Hacking [SPECULATION] SSSpwn allows kernel access?

Status
Not open for further replies.

WaryLouka

Official Representative of the SuperCard Team
Banned
Joined
Jun 22, 2013
Messages
216
Trophies
1
Age
41
Location
NO RECORDS
XP
186
Country
United States
The exploit and Homebrew Channel are not installed on the system. It is installed in the writable portion of the game card. No kernel access is ever used. End of story.
 

Foxi4

Endless Trash
Global Moderator
Joined
Sep 13, 2009
Messages
30,829
Trophies
3
Location
Gaming Grotto
XP
29,870
Country
Poland
overwriting an systemodul souns pretty kernel for me.
It doesn't overwrite any system modules, if it did, the whole firmware would become corrupt because it's signed and you can't just randomly resign it. As it stands today, the firmware is wholly protected. If HBMenu uses services and syscalls, it can only use them because Cubic Ninja can - it inherits privileges. It's the exact same case with VHBL and userland exploits - they can run code, but only to the extent of what the original binary was allowed to do.
 

Ryanrocks462

Wii U/3DS Hacker.. Will test anything, A Pirate
Banned
Joined
Jun 18, 2014
Messages
566
Trophies
0
Location
California
XP
162
Country
United States
Ooohhhh okay. So Relys, the guy who *ahem* analyzed the exploit probably knows more about how it works that the guy who made the exploit. Noooww I get it. I herd Smealum iz illuminaty, too.

well we are talking about the guy who created the decryptors Nand and decryptor I'm pretty sure relys is able to understand a basic exploit ;3
 

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,375
Trophies
4
Location
Space
XP
13,982
Country
Norway
All this guy does is talk shit, I wouldn't take his word for it.
However, that doesn't mean SSSpwn doesn't obtain kernel access. A while back it was claimed that you could not execute unsigned code without a kernel exploit. So if there's no kernel exploit there is at least something beyond simply userland that allows running homebrew.
I'll take smea's word for it that it doesn't obtain kernel access for now though :)
 

Ryanrocks462

Wii U/3DS Hacker.. Will test anything, A Pirate
Banned
Joined
Jun 18, 2014
Messages
566
Trophies
0
Location
California
XP
162
Country
United States
Decryptors for 3DS games. Not userland exploits.
Even if he is right, that still doesn't mean kernel access.

well he also released his nand decryptor ;3
and if he is able to get and decryption I'm pretty sure he will understand user land

Not really basic

userland ;3
 

Foxi4

Endless Trash
Global Moderator
Joined
Sep 13, 2009
Messages
30,829
Trophies
3
Location
Gaming Grotto
XP
29,870
Country
Poland
All this guy does is talk shit, I wouldn't take his word for it.
However, that doesn't mean SSSpwn doesn't obtain kernel access. A while back it was claimed that you could not execute unsigned code without a kernel exploit. So if there's no kernel exploit there is at least something beyond simply userland that allows running homebrew.
I'll take smea's word for it that it doesn't obtain kernel access for now though :)
That's the magic of it - Cubic Ninja is signed, it's a legit retail game. For all the ARM knows, the code is signed and verified - eXecute Never doesn't kick in because it thinks it's running something else entirely.
 

WaryLouka

Official Representative of the SuperCard Team
Banned
Joined
Jun 22, 2013
Messages
216
Trophies
1
Age
41
Location
NO RECORDS
XP
186
Country
United States
1. QR Code Overflow
2. Jump to ROP chain in QR code payload
3. Download AES encrypted payload smealum.net/ninjhax/p/POST5_WEST_4096_4096.bin from internet.
4. Escalate privilege level by overwriting a sysmodule.
5. Transfer execution over to boot.3dsx

Ok, according to professionals, it is clearly written that the escalated privilege we got is Kernel mode. Of course, all other levels are impossible to be escalated because idiots are claiming it can only be the kernel.

I will also quote Foxi4;

It doesn't overwrite any system modules, if it did, the whole firmware would become corrupt because it's signed and you can't just randomly resign it. As it stands today, the firmware is wholly protected. If HBMenu uses services and syscalls, it can only use them because Cubic Ninja can - it inherits privileges. It's the exact same case with VHBL and userland exploits - they can run code, but only to the extent of what the original binary was allowed to do.
 
  • Like
Reactions: tyons

Ryanrocks462

Wii U/3DS Hacker.. Will test anything, A Pirate
Banned
Joined
Jun 18, 2014
Messages
566
Trophies
0
Location
California
XP
162
Country
United States
All this guy does is talk shit, I wouldn't take his word for it.
However, that doesn't mean SSSpwn doesn't obtain kernel access. A while back it was claimed that you could not execute unsigned code without a kernel exploit. So if there's no kernel exploit there is at least something beyond simply userland that allows running homebrew.
I'll take smea's word for it that it doesn't obtain kernel access for now though :)

lolz ya I'm done arguing with everyone :P ill just keep my eye on gateway :3
 

Foxi4

Endless Trash
Global Moderator
Joined
Sep 13, 2009
Messages
30,829
Trophies
3
Location
Gaming Grotto
XP
29,870
Country
Poland
The burden of proof lies on the accuser, in this case GovanifY.
So far GovanifY's only achievement was leaking something he hasn't even made himself, so his word isn't exactly worth much. He's more than welcome to demonstrate kernel-level access if he feels like it. In fact, anyone can investigate this - Homebrew Launcher is open source. Go nuts. ;)
 

Esppiral

Well-Known Member
Member
Joined
Aug 24, 2014
Messages
352
Trophies
0
Age
41
XP
1,198
Country
smea said he is willing to add region free support, and I don't think how such thing could be possible without kernel access...
 

the_randomizer

The Temp's official fox whisperer
Member
Joined
Apr 29, 2011
Messages
31,284
Trophies
2
Age
38
Location
Dr. Wahwee's castle
XP
18,969
Country
United States
Two questions that I present to the members who read this thread, *ahem*

One - Who the hell is this guy?
Two - Why the hell should we care what he says again?

/useful informative thread

Edit: Ah, so he's the little braggart that leaked the CFW, meaning, whatever little credibility he "had" is lost. Just another fine day in the 3DS scene :rolleyes:
 
  • Like
Reactions: endoverend

Foxi4

Endless Trash
Global Moderator
Joined
Sep 13, 2009
Messages
30,829
Trophies
3
Location
Gaming Grotto
XP
29,870
Country
Poland
smea said he is willing to add region free support, and I don't think how such thing could be possible without kernel access...
I don't remember him ever saying that, but such a modification would normally require kernel level access, unless there's some clever trick up smea's sleeve.
 

ken28

Well-Known Member
Member
Joined
Oct 21, 2010
Messages
1,181
Trophies
1
XP
1,693
Country
Germany
So far GovanifY's only achievement was leaking something he hasn't even made himself, so his word isn't exactly worth much. He's more than welcome to demonstrate kernel-level access if he feels like it. In fact, anyone can investigate this - Homebrew Launcher is open source. Go nuts. ;)
the launcher is, not the exploit.
The question will still remain even if weaker until sources of the exploit are released.
 

ken28

Well-Known Member
Member
Joined
Oct 21, 2010
Messages
1,181
Trophies
1
XP
1,693
Country
Germany
I don't remember him ever saying that, but such a modification would normally require kernel level access, unless there's some clever trick up smea's sleeve.
he did, but somewhere he also said its quite compilcated if i remember right.
c7a053490172fd8a3e66f539f69d790d.jpg
 

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,375
Trophies
4
Location
Space
XP
13,982
Country
Norway
That's the magic of it - Cubic Ninja is signed, it's a legit retail game. For all the ARM knows, the code is signed and verified - eXecute Never doesn't kick in because it thinks it's running something else entirely.
You still can't execute your own code though.
I'm talking about a different level of protection, memory protection.
It doesn't get write access to executable regions of memory, and there's no access to setting memory to be executable either. So there should be no way to actually execute your own code even if you can load it without a kernel exploit.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    Speedcum
    +1
  • BigOnYa @ BigOnYa:
    I mean what would you really need that fast for tho, 500mb streams 4k fine. 1gb should be fine for 8k eventually. That's what I just switched to Spermrum.
  • Psionic Roshambo @ Psionic Roshambo:
    I was funny to have both networks running lol
  • Psionic Roshambo @ Psionic Roshambo:
    It was cheaper lol
  • Psionic Roshambo @ Psionic Roshambo:
    The only reason I switched was $$$
  • Psionic Roshambo @ Psionic Roshambo:
    Might have only been like 7 bucks but thats like 84 dollars at the end of the year lol
  • Psionic Roshambo @ Psionic Roshambo:
    840 dollars after 10 years
  • K3Nv2 @ K3Nv2:
    I hope I can be rich enough to pay all bills annually someday
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    Not that I will save the money, rather I will just spend it on other crap lol
  • Psionic Roshambo @ Psionic Roshambo:
    lol just do autopay it's as lazy as it gets
  • BigOnYa @ BigOnYa:
    @K3Nv2 tell uremum to start charging, then you keep the money
    +1
  • K3Nv2 @ K3Nv2:
    I charge your wife rent at this point
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Now serving number E73
    +1
  • BigOnYa @ BigOnYa:
    Good, maybe she will leave me the f alone, now I can drink, smoke, and play my games in peace!
    +1
  • K3Nv2 @ K3Nv2:
    The DMV giving citizens of Detroit empowerment
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, and with yourself :creep:
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    As a reminder crack pipes left in the lobby will be thrown away, the DMV is not responsible for lost crack pipes!
  • K3Nv2 @ K3Nv2:
    I got a camera I can film what I want
    +1
  • BigOnYa @ BigOnYa:
    Gotta give my fans what they want...
    +1
  • K3Nv2 @ K3Nv2:
    Deeze nuts
  • ZeroT21 @ ZeroT21:
    get crackin'
  • Psionic Roshambo @ Psionic Roshambo:
    Well hmm got that Eeros 6+ router working so no need for a new one for now lol
  • Psionic Roshambo @ Psionic Roshambo:
    Scratch!!! In broad daylight!!!
    Psionic Roshambo @ Psionic Roshambo: Scratch!!! In broad daylight!!!