PS4-5.05-Kernel-Exploit: A fully implemented kernel exploit for the PS4
github.com
github.com
To me this is one of the most impressive fields of CS/Software Engineering because of the skill required to understand and exploit full systems. Even though I'm a software dev, reading this makes me feel very humbled and shows how little I actually know.
Thanks for the read!
This is based off the below link which was posted in another comment. Much more informative than the github repo imo. http://crack.bargains/02r0.pdf
Sigh, of course qwertyoruiopz would choose a site like that…
https://github.com/kpwn/PS4-5.05-Kernel-Exploit/blob/9e97c39...
https://github.com/Cryptogenic/PS4-5.05-Kernel-Exploit/blob/...
A lot of console (and iphone) exploits tend to share similar webkit exploit code. This ps4 exploit uses a ROP strategy from an earlier iOS exploit.
This is a pretty good overview (though from 2016) of the techniques used in the browser based exploits:
- add your proprietary locked down bullshit on top
- make sure you don't have manpower / time to reintegrate patches into your fork
- profit.....?
Also, the PS4 has social media integration, so it might be possible to access your accounts somehow.
(I'm not saying that an attacker definitely can do this; I'm merely pointing out that there are potentially some bits of private information on the PS4.)
BPF Home | British Property Federation (BPF) British Plastics Federation British Psychotherapy Foundation
Then the Berkley Packet Filter.
This one loops history.pushState() to trigger the leak, direct link to the line:
https://github.com/Cryptogenic/PS4-5.05-Kernel-Exploit/blob/...
Here's some slides from the author (from last week) with a more in depth explanation:
I even had to look up "bpf", it's the FreeBSD packet filtering[1] interface, it's a character special device used to control the kernel's network filtering.
Nah, it's the Berkeley Packet Filter interface. It predates FreeBSD; just check out the HISTORY section of the manual page you linked. FreeBSD's first release was in 1993; BPF was implemented in 1990, with roots going back to 1980 (enet).
https://svnweb.freebsd.org/csrg?view=revision&revision=47584
https://svnweb.freebsd.org/csrg?view=revision&revision=47585
(Note that the /csrg repo in FreeBSD's SVN is history of the original BSD project, pre-FreeBSD itself.)
As other commenters have noted, Linux has adopted it as well. They've added a bunch of extensions in "eBPF," or extended BPF.
https://github.com/Cryptogenic/Exploit-Writeups/blob/master/...
Sure, my PC can sling a zillion triangles per second, but it can't make one stompy robot dinosaur shake my living room the way the PS4 can.
https://blogs.windows.com/buildingapps/2017/09/15/resources-...
I am looking for some little box to replace my aging home server and the PS4 looks powerful but small enough for the job.
You're probably better off with a NUC such as a Zotac or a Chinese knock off (example [1]). Why? Because given it has more horsepower and native hardware extensions for virtualization it can run VMs more efficiently.
[1] https://www.gearbest.com/mini-pc/pp_1698829.html?wid=1433363
I would note that the apu2 is more or less half of a PS4, ignoring the GPU (which probably wouldn't work that well anyway?).
PS4 | apu2c4
8x 1.6GHz Jaguar | 4x 1.0 GHz Jaguar
8GB GDDR5 | 4GB DDR3-1333
SATA, USB 3.0 | mSATA, SATA, USB 2.0/3.0, SD
1G Ethernet | 3x 1G Ethernet
BT 2.1, WiFi N | N/A
HDMI, SPDIF | N/AThe biggest drawback is the lack of persistence, especially if you want to use it as a server: you execute the exploit from the browser and load a Linux distribution from an external USB disk (not a real problem in itself as also the internal SATA HD is connected to the USB southbridge ^__^;)
There are some videos on YouTube that show working 3D HW acceleration tho.