Homebrew Why exploit images or else

Dr.Hacknik

Ashley | Developer | Trans
Member
Joined
Mar 26, 2014
Messages
1,773
Trophies
2
Age
24
Location
inside your fridge
Website
dochacknik.keybase.pub
XP
2,230
Country
United States
In order to cause an exploit to occur. You must cause a Buffer Overflow. Allowing the application to crash and fall back onto some code. I'm not sure how to do this with an image file, but performing it with a .mp4 is easy. On the other hand, MiiVerse includes a video player, with the MPEG Codec. Allowing things like YouTube videos to play. If you can redirect a Video, to a corrupted one you might be able to cause a buffer Overflow. I'm just speculating.
 

gudenau

Largely ignored
Member
Joined
Jul 7, 2010
Messages
3,882
Trophies
2
Location
/dev/random
Website
www.gudenau.net
XP
5,480
Country
United States
In order to cause an exploit to occur. You must cause a Buffer Overflow. Allowing the application to crash and fall back onto some code. I'm not sure how to do this with an image file, but performing it with a .mp4 is easy. On the other hand, MiiVerse includes a video player, with the MPEG Codec. Allowing things like YouTube videos to play. If you can redirect a Video, to a corrupted one you might be able to cause a buffer Overflow. I'm just speculating.
Buffer overflows are not needed. :3
 

gudenau

Largely ignored
Member
Joined
Jul 7, 2010
Messages
3,882
Trophies
2
Location
/dev/random
Website
www.gudenau.net
XP
5,480
Country
United States
How? I remember using them, especially in early Wii U exploits.
There are several ways to exploit stuff. Undocumented APIs, bad memory permissions letting you write where you shouldn't, integer overflows for index values, plain old not checking inputs, stack overflows, buffer over and underflows, type confusion, abusing hardware DMA, use after free.

Lots of things are possible. IIRC the Stagefright stuff is an interger overflow. I know for a fact that the Pegasus thing uses a use after free to create a flat array that is 0xFFFFFFFF bytes long and starts at 0x00000000.
 
  • Like
Reactions: Dr.Hacknik

Wolfer473

Active Member
Newcomer
Joined
Jul 27, 2017
Messages
30
Trophies
0
XP
103
Country
United States
set it as proxy
Yeah lol I figured it out right after I posted that. I'm now banned from Miiverse and eShop. Can't tell if it's because I was trying to replace an eShop video and it detected an invalid certificate or because the NNU-Patcher stopped working while I was still in the eShop.
 

gbatempfan1

Well-Known Member
Member
Joined
Nov 2, 2010
Messages
200
Trophies
1
XP
1,207
Country
In order to cause an exploit to occur. You must cause a Buffer Overflow. Allowing the application to crash and fall back onto some code. I'm not sure how to do this with an image file,.

Several things to check, I wrote a decoder in python 4 or 5 years ago, so it is a bit vague, but from what I remember... You can check how it handles the memory situation by creating pngs that deflate quite large through several methods. Each chunk can be 4mb, there are 4 primrary chunk types such as image data, color palettes, and a dozen or maybe even more extra types like text data, besides making fields in headers large, since it uses DEFLATE compression, just see how many series of blocks of 0 or 1s you can encode, which it will subsequently expand, you can also create literal blocks of 64k in size, and keep on pushing them. Also I think filtering bits can expand things even more. Besides checking low memory conditions to see if any of the 14 chunk types overflow, you can check which version of libpng it uses, if it does use that library, you can check for CVEs https://www.cvedetails.com/vulnerability-list/vendor_id-7294/Libpng.html

I'd imagine with some googling there might be some specially crafted pngs online for testing these things. Of course that gets you half way, if you test out a bunch and you get a crash, like you said, the other half is the code execution.
 
Last edited by gbatempfan1,

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • BigOnYa @ BigOnYa:
    I'd rather spend like $150 more for a surround receiver.
  • K3Nv2 @ K3Nv2:
    I bought the game at launch never fucked with it until recently
  • BigOnYa @ BigOnYa:
    Its fun, I like it, even tho I'm not a big harry potter fan. Like a wizard rpg. Flying around on a broomstick is cool.
  • K3Nv2 @ K3Nv2:
    Flying sucks ass on it
  • BigOnYa @ BigOnYa:
    Nuh just takes a min to get used to. I think you can upgrade or buy new broomstick also that are better.
    +1
  • K3Nv2 @ K3Nv2:
    I weirdly like inverted controls on all flying type games
  • BigOnYa @ BigOnYa:
    Prob can change it, inverted flying controls.
  • K3Nv2 @ K3Nv2:
    Only thing that annoys me is trying to find wtf to do in it
    +1
  • BigOnYa @ BigOnYa:
    Alright off to the store, later gators.
    +1
  • K3Nv2 @ K3Nv2:
    Some places amaze me were not in network with your insurance would you still like an appointment
    +1
  • AncientBoi @ AncientBoi:
    uhhh, I think I'll just stick with my PSP 3001
  • AncientBoi @ AncientBoi:
    lol, Now I gotta go to the store for more Coffee Mate n other stuff.
  • Xdqwerty @ Xdqwerty:
    i downloaded final fantasy vii into my tv stick
  • Xdqwerty @ Xdqwerty:
    i mean, the game was already there but its the japanese version
  • Xdqwerty @ Xdqwerty:
    and i only downloaded disc 1 so far bc of storage stuff
  • Psionic Roshambo @ Psionic Roshambo:
    @BigOnYa, yeah the patty on McDs burger is 1/10th of a pound now and I think that's the pre cooked weight lol
  • Psionic Roshambo @ Psionic Roshambo:
    I use the app for the 20% off coupon and it's still over priced
  • Xdqwerty @ Xdqwerty:
    @Psionic Roshambo, why is mcdonalds overpriced if their food is bad?
  • Xdqwerty @ Xdqwerty:
    i mean why is mcdonalds food overpriced
  • Psionic Roshambo @ Psionic Roshambo:
    Inflation and greed
    +1
  • ZeroT21 @ ZeroT21:
    it's just fries, make 'em at home
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    I make potato wedges at home with spices and stuff lol
    Psionic Roshambo @ Psionic Roshambo: I make potato wedges at home with spices and stuff lol