Showing posts with label PS4 Hack. Show all posts
Showing posts with label PS4 Hack. Show all posts

Thursday, 31 December 2015

Linux on PS4: Fail0verflow showcase Linux on the PS4, run a Pokémon Demo (video)

As we guessed last week in an article entitled “Fail0verflow to announce a PS4 Jailbreak Next week?“, Fail0verflow announced today at the CCC that they owned the PS4 and have Linux up and running on the PS4. They did a very short presentation to showcase the hack, and ran a Pokémon game within Linux on the PS4.

Tuesday, 15 December 2015

PS4 hack: Cturt showcases the FileSystem root and processes in RAM

News keep pouring from the recently revealed PS4 Kernel exploit. CTurt, the hacker behind the announce,posted a “tease” on twitter earlier today: a dump of the root Filesystem of the PS4, as well as the processes running in the PS4 RAM. Details below.
The Filesystem root shows some similarities with your standard FreeBSD install, with folders such as /dev or /mnt.
Files that are more PS4 specific also show up, such as SceBootSplash.elf and SceSysAvControl.elf. Elf files are executables, it is safe to assume all these files are encrypted, but it would be interesting to understand how easily they can be replaced (although probably sounds like a bad idea to mess up with those, given that they might be essential at boot time, at a point where the hack is probably not running)
Notice also the “update” folder, pretty much self explanatory, and that already existed on the PSP and the PS3.
[+] Entered shellcode
[+] UID: 0, GID: 0
[DIR]: adm
[DIR]: . [DIR]: ..
[DIR]: dev
[DIR]: app_tmp [DIR]: data
[DIR]: hdd
[DIR]: eap_user [DIR]: eap_vsh [DIR]: host
[DIR]: mnt
[DIR]: hostapp [FILE]: mini-syscore.elf [DIR]: preinst
[FILE]: SceBootSplash.elf
[DIR]: preinst2 [FILE]: safemode.elf [FILE]: SceSysAvControl.elf
[DIR]: update
[DIR]: system [DIR]: system_data [DIR]: system_ex [DIR]: system_tmp [DIR]: usb
[DIR]: user
The processes, here again, are a mix of typical stuff and PS4 specific processes. Look for the Sce* stuff for Sony specific processes, as well as orbis_* (hey, Orbis was the development codename for the PS4).
[+] PID 0, name: kernel, thread: mca taskq
[+] PID 1, name: mini-syscore.elf, thread: SceRegSyncer
[+] PID 2, name: SceHidAuth, thread: SceHidAuth
[+] PID 4, name: SceCameraDriverMain, thread: SceCameraDriverM
[+] PID 3, name: hidMain, thread: hidMain
[+] PID 6, name: hdmiEvent, thread: hdmiEvent
[+] PID 5, name: SceCameraSdma, thread: SceCameraSdma
[+] PID 10, name: audit, thread: audit
[+] PID 8, name: xpt_thrd, thread: xpt_thrd [+] PID 9, name: iccnvs, thread: iccnvs
[+] PID 13, name: geom, thread: g_notification
[+] PID 11, name: idle, thread: idle: cpu0 [+] PID 12, name: intr, thread: irq273: xhci2
[+] PID 17, name: icc_thermal, thread: icc_thermal
[+] PID 14, name: yarrow, thread: yarrow [+] PID 15, name: usb, thread: usbus2 [+] PID 16, name: md0, thread: md0
[+] PID 21, name: trsw ctrl, thread: trsw ctrl
[+] PID 18, name: sflash, thread: sflash [+] PID 19, name: sbram, thread: sbram [+] PID 20, name: trsw intr, thread: trsw intr
[+] PID 25, name: vmdaemon, thread: vmdaemon
[+] PID 22, name: SceBtDriver, thread: SceBtDriver [+] PID 23, name: pagedaemon0, thread: pagedaemon0 [+] PID 24, name: pagedaemon1, thread: pagedaemon1
[+] PID 29, name: softdepflush, thread: softdepflush
[+] PID 26, name: bufdaemon, thread: bufdaemon [+] PID 27, name: syncer, thread: syncer [+] PID 28, name: vnlru, thread: vnlru [+] PID 31, name: SceSysAvControl.elf, thread: SceAvSettingPoll
[+] PID 36, name: SceShellCore, thread: SceMsgMwSendMana
[+] PID 33, name: SceSysCore.elf, thread: SysCoreAppmgrWat [+] PID 34, name: orbis_audiod.elf, thread: AoutMonitorPid40 [+] PID 35, name: GnmCompositor.elf, thread: CameraThread [+] PID 38, name: SceShellUI, thread: SceWebReceiveQue
[+] PID 43, name: SceVideoCoreServer, thread: SceVideoCoreServ
[+] PID 39, name: MonoCompiler.elf, thread: MonoCompiler.elf [+] PID 40, name: SceAvCapture, thread: SceAvCaptureIpc [+] PID 41, name: SceGameLiveStreamin, thread: SceGlsStrmJobQue [+] PID 42, name: ScePartyDaemon, thread: SceMbusEventPoll [+] PID 44, name: SceRemotePlay, thread: SceRp-Httpd
[+] PID 49, name: SceSpkService, thread: SceSpkService
[+] PID 45, name: SceCloudClientDaemo, thread: SceCloudClientDa [+] PID 46, name: SceVdecProxy.elf, thread: proxy_ipmi_serve [+] PID 47, name: SceVencProxy.elf, thread: SceVencProxyIpmi [+] PID 48, name: fs_cleaner.elf, thread: fs_cleaner.elf [+] PID 50, name: WebProcess.self, thread: selectThread
[+] Entered main payload
[+] PID 51, name: orbis-jsc-compiler., thread: SceFastMalloc
[+] Triggering second kernel payload
This is not much at this point, it just shows that Cturt has access to the RAM and can look at all the processes running (which would generally confirm root access), but it’s still super exciting to think what could be done moving forward.
The Kernel exploit has been confirmed to work up to PS4 firmware 1.76, and no release date has been announced yet. We explained however how this PS4 exploit could benefit recent firmwares such as 3.11. Stay tuned!

Wednesday, 9 December 2015

PS4 hack: what we know of the kernel exploit so far

Several devs close to the recently revealed PS4 Kernel exploit have spoken up on IRC and other communication channels, to clarify the current status of this PS4 hack.
Probably the most important piece of information is that the Kernel exploit announced by CTurt this week is already patched on recent firmwares. It is believed that the exploit will run on PS4s up to firmware 1.76. Oh, and several sources have now confirmed that this exploit is real (not that we doubted it given that Cturt is a trusted source, but it’s good to have multiple confirmations)
Now, it being patched does not mean this exploit is a waste, quite the contrary. We’ve learned that several groups have discovered and started investigating the exploit roughly at the same time, several months ago. It is safe to assume this exploit has enabled them to investigate the PS4 firmware in depth, and understand more of its inner workings.
In other words: hackers now have access to the entire PS4 system, and can study its security mechanism, kernel, and libraries, at will.
PS4 Jailbreak 2016
Down the road, this could allow them to reverse engineer parts of the PS4 system firmware, and find more exploits (some of which would be available on recent firmwares), as well as setting the basics for a scene-driven PS4 SDK, which would later on let people write homebrews.