-
Notifications
You must be signed in to change notification settings - Fork 354
New issue
Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.
By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.
Already on GitHub? Sign in to your account
✨ 10.00/10.01 Support #2
Conversation
Special thanks to Zecoxao for his help. Don't merge this yet, gotta test it. |
You probably also want to modify the offsets.h files |
Thanks!
|
Edit: I forgot stage2 offsets. 🤦♂️ |
I am on 9.03 I can help testing it if you want |
I tried 4 times on 10.01 and no luck did u get it work ? |
@TheOfficialFloW Seems like there is something strange happening during Btw, I'm running the python script on windows. Could be the reason tho, so I'm going to boot Linux and test again. |
@EchoStretch Nope :/ |
what are u using to get offsets. Maybe not correct? |
@EchoStretch Odd. As you got to that stage, it's likely to be an offset issue then. Going to recheck all of them.
Ghidra, and I'm manually xrefing. |
What do you use? |
IDA and Ghidra |
Seems like the changes that theflow0 just made improved stability. While the script still freezes at |
Teach me your ways🥲😂 |
Also have a 9.03 and would be interested to see it working, sorry I can't really help much I'm not super proficient in this space :> |
yeah me either but I want to help and learn lol |
So I Tried I've talk with lightingmod and he is on 9.00 pro and it always work and i talked with moddedwarfare and his is on a fat 11.00 and its always works. I'm Lost.. lol |
Just for more data my 9.00 Pro exploit is 50/50 success rate |
Could we get Some sort of homebrew enabler coming soon? |
If there will be 10.50 support in progress I can help test it |
I am also on 9.03 and would like to help testing it😁 |
10.01 can wait. Gonna continue working on 9.03. |
You mean 9.03 can wait but I get you. Good luck you are doing a mighty work |
tested on 10.01 fat ps4 does not work: [+] PPPwn - PlayStation 4 PPPoE RCE by theflow [+] STAGE 0: Initialization [+] STAGE 1: Memory corruption |
Konsolendaten: Hi, I tested it on Windows with a Linux VM. But I noticed interesting behavior patterns of the console.It reacts once out of 10 cases but goes straight out. I hope I was able to contribute something useful.
Genau das gleiche bei mir. Console data: |
Can you send the precompiled file? I am on 10.01 slim it does not work. fails at corrupted object |
My way: first FW:900 Command and then FW=1100 Command At (PS4 boot) |
🎉 |
Bis jetzt kein Erfolg mehr mit Object Suche und Debug mode auch nicht (Konsole stürtzt ab) .... :( |
Just try over and over again. It will eventually work |
Ich habe es jetzt so oft versucht auf alle möglichen wege und es Funktioniert nicht mehr
|
Payload successful !!!! , but no debug menu Test 2.0: successful Payload, No Debug menu |
tested it on 10.01 [+] PPPwn - PlayStation 4 PPPoE RCE by theflow [+] STAGE 0: Initialization [+] STAGE 1: Memory corruption [+] STAGE 2: KASLR defeat [+] STAGE 3: Remote code execution then just crashes and has a bit of trouble turning on |
Mein weg: (1) PPPwn Ready |
he made an error when compiling he compiled stage1 & 2 with the FW=1100 instead of 1001 lmfao |
Oh😅, Payload always works for me now but the debug menu does not appear...🤷🏻♂️ |
It is wip, so no debug menu, all that should happen is PPPwn in top left |
ok thanks, that means I did everything right and my console is ready😇 |
why doesn't it work for me :( |
try again? |
In my experience(not a lot) it can take a lot of tries @lompaket |
You can try tuning some parameters in the script (e.g. the ones changed in 0730790) |
Might try that. I think 1/8 tries max work. either fails at memory curroption, or IPCP configure request... when it goes past those 2 points it works perfectly. |
I have tried over 20 times it mostly fails at checking for corruption or something and crashed 2~3 times |
Same here, no success on 10.01. It hangs at the Here is an ouptut :
Console : PS4 Pro |
works fine for me 10.01 fat ps4 |
use the network cable to directly connect PS4 and PC, I had the same problem. It worked perfectly here 10.00!! |
Ich habe mal aus Langeweile versucht Goldhen als Payload zu senden.... Error. D:\PPPwnGo-main>python pppwn.py --interface="Realtek Gaming 2.5GbE Family Controller" --fw=1001 [+] STAGE 0: Initialization [+] STAGE 1: Memory corruption [+] STAGE 2: KASLR defeat [+] STAGE 3: Remote code execution [+] STAGE 4: Arbitrary payload execution D:\PPPwnGo-main>pause |
Found corrupted object on Firmware 10.01 : (1) fe80::07a5:4141:4141:4141 (2) fe80::0363:4141:4141:4141 (3) fe80::0da7:4141:4141:4141 |
I have an oddly specific problem. weekstrt on discord if you want to try help me in short when I try exploiting from my main OS (fedora) it crashes my ps4 everytime If I live boot a usb with something else like linux mint it works |
✨ Added missing 10.01 offsets
(untested)