Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

not exactly an issue but a suggestion: study (and possibly port) CVE 2020-9951 #55

Open
zecoxao opened this issue Sep 18, 2020 · 10 comments

Comments

@zecoxao
Copy link

zecoxao commented Sep 18, 2020

https://talosintelligence.com/vulnerability_reports/TALOS-2020-1124

Seems like a good candidate. What better person to port this than a russian? Of course we need to check if ps4 webkit is vulnerable to this, but if it is we should have a proper webkit exploit for 7.02 and below (and who knows, 7.55 and below as well?)

@sleirsgoevy
Copy link
Owner

I will take a look into it; at least it does not like an obvious dead end, like any JIT-based exploit. Will have to build a debug version of the whole WebKit though; my current script only builds JavaScriptCore.

@zecoxao
Copy link
Author

zecoxao commented Sep 18, 2020

thanks. i hope there is a solution here :)

@zecoxao
Copy link
Author

zecoxao commented Sep 19, 2020

since i also don't know your twitter handle or handle for other social media i'll leave this here https://www.sendspace.com/file/sg19ns
MACROSS= Retail

@sleirsgoevy
Copy link
Owner

I do have Twitter, however I registered one specifically to reach Al Azif and don't really check it. As of now Telegram is my primary messenger.

Thanks anyway, will check this out as soon as I reach my PC.

@gorshco
Copy link

gorshco commented Sep 28, 2020

Sergey, did you had the chance to give it a look?

@sleirsgoevy
Copy link
Owner

It seems that I have a PoC, but nowhere close to a working exploit yet.

@zecoxao
Copy link
Author

zecoxao commented Dec 5, 2020

https://talosintelligence.com/vulnerability_reports/TALOS-2020-1155
maybe something better, since it shows where the actual flaw is

@curly-deni
Copy link

curly-deni commented Dec 10, 2020

Hey. the webkit 0day was introduced today, which should theoretically work on 7.xx. you are the developer who can implement it on this firmware. do you have time to try adapting this for 7.xx?
https://github.com/synacktiv/PS4-webkit-exploit-6.XX https://www.synacktiv.com/publications/this-is-for-the-pwners-exploiting-a-webkit-0-day-in-playstation-4.html

@sleirsgoevy
Copy link
Owner

I already saw this, but thanks anyway.

@komawoyo
Copy link

Here's a list of CVE that may be useful. I'm a fan of your talent 👍
CVE-2018-4441 has already been used on previous wekit exploits. This list has many more after 4441.
https://github.com/tunz/js-vuln-db#projectzero

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

6 participants
@zecoxao @sleirsgoevy @komawoyo @gorshco @curly-deni and others