fail0verflow(@fail0verflow) 's Twitter Profileg
fail0verflow

@fail0verflow

ID:217422891

linkhttp://fail0verflow.com calendar_today19-11-2010 13:57:42

226 Tweets

54,2K Followers

10 Following

fail0verflow(@fail0verflow) 's Twitter Profile Photo

New blog post about hacking PS VR! We managed to find some major flaws - breaking secure boot and extracting all key material: fail0verflow.com/blog/2022/ps4-โ€ฆ

account_circle
fail0verflow(@fail0verflow) 's Twitter Profile Photo

Translation: We got all (symmetric) ps5 root keys. They can all be obtained from software - including per-console root key, if you look hard enough!

account_circle
fail0verflow(@fail0verflow) 's Twitter Profile Photo

Here is our implementation of the Renesas RL78 debug protocol (as requested in a comment on the blog): github.com/fail0verflow/rโ€ฆ

account_circle
fail0verflow(@fail0verflow) 's Twitter Profile Photo

Took a peek at latest PS4 Pro (CUH-72xx, board NVG-001): same southbridge (CXD90046GG), newly marked syscon (A06-C0L2 but still RL78/G13) - so nothing changes in terms of 'Aux Hax' stuff :)

account_circle
fail0verflow(@fail0verflow) 's Twitter Profile Photo

Another 'PS4 Aux Hax' blog! Using HDMI-CEC to get code exec on all PS4 southbridge versions (including PS4 Pro, etc.), without requiring other parts of the system to be pwned:
fail0verflow.com/blog/2018/ps4-โ€ฆ

account_circle
fail0verflow(@fail0verflow) 's Twitter Profile Photo

Small update to Aux Hax:
Nearly same methods are working against devices on recent PS4 Pro board NVB-003:
Syscon A05-C0L2 (R5F101LL)
Belize southbridge (CXD90046GG)

Belize has ROM readout protection and clears stack...they're learning ;)

account_circle
fail0verflow(@fail0verflow) 's Twitter Profile Photo

A trio of new blog posts! Checkout 'PS4 Aux Hax': hacking Aeolia, Syscon, and DS4. fail0verflow.com/blog/2018/ps4-โ€ฆ

account_circle
fail0verflow(@fail0verflow) 's Twitter Profile Photo

Fun fact: we started upstreaming some patches months ago (working with the linux-tegra community on Tegra X1 support in mainline Linux), so if you've seen anyone else running Linux on the Switch recently... chances are they were running some of our code unknowingly ;-)

account_circle
fail0verflow(@fail0verflow) 's Twitter Profile Photo

Reminder: ShofEL2 cannot be patched in existing units (it will work on *any* firmware, past or future), it allows full access (all keys and secrets), and it is completely undetectable by normal software. You can dual boot Linux and Switch OS with impunity. twitter.com/fail0verflow/sโ€ฆ

account_circle
fail0verflow(@fail0verflow) 's Twitter Profile Photo

ShofEL2, a Tegra X1 and Nintendo Switch exploit fail0verflow.com/blog/2018/shofโ€ฆ github.com/fail0verflow/sโ€ฆ

account_circle
fail0verflow(@fail0verflow) 's Twitter Profile Photo

Jokes aside, we have a 90-day responsible disclosure window for ShofEL2 ending on April 25th. Since another person published the bug so close to our declared deadline, we're going to wait things out. Stay tuned.

account_circle