[Defcon] Smea to give 3DS security talk and release free arm9 exploit chain on August 11

dc-25-logo.jpg


(complete video of the talk - uploaded Oct. 22, 2018)

UPDATE (10-23-18): This hack was patched on 11.8 and was never publicly implemented
Please use Frogminer -> Free B9S cfw, works on 11.8, covers all major regions

(disclosure: Frogminer is my hack, but it serves the same purpose smeahax originally promised, so it's relevant here)


It looks like our old 3DS scene pal @smealum has returned to the limelight! Famous for his groundbreaking Ninjhax, Ironhax, and Tubehax userland exploits, and the udsploit kernel11 hax, Smea is back and better than ever with a total of four new exploits set to be revealed this Saturday at Defcon 26 in Las Vegas! So if you never got on the CFW bandwagon (full control of your 3DS with all the implied benefits), you'd better come and tune in with us this Saturday at 11:00 am PT sharp!​

Slides and Additional Videos


MHAX userland
ROHAX2 priv. escalation
ZHAX kernel11
TWLHAX arm9

(please wait for the guide to be updated for instructions)
^ skeletonwaiting.gif

DkV77xzUcAACLnW.jpg


 
Last edited by zoogie,

naddel81

Well-Known Member
Member
Joined
Dec 14, 2009
Messages
2,549
Trophies
1
XP
3,796
Country
United States
Since he found the vulnerabilities, it's entirely his right to do anything he wants with them, including reporting to Nintendo for money. Nothing says he is required to release them in any form.
Exactly. It is quite the opposite. He is not allowed to release the exploits after selling them to Nintendo. Right?

Gesendet von meinem Redmi Note 4 mit Tapatalk
 

R13

Member
Newcomer
Joined
Aug 12, 2018
Messages
7
Trophies
0
Age
33
XP
52
Country
United States
Exactly. It is quite the opposite. He is not allowed to release the exploits after selling them to Nintendo. Right?

Gesendet von meinem Redmi Note 4 mit Tapatalk

Look at Zoogie's post. He links to where it says that you are allowed to release them once given permission, which is apparantly given by nintendo 2-4 weeks after being fixed.
 
  • Like
Reactions: naddel81

naddel81

Well-Known Member
Member
Joined
Dec 14, 2009
Messages
2,549
Trophies
1
XP
3,796
Country
United States
Look at Zoogie's post. He links to where it says that you are allowed to release them once given permission, which is apparantly given by nintendo 2-4 weeks after being fixed.
So we assume he sold them to Nintendo and now he can make them public?

Gesendet von meinem Redmi Note 4 mit Tapatalk
 

zoogie

playing around in the end of life
OP
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,000
Country
Micronesia, Federated States of
Last edited by Quantumcat,
  • Like
Reactions: naddel81 and Hunter

Hunter

i'ma stuffup the board
Former Staff
Joined
Nov 20, 2003
Messages
2,651
Trophies
2
Age
43
Location
Melbourne, Australia
Website
www.bundleupdates.com
XP
3,100
Country
Australia

ihaveahax

Well-Known Member
Member
Joined
Apr 20, 2015
Messages
6,069
Trophies
2
XP
7,827
Country
United States
What's the point being a hacker, then getting paid by the company tou are fucking over to tell them how you did it. Bit hypocritical maybe, but shrug......if it pays his mortgage don't suppose he gives a fuck
Many companies have bug bounties for their software. They would be interested in paying you if you found a bug or security hole.

Why do you think he should instead hold and release them instead of reporting? The more ethical thing actually would be to report them instead of making them public. It just happens to seem like less of an issue to do so for game consoles. It's his vulnerability, not yours, he can report it all he wants and it's his right to do so. You are not entitled to anything. Stop acting like it.
 
Last edited by ihaveahax,

Tigger

Well-Known Member
Member
Joined
Jun 14, 2018
Messages
112
Trophies
0
Age
55
XP
211
Country
United Kingdom
Many companies have bug bounties for their software. They would be interested in paying you if you found a bug or security hole.

Why do you think he should instead hold and release them instead of reporting? The more ethical thing actually would be to report them instead of making them public. It just happens to seem like less of an issue to do so for game consoles. It's his vulnerability, not yours, he can report it all he wants and it's his right to do so. You are not entitled to anything. Stop acting like it.

sorry didn't realise my comments would make his followers cry. sorrrrrreeeee.

I have edited all my hurtful comments.

Good luck to Smea the wonderful mortgageless person hurrah
 
Last edited by Tigger,

ihaveahax

Well-Known Member
Member
Joined
Apr 20, 2015
Messages
6,069
Trophies
2
XP
7,827
Country
United States
sorry didn't realise my comments would make his followers cry. sorrrrrreeeee.

I have edited all my hurtful comments.

Good luck to Smea the wonderful mortgageless person hurrah
Why are you upset that he did this? He was right to report them and get a reward, and you still got the exploits in the end, so both sides are happy.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    HiradeGirl @ HiradeGirl: :discuss: