{"id":8597,"date":"2016-01-21T17:50:50","date_gmt":"2016-01-21T16:50:50","guid":{"rendered":"https:\/\/www.customprotocol.com\/?p=8597"},"modified":"2016-01-21T17:50:50","modified_gmt":"2016-01-21T16:50:50","slug":"ps4-cturt-livre-nouveaux-details-sur-exploit-kernel","status":"publish","type":"post","link":"https:\/\/www.customprotocol.com\/ps4-cturt-livre-nouveaux-details-sur-exploit-kernel\/","title":{"rendered":"[PS4] CTurt nous livre de nouveaux d\u00e9tails sur son exploit kernel"},"content":{"rendered":"<p style=\"text-align: justify;\">Le c\u00e9l\u00e8bre d\u00e9veloppeur <em>CTurt<\/em>, connu notamment pour avoir <a href=\"https:\/\/www.customprotocol.com\/programmation\/ps4-explications-cturt-sur-exploit-kernel\/\" target=\"_blank\" rel=\"noopener noreferrer\">partag\u00e9 ses nombreux travaux<\/a> sur son <strong>exploit kernel PS4<\/strong>, a r\u00e9cemment partag\u00e9 d'autres travaux sur une autre vuln\u00e9rabilit\u00e9 de la PS4 un d\u00e9passement de tas (<em>heap overflow<\/em> en anglais), ce malgr\u00e9 <a href=\"https:\/\/www.customprotocol.com\/underground\/ps4-cturt-livre-details-exploit-kernel-quitte-scene\/\" target=\"_blank\" rel=\"noopener noreferrer\">son annonce d'abandon de la sc\u00e8ne <em>underground<\/em><\/a> en d\u00e9cembre dernier.<\/p>\n<figure id=\"attachment_8027\" aria-describedby=\"caption-attachment-8027\" style=\"width: 888px\" class=\"wp-caption aligncenter\"><a href=\"https:\/\/www.customprotocol.com\/medias\/2015\/12\/PS4-depart-CTurt-details-exploit-kernel-hack.png\" rel=\"attachment wp-att-8027\"><img loading=\"lazy\" decoding=\"async\" class=\"wp-image-8027 size-full\" src=\"https:\/\/www.customprotocol.com\/medias\/2015\/12\/PS4-depart-CTurt-details-exploit-kernel-hack.png\" alt=\"C'est la mauvaise nouvelle du jour&nbsp;: CTurt quitte la sc\u00e8ne...\" width=\"888\" height=\"500\" srcset=\"https:\/\/www.customprotocol.com\/medias\/2015\/12\/PS4-depart-CTurt-details-exploit-kernel-hack.png 888w, https:\/\/www.customprotocol.com\/medias\/2015\/12\/PS4-depart-CTurt-details-exploit-kernel-hack-300x169.png 300w, https:\/\/www.customprotocol.com\/medias\/2015\/12\/PS4-depart-CTurt-details-exploit-kernel-hack-768x432.png 768w, https:\/\/www.customprotocol.com\/medias\/2015\/12\/PS4-depart-CTurt-details-exploit-kernel-hack-370x208.png 370w, https:\/\/www.customprotocol.com\/medias\/2015\/12\/PS4-depart-CTurt-details-exploit-kernel-hack-270x152.png 270w, https:\/\/www.customprotocol.com\/medias\/2015\/12\/PS4-depart-CTurt-details-exploit-kernel-hack-570x321.png 570w, https:\/\/www.customprotocol.com\/medias\/2015\/12\/PS4-depart-CTurt-details-exploit-kernel-hack-740x417.png 740w, https:\/\/www.customprotocol.com\/medias\/2015\/12\/PS4-depart-CTurt-details-exploit-kernel-hack-300x169@2x.png 600w\" sizes=\"auto, (max-width: 888px) 100vw, 888px\" \/><\/a><figcaption id=\"caption-attachment-8027\" class=\"wp-caption-text\"><em>CTurt<\/em> de retour&#8239;?<\/figcaption><\/figure>\n<hr \/>\n<p style=\"text-align: justify;\">L'<strong>exploit kernel<\/strong> a malheureusement \u00e9t\u00e9 d\u00e9j\u00e0 <em>patch\u00e9<\/em> sur les <em>firmwares <\/em>sup\u00e9rieurs \u00e0 2.00, donc les possesseurs d'une PS4 en 3.15 ou sup\u00e9rieur ne pourront pas en profiter. Mais comme l'avait dit <em>CTurt<\/em>, il ne comptait de toute fa\u00e7on pas lib\u00e9rer son <strong>exploit<\/strong> d\u00e9j\u00e0 \"tout fait\" et \"arm\u00e9\", mais simplement communiquer ses observations sur la vuln\u00e9rabilit\u00e9 exploit\u00e9e.<\/p>\n<p style=\"text-align: justify;\">Bien que l'on n'ait pas directement de <strong>hack<\/strong> sur les derni\u00e8res versions de PS4, cette nouvelle est d\u00e9j\u00e0 bonne puisqu'elle signe le retour apparent de <em>CTurt<\/em> sur la sc\u00e8ne et la collaboration de <em>Qwertyoruiop<\/em>, autre <em>hacker<\/em> connu mais chez les f\u00e9rus d'iOS. D'apr\u00e8s ce dernier, <em>Sony\u00a0<\/em>serait \"p**in de retard\u00e9\" et un grand nombre d'attaques seraient possibles \u00e0 la \"surface\" de la console. Voil\u00e0 qui est une plut\u00f4t bonne nouvelle non (m\u00eame si on savait d\u00e9j\u00e0 que\u00a0<em>Sony<\/em> \u00e9tait retard\u00e9 #troll)&#8239;?&nbsp;\ud83d\ude42<\/p>\n<div align=\"center\">\n<blockquote class=\"twitter-tweet\" lang=\"fr\">\n<p dir=\"ltr\" lang=\"en\">Sony is fucking retarded. Why would anyone do a kernel-mode dynamic linker? That's literally a fuck ton of attack surface..<\/p>\n<p>\u2014 Luca Todesco (@qwertyoruiop) <a href=\"https:\/\/twitter.com\/qwertyoruiop\/status\/689133148978966528\">18 Janvier 2016<\/a><\/p><\/blockquote>\n<p><script src=\"\/\/platform.twitter.com\/widgets.js\" async=\"\" charset=\"utf-8\"><\/script><\/div>\n<p style=\"text-align: justify;\">Comme l'a fait remarquer <a href=\"http:\/\/wololo.net\/2016\/01\/18\/kernel-keys-for-wii-u-iosu-5-5-1-revealed\/\" target=\"_blank\" rel=\"noopener noreferrer\"><em>Wololo<\/em> sur son blog<\/a>, cette annonce co\u00efncide avec les <a href=\"http:\/\/wololo.net\/2016\/01\/18\/new-ps4-kernel-vulnerability-exploited-by-cturt-sys_dynlib_prepare_dlclose-ps4-kernel-heap-overflow\/\" target=\"_blank\" rel=\"noopener noreferrer\">propos tenus par <em>Fail0verflow<\/em><\/a> d'il y a quelques semaines, qui d\u00e9clarait alors qu'il n'avait \"aucun doute sur le fait que des vuln\u00e9rabilit\u00e9s sur le dernier <em>firmware<\/em> seraient trouvables sans trop de peine\".\u00a0<\/p>\n<p style=\"text-align: justify;\">L'<strong>exploit kernel<\/strong> se situe au niveau de la fonction <em>sys_dynlib_prepare_dlclose<\/em> et certains de ses appels internes tel que la copie. Si vous \u00eates int\u00e9ress\u00e9 et n'avez pas peur de lire un mur de texte, voil\u00e0 le <a href=\"http:\/\/cturt.github.io\/dlclose-overflow.html\" target=\"_blank\" rel=\"noopener noreferrer\">lien vers <strong>les explications de <em>CTurt<\/em><\/strong><\/a> tr\u00e8s d\u00e9taill\u00e9es comme d'habitude.<\/p>\n<p style=\"text-align: justify;\">Quoiqu'il en soit, il est clair que le moindre <strong>exploit kernel PS4<\/strong> est tr\u00e8s attendu par la communaut\u00e9, ne serait-ce que pour b\u00e9n\u00e9ficier de <em>homebrews<\/em>, de <em>plugins<\/em> ou bien du <a href=\"https:\/\/www.customprotocol.com\/underground\/linux-sur-ps4-fail0verflow-rendu-pilotes-3d-fonctionnels\/\" target=\"_blank\" rel=\"noopener noreferrer\">portage de Linux<\/a>.<\/p>\n","protected":false},"excerpt":{"rendered":"<p>Un exploit kernel qui se baserait sur un d\u00e9passement de tas dans le noyau.<\/p>\n","protected":false},"author":481,"featured_media":8027,"comment_status":"open","ping_status":"closed","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,29,30],"tags":[],"plateformes":[1014],"genres":[872,873,1740],"developpeurs":[1703,2143],"editeurs":[1704],"types":[1126,864],"sources":[2141,2142],"class_list":["post-8597","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-news","category-news-underground","category-underground","plateformes-ps4","genres-exploits","genres-exploits-kernel","genres-exploits-ps4","developpeurs-cturt","developpeurs-qwertyoruiop","editeurs-cturt","types-hack-ps4","types-news","sources-httpwololo-net20160118new-ps4-kernel-vulnerability-exploited-by-cturt-sys_dynlib_prepare_dlclose-ps4-kernel-heap-overflow","sources-httpstwitter-comcturtestatus689124911978278916"],"yoast_head":"\n<title>[PS4] CTurt nous livre des d\u00e9tails sur son exploit kernel - CTP<\/title>\n<meta name=\"description\" content=\"Un exploit kernel qui se baserait sur un d\u00e9passement de tas dans le noyau.\" \/>\n<meta name=\"robots\" content=\"index, follow, max-snippet:-1, max-image-preview:large, max-video-preview:-1\" \/>\n<link rel=\"canonical\" href=\"https:\/\/www.customprotocol.com\/ps4-cturt-livre-nouveaux-details-sur-exploit-kernel\/\" \/>\n<meta property=\"og:locale\" content=\"fr_CA\" \/>\n<meta property=\"og:type\" content=\"article\" \/>\n<meta property=\"og:title\" content=\"[PS4] CTurt nous livre des d\u00e9tails sur son exploit kernel - CTP\" \/>\n<meta property=\"og:description\" content=\"Un exploit kernel qui se baserait sur un d\u00e9passement de tas dans le noyau.\" \/>\n<meta property=\"og:url\" content=\"https:\/\/www.customprotocol.com\/ps4-cturt-livre-nouveaux-details-sur-exploit-kernel\/\" \/>\n<meta property=\"og:site_name\" content=\"Custom Protocol\" \/>\n<meta property=\"article:published_time\" content=\"2016-01-21T16:50:50+00:00\" \/>\n<meta property=\"og:image\" content=\"https:\/\/www.customprotocol.com\/medias\/2015\/12\/PS4-depart-CTurt-details-exploit-kernel-hack.png\" \/>\n\t<meta property=\"og:image:width\" content=\"888\" \/>\n\t<meta property=\"og:image:height\" content=\"500\" \/>\n\t<meta property=\"og:image:type\" content=\"image\/png\" \/>\n<meta name=\"author\" content=\"Wirus\" \/>\n<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n<meta name=\"twitter:creator\" content=\"@https:\/\/twitter.com\/HackerGen\" \/>\n<meta name=\"twitter:label1\" content=\"\u00c9crit par\" \/>\n\t<meta name=\"twitter:data1\" content=\"Wirus\" \/>\n\t<meta name=\"twitter:label2\" content=\"Estimation du temps de lecture\" \/>\n\t<meta name=\"twitter:data2\" content=\"2 minutes\" \/>\n<script type=\"application\/ld+json\" class=\"yoast-schema-graph\">{\"@context\":\"https:\/\/schema.org\",\"@graph\":[{\"@type\":\"WebPage\",\"@id\":\"https:\/\/www.customprotocol.com\/ps4-cturt-livre-nouveaux-details-sur-exploit-kernel\/\",\"url\":\"https:\/\/www.customprotocol.com\/ps4-cturt-livre-nouveaux-details-sur-exploit-kernel\/\",\"name\":\"[PS4] CTurt nous livre des d\u00e9tails sur son exploit kernel - CTP\",\"isPartOf\":{\"@id\":\"https:\/\/www.customprotocol.com\/#website\"},\"datePublished\":\"2016-01-21T16:50:50+00:00\",\"dateModified\":\"2016-01-21T16:50:50+00:00\",\"author\":{\"@id\":\"https:\/\/www.customprotocol.com\/#\/schema\/person\/e2f5c3e6cbb948e59756b98bed512cf9\"},\"description\":\"Un exploit kernel qui se baserait sur un d\u00e9passement de tas dans le noyau.\",\"breadcrumb\":{\"@id\":\"https:\/\/www.customprotocol.com\/ps4-cturt-livre-nouveaux-details-sur-exploit-kernel\/#breadcrumb\"},\"inLanguage\":\"fr-CA\",\"potentialAction\":[{\"@type\":\"ReadAction\",\"target\":[\"https:\/\/www.customprotocol.com\/ps4-cturt-livre-nouveaux-details-sur-exploit-kernel\/\"]}]},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\/\/www.customprotocol.com\/ps4-cturt-livre-nouveaux-details-sur-exploit-kernel\/#breadcrumb\",\"itemListElement\":[{\"@type\":\"ListItem\",\"position\":1,\"name\":\"Accueil\",\"item\":\"https:\/\/www.customprotocol.com\/\"},{\"@type\":\"ListItem\",\"position\":2,\"name\":\"[PS4] CTurt nous livre de nouveaux d\u00e9tails sur son exploit kernel\"}]},{\"@type\":\"WebSite\",\"@id\":\"https:\/\/www.customprotocol.com\/#website\",\"url\":\"https:\/\/www.customprotocol.com\/\",\"name\":\"Custom Protocol\",\"description\":\"Site d&#039;hack-tualit\u00e9 et de tutoriels sur la customisation de consoles et appareils (homebrews, plugins, \u00e9mulation...)\",\"potentialAction\":[{\"@type\":\"SearchAction\",\"target\":{\"@type\":\"EntryPoint\",\"urlTemplate\":\"https:\/\/www.customprotocol.com\/?s={search_term_string}\"},\"query-input\":\"required name=search_term_string\"}],\"inLanguage\":\"fr-CA\"},{\"@type\":\"Person\",\"@id\":\"https:\/\/www.customprotocol.com\/#\/schema\/person\/e2f5c3e6cbb948e59756b98bed512cf9\",\"name\":\"Wirus\",\"image\":{\"@type\":\"ImageObject\",\"inLanguage\":\"fr-CA\",\"@id\":\"https:\/\/www.customprotocol.com\/#\/schema\/person\/image\/\",\"url\":\"https:\/\/secure.gravatar.com\/avatar\/ff65bb0fba0be9639885c04a3ed7d8a895a98260fc23f283286dc9cf20bf3871?s=96&d=mm&r=g\",\"contentUrl\":\"https:\/\/secure.gravatar.com\/avatar\/ff65bb0fba0be9639885c04a3ed7d8a895a98260fc23f283286dc9cf20bf3871?s=96&d=mm&r=g\",\"caption\":\"Wirus\"},\"description\":\"Avez-vous d\u00e9j\u00e0 vu un gentil virus ? Maintenant, oui.\",\"sameAs\":[\"https:\/\/hackergen.com\",\"https:\/\/twitter.com\/https:\/\/twitter.com\/HackerGen\",\"https:\/\/www.youtube.com\/user\/Wirusalization\"],\"url\":\"https:\/\/www.customprotocol.com\/auteur\/wirus\/\"}]}<\/script>\n","yoast_head_json":{"title":"[PS4] CTurt nous livre des d\u00e9tails sur son exploit kernel - CTP","description":"Un exploit kernel qui se baserait sur un d\u00e9passement de tas dans le noyau.","robots":{"index":"index","follow":"follow","max-snippet":"max-snippet:-1","max-image-preview":"max-image-preview:large","max-video-preview":"max-video-preview:-1"},"canonical":"https:\/\/www.customprotocol.com\/ps4-cturt-livre-nouveaux-details-sur-exploit-kernel\/","og_locale":"fr_CA","og_type":"article","og_title":"[PS4] CTurt nous livre des d\u00e9tails sur son exploit kernel - CTP","og_description":"Un exploit kernel qui se baserait sur un d\u00e9passement de tas dans le noyau.","og_url":"https:\/\/www.customprotocol.com\/ps4-cturt-livre-nouveaux-details-sur-exploit-kernel\/","og_site_name":"Custom Protocol","article_published_time":"2016-01-21T16:50:50+00:00","og_image":[{"width":888,"height":500,"url":"https:\/\/www.customprotocol.com\/medias\/2015\/12\/PS4-depart-CTurt-details-exploit-kernel-hack.png","type":"image\/png"}],"author":"Wirus","twitter_card":"summary_large_image","twitter_creator":"@https:\/\/twitter.com\/HackerGen","twitter_misc":{"\u00c9crit par":"Wirus","Estimation du temps de lecture":"2 minutes"},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"WebPage","@id":"https:\/\/www.customprotocol.com\/ps4-cturt-livre-nouveaux-details-sur-exploit-kernel\/","url":"https:\/\/www.customprotocol.com\/ps4-cturt-livre-nouveaux-details-sur-exploit-kernel\/","name":"[PS4] CTurt nous livre des d\u00e9tails sur son exploit kernel - CTP","isPartOf":{"@id":"https:\/\/www.customprotocol.com\/#website"},"datePublished":"2016-01-21T16:50:50+00:00","dateModified":"2016-01-21T16:50:50+00:00","author":{"@id":"https:\/\/www.customprotocol.com\/#\/schema\/person\/e2f5c3e6cbb948e59756b98bed512cf9"},"description":"Un exploit kernel qui se baserait sur un d\u00e9passement de tas dans le noyau.","breadcrumb":{"@id":"https:\/\/www.customprotocol.com\/ps4-cturt-livre-nouveaux-details-sur-exploit-kernel\/#breadcrumb"},"inLanguage":"fr-CA","potentialAction":[{"@type":"ReadAction","target":["https:\/\/www.customprotocol.com\/ps4-cturt-livre-nouveaux-details-sur-exploit-kernel\/"]}]},{"@type":"BreadcrumbList","@id":"https:\/\/www.customprotocol.com\/ps4-cturt-livre-nouveaux-details-sur-exploit-kernel\/#breadcrumb","itemListElement":[{"@type":"ListItem","position":1,"name":"Accueil","item":"https:\/\/www.customprotocol.com\/"},{"@type":"ListItem","position":2,"name":"[PS4] CTurt nous livre de nouveaux d\u00e9tails sur son exploit kernel"}]},{"@type":"WebSite","@id":"https:\/\/www.customprotocol.com\/#website","url":"https:\/\/www.customprotocol.com\/","name":"Custom Protocol","description":"Site d&#039;hack-tualit\u00e9 et de tutoriels sur la customisation de consoles et appareils (homebrews, plugins, \u00e9mulation...)","potentialAction":[{"@type":"SearchAction","target":{"@type":"EntryPoint","urlTemplate":"https:\/\/www.customprotocol.com\/?s={search_term_string}"},"query-input":"required name=search_term_string"}],"inLanguage":"fr-CA"},{"@type":"Person","@id":"https:\/\/www.customprotocol.com\/#\/schema\/person\/e2f5c3e6cbb948e59756b98bed512cf9","name":"Wirus","image":{"@type":"ImageObject","inLanguage":"fr-CA","@id":"https:\/\/www.customprotocol.com\/#\/schema\/person\/image\/","url":"https:\/\/secure.gravatar.com\/avatar\/ff65bb0fba0be9639885c04a3ed7d8a895a98260fc23f283286dc9cf20bf3871?s=96&d=mm&r=g","contentUrl":"https:\/\/secure.gravatar.com\/avatar\/ff65bb0fba0be9639885c04a3ed7d8a895a98260fc23f283286dc9cf20bf3871?s=96&d=mm&r=g","caption":"Wirus"},"description":"Avez-vous d\u00e9j\u00e0 vu un gentil virus ? Maintenant, oui.","sameAs":["https:\/\/hackergen.com","https:\/\/twitter.com\/https:\/\/twitter.com\/HackerGen","https:\/\/www.youtube.com\/user\/Wirusalization"],"url":"https:\/\/www.customprotocol.com\/auteur\/wirus\/"}]}},"_links":{"self":[{"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/posts\/8597","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/users\/481"}],"replies":[{"embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/comments?post=8597"}],"version-history":[{"count":0,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/posts\/8597\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/media\/8027"}],"wp:attachment":[{"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/media?parent=8597"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/categories?post=8597"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/tags?post=8597"},{"taxonomy":"plateformes","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/plateformes?post=8597"},{"taxonomy":"genres","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/genres?post=8597"},{"taxonomy":"developpeurs","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/developpeurs?post=8597"},{"taxonomy":"editeurs","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/editeurs?post=8597"},{"taxonomy":"types","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/types?post=8597"},{"taxonomy":"sources","embeddable":true,"href":"https:\/\/www.customprotocol.com\/api\/wp\/v2\/sources?post=8597"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}