I know this thread is more oriented towards flashcart hard-modding, but I do have a bit of input relating to soft-modding. Maybe TheHomesk1llet will appreciate it, seeing as how he favors soft-modding, as I do.
Smea and I talked when he first released his Ninjhax Write-Up. I said that it would be nice to use a GPU DMA hack to gain control of spider/SKATER (browser) for some sort of code execution, but it seemed their .text was out of range. He then told me that you should be able to use 'spiderhax' with 'rohax' to gain complete code execution through ROP. For reference, look at his stage three and four found here. Knowing that spider/SKATER has very limited RAM privilege, it would be rather pointless to take control of this for the use of homebrew. I'd imagine it would be okay for some simple apps, but definitely not any sort of emulator or game. Later, he suggested using an spider/SKATER to gain access to an application. If you look at your handheld's home menu, you will see two things: Applets and applications. Your applets are the small icons located at the top, and your applications are the larger icons on your grid. The handheld supports a fully functional multi-layered OS, meaning you can run one applet and one application at the same time. His suggestion was to use spider/SKATER to take control over Mii Plaza by opening Mii Plaza, returning home while it runs in the background, and opening your browser to execute the hack. This, of course, brings us a downside the that an internet connection must be present each time you'd like to access your homebrew menu. While it is a working solution, it is not the best we can use. We need an application that can store our homebrew menu in a convenient way. With that in mind, the only application I can think of fit for the job is Download Play. Download Play stores a .CIA grabbed from another device until another .CIA is introduced. My theory, crazy as it seems, it to use spider/SKATER to hijack Download Play as a 'base of operations' for our homebrew menu. Seeing as how it stores the .CIA until reintroduced, it should allow us to install once with a connection, and not have to worry any longer. Smea states that other applications may be able to do the same. Don't get your panties in a twist and froth at the mouth just yet, because Nintendo had to give us the ol' one-two and rain on our parade. In order for this to work, as Smea says, we'd need properly signed NCCHs and properly signed corresponding tickets dumped specifically for our device. This is where I think the conversation got a bit fuzzy, because he began going on about installing certain parts of new updates, and some stuff about the eShop checking things, so I feel he may have thought my target was different than it was. The only way we can test this, is to, well, try. I have given you all of the information I have, and my idea to follow. I would test this myself, but my time is limited, and it would be pointless for me to work on this with the little time and experience I have. I hope I helped in some way, at least.
Smea and I talked when he first released his Ninjhax Write-Up. I said that it would be nice to use a GPU DMA hack to gain control of spider/SKATER (browser) for some sort of code execution, but it seemed their .text was out of range. He then told me that you should be able to use 'spiderhax' with 'rohax' to gain complete code execution through ROP. For reference, look at his stage three and four found here. Knowing that spider/SKATER has very limited RAM privilege, it would be rather pointless to take control of this for the use of homebrew. I'd imagine it would be okay for some simple apps, but definitely not any sort of emulator or game. Later, he suggested using an spider/SKATER to gain access to an application. If you look at your handheld's home menu, you will see two things: Applets and applications. Your applets are the small icons located at the top, and your applications are the larger icons on your grid. The handheld supports a fully functional multi-layered OS, meaning you can run one applet and one application at the same time. His suggestion was to use spider/SKATER to take control over Mii Plaza by opening Mii Plaza, returning home while it runs in the background, and opening your browser to execute the hack. This, of course, brings us a downside the that an internet connection must be present each time you'd like to access your homebrew menu. While it is a working solution, it is not the best we can use. We need an application that can store our homebrew menu in a convenient way. With that in mind, the only application I can think of fit for the job is Download Play. Download Play stores a .CIA grabbed from another device until another .CIA is introduced. My theory, crazy as it seems, it to use spider/SKATER to hijack Download Play as a 'base of operations' for our homebrew menu. Seeing as how it stores the .CIA until reintroduced, it should allow us to install once with a connection, and not have to worry any longer. Smea states that other applications may be able to do the same. Don't get your panties in a twist and froth at the mouth just yet, because Nintendo had to give us the ol' one-two and rain on our parade. In order for this to work, as Smea says, we'd need properly signed NCCHs and properly signed corresponding tickets dumped specifically for our device. This is where I think the conversation got a bit fuzzy, because he began going on about installing certain parts of new updates, and some stuff about the eShop checking things, so I feel he may have thought my target was different than it was. The only way we can test this, is to, well, try. I have given you all of the information I have, and my idea to follow. I would test this myself, but my time is limited, and it would be pointless for me to work on this with the little time and experience I have. I hope I helped in some way, at least.







