Hacking Wii U Browser Exploit Leaked for v4.10

opal

Well-Known Member
OP
Newcomer
Joined
Dec 30, 2008
Messages
70
Trophies
0
XP
303
Country
Poland
"Finally the secret 'Wii U Browser Exploit' is now out in the wild for everyone to enjoy on their Nintendo Wii U Console, if you lucky enough to still be at v4.10 firmware."

Source: Maxconsole.com
 
  • Like
Reactions: Diablos90

markehmus

Well-Known Member
Member
Joined
Jul 26, 2008
Messages
1,521
Trophies
0
Age
112
Location
in the GAME
XP
1,279
Country
Canada
"Finally the secret 'Wii U Browser Exploit' is now out in the wild for everyone to enjoy on their Nintendo Wii U Console, if you lucky enough to still be at v4.10 firmware."

Source: Maxconsole.com

yay , and whats it load ?

icon_xl.jpg


nothing ? eh

still need some homebrew IMO , a shame nintendo will get there hands on this now, no ?
 

crwys

Well-Known Member
Member
Joined
Jun 26, 2008
Messages
1,146
Trophies
1
XP
637
Country
United States
Assuming this is even true. It doesn't matter for those who upgraded to 5.0 because it has already been confirmed that the browser exploit is still there.
 
D

Deleted User

Guest
Exploit is legitimate, but is very unfinished - /golfclap. There went your only way in.
 

NWPlayer123

Well-Known Member
Member
Joined
Feb 17, 2012
Messages
2,642
Trophies
0
Location
The Everfree Forest
XP
6,693
Country
United States
I'm in 5.0.0, but I'll try it and I see what happends...

No need, we've already done so. Doesn't work. Like we've said many times, the bug is still there (though in future updates it won't be because some idiot decided to leak an unfinished exploit for nintendo to patch), but we have no code execution.
 

WulfyStylez

SALT/Bemani Princess
Member
Joined
Nov 3, 2013
Messages
1,149
Trophies
0
XP
2,867
Country
United States
It's old webkit. Finding another exploit isn't an issue. The real issue would be if nintendo tightened the browser's permissions.

Also what's this about no code execution? This package clearly is able to do ROP stuff. If that's not code execution, I'm not entirely sure what is.
 
  • Like
Reactions: BvanBart

Snailface

My frothing demand for 3ds homebrew is increasing
Member
Joined
Sep 20, 2010
Messages
4,324
Trophies
2
Age
40
Location
Engine Room with Cyan, watching him learn.
XP
2,256
What's interesting is the name on some of the files in the exploit are similar to NWPlayer, who first-replied under GaryOPA's announcement thread on Maxconsole. He didn't sound happy. :P

I don't think this leak is the end-of-the-world since people can just stay put on the vulnerable firmware, but ticked off devs are never a good thing.

Edit: Speak of the devil. :ninja:
 

NWPlayer123

Well-Known Member
Member
Joined
Feb 17, 2012
Messages
2,642
Trophies
0
Location
The Everfree Forest
XP
6,693
Country
United States
It's old webkit. Finding another exploit isn't an issue. The real issue would be if nintendo tightened the browser's permissions.

Also what's this about no code execution? This package clearly is able to do ROP stuff. If that's not code execution, I'm not entirely sure what is.

The addresses moved/the code changed, so the ROP chain broke from 4.1.0 to 5.0.0.
 

Goku Junior

Well-Known Member
Member
Joined
Dec 27, 2013
Messages
951
Trophies
0
Age
23
Location
Buenos Aires, Argentina
XP
482
Country
Argentina
No need, we've already done so. Doesn't work. Like we've said many times, the bug is still there (though in future updates it won't be because some idiot decided to leak an unfinished exploit for nintendo to patch), but we have no code execution.

Yes I know it won't work but I'm a veru curiosity person, I like to test some things, and I want to see what kind of error code shows up, it is a stupid thing, I know. And yes, I don't know what stupid person did that, but I WON'T UPDATE ANYMORE! I'll stay in 5.0 from now to the end!, I'm not scared about 5.0 because I trust Marionumber1 so I belive him and the others sceners working in this exploit, thanks for all!

EDIT:Code execution... I didn't read that, so it is useless because it can't launch nothing now... right?
 

markehmus

Well-Known Member
Member
Joined
Jul 26, 2008
Messages
1,521
Trophies
0
Age
112
Location
in the GAME
XP
1,279
Country
Canada
No need, we've already done so. Doesn't work. Like we've said many times, the bug is still there (though in future updates it won't be because some idiot decided to leak an unfinished exploit for nintendo to patch), but we have no code execution.


love your 1st and only post on max
 
D

Deleted User

Guest
It's old webkit. Finding another exploit isn't an issue. The real issue would be if nintendo tightened the browser's permissions.

As a developer, it isn't fun having your work released unfinished and untested (See PS3 CFW) and having an exploit closed before future fimrwares can take advantage of it. Just look at the exploit itself. The idea is to have a way in so you can document the entire system and find further vulnerabilities. Now 5.0 will be the last hackable firmware you can take advantage of. Even if it's as easy as "Old webkit", I doubt any dev would be willing to put forth the effort after this.
 

WulfyStylez

SALT/Bemani Princess
Member
Joined
Nov 3, 2013
Messages
1,149
Trophies
0
XP
2,867
Country
United States
As a developer, it isn't fun having your work released unfinished and untested (See PS3 CFW) and having an exploit closed before future fimrwares can take advantage of it. Just look at the exploit itself. The idea is to have a way in so you can document the entire system and find further vulnerabilities. Now 5.0 will be the last hackable firmware you can take advantage of. Even if it's as easy as "Old webkit", I doubt any dev would be willing to put forth the effort after this.
One leak isn't going to singlehandedly slaughter the scene like you seem to think it will.

Anyways, anyone try this yet? You should just be able to host a local server and browse to index.html. Opens an RPC on 192.168.1.4, but you can change that in socket.h. Should also throw logs somewhere.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    K3Nv2 @ K3Nv2: Like for micro