumption.


    .Exploit Disclosure @: hackerone.com


Updates:
 
Last edited:
Still does not pass the standards test. (seems there is still some issues)
That's what happens when people rush to a bounty....
They did this for the 10k, nothing more, nothing less.
That person may say otherwise, but all forms of proof, speak otherwise.
 
That's what happens when people rush to a bounty....
They did this for the 10k, nothing more, nothing less.
That person may say otherwise, but all forms of proof, speak otherwise.
The issue at hand here has more to do with wanting to be the first to deliver a payload loader on 6.72, in a matter of days after the kernel poc was made public, as opposed to being the first to deliver a stable & polished payload loader on 6.72, even if it takes several weeks to get there.
I don't think the bounty (which was rewarded for finding the vulnerability btw, not for the quality of an exploit implementation) made any difference in that regard, this payload loader release was rushed by choice, not by necessity.
 
Last edited:
That's what happens when people rush to a bounty....
They did this for the 10k, nothing more, nothing less.
That person may say otherwise, but all forms of proof, speak otherwise.

Know your facts...

Has ZERO to do with TheFlow.
Fire30 (webkit) and TheFlow (kernel) produced the needed pieces.

Now its someone putting it together (which is a task as well).
However,the person rushing is the one putting the pieces together and rushing to be first and released something that was not ready. THAT IS THE ISSUE. That is where the mistake were made.

Edit: @bguerville beat me :)
 
Know your facts...

Has ZERO to do with TheFlow.
Fire30 (webkit) and TheFlow (kernel) produced the needed pieces.

Now its someone putting it together (which is a task as well).
However,the person rushing is the one putting the pieces together and rushing to be first and released something that was not ready. THAT IS THE ISSUE. That is where the mistake were made.

Edit: @bguerville beat me :)
Yeah, I misunderstood that the exploit was buggy, not the implementation. My bad.
 
can anybody confirm which firmware mortal kombat 11 aftermath kollection needs?

that would depend on the patch update. I recently learned that dlc contains no firmware version or it doesn't have the necessary files for backporting. it does contain a param.sfo, but it doesn't have a firmware listed in it. I bought aftermath on the switch, and from what I remember, it was kinda recent (before it was out even). I don't know if it's out now, but if it is, it's almost assuredly over 6.72.

btw, you can tell by the patch and pkg viewer. it will tell you the firmware even for official pkg and ones over 5.05.
 
Easy rule of thumb. If it released in 2020, we can't get it yet.

Even December 2019 is out. November 2019 some base games work but you can't update because the firmware is too high. Anything before that should work since the next exploit after 6.72 was 7.0 came out October 8th 2019 but there's always a lag in time that the old firmware will work.

I decided to try to dump my Shenmue 3 disc which came out November 19th. I was thinking it would probably say I need to update my system firmware. But to my surprise it worked and I was able to dump it and I installed the PKG. It's probably just about the newest game that will work and it was released over 9 months ago.
 
Now that there's a 6.72jb or whatever its called any reason to stay on 6.20? I think I've read in the past that to stay on that FW?

I'm in no rush as I'm still playing ghost of Tsushima on my other ps4.
 
Now that there's a 6.72jb or whatever its called any reason to stay on 6.20? I think I've read in the past that to stay on that FW?

I'm in no rush as I'm still playing ghost of Tsushima on my other ps4.

If on 5.05 best to stay as things on 6.72 stablilze.(if playing some newer games is a draw then backporting games is a solution for 5.05 users.)

However if your on 6.20 now, Then yes you can goto 6.72 there would be no good reason to stay on 6.20 . However know that exploits are not as stable as they should of been on release. While they are improving quite a bit its still a work in progress. So know that going in.
 
Anyone know if the chendochap version that al azif was testing is more stable? Seems as if it's a different exploit from what I was reading. don't have the time to update and to give it a whirl.
wont be able to update til next week. also from what I understand sleep mode is not working for current exploit correct?
 
Back
Top