[Defcon] Smea to give 3DS security talk and release free arm9 exploit chain on August 11

dc-25-logo.jpg


(complete video of the talk - uploaded Oct. 22, 2018)

UPDATE (10-23-18): This hack was patched on 11.8 and was never publicly implemented
Please use Frogminer -> Free B9S cfw, works on 11.8, covers all major regions

(disclosure: Frogminer is my hack, but it serves the same purpose smeahax originally promised, so it's relevant here)


It looks like our old 3DS scene pal @smealum has returned to the limelight! Famous for his groundbreaking Ninjhax, Ironhax, and Tubehax userland exploits, and the udsploit kernel11 hax, Smea is back and better than ever with a total of four new exploits set to be revealed this Saturday at Defcon 26 in Las Vegas! So if you never got on the CFW bandwagon (full control of your 3DS with all the implied benefits), you'd better come and tune in with us this Saturday at 11:00 am PT sharp!​

Slides and Additional Videos


MHAX userland
ROHAX2 priv. escalation
ZHAX kernel11
TWLHAX arm9

(please wait for the guide to be updated for instructions)
^ skeletonwaiting.gif

DkV77xzUcAACLnW.jpg


 
Last edited by zoogie,

ihaveahax

Well-Known Member
Member
Joined
Apr 20, 2015
Messages
6,070
Trophies
2
XP
7,841
Country
United States
Maybe this is a dumb question but if the videos on how to do it (From smea's talk) arn't going to be released for a long time, surely it is going to be quite a while before any guide for normal users will prop up? I don't think anyone is going to do the guide from memory of the talk. Unless other people already know how to do it.
The slides and repositories with the exploits are public.

https://media.defcon.org/DEF CON 26/DEF CON 26 presentations/smea/

https://github.com/smealum/mhax
https://github.com/smealum/rohax2
https://github.com/smealum/zhax
https://github.com/smealum/twlhax
 
  • Like
Reactions: CuriousTommy

jellybeangreen2

Well-Known Member
Member
Joined
Dec 9, 2015
Messages
703
Trophies
0
XP
2,497
Country
United States
Just ordered myself a N3DS and it’s coming Thursday or before. Do I need a card to do NTRBoot or can this method be used, of course for below 11.8? - how does this actually work please
 

Blue

Well-Known Member
Member
Joined
Oct 2, 2015
Messages
2,606
Trophies
2
XP
1,060
Country
United Kingdom
Just ordered myself a N3DS and it’s coming Thursday or before. Do I need a card to do NTRBoot or can this method be used, of course for below 11.8? - how does this actually work please
There's no end user instructions on how to use this yet, but yes it will work on below 11.8. And you won't need ntrboot. If the N3DS is brand new it may come on 11.3 or under in which case you won't need to wait for this method.
 

OrGoN3

Well-Known Member
Member
Joined
Apr 23, 2007
Messages
3,241
Trophies
1
XP
3,269
Country
United States
I can't get it to work on 11.7, however. Perhaps already having CFW affects this...
No idea if already having CFW affects it. And yes, these are specifically 11.7 and below. Most likely patched out in 11.8 as previously mentioned. I mean, are you sure you are doing it correctly? :P
 

SRKTiberious

Well-Known Member
Member
Joined
Sep 4, 2014
Messages
240
Trophies
0
Age
41
XP
404
Country
United States
Hmm.... so, if I'm reading the slides and understanding them correctly, it sounds like there's a couple new exploits to get to full ARM11 control, where we then build/load a 'malicious' DS ROM (say, a DS homebrew B9S installer) and load it from there to take over ARM9.

Am I in the ballpark on the simple explanation here?
 

:-infern:

GBAtemp Legend
Member
Joined
Jun 1, 2013
Messages
256
Trophies
0
XP
423
Country
United States
These are patched cause smea sold them to Big N for $$$$. You got to get that extra lambo money even if your a senior Microsoft software security engineer at 24 lololol. $$$
 

R13

Member
Newcomer
Joined
Aug 12, 2018
Messages
7
Trophies
0
Age
33
XP
52
Country
United States
If you want a guide then look at the PDF. No one has a guide on how to do it excatly, otherwise we would all be doing it and not waiting.
 

bennyman123abc

Well-Known Member
Member
Joined
Mar 21, 2013
Messages
920
Trophies
1
Age
22
Location
Alton, IL
XP
1,208
Country
United States
No idea if already having CFW affects it. And yes, these are specifically 11.7 and below. Most likely patched out in 11.8 as previously mentioned. I mean, are you sure you are doing it correctly? :P
I doubt I'm doing it correctly lmao
These are patched cause smea sold them to Big N for $$$$. You got to get that extra lambo money even if your a senior Microsoft software security engineer at 24 lololol. $$$
I doubt he did it for the money, but probably more for the ethics of it.
 
Last edited by bennyman123abc,
  • Like
Reactions: OrGoN3

TeilzeitTaco

Member
Newcomer
Joined
Aug 1, 2018
Messages
12
Trophies
0
Age
28
XP
103
Country
Austria
I dont get the ethics point. All of his exploits are open source, so nintendo would still be able to take action even if he doesnt report it
 

zoogie

playing around in the end of life
OP
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,000
Country
Micronesia, Federated States of
Last edited by zoogie,
  • Like
Reactions: EmBlaze

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    Psionic Roshambo @ Psionic Roshambo: https://youtu.be/Hn-gx9VjRt8?t=153