Hacking 3ds download play hax possible?

PabloMK7

Red Yoshi! ^ω^
Developer
Joined
Feb 21, 2014
Messages
2,604
Trophies
2
Age
24
Location
Yoshi's Island
XP
5,025
Country
Spain
I don't think using too many objects or polys in MK7 will make an exploit possible, however, MK7 tracks have yaz0 and sarc compressed. If MK7 doesn't check for the decompressed size of the file, then a buffer overflow exploit may be possible. For some reason, MK7 programmers decided to send tracks from the main cxi instead of putting them into the dlp cia, but that may also mean they had put extra effort into preventing silly exploits.

--------------------- MERGED ---------------------------

If we can do it within the browser, we can most likely do it through Download Play.
As mentioned before, any executable data has to be signed in order to be executed, sending a payload will only make the client 3ds to prompt an error.
 
Last edited by PabloMK7,

RosalinaFan573

Well-Known Member
OP
Newcomer
Joined
Jan 27, 2016
Messages
97
Trophies
0
Age
21
XP
301
Country
United States
I don't think using too many objects or polys in MK7 will make an exploit possible, however, MK7 tracks have yaz0 and sarc compressed. If MK7 doesn't check for the decompressed size of the file, then a buffer overflow exploit may be possible. For some reason, MK7 programmers decided to send tracks from the main cxi instead of putting them into the dlp cia, but that may also mean they had put extra effort into preventing silly exploits.
You actually make a good point. But since MK7 is actually an early 3DS game Nintendo probably didn't do anything to prevent exploits since *hax didn't exist yet. How could we inject desync code...?

Would there be a possible Triforce Heroes sploit through the multiplayer mode? Since it's been done with SSB3DS it's most likely possible...
 

Lotoonlink

Probably doesn't know what he's talking about
Member
Joined
Aug 15, 2016
Messages
242
Trophies
0
XP
1,252
Country
United States
Hey guys... I may look like a total noob right now, and I get it: you can't download play unsigned games... but... what about sighax (please don't flame me if I get this wrong just explain it simply...) since we could sign our own cias and cfw and whatnot using sighax, couldnt we sign some kind of data that we made to downgrade then send it over through downloadplay? The target 3ds would recgonize it as a legit piece of software and accept it right? Just my two cents, although probably wrong.
 

PabloMK7

Red Yoshi! ^ω^
Developer
Joined
Feb 21, 2014
Messages
2,604
Trophies
2
Age
24
Location
Yoshi's Island
XP
5,025
Country
Spain
Hey guys... I may look like a total noob right now, and I get it: you can't download play unsigned games... but... what about sighax (please don't flame me if I get this wrong just explain it simply...) since we could sign our own cias and cfw and whatnot using sighax, couldnt we sign some kind of data that we made to downgrade then send it over through downloadplay? The target 3ds would recgonize it as a legit piece of software and accept it right? Just my two cents, although probably wrong.
Sighax only works with bootroms :P
Also, the same downgrade problem is applied here. You can't install older versions of the titles already installed.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    Veho @ Veho: The cybertruck is a death trap.