Showing posts with label BadIRET. Show all posts
Showing posts with label BadIRET. Show all posts

Thursday, 21 April 2016

Proof of concept webkit exploit running on PS4 firmwares 2.xx

Developer Fire30 released a webkit exploit proof of concept for the PS4, ported from a webkit heap buffer overflow revealed in 2014. I haven’t tested this myself, and this is still unconfirmed information at this point.
Fire30 says the exploit should run on any PS4 firmware below 2.50, although he mentions parts of the exploit implementation will only work on firmware 2.03, presumably because this is the firmware he’s using to write the code.
There’s not much to be said about this at this point, although in theory the kernel exploits BadIRET and dlclose could be ported to this exploit, if confirmed legit: it has been mentioned these kernel exploits are compatible up to firmware 2.xx, and the only thing preventing those from being used on any other firmware than 1.76 so far was because the only publicly available userland exploit has been the 1,76 webkit exploit.
CVE-2014-1303
A port of the dlclose exploit to this new webkit vulnerability could bring some Linux joy to more PS4 users, and help decrease the current asking price for hackable PS4s.

Download and install the CVE 2014-1303 Proof Of Concept for PS4

You can Download Fire30’s proof of concept on his github here. You’ll need a PS4 running below firmware 2.50, ideally firmware 2.03. According to the readme:
a poc for the CVE 2014-1303 originally disclosed by Liang Chen. It has been tested to work on system firmware 2.03, but should work for systems on a firmware < 2.50, the ROP test will however only work on 2.03.
Usage
You need to edit the dns.conf to point to the ip address of your machine, and modify your consoles dns settings to point to it as well. Then run
python fakedns.py -c dns.conf
then
python server.py
Debug output will come from this process.
Navigate to the User’s Guide page on the PS4 and various information should be printed to the console. The ROP test will print what is stored in the rsp register. Continuing execution after rsp is pivoted still needs to be done.

fire30 credits the following people, in addition to Liang Chen who revealed the vulnerability in 2014:
thexyz
dreadlyei
If you happen to have a PS4 running a firmware below 2.50, and have the skills to 1) confirm that this is true and 2) try and get the dlclose exploit to run on this, then by all means, help the PS4 scene :)
Otherwise… stay tuned!
source: github, thanks to @isset_asset

Monday, 28 March 2016

Is now the right time to buy a 1.76 PS4?

The PS4 scene is boiling right now, with people making daily progress on the dlclose and BadIRET kernel exploits on PS4 1.76. It’s probably going to be a matter of weeks now until people start poking into the Ps4 firmware, or get a full toolkit to install Linux on the device. Is now the right time to get a 1.76 PS4?
If you’ve been on the console scene for a while, you’re probably familiar with the concept of “golden firmware”. The golden firmware is the firmware that gives you the best of what your console can achieve, both from a perspective of official games, and from a hacking point of view. On the PSP, firmware 1.5 was the “golden firmware” for a very long time, as it was the only one with all the cool exploits, piracy, and homebrews. If I recall correctly, the first custom firmwares on the PSP from Dark Alex were basically taking all the cool stuff from firmware 1.5, and merging those on top of the latest firmware, to get the best of both worlds.
Nowadays, with online access being a prerequisite to do anything official on your console, it’s difficult to bypass firmware updates. Most games or applications on your PS4 will probably refuse to run if you’re not running on the latest firmware, and very soon you’d have to say goodbye to the latest games if you decided to stay forever on, say, firmware 1.76.
In that kind of context, I’m convinced people who are interested in the PS4 scene will need basically two consoles: one for hacks that you’d keep on a lower firmware, the other for “regular” gaming, constantly up to date.
dlclose PS4 Kernel exploit
The dlclose kernel exploit was released a few days ago
Now that the scene is just getting ramped up on PS4 exploits with firmware 1.76, it is still possible to find a 1.76 PS4 for a “reasonable” price. We’re all facing a choice at this point: some of us will be buying one now for a reasonable price, in the hope that 1.76 exploits take off soon. Others will just be waiting, hoping that new kernel exploits surface for the latest firmware (3.50?) by the time user-friendly hacks and tools are available.
Our first guy is buying a 1.76 console at a quite expensive price, but still reasonable (you can easily find 1.76 PS4s around $550 today). If hacks on 1.76 become mainstream, prices of 1.76 consoles will skyrocket, and I can easily picture such devices selling for more than $1000 very soon. On the other hand, if an exploit is revealed on the latest firmware, which gives people the same level of tools as 1.76 provides now, our  friend has overpaid about $150 for his second PS4.
My second guy doesn’t want to buy a 1.76 PS4 just yet. If an exploit is revealed for the latest firmware 3.50, he can buy any second-hand PS4 for $300, keep it at 3.50, and be done with it. On the other hand, if 1.76 PS4 hacks become mainstream and no “latest firmware” exploit is revealed for a long time, he’ll be the *** having to buy a 1.76 PS4 for more than $1000.
ps4_jailbreak_1_76_Glacier_white_destiny_bundle

I’m personally on the fence right now. It’s a bet. Statistics tell me there’s always going to be an exploit for the latest firmware at some point, however I can’t help but realize that times have changed: hackers don’t release kernel exploits as often as they used to for, say, the PSP. Maybe what we have on 1.76 right now is a “one time thing”, and we might not see more PS4 kernel exploits for a long time.
Thoughts?