Specter Brought The achievement on 3.50 / 3.55 /3.70 /4.0/4.06 and 4.07

  • Hello Guest! Welcome to ConsoleCrunch, to help support our site check out the premium upgrades HERE! to get exclusive access to our hidden content.
  • Unable to load portions of the website...
    If you use an ad blocker addon, you should disable it because it interferes with several elements of the site and blocks more than just adverts.
  • Read Rules Before Posting Post Virus Scans with every program.

Miss @ Security

Avid Poster
CC Dev Team
Determined Poster
Active Member
Jul 13, 2016
1,040
578
198
These are still important advances on the long road which will lead us one day to the doors of happiness. The developer Specter as promised informs us via his Twitter profile that he finally managed to carry the feat of qwertyoruiopz on most of the latest firmwares offered by Sony.

He says he has ported the firmware code 3.50, 3.55, 3.70, 4.00, 4.06 and 4.07, yes you read correctly, so there is the 3.50 and 4.07.

in-specter-a-porte-lexploit-sur-350-355-370-400-406-et-407-1.jpg


It is surprising to see the 4.07, but it is now confirmed the fault walks on the 4.07, and of course as we showed our friend Markus the feat is compatible with the PS4 Pro under firmware 3.70.

Markus offers us the video of the exploit under firmware 4.07:


Organization

Files in order by name alphabetically;
expl.js - Contains the heart of the exploit and establishes a read/write primitive.
gadgets.js - Contains gadget maps and function stub maps for a variety of firmwares. Which map is used is determined in the post-exploitation phase.
index.html - The main page for the exploit. Launches the exploit and contains post-exploitation stuff, as well as output and code execution.
rop.js - Contains the ROP framework modified from Qwerty's original exploit as well as the array in which module base addresses are held and gadget addresses are calculated.
syscalls.js - Contains a system call map for a variety of firmwares as well as a 'name -> number' map for syscall ID's.
Usage

Simply setup a web-server on localhost using xampp or any other program and setup these files in a directory. You can then go to your computer's local IPv4 address (found by running ipconfig in cmd.exe) and access the exploit.

Notes
The exploit is pretty stable but will still sometimes crash. If the browser freezes simply back out and retry, if a segmentation fault (identified by prompt "You do not have enough free system memory") occurs, refresh the page before trying again as it seems to lead to better results.
This only allows code execution in ring3, to get ring0 execution a kernel exploit and KROP chain is needed.
If I've made an error (particularly having to do with firmware compatibility and gadgets) feel free to open an issue on the repo.
The exploit has been tested on 3.55 and 4.00, it is assumed to work on other firmwares listed but not guaranteed, again if you encounter a problem - open an issue on the repo.



It is necessary to keep in mind that qwertyoruiopz is forced to work on a firmware so as not to scatter and especially since it also does not have 10 different consoles ... its firmware is 4.06, so All the tests and the Poc are made from this firmware, leaving the charge to the other developers to adapt it to other firmwares if they wish, besides some like Cryptogenic works on the 3.15.


Source link: PS4-4.0x-Code-Execution-PoC https://github.com/Cryptogenic/PS4-4.0x-Code-Execution-PoC
 
General chit-chat
Help Users
  • Chat Bot:
    QM|T has joined the room.
  • Chat Bot:
    Diabloron is our newest member. Welcome!
  • Chat Bot:
    mr kiki is our newest member. Welcome!
  • Chat Bot:
    NorwayVon is our newest member. Welcome!
  • Chat Bot:
    QM|T has joined the room.
  • Chat Bot:
    cynthia is our newest member. Welcome!
  • Chat Bot:
    LilBoat100 has joined the room.
  • @ LilBoat100:
    been a min
  • @ LilBoat100:
    i have uncharted 3, (digital) my disc aint working for shit lol, so whenever i try finding "LAN Party" its not on digital, only on disc. so if theres like a eboot maybe, or something i can do to activate the LAN Party to play offline, that shit would be dope bro. anyone.
  • @ LilBoat100:
    or maybe if i download it as iso? idk
  • Chat Bot:
    tazl is our newest member. Welcome!
  • Chat Bot:
    LilBoat100 has joined the room.
  • Chat Bot:
    QM|T has joined the room.
  • Chat Bot:
    salih01barwari has left the room.
  • Chat Bot:
    ImMike is our newest member. Welcome!
  • Chat Bot:
    ImMike has posted a new reply in the thread "PS4 v3.50 Neighborhood".
  • Chat Bot:
    QM|T has joined the room.
  • Chat Bot:
    nhandinhkeonhacaidee is our newest member. Welcome!
  • Chat Bot:
    go88ttacom is our newest member. Welcome!
  • Chat Bot:
    Christo has joined the room.
  • Chat Bot:
    hitclub69com1 is our newest member. Welcome!
  • Chat Bot:
    toli is our newest member. Welcome!
  • Chat Bot:
    QM|T has joined the room.
  • Chat Bot:
    Christo has joined the room.
      Chat Bot: Christo has joined the room.