TL;DR Summary of Talk:
- Soundhax - Excellent, convenient, and free userland primary that hacks the built in sound application with just an MP3 on the sd card. Will be released soon according to nedwill.
- Fasthax - New arm11 kernel expoit (like memchunkhax, waithax, etc.) also by nedwill. Works on latest firm and should be released soon just like Soundhax. Should allow nfirm downgrading on latest firm when more advanced dsiware injection techniques are released very soon.
- Method to dump arm9 bootrom detailed by derrek. Hash given as proof. The same technique has been worked on for months already by #Cakey devs, so this will likely take quite a bit more time for a public dump to show up. One benefit of bootrom dumping is faster PC based crypto stuff instead of slow 3ds methods. The second benefit is the next exploit:
- Sighax - The big one. Flaw discovered in the bootrom's RSA parsing process of the 3ds's firmware partition. This will allow us to sign our own custom firm and no more having to do risky downgrades and 100 step guides to get the OTP. Unfortunately, we need a bootrom dump to implement this and that is an issue, see above bullet point for why. You will also still need a way to actually write to system NAND, and even k11 hax usually isn't enough for that. Hardmod is also an option, but it's expensive and inconvenient. That should always be an option, at least, given sighax itself is unpatchable without hardware revision.
- Method to dump arm11 bootrom and hash of it given by derrek. This isn't considered important.
(skip yt video ahead to 20:00 for 3ds part of the speech - full talk at link below)
https://media.ccc.de/v/33c3-8344-nintendo_hacking_2016
https://media.ccc.de/v/33c3-8344-nintendo_hacking_2016
Last year, this very event produced groundbreaking new 3ds hacks such as arm9loaderhax and memchunkhax2 that really shook up the scene. What will happen this year?
Looks like our 32c3 friend derrek will return, but this time tagging along will be fresh new talent nedwill and Nintendo/Sony scene veteran naehrwert. Gonna be big, so stay tuned!
Day: 2016-12-27Looks like our 32c3 friend derrek will return, but this time tagging along will be fresh new talent nedwill and Nintendo/Sony scene veteran naehrwert. Gonna be big, so stay tuned!
Start time: 20:30 (German time)
Duration: 01:00
Room: Saal 2
Track: Security
Language: en
lecture: Nintendo Hacking 2016
Game Over
Duration: 01:00
Room: Saal 2
Track: Security
Language: en
lecture: Nintendo Hacking 2016
Game Over
This talk will give a unique insight of what happens when consoles have been hacked already, but not all secrets are busted yet. This time we will not only focus on the Nintendo 3DS but also on the Wii U, talking about our experiences wrapping up the end of an era. We will show how we managed to exploit them in novel ways and discuss why we think that Nintendo has lost the game.
As Nintendo's latest game consoles, the 3DS and Wii U were built with security in mind.
While both have since been the targets of many successful attacks, certain aspects have so far remained uncompromised, including critical hardware secrets.
During this talk, we will present our latest research, which includes exploits for achieving persistent code execution capabilities and the extraction of secrets from both Wii U and 3DS.
Basic knowledge of embedded systems, CPU architectures and cryptography is recommended, though we will do our best to make this talk accessible and enjoyable to all. We also recommend watching the recording of last year's C3 talk called "Console Hacking - Breaking the 3DS".
Courtesy of Julian20
Update6: Jan. 09 - WiiU Summary point removed. Nobody cares.
Update5: Dec. 27 - Youtube recording posted, thanks @Sasori
Update5: Dec. 27 - Event complete
Update4: Dec. 27 - Smealum sighting
Update3: Dec. 26 - Countdown added courtesy of@gnmmarechal
Update2: Dec. 22 - Video links added.
Update1: Dec. 17 - 33c3 Bingo courtesy of @Suiginou
Update0: Dec. 15 - Event date/time and other details.
Source
Update5: Dec. 27 - Youtube recording posted, thanks @Sasori
Update5: Dec. 27 - Event complete
Update4: Dec. 27 - Smealum sighting
Update3: Dec. 26 - Countdown added courtesy of@gnmmarechal
Update2: Dec. 22 - Video links added.
Update1: Dec. 17 - 33c3 Bingo courtesy of @Suiginou
Update0: Dec. 15 - Event date/time and other details.
Source
Last edited by zoogie,