Hacker finds a way to write Javascript on the Nintendo Switch

Deleted member 546149

Well-Known Member
OP
Member
Joined
Dec 18, 2020
Messages
2,000
Trophies
2
XP
6,972
nintendo-switch.900x.jpg
A hacker referred to as Connor has found a possible exploit revealed in his Pwinstry blog that he found a bug in the screenshot transfer feature. The bug allows for any javascript code to be written on the switch, which can lead to a possible exploit. Although, he has agreed with Nintendo to not publically share the code of the exploit. According to Game4Check, Nintendo is working to patch the bug. Connor has stated that unsigned code couldn't knowingly be written but it can still lead to a possible exploit
:arrow:https://www.game4check.com/2021/05/...a-javascript-exploit-but-dont-worry-too-much/
 
Last edited by Deleted member 546149,

NoNAND

Give me back my legions!
Member
Joined
Aug 22, 2015
Messages
2,274
Trophies
1
Location
Somewhere
XP
5,064
Country
Albania
nintendo-switch.900x.jpg
A hacker referred to as Connor has found a possible exploit revealed in his Pwinstry blog that he found a bug in the screenshot transfer feature. The bug allows for any javascript code to be written on the switch, which can lead to a possible exploit. Although, he has agreed with Nintendo to not publically share the code of the exploit. According to Game4Check, Nintendo is working to patch the bug. Connor has stated that unsigned code couldn't knowingly be written but it can still lead to a possible exploit
:arrow:https://www.game4check.com/2021/05/...a-javascript-exploit-but-dont-worry-too-much/

Inb4 kernel exploit on patched switches
 

Deleted member 546149

Well-Known Member
OP
Member
Joined
Dec 18, 2020
Messages
2,000
Trophies
2
XP
6,972
how could it even lead to an exploit?

the name for your switch has only 32 characters, I don't think you can write something crazy with this limitation...
Well, from what I hear, it has to do with a server and qr code program, but it probably can't lead to much.
I wanna see what @SciresM says before jumping to conclusions
 
  • Like
Reactions: apaltado

Deleted member 514389

GBA Connoisseur
Member
Joined
Dec 24, 2019
Messages
510
Trophies
0
Location
the toolshed
Website
f.ls
XP
753
Country
Germany
Since when have hackers become such pu** in the boots anyways ?

White Hat. Yeah right.

At one point it'll turn into the apple-esque:
"Forget your perma exploits, we -the hackers'd rather sell our exploits.."


You could release it, then tell Ninty.
(They'll patch it anyways)
That way both parties have something.

If it allows someone to program without an expensive devkit that't work double in nintys favor anyways...
 

Deleted member 546149

Well-Known Member
OP
Member
Joined
Dec 18, 2020
Messages
2,000
Trophies
2
XP
6,972
Since when have hackers become such pu** in the boots anyways ?

White Hat. Yeah right.

At one point it'll turn into the apple-esque:
"Forget your perma exploits, we -the hackers'd rather sell our exploits.."


You could release it, then tell Ninty.
(They'll patch it anyways)
That way both parties have something.

If it allows someone to program without an expensive devkit that't work double in nintys favor anyways...
It seems like this hacker just believes in open source projects
 

Deleted member 546149

Well-Known Member
OP
Member
Joined
Dec 18, 2020
Messages
2,000
Trophies
2
XP
6,972
@Prans is this front page worthy or not?
Haha I can see it now, @WiiMiiSwitch future GBAtemp news reporter, where @WiiMiiSwitch started his time on the forum hating/holding grudges against staffs become a staff.
I don't have any grudges or hate to the staff, just some respectful disagreements

--------------------- MERGED ---------------------------

Polly has found his new role in life from polls to rap to news reporter. This is one role I won't bitch about :rofl2:
Polly has found his new role in life from polls to rap to news reporter. This is one role I won't bitch about :rofl2:
Rapping was for that one dude who locked me in a cage. The polls are on another secret website that I can't spill the beans about because YOU GOT ME BANNED FROM DIGITALWORLDZ!!!!
 

Deleted member 668561

GBAtemp Official Psychonaut
Banned
Joined
Jan 29, 2008
Messages
1,875
Trophies
0
Location
somewhere within 4 dimensional space-time
XP
2,654
Country
United States
how could it even lead to an exploit?

the name for your switch has only 32 characters, I don't think you can write something crazy with this limitation...

Buffer overflow, rop chain

That's how the 3ds mset pretty much worked, not one exploit but a chain of different exploits

--------------------- MERGED ---------------------------

Since when have hackers become such pu** in the boots anyways ?

White Hat. Yeah right.

At one point it'll turn into the apple-esque:
"Forget your perma exploits, we -the hackers'd rather sell our exploits.."


You could release it, then tell Ninty.
(They'll patch it anyways)
That way both parties have something.

If it allows someone to program without an expensive devkit that't work double in nintys favor anyways...

That's why I'm a greyhat

Pay me Nintendo, it's technically your fuck up, you'll lose more in profit potential then what you'll pay me for it


Also officially, you can't use retail units for development, if you're a Nintendo developer, you can via cfw but it is specifically stated in the development contract, libctr and devkit pro (open source SDK) is not allowed (officially)

3ds and wiiu devkits are cheap, around $1500 or less, compare it to Xbox or sony

For a company or a person with a decent job, this isn't expensive, especially if you're going actually use it to make games to sell, which you will make the $1500 investment back.....
 
Last edited by Deleted member 668561,

Deleted member 668561

GBAtemp Official Psychonaut
Banned
Joined
Jan 29, 2008
Messages
1,875
Trophies
0
Location
somewhere within 4 dimensional space-time
XP
2,654
Country
United States
i really doubt you can achieve that on the switch browser with only 32 characters (also switch has aslr so that won't work unlike the 3ds)

A buffer overflow works by feeding data that's larger than 32 characters, if possible, this hopefully allows you to arbitrarily access memory you're not supposed to, which from there you hopefully can use a rop chain to disable drm

It won't work if the switch does sanity checks on what you're putting in

Also the switch DRM is very similar to what was used on the 360, aslr, memory hashing and encryption, update revocation, and they went partying with efuses


Wonder if an rgh style exploit is possible, via clock or power rail glitching
 
Last edited by Deleted member 668561,
  • Like
Reactions: apaltado

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    K3Nv2 @ K3Nv2: https://youtu.be/IihvJBjUpNE?si=CsvoEbwzNKFf0GAm cool