Skip to content

Repository files navigation

🎬 Cinebreak

release license stars updated

A one-shot, chainable PS5 jailbreak built on Gezine's BD-JB5 — a Blu-ray Disc Java sandbox escape — extended into a full userland → kernel → root → homebrew chain with automation tooling.

🎬 play the disc (BD-J sandbox escape)
   ↓
📡 RemoteJarLoader :9025
   ↓ push poops.jar
💥 Poopsploit — TheFlow NetControl kernel exploit → "Arbitrary R/W achieved"
   ↓
👑 AIO JB shellcode (ufm42) → root, syscall gate, dlsym
   ↓
🚀 elfldr :9021 → deploy any PS5 x86-64 ELF, runs with root

Firmware: kernel offsets 9.00 → 13.52. Explore at your own risk, on your own hardware, in a region where research is legal.


⚡ One-shot chain (the new part)

# 1. find your console
./ps5chain.py --find 192.168.1.0/24

# 2. run the whole chain and deploy an ELF
./ps5chain.py --chain <ps5-ip> --elf ./my_homebrew.elf

ps5chain.py finds the PS5, pushes the exploit, watches the log for the kernel stage, waits for elfldr, deploys your ELF, and streams everything live. Also ships:

Tool What it does
ps5chain.py Full-chain orchestrator (find → exploit → deploy)
ps5find.py Scans LAN for RemoteJarLoader :9025 / elfldr :9021
probe/ A custom diagnostic payload (safe self-tests, kernel R/W check)
tools/ Local console simulators for testing without hardware
CHAIN.md Every link of the chain mapped and documented

🧰 Cinebreak Suite (v1)

Tool What it does
cinebreak Unified CLI: build · find · chain · payload new <name> · status · update
payloads/cinebreak-shell/ Network command shell — after the chain lands, nc <ps5> 9026 gives kernel read/write, memory dumps, notifications
tools/kernel-offsets.py Pattern scanner for the 5 kernel offsets Poopsploit needs — future firmware drops don't break the chain (selftest included)
.github/workflows/build.yml CI: auto-builds the ISO on push + weekly (tracks upstream offset changes)

Shell quickstart:

./cinebreak chain <ps5-ip> --elf <elfldr-deployed-tool>   # or push cinebreak-shell.jar
nc <ps5-ip> 9026
> kread 0xffffffff...      # kernel read32
> kdump <addr> 64          # hex dump
> notify hello             # PS5 notification

🛰️ Cinebreak Hub — live scene operations

./cinebreak scene          # live GitHub tracker: latest releases from Gezine, etaHEN,
                           # ps5-linux, kexp, SDKs + cached matrix
./cinebreak scene --json   # machine-readable
./cinebreak hub            # zero-dependency web dashboard on :8777
                           # (scene status + LAN console discovery)
python3 hub/autoload.py demo   # build a USB autoload package (autoload.txt + payloads)

Scene tracker covers 12 projects: BD-JB5, Y2JB, Luac0re, P2JB port, etaHEN (+cheats), GoldHEN, ps5-linux, kexp, both SDKs, and scene tooling — with latest tags/dates pulled live from GitHub and cached locally.

🔨 Build the ISO

git clone https://github.com/john-tornblom/bdj-sdk bdj-sdk
# provide bdj-sdk/host/jdk8 + build its makefs/bdsigner host tools (see bdj-sdk README)
./build.sh          # → BD-JB5-2.0.iso (burn to BD-R/BD-RE)

📦 Payloads

Payload Purpose
hello/ Smoke test — proves the sandbox escape works
probe/ My diagnostic payload — safe system + kernel self-tests
poops/ The full chain — NetControl kernel exploit + kexp + AIO shellcode + ELF loader

🙏 Credits — this is their work first

  • Gezine — BD-JB5, the entire BD-J sandbox escape and Poopsploit
  • TheFlow — NetControl kernel exploit, BD-J documentation, native code execution
  • ufm42 — kexp + AIO all-in-one jailbreak shellcode
  • john-tornblom — bdj-sdk, ps5-payload-sdk, elfldr, makefs
  • hammer-83 — PS5 Remote JAR Loader reference
  • kuba-- — zip, used in the unpatch payload

This repository is a fork + tooling layer over Gezine's MIT-licensed BD-JB5. All original copyright notices and licenses are preserved (see LICENSE and file headers). The build chain pulls in john-tornblom/bdj-sdk (GPL-3.0) as an external build dependency — clone it separately, its terms apply to it.

⚠️ Not a CFW

This is a per-boot jailbreak — reboot and you re-trigger. There is no PS5 custom firmware. Use for homebrew, research, and patches, on hardware you own.

About

One-shot chainable PS5 jailbreak: BD-J sandbox escape -> kernel root -> homebrew. A fork + tooling layer over Gezine's BD-JB5, full credits preserved.

Topics

Resources

Stars

0 stars

Watchers

1 watching

Forks

Releases

Packages

Contributors

Languages