Pick the loader that matches your firmware, then the build that matches your console. Every offset here is verified against the decrypted firmware modules before it ships.
Mirror of zecoxao’s luasauce / luasaucedev, kept here so the link does not depend on someone else’s hosting. Upstream is the source of truth.
7.00 – 12.00
netcontrol IPv6 rthdr UAF. Jailbreaks in seconds and
tears down cleanly. Offsets for 9.00–12.00 match j0rdy’s slopkit in all
1035 shared constants; 7.00–8.60 add the older-JSC constants, each vtable
offset verified unique in that firmware’s own module.
12.00 – 12.70
A kqueueex cr_ref leak feeding a triple-free
race. Reach for this only above 12.00 — on 12.00 and below poopsploit
does the same job in seconds. Budget roughly an hour: the reference count has to
wrap 232 before the race can start, and the page looks idle for most of
that on purpose. Leave the console on until the payload menu appears. A
“system software error” right at the end is expected — press OK
and the payload page loads.
7.00 – 13.60
The aio bug: a _aio_multi_delete waiter race double-free,
reached through a WebKit history.state clone UAF. The widest firmware
range here by some way. 7.00 is confirmed on hardware; 7.01–11.20 were
extracted from the decrypted firmware modules by the same tool that reproduces every
11.60–13.60 value byte for byte, but have not been run yet. 10.60 and 11.40 are
absent — those firmware images are missing the modules the offsets have to be
read out of. A successful run draws the payload menu in place and sends each ELF
through the console’s own syscalls, so nothing is asked of the host.
Type any address and go. A bare hostname works — on the offline
host every mirrored site answers by name, so p2jb is enough.
Which one is for my console? A devkit needs the devkit site — it sets target ID
0x81 and the debugger auth ID, and offers the devkit kstuff build. Retail and
testkit both take the ordinary site: a testkit is close enough to retail here that it wants
target ID 0x82, not 0x81. Picking the wrong one just fails to jailbreak
— it does not harm the console.
based on the slopkit by j0rdy