Hacking ROP from within IOS_USB (5.5.1)

kingraa777

boom!
Member
Joined
Apr 17, 2015
Messages
1,241
Trophies
0
Age
40
XP
905
Country
This is an implementation of ROP getting userland code execution on the IOSU processor, which you can then use to run code in IOSU userland to exploit it's kernel

excuse me if im being stupid but couldn't you theoretically boot into a cfw or shell or similar from user-land this way ? from a hbl elf ->iosu code executed user-land exacuted kernal cfw ? there's something i'm trying to get at similar to how the 3ds uses rop maybe sorry for my vague description :)
 

Swiftloke

Hwaaaa!
Member
Joined
Jan 26, 2015
Messages
1,772
Trophies
1
Location
Nowhere
XP
1,506
Country
United States
excuse me if im being stupid but couldn't you theoretically boot into a cfw or shell or similar from user-land this way ? from a hbl elf ->iosu code executed user-land exacuted kernal cfw ? there's something i'm trying to get at similar to how the 3ds uses rop maybe sorry for my vague description :)
Keep in mind this is to my knowledge. Please Understand.
ROP, or Return Oriented Programming, is a technique used to get around modern ARM processors eXecute Never (XN) bit for memory, which means the processor will never execute it, meaning you can't just write code wherever in memory (usually areas with XN are areas that initial exploits have access to, like save data) and expect the processor to execute it. Instead, what we do is call instructions that already exist in memory to build up further exploits. For example, this ROP calls instructions in IOSU userland that reboot the console. From here, what we need to do is find instructions and use them to set up the IOSU kernel exploit and have full console control. (No, IOSU userland which is what this runs in doesn't have enough control to boot a CFW)
 
Last edited by Swiftloke,

KiiWii

Editorial Team
Editorial Team
Joined
Nov 17, 2008
Messages
16,653
Trophies
3
Website
defaultdnb.github.io
XP
27,127
Country
United Kingdom

Attachments

  • image.png
    image.png
    5.3 KB · Views: 529

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • Veho @ Veho:
    Nah, a hit gives them mad meth powers, but makes them more difficult to control.
    +1
  • Veho @ Veho:
    Before a hit they're like zombies, persistent but slow.
    +1
  • Veho @ Veho:
    It's a tradeoff.
    +1
  • The Real Jdbye @ The Real Jdbye:
    no i mean, before a hit is after the previous hit
    +1
  • The Real Jdbye @ The Real Jdbye:
    if you keep them well enough fed, it's the same thing
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    By the power of Florida Man, I have the power!!! *Lifts up meth pipe* Meth Man!!! lol
  • BakerMan @ BakerMan:
    Guys, I just learned my little brother is in the hospital because he had a seizure last night.
  • cearp @ cearp:
    Sorry to hear that BakerMan
    +2
  • BakerMan @ BakerMan:
    Just found out he's doing alright, doing a lot of complaining too, rightfully so. Who wouldn't complain after having a seizure and being hospitalized?
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Glad he is OK and complaining is cool :)
    +1
  • K3Nv2 @ K3Nv2:
    Yeah been there had that no fun
    +1
  • K3Nv2 @ K3Nv2:
    They'll give him sleep studies eegs and possibly one week hospital stay
    +1
  • BakerMan @ BakerMan:
    I hope it's not a week.
  • K3Nv2 @ K3Nv2:
    It's standard so doctors can get a idea about what's going on
  • BakerMan @ BakerMan:
    understood
  • BakerMan @ BakerMan:
    well, i'm glad he seems to be doing fine, and ig i'm going to start spewing goofy shit again
  • BakerMan @ BakerMan:
    Update: Turns out he's epileptic
  • K3Nv2 @ K3Nv2:
    Get a 2nd opinion run mris etc they told me that also
  • Psionic Roshambo @ Psionic Roshambo:
    Also a food allergy study would be a good idea
  • K3Nv2 @ K3Nv2:
    Turns out you can't sprinkle methamphetamine on McDonald's French fries
    +1
  • ZeroT21 @ ZeroT21:
    they wouldn't be called french fries at that point
    +1
  • ZeroT21 @ ZeroT21:
    Probably just meth fries
    +1
  • K3Nv2 @ K3Nv2:
    White fries hold up
    +1
    K3Nv2 @ K3Nv2: White fries hold up +1