PS4 Rest mode exploit revealed (5.xx firmware)

3.7
Hacker Volodymyr Pikhur has presented an exploit of the PS4’s Rest mode a couple days ago at the Recon Brussels hacking conference. Earlier today, he released the slides and a demo video of his work in action. The slides state he’s been sitting on the exploit for 2 years and decided to disclose it since Sony does not have a bug bounty.

In the Video below, we can see the hacker running an FTP server, among other things, on the PS4 that was hacked in Rest mode.

According to the developer:

The custom Southbridge silicon, responsive for background downloads while main SoC is off, didn’t help to secure Playstation 4. We explain how a chain of exploits combined with hardware attacks will allow code to run in the context of the secure bootloader, extract private keys, and sign a custom kernel.




Posted:
Related Forum: PlayStation Forum

Source: http://wololo.net/2018/02/05/ps4-rest-mode-exploit-revealed-vpikhur-5-xx-firmware/

Comments

"PS4 Rest mode exploit revealed (5.xx firmware)" :: Login/Create an Account :: 23 comments

If you would like to post a comment please signin to your account or register for an account.

ZydrinPosted:

Crazy that exploits are starting to come out already.

MikePosted:

Hope this leads into something Big

QTPosted:

Mikey I'm sure Sony will fix this soon.


They should be already on it! No doubt.

TOXICPosted:

I'm sure Sony will fix this soon.

IQPosted:

I'll keep my PS4 on 5.05 until further notice. I would love to see this progress to allow users to use emulators!

SilkyPosted:

Big news in the hacking department although I hope this doesn't ruin the PS4.

ChatPosted:

It's no real surprise, I mean it sucks the amount of times Sony Has been hacked, Exploited or just messed with in general due to how bad their security is they make the money they can afford better, but they do not. Microsoft / xbox does it perfectly... literally hardly any progress if any progress at all, due to how strict and the actions they take.

TTGPosted:

Famous I will say Sony security team is worthless. It was a few years back where they started their enforcement team.

Yeah there not the greatest team for exploits. And didn't know they started a few years ago lol

hootPosted:

Not impressive defense by Sony.

Sad to see this happen on the 4.

FamousPosted:

I will say Sony security team is worthless. It was a few years back where they started their enforcement team.