Hacking 5.4.0/5.5.0 MP4 Exploit

Status
Not open for further replies.

Mathew_Wi

bye
OP
Member
Joined
Sep 29, 2009
Messages
233
Trophies
0
XP
1,091
Country
Since it was patched, there's no point in keeping this anymore. R.I.P StageFright.

- Info -
With this you can build (and in theory, run) homebrew for Wii U version 5.4.0 and 5.5.0. It is incredibly bad, and likely won't run any code for you whatsoever. Sounds good right? Yeah? Right on!

- For Developers -
We have been incredibly lazy about fixing this. However, I have a hint for you. Use the code spray code from previous HTML exploits, and embed the MP4 exploit to run code that way.

In template540 and template550, at offset 0x79 to 0x7C contains the value that is in r30 when it crashes, which is an address to a point in the ROP buffer. Essentially leave the rest of the MP4 file unchanged if you plan on doing it via HTML/JS. If you want to use another ROP gadget, then the address that is spammed at the end of the file is the gadget that we initially jump to.

- Download -
http://puu.sh/mt6LQ/45a4ab7ae8.zip (Only builds 5.5.0 payloads, edit generate_mp4.py to generate 5.4.0 payloads.)

- Credits -
zhuowei - Pointing out the bug to Marionumber1 and I.
Marionumber1 - All the fantastic ROP chain work. Plus all around masterful work. Wouldn't have been possible without him.
Mathew_Wi - Shitty initial exploitation/debugging/5.5.0 ROP Gadgets
MrRean - Helping in a way I can't quite remember.
NWPlayer123 - Something!
Hykem - I think he did something too, I can't remember, sue me.
Original Crew - comex, Relys, TheKit, and of course Mr. Chadderz himself.

- Special Thanks -
NWPlayer123 for convincing Marionumber1 to allow me to participate in the group. <3

If I forgot you, feel free to verbally abuse me on IRC or Skype.
 
Last edited by Mathew_Wi,

JohnathanMonkey

Well-Known Member
Member
Joined
Apr 26, 2013
Messages
630
Trophies
0
Age
35
XP
688
Country
United States
Since it was patched, there's no point in keeping this anymore. R.I.P StageFright.

- Info -
With this you can build (and in theory, run) homebrew for Wii U version 5.4.0 and 5.5.0. It is incredibly bad, and likely won't run any code for you whatsoever. Sounds good right? Yeah? Right on!

- For Developers -
We have been incredibly lazy about fixing this. However, I have a hint for you. Use the code spray code from previous HTML exploits, and embed the MP4 exploit to run code that way.

In template540 and template550, at offset 0x79 to 0x7C contains the value that is in r30 when it crashes, which is an address to a point in the ROP buffer. Essentially leave the rest of the MP4 file unchanged if you plan on doing it via HTML/JS. If you want to use another ROP gadget, then the address that is spammed at the end of the file is the gadget that we initially jump to.

- Download -
http://puu.sh/mt27J/b994df006e.zip

- Credits -
zhuowei - Pointing out the bug to Marionumber1 and I.
Marionumber1 - All the fantastic ROP chain work. Plus all around masterful work. Wouldn't have been possible without him.
Mathew_Wi - Shitty initial exploitation/debugging/5.5.0 ROP Gadgets
MrRean - Helping in a way I can't quite remember.
NWPlayer123 - Something!
Hykem - I think he did something too, I can't remember, sue me.
Original Crew - comex, Relys, TheKit, and of course Mr. Chadderz himself.

- Special Thanks -
NWPlayer123 for convincing Marionumber1 to allow me to participate in the group. <3

If I forgot you, feel free to verbally abuse me on IRC or Skype.
lol.jk nice touch
 
  • Like
Reactions: MAXLEMPIRA

Droyd

Well-Known Member
Member
Joined
Jan 3, 2016
Messages
159
Trophies
0
Age
101
XP
150
Country
Antarctica
So will 5.5.0 users be able to install homebrew channel without using any game for the exploit to run ?
 

shaneod

Well-Known Member
Member
Joined
Mar 3, 2011
Messages
348
Trophies
0
XP
427
Country
So will 5.5.0 users be able to install homebrew channel without using any game for the exploit to run ?
5.5.0 users can't do much with this alone. 5.4.0 users will be able to do the same as 5.3.2 users basically, but 5.5.0 users won't be able to until an IOSU or kernel exploit is released
 

JohnathanMonkey

Well-Known Member
Member
Joined
Apr 26, 2013
Messages
630
Trophies
0
Age
35
XP
688
Country
United States
Could loadiine 5 come of this? Sorry if it's a stupid question and feel free to bash away! I'm a big boy and can handle it ;)
 

Droyd

Well-Known Member
Member
Joined
Jan 3, 2016
Messages
159
Trophies
0
Age
101
XP
150
Country
Antarctica
5.5.0 users can't do much with this alone. 5.4.0 users will be able to do the same as 5.3.2 users basically, but 5.5.0 users won't be able to until an IOSU or kernel exploit is released
Aww, I was hoping to get a homebrew channel since I can't get the games needed for triggeing the exploit, but great reveal for 5.4 users, enjoy.
 
Status
Not open for further replies.
General chit-chat
Help Users
  • No one is chatting at the moment.
  • Dark_Phoras @ Dark_Phoras:
    And I'm still on Batman: Arkham City. Such a good game. Mr Freeze's boss fight is hard and extensive, we're currently at a point where whoever gets the next strike wins. If I miss I'll lose another 30 mins at least.
    Gift
  • Psionic Roshambo @ Psionic Roshambo:
    Lol Mr Freeze "Remember kids it's not the size of your gun, it's how you use it"
    +1
    Gift
  • AncientBoi @ AncientBoi:
    And to shoot it well. :)
    Gift
  • Psionic Roshambo @ Psionic Roshambo:
    Indeed! Lol
    +1
    Gift
  • Dark_Phoras @ Dark_Phoras:
    Do you guys know what's Mr. Freeze's favorite date program? Netflix and chill
    Gift
  • Gift
  • Gift
  • FAST6191 @ FAST6191:
    Isn't Mr Freeze's backstory about him losing his wife?
    Gift
  • Flame @ Flame:
    @FAST6191 his called @Dark_Phoras for a reason
    Gift
  • Dark_Phoras @ Dark_Phoras:
    Mr. Freeze's wife is frozen while he looks for a cure to her illness
    Gift
  • Dark_Phoras @ Dark_Phoras:
    But, in the meantime, he knows how to throw a cool party
    Gift
  • Psionic Roshambo @ Psionic Roshambo:
    He's a chill dude lol
    Gift
  • Flame @ Flame:
    is that true @Dark_Phoras ? thats so cool
    Gift
  • Flame @ Flame:
    a little ice cold too at the same time
    Gift
  • Psionic Roshambo @ Psionic Roshambo:
    Dude is frosty
    Gift
  • gudenau @ gudenau:
    Does anyone happen to know if the gecko code handler will always be in the same location? It would be useful if you could call into it's own subroutines in ASM codes.
    Gift
  • FAST6191 @ FAST6191:
    Are there any codes that modify the handler to do fun extras like there are for DS codes?
    Gift
  • gudenau @ gudenau:
    I don't see why you would need that, Gecko just allows you to do ASM directly instead of needing to make codes to add new code types.
    Gift
  • gudenau @ gudenau:
    There is nothing stopping you from doing that though.
    Gift
  • FAST6191 @ FAST6191:
    I was thinking more if there were (some of the DS stuff allowing I think it was different boolean masks than stock) then it would confirm that.
    Gift
  • gudenau @ gudenau:
    Some of the later DS stuff was pretty impressive. I do want to figure out how some of the lower level stuff worked one of these days.
    Gift
  • gudenau @ gudenau:
    Is this chat still on IRC?
    Gift
  • FAST6191 @ FAST6191:
    I don't know if there is a second room connected to it
    but I doubt it
    Gift
  • FAST6191 @ FAST6191:
    There is still an IRC server/channel though
    Gift
  • KenniesNewName @ KenniesNewName:
    Neat steam deck dock shipped finally
    Gift
    KenniesNewName @ KenniesNewName: Neat steam deck dock shipped finally