Hacking Exploit in youtube, might lead to something?

  • Thread starter Thread starter rondoh70
  • Start date Start date
  • Views Views 17,880
  • Replies Replies 94

rondoh70

Well-Known Member
Member
Joined
Sep 1, 2011
Messages
334
Reaction score
41
Trophies
0
Age
28
Location
new york
XP
307
Country
United States
Using the exploit in this forum: http://gbatemp.net/threads/use-the-youtube-3ds-app-to-watch-videos-on-other-sites.358618/
Would it be possible to create a .mp4 video with code in that somehow exploits the 3ds? I've noticed that if the player tries to load a certain video type( I can't remeber it at the moment) it will display a yellow glitchy screen, freeze, then restart the system. The yellow glitchy screen shows that the code is loading no matter what as long as its a readable filetype. I havent seen this idea yet so i thought i would post it. probably just another dead end, but who knows.
 
well, it does mean something a bit... there's a flaw, maybe not an exploitable one.. but there's one at least (like how something correctly coded can freeze a system????). Now if you can give a link to the said video, it would help a lot I guess...
 
Freeze's mean nothing. Its been said over and over again.
inb43paragraphlongeassyonthesubjectbyfoxi4


Yes, I know that. The point I was trying to make is that the youtube app is executing files it shouldn't be loading, and this can be possibly exploited. You are right though. A freeze means nothing.
 
  • Like
Reactions: BvanBart
Maybe it was on a site you don't want to share :rofl2:

But anyways isn't the bug cause with the page that the youtube app loads having external links.....so it could probably be fixed by them simply editing page to exclude the links.......I wonder if page redirection could re-enable it though, or would the youtube app not load if it was being redirected
 
well, by using a little proxy, you could use a custom dns to redirect this exact page to a local one with a link to google or to the video file?
 
Can seriously a video contain executable code? I mean, I think the way these files are handled doesn't allow the execution of code other than decodable video and audio data.
 
  • Like
Reactions: NEP
idk. I cant find a good source of 3gp videos to fuly test the theory. As gamesques1 guessed it was on an adult site.
 
some 3gp files work and others dont. search "3gp test" in google and select the first result. sample 50kbit at the bottom of the page crashes, while the blackberry ad above it works
 
Even if this causes a crash it has to be exploitable. I recall the exploit used by gateway caused the 3DS to crash and load a launcher.dat file. I don't think a YouTube app crashing will suddenly cause the 3DS looking for something to load. It has to happen a certain way and one must have a way of injecting code into the process to make the 3DS load the hack. I don't think YouTube will be the entry point. Most likely the best route is to find a flaw in a app that has greater access to the 3DS system. I don't think YouTube is one of them.
 
Well, it could.. but the magic in gateway exploit reside in the ropchain. If by any mean, this is exploitable, it would need a different ropchain to load the launcher.dat. It's not like the 3ds itself look for launcher.dat when accessing the ds settings... it's because of the ropchain.
 
  • Like
Reactions: dot7z
Can seriously a video contain executable code? I mean, I think the way these files are handled doesn't allow the execution of code other than decodable video and audio data.

Yes a video can contain executable code. Example psp tiff exploit. You can even mask a compressed container as a png gif you name it
 

Site & Scene News

Popular threads in this forum