{"id":6281,"date":"2015-08-28T11:50:15","date_gmt":"2015-08-28T09:50:15","guid":{"rendered":"https:\/\/www.customprotocol.com\/?p=6281"},"modified":"2015-08-28T11:50:15","modified_gmt":"2015-08-28T09:50:15","slug":"ps4-execution-code-non-signe-sur-console","status":"publish","type":"post","link":"https:\/\/www.customprotocol.com\/ps4-execution-code-non-signe-sur-console\/","title":{"rendered":"[PS4] De l&#8217;ex\u00e9cution de code non-sign\u00e9 sur la console&#8239;?"},"content":{"rendered":"<p style=\"text-align: justify;\">Apr\u00e8s <a href=\"https:\/\/www.customprotocol.com\/underground\/ps4-c-turt-met-en-ligne-open-sdk-ps4-file-browser\/\" target=\"_blank\" rel=\"noopener noreferrer\">l'annonce d'un <em>Open SDK<\/em> ainsi que d'un<em> PS4 File Browser<\/em> pour PS4<\/a> par <em>C Turt<\/em> qui a cr\u00e9e l'\u00e9v\u00e9nement dans le milieu <em>underground<\/em>, voil\u00e0 que le m\u00eame d\u00e9veloppeur vient d'annoncer que l'<strong>ex\u00e9cution de code non-sign\u00e9<\/strong> \u00e9tait r\u00e9alisable sur la derni\u00e8re console de salon de <em>Sony<\/em>. S'agit-il de la porte ouverte aux <em>homebrews<\/em>, et plus g\u00e9n\u00e9ralement au <strong>hack PS4<\/strong> attendu avec impatience&#8239;? R\u00e9ponses plus bas.&nbsp;\ud83d\ude42<\/p>\n<p style=\"text-align: justify;\"><a href=\"https:\/\/www.customprotocol.com\/medias\/2015\/08\/execution-code-non-signe-ps4-exploit-webkit-c-turt.png\"><img loading=\"lazy\" decoding=\"async\" class=\"aligncenter size-large wp-image-6283\" src=\"https:\/\/www.customprotocol.com\/medias\/2015\/08\/execution-code-non-signe-ps4-exploit-webkit-c-turt-764x418.png\" alt=\"execution code non sign\u00e9 ps4 exploit webkit c turt\" width=\"764\" height=\"418\" \/><\/a><\/p>\n<p style=\"text-align: justify;\">Techniquement, on en \u00e9tait d\u00e9j\u00e0 capables via la faille <em>WebKit<\/em>, mais on \u00e9tait surtout tr\u00e8s limit\u00e9s en raison des restrictions du navigateur de la PS4. Ici, il s'agit \"d'autre chose\" (quelle pr\u00e9cision, merci <em>Wirus<\/em>), bien qu'au final cela exploite \u00e9galement la faille <em>WebKit<\/em> et est donc de ce fait limit\u00e9 aux consoles dont le <em>firmware <\/em>est inf\u00e9rieur ou \u00e9gal \u00e0 1.76. Le <em>hacker<\/em> n'en n'a pas trop dit \u00e0 ce sujet, \u00e0 part qu'il a re\u00e7u ses infos depuis <em>flat_z<\/em> et que cet <em>exploit<\/em> n'\u00e9tait utile qu'aux d\u00e9veloppeurs, qui doivent donc se partager \"l'astuce\" entre eux tapis dans l'ombre...<\/p>\n<p style=\"text-align: justify;\">On peut supposer que ce <strong>hack<\/strong> brise les limitations du navigateur via une <a href=\"https:\/\/fr.wikipedia.org\/wiki\/%C3%89l%C3%A9vation_des_privil%C3%A8ges\" target=\"_blank\" rel=\"noopener noreferrer\">\u00e9l\u00e9vation des privil\u00e8ges<\/a>, ce qui laisserait sous-entendre qu'un autre <em>exploit<\/em> se cache derri\u00e8re tout ceci. En tout cas, <em>C Turt<\/em> pr\u00e9f\u00e8re pour le moment se concentrer sur l'\u00e9criture d'un <em>homebrew loader<\/em> et \u00e9tudier par <a href=\"https:\/\/fr.wikipedia.org\/wiki\/R%C3%A9tro-ing%C3%A9nierie\" target=\"_blank\" rel=\"noopener noreferrer\">r\u00e9tro-ing\u00e9nierie<\/a> la biblioth\u00e8que des options graphiques avant d'envisager une <em>release<\/em> publique.<\/p>\n<div align=\"center\">\n<blockquote class=\"twitter-tweet\" lang=\"fr\">\n<p dir=\"ltr\" lang=\"en\"><a href=\"https:\/\/twitter.com\/FiPE_ZOE\">@FiPE_ZOE<\/a> <a href=\"https:\/\/twitter.com\/frtomtomdu80\">@frtomtomdu80<\/a> First I need to write a homebrew loader (over WiFi - can't mount USBs), and RE the graphics lib<\/p>\n<p>\u2014 CTurt (@CTurtE) <a href=\"https:\/\/twitter.com\/CTurtE\/status\/633633847738007552\">18 Ao\u00fbt 2015<\/a><\/p><\/blockquote>\n<p><script src=\"\/\/platform.twitter.com\/widgets.js\" async=\"\" charset=\"utf-8\"><\/script><\/div>\n<p style=\"text-align: justify;\">On peut aussi esp\u00e9rer que \u00e7a aboutisse \u00e0 la trouvaille de nouvelles informations quant aux autres vuln\u00e9rabilit\u00e9s du syst\u00e8me pour les possesseurs d'une PS4 mise \u00e0 jour, mais il est clair qu'il ne faut pas vous attendre \u00e0 quoi que ce soit si vous avez un <em>firmware<\/em> strictement sup\u00e9rieur \u00e0 1.76 (la faille <em>WebKit<\/em> \u00e9tait <em>patch\u00e9e<\/em>).<\/p>\n<p style=\"text-align: justify;\">L'annonce est dans tous les cas tr\u00e8s excitante et prometteuse, bien qu'il soit impossible de pr\u00e9dire quand sortira un \u00e9ventuel <em>homebrew loader<\/em> voire un <em>hello world<\/em> natif... Bref, comme on le dit souvent dans le milieu&nbsp;: <em>Wait &amp; See<\/em>&#8239;!&nbsp;\ud83d\ude1b<\/p>\n","protected":false},"excerpt":{"rendered":"<p>C Turt a annonc\u00e9 sur son Twitter que l'ex\u00e9cution de code non-sign\u00e9 sur PS4 \u00e9tait possible&nbsp;: bient\u00f4t la porte ouverte aux homebrews&#8239;?<\/p>\n","protected":false},"author":481,"featured_media":6283,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,29,30],"tags":[1739],"plateformes":[1014],"genres":[1741,1740],"developpeurs":[1703],"editeurs":[1704],"types":[1126,864],"sources":[1742,1743,1744],"class_list":["post-6281","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-news-underground","category-underground","tag-execution-de-code-non-signe","plateformes-ps4","genres-exploit-webkit-pour-ps4","genres-exploits-ps4","developpeurs-cturt","editeurs-cturt","types-hack-ps4","types-news","sources-httpwololo-net20150819ps4-unsigned-code-execution-announced-by-cturt","sources-httpwololo-net20150825ps4-code-execution-some-details","sources-httpstwitter-comcturtestatus633607314818379776"],"yoast_head":"\n<title>[PS4] De l&#039;ex\u00e9cution de code non-sign\u00e9 sur la console ?<\/title>\n<meta name=\"description\" content=\"C Turt a annonc\u00e9 sur son Twitter que l&#039;ex\u00e9cution de code non-sign\u00e9 sur PS4 \u00e9tait possible : bient\u00f4t la porte ouverte aux homebrews ?\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.customprotocol.com\/ps4-execution-code-non-signe-sur-console\/\" \/>\n<meta property=\"og:locale\" content=\"fr_CA\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"[PS4] De l&#039;ex\u00e9cution de code non-sign\u00e9 sur la console ?\" \/>\n<meta property=\"og:description\" content=\"C Turt a annonc\u00e9 sur son Twitter que l&#039;ex\u00e9cution de code non-sign\u00e9 sur PS4 \u00e9tait possible : bient\u00f4t la porte ouverte aux homebrews ?\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.customprotocol.com\/ps4-execution-code-non-signe-sur-console\/\" \/>\n<meta property=\"og:site_name\" content=\"Custom Protocol\" \/>\n<meta property=\"article:published_time\" content=\"2015-08-28T09:50:15+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.customprotocol.com\/medias\/2015\/08\/execution-code-non-signe-ps4-exploit-webkit-c-turt.png\" \/>\n\t<meta property=\"og:image:width\" content=\"844\" \/>\n\t<meta property=\"og:image:height\" content=\"462\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Wirus\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@https:\/\/twitter.com\/HackerGen\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"Wirus\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimation du temps de lecture\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.customprotocol.com\/ps4-execution-code-non-signe-sur-console\/\",\"url\":\"https:\/\/www.customprotocol.com\/ps4-execution-code-non-signe-sur-console\/\",\"name\":\"[PS4] De l'ex\u00e9cution de code non-sign\u00e9 sur la console ?\",\"isPartOf\":{\"@id\":\"https:\/\/www.customprotocol.com\/#website\"},\"datePublished\":\"2015-08-28T09:50:15+00:00\",\"dateModified\":\"2015-08-28T09:50:15+00:00\",\"author\":{\"@id\":\"https:\/\/www.customprotocol.com\/#\/schema\/person\/e2f5c3e6cbb948e59756b98bed512cf9\"},\"description\":\"C Turt a annonc\u00e9 sur son Twitter que l'ex\u00e9cution de code non-sign\u00e9 sur PS4 \u00e9tait possible : bient\u00f4t la porte ouverte aux homebrews ?\",\"breadcrumb\":{\"@id\":\"https:\/\/www.customprotocol.com\/ps4-execution-code-non-signe-sur-console\/#breadcrumb\"},\"inLanguage\":\"fr-CA\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.customprotocol.com\/ps4-execution-code-non-signe-sur-console\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.customprotocol.com\/ps4-execution-code-non-signe-sur-console\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.customprotocol.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"[PS4] De l&#8217;ex\u00e9cution de code non-sign\u00e9 sur la console&#8239;?\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.customprotocol.com\/#website\",\"url\":\"https:\/\/www.customprotocol.com\/\",\"name\":\"Custom Protocol\",\"description\":\"Site d&#039;hack-tualit\u00e9 et de tutoriels sur la customisation de consoles et appareils (homebrews, plugins, \u00e9mulation...)\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.customprotocol.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-CA\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.customprotocol.com\/#\/schema\/person\/e2f5c3e6cbb948e59756b98bed512cf9\",\"name\":\"Wirus\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-CA\",\"@id\":\"https:\/\/www.customprotocol.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/ff65bb0fba0be9639885c04a3ed7d8a895a98260fc23f283286dc9cf20bf3871?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/ff65bb0fba0be9639885c04a3ed7d8a895a98260fc23f283286dc9cf20bf3871?s=96&d=mm&r=g\",\"caption\":\"Wirus\"},\"description\":\"Avez-vous d\u00e9j\u00e0 vu un gentil virus ? Maintenant, oui.\",\"sameAs\":[\"https:\/\/hackergen.com\",\"https:\/\/twitter.com\/https:\/\/twitter.com\/HackerGen\",\"https:\/\/www.youtube.com\/user\/Wirusalization\"],\"url\":\"https:\/\/www.customprotocol.com\/auteur\/wirus\/\"}]}<\/script>\n","yoast_head_json":{"title":"[PS4] De l'ex\u00e9cution de code non-sign\u00e9 sur la console ?","description":"C Turt a annonc\u00e9 sur son Twitter que l'ex\u00e9cution de code non-sign\u00e9 sur PS4 \u00e9tait possible : bient\u00f4t la porte ouverte aux homebrews ?","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.customprotocol.com\/ps4-execution-code-non-signe-sur-console\/","og_locale":"fr_CA","og_type":"article","og_title":"[PS4] De l'ex\u00e9cution de code non-sign\u00e9 sur la console ?","og_description":"C Turt a annonc\u00e9 sur son Twitter que l'ex\u00e9cution de code non-sign\u00e9 sur PS4 \u00e9tait possible : bient\u00f4t la porte ouverte aux homebrews ?","og_url":"https:\/\/www.customprotocol.com\/ps4-execution-code-non-signe-sur-console\/","og_site_name":"Custom Protocol","article_published_time":"2015-08-28T09:50:15+00:00","og_image":[{"width":844,"height":462,"url":"https:\/\/www.customprotocol.com\/medias\/2015\/08\/execution-code-non-signe-ps4-exploit-webkit-c-turt.png","type":"image\/png"}],"author":"Wirus","twitter_card":"summary_large_image","twitter_creator":"@https:\/\/twitter.com\/HackerGen","twitter_misc":{"\u00c9crit par":"Wirus","Estimation du temps de lecture":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.customprotocol.com\/ps4-execution-code-non-signe-sur-console\/","url":"https:\/\/www.customprotocol.com\/ps4-execution-code-non-signe-sur-console\/","name":"[PS4] De l'ex\u00e9cution de code non-sign\u00e9 sur la console ?","isPartOf":{"@id":"https:\/\/www.customprotocol.com\/#website"},"datePublished":"2015-08-28T09:50:15+00:00","dateModified":"2015-08-28T09:50:15+00:00","author":{"@id":"https:\/\/www.customprotocol.com\/#\/schema\/person\/e2f5c3e6cbb948e59756b98bed512cf9"},"description":"C Turt a annonc\u00e9 sur son Twitter que l'ex\u00e9cution de code non-sign\u00e9 sur PS4 \u00e9tait possible : bient\u00f4t la porte ouverte aux homebrews ?","breadcrumb":{"@id":"https:\/\/www.customprotocol.com\/ps4-execution-code-non-signe-sur-console\/#breadcrumb"},"inLanguage":"fr-CA","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.customprotocol.com\/ps4-execution-code-non-signe-sur-console\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.customprotocol.com\/ps4-execution-code-non-signe-sur-console\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.customprotocol.com\/"},{"@type":"ListItem","position":2,"name":"[PS4] De l&#8217;ex\u00e9cution de code non-sign\u00e9 sur la console&#8239;?"}]},{"@type":"WebSite","@id":"https:\/\/www.customprotocol.com\/#website","url":"https:\/\/www.customprotocol.com\/","name":"Custom Protocol","description":"Site d&#039;hack-tualit\u00e9 et de tutoriels sur la customisation de consoles et appareils (homebrews, plugins, \u00e9mulation...)","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.customprotocol.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-CA"},{"@type":"Person","@id":"https:\/\/www.customprotocol.com\/#\/schema\/person\/e2f5c3e6cbb948e59756b98bed512cf9","name":"Wirus","image":{"@type":"ImageObject","inLanguage":"fr-CA","@id":"https:\/\/www.customprotocol.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/ff65bb0fba0be9639885c04a3ed7d8a895a98260fc23f283286dc9cf20bf3871?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ff65bb0fba0be9639885c04a3ed7d8a895a98260fc23f283286dc9cf20bf3871?s=96&d=mm&r=g","caption":"Wirus"},"description":"Avez-vous d\u00e9j\u00e0 vu un gentil virus ? Maintenant, oui.","sameAs":["https:\/\/hackergen.com","https:\/\/twitter.com\/https:\/\/twitter.com\/HackerGen","https:\/\/www.youtube.com\/user\/Wirusalization"],"url":"https:\/\/www.customprotocol.com\/auteur\/wirus\/"}]}},"_links":{"self":[{"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/posts\/6281","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/users\/481"}],"replies":[{"embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/comments?post=6281"}],"version-history":[{"count":0,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/posts\/6281\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/media\/6283"}],"wp:attachment":[{"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/media?parent=6281"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/categories?post=6281"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/tags?post=6281"},{"taxonomy":"plateformes","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/plateformes?post=6281"},{"taxonomy":"genres","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/genres?post=6281"},{"taxonomy":"developpeurs","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/developpeurs?post=6281"},{"taxonomy":"editeurs","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/editeurs?post=6281"},{"taxonomy":"types","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/types?post=6281"},{"taxonomy":"sources","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/sources?post=6281"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}