Releases: soniciso1/poopicker
Release list
poopicker-host 2026.08.29
poopicker-host.exe - the offline DNS + HTTP/HTTPS host, one file, no install.
Run it elevated, point the console's DNS at the PC, open any address in the console
browser. Any unknown hostname serves the poopicker page, so a stale bookmark lands
on the index instead of an error.
Packed inside (707 files, 189.9 MB raw, 119.4 MB stored):
| site | chain | firmware | console |
|---|---|---|---|
poopicker |
- | - | the index |
p2jb |
kqueueex cr_ref leak |
12.00 - 12.70 | retail / testkit |
p2jb-dev |
same | 12.00 - 12.70 | devkit |
poopsploit |
netcontrol IPv6 rthdr UAF |
7.00 - 12.00 | retail / testkit |
poopsploit-dev |
same | 7.00 - 12.00 | devkit |
luasauce |
UMTX | retail / testkit | |
luasaucedev |
UMTX | devkit |
Use poopsploit on 12.00 and below - it jailbreaks in seconds and tears down cleanly.
p2jb is only needed above 12.00: its leak runs ~55 minutes before the race starts.
luasauce / luasaucedev are a verbatim copy of zecoxao's
sites (commit 1a107fe). Not our work; the credits on those pages are theirs and unmodified.
Changed from the previous build: the combined poop2jb / poop2jb-dev sites are
replaced by the two engines they bundled, shipped separately so each is picked directly.
No experimental forks are included.
Verified before shipping, on spare ports so the live host was never touched: all seven
hostnames 200 over HTTPS with the right title; an unknown hostname falls back to poopicker;
every asset referenced by any html/js/appcache in any site resolves 200;
kstuff-devkit-only.elf 200 on the -dev sites and 404 on retail; bridge.elf, *.orig
and *.pre-* all 404.
Source is in host-src/. host-src/tools/unpak.py lists or
extracts the archive appended to the exe, so you can check what is actually in it rather
than taking this list on trust.