Hacking Question Can someone explain me why a Web Browser exploit wouldn't work?

Deleted member 191657

Well-Known Member
Newcomer
Joined
Aug 10, 2009
Messages
87
Trophies
0
XP
1,315
Country
Italy
Switch has a hidden web browser. Why is an exploit not possible?
Webkit exploit do work on the Nintendo Switch (the one PegaSwitch used is a good example of it), but there are two main reason why they are not (yet) the entry point of choice:
- We already have a RCM exploit (or rather two of them, but they are based upon the same vulnerability) which allow code execution at the lowest level possible
- Due to pretty good security measures that Horizon takes (including ASLR which is a pain in the butt) escalating from user-space using a WebKit exploit is no easy feat (it still can be done)

We will probably see new and creative entry-points (probably based on WebKit) as soon as a new hardware revision (see Mariko) fixes the RCM exploit.

Sources and good reads:

https://github.com/reswitched/pegaswitch (Exploitation suite for Switches <= 3.0.0)
https://nvd.nist.gov/vuln/detail/CVE-2016-4657 Exploit on which PegaSwitch is based upon

https://www.ktemkin.com/faq-fusee-gelee/ (Fusee-Gelee, RCM exploit for any first-gen Switch)
https://github.com/fail0verflow/shofel2 (Shofel2, RCM exploit for any first-gen Switch)

http://switchbrew.org/index.php?title=Main_Page (Switchbrew, a great community driven Wiki for Switch hacking)
 
Last edited by Deleted member 191657,

link42586

Well-Known Member
Member
Joined
May 9, 2018
Messages
321
Trophies
0
Age
38
XP
1,184
Country
United States
u can access the web browser with rocket league when u click on the articles on the right of the main menu..worked on 4.1.0 I figured someone would use that at some point but it's never A thought it seems.
 

r5xscn

Well-Known Member
Member
Joined
Apr 8, 2014
Messages
317
Trophies
1
Location
On earth, somewhere
XP
2,284
Country
Antarctica
I think the people who know the exploits are keeping it for a later hardware revision where RCM is patched. Its better save the exploits for later use than getting patched now and search for more later.
 

IPLbug

Well-Known Member
Member
Joined
Jun 6, 2018
Messages
127
Trophies
0
Age
35
Location
Under Your bed stealing your data
XP
360
Country
United States
I think the people who know the exploits are keeping it for a later hardware revision where RCM is patched. Its better save the exploits for later use than getting patched now and search for more later.

There a reason why 0 day exploits are so well kept from the public for private use only. The WebKit will be patched completely in the new Mariko hardware with a version update pre installed. The problem right now is the scene burned out a lot of exploits to fast exposing to Nintendo what little holes there OS had it pretty easy to see how moving forward exploits will become a lot harder to find and escalate. This is my speculation from what documentation was released along with the rcm exploit.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BakerMan @ BakerMan:
    this is my first aurora tbh
    +1
  • BakerMan @ BakerMan:
    i mean, multiple have happened in my lifetime, but it's always been too cloudy
  • BakerMan @ BakerMan:
    IT'S LIKE THAT ALMOST EVERY FUCKING METEOR SHOWER TOO
  • BigOnYa @ BigOnYa:
    You need to setup a time lapse camera, be neat
  • BigOnYa @ BigOnYa:
    I actually use a pic of it on my pc desktop cause its cool looking
  • Xdqwerty @ Xdqwerty:
    Apparently the pro versión of pizza boy is back aswell
  • Xdqwerty @ Xdqwerty:
    Gonna download the update
  • Xdqwerty @ Xdqwerty:
    Only 2 antiviruses detected the APK as a virus on virustotal so it Must be safe
  • Xdqwerty @ Xdqwerty:
    Cuz false positive
  • Xdqwerty @ Xdqwerty:
    Wait
  • Xdqwerty @ Xdqwerty:
    Eh nvm
  • BakerMan @ BakerMan:
    sadly, the clouds are setting in now

    hey BigOnYa the clouds are coming from the south, maybe check again
  • Xdqwerty @ Xdqwerty:
    Good night it's 11 pm
  • BakerMan @ BakerMan:
    night
  • BigOnYa @ BigOnYa:
    @BakerMan Nuh I'm in for the night playing Fallout 4, ill look tomorrow night
  • BigOnYa @ BigOnYa:
    Ok had let dog out, and yea still can't see it, oh well. Maybe tom night.
  • K3Nv2 @ K3Nv2:
    Ballocks these drives aren't allowing raid
  • BigOnYa @ BigOnYa:
    That sucks, well you will get double the space then atleast.
  • K3Nv2 @ K3Nv2:
    @Sicklyboy needs to come back
  • BigOnYa @ BigOnYa:
    Did you try Raid 10?
  • K3Nv2 @ K3Nv2:
    I did raid69
  • K3Nv2 @ K3Nv2:
    The physical disk keeps disabling in bios
  • BakerMan @ BakerMan:
    hey ken did you see the aurora tonight?
  • BakerMan @ BakerMan:
    also sorry it was too cloudy, that sucks
    BakerMan @ BakerMan: also sorry it was too cloudy, that sucks