PS4 4.05 Exploit for PS4, Released by SpecterDev..

It appears there is a new release but it can be considered as an "old release" coming to the PS4 Soon, UPDATE: the exploit has been released . A couple months ago we seen Team FailOverflow release the breadcrumbs to exploit v4.05 firmware with the details reveled on there blog ": The First PS4 Kernel Exploit: Adieu" Since that time developer SpecterDev has been on a mission to put the pieces together for a workable jailbreak (not an easy task by any means) on the PS4 (4.05 firmware)., Over the course of the past several months SpecterDev has spent many hours of work to get this exploit stable state usable state for anyone interested. He has done amazing work for the PS4 development community is a vital step forward for the PS4. Now 1.76 is not the only window for the PS4 but also 4.05 provides a new window that is now easier to obtain, but will this be enough to launch the PS4 Homebrew Scene to a new level?

In my personal opinion i think we have another step or two before the PS4 Scene breaksout Personally I am not as excited about this exploit as some are from an end-user perspective, i do not think this will be a "golden firmware" just as i did not believe 1.76 ever was, both exploits have came to late in the PS3 life-cycle. Just as Team Fail0verflow themselves suggested in closing when they first detailed this 4.05 window and i quote "And so we say goodbye to a nice exploit." . As we can be extremely thankful for the contributions from Team fail0verflow we can also gather through comments and actions that they will not be the ones to release an exploit themselves or be the ones to give the fuel to something current, i could be wrong here but this is what I have gathered. So this exploit originating from them i would say does show there is a bit of steam knock off the exploit potential impact for launching a community, I think this is a great step forward but i do not think a 2nd PS4 is needed quite yet, i think there will be more to come as times passes, but that is your choice and i can only offer a different perspective then what others have been given, i would just point to my track record on being correct in many of these situation ;p . This is exciting on many levels but not sure its worth buying a 2nd PS4..?..?..​


ps4_fw19.1920.jpg



  • DSBsgbNVwAItDbm.jpg

    PS4 4.05 Kernel Exploit
    Summary
    In this project you will find a full implementation of the "namedobj" kernel exploit for the PlayStation 4 on 4.05. It will allow you to run arbitrary code as kernel, to allow jailbreaking and kernel-level modifications to the system. . This exploit does include a loader that listens for payloads on port 9020 and will execute them upon receival.

    You can find fail0verflow's original write-up on the bug here, you can find my technical write-up which dives more into implementation specifics here (this is still in progress and will be published within the next few days).

    Patches Included
    The following patches are made by default in the kernel ROP chain:
    1. Disable kernel write protection
    2. Allow RWX (read-write-execute) memory mapping
    3. Dynamic Resolving (sys_dynlib_dlsym) allowed from any process
    4. Custom system call #11 (kexec()) to execute arbitrary code in kernel mode
    5. Allow unprivileged users to call setuid(0) successfully. Works as a status check, doubles as a privilege escalation.

    Notes

    • This exploit is actually incredibly stable at around 95% in my tests. WebKit very rarely crashes and the same is true with kernel.
    • I've built in a patch so the kernel exploit will only run once on the system. You can still make additional patches via payloads.
    • A custom syscall is added (#11) to execute any RWX memory in kernel mode, this can be used to execute payloads that want to do fun things like jailbreaking and patching the kernel.
    • An SDK is not provided in this release, however a barebones one to get started with may be released at a later date.
    • I've released a sample payload here that will make the necessary patches to access the debug menu of the system via settings, jailbreaks, and escapes the sandbox.

    Contributors

    I was not alone in this exploit's development, and would like to thank those who helped me along the way below.



Great news for the PS4,this is a great step forward for development but i caution people getting too excited about this and running out to buy a new PS4.
Personally I will get excited when we see a CURRENT FIRMWARE exploited, That will be the start to the Explosion of PS4 Homebrew IMO.


Update: via @Red: Much like ps3xploit I have hosted this files for others to use, in case anyone would like to mess around with this but doesnt feel like hosting the files themselves. http://redthetrainer.com/ps4/


Source(s):
github.com/Cryptogenic
twitter.com/SpecterDev / Reddit.com
 
Last edited:
You can try it but I doubt it's going to work, it makes no sense.

You know what? I encourage you to try and help to put a rest on this voice, it will require only a few minutes to swap the internal HD with a spare one (even a smaller one) and copy a 4.05 recovery PUP (the 800~900 MB type) on a flash USB memory. I'm confident it will only take a few minutes because I'm sure it will straight forbid you to proceed with the process, unfortunately... ^__^;

I totally forgot i had a small HDD in my draw, my original plan was to format my original drive and give it ago but didnt want to lose any data over a fail.

Anyway...
With the full RECOVERY.PUP it would give an error.
Then with the original UPDATE.PUP it would give an error.

I even tried renaming the RECOVERY.PUP to update.pup and still the same errors.

The two error codes were CE-30774-1 and SU-30649-2
 
Last edited:
According to Google the two error codes mean basically "can't find the firmware on your media".^1

As I suggested, if your console is on 4.70 it expects a 4.70 or later firmware, it wouldn't accept a previous one.

[1] unless the problem is with your USB flash memory ^__^;
 
Just in case no one's been paying attention. Fedora with emulators and steam were ported over to 4.05.

I KNOW ITS NOT A BIG DEAL...

AND NOT FOR EVERYONE...

but I think it's Kool af.. my PS4 booting another OS to run dolphin/psx or snes is dope.
 
I wish I could check those out. my system has 4.07 on it. damn dq theme. it had lower firmware than that. iirc, the metal slime system (the one I have) came with 3.xx out-of-the-box.
 
I wish I could check those out. my system has 4.07 on it. damn dq theme. it had lower firmware than that. iirc, the metal slime system (the one I have) came with 3.xx out-of-the-box.

Im the same as you. I am pretty sure i left my ps4 on 3.50 though so dont have a clue how it updated itself.
 
Im the same as you. I am pretty sure i left my ps4 on 3.50 though so dont have a clue how it updated itself.

that's actually why I wrote my ps4 tutorial to block updates it will still nag you, but no updates will be downloaded nor installed. I know several people who have disabled automatic download and install, but the system did so anyway. I think it's a bug. I own a Japanese system, and it still downloads automatically. it doesn't install though, so it must be a bug with the system software. I got the url's to block those servers from cc proxy. I'd attempt to signin, then grab the url. the system connects to an xml file just ;like the vita,, so the download. server can change. I'm not sure which url I have is the xml. I just know \that it's in there somewhere. it may be overkill with my tutorial, but it will error if signing in. :) on the vita, you can manipulate the xml file. it's how I updated mine\ without signing in and updating past 3.60. ;) I'm blocking several urls with the wii u, but it also blocks the eshop, you can get around that with nnu patcher. btw, on the ;ps4, blocking updates tutorial - you can still connect to the internet to run the exploit. I've tested it with the 4.07 web exploit. :)
 
Less than a month and full on pirate type shit..

Not for everyone...
Not a big deal....
More meow meow meow meeeeeeeefucking-ouch...
 
supposedly up to 5.01 is hackable as there's a 5.00 hack that wasn't patched in 5.01. when or if that will ever be released is anyone's guess. I'm currently on 4.07, and I can wait like the rest of us. the older exploit could be done up to 4.07 with 4.06 having the kernel exploit. however, the kernel exploit was supposed to work on at least as high as 4.07. I was able to use the webkit exploit on my system via the same method of deployment as the 4.05 exploit, so I expect that newer firmwares will be hackable. remember: you can only play games up to 4.05. I believe the last games to come with that firmware were released in or around January of last year, so games like god of war will be unplayable.
 
hope for the rest of us: https://twitter.com/qwertyoruiopz/status/958937379288559617

he's one of the devs mentioned with the 4.05 hack.

carrot-stick.jpg

"will eventually be published."
Maybe the time for this tweet would of been when he was ready to published the findings. Otherwise we are just left with a tease (which may not be the intent but the result) and what is the point of a tease?
I guess so people can ask him to release the findings and he get mad for people asking? Because in reality that all these tweets accomplish..

Obviously they have done some great work and everyone I think has alot of respect for that but respect is two way street. Respect the community. don't keep teasing us (be-aware that is what it is if not the intent).. Either bring it or stop dangling the carrot, but just one man's opinion...
 
Last edited:
^&%!@*?% --- I just came across a ps4 i bought and was gonna fix and flip it...looked at the firmware........its on 4.07 !! damn it :mad:

i may just keep it now tho :rolleyes:
 
Will this ps4 come with 4.05 or below or the latest exploitable firmware cause i dont wanna spend all my 400$ (savings + by selling my ps3 cfw) on an unhackable so please someone help me also the link doesnt work directly so just copy paste it in a new tab.

https://www.jumia.co.ke/sony-ps4-slim-500gb-hits-bundle-v2-1383234.html

Also ps4 are super expensive in my country so i dont want an unhackable.
are u from kenya??

Sent from my SM-C5010 using Tapatalk
 
Back
Top