poopicker

Pick the loader that matches your firmware, then the build that matches your console. Every offset here is verified against the decrypted firmware modules before it ships.

UMTX

Mirror of zecoxao’s luasauce / luasaucedev, kept here so the link does not depend on someone else’s hosting. Upstream is the source of truth.

luasauceretail / testkit
luasaucedevdevkit

POOPSPLOIT

7.00 – 12.00

netcontrol IPv6 rthdr UAF. Jailbreaks in seconds and tears down cleanly. Offsets for 9.00–12.00 match j0rdy’s slopkit in all 1035 shared constants; 7.00–8.60 add the older-JSC constants, each vtable offset verified unique in that firmware’s own module.

poopsploitretail / testkit
poopsploit-devdevkit

P2JB

12.00 – 12.70

A kqueueex cr_ref leak feeding a triple-free race. Reach for this only above 12.00 — on 12.00 and below poopsploit does the same job in seconds. Budget roughly an hour: the reference count has to wrap 232 before the race can start, and the page looks idle for most of that on purpose. Leave the console on until the payload menu appears. A “system software error” right at the end is expected — press OK and the payload page loads.

p2jbretail / testkit
p2jb-devdevkit

RELAPSE

7.00 – 13.60

The aio bug: a _aio_multi_delete waiter race double-free, reached through a WebKit history.state clone UAF. The widest firmware range here by some way. 7.00 is confirmed on hardware; 7.01–11.20 were extracted from the decrypted firmware modules by the same tool that reproduces every 11.60–13.60 value byte for byte, but have not been run yet. 10.60 and 11.40 are absent — those firmware images are missing the modules the offsets have to be read out of. A successful run draws the payload menu in place and sends each ELF through the console’s own syscalls, so nothing is asked of the host.

relapseretail / testkit
relapse-devdevkit

Browse

Type any address and go. A bare hostname works — on the offline host every mirrored site answers by name, so p2jb is enough.

Which one is for my console? A devkit needs the devkit site — it sets target ID 0x81 and the debugger auth ID, and offers the devkit kstuff build. Retail and testkit both take the ordinary site: a testkit is close enough to retail here that it wants target ID 0x82, not 0x81. Picking the wrong one just fails to jailbreak — it does not harm the console.

creds & greetz

zecoxao, ChendoChap, abc/psfree, idlesauce, flat_z, TheFlow, c0w-ar, earthonion, SIStro, egycnq, abkarino, gezine, Dr.Yenyen, StonedModder, VoidWhisper, EchoStretch, BestPig, AlAzif, drakmor, hzhreal, hammer-83, ntfargo, shahrilnet, Znullptr, LM, ItsJokerZz, cblock, BeLegal, Lord Caio Barros

based on the slopkit by j0rdy