Hacking WIP Switch Exploit Idea - I want the Community to Use it!

Status
Not open for further replies.

aarock1234

New Member
OP
Newbie
Joined
Aug 4, 2017
Messages
1
Trophies
0
Age
24
XP
41
Country
United States
I made an account just to post this.

Mostly I have been a browser of this forum for a long time and like to look at random posts.

I have been developing an idea with a friend and we decided we wanted to share it with the community and see what they could do withit.

Exploit

Notes:
  • Involves JPEG images and buffer overflow.
Usage:

The basic premises state that you would essentially take an image from the switches SD card and edit it in a text editor. You would in theory add many characters to the file so the switch would not know what to do. Basic rules for computers say if a file is too large it would write that overflowing data somewhere else (buffer overflow). That data could be a homebrew launcher, program, game or some other thing that could be written on the switch itself. The reason we use JPEG images is that they are injectable/can be edited. The idea would be to somehow take some code (arm asm) and compile it into a jpeg and use the switch image viewer to access the program.​
 

Sonic Angel Knight

Well-Known Member
Member
Joined
May 27, 2016
Messages
14,408
Trophies
1
Location
New York
XP
12,984
Country
United States
Sounds like psp Chicken hen exploit.... Would that really work a second time, especially on a console 10 years later? :blink:
(Not denying the possibility, just was curious what others thinks)
 

Urbanshadow

Well-Known Member
Member
Joined
Oct 16, 2015
Messages
1,578
Trophies
0
Age
33
XP
1,723
Country
I'd honestly try malforming a .tiff header like was done to the PSP, or malform a .svg to load it from the "browser" but I'm sure it doesn't lead anywhere.

--------------------- MERGED ---------------------------

Sounds like psp Chicken hen exploit.... Would that really work a second time, especially on a console 10 years later? :blink:
(Not denying the possibility, just was curious what others thinks)

Oh the ninja. That was a .tiff file preview, back in the day.
 
  • Like
Reactions: WeedZ

Urbanshadow

Well-Known Member
Member
Joined
Oct 16, 2015
Messages
1,578
Trophies
0
Age
33
XP
1,723
Country
I dunno what it was to be exact, I just now every video i watched was someone opening the picture folder filled with images, and scrolling to the bottom one, and enable homebrew. BAM! I'm batman... err Chicken hen! :P

The tiff header is limited in size, the tiff header reader for psp was coded by sony, they didn't check the size. It was really cheap and dirty. The hit and miss part was depending on what was after the tiff header in memory and if it corrupts the xmb menu memory. After that went the hen payload and the rest is history.
 

DarkOrb

Well-Known Member
Member
Joined
Oct 11, 2013
Messages
290
Trophies
0
Age
31
XP
874
Country
Germany
That won't work. This way the file will be corrupt and not readable anymore. You have to edit the file in a special way, so it's still readable AND will cause a buffer overflow, but this would need an exploit in the Switch image viewer app in the first place. You don't have the slightest chance to make that happen if you're not a very talented dev.
 
D

Deleted User

Guest
In theory it would work if:

  • Somebody could make a tool to re-calculate the hashes for images so that they would be compatible with the Switch (because they are HMAC-SHA256 hash checked)
  • We could patch out the size check on screenshots
They size check is pretty much impossible to bypass (that we know of right now) because it is coded into the firmware.

Also, please read the forums like you said you did before posting stuff like this.
 
  • Like
Reactions: Deleted User

The Catboy

GBAtemp Official Catboy™: Savior of the broken
Member
Joined
Sep 13, 2009
Messages
28,034
Trophies
4
Location
Making a non-binary fuss
XP
39,651
Country
Antarctica
Honestly I think this thread should be locked until the OP has something to show (though extremely doubtful) If they want to take the time and try something, they are clearly not going to get the support of the community until we have something to see.
 
Last edited by The Catboy,
  • Like
Reactions: VinsCool
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • Jayro @ Jayro:
    Eventhough the New 3DS XL is more powerful, I still feel like the DS Lite was a more polished system. It's a real shame that it never got an XL variant keeping the GBA slot. You'd have to go on AliExpress and buy an ML shell to give a DS phat the unofficial "DS Lite" treatment, and that's the best we'll ever get I'm afraid.
    +1
  • Jayro @ Jayro:
    The phat model had amazingly loud speakers tho.
    +1
  • SylverReZ @ SylverReZ:
    @Jayro, I don't see whats so special about the DS ML, its just a DS lite in a phat shell. At least the phat model had louder speakers, whereas the lite has a much better screen.
    +1
  • SylverReZ @ SylverReZ:
    They probably said "Hey, why not we combine the two together and make a 'new' DS to sell".
  • Veho @ Veho:
    It's a DS Lite in a slightly bigger DS Lite shell.
    +1
  • Veho @ Veho:
    It's not a Nintendo / iQue official product, it's a 3rd party custom.
    +1
  • Veho @ Veho:
    Nothing special about it other than it's more comfortable than the Lite
    for people with beefy hands.
    +1
  • Jayro @ Jayro:
    I have yaoi anime hands, very lorge but slender.
  • Jayro @ Jayro:
    I'm Slenderman.
  • Veho @ Veho:
    I have hands.
  • BakerMan @ BakerMan:
    imagine not having hands, cringe
    +1
  • AncientBoi @ AncientBoi:
    ESPECIALLY for things I do to myself :sad:.. :tpi::rofl2: Or others :shy::blush::evil:
    +1
  • The Real Jdbye @ The Real Jdbye:
    @SylverReZ if you could find a v5 DS ML you would have the best of both worlds since the v5 units had the same backlight brightness levels as the DS Lite unlockable with flashme
  • The Real Jdbye @ The Real Jdbye:
    but that's a long shot
  • The Real Jdbye @ The Real Jdbye:
    i think only the red mario kart edition phat was v5
  • BigOnYa @ BigOnYa:
    A woman with no arms and no legs was sitting on a beach. A man comes along and the woman says, "I've never been hugged before." So the man feels bad and hugs her. She says "Well i've also never been kissed before." So he gives her a kiss on the cheek. She says "Well I've also never been fucked before." So the man picks her up, and throws her in the ocean and says "Now you're fucked."
    +1
  • BakerMan @ BakerMan:
    lmao
  • BakerMan @ BakerMan:
    anyways, we need to re-normalize physical media

    if i didn't want my games to be permanent, then i'd rent them
    +1
  • BigOnYa @ BigOnYa:
    Agreed, that why I try to buy all my games on disc, Xbox anyways. Switch games (which I pirate tbh) don't matter much, I stay offline 24/7 anyways.
  • AncientBoi @ AncientBoi:
    I don't pirate them, I Use Them :mellow:. Like I do @BigOnYa 's couch :tpi::evil::rofl2:
    +1
  • cearp @ cearp:
    @BakerMan - you can still "own" digital media, arguably easier and better than physical since you can make copies and backups, as much as you like.

    The issue is DRM
  • cearp @ cearp:
    You can buy drm free games / music / ebooks, and if you keep backups of your data (like documents and family photos etc), then you shouldn't lose the game. but with a disk, your toddler could put it in the toaster and there goes your $60

    :rofl2:
  • cearp @ cearp:
    still, I agree physical media is nice to have. just pointing out the issue is drm
    cearp @ cearp: still, I agree physical media is nice to have. just pointing out the issue is drm