OSM ツ
@LegendaryOSM
Followers
3K
Following
51
Media
78
Statuses
587
Decided I was fed up with my old blog being clunky so I transitioned it to an Astro blog and so far it's been amazing! Check out the new series page for RetailKit: https://t.co/4t9uUo8Ovg
hackingadventures.ca
All posts in the PS4 RetailKit series
1
3
9
Curious for the folks on PS4 would it be useful if I documented how to set the RTC/Kernel Clock? I have sorted the way to set this clock properly.
2
2
25
Something a bit different from my normal post but I recently put together a blog post on a vulnerability I discovered in Samsung's Account API. With just the username an attacker would get information disclosure that lead to a 2FA bypass. https://t.co/LCL2hp1HdT
hackingadventures.ca
I'm Greg, a Senior Reverse Engineer who hunts for security vulnerabilities in protected systems and documents unknown system internals. This is where I walk through my research from security flaws...
0
2
17
I created a blog entry on some research I did into the SceAppMessaging check it out :D https://t.co/s5vrFv0mCr
hackingadventures.ca
I'm Greg, a Senior Reverse Engineer who hunts for security vulnerabilities in protected systems and documents unknown system internals. This is where I walk through my research from security flaws...
0
1
14
I have updated my research into the PS4 notifications: https://t.co/dY6blbuk0Q This mechanism is really just a form of IPC that will just forward buffers to the listening/reading half. You can monitor what is passed around by hooking the kernel part. 😃
github.com
A different way of calling the notify function on the ps4 for homebrew development. - OSM-Made/PS4-Notify
2
6
60
"so you spent a year finding a high impact vulnerability?" "Yes, Dave" "and you disclosed it responsibly for $5 and a t-shirt?" "That's correct, Dave"
16
67
1K
etaHEN Game Overlay test, big thanks to @LegendaryOSM If you want to test it early soon join the PKG-Zone discord and join the etaHEN Public test channel via the invite below https://t.co/fTEpQW3W05
20
32
302
incredible things happened today with someone who hacked into my extension to make it work without a paid subscription The hack? intercept all server calls locally and return values the extension would expect from a paid user
349
751
18K
I can confirm DECI does work on retail environments up to 12.02 and likely up to current 😀
6
10
115
After many life events getting in the way the long awaited part 3 to my RetailKit series is now live! I think part 3 has been my favourite to write, I hope you all enjoy! Check it out! https://t.co/UVqKyUqVvB
11
29
166
For those who were interested I've published the first part of my write up on the PS4 debugger. I'll continue to work on the next parts as I get some free time. 😀 https://t.co/Y6b31IjzUS
3
15
94
It is also possible to get the Mono debugger running on ShellUI though it seems to fight with ShellCore wanting to force kill ShellUI when its halted.
0
0
8
This does also mean that DECI works on a retail kernel. I'm working on a write up with more details soon. 😉
3
3
25
Fun Fact: Contrary to popular belief the PS4's mdbg system is fully functional on retail kernels, Including its debugger capabilities. I've verified this on 9.00 & 5.05.
5
18
117
Hey friends! If anyone has a PS5 on an exploitable firmware I'm looking to get one for research.
9
11
41
Not sure if its possible but does anyone have a dumped shellcore for ps5 4.51? Or the equivalent for ps5.
1
2
7