| Note that, there are many scam sites that claim that permanent custom firmware (CFW), downgrading, online jailbreaks, retail game unlockers, and online cheats are possible. This is not true. |
Questions and Answers
What is jailbreaking?
Jailbreaking is, on a basic level, a term used when the console gets exploited to unlock various levels of the firmware that allows the access to many features previously accessible on a DevKit/TestKit (used by game developers and testers) to a consumer or to add additional functionality.
How do I jailbreak my system?
Refer to the Basic Guide.
What is the status of jailbreaks across all firmwares?
4.05 to 13.00 have been fully exploited and implemented. (13.02 and above have no jailbreak).
Exploits on some of these firmwares have been ported to “fill in” the gaps in releases. Most, if not all, firmware versions between 4.05 and 13.00 can currently be jailbroken.
How can I downgrade if I’m not on an exploitable PS4?
Downgrading is NOT possible with just firmware installs on normal PS4s, only on TestKits and DevKits.
There is a way to revert to a previous firmware ONLY IF the user has made backups of the sflash, Syscon, and HDD, and requires soldering skills. Alternatively, you can downgrade to the immediate prior firmware to your current one, this also requires soldering.
- Why? Can’t I just swap HDDs, or put a lower firmware on USB and install it via Safe Mode?
- NO. The firmware is not just stored on the internal HDD. Part of the firmware is stored in a read-only encrypted soldered chip on the PS4’s motherboard that also keeps track on the installed firmware and restricts the install of a lower firmware.
The reason is to ensure the user stays on latest firmware, and it also makes the firmware experience faster and easier than normal.
Can I revert to previous firmware?
See: PS4 Firmware Revert
Can I install Custom Firmware (CFW) on my console?
GoldHEN and Mira already have Custom Firmware level access, but they do it in memory and require user interaction or an external setup to be loaded via a kernel exploit which resets after a reboot or shutdown.
The 3DS, for example, patches the firmware on boot via a bootloader exploit. Enso on the PS Vita, which modifies the boot process by loading HENkaku at start-up but requiring the Vita to already be on a certain firmware or go to it via a downgrade with modoru while running h-encore². Both of them are easily accepted as having CFW.
The PS3, for example, is an extremely special case whereby they acquired private signing keys via an ECDSA implementation vulnerability on the console and later acquired leaked universal lv0 decryption keys. They were able to use them to edit the firmware and add the desired changes, with the limitation being that certain PS3 Slim and all Super Slim models did not have their keys available via the same methods, so they were left with only HEN, which is much less stable and cannot alter firmware like on CFW compatible consoles. Seeing a PS3 style of CFW on the PS4 or any other console is highly unlikely.
How do I know if a console has a jailbroken/exploitable firmware version
Starting with January 2021, any brand new PS4 Pro and OG PS4 (fat) console are guaranteed to be on 8.03 or lower. PS4 Slims, while they were still made after 2021, have a 60/40 chance to be on 8.50 or lower.
Second hand devices will all have different firmware installed depending on how the system was used, and an attempt to contact the seller about the current firmware should be made.
Is it worth it to stay on a lower firmware?
If you are on a non-exploited firmware and some day want to be able to run homebrew, it is recommended to stay on the lowest version possible. If you have the money to spare to buy a second console, that would be an option. If you are on an exploitable firmware it is best to stay on the lowest major release with some exceptions (the stable recommended firmwares are 5.05, 6.72 and 9.00). Do note, jailbreaks can be updated in the future.
Can I spoof my firmware version in order to play online with a lower firmware?
You can not access the PlayStation Network without being on the current firmware. In the past, PSProxy has allowed you to do this, however it no longer works.
Will a factory reset update my firmware to the latest version
No, it will not. It will only reinstall the current firmware; see the First setup, updating or replacing/upgrading storage Guide for more information.
How can I replace internal storage, factory reset or update to a desired firmware
Refer to the First setup, updating or replacing/upgrading storage Guide.
What can I do with a jailbroken PS4?
After a successful jailbreak, you can:
- Install and play your game backups/disc games without needing a disc/license/PSN account.
- Access emulators to play your favourite classic games.
- Access various homebrew and other fan-made tweaks to your favourite games such as useful applications, emulators, 60FPS patches, etc.
- Access and install a fully featured Linux distro.
- Access mods for your games.
Emulation
- PS1 Games run with varying performance. See: PS1 Classics Compatibility List
- PS2 Games run with varying performance. See: PS2 Classics Compatibility List
- PSP Games run with varying performance. See: PSP Emulator Compatibility List
- PS3 Emulation can only be achieved in Linux on the PS4, but it's not a playable experience.
- In Linux, you can run emulators for other consoles as well, but performance will vary.
How can I exit IDU Mode?
See the IDU Mode Escape article.
What can’t I do with a jailbroken PS4?
While the advantages are plenty, you will lose some functionality such as:
- Online play on most games. You can play online on some games by using tunnelling software such as XLink Kai, or using custom servers.
- All PSN features such as messaging, online trophy syncing, various PS Plus features such as online save data upload and other features that are dependent on PSN such as Spotify.
- Depending on the release date of the jailbreak, firmware and games, some newer games will not be available. Games can be backported to work on older firmwares, but not every game gets one.
- Jailbreaking, regardless of firmware version, is NOT permanent/persistent after reboot or shutdown, compared to PS3 and Vita with a CFW. A persistent CFW is impossible on PS4 currently. The exploit runs in memory.
What is GoldHEN?
Here are some things GoldHEN can do.
- Integrated cheat, patch and plugin support.
- Create an FTP Server for file transfers giving you full access to the PS4's internal and any external storage.
- Create a BinLoader Server to load community made payloads like firmware update blocking, fan speed control, UART enabling and many more.
- Homebrew Enabler: These features allow you to install community made applications and utilities like and install game dumps in FPKG format along with updates and dlc.
- Homebrew Store > a homebrew-oriented store front-end which lets users download and install apps and homebrew games directly onto the PS4 where you can also download the homebrew apps mentioned bellow or visit the website PKG-Zone
- Itemzflow Game Manager > Itemzflow is a Free and Open source PS4 home menu alternative Itemzflow expands the beyond limits of Sony's ShellUI as it allows you to launch games back up games,updates, dlc etc.
- Apollo Save Tool > Automatic Save-mounting (GoldHEN or ps4debug required), Offline Account activation, Save editing utility
- PS4 Cheats Manager > A Homebrew application that allows you to load cheats,patches and plugins via GoldHEN for games.
What is the difference between Mira and HEN (GoldHEN)
Mira and HEN/GoldHEN are both payloads that share the same main purpose. They modify the operating system of the PS4 to give the user more control over their console. Namely, they give the user access to debug settings, allow game backups to played, and allow homebrew to run. Since the release of GoldHEN, general users should be using GoldHEN, while homebrew devs might need to use Mira. GoldHEN does this main task with a handful of other features. It is more lightweight than Mira and is therefore more stable on firmwares above 6.72.
WARNING FOR GAME DEBUG SETTINGS
In GoldHEN you have the option to enable game debug settings which give you more power over game data. If you're not careful in the extra *Delete menu that shows up once this is enabled, you may delete save data on the whole system, so take note of the ticked boxes.
How do I disable automatic updates?
You can disable automatic updates by navigating to Settings → System → Automatic Downloads and Uploads, and uncheck “System Software Update Files” and “Install Automatically”. It may also be a good idea to turn off Internet connection while in stand-by mode under Settings → Power Save Settings → Set Functions Available in Rest Mode and uncheck “Stay Connected to the Internet”, as this feature is only useful for being able to turn on a rest mode console from the network with Remote Play. You can also just disable the Internet altogether.
- Additionally see Disabling Updates for more advanced update blocking.
How do I install PKGs to internal and external storage?
For information on how to install fpkgs and retail pkgs see: How to Install PKG Files.
For information on how to install fpkgs and retail pkgs to the external drive see: Installing PKGs to an External Hard Drive.
How can I manage my savedata or import new savedata/ offline account activation?
For all of the above, see the Apollo Save Tool article.
How can I use cheats, patches and plugins? (mod menu related)
See the guide on Using Cheats Patches and Plugins
The PS4 system internal storage structure and how to browse it
For an overview of the HDD and all visible contents like user data, savedata, game data and much more see Files and Directories.
Take caution when accessing the internal storage.
To browse with FTP see Transferring Files with FTP and FileZilla.
You can also use PS4-Xplorer without a PC.
Firmware required for games and backporting
Retail/FPKG games and their updates have a minimum firmware version that they can run on, although FPKGs usually have backports which means they can run on lower firmware than the retail games.
- Backports patch the minimum required firmware version to allow it to run on lower firmware.
Why are newer games not available on latest jailbroken firmwares?
Game backups can be made by either dumping or by knowing a unique, very hard to guess, decryption key. Most backups are made by dumping.
Sony implemented a minimum firmware for both games and updates to games, forcing the user to update to launch the content. To dump a game, the user must have the game running, thus why a dump is not possible.
As for the decryption keys, you will rarely see game backups being made from this method. This method might be better for updates, on which, a fpkg version of the update can be made with the decryption key, as some games will have the same key for both main game and updates.
Can I play games that require a higher firmware version than what I have?
Yes, you can for instance play backups made on a 6.72 exploited system on a 5.05 by applying specific patches to the pkg files. See this list made by kiwi/defaultdnb to check what minimum firmware requirement a game needs. For updates, see OrbisPatches to check what minimum firmware requirement a game update needs.
Title IDs, User IDs, and Account IDs
What is a Title ID?
- The product code is distinct to a region, and the common codes you’ll see are CUSA, PCAS, and PLAS.
- R1 USA-CUSA
- R2 Europe-CUSA
- R3 Asia-PLAS, PCAS
- The product code is followed by a 5 digit unique number identifier.
- The Title ID is the Product code along with the unique numerical identifier of the game.
- For example Minecraft USA is CUSA00744 while Minecraft EU is CUSA00265
- Another example Resident Evil 2, USA is CUSA09193 while Asia is PLAS10335
- The majority of games you come across will use CUSA.
What is a User ID?
The user ID is the internal description for the local user account. (Example - 11cd8de)
What is an Account ID?
The Account ID a PSN ID assigned to the local user. (Example - abcdef01234556789) but must be 16 hex characters.
I rebuilt my database and now all my homebrew and games are gone! How do I get them back?
Jailbreaks, how they work, and which firmware should I stay on (5.05-13.00)
| No jailbreak is currently available that is persistent after a reboot. |
In the context of the PS4, exploits allow you to run arbitrary/unsigned code by exploiting weaknesses in the system and gaining userland access to execute code in the console with the same permissions as an average app or for a full jailbreak to run Homebrew like Goldhen a kernel vulnerability is also needed.
TLDR: Exploits come before GoldHWN/Mira/HEN.
Userland Exploits
WebKit Exploit
WebKit exploits which are loaded solely through the PS4 Browser. The active ones range 5.05, to 9.60, currently have kernel access.
BD-J Blu-Ray Exploit
BD-J is an entrypoint through the PS4 Blu-Ray player. The current active one works on 12.52 and below.
It requires a Blu-Ray disc to be burned with the exploit data (iso) and put into the console to load. Preburned discs are also available for purchase by 3rd parties.
- DVD's and CD's will not work.
Lua Save game exploit
The Lua save game exploit is a userland exploit which can be achieved by injecting Lua code into a save file of specific Japanese erotic games... The exploit is loaded upon opening the game.
- The requirements to use the exploit is as follows.
- An activated PSN account on your console which will allow you to import and export save files.
- As an alternative, you can download a console backup file which will initialize your console while importing the save file you need. After which you can fake activate the account with Apollo Save Tool for future use.
- A Lua exploit compatible game disc or demo. The demo cannot be acquired if you did not previously download it, this means if you do not have the demo now you have to buy a game disc.
- A way to decrypt save data and resign/encrypt it. This can be done with another jailbroken PS4 or with a discord bot or Save Wizard(Paid).
A list of the compatible games can be found here.
Obtaining Lua game FAQ/Q&A
For game demos:
- No, you cannot download a demo on a different console and transfer it with an external drive.
- No, you cannot take someone's console backup that has the game demo and have it work.
- No, you cannot use IDU or anything else to install the demo and have it work.
- No, you cannot download the demo if you aren't on latest firmware.
- No, you cannot get the demo at all if you already don't have it while keeping your current firmware.
In conclusion, you're going to have to buy the game disc if you don't have the demo, or use another exploit. You can buy the game disc from various sites, especially proxy sites that buy the item for you in Japan and ship to you like FromJapan and Buyee. This makes the total price quite a bit cheaper than eBay etc, especially if you're buying multiple other items from Japan.
Netflix Exploit
The Netflix application on both PS4 & PS5 can be used as a userland exploit for 9.00 to 12.02, in a similar way to the Lua games and Yarpe. (All 3 usable as a userland up to latest firmware.)
However, like PS4 game demos, it also requires a valid license on a PS4 that has previously been activated as a primary PS4 in order to be usable.
A tutorial on using this exploit via a MITM attack can be seen on the Netflix-N-Hack article.
Yarpe Exploit
Similar to Lua this exploit is python based in renpy games from Ratalaika Games. The games are available physically and digitally. Although only usable with a kernel exploit up to 12.02 but still work as a userland exploit up to latest firmware. https://github.com/Helloyunho/yarpe
PS2 Emulator Exploit
The PS4's PS2 emulator can also be utilized as an exploit entry point, as shown with Mast1c0re.
Mast1c0re is currently the only game with a public userland+kernel exploit chain implementation (Okage: Shadow King with Lap3ec0re), but since this game is only available as a digital-only game, it has similar requirements to the Lua games and Netflix application. This means that this exploit method is typically not very useful for average users.
Luac0re is another such game. It uses Star Wars Racer Revenge USA (CUSA03474) or EU (CUSA03492). The EU version being digital only, while the USA version being available physically or digitally. This exploit has only a userland implementation. https://github.com/Gezine/Luac0re
PlayStation Vue Exploit
PlayStation Vue a decommissioned Sony streaming app has a rare free use license available that can even be transferred between consoles. This means the app can be install manually with a kernel exploit(jailbreak) or via the system backup and restore feature. Dubbed Vue After Free the userland is based on loading js code locally for the exploit, although the app is also vulnerable to MITM like Netflix. PS Vue is a rare app with the extra system access required for poopsploit. Vue is usable as a userland from 5.05-latest firmware. And will be chained with lapse and poopsploit up to 13.00 for a jailbreak. (Refer to VueAfterFree)
Kernel Exploits
Kernel Exploits are loaded via different methods. Some are loaded entirely through userland exploits like WebKit and Lua Loader, while others require extra hardware. Below are some of the available kernel exploits.
poobs4
The 9.00, kernel exploit pOOBs4 directly gains kernel access the exploit is only implemented for firmware 9.00, this exploit is unlike previous ones which were purely software based. Triggering the vulnerability requires plugging in a specially formatted USB device at just the right time or by using a small single-board computer like a Raspberry Pi zero or a Esp32 low-power system on a chip microcontroller with integrated Wi-Fi additionally it has been chained with a WebKit Exploit PSfree for better performance.
PPPwn
PPPwn is a kernel remote code execution exploit which uses a malicious PPPoE server to cause denial-of-service or potentially remote code execution in kernel context on the PS4/PS5.
This exploit is the first to cover a large range of firmware versions (7.00 to 11.00) on the PS4.
Lapse
The Lapse kernel exploit is the next exploit that covers an even larger range of firmwares than PPPwn. It works on firmware 5.00 to 12.02, though Lapse implementations only have the minimum firmware as 7.00.
It requires an entry point like WebKit exploit or a Lua game.
Poopsploit
The sys_netcontrol exploit (nicknamed as Poopsploit) is the latest kernel exploit that currently has the largest compatible firmware range.
Due to how the exploit works, it needs a application with a higher level of access compared to what a PS4 game has access to. This means that it can only normally work with the web browser, BD-J, or the PS2 emulator and PS Vue.
Using Jailbreaks (5.05-13.00)
When running any of the jailbreaks below, you will have to rerun the jailbreak after shutting off or restarting the PS4 even when using a Luckfox Pico, Raspberry Pi or ESP32-S2.
5.05
The 5.05 jailbreak is ran solely from the Browser/User Guide and has very good performance all around and it is highly recommended to stay on it and jailbreak by following the Standard Jailbreak Guide.
- Although you may need to wait a bit longer for backports to come to you, it is worth the wait, as the higher you go in firmware the less stable things get. A lot are already available.
6.72
The 6.72 jailbreak is also run solely from the PS4 Browser/User Guide, just like on 5.05, but it has slightly worse overall performance but it has had some improvements, and it is recommended to stay on it and jailbreak by following the Standard Jailbreak Guide.
- Although you may need to wait a bit longer for backports to come to you, it is worth the wait, as the higher you go in firmware the less stable things get. A lot are already available.
7.00-7.02 (Old Exploit)
This exploit can be ignored in favor of Lapse.
The 7.00-7.02 jailbreak is also run solely from the PS4 Browser/User Guide, just like on 5.05 and 6.72, but it has an overall worse performance than 6.72. but it has had some improvements that make it somewhat good to stay on and if you have a decent experience stay on it (or update to 9.00 if you have access to a spare USB Drive or are able to purchase a small device more below in the 9.00 section) you can jailbreak by following the Standard Jailbreak Guide.
- Although you may need to wait a bit longer for backports to come to you, it is worth the wait.
7.50-7.55 (Old Exploit)
This exploit can be ignored in favor of Lapse.
- This jailbreak, like the previous ones is also loaded solely from the Browser/User Guide.
- The jailbreak on this small range of firmware is extremely unstable to load in the first place among other things. It is highly recommended NOT to stay on it and to update to 9.00 after reading it's method of running if you have access to a spare USB Drive or are able to purchase a small device. More below in the 9.00 section.
- Although you may need to wait a bit longer for backports. A lot are already available.
9.00 (poobs4)
This exploit can be ignored in favor of Lapse.
- Usually this exploit is more stable than 7.02 and 7.50-7.55.
- The 9.00 jailbreak is ran from the PS4 Browser/User Guide.
- With the additional requirement of needing a USB Drive flashed with a special image to it and plugging and unplugging it from the PS4 at a certain point. This causes the USB to be dedicated to this part of the jailbreak but alternatives are available.
- It is recommended to stay on it and jailbreak by following the Standard Jailbreak Guide.
- Using an ESP32-S2 (or above must have USB emulation support) see: ESP32 Self-hosting or a Raspberry Pi Zero (or above must have USB emulation support) you can self host a webhost and load Goldhen and other payloads through it along with it automating the USB Drive part of the jailbreak.
- pOOBs4 has been paired with a webkit exploit for better performance.
- The USB Drive can have extremely small space sub 1GB.
- Connecting to a self hosted device does not give you real internet access but only local network access on the device running it.
- Backports arrive reasonably fast and a lot are already available.
7.00-9.60 (PSFree + Lapse)
On firmwares 7.00 to 9.60, the jailbreak can be loaded entirely from the browser by chaining it with PSFree; this will allow the 9.00 poobs4 usb exploit to be retired, while also allowing 7.00 to 8.52 and 9.03 to 9.60 to be jailbreakable without extra hardware, removing the need to use PPPwn.
See the Standard Jailbreak Guide in order to see how to use it.
- No reason to update to anything newer than 9.60 while on any of the firmwares in the range.
PPPwn (7.00-11.00)
PPPwn on any of the listed firmwares below is ran from a separate external device like a Desktop Computer, Laptop, Raspberry Pi, Specific Routers, Luckfox Pico, Specific LG Smart TV's, etc.
You connect your device of choice to the PS4 via Ethernet and launch the jailbreak. WiFi is not an option.
- Additionally, if your PS4 Ethernet port is damaged. you need to repair it first as no adapter is available that can forward an Ethernet connection to the PS4.
A small USB Drive is required to initially load GoldHEN or PS4HEN.
- You can use a USB to Ethernet adapter on the device hosting the jailbreak process but not all adapters are compatible.
- Backports usually arrive to 11.00 first as it is the latest jailbreakable firmware but 9.00 is quickly done next.
- On a Desktop PC or Laptop running Windows 7/10/11, Linux, or macOS you can run the exploit. An Ethernet port or USB to Ethernet adapter may be needed if you don't have a spare port on your computer. (Some USB to Ethernet adapters may not be compatible)
- On a Raspberry Pi with a Ethernet port or by adding a USB to Ethernet adapter (Some USB to Ethernet adapters may not be compatible) you can have it automatically apply by running the needed scripts and setting up the PS4 internet settings correctly. On compatible pi models you can forward internet to the PS4 or load payloads.
- On a Luckfox Pico you can have it automatically apply by running the needed scripts and setting up the PS4 internet settings correctly.
- On a Router compatible with OpenWRT you can have it automatically apply by running the needed scripts and setting up the PS4 internet settings correctly. You can also forward internet.
- On Rooted LG Smart TV's you can have it load the jailbreak by running the needed scripts and setting up the PS4 internet settings correctly.
- You can also run PPPwn from some quirky places like for example a Steam Deck with a Type-C to Ethernet adapter, a PS3 running Linux, a rooted Android Phone or TV Box, Docker, Proxmomx or similar.
7.00-9.60 (PPPwn)
Although PPPwn functions on as low as 7.00, it is recommended to instead use the 7.00-9.60 Lapse web browser exploit.
- Backports will be a mix depending on your firmware.
- 9.00-9.60 backports arrive reasonably fast and a lot are already available.
10.00-11.00 (PPPwn)
- While on any of these firmwares, you can either stay on them or update only up to 11.00 they all have Goldhen support.
- Backports arrive reasonably fast and a lot are already available.
- You can jailbreak by following the PPPwn Guide.
- If you are on 10.00-11.00, stay there to retain access to PPPwn. If you are on 11.02 to 12.02 updating has no advantages and you should wait for the exploit to be implemented and wait for a WebKit exploit if you do not want to use the Lua exploit or BD-J.
11.02-13.00
On 11.02 to 12.02 firmware versions, Lapse can be loaded though various places (Lua save game exploit, BD-J exploit, Netflix-N-Hack, Lapsecore or with Playstation Vue);
12.50 to 12.52 users can use the BD-J exploit or Playstation Vue.
13.00 users can only use Playstation Vue.
Troubleshooting jailbreak issues
5.05-9.60 Troubleshooting
- An error "Not enough memory" appears.
- It's a common error. Keep pressing OK until you pass it.
- The PS4 just shutdown/rebooted itself.
- Another common error. Do not worry, remove the USB drive if on 9.00 and keep trying the same procedure starting with User Guide.
- PS4 is stuck on a blue/white light either pulsing or solid after trying to shut it down or put it into rest mode or wake it up from rest mode.
- The PS4 has crashed force it to shutdown by holding down the power button for a long time or unplug it.
- I rebooted the PS4, and now I can't launch my games/apps.
- Jailbreaking is not persistent/permanent and as a result you need to re-jailbreak your PS4 every time you reboot/shut down your PS4. As a alternative, you can put your PS4 on rest mode and you don't need to re-jailbreak.
- PS4 is stuck on a blue/white light either pulsing or solid.
- The PS4 has crashed force it to shutdown by holding down the power button for a long time or unplug it.
- Will my PS4 die from doing this?
- No, even forced reboots won't kill your PS4.
7.00-11.00 PPPwn Troubleshooting
- The PS4 just shutdown/rebooted itself.
- A common error start it up and try the jailbreak again.
- I rebooted the PS4, and now I can't launch my games/apps.
- Jailbreaking is not persistent/permanent and as a result you need to re-jailbreak your PS4 every time you reboot/shut down your PS4. As a alternative, you can put your PS4 on rest mode and you don't need to re-jailbreak.
- PS4 is stuck on a blue/white light either pulsing or solid after trying to shut it down or put it into rest mode or wake it up from rest mode.
- The PS4 has crashed force it to shutdown by holding down the power button for a long time or unplug it.
- Will my PS4 die from doing this?
- No, even forced reboots won't kill your PS4.
- For issues with running the jailbreak, see PPPwn Issues
How can I get Klogs?
- Download and install Putty https://putty.software/
- Connect your PC and PS4 to the same network.
- Make sure the Klog server is enabled in GoldHEN/HEN/Mira.
- Now open Putty and start configuring it.
- In the Host Name set it to your PS4's IP address.
- In the Port set it to the Klog server port for GoldHEN/HEN/Mira.
- Under Connection type: set it to "Other" and from the dropdown select "Telnet".
- Go to Session>Logging.
- Set Session login: to "All session output".
- Set a log file and name by browsing and setting a directory and a file name.
- Go back to Session and name the session in the field under "Saved Sessions" then save it.
- You can now press "Open" and connect to the PS4. The output will be saved to the previously chosen file.
Are developers afraid of lawsuits like ones seen in the PS3 scene?
Starting with the PS4, Sony officially began a bug bounty program on HackerOne for any security researcher to submit exploits to PS4, PS5, PSN, and other related services directly. As a result, exploit developers will be compensated and can request disclosure, making exploit finding and releasing legal and encouraged. Likely, we will not see a lawsuit like what had happened with GeoHot and Graf_Chokolo.
I'm good at programming, how can I contribute?
If you do have the technical knowledge and a exploitable PS4, check out this page and this page to learn how to use the exploits to gain kernel-level access, then search for new ones in more recent firmware. You can find more scene-related help on the PS4 Developers Wiki. If you are looking to contribute by making homebrew, check out the OpenOrbis project on GitHub. You can also watch this video series which helps explain how to use OpenOrbis.
From a programming perspective, what is required to gain full system access?
In simple terms, you need an exploit in userland (where an application or game can execute code) and an exploit in the kernel (the core of the customized FreeBSD operating system). Userland exploits so far have all been using the PS4 web browser (WebKit), though userland could be exploited through other system apps such as a photo viewer, video viewer, or game save. Kernel exploits rely on finding a vulnerability in the operating system functions, called Syscalls, in order to allow you to execute code on the operating system level.
When was the first time the PS4 was jailbroken?
On December 6th, 2015, a user by the name of CTurt published information about an exploit in the 1.76 firmware kernel that allows users to break out of the FreeBSD jail that the PS4 uses to contain processes. By the end of the month, the group Fail0verflow demonstrated that they could execute code by successfully running a modified version of Linux on the system. We have since seen several full exploit releases on higher firmwares.
What other websites can I visit for PS4 information or resources?
Here are some sites:
- Wololo.net
- PSX-Place.com
- PS4 Developer Wiki
- ConsoleHax.com (Dutch)
- GBAtemp.com
- Homebrew pkg downloads
Definitions
| Term | Definition |
|---|---|
| Custom Firmware (CFW) | Firmware modified to add in extra features not present in original firmware (OFW). These modifications can be permanently installed or temporarily added in real time in memory. |
| Original Firmware (OFW) | Stock firmware released by Sony. |
| Kernel | The core of the operating system. Obtaining kernel-level code execution allows for great freedom and ability to run homebrew. |
| Orbis | The PS4’s code name used internally by Sony when it was in development.
Orbis is also the name of the native operating system of the PlayStation 4, a fork of FreeBSD version 9.0, released on January 12, 2012. |
| PKG | An installation “package” file that can be run from the XMB to install software on the PS4. |
| GP4 | A file that is a blueprint to generate PKGs. |
| Signing | The process of setting a PKG file such that it appears to the PS4 as a normal, officially allowed package. All PSN games, updates, etc. are signed, and must be so for the PS4 to allow them to install. |
| Internet Relay Chat (IRC) | A popular form of real-time Internet text messaging (chat) or synchronous conferencing. It is mainly designed for group communication in discussion forums, called channels, but also allows one-to-one communication via private message as well as chat and data transfer (including file sharing). |
| SEN / PSN | Sony Entertainment Network, also known as the PlayStation Network (PSN) is the online PlayStation service. |
| Syscall | An operating system function. There is a limited number of these which can be called from an application or game. |
| Userland | The security level at which games and applications run to prevent major system modification. |
| XMB | Xross Media Bar - Graphical Interface User designed as a cross. Used on the OS on PSX, PSP, and PS3 and other Sony Products. |