Hacking GO Exploit

ernilos

Well-Known Member
OP
Member
Joined
Aug 28, 2013
Messages
145
Trophies
0
Location
CAT
XP
280
Country
United States
The other thread is getting fulled with stuff like "halp me plz, it don't works", so I thought on create another thread to talk about the GO exploit...
Going to the website with no 3DS webAgent you get what the memory block is fulled with "counter+4 08 0E" (http://gyazo.com/77fb2460da8543a36e8ebed1d4f30037), when you activate the 3DS UserAgent you get the exploit. Seems the *exploit* is copying a lot of times 0x200 bytes to memory, making overflow or something and then run the *second stage*.
At first look it seems to be a ROPLoader (like on MSetHax). Here we can see "dmc:/Launcher.dat" coded on UTF-16, so this ROPLoader isn't obfuscated, well. A good way to continue studying how it works is getting a RAM dump with browser applet open, it should be easy with the released CFW.
Hope we can get Kernel Execution on FW 4.0-9.2

PD: There's some paste with title "GW_GO_Exploit.bin" with download link of the exploit binary
 

Kylecito

eats warnings for breakfast
Member
Joined
May 6, 2009
Messages
356
Trophies
0
XP
874
Country
Cote d'Ivoire
well why not trying to launch the ninjhax launcher with it, instead of launcher.dat?
Just an idea.


Not the same ROP chain, I doubt it.

Has anyone tried to copy the site as-is to a local folder, set up a web server and run it locally? Having to rely on an Internet connection might be a risky business
 

Zidapi

Well-Known Member
Member
Joined
Dec 1, 2002
Messages
3,112
Trophies
3
Age
42
Website
Visit site
XP
2,681
Country
It looks like the "GO Exploit" is the Swebug exploit that the enigmatic MathewE documented on this pastebin in early December, as it mentions the 0x200 bytes in the notes.

The Swebug 3DS bug
Code:
Bug found: 12/6/14 9:24 PM
Posted: 12/8/14 12:36 AM
Updated: 12/8/2014 7:32 PM

Bug tested on:
-New 3DS 9.2.0-20J
-2DS 9.0.0-20E
-3DS 4.5.0-4U
--EmuNAND 9.2.0-20U
-3DS 5.0.0-11E
-3DS 6.3.0-12J
-3DS 9.1.0-20J
-3DS XL 9.0.0-20U
--EmuNAND 9.2.0-20U
-3DS XL 9.2.0-20U
-Dev 3DS (2)
-New 3DS 9.0.0-20E
-New 3DS 9.3.0-21J

Bug worked:
-New 3DS 9.2.0-20J
-New 3DS 9.0.0-20E
-New 3DS 9.3.0-21J

Bug location:
Internet Browser
Repeating CTR Savegame

"boot.12.8.14.zip" MD5: CE CE F5 8B 99 47 C5 61 DA 52 44 D3 72 3D 85 39
"revision.12.8.14.zip" MD5: 23 CE 1B 24 4E 56 E7 0C 9D A8 17 31 F4 5F 24 00

Contents:
"webkit_root.zip" webkit bug
"savetest_multi.zip" pre-written savegame bug (AQNx) (ACVx)
"savecreate_root.zip" savegame bug
"extdata_root.zip" savegame bug for extdata
"hellow_world.khb" test homebrew

The notes
Code:
savegame bug:
rop:
set 0x00 as start instead of 0x2000
0x00000100
0x00000010
0x00004120
0x00000200
0x0000FF20
0x01111110 
0x00001210
0x00000100
0x0023A010
0x0023A010
0x00000100
0x0000FF20
0x0023A010
0x0B1BCE90
0x0000FF20
0x0000FF20
0x0023A010
0x0000A1B0
0x0000A1B0
0x0000A1B0
0x0000A1B0
0x0000A1B0
0x0000A1B0
0x00000100
0x0023A010
0x0023A010
0x0023A010
0x00000100
0x00000100
0x0BIBCE90
0x00000100
0x0A121730 
0x0000FCF0
0x0000FCF0
0x0000FCF0
0x0A121730 
0x0A121730 
0x0A121730 
0x00000100
0x00004120
0x00004120
0x00004120
0x00004120
jump to internetBrowser

webkit bug:
localhost.***/savegame/gameID/1112/bug.html
FF FF FF FF 01 22 00 20
byte 4
FF^0x1
0xF(G)/FF 01/(02)
(0x0102 02 01)
 

hias

Active Member
Newcomer
Joined
Jun 16, 2014
Messages
32
Trophies
0
Age
44
XP
132
Country
Argentina
Nice work. If this is not more than you found that means we can mirror Gateways files on a local webserver and can start the launcher even when Gateway Go is down?
Or is there still a payload that gets downloaded on boot?

Would be nice if you could try this, thanks :)
 
  • Like
Reactions: Margen67

Dr Eggman

I am THE Eggman.
Member
Joined
Jul 12, 2008
Messages
230
Trophies
1
Location
Eggmanland! (Toronto IRL)
Website
facebook.com
XP
716
Country
Canada
It looks like the "GO Exploit" is the Swebug exploit that the enigmatic MathewE documented on this pastebin in early December, as it mentions the 0x200 bytes in the notes.
-snip-


How did this go unnoticed??

Hopefully the ROP chain is friendly so we can get homebrew up and running ASAP :)

[user]ernilos[/user] what CFW are you talking about for this RAM dumping?
 
  • Like
Reactions: Margen67

Vappy

Well-Known Member
Member
Joined
May 23, 2012
Messages
1,508
Trophies
2
XP
2,613
Country
It'd been mentioned prior to that, by piratesephiroth and a few other people, but it kind of went unnoticed or just forgotten about because no one knew who MathewE was, or how to get in contact with him. And it's almost certain he won't be publicly releasing his work either way. :P
 

PewnyPL

Well-Known Member
Member
Joined
Feb 2, 2014
Messages
771
Trophies
1
XP
2,207
Country
Poland
So, as this exploit launches Launcher.dat from SD card... does anyone know if Gateway's exploit could be used to load Homebrew? Anyone tried?
 
  • Like
Reactions: Margen67

PewnyPL

Well-Known Member
Member
Joined
Feb 2, 2014
Messages
771
Trophies
1
XP
2,207
Country
Poland
You'd need to reverse the Launcher.dat to find the exploit it uses. Without that, you're limited to basic ROP with the browser.

But is the ROP chain of the bowser identical to MSET ROP chain? Or even more limited (as in, the actual exploit to launch unsigned code is in Launcher.dat this time)
 

Vappy

Well-Known Member
Member
Joined
May 23, 2012
Messages
1,508
Trophies
2
XP
2,613
Country
But is the ROP chain of the bowser identical to MSET ROP chain? Or even more limited (as in, the actual exploit to launch unsigned code is in Launcher.dat this time)
Functionally similar, if not identical, both confined to usermode ROP, no arbitrary execution.
but not with pure 100% nand access
No real ARM9 access either, I believe, which is why there was never a .3ds or .cia of the decryptor homebrews.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • SylverReZ @ SylverReZ:
    Why not they just mine Monero instead of scamming vulnerable people? If they have a decent machine they can hit a jackpot at any given time.
    +1
  • SylverReZ @ SylverReZ:
    Bitcoin on the other hand, requires a very powerful mining rig and is more costly.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, different cultures so probably they have their reasons
  • K3Nv2 @ K3Nv2:
    Yes a $2,000 rig for $5 a day
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Or could be in correlation to laws.
    +1
  • SylverReZ @ SylverReZ:
    Technically, cryptocurrencies aren't illegal, as long as you don't use it for criminal activity. If you sign up with an exchange, and that they get a tip from law enforcement, they have the right to freeze your assets.
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, Yea I heard law is vastly different there
  • SylverReZ @ SylverReZ:
    Nigeria's central bank did make crypto illegal before, until last year they lifted the ban. Always make sure to check before you exchange. ;)
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, speaking of crypto i remember reading about a guy who spend like 10 grand bitcoin on a couple pizzas (when bitcoin wasnt as worthy as nowadays)
  • SylverReZ @ SylverReZ:
    @Xdqwerty, That's mental. If he had saved up when Bitcoin sky-rocketed in price, then he might've become the next Jeff Bezos for all I know.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, he couldnt know the price was gonna skyrocket anyway
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Then it dropped sometime in 2022, 2021 was when it really went up in price.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, I also recall watching a video of some failed games with their own crypto currency or smth like that, lemme link it to you (it's in spanish tho)
  • SylverReZ @ SylverReZ:
    @Xdqwerty, I remember that. Didn't Steam ban games with NFTs before somehow devs managed to circumvent it? Think EA tried to dabble in NFTs too.
  • SylverReZ @ SylverReZ:
    Glad to hear people realise that NFTs aren't worth it these days. They realise that they're JPEGs hosted on a file-hosting site like AWS or Google Drive.
  • Xdqwerty @ Xdqwerty:
    Atleast it has captions
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Meta also tried to create their own crypto, but that fell through.
  • SylverReZ @ SylverReZ:
    Was called Libra, they had around 100 employees and wanted to hire more near to end of the year.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, idk why facebook tried to do that metaverse thing if mmo games already existed before
  • Xdqwerty @ Xdqwerty:
    And Yea I refuse to call it meta
  • SylverReZ @ SylverReZ:
    @Xdqwerty, I refuse to call it Meta, too. It's a stupid name.
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, then why did you call it like that a minute ago?
  • SylverReZ @ SylverReZ:
    I don't get why Facebook ever wanted to dabble into virtual reality, when other companies were doing it.
    +1
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Just to emphasize on what I mean.
    +1
    SylverReZ @ SylverReZ: @Xdqwerty, Just to emphasize on what I mean. +1