Hacking [SPECULATION] SSSpwn allows kernel access?

Status
Not open for further replies.

Foxi4

Endless Trash
Global Moderator
Joined
Sep 13, 2009
Messages
30,825
Trophies
3
Location
Gaming Grotto
XP
29,841
Country
Poland
the launcher is, not the exploit.
The question will still remain even if weaker until sources of the exploit are released.
That doesn't matter - if the exploit "allows kernel-level access" then the HBMenu itself would run at kernel level.
You still can't execute your own code though.
I'm talking about a different level of protection, memory protection.

It doesn't get write access to executable regions of memory, and there's no access to setting memory to be executable either. So there should be no way to actually execute your own code even if you can load it without a kernel exploit.
My guess is that Cubic Ninja developers simply f*cked up, which does happen quite often, and allocated more memory than they would ever possibly need, leaving plenty of space for your own binary. Of course this is all speculation, I don't dabble in this sort of thing.
 

ken28

Well-Known Member
Member
Joined
Oct 21, 2010
Messages
1,181
Trophies
1
XP
1,693
Country
Germany
That doesn't matter - if the exploit "allows kernel-level access" then the HBMenu itself would run at kernel level.
not if its only granted user rights by the exploit.
(esploit runs in kernel mode - starts hbmenu with user land rights)
 

Foxi4

Endless Trash
Global Moderator
Joined
Sep 13, 2009
Messages
30,825
Trophies
3
Location
Gaming Grotto
XP
29,841
Country
Poland
not if its only granted user rights by the exploit.
The exploit in and out of itself does nothing - it just overflows memory to push custom code into executable space. You're free to speculate though.

Is it just me, or do people have difficulty reading what you're saying?
I think it's just genuine curiosity, which is fine. People naturally want a full-blown CFW with total control of the system - that's always the ultimate goal. They're free to investigate, too - curiosity is the mother of all CFW's, much like necessity is the mother of invention.
 
  • Like
Reactions: Margen67

ken28

Well-Known Member
Member
Joined
Oct 21, 2010
Messages
1,181
Trophies
1
XP
1,693
Country
Germany
The exploit in and out of itself does nothing - it just overflows memory to push custom code into executable space. You're free to speculate though.
that the problem imho. We dont know how far the exploits goes. For all we know it could install a silent programm with kernel rights that manages the HBmenu instaltion.
We wont really know for 100% until we see the source code.
 

Foxi4

Endless Trash
Global Moderator
Joined
Sep 13, 2009
Messages
30,825
Trophies
3
Location
Gaming Grotto
XP
29,841
Country
Poland
that the problem imho. We dont know how far the exploits goes. For all we know it could install a silent programm with kernel rights that manages the HBmenu instaltion.
We wont really know for 100% until we see the source code.
Once again, you're exploiting a userland application, so all you're going to get is userland privileges of that application - that's how the protection works. Executables allowing for kernel-level access have allocated space, they belong to the OS, you would have to exploit them to gain higher access. In some cases there is an area of opportunity or some overlap there, but that's a one in a million case. This is why mset worked and there's a 99% chance that this does not.
 

ken28

Well-Known Member
Member
Joined
Oct 21, 2010
Messages
1,181
Trophies
1
XP
1,693
Country
Germany
Once again, you're exploiting a userland application, so all you're going to get is userland privileges of that application - that's how the protection works. Executables allowing for kernel-level access have allocated space, you would have to exploit them to gain higher access. In some cases there is an area of opportunity or some overlap there, but that's a one in a million case.
and what if this is such a case? Smealum said afterall that the devs tried to close one exploits but opened and even bigger one. My point still is without the source we wont know for sure.
 

tyons

Well-Known Member
Member
Joined
Jul 11, 2012
Messages
657
Trophies
1
XP
282
Country
Italy
can some mod edit the title of the thread? it states something that is VERY probably not true and anyway 100% unconfirmed.
 

Foxi4

Endless Trash
Global Moderator
Joined
Sep 13, 2009
Messages
30,825
Trophies
3
Location
Gaming Grotto
XP
29,841
Country
Poland
I would be terribly pleased if no leaks or quotes of leaks would occur from this point onwards. Anyone's welcome to do RE on their own - not here.

can some mod edit the title of the thread? it states something that is VERY probably not true and anyway 100% unconfirmed.
Granted.
 
  • Like
Reactions: tyons

Kylecito

eats warnings for breakfast
Member
Joined
May 6, 2009
Messages
356
Trophies
0
XP
874
Country
Cote d'Ivoire
I would be terribly pleased if no leaks or quotes of leaks would occur from this point onwards. Anyone's welcome to do RE on their own - not here.


Oh come on, it was just a dumb joke, I didn't provide any links and what little appeared on the screen was useless. Take that stick out your ass willya


EDIT: see, even smealum liked my post :)
 

Foxi4

Endless Trash
Global Moderator
Joined
Sep 13, 2009
Messages
30,825
Trophies
3
Location
Gaming Grotto
XP
29,841
Country
Poland
No need for another thread about this, merging with the other thread. Keep your calm, ladies and gentlemen. ;) Also, little point in quoting me - I'm no hacker, I just post educated opinions. :P
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: