@flat_zi
iAccount based inNorth America!
About this account
- Account based in
- North America
- Connected via
- West Asia App Store
! X says this location may be affected by a proxy or VPN.
Account-level information from X, not a live location or the device used for a specific post.
Console hacker, former Kaspersky Team Lead of Exploits & Network Threat Detection, security researcher. For tips (thx!): https://nitter.cf/t.co/VxJMiawFpP
Joined December 2008
- Tweets565
- Following1.2K
- Followers12.7K
- Likes10.2K
Aleksei Kulaev retweeted
Method we used (>5 years ago, now) on ps5 to fiddle with mp4 and hv memory: github.com/fail0verflow/pros…
hope it helps for linux!
Aleksei Kulaev retweeted
I ported Linux to the PS5 and turned it into a Steam Machine. Running GTA 5 Enhanced with Ray Tracing. 🤯
This is funny, just found an easter egg in Siglent oscilloscope that contains Super Mario game available through Web interface.
Aleksei Kulaev retweeted
Here's the link to the tool I meant to release at the end: github.com/symbrkrs/ps5-uart
It makes fiddling with EMC/EFC/EAP easy, have fun!
Aleksei Kulaev retweeted
Having a great time at #TheSAS2024 ! You find find slides for my talk here: symbrk.rs/presentations/Beyo… I didn't get through all slides...😅
Aleksei Kulaev retweeted
Living legend Shawn Hoffman @shuffle2, who extracted all keys from crypto processors of all video game consoles, talks at #TheSAS2024 about hacking PlayStation 5 chips
Aleksei Kulaev retweeted
Lars Fröder @opa334dev, creator of the Dopamine jailbreak, on stage to talk about iOS hacking in 2024 #TheSAS2024
There are a few ways on PS5 to defeat HV. One of methods that I've found was related to APIC: struct apic_ops is located in RW segment of kernel data. With KRW you can overwrite a function pointer inside it like xapic_mode and get into ROP, for example (just need to bypass CFI).
Then, after you do suspend/resume cycle your code will be executed before HV restarts and you can apply kernel patches, etc.
Aleksei Kulaev retweeted
Beyond Oberon: Exploiting PlayStation 5's EFC and EMC by Shawn Hoffman @shuffle2 #TheSAS2024 thesascon.com/ 👀
PS5's umtx exploit for Lua?gist.github.com/flatz/5e12f7…
Well, this is PS5's umtx exploit for BD-J (a part related to the exploit actually): gist.github.com/flatz/89dfe9…
Aleksei Kulaev retweeted
want to play with the fbsd umtx exploit? check out github.com/fail0verflow/ps5-…
Hello, folks. I'm in Serbia/UAE nowadays and looking for new job opportunities in info security. Remote jobs are currently preferred. CV: github.com/flatz/cv
Aleksei Kulaev retweeted
Decided to publish PPPwn early. The first PlayStation 4 Kernel RCE. Supporting FWs upto 11.00.
github.com/TheOfficialFloW/P…
On 4800s the Nuvoton chip marked 5565D-M was used as multi-controller. Unfortunately, there is no datasheet for it and its pinout very differs from all public datasheets of similar chips that I can find.
After a week of guessing, bruteforcing, reflashing BIOS (where I put my PSP payload) and observing LPC bus using Logic Analyzer, I was able to find a combination of register/bits that needed to be toggled to activate UART.