PS4 PS4 5.05 Kernel Exploit released by @SpecterDev - including Homebrew Payloads !!!

Discussion in 'PS4 News' started by Roxanne, May 27, 2018.

By Roxanne on May 27, 2018 at 4:32 PM
  1. 186

    Roxanne Moderator

    Mar 3, 2018
    Likes Received:
    Trophy Points:
    Home Page:
    After the first announcement for a Kernel Exploit incoming for System Firmware 5.05, Developer @SpecterDev "has been true to one's word" by releasing the announced Kernel Exploit (PS4 Hack) for System Firmware 5.05 (& 5.07). This is some Great News not because of a newer System Firmware is now exploitable, but it could be a giant stride towards great evolution for getting more and more Homebrew Applications available - as already previewed before. Those mentioned "Tools" weren't fully released yet by the time of this writing but a full release should be available in the near future. This Release however also includes several Payloads and other useful Patches, as you can check them down below.

    5.05 Kernel Exploit.jpg Screenshot from the 5.05 Kernel Exploit in Action - including some funny "Warning" Notes (Picture Credits by @qwertyoruiopz)

    • PS4 5.05 / 5.07 Kernel Exploit
      • In this project you will find a full implementation of the second "bpf" kernel exploit for the PlayStation 4 on 5.05. It will allow you to run arbitrary code as kernel, to allow jailbreaking and kernel-level modifications to the system. This exploit also contains autolaunching code for Mira and Vortex's HEN payload. Subsequent loads will launch the usual payload launcher. This bug was discovered by qwertyoruiopz, and can be found hosted on his website here.

      Patches Included
      • The following patches are made by default in the kernel ROP chain:
      1. Disable kernel write protection
      2. Allow RWX (read-write-execute) memory mapping
      3. Syscall instruction allowed anywhere
      4. Dynamic Resolving (sys_dynlib_dlsym) allowed from any process
      5. Custom system call #11 (kexec()) to execute arbitrary code in kernel mode
      6. Allow unprivileged users to call setuid(0) successfully. Works as a status check, doubles as a privilege escalation.
      Payloads included
      1. Vortex's HEN (Homebrew Enabler)
      2. Mira

      The page will crash on successful kernel exploitation, this is normal

      Contributors -
      Massive credits to the following:

    • item_XL_8608470_16936945.jpg
      @SpecterDev Tweet
      @SpecterDev Tweet
      ‏@qwertyoruiopz - Tweet
      @SpecterDev Tweet
      @SpecterDev Tweet
      @SpecterDev Tweet (July 13)

    • Various Demonstration from around the Scene.

    • @SpecterDev Tweet

      • Oni Auto Installer
      • Oni Framework
      • Mira Framework
      • Console Output Viewer
      • Mira Companion App
      • Debugger
      • Remote Viewer
      • Screenshot Capture
      • FTP Explorer
      • Theme Editor


      • LLVM Linker
      • Fake PKG Generator
      • PARAM.SFO Editor

      Polish/End User Friendliness

      • 5.05 Exploit Page W/ Mira Autoload
      • Built-In App Auto-jailbreak / Auto-unsandboxing via Mira
      • Remote PKG Installing
      • Homebrew Store
      • Persistence


      • MKDIR Mira Bug
      • Mira crashes system rebooting from sleep mode
      • Notification Code (Not Working)


    • Homebrew Enabler (External-HDD Support) (by xvortex)
      • For firmware v5.05 - Make fpkg installer working with external HDD (kudos to flatz for ShellCore offset)

      Psxitarch Linux: (by PSXITA Team)
      • Psxitarch is a linux distribution for PS4 based on Arch Linux, developed to be light, with low resource usage and easy to install. It includes the graphics drivers (radeon drm, radeonsi) needed to use 3D hardware video acceleration, kernel 4.14.14, support for * bluetooth, * wi-fi, ethernet and USB sound cards. INSTALLED APPLICATIONS, Window manager: jwm, Terminals: lxterminal, xterm, Web Browser: midori, Network Manager: wicd, File manager: pcmanfm, Emulators/Games: steam, retroarch (MULTI EMU), mupen64plus (N64), snes9x (SNES), epsxe (PSX), ppsspp (PSP), Utilities: playonlinux (Gui for wine), leafpad (Text editor), htop (System monitor), xreader (PDF viewer), xarchiver (Archive manager), blueman (Bluetooth manager), Multimedia: gpicview (Img viewer), xnoise (Audio/video player) ADDITIONAL DETAILS & DOWNOADS @ OFFICIAL WEBSITE >>> LINK

      PS4 Linux Loader Payload (by valentinbreiz)
      • Updated support for the newest System Firmware 5.05 Kernel Exploit that let you run Linux on your PS4.

      reactPSPLUS Payload (by Zer0xFF)

      • Have a PS Plus Subscription? but can't access your game collection being on a lower firmware and games have reach its expiration for signing into PSN for re-activation, Well, hopefully with this payload it will help you play those games once again. May need a few updates to make all games play as some reports did surface but to early to tell if user error or a issue with the tool that an update will fix.

      UI Mod 0.3 Custom Home Menu for 5.05 (by e✘treme)

      • Transparent Content Icons / Title Names changed / Location changed for fPKGs / Removed some Icons / Custom User Avatar / Custom Background Music

      PS2 Classic GUI (Tool) (by TheDarkProgrammer)

      • This utility did not need an update for 5.05 Support, but is a useful tool for preparing a PS2 (Classic) PKG on your exploited PS4, Play your PS2 Collection by preparing your own PS2 PKGs.

      PS4 Exploit Host (by Al-Azif)

      • A great solution for hosting the exploit on your own LAN connection, no need to rely on a 3rd party site hosting the exploit this handy utility has alot of great features . UPDATE @eXtreme has created a custom playground based on this release (hosting on his website and adding new visuals (and all payloads from Al-Azif's collection) take a look >>> LINK to PS4Brew 5.05 Playground

      PS4 Trainer By TylerM
      • Here is a trainer for PS4 that I have been working on and it is not 100% just like PS4 modding isn't. I will NOT be adding GTA or COD to this tool. I hope everyone likes it and finds it helpful.YOU MUST ENABLE MIRA+HEN FIRST TO INJECT THE PAYLOAD It is possible these cheats work for different CUSA's. Just have to try and see. If you make a working .cht file. (Pointers preferred) I will add them. I just need you to provide CUSA and game version

      X-PROJECT (XMB SELF HOST PROJECT) 5.05 by KiiWii (aka defaultdnb

      • Aims to be the AIO customizable toolbox for all your PS4 payload needs on FW 5.05

      Development Releases

      PS4Debug (Dev Use) (by Xemio)
      • A debugger with support for the PlayStation 4! Have a look at blank for a little example! I hope someone will come along and make a full featured debugger with this framework. Currently supports firmware 5.05 only!
      liborbis (by OrbisDev)
      PS4SDK (bypsxdev)
      • via ReadMe" ps4sdk is a modular open source SDK for the PS4 with userland and kernel support.The SDK currently supports most of the standard C library, various FreeBSD 9.0 userland and kernel, as well as some SCE functions. It is designed to be adaptable to new firmwares and entry points and new reverse engineered functions can be integrated into the SDK, by adding headers, function signatures and their names to the list of function stubs. Currently, running user and kernel code on firmwares ~5.05 is supported"

      Are we missing something???? let us know in the comments below.

    Direct Link to the 5.05 Kernel Exploit (visit from PS4): >>> Click Here <<<


    for an unofficial version with added payloads / eye candy checkout this link

    Source Code:

    Ps4 Homebrew Toolchain Roadmap >>> Check it out <<<<
    Source(s): /(2)/qwertyoruiop

    Update: PS4 Write-Up of the 5.05 by SpecterDev
    Last edited by a moderator: Jul 21, 2018
    gercapo, jhangleigh, T.A.U and 16 others like this.


Discussion in 'PS4 News' started by Roxanne, May 27, 2018.

    1. Bloodmoons366466
      The ps4 just seems to be more vulnerable due to hen.Otherwise we wouldn't be able to run unsighned code.The ps3 might of had hen that worked on a earlier firmware before 3.55,then got closed off once discovered,but I have no idea.
    2. DrexploidHax
      Well I also didn’t mean “vulnerable” in general, I meant vulnerable in the sense that it’s way more vulnerable to publicly available exploits. I only assumed HEN on several FW versions of PS3 (before or after 3.55 imho is regardless) it would be more “vulnerable” to publicly available premade exploits, although I also assume the PS3 would have more undicovered vulnerability’s than PS4 would, since Sony would learn from mistakes made and prevent them somewhat.
    3. DeViL303
      There was never any need to put any work into PS3, as they have been fully hackable since the 3.41 days, there are approx. 65 million Ps3 that are fully exploitable with CFW regardless of FW (hardware flashing), no one cared about the few that are not hackable . Anyone who wanted an exploited ps3 could just buy a CFW compatible one, and that's what they did. It was pure luck really that there is any HAN, and afaik it only came around due to someone finding an exploit in the webkit that the ps3 happens to use as well as other devices. If it wasn't for that the scene was happy enough with CFW really.

      As for the PS4, it shares a webkit/some of the OS (FreeBSD) with even more devices, so this is why more exploits are discovered afaik, bigger attack surface.
    4. Killer Bunny
      Killer Bunny
      Actually I am happy with HAN. The only problem is that I can't install mods or play disc games that don't have an update
    5. Killer Bunny
      Killer Bunny
      Guys I am not an expert in this field. I just thought the PS4 might be harder to jailbreak than the ps3. But still nobody is doing that
    6. DrexploidHax
      Doing what? Plenty of people are hard at work trying to exploit the PS4 and some even trying (to my knowledge) to get a CFW running, which (permanent or not) would be a jailbreak.
    7. pink1
      A kind warning for anyone reading this.
      This thread is for the new ps4 Kernel Exploit, not anything to do with ps3 hacking.
      When someone post off topic ignore it and don't help them derail the thread like this.
      al-sadiq, esc0rtd3w and DrexploidHax like this.
    8. Killer Bunny
      Killer Bunny
      Did you not read carefully? I said "I thought".
    9. al-sadiq
      i hv seen some people around the websites posting that this release for 5.05 and 5.07 is also compatible with up firmware like 5.50 and 5.53 and some of them show that the latest 5.55 too

      so whats the deal ? which firmware is more fine and compatible with this release??
    10. DrexploidHax
      5.05 & 5.07 are compatible, don’t trust anything (imho) that’s not from this forum, and I haven’t seen anything on THIS FORUM about anything over 5.07 being publicly exploited.
      al-sadiq likes this.
    11. al-sadiq
      I just wanna be sure
      DrexploidHax likes this.
    12. DrexploidHax
      Never EVER trust websites like ps4portal or cfwjailbreak, there’s allot of fake website out there, and all they do is claim to hack what they can’t, and usually ends in a brick, or worse, being hacked by visiting sites, using personal info, etc.

      Edit: ps4portal might be the legit one, I’m not sure. Can’t hurt to ask whether another site is trustable or not, it can hurt not asking and going ahead with what tbey claim to have. Also I’m not sure, but for a question regarding 5.53/5.55 it might be best to start a thread asking that question instead of doing it in a place for an unrelated matter.
      al-sadiq and DeViL303 like this.
    13. al-sadiq
      local server on the android phone that been released before for 4.55 on this app : Ps4_Serve2_v1_9.apk
      how can i change the hosted file for 4.55 to 5.05 ?
    14. al-sadiq
      tnx alot again ^_^ luv u guys
      DrexploidHax likes this.
    15. DrexploidHax
      I would personally use a HTTP server and accompanying tools, a Raspberry PI costs anywhere from $5-$35 and some adapters for it in total shouldn’t set you back more than $50 if you don’t have a PC already to use.
      no problem on my end. And think about this, would these hacks have been made, tested managed by people who didn’t love us? Would people host and manage a free open forum for those who need it, if they didn’t love us? Imho the feelings mutual

      Edit: I wouldn’t personally come with all your problems and unload them on everybody, but when in doubt (and google didn’t work) ask the forum.
      al-sadiq likes this.
    16. al-sadiq
      we hv seen on 4.55 released a ps4 dumper for copying ps4 game disc over to the usb stick ?

      is it work on the new release for 5.05 automatically ! or should hv use the same way to the 4.55 exploit ?

      is there any 5.05 exploit tool for that ?
    17. JuniorJunior
      Hi. What is the maximum size of pkg files suports to transfer to ps4 via usb?
    18. Bloodmoons366466
      Im just going to throw this out there as an opinion.

      5.50 or 5.55 will probably take a whole year for a kexploit,if not then probably never.Hopefully that helps people from getting there hopes up for nothing.
    19. DrexploidHax
      That’s strange, I can’t find a dislike button.
    20. pinky
      I'm pretty sure the app dumper has been updated.

      there should be no limit. I've dumped and installed FFX HD Remastered which is around 49.7GBs.
      al-sadiq and JuniorJunior like this.

Share This Page