Homebrew [33c3] Console Hacking 2016 (3DS/WiiU) talk Dec 27-30: smea, derrek, nedwill, naehrwert

What will Santa Hax bring us this year?

  • Slowhax (arm11 kernelhax)

    Votes: 184 32.1%
  • Soundhax (free primary userland sploit)

    Votes: 183 31.9%
  • Bootrom dump method !!

    Votes: 166 28.9%
  • Something more awesome than the above.

    Votes: 156 27.2%
  • Something nice for the WiiU

    Votes: 178 31.0%
  • Nothing. Ninty will banhammer: 001-1337 "Your use of this speech has been restricted by Nintendo"

    Votes: 80 13.9%
  • This checkbox pleases me

    Votes: 152 26.5%
  • ( ͡° ͜ʖ ͡°)

    Votes: 92 16.0%

  • Total voters
    574
  • Poll closed .

CeeDee

fuckin dork
Member
Joined
May 4, 2014
Messages
5,360
Trophies
3
XP
9,937
Country
United States
Also, for any new console you would buy, you only need to gain access to NAND. Either through nand mod or DSiWare hax/Arm11 kernel exploit to install dsiware hax so that you can plaintext attack the FIRM section and replace it with your "custom" FIRM. Game over. Nintendo can't stop this unless they can completely block plaintext attack. (which would be difficult to do)
Am I right in understanding that through the shown off soundhax + fasthax, we get arm11 kernel, therefore allowing us to install custom FIRM and such on latest FW?
 

Gnarmagon

Noob <3
Member
Joined
Dec 12, 2016
Messages
647
Trophies
0
Age
22
XP
794
Country
Germany

JerryX

Active Member
Newcomer
Joined
Dec 13, 2008
Messages
38
Trophies
1
XP
384
Country
United States
A minor thing I wanna ask: could it now be possible to give the 3DS the ability to launch certain flashcarts without TWL Slot 1 Launcher?
 

Apache Thunder

I have cameras in your head!
Member
Joined
Oct 7, 2007
Messages
4,433
Trophies
3
Age
36
Location
Levelland, Texas
Website
www.mariopc.co.nr
XP
6,806
Country
United States
Am I right in understanding that through the shown off soundhax + fasthax, we get arm11 kernel, therefore allowing us to install custom FIRM and such on latest FW?

Yes. I recall there was a method to install a DSiWare exploit save via Arm11. You would need to buy a DSiWare game. Sudoku is still on eShop. You can buy that game and use arm11 exploit/nand mod to replace it with older exploitable version of Sudoku. I don't know the details though so I could be wrong here. :P
 

Mrrraou

Well-Known Member
Member
Joined
Oct 17, 2015
Messages
1,873
Trophies
0
XP
2,374
Country
France
all the wii u hax were kinda to be expected and pretty fun actually, but there's so much to say about the wii u that i'm kinda disappointed that they didn't disclose any vuln in the boot procedure besides haxchi/contenthax stuff

soundhax is cool and i like it
fasthax is smart but complicated
the bootrom dumping method was known (3dbrew) and no one exploited it tho but still pretty cool to see these guys making it work and explaining it in more detail
sighax is fun and lovely
no p9 exploit tho? :P

anyway it was pretty nice and interesting, thanks and gj to the guys :)
 

shinyquagsire23

SALT/Sm4sh Leak Guy
Member
Joined
Nov 18, 2012
Messages
1,977
Trophies
2
Age
26
Location
Las Vegas
XP
3,765
Country
United States
all the wii u hax were kinda to be expected and pretty fun actually, but there's so much to say about the wii u that i'm kinda disappointed that they didn't disclose any vuln in the boot procedure besides haxchi/contenthax stuff

soundhax is cool and i like it
fasthax is smart but complicated
the bootrom dumping method was known (3dbrew) and no one exploited it tho but still pretty cool to see these guys making it work and explaining it in more detail
sighax is fun and lovely
no p9 exploit tho? :P

anyway it was pretty nice and interesting, thanks and gj to the guys :)
Also gotta love "you also have to exploit a userland process but we're not talking about that." Still better than "we did a thing and got ROP" but eh, idk.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    K3Nv2 @ K3Nv2: Cool mgs4 can finally play at 35fps on it