Playstation confirms chain of 5 vulnerabilities on PS4/PS5
hackerone.com
hackerone.com
- theflow0 submitted a report to PlayStation. Oct 25th (8 months ago)
- PlayStation rewarded theflow0 with a $20,000 bounty. Nov 12th (7 months ago)
- shoshin_cup PlayStation staff closed the report and changed the status to Resolved. Apr 4th (3 months ago)
- theflow0 requested to disclose this report. Apr 4th (3 months ago)
- sazerac HackerOne staff agreed to disclose this report. Jun 10th (9 days ago)
I generally refuse to participate in Bug bounty programs through intermediaries like HackerOne, because they severely restrict and delay your ability to disclose. After having been denied a bug bounty for reporting a vulnerability directly, and often spent frustrating amounts of time just trying to get a response even from major companies, I've basically given up completely on bug bounty programs, and will likely go for full disclosure in the future (with a note to the corresponding security team for awareness).
For smaller issues, the bounties often don't even fairly compensate the (usually significant) effort spent communicating with the security team if you value your time at a competitive hourly rate, and payment is hit or miss. Not worth giving up your right to talk about the issues in exchange.
Bounty programs require a hacker to reveal their secret. That cripples a hacker’s negotiation strength, and the hacker cedes nearly all control (as you point out).
Are there any organisations which can authenticate a vulnerability, without the hacker revealing the vulnerability itself?
Vulnerability authentication seems like a hard problem:
* powerful adversaries will wish to “steal” the vulnerability for themselves,
* the hacker will want to remain anonymous,
* the hacker needs to believe they will be safe and their vulnerability will not be stolen,
* legal, social, and financial incentives would be difficult to align for such an organisation to even exist. In a “safe jurisdiction” three-letter-agency and legal issues would probably be prohibitive (can’t aid extortion etcetera), and in other looser jurisdictions there would be powerful dark threats (far dominating over any legal issues).
* in most markets authentication is handled by organisations doing repeat transactions so that their incentive is to be trustworthy. However in this market government or blackhat organisations will want to create fronts or suborn organisations.
I guess on the dark markets there are authentication options for black hats. Any links to discussions about that?
Can vulnerability authentication be solved for white hats?
There's already a trusted intermediary, you don't really need to hide the report from the company -- the intermediary just needs to provide protections to both sides.
> Practically, HackerOne is already in the business of validating vulnerability reports, and they did so here.
This is true of some programs, but not all. Only for programs that HackerOne manages and triages for is this the case. Companies can and do refuse the triage service. The triage service, and H1 staff are incredibly devoted to the hacker side of things. H1 staff routinely advises when we should pay more, when we should award bounties on borderline issues, and offers their mediation process if a hacker disagrees with our judgement. They push us (and I assume other companies) to increase the scope of your program, to increase bounty payouts, and to decrease complexity with complying with program rules.
> The real problem is that HackerOne takes a commission on vulnerability reports but does not protect the researcher if the program doesn't pay for the validated report.
I manage a HackerOne program, and at least on our contract, this isn't as straightforward as you might expect. We pay for HackerOne's services with a tiered billing structure based on how many bounties we pay out. If we pay out $1500 we pay out $1500 flat, nothing skimmed off the top. If we pay out more than $x, we have to pay for an additional consumption tier irrespective of whether or not we pay out bounties up to the max on that tier.
> Other platforms like Bugcrowd do protect you (which is probably sufficient for the problem you describe), but HackerOne strangely does not.
For the most part, Bugcrowd has its own set of problems, which is offputting to a lot of people, including my team. Specifically, Bugcrowd’s Vulnerability Rating Taxonomy [0] includes many things, particularly in the P4/P5 categories, that are extremely noisy. In both cases, both companies don't pay out on dupe reports, for example.
In principle, with standalone software that can be run under emulation, including OSes and device software, it's possible to publish a verifiable, zero-knowledge proof of execution of the exploit leading to some state (e.g. root access or changing a file) without revealing how it's done.
The principle is similar to public key crypto: Everyone can verify the proof, only those with knowledge of the secret input can produce the proof.
The proof does not contain the actual execution steps because that would reveal the secret input, but it may contain before and after states for the verifier to convince themselves an exploit took place between them, along with a cryptography-style proof that the after state is reachable under this emulator using secret input known by the hacker.
It depends. If you're a graduate with multiple FAANG offers in the US, they're not worth it. If you're in a developing country, they're worth it a lot.
Unfortunately, that also means that people who have good skills are less likely to participate and people who don't have marketable skills have an apparent incentive to try (they will not get the money, but the promise/possibility still lures them to submit reports) resulting in an absolutely atrocious quality of reports.
I don't think authentication is useful for white hats. A whitehat can just report it (which he'd do anyways) and then either get the bounty or not. The only benefit of authentication would be for the receiving company, and that's called triage and exists as a service (as we see in the full timeline, it was used here).
Having seen a glimpse of what you get out of a bug bounty program (lots and lots of people with no clue submitting bogus reports) I understand why companies are doing that, but especially for a commercial company, their triage burden is not my problem. I'm doing them a massive favor by reporting it, and as mentioned above I'm not getting paid adequately for it... so either they do the triage properly (yes, that's a lot of work), or they pay me to spend time to give them a clearer proof... or they don't get the vulnerability reported/responsibly disclosed.
Ironically, if you went through one of the platforms initially and they responded like that, you can't just go full disclosure anymore without violating the platform ToS, just like this post showed.
The absolute minimum that such platforms should do would be report closed = NDA lifted, but since they're more dependent on their paying customers than the researchers, they won't do that.
They denied it as it was under NDA during a "scheduled" pentest (their client paid them to pentest and they alerted the vendor letting them know they'd be doing it during a 2 week period like most cloud vendors).
For someone to spend weeks developing that many vulnerabilities to get an RCE and then get nothing from the vendor other than "haha technically we don't have to pay you" - there is zero reason to not go through agencies that sell to governments (ZDI, Zerodium, etc).
You'll get paid and now the bug won't get patched.
Congratulations vendor, you played yourself.
Gaming devices have always been special I think cuz basically every heavy gamer pirates games as a kid (no money!) and there’s a very legit “I just want my device to run software” feeling, but I think generally people want shit to be fixed.
At this point in life, I feel “responsible disclosure” is just a PR tool for shit-birds to use to dodge accountability. The only thing they will respond to is pain.
Now, you might want to somehow tell these users about this, so they can get off of the software. And there's this balancing act in that case...
In the abstract universe where I have a nasty exploit and the company wants to ignore it, I suppose I would just try to loudly publish a first step which is like "hey, I have this PoC which gives me RCE with this software, and the company is ignoring it", without revealing the methodology at first. Perhaps at least publishing some mitigation strategies.
I am not a security researcher, but I understand that this would be hard. But I think it's not honest to say that just dumping an exploit to the world is the best alternative to stonewalling.
Sony, Deloitte, Marriott, Tumblr, Disney, Maersk..
There's no repercussions for companies who are hacked. Until GDPR style fines are dealt, and companies are taken out back by regulatory agencies and shot - this will continue.
Was your friend the one paid to do the pentest? And during that 2 week period your friend was doing the pentest they found the 7 vuln chain RCE?
Or did they find the vulns during a period in time someone else was pentesting the company?
There's three parties: 1. Cloud service provider, 2. Client, 3. Tester
Client pays Tester to find vulns in Client's setup, including third party tools used by Client. Client notifies Cloud that there will be testing, and presumably the ToS allow such pentesting. In the process Tester discovers vulns in Cloud.
The AWS rules are complicated https://aws.amazon.com/security/penetration-testing/, for Google Cloud, you don't need to notify https://support.google.com/cloud/answer/6262505?hl=en#zippy=..., Microsoft used to require notification but no longer does https://docs.microsoft.com/en-us/azure/security/fundamentals... and seems to allow pentesting their services as long as you don't DoS them or exploit found vulnerabilities beyond a proof of concept.
> After having been denied a bug bounty for reporting a vulnerability directly, and often spent frustrating amounts of time just trying to get a response even from major companies, I've basically given up completely on bug bounty programs, and will likely go for full disclosure in the future (with a note to the corresponding security team for awareness).
I personally believe that if a bug bounty program denies your report / closes it out as N/A or out-of-scope, you should be able to disclose it. The whole point of bug bounty is practically "legal extortion". The buy-in is that you're getting security details in exchange for payment. If you're not paid, the information shouldn't be used or worthy of payment. The security issue's severity should command a level of payment. If it fails to command this, surely the company doesn't think it's valuable, right?
> I've basically given up completely on bug bounty programs, and will likely go for full disclosure in the future (with a note to the corresponding security team for awareness).
I think you should still report to bounty programs, at least ones with "HackerOne managed" badges on them, because at least HackerOne will try to reproduce the issue / triage it. If you want you can go full disclosure, but believe it or not, smaller companies with people like me at the helm are more than happy to pay out bounties. We may not have big company budgets, but we really do take things seriously, and we enjoy rewarding people who find interesting problems.
For the record, emails to security@ company are practically inundated with false positive "bug bounty" reports from researchers who have very low signal. HackerOne/Bugcrowd are often just better ticket management systems, because when you get 10 of the same report about something that isn't a security problem a day, real issues slip through the cracks. HackerOne's triage team is very good at identifying an exceptional issue and raising it up to us, which was often difficult pre-H1 via security@ emails. Also, more and more, GDPR data deletion requests get flooded to privacy@ and security@. When this happens, the security inbox looks more like GDPR/low hanging fruit zone than an actual "important security issue that needs attention immediately" zone.
Public reimplementation: https://github.com/sleirsgoevy/bd-jb (not a "full" jailbreak yet, the kernel part is missing)
To clarify, this exploit only works up to firmware 9.04 on the PS4 and up to 4.51 on the PS5.
edit: or contract
Meanwhile, his twitter says ‘Security Engineer @ Google’.
Bit weird that he didn't turn this into a jailbreak for PS5, though. But perhaps I'm missing something about PS5's firmware update scheme.
When I lived in Bolivia I remember buying PS2 games in the market for 10 Bs. ($2). I imagine few people in Bolivia can buy these games. Same for other third world countries.
I imagine the exploit author reported it for the clout and a "good get" right? It's quite the feather in your cap.
That there is a huge market in less-wealthy countries for pirated games is a well-known fact. What strikes me as a leap is that there is some mastermind behind it all that has enough savings (or other liquidity) to buy these exploits for whatever you would consider the true value (if $20k is "ridiculously" low), and then needs to earn all that money back by selling game copies (presumably there is some hardware cost to burn discs) to a population that is large but, indeed, poor.
And this possibly cuts well beyond simple piracy. PlayStation enjoys exclusive control over who does and does not get to publish on their platform. A mechanism that earns them millions in licensing deals, to the extent that they can happily lose money on the sale of the hardware itself. The destruction of that mechanism seems akin to destruction of their entire platform.
This isn't a "we found your front door unlocked" situation. This is a "we found a bomb attached to your spine, and we know exactly how to dismantle it."
Plenty of folks would have welcomed a change to play those kinds of games if they were just a download away. Even multiplayer games aren't necessarily off the table if unofficial servers are created and can be used, and piracy aside, it's compelling to be able to run your own software on the devices you own.
In the modern internet connected era, piracy is almost completely solved. A good example is the Nintendo Switch. There have been several major exploits which have allowed full access to the system and priacy, and yet it has hardly touched their profits since multiplayer has become such a big aspect and network updates allow this stuff to be fixed.
Compare this to the Nintendo DS and DSI. You could buy piracy carts at almost every retail store and almost everyone was doing it. There was also no downside to the consumer since it didn't require giving up anything. Piracy was a massive issue for this console.
Like, make all the scenes in the US sepia filtered, then make the Latin country’s clear filtered kind of jokes.
I've seen some interesting things out this way, like a 1980s IBM computer still running some dBASE II app in an auto parts store for it's inventory on a green phosphor screen, which I'd love to do some videos about
When I was a teenager there was this abandoned Catholic girls school in our neighborhood which we used to go exploring in dodging the security guard and etc. It had this huge hole in the gym floor completely filled with desks JUST LIKE IN THE GAME so that was a lot of fun to bring friends who had played silent hill to come and check out.
As for the console I also got extremely lucky and managed to snag one with no mod chip or any other alterations whatsoever. Now that we have software exploits for the PS2 through FreeMcboot it seemed like the best bet from a collection standpoint.
For some reason I've noticed that in Nicaragua families really like watching horror flicks together, it's like part of the culture there for some reason. I was watching the silent hill movie with one and they actually didn't know it was originally a video game.
Pyramid head sounds like a fun halloween costume for next year, a friend of mine went as a nurse from that last time. Can do it with some cardboard boxes I think.
Maybe one could make it an adversarial kickstarter kind of thing. The public pools against sony, full disclosure vs. time-delayed disclosure.
Interesting to see that one of the most impactful exploits is in an open source library.
I’m not saying that’s what should have happened, but $20k for something this severe is practically asking for that to happen.
If that was a chain of 5 vulnerabilities for say the iPhone or Android, that would be worth over $1 million.
But what we got here is a way to pirate video games.
Weaponizing this vulnerability means someone can play bootleg video games. And to profit from bootlegging video games, you'd have to create manufacturing and distribution channels. Then you'd have to find people who want to buy games. That's a lot of work, and when you inevitably get caught you'll like face stiff fines (if not prison).
Is this vulnerability worth more than $20k to Sony? Yes. Is it worth more than $20k to the person who found the vulnerability? Only if they can monetize it, which would require breaking various and sundry laws.
I mean, doesn't the same restriction apply to mobile exploits? You'd be breaking some kind of law by selling the exploit off, no?
In my opinion, game piracy for latest gen consoles would be very easily monetizable. The challenge is figuring out how to make money without revealing your identity and/or basing your operations out of a more piracy-tolerant jurisdiction. Or you could sell the exploit off to someone who is willing to deal with all of this.
This is especially true with PS5 thanks to the ongoing console shortage.
I do think that the bounty is underpaid but not by that much it should probably be closer to 100k.
> With these vulnerabilities, it is possible to ship pirated games on bluray discs. That is possible even without a kernel exploit as we have JIT capabilities.
So this person basically saved them from loosing tons of money (if you accept these companies claim that pirating games actually make them lose money in the first place) and they only awarded them $20K.
Good way to ensure others who find similar exploits to sell them to highest bidder on darkmarkets instead as they'll be able to get way more than that.
You can be very sure that if a piracy case went to court, Sony would claim to suffer billions in damages.
https://torrentfreak.com/gary-bowser-agrees-to-pay-10-millio...
IANAL, but I think you have to keep the scope of the damages in consideration.
It is not like PS5 owners are going to be upset for having a straightforward way to run games -- e.g. make their own Blu-ray copies etc.
Edit: To clarify: that this is valued for/by Sony at only 20k is beyond me. But absolutely that valuation should be admissible in court in my opinion. On the other hand, this number tells me to never submit a bug bounty for the money -- at least to some companies. It is simply not worth most of the time/most of the contexts. Write a paper/publication of some short and use it to get a good job that pays you salaried for more -- if you have already one just publish them immediately with a ping to the sec team. If they want to fix these fine, otherwise... they can pre-pay you to report them to them under contract for a good amount of money.
I don’t understand why there isn’t an industry of selling pirate copies of official games. What I mean is buying an official copy of the game, “image” the disc, and press 1:1 copies for cost + a couple dollars.
Why didn’t that happen? Are there technical issues preventing this from working? I can’t think it’s a matter of cost, BRD can’t cost that much to make at scale.
You don’t have to do research on any given platform. If you don’t like the terms of their bounty, find something else to play with. If you are skilled enough to find something like this you will have no problem finding very highly paid jobs.
1 in 5 have different variations of devils horns on the characters heads. 3 in 5 look like they've been cropped from communist murals around my city. Almost all of the characters look angry and criminal.
Browse these avatars and in your mind compare them to Nintendos. The vast majority of users are interacting with each other and seeing these creepy avatars as they're friends virtual faces. What effect is this having on young kids?
An example, if you find a bag of cash, typical finders fee is 10%. Insurance companies, others, often offer this.
Meanwhile, Sony is kicking maybe .01% "cash saved" for this vulnerability.
Wrong website.
It’s selling bugs in customer hardware that can used to reduce control of the manufacturer of it and allow users to run pirated stuff (and homebrew likely as a result). It’s totally in the best interest of the manufacturer to always be the highest bidder.
I don’t have any moral issues with people selling those issues on the black market, if manufacturer isn’t interested in rewarding researcher properly.
I understand that nobody has to do the research of any sort but my point is that these skills and effort involved are being commoditised very quickly and become comparable to gig economy. Bounty programmes are very very cheap to large corps, compared to the returns involved. Building a substantial infosec division that could match the crowdsourced model is way more expensive.
Try not to regard things in such an all-or-nothing perspective. At worst it indicates a psychological disorder, at best—a high conflict personality. Either way, it wont benefit you or the people that interact with you.
I also disagree that it ‘completely’ lacks morals. If OP is being truthful, then he has a desire to work hard and put in the time necessary to fulfill a virtuous (albeit under-compensated) calling.
However, OP is also cognizant of a hypothetical (albeit realistic) temptation that will most likely confront him, should he carry out these pursuits: ethical conflicts which would force him to choose between large financial gains (selling exploits to bad actors), or the less lucrative (and often thankless) white hat approach of reporting it in good faith, and expecting (but not necessarily receiving) equal measures of good faith from corporations (like Sony in this case).
Having an awareness of one’s own weaknesses or susceptibilities to temptation isn’t a weakness to be admonished from atop a digital soap box. Instead, recognize and reinforce OPs desire to do good—it costs little more energy to encourage the good in people, rather than shaming them for not having an unshakable moral fortitude. Have a Happy Father’s Day.
One of note: the "criminals" in this context are, at best, homebrew developers and users who'd like to unlock the full potential of the hardware they bought. At worst, they're "pirates" (the industry term, not mine) and game cheats. Nobody likes a cheater in a video game, but I don't know if I'd go as far as to make ethical prescriptions about it.
Sony feels comfortable paying a pittance for these vulnerabilities because the market for them is relatively soft. But that doesn't mean that the underlying asset actually lacks value; it means that Sony has successfully criminalized applications of the asset, artificially lowering their salability.
Your position affords you a unique opportunity to have some perspective here.
It's not that straightforward (even if I wish it was).
First, it requires a judge and jury who understand "interoperability" to include "connecting to a server you don't own and sending it payloads that it isn't expecting."
Second, it requires a lenient interpretation of EULAs under the DMCA: the DMCA promotes otherwise legal reverse engineering activities into illegal activities by allowing companies to establish "acceptable use," which can include prohibiting reverse engineering activities that circumvent restrictions on copyrighted or other controlled material. A bank may plausibly (in the eyes of attorneys) claim that third-party uses of its APIs compromise the bank's ability to comply with federal regulations, since no law requires that compliance and operation be integral operations.
ianal etc.
Reverse engineering would also be a copyright infringement issue, which does have a carve out for reverse engineering.
Its literally only the corporation beneficiaries of having their own product fixed that are paying the wrong amount. Inching up the payout amounts ever so slowly.
Anything that makes those corporations pay out better is also a moral outcome, and doing things that supports this status quo lacks ethics as well.
(We actually agree that selling to some bidders, and some actions, lack ethics)
But what hasn't worked and will continue to not work is using social moral condemnation. I think we all find "you wouldn't download a car" funny, right? Worse for this situation is the context of the growing economic divide worldwide in 2022. Under that lens I wouldn't be surprised to see this happening more. The more oligarchies show individuals that they don't care, why should individuals show they care about the oligarchies?
That Sony is not the criminal here is a reflection of our inadequate laws, not morals, and selling vulnerabilities to them is just as bad.
If I find a high tier vuln and the company isn't giving reasonable bounties, it's going straight onto Zerodium or similar platforms and I won't lose a second of sleep over it.
Nah, copyright is immoral, bypassing it is the morally right thing to do.
When I worked with someone who was a point of contact for outside security researchers it seemed for many were just happy to get their name in the release notes.
And I’m not sure if you’re selling that you’re a white hat researcher anymore…
>Good way to ensure others who find similar exploits to sell them to highest bidder on darkmarkets instead as they'll be able to get way more than that.
Sure, sell it for how much? twice? thrice? as much
instead using it for your own branding, cv, to negotiate salary which will pay you way more over years
> With these vulnerabilities, it is possible to ship pirated games on bluray discs
This is illegal AFAIK.
This isn't always the case. On the Switch for example you can very easily bypass system version checks.
Compare this to the DS and DSI where piracy carts were sold at retail stores and had zero downsides and were widely popular.
It's also worth mentioning that vulnerable consoles were sold for a relatively small window of the console's lifetime, and while patched units are still hackable to some extent its much more inconvenient. For the DS all you needed was a flash cart, regardless of anything else.
WebKit is infested with vulnerabilities and it is a hackers paradise for exploitation. Probably the most exploited and targeted software component out there.
What's the market for this exploit, though? Who is going to pay never mind $20k but more or less anything for it?
Possibly but who is going to pay you $20k to realize these theoretical profits? They essentially mean un-networking your console, never updating it, only using physical media, likely losing your PSN account. There's a huge leap from step 1. 'an exploit exists', step N 'lots of hacked consoles and people buying pirated discs for them' and whatever step 'PROFIT' appears in. A latent market for free or cheap stuff is not the same thing as a market for this exploit.
Everything you list there is a plus in non-wealthy countries were internet access is slow and expensive. I suspect the total sales of bootleg PS2 games greatly exceeded Sony's legit sales in the global south due to the widespread availability of "chipped" PS2 consoles.
I’m not sure many people could afford a PS5 in places such as this. And in most ‘second world’ where people have a but more money internet is generally cheap and fast especially compared so countries like US or Canada.
Why does it have to be "many"? Bootleg games have extremely high margins for the bootleggers.
That said, the PS5 is cheaper than an iPhone, and there are plenty of those. If you're bored, look up instagram pictures geolocated in the poorest cities you can think of, then count the number of recent iPhones that at least worth a new PS5. The number may surprise you.
Especially when so many people work on sensitive work in their homes due to COVID, huge chunks of the federal government are having conversations next to hot mics as they do Tinder and the like on their "personal" devices.
Who would want to jailbreak and leave their ps5 offline to get 5$ games that won’t work once the station is updated. Where on the flip side you could pay 5-15$ Monthly (not sure of PlayStation Nows cost but that amount is for Xbox game pass) to have hundreds of games at your disposal and never have to physically acquire a new disk via black market to play a new game?
PlayStations’ main unique feature are the narrative based single player exclusives. So, if you were going to get a PS5 and Xbox, it seems Xbox for multi and hacked PS5 for single seems like an excellent combo - you know - if you were the type of person that could justify that sort of thing.
There's 2 types of people that will find these kinds of exploits. Black hat hackers that do it for the money, and white hat hackers that do it for themselves/openness.
The black hat hacker would have to be paid handsomely so that he could disclose his exploit. For these types of exploits I assume they would do something like sell you a PS5 with dozens of games included for $700, and tell you that you can load many more. That means that he only needs to sell 101 hacked PS5s to make more than the reward money, and he'll probably sell thousands of them before a copycat copies him stealing his profits or Sony patches the bug, which won't stop him completely since he'll probably have a big stock of unpatched PS5s.
The white hat hacker does it for fun or curiosity, a white hat hacker is usually an advocate for open source and probably trying to run linux on the thing is the main motivation for him to keep going. After they find something they'll release it to the public, usually with piracy enabling things off by default, but since it's all open source the pirates will find a way to use it anyway.
Sony is doing the smart thing and targeting the white hacker, they're the most likely to find these exploits anyway. If they made the reward money high enough that it would disincentivize the black hat hacker from commercializing his findings, it would instead be an incentive for people to find exploits. Lets say they pay $200k per exploit, they would no longer be paying these types of bounties once a year, but every month. I'd argue that paying millions a year to protect their system is valuable, but the fact is that they can get away with much less, hence $20k is just about the perfect amount of money for a bounty like this.
tl;dr: If they paid more they'd basically be creating and funding a market of exploit finders for little gain.
EDIT: looks like it's not critical because of this https://twitter.com/theflow0/status/1535424299397369856
In which case, 20k still feels low, but not as unfair.