- detection: probe-first (ShellCoreUtil dlopen, msgbuf AppFocusChanged, sysctl kinfo via verified-only fw table, sandbox/save fallbacks) - new orbisrpc/focus.c + fw.c/fw.h (bounded scans, fail-closed unknowns) - daemon: no-exit everywhere (token wait-loop, 4004 retry), status.json heartbeat, daemon.gen supersede protocol - installer: progress UI, token IME retry + FTP fallback, install.log, drop evict.elf (delete tools/evict.c, build_evict.sh) - packaging: Apollo parity CATEGORY=gde ATTRIBUTE=32 --authinfo - security: chmod 0600 on token-bearing files - docs: firmware-independent injecting guide, SUPPORT.md, release.sh
4.4 KiB
Injecting OrbisRPC into the PS4 — the complete guide
This exists because getting a payload to execute took longer than writing the payload. Everything below was learned on real consoles (9.00 primary). The flow is firmware-independent: the payload resolves its symbols at runtime and probes firmware-specific details (kinfo layout via a version table with a bounded-scan fallback), so the same binary runs anywhere you can get a loader listening.
You need first
- PS4 on a jailbreakable firmware (9.00 via pOOBs4 is the proven path; newer firmwares need their own entry point, e.g. lapse-based hosts — once jailbroken the steps below are identical), GoldHEN 2.4b18+ recommended (older payloader builds segfault on ELF files, see below).
- Console and computer on the same network. Find the PS4 IP:
Settings → Network → View Connection Status (ours is
192.168.1.136). - The payload file:
build-sdk/orbisrpc_sdk.elf(built via./scripts/build_sdk.sh).
Method 1 — elfldr (recommended)
elfldr (ps4-payload-dev's ps4-payload-elfldr) is a proper ELF loader
that runs payloads as separate processes with runtime symbol resolution.
- Get it listening. Either load
elfldr.elfthrough GoldHEN's payloader page once, or keep it running — it serves on port 9021 until reboot. - Send the payload with a raw TCP connection, then close the write side:
import socket
data = open("build-sdk/orbisrpc_sdk.elf", "rb").read()
s = socket.socket()
s.settimeout(25)
s.connect(("192.168.1.136", 9021))
s.sendall(data)
try:
s.shutdown(socket.SHUT_WR) # signals end-of-payload
except OSError:
pass
s.close()
- Verify it runs: within ~20 seconds
/data/orbisRPC/log.txtmust containorbisRPC payload boot. No file = it never executed.
Method 2 — GoldHEN BinLoader server (port 9020)
The classic route (NetCat tools, phone apps, scripts all speak it).
- Arm it: tap BinLoader in the exploit host menu (NOT the GoldHEN settings payloader page — different loader).
- Within seconds, fire blind — one single connection carrying the full payload, no port check first:
import socket
data = open("build-sdk/orbisrpc_sdk.elf", "rb").read()
s = socket.socket()
s.settimeout(25)
s.connect(("192.168.1.136", 9020))
s.sendall(data)
s.close()
- Same verification: look for
orbisRPC payload bootin the log.
THE ONE-SHOT RULE (read this twice)
GoldHEN's BinLoader arms once. Any empty port check (connect_ex,
nc -z, port scanners) connects with nothing to send and burns the
arm — the real payload then arrives at a dead listener. Sequence is
always: tap → say go → fire immediately → verify. Never probe first.
Method 3 — sender page (no PC tools)
https://SirHumza.github.io/orbisrpc-host/ in the PS4 browser
auto-sends the bundled backend to the console's own loader and prints
the result on screen.
What NOT to use
- GoldHEN settings payloader page: on GoldHEN ≤ 2.4 (pre-b18.5
lineage) its loader thread segfaults (
SIGSEGV, null read inGoldHENLoader) on every ELF — including 90KB hello-worlds. The klog printspayload launched successfullyand then dies. If you see this, update GoldHEN, don't rebuild the payload. - Raw SELF files: the page expects ELF (
\x7fELF). SELF uploads report "invalid payload".
Troubleshooting
| Symptom | Meaning | Fix |
|---|---|---|
Connection refused on 9021/9020 |
No listener armed | Tap BinLoader / open payloader page, retry instantly |
payload launched successfully then silence, no log |
Loader segfault (see above) | Update GoldHEN ≥ v2.4b18.5, use BinLoader server |
Error handling payload |
Loader rejected the bytes | Re-check file integrity (shasum), resend |
Log shows token rejected (4004) |
Token rotated/dead | Fresh token into /data/orbisRPC/config.json — the daemon picks it up alone, no relaunch needed |
Multiple Payload processes in process list |
Old instances piled up | Reinstall: the daemon.gen bump retires them; reboot clears stragglers |
Watching it work
- Kernel log (loader events, faults): TCP
192.168.1.136:3232, raw stream. - Daemon log:
/data/orbisRPC/log.txtvia FTP (192.168.1.136:2121, anonymous). Absent file = payload never executed, full stop. - Process list:
sysctl kern.proc(seescripts/ps4_watch.py) — look forPayloadandeboot.binentries. - Final proof: Discord profile shows the game + ticking timer.