Hacking CVE-2016-4657 walk-through and intro to browser exploitation

  • Thread starter Deleted User
  • Start date
  • Views 30,841
  • Replies 62
  • Likes 3

AecdArmy

Biscuit#0001
Member
Joined
Jan 4, 2016
Messages
505
Trophies
0
Age
21
Location
The Ninty Ninja HQ
Website
mariebot.tech
XP
605
Country
Australia
Yes, it's a proof of concept, but a critical part of the proof is seeing that the length changed, and I'm not reaching that alert. So this makes me curious exactly what his setup was, if he was reliably having success.

Edit: Okay, now if I set up my server with his exact files freshly unzipped from his github master (not just poc1.html but also his index.html which redirects to it), then I am able to get to the end of the PoC reliably.

Same thing when im using it on my domain instead of localhosting it.
 

ehnoah

Well-Known Member
Member
Joined
Oct 9, 2012
Messages
918
Trophies
0
XP
781
Country
Netherlands
New
Well I understood absolute nothing :D But it was informative and I watched it til the End :X

So the exploit give us access to the Memory Range of the Web Browser? Like we can access 100 MB of the RAM? From there we can try go deeper?
 

gluffl

New Member
Newbie
Joined
Jun 10, 2014
Messages
3
Trophies
0
XP
104
Country
really bad, this was published. now it's a matter of hours or a few days, until it's fixed. IT's also really easy for Nintendo to fix it, just updating a few files of the webkit.
 

ehnoah

Well-Known Member
Member
Joined
Oct 9, 2012
Messages
918
Trophies
0
XP
781
Country
Netherlands
I don't own a Switch (yet). Really really bad, the exploit was made public until an useful hack was developed...

Well that is the reason why I think about buy switch now and keep it. But since there is lot of Hardware Protection I doubt we get any useful without wire cables to the board.
 

empulse

New Member
Newbie
Joined
Oct 27, 2008
Messages
3
Trophies
0
XP
185
Country
United States
Think it was released because there is more coming, has advanced further. already have seen 2 diff emulators load -- no gameplay, but they loaded.
 

koffieleut

Well-Known Member
Member
Joined
Jan 22, 2009
Messages
684
Trophies
1
Age
39
Location
probably at home
XP
1,887
Country
Netherlands
I loved the part where he stated that he was just a noob. On that point I thought that I would understand what he was saying about the code.... I understood like 5% of the story :wacko:
 

McHaggis

Fackin' Troller
Member
Joined
Oct 24, 2008
Messages
1,749
Trophies
0
XP
1,466
Country
The Switch notices and recovers from the exception much like the 3DS used to for non-exploitable vulnerabilities, so I'm skeptical as to how useful this is.
 
  • Like
Reactions: peteruk

studio1b

Well-Known Member
Member
Joined
Mar 14, 2009
Messages
146
Trophies
1
Age
43
Location
NEW YORK CITY
XP
444
Country
United States
this is just the start and this is a great tool that will lead to alot of stuff.

right now we are looking for aes key for dfu mode.

but with this we might be able to hit something that gives us the info we need
to everyone that keeps saying a hack will make they devs run away this is not true at all. every console get a hacked and only effects Sales of the console. so more and more people will buy the console. and just beause some one runs backups don't mean they don't buy games
 

yeddish

Active Member
Newcomer
Joined
Feb 2, 2016
Messages
25
Trophies
0
Age
45
XP
146
Country
United States
Does fiddler work with this? And what about the public dns's for browsing?
Fiddler will work. It has many of the same basic features that Burp Suite has. Burp Suite is better, though, IMO. It also has a basic free version that will do what is needed for this hack. I would recommend giving it a look.

EDIT: Also, the public DNS works for me for browsing.
 
Last edited by yeddish,

hitodesu

Well-Known Member
Member
Joined
Mar 10, 2017
Messages
136
Trophies
0
Age
25
XP
259
Country
United States
Fiddler will work. It has many of the same basic features that Burp Suite has. Burp Suite is better, though, IMO. It also has a basic free version that will do what is needed for this hack. I would recommend giving it a look.

EDIT: Also, the public DNS works for me for browsing.
If you went to the CVE page on that with the public DNS, did it do a successful run through?
 

chaoskagami

G̷̘̫̍̈́̊̓̈l̴̙͔̞͠i̵̳͊ţ̸̙͇͒̓c̵̬̪̯̥̳͒͌̚h̵̹̭͛̒̊̽̚
Developer
Joined
Mar 26, 2016
Messages
1,365
Trophies
1
Location
↑↑↓↓←→←→BA
Website
github.com
XP
2,287
Country
United States

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • BigOnYa @ BigOnYa:
    Biomutant looks cool tho, may have to try that
  • Quincy @ Quincy:
    Usually when such a big title leaks the Temp will be the first to report about it (going off of historical reports here, Pokemon SV being the latest one I can recall seeing pop up here)
  • K3Nv2 @ K3Nv2:
    I still like how a freaking mp3 file hacks webos all that security defeated by text yet again
  • BigOnYa @ BigOnYa:
    They have simulators for everything nowdays, cray cray. How about a sim that shows you playing the Switch.
  • K3Nv2 @ K3Nv2:
    That's called yuzu
    +1
  • BigOnYa @ BigOnYa:
    I want a 120hz 4k tv but crazy how more expensive the 120hz over the 60hz are. Or even more crazy is the price of 8k's.
  • K3Nv2 @ K3Nv2:
    No real point since movies are 30fps
  • BigOnYa @ BigOnYa:
    Not a big movie buff, more of a gamer tbh. And Series X is 120hz 8k ready, but yea only 120hz 4k games out right now, but thinking of in the future.
  • K3Nv2 @ K3Nv2:
    Mostly why you never see TV manufacturers going post 60hz
  • BigOnYa @ BigOnYa:
    I only watch tv when i goto bed, it puts me to sleep, and I have a nas drive filled w my fav shows so i can watch them in order, commercial free. I usually watch Married w Children, or South Park
  • K3Nv2 @ K3Nv2:
    Stremio ruined my need for nas
  • BigOnYa @ BigOnYa:
    I stream from Nas to firestick, one on every tv, and use Kodi. I'm happy w it, plays everything. (I pirate/torrent shows/movies on pc, and put on nas)
  • K3Nv2 @ K3Nv2:
    Kodi repost are still pretty popular
  • BigOnYa @ BigOnYa:
    What the hell is Kodi reposts? what do you mean, or "Wut?" -xdqwerty
  • K3Nv2 @ K3Nv2:
    Google them basically web crawlers to movie sites
  • BigOnYa @ BigOnYa:
    oh you mean the 3rd party apps on Kodi, yea i know what you mean, yea there are still a few cool ones, in fact watched the new planet of the apes movie other night w wifey thru one, was good pic surprisingly, not a cam
  • BigOnYa @ BigOnYa:
    Damn, only $2.06 and free shipping. Gotta cost more for them to ship than $2.06
  • BigOnYa @ BigOnYa:
    I got my Dad a firestick for Xmas and showed him those 3rd party sites on Kodi, he loves it, all he watches anymore. He said he has got 3 letters from AT&T already about pirating, but he says f them, let them shut my internet off (He wants out of his AT&T contract anyways)
  • K3Nv2 @ K3Nv2:
    That's where stremio comes to play never got a letter about it
  • BigOnYa @ BigOnYa:
    I just use a VPN, even give him my login and password so can use it also, and he refuses, he's funny.
  • BigOnYa @ BigOnYa:
    I had to find and get him an old style flip phone even without text, cause thats what he wanted. No text, no internet, only phone calls. Old, old school.
    K3Nv2 @ K3Nv2: @BigOnYa...