Hacking ROP from within IOS_USB (5.5.1)

kingraa777

boom!
Member
Joined
Apr 17, 2015
Messages
1,241
Trophies
0
Age
40
XP
905
Country
This is an implementation of ROP getting userland code execution on the IOSU processor, which you can then use to run code in IOSU userland to exploit it's kernel

excuse me if im being stupid but couldn't you theoretically boot into a cfw or shell or similar from user-land this way ? from a hbl elf ->iosu code executed user-land exacuted kernal cfw ? there's something i'm trying to get at similar to how the 3ds uses rop maybe sorry for my vague description :)
 

Swiftloke

Hwaaaa!
Member
Joined
Jan 26, 2015
Messages
1,772
Trophies
1
Location
Nowhere
XP
1,508
Country
United States
excuse me if im being stupid but couldn't you theoretically boot into a cfw or shell or similar from user-land this way ? from a hbl elf ->iosu code executed user-land exacuted kernal cfw ? there's something i'm trying to get at similar to how the 3ds uses rop maybe sorry for my vague description :)
Keep in mind this is to my knowledge. Please Understand.
ROP, or Return Oriented Programming, is a technique used to get around modern ARM processors eXecute Never (XN) bit for memory, which means the processor will never execute it, meaning you can't just write code wherever in memory (usually areas with XN are areas that initial exploits have access to, like save data) and expect the processor to execute it. Instead, what we do is call instructions that already exist in memory to build up further exploits. For example, this ROP calls instructions in IOSU userland that reboot the console. From here, what we need to do is find instructions and use them to set up the IOSU kernel exploit and have full console control. (No, IOSU userland which is what this runs in doesn't have enough control to boot a CFW)
 
Last edited by Swiftloke,

KiiWii

Editorial Team
Editorial Team
Joined
Nov 17, 2008
Messages
16,707
Trophies
3
Website
defaultdnb.github.io
XP
27,266
Country
United Kingdom

Attachments

  • image.png
    image.png
    5.3 KB · Views: 529

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    Speedcum
    +1
  • BigOnYa @ BigOnYa:
    I mean what would you really need that fast for tho, 500mb streams 4k fine. 1gb should be fine for 8k eventually. That's what I just switched to Spermrum.
  • Psionic Roshambo @ Psionic Roshambo:
    I was funny to have both networks running lol
  • Psionic Roshambo @ Psionic Roshambo:
    It was cheaper lol
  • Psionic Roshambo @ Psionic Roshambo:
    The only reason I switched was $$$
  • Psionic Roshambo @ Psionic Roshambo:
    Might have only been like 7 bucks but thats like 84 dollars at the end of the year lol
  • Psionic Roshambo @ Psionic Roshambo:
    840 dollars after 10 years
  • K3Nv2 @ K3Nv2:
    I hope I can be rich enough to pay all bills annually someday
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    Not that I will save the money, rather I will just spend it on other crap lol
  • Psionic Roshambo @ Psionic Roshambo:
    lol just do autopay it's as lazy as it gets
  • BigOnYa @ BigOnYa:
    @K3Nv2 tell uremum to start charging, then you keep the money
    +1
  • K3Nv2 @ K3Nv2:
    I charge your wife rent at this point
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Now serving number E73
    +1
  • BigOnYa @ BigOnYa:
    Good, maybe she will leave me the f alone, now I can drink, smoke, and play my games in peace!
    +1
  • K3Nv2 @ K3Nv2:
    The DMV giving citizens of Detroit empowerment
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, and with yourself :creep:
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    As a reminder crack pipes left in the lobby will be thrown away, the DMV is not responsible for lost crack pipes!
  • K3Nv2 @ K3Nv2:
    I got a camera I can film what I want
    +1
  • BigOnYa @ BigOnYa:
    Gotta give my fans what they want...
    +1
  • K3Nv2 @ K3Nv2:
    Deeze nuts
  • ZeroT21 @ ZeroT21:
    get crackin'
  • Psionic Roshambo @ Psionic Roshambo:
    Well hmm got that Eeros 6+ router working so no need for a new one for now lol
  • Psionic Roshambo @ Psionic Roshambo:
    Scratch!!! In broad daylight!!!
    Psionic Roshambo @ Psionic Roshambo: Scratch!!! In broad daylight!!!