Hacking Speculations about Switch 2 hacking

  • Thread starter Thread starter KeeperCP1
  • Start date Start date
  • Views Views 304,035
  • Replies Replies 803
  • Likes Likes 10
Correct me if this can be possible: With this vulnerability over the GPU https://gddr.fail/. An attack can start over the userland(WebGTK exploit), and with the exploit take over the gpu and cpu, dump the kernel,keys,etc and start investigatiom to find a more "easy" vulnerability to exploit so the full attack chain will be: WebGTK Userland -> GDDR Rowhammer over the GPU -> CPU takeover-> Kernel dump
 
  • Like
Reactions: Sun_7zu
Correct me if this can be possible: With this vulnerability over the GPU https://gddr.fail/. An attack can start over the userland(WebGTK exploit), and with the exploit take over the gpu and cpu, dump the kernel,keys,etc and start investigatiom to find a more "easy" vulnerability to exploit so the full attack chain will be: WebGTK Userland -> GDDR Rowhammer over the GPU -> CPU takeover-> Kernel dump
Someone with more knowledge of the switch/2 eco system correct me if im wrong but Apparently the switch 2 uses LPDDR5X memory, and like all consoles now it's shared. Does this mean it wont be compatable?
 
Correct me if this can be possible: With this vulnerability over the GPU https://gddr.fail/. An attack can start over the userland(WebGTK exploit), and with the exploit take over the gpu and cpu, dump the kernel,keys,etc and start investigatiom to find a more "easy" vulnerability to exploit so the full attack chain will be: WebGTK Userland -> GDDR Rowhammer over the GPU -> CPU takeover-> Kernel dump
The switch doesn't use webgtk. You can't run any custom code even in the exploited browser user space, so how do you think your can take over the CPU and GPU from just the browser
 
Such a concentration of unawareness makes it difficult to take anything seriously at all. Not knowing is no disgrace, but invoking ordinary technical limitations as absolute reasons for impossibility reflects a failure of understanding rather than a meaningful argument.
 
Why do people want to believe so badly the Switch 2 is unhackable?

Is it because you'd want a hacked Switch 2, and don't want to be disappointed when if it takes a very long time?

Genuinly wondering, what is the point pretending any computer system is unhackable?

Or is the obvious pattern of unhackable devices, that sooner or often, much later, do get hacked really that hard to see?
 
Why do people want to believe so badly the Switch 2 is unhackable?

Is it because you'd want a hacked Switch 2, and don't want to be disappointed when if it takes a very long time?

Genuinly wondering, what is the point pretending any computer system is unhackable?

Or is the obvious pattern of unhackable devices, that sooner or often, much later, do get hacked really that hard to see?
Well, it is unhackable.

Is a hack available? No? Then it is unhackable.
 
Well, it is unhackable.

Is a hack available? No? Then it is unhackable.
That's.... kinda really poor logic.
We didn't notice a hole here, so therefore there isn't any holes, therefore, hole-less.


There's just no known exploits, doesn't mean no exploits.
 
That's.... kinda really poor logic.
We didn't notice a hole here, so therefore there isn't any holes, therefore, hole-less.


There's just no known exploits, doesn't mean no exploits.

This whole thread is pointless. Some people will claim that there might be an exploit, others will say that if there's no proof then there's no exploit, but there might be, but there isn't one right now, but maybe eventually, but... and it just loops back and forth.
 
This whole thread is pointless. Some people will claim that there might be an exploit, others will say that if there's no proof then there's no exploit, but there might be, but there isn't one right now, but maybe eventually, but... and it just loops back and forth.
Then let them loop, you don't have to engage with the thread.
 
  • Like
Reactions: mad_dog
Why do people want to believe so badly the Switch 2 is unhackable?

Is it because you'd want a hacked Switch 2, and don't want to be disappointed when if it takes a very long time?

Genuinly wondering, what is the point pretending any computer system is unhackable?

Or is the obvious pattern of unhackable devices, that sooner or often, much later, do get hacked really that hard to see?
I personally do not care if it is unhackable or not, I simply do not want piracy on the system in the first couple of years at least (although ideally until the console stops being supported).

I do not mind mods or CFW, my Wii, DSi and 3DS were softmodded after the systems stopped being supported, although in my case I mainly I only use them for fan translations for the most part. However I do hate piracy on current systems, especially when it's done in a way that ruins the fun for everyone, namely leaks and spoilers. It was great to play Pokopia without a single leak or anything like it.
 
The switch doesn't use webgtk. You can't run any custom code even in the exploited browser user space, so how do you think your can take over the CPU and GPU from just the browser
Well the first exploit we saw runned arbitrary code in the userland it was not a browser the entry point was the browser. And you only need to make sure that the gpu is used to try hammering the dram and make the bit flips for a cpu take over
 
Well the first exploit we saw runned arbitrary code in the userland it was not a browser the entry point was the browser. And you only need to make sure that the gpu is used to try hammering the dram and make the bit flips for a cpu take over
It was in the browser, and it was not running arbitrary code. It used ROP, and was only calling functions already compiled into the browser applet. There's a reason nothing came of it. We want to be able to map memory as executable, but the browser can only map memory as read-write
 
It was in the browser, and it was not running arbitrary code. It used ROP, and was only calling functions already compiled into the browser applet. There's a reason nothing came of it. We want to be able to map memory as executable, but the browser can only map memory as read-write
Oh thats sad news :(
 
It was in the browser, and it was not running arbitrary code. It used ROP, and was only calling functions already compiled into the browser applet. There's a reason nothing came of it. We want to be able to map memory as executable, but the browser can only map memory as read-write
Do you know how many console exploits have been written completely with ROP?
 

Site & Scene News

Popular threads in this forum