Hacking Just an idea: update proxy?

WiiFoundLove

Well-Known Member
OP
Member
Joined
Jan 18, 2015
Messages
280
Trophies
0
Age
54
XP
367
Country
Afghanistan
Hi!

This is just an idea, but wouldn't it be possible to create something like an update proxy that stores the downloaded update on hdd instead of sending it to the switch and serve it later on demand? I think of something like this:

Fetch update and store it as X.X (i don't know if it is possible to automaticly get the info about the version since the updates are encrypted):
up1.png
And than serve the update on demand:
up2.png
So we could collect upcoming updates without updating our switch, and if a further firmware get hacked, then just update to it, even if nintendo offers a newer update than the desired update. I know the updates are encrypted, but it shouldn't be the problem to get them if the proxy would store and recognice the raw http requests too?
 

Attachments

  • up1.png
    up1.png
    5.9 KB · Views: 290
  • up1.png
    up1.png
    5.9 KB · Views: 265
D

Deleted User

Guest
Hi!

This is just an idea, but wouldn't it be possible to create something like an update proxy that stores the downloaded update on hdd instead of sending it to the switch and serve it later on demand? I think of something like this:

Fetch update and store it as X.X (i don't know if it is possible to automaticly get the info about the version since the updates are encrypted):
View attachment 90226
And than serve the update on demand:
View attachment 90227
So we could collect upcoming updates without updating our switch, and if a further firmware get hacked, then just update to it, even if nintendo offers a newer update than the desired update. I know the updates are encrypted, but it shouldn't be the problem to get them if the proxy would store and recognice the raw http requests too?
iirc, the switch uses encrypted SSL requests, so this wouldn't work.
 
  • Like
Reactions: Garblant

WiiFoundLove

Well-Known Member
OP
Member
Joined
Jan 18, 2015
Messages
280
Trophies
0
Age
54
XP
367
Country
Afghanistan
I don't have any knowledge of SSL encryption, but is this a hardware thing? Or is ist simply encrypted data that is sended over a simply socket connection? Cause if the switch doesn't send anything inside the request that will change the encrypted data it should be possible to teach the proxy by starting the firmware download how the encrypted request for the firmware download looks like, so that it could recognice it and act appropriate.
 
Last edited by WiiFoundLove,

Garou

Well-Known Member
Member
Joined
Jan 13, 2015
Messages
1,213
Trophies
0
XP
1,667
Country
SSL is common for security connection and no it's not hardware thing
Simply put with SSL the client connect to the server at some URL (say nintendo.com) and then the server will pass a certificate stating that it really is a server with URL nintendo.com
This certificate is hard to forge unless you can already tamper the certificate authority in the client, so basically it's not easy to make a fake nintendo.com server using SSL
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • SylverReZ @ SylverReZ:
    @Sonic Angel Knight, Is that SAK I see. :ninja:
  • BigOnYa @ BigOnYa:
    What a weird game
  • K3Nv2 @ K3Nv2:
    Yeah I wanted to see shards of the titanic
  • BigOnYa @ BigOnYa:
    I kept thinking jaws was gonna come up and attack
  • K3Nv2 @ K3Nv2:
    Jaws is on a diet
  • K3Nv2 @ K3Nv2:
    Damn power went out
  • BigOnYa @ BigOnYa:
    Ok xdqwerty, your little bro prob tripped On the cord and unplugged you
  • K3Nv2 @ K3Nv2:
    Ya I'm afraid of the dark hug me
  • BigOnYa @ BigOnYa:
    Grab and hold close your AncientBoi doll.
  • K3Nv2 @ K3Nv2:
    Damn didn't charge my external battery either
  • BigOnYa @ BigOnYa:
    Take the batteries out of your SuperStabber3000... Or is it gas powered?
  • K3Nv2 @ K3Nv2:
    I stole batteries from your black mamba
    +1
  • K3Nv2 @ K3Nv2:
    My frozen food better hold up for an hour I know that
  • BigOnYa @ BigOnYa:
    Or else gonna be a big lunch and dinner tomorrow.
  • BigOnYa @ BigOnYa:
    Did you pay your power bill? Or give all yo money to my wife, again.
  • K3Nv2 @ K3Nv2:
    Oh good the estimated time is the same exact time they just said
    +1
  • BigOnYa @ BigOnYa:
    Load up your pc and monitor, and head to a McDonalds dining room, they have free WiFi
  • K3Nv2 @ K3Nv2:
    Sir please watch your porn in the bathroom
    +1
  • BigOnYa @ BigOnYa:
    No sir we can not sell you anymore apple pies, after what you did with the last one.
  • K3Nv2 @ K3Nv2:
    We ran out
  • HiradeGirl @ HiradeGirl:
    for your life
    +1
  • K3Nv2 @ K3Nv2:
    My life has no value my fat ass is staying right here
    K3Nv2 @ K3Nv2: My life has no value my fat ass is staying right here