Working Webkit exploit on FW 3.15

Working Webkit exploit on FW 3.15

Post by m0rph3us1987 » Thu Mar 24, 2016 10:49 am

by snooping around in FW 3.15 I have found at least two new
entry points where the webkit exploit is working. Yes the
webkit exploit is still working on FW 3.15 (the skilled people here already knew this),
the difference is, it cannot be exploited in the browser but from a different place.

Changing some of Nas, Proxima and CTurt's code I am able to dump the memory the ps4.

I have identified the base address of two processes and some modules loaded by the
application I am using as entry point.

I am trying to get some code execution in form of ROP to work, this could be used
to trigger some kernel exploit that maybe will be found in the future.

The problem I am facing, is that I do not know how to find the address on the stack
where I should write the ROP chain.

Is there anybody out there who is able to give me some help? Thank you in advance.

And of course thanks to Nas, Proxima and CTurt.

Re: Working Webkit exploit on FW 3.15

Post by fx0day » Thu Mar 31, 2016 1:00 am

The apps that are using the webkit are useless, since as Cturt said, they have no access to JIT... only the main browser does.
but he did say, ROP still works in them, and you could trigger a kernel exploit from them, but for the most part they're not feasible....

Thanx to Zer0xFF for the tip ;)

Re: Working Webkit exploit on FW 3.15

Post by abcdf » Mon Apr 11, 2016 5:07 pm
Re: Working Webkit exploit on FW 3.15

Post by » Sun Apr 17, 2016 7:53 am

Well done m0rph3us1987 ! :)

Have you thinked about selling your 3.15 PS4 for a new or 2nd hand 2.xx PS4 ? (easy to find...)
You won't loose too much money and you will be able to reuse the dlclose kernel exploit.

Open it to 2.xx PS4 will make it grow the comunity at least by x10 I think !

