Homebrew RAM editing glitch on any 3DS, might lead to an exploit?

  • Thread starter Thread starter Trinitro21
  • Start date Start date
  • Views Views 56,660
  • Replies Replies 445
  • Likes Likes 34
I think we can acess arbitrary ram well outside what.this glitch directly allows. What if you change a variable pointer to ram outside the area 0x087E8CECto 0x0CAF8D20 in process 0x29? Arbitrarily writing any data anywhere in rw data is extremely powerful and I think should almost always be able to lead to rop.
 
20160630_193609-640x360.jpg
I have a EUR N3DS on Luma3DS with A9HL on latest firmware running smileBASIC 3.3.1 and it doesn't work. All I get is ok afterwards and that's it

Edit:

Here is a photo
 
Last edited by MartinDocNewland,
I have a EUR N3DS on Luma3DS with A9HL on latest firmware running smileBASIC 3.3.1 and it doesn't work. All I get is ok afterwards and that's it

Edit:

Here is a photo
It did work, but you can't see what it did because you didn't offset the layer.
Try these inputs:
Code:
XSCREEN 2
BGSCREEN 0,134217728,16
BGOFS 0,6400*16,0
That sets the screen up, sets the glitch up, and then shows you an interesting bit. You can try other offsets in the third command if you want to explore.
 
  • Like
Reactions: MartinDocNewland
It did work, but you can't see what it did because you didn't offset the layer.
Try these inputs:
Code:
XSCREEN 2
BGSCREEN 0,134217728,16
BGOFS 0,6400*16,0
That sets the screen up, sets the glitch up, and then shows you an interesting bit. You can try other offsets in the third command if you want to explore.
Definitely look promising.
 

Site & Scene News

Popular threads in this forum