[Defcon] Smea to give 3DS security talk and release free arm9 exploit chain on August 11

dc-25-logo.jpg


(complete video of the talk - uploaded Oct. 22, 2018)

UPDATE (10-23-18): This hack was patched on 11.8 and was never publicly implemented
Please use Frogminer -> Free B9S cfw, works on 11.8, covers all major regions

(disclosure: Frogminer is my hack, but it serves the same purpose smeahax originally promised, so it's relevant here)


It looks like our old 3DS scene pal @smealum has returned to the limelight! Famous for his groundbreaking Ninjhax, Ironhax, and Tubehax userland exploits, and the udsploit kernel11 hax, Smea is back and better than ever with a total of four new exploits set to be revealed this Saturday at Defcon 26 in Las Vegas! So if you never got on the CFW bandwagon (full control of your 3DS with all the implied benefits), you'd better come and tune in with us this Saturday at 11:00 am PT sharp!​

Slides and Additional Videos


MHAX userland
ROHAX2 priv. escalation
ZHAX kernel11
TWLHAX arm9

(please wait for the guide to be updated for instructions)
^ skeletonwaiting.gif

DkV77xzUcAACLnW.jpg


 
Last edited by zoogie,

zoogie

playing around in the end of life
OP
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,001
Country
Micronesia, Federated States of
can someone give me a rundown on or a link to his presentation?
There won't be a video for a good while (6 months I heard).
Check out "slides and videos" in the OP and the hax repos.
That's all we have right now.

People are still working on getting the exploits ready for public consumption.
 

Myria

Well-Known Member
Member
Joined
Jul 24, 2014
Messages
464
Trophies
0
Age
42
XP
877
Country
United States
I have a feeling that Nintendo's fix for TWL_FIRM is very...incomplete, and that exploiting it is still simple. I know of a few attack vectors to try. However, it would still require an ARM11 exploit, now that one has been burned.
 
  • Like
Reactions: jimmyj and zoogie

zoogie

playing around in the end of life
OP
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,001
Country
Micronesia, Federated States of
It only has access to ARM7 which is not even powered on when not playing GBA VCs.
You're confusing agb_firm with the GBA bios.
agb_firm is a 3ds mode title with various arm9 and arm11 executables included.
It's responsible for setting up the 3ds hardware for GBA BC mode and then switching to it.
 
Last edited by zoogie,
  • Like
Reactions: WBW

jimmyj

Official founder of altariaism. Copyright jimmyj
Member
Joined
May 26, 2017
Messages
1,485
Trophies
1
Location
Hyrule
XP
1,632
Country
United Kingdom
I have a feeling that Nintendo's fix for TWL_FIRM is very...incomplete, and that exploiting it is still simple. I know of a few attack vectors to try. However, it would still require an ARM11 exploit, now that one has been burned.
You could install cfw,inject 11.8 twl firm, and leave agb firm and native firm to 11.4 so you can uninstall cfw and use the existing arm11 exploit to start looking for vulns in the 11.8 twl firm.(this is only for finding vulns,this would be useless for any normal user)
 
  • Like
Reactions: aphirst

R13

Member
Newcomer
Joined
Aug 12, 2018
Messages
7
Trophies
0
Age
33
XP
52
Country
United States
Anybody got a rough estimate for how long until actual instructions on how to do it are uploaded? Wondering if I should wait or just do seedminer method. (Sorry if this has already been asked)
 
Last edited by R13,

Akira

I'm not a SHRIMP!!!!
Member
Joined
Apr 28, 2013
Messages
1,246
Trophies
0
XP
1,666
Country
United States
Anybody got a rough estimate for how long until instructions are uploaded? Wondering if I should wait or just do seedminer method. (Sorry if this has already been asked)
If you have the capability to cash out $2 then just do the seedminer method.
 

R13

Member
Newcomer
Joined
Aug 12, 2018
Messages
7
Trophies
0
Age
33
XP
52
Country
United States
I mean, if it was going to come out within the next day or 2, I'd be willing to wait. It was more of "will take a day or a month?."
 

Scooty789

Member
Newcomer
Joined
Jul 22, 2018
Messages
10
Trophies
0
Age
24
XP
73
Country
Czech Republic
Hey zoogie, I'm sorry for this stupid question, but do you have an estimated release date for the exploit's instructions on 3ds.hacks.guide?
Thanks in advance.
Edit: I just saw that somebody asked this question before me.... I'm sorry for repeating questions.
 
Last edited by Scooty789,

PICTOCHAT

Active Member
Newcomer
Joined
Nov 5, 2017
Messages
34
Trophies
0
Age
23
XP
651
Country
Antarctica
I can't play any of the videos or the slide... For me opening the PDF only shows a gray vertically-oriented oval, and the videos show some sort of crack going through a square in the frame the video is supposed to be, and the time in the bottom left corner showing "0:00"... Any help would be appreciated.
 

Brawl345

Well-Known Member
Member
Joined
Jan 14, 2012
Messages
777
Trophies
2
Website
wiidatabase.de
XP
2,880
Country
Germany
I can't play any of the videos or the slide... For me opening the PDF only shows a gray vertically-oriented oval, and the videos show some sort of crack going through a square in the frame the video is supposed to be, and the time in the bottom left corner showing "0:00"... Any help would be appreciated.
Try downloading it instead of opening it in the browser. Works for me.
 

SirNapkin1334

Renound Aritst
Member
Joined
Aug 20, 2017
Messages
1,665
Trophies
1
XP
975
Country
United States
Can you provide a link to the full talk? Ideally on YouTube so I can watch it on my phone (won’t have computer access for 2 more days)
 

R13

Member
Newcomer
Joined
Aug 12, 2018
Messages
7
Trophies
0
Age
33
XP
52
Country
United States
Maybe this is a dumb question but if the videos on how to do it (From smea's talk) arn't going to be released for a long time, surely it is going to be quite a while before any guide for normal users will prop up? I don't think anyone is going to do the guide from memory of the talk. Unless other people already know how to do it.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Sicklyboy @ Sicklyboy:
    obamna
  • The Catboy @ The Catboy:
    SODA
  • Sonic Angel Knight @ Sonic Angel Knight:
    Catboy back in chat. :ninja:
  • Sonic Angel Knight @ Sonic Angel Knight:
    Don't forget to pet it for good luck
  • K3Nv2 @ K3Nv2:
    That cat bites
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Hmmm yes she does
  • Psionic Roshambo @ Psionic Roshambo:
    Float like a butterfly burns when I pee lol
    +1
  • BigOnYa @ BigOnYa:
    So does that mean your date was not good? It burns now?
    +1
  • K3Nv2 @ K3Nv2:
    Got two new stds in one night
    +1
  • BigOnYa @ BigOnYa:
    Giggity
    +1
  • The Catboy @ The Catboy:
    I don't bite! Minus the times when I did bite
  • The Catboy @ The Catboy:
    Like 5 minutes ago
  • K3Nv2 @ K3Nv2:
    Billie needs her lunch
  • K3Nv2 @ K3Nv2:
    Ffs papa brought back the cheeseburger pizza it's like the only decent pie they had since the 80s
  • BigOnYa @ BigOnYa:
    I'm not a fan of papa johns, but that does sound good. We hardly order out pizza, I like making my own, but when we do its donatoes
  • K3Nv2 @ K3Nv2:
    I get them like once every two months anymore
  • K3Nv2 @ K3Nv2:
    Just because it's half a mile from where I live
  • BigOnYa @ BigOnYa:
    Request next time you order, that Shaq deliver it to you
  • K3Nv2 @ K3Nv2:
    I want him to buy me a chain also
  • K3Nv2 @ K3Nv2:
    Open it right next to the one we have
    +1
  • BakerMan @ BakerMan:
    guys should i make a new thread and just count the amount of posts until kyle, luke or leo joins the thread for fun?
  • BakerMan @ BakerMan:
    kyle's fine, just waiting for that wario joke

    luke and leo though, they yap until the thread's enjoyability is about halved
  • K3Nv2 @ K3Nv2:
    Leo is Luke's alterego when he gets hard
  • BigOnYa @ BigOnYa:
    Luke is gone, he got banned. And I'm surprised Leo hasn't yet
  • K3Nv2 @ K3Nv2:
    Subway was actually pretty decent tonight
    K3Nv2 @ K3Nv2: Subway was actually pretty decent tonight