Homebrew [Need Implementation] 3DS ARM11 Kernel Exploit by TuxSH

NexoCube

Well-Known Member
OP
Member
Joined
Nov 3, 2015
Messages
1,222
Trophies
0
Age
29
Location
France
XP
1,340
Country
France
Hello, 2 days ago, @TuxSH revealed (on 3dbrew) a bug he found in ARM11 Kernel.

Summary : svcGetThreadList (svc 0x66) process reference leak

Description given : When given a valid process handle (including 0xFFFF8001), svcGetThreadList forgets to decrement the reference count of the underlying KProcess instance, after having finished using it.

What could happen if we exploit this bug : Before 11.2: reference count overflow and therefore use-after-free, but this UAF was most likely not exploitable

Note (by me, lol) :

- 0xFFFF8001 = Current KProcess Handle
- Kernel Objects are C++ Virtual Classes : So, it means vtable (so, if you find a UAF bug in KObject management, it is "probably" exploitable)

From what i understood ; if that UAF were exploitable, it would lead to K11 Code Execution, because it means vtable call (from a forged vtable)

and pssstt... kernel exploit doesn't always mean code execution
 
Last edited by NexoCube,

Arck

Well-Known Member
Member
Joined
Mar 13, 2016
Messages
955
Trophies
0
XP
878
Country
just check how the fasthax "System Flaws" work on 3dbrew and check his repo so you can easily compare.
 

Giodude

GBAtemp's official rock
Member
Joined
May 17, 2015
Messages
5,094
Trophies
1
Age
23
Location
New York
XP
2,761
Country
United States
Interesting, more or less interested in the idea of arm11loaderhax coldbooting a custom OS vs installing an entire new one.
 

rotomington

Active Member
Newcomer
Joined
Dec 27, 2016
Messages
35
Trophies
0
XP
116
Country
I heard each CPU have his bootrom, so, maybe someone can find a bug in the ARM11 BootROM
According to derrek, there really isn't anything interesting in prot_boot11.bin or unprot_boot11.bin. All the fun stuff's in prot_boot9.bin.

Although, if there are any bugs in the arm11 bootrom, they wouldn't be of much use since we'd need to reboot and have code execution just after boot (Which if you have, you might as well exploit the arm9 like in A9LH)
 
  • Like
Reactions: NexoCube

NexoCube

Well-Known Member
OP
Member
Joined
Nov 3, 2015
Messages
1,222
Trophies
0
Age
29
Location
France
XP
1,340
Country
France
According to derrek, there really isn't anything interesting in prot_boot11.bin or unprot_boot11.bin. All the fun stuff's in prot_boot9.bin.

Although, if there are any bugs in the arm11 bootrom, they wouldn't be of much use since we'd need to reboot and have code execution just after boot (Which if you have, you might as well exploit the arm9 like in A9LH)

ARM9 boot time exploi is much more needed because it means we have have full control over the 3DS a few milliseconds after boot
 

adrifcastr

Well-Known Member
Member
Joined
Sep 12, 2016
Messages
2,038
Trophies
0
XP
1,947
Country
Germany
wow, nobody seems to care that an implementation of this could actually lead to kernel11 code execution.
If I was any good in C/C++
I would go and try, but I'm not good at all.
 

metroid maniac

An idiot with an opinion
Member
Joined
May 16, 2009
Messages
2,092
Trophies
2
XP
2,696
Country
Not that I want to hijack this thread, but I'm curious about something.
How exactly can a use-after-free bug lead to an arbitrary code execution exploit in an NX environment?
I assume the first step once you have a user-after-free bug would be to make a phony vtable with function pointers to useful gadgets, and then corrupt the free'd object so its vptr points to your vtable.
But then, how can you execute multiple gadgets in a row? Once your gadget executes, won't you just return to the regular program flow?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • S @ salazarcosplay:
    hunter x hunter
  • S @ salazarcosplay:
    he has not allowed anyone to continue it for him for example
  • Xdqwerty @ Xdqwerty:
    @salazarcosplay, theres a dragon ball af mod for budokai 3
  • Xdqwerty @ Xdqwerty:
    updated ship of harkinian, gonna install some hd texture pack
  • Xdqwerty @ Xdqwerty:
    I might download rayman revolution for my ps3
  • BigOnYa @ BigOnYa:
    I may try the new ram site, and download more RAM to my Switch. Not sure if ddr3 is the right ram
    for it tho. Edit- no it uses floppy Ram, just like @AncientBoi
    +1
  • Xdqwerty @ Xdqwerty:
    aeiou
  • BigOnYa @ BigOnYa:
    And sometimes Z
  • SylverReZ @ SylverReZ:
    @K3Nv2, MAGA supporters be wearing tin foil hats lol.
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, whats maga?
  • BigOnYa @ BigOnYa:
    It stands for Maniacs Against General Acceptance
    +1
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, people rejecting general consensus about stuff?
    +1
  • BigOnYa @ BigOnYa:
    Yup, nuh its really just Trump followers
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, im not american so i dont care about trump
    +1
  • Xdqwerty @ Xdqwerty:
    or us elections
  • BigOnYa @ BigOnYa:
    Me niether, us north Koreans don't care
  • Xdqwerty @ Xdqwerty:
    good night
  • BakerMan @ BakerMan:
    i don't care either, even if i'm american
  • BakerMan @ BakerMan:
    truth be told, i agree with psi, i dislike both candidates, but i'd probably vote trump simply because the economy was better during his presidency
  • AngryCinnabon @ AngryCinnabon:
    Just be careful, if trump ends up winning and using project 2025 America might really change...for the worse.
  • AngryCinnabon @ AngryCinnabon:
    I'm not american and even that sends shivers down my spine.
  • AngryCinnabon @ AngryCinnabon:
    anything that offers trump an opportunity to become an actual dictator
    is bad in my book, i could care less if it wasn't for that...
  • K3Nv2 @ K3Nv2:
    Canada: America's Russia
  • NinStar @ NinStar:
    people are so dramatic that I can't even tell if they are being serious
    NinStar @ NinStar: people are so dramatic that I can't even tell if they are being serious