Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

10.50 / 10.70 / 10.71 and 9.50 / 9.60 Support #23

Merged
merged 7 commits into from
May 2, 2024

Conversation

rafaelflromao
Copy link
Contributor

@rafaelflromao rafaelflromao commented May 2, 2024

Added offsets for 10.50 / 10.70 / 10.71 and for 9.50 / 9.60

Tested versions:

  • 9.50
  • 9.60
  • 10.50
  • 10.70
  • 10.71

@rafaelflromao rafaelflromao changed the title 10.50 Support 10.50 / 10.70 / 10.71 Support May 2, 2024
@EchoStretch
Copy link
Contributor

EchoStretch commented May 2, 2024

I'm not 100% sure but i search half and they all came up the same.
once I'm done with helping sistro ill update to 10.70 and test

@Sulfrix
Copy link

Sulfrix commented May 2, 2024

Works on 10.71
image

@rafaelflromao
Copy link
Contributor Author

once im done with helping sistro ill update to 10.70 and test

Works on 10.71 image

Thank you

@amraj007
Copy link

amraj007 commented May 2, 2024

I have 10.70

@rafaelflromao
Copy link
Contributor Author

I have 10.70

Can you test it?

@rafaelflromao rafaelflromao changed the title 10.50 / 10.70 / 10.71 Support 10.50 / 10.70 / 10.71 and 9.50 / 9.60 Support May 2, 2024
@Incineroar
Copy link

I haveve 10.50 and I am currently getting my laptop set up to build this so I can test it out for you.

@kotn3l
Copy link

kotn3l commented May 2, 2024

I have 9.60, gonna test once it's available.

@rafaelflromao
Copy link
Contributor Author

I have 9.60, gonna test once it's available.

Can you build it?

@kotn3l
Copy link

kotn3l commented May 2, 2024

I have 9.60, gonna test once it's available.

Can you build it?

I think so, but I'll let you know if I need a build.

@amraj007
Copy link

amraj007 commented May 2, 2024

I have 10.70

Can you test it?

I don’t know how to do xD

@rafaelflromao
Copy link
Contributor Author

I have 10.70

Can you test it?

I don’t know how to do xD

Do you have Linux?

@amraj007
Copy link

amraj007 commented May 2, 2024

I have 10.70

Can you test it?

I don’t know how to do xD

Do you have Linux?

No

@Incineroar
Copy link

I haveve 10.50 and I am currently getting my laptop set up to build this so I can test it out for you.

Update:

PXL_20240502_054018404.jpg

Took a couple attempts but it worked 👍 First attempt failed at scanning for corrupted object and the second attempt was successful.

@rafaelflromao
Copy link
Contributor Author

I have 9.60, gonna test once it's available.

Can you build it?

I think so, but I'll let you know if I need a build.

You can build it from https://github.com/rafaelflromao/PPPwn/

@amraj007
Copy link

amraj007 commented May 2, 2024

I haveve 10.50 and I am currently getting my laptop set up to build this so I can test it out for you.

Update:

PXL_20240502_054018404.jpg

Took a couple attempts but it worked 👍 First attempt failed at scanning for corrupted object and the second attempt was successful.

Can you try the 10.70

@Incineroar
Copy link

Incineroar commented May 2, 2024

Can you try the 10.70

I think @EchoStretch was going to test that. I don't really want to update my system and I have everything set up for 10.50 now.

@rafaelflromao
Copy link
Contributor Author

I haveve 10.50 and I am currently getting my laptop set up to build this so I can test it out for you.

Update:
PXL_20240502_054018404.jpg
Took a couple attempts but it worked 👍 First attempt failed at scanning for corrupted object and the second attempt was successful.

Can you try the 10.70

If it works on version 1.50 and on version 1.71, the chance of it working on version 1.70 is very high.

@fffoo
Copy link

fffoo commented May 2, 2024

I'm gonna test on my 10.50 console too in a minute or two

@W-i-n-7
Copy link
Contributor

W-i-n-7 commented May 2, 2024

tested 8 times on 10.50 ps4 pro
linux mint on vmware workstation

attempts:
1: crashed ps4 and bootlooped a few times
2 & 3: please retry (scanning object failed)
4: started before i tested the connection & failed please retry (scanning object failed)
5: failed please retry (scanning object failed)

--i restarted the ps4--

6: failed please retry (scanning object failed)
7: failed please retry (scanning object failed)
8: crashed ps4 when i unplugged ethernet (scanning object failed)

@rafaelflromao
Copy link
Contributor Author

rafaelflromao commented May 2, 2024

tested 8 times on 10.50 ps4 pro linux mint on vmware workstation

attempts: 1: crashed ps4 and bootlooped a few times 2 & 3: please retry (scanning object failed) 4: started before i set up the connection & failed please retry (scanning object failed) 5: failed please retry (scanning object failed)

--i restarted the ps4--

6: failed please retry (scanning object failed) 7: failed please retry (scanning object failed) 8: crashed ps4 when i unplugged ethernet (scanning object failed)

tested 8 times on 10.50 ps4 pro linux mint on vmware workstation

attempts: 1: crashed ps4 and bootlooped a few times 2 & 3: please retry (scanning object failed) 4: started before i tested the connection & failed please retry (scanning object failed) 5: failed please retry (scanning object failed)

--i restarted the ps4--

6: failed please retry (scanning object failed) 7: failed please retry (scanning object failed) 8: crashed ps4 when i unplugged ethernet (scanning object failed)

Did you specify the correct firmware version when building?

@W-i-n-7
Copy link
Contributor

W-i-n-7 commented May 2, 2024

yes i did

@W-i-n-7
Copy link
Contributor

W-i-n-7 commented May 2, 2024

i have a hunch it was vmware doing something as linux mint was spamming network errors constantly
im installing mint on virtual box at the moment will test with that too

@dany1305
Copy link

dany1305 commented May 3, 2024

I have 10.50 version. If i try to do this script on my console, i risk to damage it? Or is only a test to verify that console is compatible with a future jailbreak?

@fffoo
Copy link

fffoo commented May 3, 2024

I have 10.50 version. If i try to do this script on my console, i risk to damage it? Or is only a test to verify that console is compatible with a future jailbreak?

Won't damage, only a test.

@W-i-n-7
Copy link
Contributor

W-i-n-7 commented May 3, 2024

I have 10.50 version. If i try to do this script on my console, i risk to damage it? Or is only a test to verify that console is compatible with a future jailbreak?

currently its a PoC (proof of concept)
its a test payload that sends a notification

it wont damage your ps4

goldhen is being ported right now

@dany1305
Copy link

dany1305 commented May 3, 2024

Ok thank you.
If goldhen go to port, it's very very good

@W-i-n-7
Copy link
Contributor

W-i-n-7 commented May 3, 2024

@se2crid i upgraded my ps4 from 10.50 to 10.50 with safe mode (reinstall but without losing data?)
and its still not working for me

@PierreCsn
Copy link

n-pip py

you got me farther than my previous attempt on arch , thanks for the tip about the arch package instead of using pip, now i have this error
``make -C stage1 FW=960 clean && make -C stage1 FW=960
make: Entering directory '/home/pierre/PPPwn/stage1'
make: Leaving directory '/home/pierre/PPPwn/stage1'
make: Entering directory '/home/pierre/PPPwn/stage1'
gcc -c -o start.o start.S
gcc -DSMP -isystem ../freebsd-headers/include -Wl,--build-id=none -Os -fno-stack-protector -DFIRMWARE=960 -c -o stage1.o stage1.c
stage1.c:13:10: fatal error: sys/_lock.h: No such file or directory
13 | #include <sys/_lock.h>
| ^~~~~~~~~~~~~
compilation terminated.
make: *** [: stage1.o] Error 1
make: Leaving directory '/home/pierre/PPPwn/stage1'
I ve a ps4 pro with 9.6 if you need more testing

@PierreCsn
Copy link

my bad i didnt clone the repo properly

Tested on 9.60 on ps4 pro, took me 8 tries , alot of fail on stage 1 , one crash , and i finally got the ppwned message.
feel free to ask me if you need more tests, kids have been waiting for 18months with no ps4 so i ll help if i can

@se2crid
Copy link
Contributor

se2crid commented May 3, 2024

@se2crid i upgraded my ps4 from 10.50 to 10.50 with safe mode (reinstall but without losing data?) and its still not working for me

Weird, it is confirmd that some people have problems with the exploit not work or it takes 50+ tries for it to work so wait until that fix

@W-i-n-7
Copy link
Contributor

W-i-n-7 commented May 3, 2024

it doesnt work for me at all
i really hope its something fixable

@Superredstone
Copy link

My 10.71 shuts down after trying the exploit

@W-i-n-7
Copy link
Contributor

W-i-n-7 commented May 3, 2024

My 10.71 shuts down after trying the exploit

try again

@Superredstone
Copy link

i tried 3 times now, i'm gonna try again and let you know

@se2crid
Copy link
Contributor

se2crid commented May 3, 2024

i tried 3 times now, i'm gonna try again and let you know

some people need to try veryyy many times for it to work

@se2crid
Copy link
Contributor

se2crid commented May 3, 2024

it doesnt work for me at all i really hope its something fixable

I think when LM ports the 11.00 offsets so goldhen works it will be looked into

@se2crid
Copy link
Contributor

se2crid commented May 3, 2024

it doesnt work for me at all i really hope its something fixable

2d96a6c

@W-i-n-7
Copy link
Contributor

W-i-n-7 commented May 3, 2024

it doesnt work for me at all i really hope its something fixable

2d96a6c

whats this? debug settings enabled?

@joseashb
Copy link

joseashb commented May 3, 2024

win_7

Still in the works for 11.00

@W-i-n-7 Added

@annahana
Copy link

annahana commented May 3, 2024

Just a question is the 9.60 implementation compatible with SSD upgrad on ps4 because I have the problem that every time on stage 1 CPU corruption 93% the ps4 shuts down with unrepairable SSD corruption that forces me to make a recovery installation of the Firmware.

@Hackerpunk1
Copy link

Hackerpunk1 commented May 3, 2024

Just a question is the 9.60 implementation compatible with SSD upgrad on ps4 because I have the problem that every time on stage 1 CPU corruption 93% the ps4 shuts down with unrepairable SSD corruption that forces me to make a recovery installation of the Firmware.

Just a question is the 9.60 implementation compatible with SSD upgrad on ps4 because I have the problem that every time on stage 1 CPU corruption 93% the ps4 shuts down with unrepairable SSD corruption that forces me to make a recovery installation of the Firmware.

I think that the kernel panic is what triggers the issue where you're sent to safe mode. Try switching back to a HDD and see if the same happen. I also did upgrade my PS4 with an SSD yesterday, and installed 9.60 from recovery. So far everything seems to be working as intended.

I also noticed that depending on the host machine, the exploit reliability greatly varies, if the machine is too slow, it will fail as it will take a lot of time to send the instructions and scan back.

  • Try reducing the variables such as Antivirus disabled and unnecessary apps closed on Windows
  • Use a faster host or even change distro if needs be. On about 15 attempts, only 1 passed on a dual-core machine (Celeron N3060), changing to a better machine (i5 7200U), the exploit runs without failing. I shall test the same machines on Windows and report back.
    NOTE: Both machine got 8GB RAM and SSD.
  • Also exploit seems to run better on Linux Mint than Ubuntu 22.04/24.04 & Manjaro (from my experience)

If I find anything else, I shall let you guys know.

@Fastball2880
Copy link

Fastball2880 commented May 3, 2024

Just a question is the 9.60 implementation compatible with SSD upgrad on ps4 because I have the problem that every time on stage 1 CPU corruption 93% the ps4 shuts down with unrepairable SSD corruption that forces me to make a recovery installation of the Firmware.

Just a question is the 9.60 implementation compatible with SSD upgrad on ps4 because I have the problem that every time on stage 1 CPU corruption 93% the ps4 shuts down with unrepairable SSD corruption that forces me to make a recovery installation of the Firmware.

I think that the kernel panic is what triggers the issue where you're sent to safe mode. Try switching back to a HDD and see if the same happen. I also did upgrade my PS4 with an SSD yesterday, and installed 9.60 from recovery. So far everything seems to be working as intended.

I also noticed that depending on the host machine, the exploit reliability greatly varies, if the machine is too slow, it will fail as it will take a lot of time to send the instructions and scan back.

  • Try reducing the variables such as Antivirus disabled and unnecessary apps closed on Windows
  • Use a faster host or even change distro if needs be. On about 15 attempts, only 1 passed on a dual-core machine (Celeron N3060), changing to a better machine (i5 7200U), the exploit runs without failing. I shall test the same machines on Windows and report back.
    NOTE: Both machine got 8GB RAM and SSD.
  • Also exploit seems to run better on Linux Mint than Ubuntu 22.04/24.04 & Manjaro (from my experience)

If I find anything else, I shall let you guys know.

I don't think this will be dependent on the speed of the CPU, amount of RAM and version of Linux distribution. The only thing that it's dependent on is the CPU architecture because it must be on AMD64 and uses gcc as its compiler to run the exploit, from the make command.

More info - https://gcc.gnu.org/install/prerequisites.html

@Fastball2880
Copy link

I also hope that this will be supported on ARM processors but there's no news for now to run it. I heard reports that it can be run on OpenWRT.

@Loafdude
Copy link

Loafdude commented May 3, 2024

The python script will run on arm but you need to compile the payloads on an x86
(or cross compile, or compile in a x86 docker container but its easy to compile on x86)

@Fastball2880
Copy link

The python script will run on arm but you need to compile the payloads on an x86
(or cross compile, or compile in a x86 docker container but its easy to compile on x86)

I was thinking the same as you'll build the binary either way. I'll try that on an Amlogic processor in the future. Great thinking.

@se2crid
Copy link
Contributor

se2crid commented May 4, 2024

win_7

Still in the works for 11.00

@W-i-n-7 Added

added to what?

@se2crid
Copy link
Contributor

se2crid commented May 4, 2024

it doesnt work for me at all i really hope its something fixable

2d96a6c

whats this? debug settings enabled?

It is payloaded loader for 11.00 that is now done, now we wait for goldhen port

@W-i-n-7
Copy link
Contributor

W-i-n-7 commented May 4, 2024

and then we wait for them to be ported to 9.03 through 10.71

@greetingstraveler
Copy link

Did over 15 failed attempts on a 9.60 console that had "Quick Initialize" done like a week ago.
Got stuck on either Stage1 "[*] Waiting for LCP configure request..." or Stage1 "[+] Scanning for corrupted object... failed".

Did a "Full Initialize" earlier today and it went through in first try afterwards, similar to #23 (comment)

Console: CUH-2216B
FW: 9.60
OS: Lubuntu 24.04

Done on a 2015 Asus X553MA .

@W-i-n-7
Copy link
Contributor

W-i-n-7 commented May 4, 2024

i reinstalled the whole fw on a separate ssd i still cant get it to find the corrupted object
i have ruled out everything the issue is in the exploit

@annahana
Copy link

annahana commented May 5, 2024

Tried it 30 times on 9.60 on Ubuntu 24.04 and even try Windows Version 20 times. Every time it stopped on stage 1 93% withe console crash or the check failed afterwards.

Multiple hardware testet

Os Ubuntu 24.04 and Windows 10
Gaming rig with Ryzen 9 7950X3D
Separate testet with Dell Latitude 5580 same OS tests
And an XPS 13 with network USB c adapter no change on behavior.

PS4 model CUH 1004A

@Superredstone
Copy link

My 10.71 shuts down after trying the exploit

I tried a lot of times in the last 2 days, i tried with a Windows 11 PC and with a Arch Linux laptop, i even tried initializing the PS4. The model is CUH-2216A.

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet