Hacking IOSU exploit details released for pre-5.2 systems

QuarkTheAwesome

🦊
OP
Member
Joined
Apr 19, 2015
Messages
1,023
Trophies
1
Location
Stuck in the PowerPC
Website
heyquark.com
XP
3,911
Country
Australia
https://nwert.wordpress.com/2016/05/03/ioctlvhax/

Well, this will be interesting.

It's worth noting that this bug may still be exploitable on newer systems through the use of SysCall 0x2E, which changes the limit on the amount of vectors we can pass in. However, we need IOSU userland access to run it. And if we've already got IOSU userland access, what use is an exploit that gives us userland access? ;D
 
Last edited by QuarkTheAwesome,

QuarkTheAwesome

🦊
OP
Member
Joined
Apr 19, 2015
Messages
1,023
Trophies
1
Location
Stuck in the PowerPC
Website
heyquark.com
XP
3,911
Country
Australia
In fact. It reveals a way that could lead to exploitation even after the vector fix in 5.2.

Syscall 0x2E, eh? It's funny that Nintendo added a call so we can re-enable a bug they think they fixed.

The fun thing is almost every homebrew user is on 5.3.2-5.5.1. We need a way to donwgrade to 5.1.0

Yeah, all those people saying that there's "no reason to no update to 5.3.2" are going to be embarrassed ;3
 
  • Like
Reactions: TotalInsanity4

davetheshrew

Well-Known Member
Member
Joined
Jan 2, 2016
Messages
562
Trophies
0
Age
41
XP
671
Country
perhaps they added a call so that they can re-enable when doing fw updates etc then repatch. It might be important so they noobishly 'fixed' a sploit to a function they need at times.
 
  • Like
Reactions: TotalInsanity4

leonmagnus99

Well-Known Member
Member
Joined
Apr 2, 2013
Messages
3,704
Trophies
2
Age
33
Location
Seinegald
XP
2,875
Country
Iraq
it would be nice if we could get the exploit stick permanent and maybe (rednand? /usbloader) ;-;

loading up the kexploit loadiine alone is so hassly, it works once out of 10 tries ( deleting cookies doesnt help ,its a matter of luck XD ) .

that aside, can the tubehax dns affect the hax somehow?
 
  • Like
Reactions: TotalInsanity4

Net-KILLER

computer says no
Member
Joined
Oct 22, 2009
Messages
611
Trophies
0
Location
in a pineapple under the sea
XP
526
Country
Saint Kitts and Nevis
Syscall 0x2E, eh? It's funny that Nintendo added a call so we can re-enable a bug they think they fixed.



Yeah, all those people saying that there's "no reason to no update to 5.3.2" are going to be embarrassed ;3
Well I updated from 5.0.0 to 5.3.2 a few months ago.
If I can't use iosu now it's ok for me.
Loadiine and the others tools were worth it.
 

SirByte

Well-Known Member
Member
Joined
Dec 30, 2012
Messages
524
Trophies
1
XP
1,059
Country
Canada
and for permanent exploit you'll need a boot-time entrypoint

No you don't, my o3DS firmware 4.1.0U is working right fine with a 10.7.0U EmuNAND. That's all you need; an exploitable firmware to gain access which you can keep perpetually, but you need to be able to run a RedNAND/EmuNAND which means you need both Kernel and IOSU exploits.
 
Last edited by SirByte, , Reason: typo

andriy921

Well-Known Member
Member
Joined
Dec 1, 2015
Messages
268
Trophies
0
Age
33
XP
240
Country
No you don't, my o3DS firmware 4.1.0U is working right fine with a 10.7.0U EmuNAND. That's all you need; an exploitable firmware to gain access which you can keep perpetually, but you need to be able to run a RedNAND/EmuNAND which means you need both Kernel and IOSU exploits.
You didn't understand what he means by permanent.
 

QuarkTheAwesome

🦊
OP
Member
Joined
Apr 19, 2015
Messages
1,023
Trophies
1
Location
Stuck in the PowerPC
Website
heyquark.com
XP
3,911
Country
Australia
Worth noting that the syscall mentioned in the article is an IOSU call (set_device_state to be specific) which we can only access from the IOSU.
To sum up, this is an exploit that allows us to access IOSU userland that was patched. We can unpatch it with Syscall 0x2E but that is only accessible from IOSU userland, which we don't have, but this exploit will give us, but needs Syscall 0x2E, which needs IOSU userland, which we don't have...

At least <5.2 users can be happy.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BigOnYa @ BigOnYa:
    Yea true, but using a wheel and pedals for gas/brake was awesome feature back in the day.
  • Psionic Roshambo @ Psionic Roshambo:
    Not sure if that or RC Pro AM was my favorite NES racing game... hmmmm
  • BigOnYa @ BigOnYa:
    Yea I loved the rc pro am games
  • Psionic Roshambo @ Psionic Roshambo:
    @SylverReZ, RC Pro AM was made by Rare, and that explains why I liked it. Just learned the other day about a game I loved that was made by Rare and I was surprised lol
  • K3Nv2 @ K3Nv2:
    I was playing need for speed remastered and said to myself this is a nice Forza remaster
  • Psionic Roshambo @ Psionic Roshambo:
    https://en.wikipedia.org/wiki/List_of_video_games_developed_by_Rare Not all of them are awesome but man the hits on that list.
  • Psionic Roshambo @ Psionic Roshambo:
    Oh snap Super Offroad was by them too? lol damn
    +1
  • BakerMan @ BakerMan:
    Today I learned that the creators of the Donkey Kong games also made Sea of Thieves
  • BakerMan @ BakerMan:
    why do i feel the sudden urge to start singing pirate's scorn from the donkey kong country cartoon?
  • BigOnYa @ BigOnYa:
    Are you being for real, cause that's hard to believe, DK is Nintendo and made in japan, Sea of thieves was from Microsoft, in America. I'm not calling you a liar, just didn't know.
  • BigOnYa @ BigOnYa:
    Ok yes they were both made by Rare, but DK was from Rare back then, Rare now is owned by MS. So makes since.
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    They even developed a LJN game.... lol
  • K3Nv2 @ K3Nv2:
    It was pretty rare
  • Psionic Roshambo @ Psionic Roshambo:
    I wonder what deal with Satan LJN worked to get Rare to make that one...
  • BigOnYa @ BigOnYa:
    I remember couple years ago, they announced they were working on a Perfect Dark remake, wonder what ever happen with that?
  • K3Nv2 @ K3Nv2:
    It went into the darkness
  • BigOnYa @ BigOnYa:
    Me and buddies used to play the hell out of Perfect Dark on N64, that and Goldeneye, was the first real PvP shooter games I remember
  • BigOnYa @ BigOnYa:
    4-way split screen on a tiny 19" TV, lol
  • K3Nv2 @ K3Nv2:
    Did you share joysticks also
  • BigOnYa @ BigOnYa:
    Nuh we had the 4 controller add on thingy for n64. Duh I just got your joke, lol
  • K3Nv2 @ K3Nv2:
    So you touched ends
  • BigOnYa @ BigOnYa:
    Yea, but being in the boy scouts, they forced us to
  • K3Nv2 @ K3Nv2:
    Chopped down some wood for the scout master
    K3Nv2 @ K3Nv2: Chopped down some wood for the scout master