Jump to content
New Front Page Read more... ×

    Specterdev publishes WriteUp about the 5.05 PS4 Kernel Exploit

    By Thibobo,
    Today Specterdev published a writeup about how the 5.05 Kernel Exploit/Jailbreak for PS4 was realised that was found by Qwertyoruiop. The WriteUp is full of technical information how everything was done & patched by sony on 5.05-5.07<5.XX       https://github.com/Cryptogenic/Exploit-Writeups/blob/master/FreeBSD/PS4 5.05 BPF Double Free Kernel Exploit Writeup.md

    [Released] Skyrim CFW/HAN Modding Toolkit v1.0

    By clayson,
    Hey PS3 CFW/HAN Skyrim modders! Today I (@clayson of Elite Electronics) am releasing this All-In-One Skyrim Modding Toolkit for CFW/HAN which will be capable of converting a .bsa's file formats to work on PS3, converting plugins to master plugins and vice versa, and also building mods into a .pkg to use on HAN/CFW (which works without Elite Edition, although Elite Edition v3.0 is recommended). This tool can convert Sounds/Music, Voice Dialog, and Animations automatically in a .bsa to work on PS3 Skyrim. Unfortunately no DDX to DDS/DDX to DDS yet, but in the future we hope to include this. So enjoy and if you find any bugs or want any features please write a response on the thread and I will get to you, thanks! 😀

      Download: PS3 Skyrim CFW/HAN Modding Toolkit v1.0 - (Virus Scan)
    Disclaimer: Do not re-upload my work anywhere without my permission first, also please do not use any of the resources in this program without my permission, thank you.   Features of Skyrim CFW/HAN Modding Toolkit: Can convert file formats inside .bsa automatically to work on PS3 with a click of a button. Can convert plugins to master plugins and vice versa. Can convert file formats such as Sounds/Music, Animations, and Voice Dialog from PC to work on PS3. Can build mods into working installable .pkg files for HAN/CFW, mod .pkg files don't require Elite Edition, but Elite Edition v3.0 is recommended.   Credits: @clayson (Programmed the converter tools, researched and reverse engineered certain file formats, and programmed main tool.) @Death_Dealer (Helped research .hkx format and taught me a lot about reverse engineering files. Also researched a lot about DDX files.) valentinbreiz (Helped improve some of the code in the converter tools.) figment (Programmed the unpack bsa function of this tool, code available on his GitHub.) zilav (Programmed the bsa packing function of this program aka "bsarch", code available on his GitHub.)   Changelog: v1.0:   Join the PlayStation Game Modding Discord!   If there is a problem with something here or bug with my tool please PM me on Discord or reply to this thread and tell me. Keep in mind if you mess with any of the folders/files that come with the tool EXPECT errors, I won't help you if you modified any of the files (unless you are trying to add a new game id to the pkg builders, I can make a new version supporting different versions of Skyrim if needed). Thank you! 

    h-encore, 3.65-3.68 FW Hack has been released by TheFlow

    By Shiro,
    As TheFlow has promised the community to release hacks for versions higher than 3.60, he finally released h-encore which installs Henkaku/TaiHen on the device.   What could i do with h-encore ?
    1- install pirated games(PSP/PSVita) .
    2- run unofficial apps/games (Homebrews). 3-Custom plugins/modifications . 4-If you are still on 3.65 or below, you can update to 3.68 to run games required higher FW.   What is the difference between FW 3.65,3.67, and 3.68 ? 1-3.65 Users will be able to install Enso, a Custom Firmware for the PSVita, which boots Henkaku at the booting process automatically. 2-There is no a big difference between both 3.67 and 3.68. The most advantage that those two FWs has is the ability to run required newer Fw games    How do i Hack my Vita ? 1- If you are below FW 3.65, Update your PSVita to FW 3.65 or above by two methods :
    A- Updating manually to FW 3.65 Using qcma. Use this site to find the Specific FirmWare : DarkSoftware Follow the instructions in the video below:          or  Instructions B-Updating Directly to FW 3.68 by going Settings>System Updates. 2-If you are on the right Firmware ....Click Here and follow the steps given:   Here are some links to put in consideration:   1- Enso 2-Adrenaline(a PSP Emulator) 3-NoNpDrm v1.2(fake license 4-How to install plugins   Sources :
    1-TheFlow 2- Wololo 3-Darksoftware 4-github

    [Tutorial] How to | Change the SSID/AP name of your esp chip

    By zapptheman,
    Hi guys.   One of my subscribers recently asked me to show them how to change the SSID name for their ESP8266 chip while running someone else's firmware.   At the time of writing this, it seems that c0d3m4st4's firmware is one of the best around, which also has the greatest user base. So i will be making this tutorial using his firmware. You can download it by clicking here. He has also advised me that in a future release, it will be much easier to change the AP name as it will be a built in function which i will show below. But for the time being, there are many other firmware's out there which also do not allow you to change the AP name, so i will be showing you how in today's tutorial. Please find a video below for visual instructions, and a written tutorial beneath for written instructions (for your preference)   Video     Written Tutorial   What you will need:   c0d3m4st4 firmware - https://playstationhax.xyz/forums/topic/4550-released-esp8266-xploit-host-v271-by-c0d3m4st4-ps4/ The Tool to flash your ESP chip - https://github.com/marcelstoer/nodemcu-pyflasher/releases HXD - https://mh-nexus.de/en/hxd/ FileZilla - https://filezilla-project.org/download.php (optional if you want to use FTP functions)   Step 1: Download all of the above files, you can substitute the firmware for one you wish to use. (I AM USING VERSION 2.70) Step 2: Make sure you install HXD and extract the firmware file and flash tool to a location you will remember. Step 3: Flash the Firmware file to your ESP chip for the first time if you haven't already. Step 4: Unplug it from usb for about 10 sec once done flashing, then plug it back in and wait for the wifi network to come up. Take note of the AP name, in my case it's "ESP8266XploitHost"  Step 5: Locate the firmware file you flashed and open it up with HXD. Step 6 (you can skip to step 17 if you are using the same firmware as me): Now you need to find the correct offsets to modify. This will be trial and error so can take some time depending on how fast you are Step 7: Press (ctrl + r) on your keyboard to bring up the replace tool.  Step 8: In the "Search For" field, populate this with the AP name I told you to take note of earlier. In my case, it was "ESP8266XploitHost" Step 9: In the "Replace With" field, enter what you want your WiFi name to be, In my case, i did "ESP8266XploitTest" (note that when changing the name, do not make it anything longer than what was originally there or else you will break the firmware)  Step 10: Select "prompt on replace" and select "All" for the search function and then press "replace all". When the first notification comes up it should read "Confirm" Before clicking ok, take note of the Offset, write this down somewhere. (The part highlighted yellow in the image below is the offset) Step 11: Once you have written down the offset, press "Yes" and let it replace that value with the name you want to use.  Step 12: Another box will come up asking you to confirm, you can click the cross in the top right corner of the box to close it. Step 13: Flash save this file and flash it to your ESP chip. Step 14: Repeat step 4 and see if the WiFi name has changed (i would recommend using a phone to check as windows wifi cache's the old ssid/AP name so it might not show thenew one) Step 15: If this worked for you, then you can continue to the next step, otherwise, continue performing steps 6 - 14 with the same firmware file until the AP name changes. Step 16: If you are here now, the last change you made must have updated the ssid/AP Name, Make sure you remember the offset for the one that changed it, and now extract a fresh version of the firmware which you have not yet modified. Step 17: Open the fresh firmware file and press (ctrl + g) and enter the Offset value in there. (In my case, it was 00056970) then press "ok" and it will take you to that offset.  Step 18: Click on the text in the right side (click just before the first letter of the wifi name) And begin typing the name you want it to be (DO NOT PRESS THE DELETE BUTTON) Step 19: If your name is shorter than the one which was there, you will need to click on the hex values on the left, and click on the one which resembles the next character on the right. See the image below Step 20: type 0's until you reach the zero's which are already there (this is so that no further text is entered into the SSID/AP name Step 21: Flash it and repeat step 14 to test that it all worked. (If this didn't, try again the process again from the beginning until it works for you) Step 22: Profit? This should now work as normal just with a different name.   Optional extras to FTP   Step 23: In order to FTP to this device you will need to download an FTP client such as filezilla, and install and open it for use. Step 24: Connect to your ESP chips WiFi with your PC. Step 25: In the top left corner, you will see a button which when hovered over states "Open the site manager" Click this button Step 26: Click on the "New Site" Button on bottom left of the box that popped up. Name it whatever you want.  Step 27: To the right, put the host address and port (Consult your firmware's documentation to see if FTP is supported and the credentials) For me, the IP was and the port was 21. Step 28, just a bit further beneath the "Host" textbox, you will see a dropdown menu for "encryption" click this and select "only use plain FTP" Step 29: For logon type, select "Normal" and enter the credentials for your chips firmware. for me it is User:ps4xploit Pass:ps4xploit (note, password may change when you change the password for the WiFi) Step 30: click on transfer settings and select "limit number of simultaneous connections" and make sure it is set to "1" Step 31: Click Connect and it should work. (if not, try unplugging for a minute and plugging back in and wait a min for your PC to connect and try again. Step 32: Profit?   Thanks to @c0d3m4st4 for the great firmware and for letting me make this video/tutorial. If you guys want to say thanks to him for his time, please feel free to support him   Should you have any Questions or queries, feel free to drop a comment below and I'll see if i can help you out.

    [Released] reactPSPLUS v0.1

    By GregoryRasputin,
    Developer @Zer0xFF has updated reactPSPlus to version 0.1   Download  Official Blog Post Source

    PS4 SDK Updated For Firmware 5.05

    By GregoryRasputin,
    So the PS4 5.05 hack has been out for a while, yet no one has created any homebrew for the console, developers claiming they don't want to use the official Sony SDK have hidden away, now they can stop being lazy as @bigboss has updated his SDK for use on firmware 5.05, here is a quote from the source:       Download/Source

    PS4 Trainer By TylerMods

    By GregoryRasputin,
    TylerMods has released a Trainer for PS4 games, here is a quote from the source:       Source/Download

    bigboss Releases fMSX For PS4

    By GregoryRasputin,
    Veteran scene developer @bigboss has released fMSX, which is a FSX Emulator for the PS4:   Source Via

    PS4DLL RTM, a simple way to code your own C# tool

    By ImMrNiato,
    PS4DLL RTM, a simple way to code your own C# tool    Today I bring you a C# library wich allow you to code easely your RTM tool for Playstation 4. This library include the PS4Lib by BISOON but also include something new like an adresses library.   In this Library you will be allow to put your own offset and bytes like you can see on the pictures so it will be very easy to code your tool and share your offsets with the rest of the community. I share this project in open source and I have included a sample to help to understand how it work. You can create the most complete library for your RTM Tool, I left some exemple on the library like the offset I use on BO3 1.23 & 1.26.   You can also grab offsets from .cht files and include them in the library to code your own tool.     Dll + Sample + more informations :  here

    [Tutorial] Dump Ps4 games on 5.05 and create Fake Packages (Works With ESP8266 Chip)

    By zapptheman,
    Hello everyone   Back again with another tutorial   Getting straight into it, this is a long and lengthy process. I have made a video which i will post below, i highly suggest following the video as it goes more in depth than the written tutorial i will have below, but if you are more experienced and know things, then you should be able to figure it out from my written tut. Feel free to refer to the video at any point. This might not be easy the first time round   Video:           Written Tutorial   What you will need:   - PS4 on 5.05, 4.55, or 5.05 firmware. - xVortex's Dumper payload/tool - Al azif's exploit host (if you are hosting locally) - Fake Package generator (You need to find this yourself)  - A hard drive or USB big enough to fit the game you are ripping - A PC   Optional: - Node MCU ESP8266 chip - (ENTER INTO THE COMPETITION TO WIN ONE BY CLICKING HERE TO GO TO THE COMPETITION THREAD) - The Tool to flash your ESP chip - c0d3m4st4 firmware for your ESP Chip - Notepad ++ - Compare plugin for Notepad ++     Process: Step 1: Setup your exploit method of choice. Step 2: Make sure you can use xVortex's payload. Step 3: Boot your PS4 and make sure the game you want to dump is uninstalled. Step 4: Make sure you adjust your power settings so your PS4 does not automatically shut off. Step 5: Insert the disc for the game you want to rip. Step 6: Plug in your hard drive into the USB port. Step 7: Run your exploit and inject the PS4-dumper-vtx.bin payload. Step 8: Wait for the message to come up on the screen "waiting for game to launch" Step 9: Wait a very long time (this will depend on the size of your game) - you will see updates every 30 sec, first they will say "waiting for game to copy" and followed by a percentage. This is copying from the disc to your PS4. Once it is done copying to the PS4, it will then begin to copy to your Hard Drive. (i suggest you just leave your ps4 until it shuts itself off and go do something else for a few hours) Step 10: Once your PS4 has shut down, wait for the lights to go out completely, then you can remove your Hard drive and plug it into your PC Step 11: Open your hard drive's root directory on your PC, you should see 3 files (a folder and a file which begin the same, this is the serial number for your game, and a dumper.cfg file) check the file which is names similar to the folder, but it's just a file. You need to see if the extension is ".complete" or ".dumping" [For example "CUSA02624.complete"] Step 12: If your filename ends in .complete, you can move forward, if it ends in .dumping, then go back to step 1 and try again. Step 13: Copy these files to a folder on your PC somewhere of your choice. Step 14: Open Vortex's GenGP4 program, click on the browse button, and seek to the folder where you copied the files to, and then click on the game folder. (for example, the folder name for my game was CUSA02624-app) Then click open. Step 15: Now click on "Genetate .GP4" and wait for it to say "Done" then click on "Save .GP4" and then save this to the same directory your game files were in.  Step 16: You will need to open your fake package generator, and then flick on "File" and then "Open" and seek for the .GP4 file you just created and try to open it. - If this worked without any problems, you can skip to step 23. If you just got an error, particularly the scenario Error, follow along. Step 17: you will need to have notepad ++ and the compare plugin installed. Step 18: Open the GP4 file you created in notepad++ then go to the game folder you copied to your computer earlier. open "sce_sys" folder. Locate the "Playgo Manifest.xml" and open that in Notepad ++ Step 19: Make sure you have the last file you opened in notepad ++, currently in the viewer. Click on plugins on notepad ++. and click on compare. If a message comes up click yes. Step 20: You should be able to see how the start is quire similar. Make sure you mirror anything that is missing, i would suggest checking my video for this part as it is hard to understand without seeing. open spoiler for more info. Step 21: Once finishes mirroring files, you can save them and close them.  Step 22: Open fake package tools again and try open that .GP4 File. It should work now. Step 23: Click on the command drop down menu --> Project Settings --> Package and change the storage type to Digital and BD Max. Step 24: Click build on the rights of the program up the top. Then click "select" next to "Output path" and select where you want to output the pkg. You can name it whatever you want. Select Build again and it will now build the PKG Step 25. If you get any errors, feel free to comment down below and I can try help you out, but only if you have tried to fix your gp4 file. If you get the error prior to building, please upload your GP4 file's contents to pastebin and comment down below with a link to it in pastebin. If you are getting an error during the build process, please save your log and upload to pastebin and then link to it here.  Step 26: If you have made it this far, then you are almost there. Copy the pkg you have created back to your Hard drive, then safely remove it, and plug it into your PS4. Step 27: Run your exploit, launch mira + hen or just hen, then install the package through package installer in the debug menu. Step 28: Try run the game once it's finished installing. Step 29: Profit? Step 30: Didn't really need a step 30 but i wanted to make it look nicer Feel free to support me by watching my videos, or even buying me a coffee. Let me know if you guys need any help and i will do my best to help where i can.   BIG SHOUT OUT TO @cfwprophet FOR HELPING ME WITH THE ALTERNATE METHOD TO PKG THESE GAMES SHOWN IN THE VIDEO!   Thanks to all over devs involved in making the scene what it is this far, including Al-Azif and xVortex and c0d3m4st4.   If you want to create a FPKG without the genGP4 program, open this spoiler for some info. This way is more complicated, but works for 75% of games, worth a shot if nothing else is working for you.  

Portal by DevFuse · Based on IP.Board Portal by IPS