Cool to see the N64 cartridge swap exploit finally released publicly.
I originally found this back in 2024, but couldn’t publicly release it for contractual reasons.
Here’s an old demo using it for region lock bypass, chained with RCE from shogihax: https://t.co/qEu7OKsBFf
… and just a couple of months later @gezine_dev managed to exploit the compiler process too!
This completes the mast1c0re exploit chain for the first time, allowing for arbitrary native userland code execution on the latest PS4 / PS5 firmwares, without needing a kernel exploit
Interesting FreeBSD advisory: https://t.co/bA924kg8O4
It’s the first path traversal I’ve seen where the kernel itself is returning filenames with ../ (normally path traversal bugs are at the application-level).
‘Universal Path Traversal’ (akin to UXSS) could be a new bug class?
i'm excited to share Collateral Damage, a kernel exploit for SystemOS on Xbox One/Series consoles! this initial release is mostly intended for developers, but i hope people will enjoy playing around with it! writeup and more updates in the near future :) https://t.co/D1VW0u79pr
This is big! New original Xbox exploit has been released, working on stock consoles with just a save.
Can be triggered from the Dashboard and used as an entrypoint for unsigned code, no exploit games or swaps needed!!
🥳
https://t.co/7EbRZSpSud
Part 2 - Attacking the compiler process: https://t.co/X2u4LmtSux
Ultimately I didn't finish the exploit, but hopefully it's still interesting, and maybe we will see a full exploit implementation from someone else in the future.
Part 2 - Attacking the compiler process: https://t.co/X2u4LmtSux
Ultimately I didn't finish the exploit, but hopefully it's still interesting, and maybe we will see a full exploit implementation from someone else in the future.
New blog post!
Part 1 in my new PlayStation hacking series: An **unpatched** PS4 / PS5 userland exploit that also allows pirating PS2 games.
mast1c0re: Hacking the PS4 / PS5 through the PS2 emulator - Part 1 - Escape: https://t.co/WOVd1YlZ8R
Video demo: https://t.co/C9bKvS9Cu4
For a variety of reasons, it’s time for me to move on from the PlayStation hacking scene.
I’m very thankful to have met some great people through this hobby over the years, and for the boost it’s given my security career.
Some of the highlights for me were:
6 months later and I’m still receiving new bounties from PlayStation. Just wanted to say: I’m very happy with my interactions with this team, and I can’t wait to disclose some of the findings!
mast1c0re: The first public PS4/5 userland exploit targeting a game instead of part of the operating system, making it the only one still unpatched on the latest firmware versions.
New blog post!
Part 1 in my new PlayStation hacking series: An **unpatched** PS4 / PS5 userland exploit that also allows pirating PS2 games.
mast1c0re: Hacking the PS4 / PS5 through the PS2 emulator - Part 1 - Escape: https://t.co/WOVd1YlZ8R
Video demo: https://t.co/C9bKvS9Cu4