Hacking Mario Kart 8 Mods

Status
Not open for further replies.

Bug_Checker_

Well-Known Member
Member
Joined
Jun 10, 2006
Messages
950
Trophies
0
XP
664
Country
United States
Yes, I know that. But to port the browser exploit from 4.1->5.0 we need the 5.0 binaries.

I have the 4.1 binaries which were used to create the ROP chain:
ZQ6F84L.png


If Chadderz releases his exploit this will allow us to start working on reverse engineering the system and develop an IOS exploit to gain access to the starbuck kernel where all the common keys are located. When we get the common keys we can decrypt the 5.0 binaries (the ones shown in the picture above, except for version 5.0) and port the exploits over to 5.0.

If I'm not clear enough, this is our current exploitation vector:

  1. Wii U browser "use after free" memory exploit using heap spray
  2. ROP chain in JIT code execution area to bypass Address Space Layout Randomization
  3. Chadderz kernel exploit to escalate privilege level to gain access to the espresso kernel (Everything is theoretically possible on 4.1 now. The Wii U's security is toast).
  4. IOS exploit to gain access to the starbuck kernel
  5. Dump wii u common keys from starbuck
  6. Decrypt 5.0 binaries from the Nintendo CDN
  7. Port all exploits over to 5.0
  8. Disable signature verification checks in CafeOS
  9. Reverse engineer CafeOS to understand how to package our own channels
  10. Create homebrew loader channel (which will require some home-aid libs for SD storage loading etc.)
  11. Continue work on developing Wii U libs and documentation.

So where did the access to those original elfs:
Account Settings
Internet Browser
Nintendo TVii
Nintendo eShop
Miiverse
come from?

a ramdump?
Something that can be duplicated?
Were they posted somewhere?
 

Relys

^(Software | Hardware) Exploit? Development.$
Member
Joined
Jan 5, 2007
Messages
878
Trophies
1
XP
1,239
Country
United States
Yes, but the server uses HTTPS.


Doesn't matter you still can grab the files. HTTPS has nothing to do with their encryption method. They are encrypted with the Wii U common key. The hash can be found in f0f's initial blog post https://fail0verflow.com/blog/2014/console-hacking-2013-omake.html

How was the original ROP chain developed in the first place? Guess and check, mitm ram, reversing binarysomehow?


Reversing the Webkit Binary for 4.1 and the Eshop binary from 4.1 for the 4.0.x port (Mario told me this). He built the ROP chain manually by looking at the binaries.

So where did the access to those original elfs:
Account Settings
Internet Browser
Nintendo TVii
Nintendo eShop
Miiverse
come from?

a ramdump?
Something that can be duplicated?
Were they posted somewhere?


They are still 0 day. They were downloaded from Nintendo's CDN (You can download them via your browser) and decrypted the with Wii U common key that was mentioned above by an f0f member who already has all the keys.

Marionumber1 is currently trying to get in touch with Chadderz. It would really be a nice gesture if Chadderz shared this exploit with Marionumber1 so we can continue to open up the Wii U to grab the keys from the Starbuck OTP. Once we have the keys we can decrypt the binaries which will allow porting to 5.0.
 

PhyChris

Well-Known Member
Member
Joined
May 6, 2009
Messages
368
Trophies
1
XP
2,094
Country
Canada
If you are on 5.0+ then you are screwed for the browser exploit (i'm on 5.0)... I have seen this happen meany times in the past with different console/handheld scenes
anyone who is working on getting the needed keys have what they need, a pre-5.0 wiiu, there is no reason to port it. so like me whoever is on 5.0 is SOL until the needed keys are found....
 

Rinnux

Well-Known Member
Member
Joined
Aug 3, 2010
Messages
655
Trophies
0
Age
29
XP
705
Country
United States
If you are on 5.0+ then you are screwed for the browser exploit (i'm on 5.0)... I have seen this happen meany times in the past with different console/handheld scenes
anyone who is working on getting the needed keys have what they need, a pre-5.0 wiiu, there is no reason to port it. so like me whoever is on 5.0 is SOL until the needed keys are found....

We're not screwed. The exploit still exists in the browser. Yes it will require more work to port over, however that does not mean anyone who updated to 5.0 is as you put it, SOL.
 
  • Like
Reactions: Margen67

Bladexdsl

fanboys triggered 9k+
Member
Joined
Nov 17, 2008
Messages
21,154
Trophies
2
Location
Queensland
XP
12,255
Country
Australia
If you are on 5.0+ then you are screwed for the browser exploit (i'm on 5.0)... I have seen this happen meany times in the past with different console/handheld scenes
anyone who is working on getting the needed keys have what they need, a pre-5.0 wiiu, there is no reason to port it. so like me whoever is on 5.0 is SOL until the needed keys are found....
it still works on 5.0 :lol:
 
  • Like
Reactions: Margen67

PhyChris

Well-Known Member
Member
Joined
May 6, 2009
Messages
368
Trophies
1
XP
2,094
Country
Canada
yes the browser bug is still there but NOT exploited yet. why go through all the trouble to port a half-backed browser exploit, its a LOT of work. the next logical step is to 'use' the current exploit and get the keys... now I cant predict the future but a 5.0 port of the web exploit is a wast of time and i doubt we will see it.
 

Rinnux

Well-Known Member
Member
Joined
Aug 3, 2010
Messages
655
Trophies
0
Age
29
XP
705
Country
United States
yes the browser bug is still there but NOT exploited yet. why go through all the trouble to port a half-backed browser exploit, its a LOT of work. the next logical step is to 'use' the current exploit and get the keys... now I cant predict the future but a 5.0 port of the web exploit is a wast of time and i doubt we will see it.

From what I've seen over the past few days, the devs here have every intention of porting it to 5.0.
 

PhyChris

Well-Known Member
Member
Joined
May 6, 2009
Messages
368
Trophies
1
XP
2,094
Country
Canada
Like i said I can't predict the future. however I will give some advice if you are not a dev don't touch any exploit until things have matured to the point that you have good homebrew to run.. never before. thats how I got my wanko brick lol
 

Bug_Checker_

Well-Known Member
Member
Joined
Jun 10, 2006
Messages
950
Trophies
0
XP
664
Country
United States
If you are on 5.0+ then you are screwed for the browser exploit (i'm on 5.0)... I have seen this happen meany times in the past with different console/handheld scenes
anyone who is working on getting the needed keys have what they need, a pre-5.0 wiiu, there is no reason to port it. so like me whoever is on 5.0 is SOL until the needed keys are found....
yes the browser bug is still there but NOT exploited yet. why go through all the trouble to port a half-backed browser exploit, its a LOT of work. the next logical step is to 'use' the current exploit and get the keys... now I cant predict the future but a 5.0 port of the web exploit is a wast of time and i doubt we will see it.
When one of the main developers of the browser exploit is accidentally locked out by his own brother updating the wiiu to 5.0, I can say with certainty that
"There WILL be a 5.0 browser exploit. Period."
Now nuttin' more to say on this topic. Move along.
 
  • Like
Reactions: filfat and PhyChris

Chadderz

Well-Known Member
Newcomer
Joined
Apr 12, 2009
Messages
46
Trophies
1
Age
30
Location
England
Website
www.chadsoft.co.uk
XP
339
Country
Unfortunately, I really don't want my kernel exploit released to anyone. Normally, I'm big on open source, I release most stuff under MIT licesnse, but the trouble is, there is a lot more at stake here. The reaction to our video is quite rightly a mix of excitement and fear, because people worry about online cheating and I refuse to be the one responsible for that. I know I built on other people's work to do this and so I really would like to give something back, but I just can't trust anyone. Once the exploit leaves my possession I have no control, the only control I have is not to release. As I understand it the browser exploit was leaked in the first place, who's to say the same wouldn't happen again?
 
  • Like
Reactions: filfat and PhyChris

the_randomizer

The Temp's official fox whisperer
Member
Joined
Apr 29, 2011
Messages
31,284
Trophies
2
Age
38
Location
Dr. Wahwee's castle
XP
18,969
Country
United States
Unfortunately, I really don't want my kernel exploit released to anyone. Normally, I'm big on open source, I release most stuff under MIT licesnse, but the trouble is, there is a lot more at stake here. The reaction to our video is quite rightly a mix of excitement and fear, because people worry about online cheating and I refuse to be the one responsible for that. I know I built on other people's work to do this and so I really would like to give something back, but I just can't trust anyone. Once the exploit leaves my possession I have no control, the only control I have is not to release. As I understand it the browser exploit was leaked in the first place, who's to say the same wouldn't happen again?


Very baffling indeed, this would be quite a predicament, if you will. Very odd that something would be showcased and not released. This would undeniably be a detriment to the Wii U hacking scene, would it not? I don't have the highest of hopes to be honest, Wii U interest is well, kinda no there, at least. not a lot. This exacerbates the issue IMHO.


Eh, I mean chadderz is good and all, but I don't think he was touched by the gods as the only one who could possibly find this exploit. Maybe he is tho.

Lesson is, this is how scenes die off. I know that they don't owe us, etc etc, but there really is no point in showing off something that'll never be leaked, right?? Just because something can be shown off, doesn't mean it should.
 
  • Like
Reactions: Margen67

headpie

Member
Newcomer
Joined
Jul 7, 2014
Messages
21
Trophies
0
Age
54
XP
92
Country
United States
Eh, I mean chadderz is good and all, but I don't think he was touched by the gods as the only one who could possibly find this exploit. Maybe he is tho.
 

s-arash

Well-Known Member
Member
Joined
Sep 3, 2013
Messages
185
Trophies
0
Age
32
XP
364
Country
United States
Unfortunately, I really don't want my kernel exploit released to anyone. Normally, I'm big on open source, I release most stuff under MIT licesnse, but the trouble is, there is a lot more at stake here. The reaction to our video is quite rightly a mix of excitement and fear, because people worry about online cheating and I refuse to be the one responsible for that. I know I built on other people's work to do this and so I really would like to give something back, but I just can't trust anyone. Once the exploit leaves my possession I have no control, the only control I have is not to release. As I understand it the browser exploit was leaked in the first place, who's to say the same wouldn't happen again?

if you dont release it , some else will do , like what happend to 3ds, neimod didnt released exploit , gateway 3ds did it (with money)
you cant prevent cheating,homebrew,piracy,... cause one day they'll happen, its just the matter of time :)
 
  • Like
Reactions: Margen67

Chadderz

Well-Known Member
Newcomer
Joined
Apr 12, 2009
Messages
46
Trophies
1
Age
30
Location
England
Website
www.chadsoft.co.uk
XP
339
Country
I know, I do genuinely feel really bad about this, but I would feel even worse if the work was used for bad purposes. As headpie says, if we can do it, someone else can, hopefully that will take matters out of my hands.
 
  • Like
Reactions: gudenau

Bug_Checker_

Well-Known Member
Member
Joined
Jun 10, 2006
Messages
950
Trophies
0
XP
664
Country
United States
I know, I do genuinely feel really bad about this, but I would feel even worse if the work was used for bad purposes. As headpie says, if we can do it, someone else can, hopefully that will take matters out of my hands.
Do you have complete control of the WiiU?
Or Do you just have control of the ppc?
Do you have any or all control of the arm?
Do you have any or all control of the DRH?
Do you have any or all control of the DMCU?
Do you have the ability you dump the full 2GB of ram?
Do you have the ability you dump the DRH firmware?

Can you take control of the WiiU before the system menu loads?
 

Chadderz

Well-Known Member
Newcomer
Joined
Apr 12, 2009
Messages
46
Trophies
1
Age
30
Location
England
Website
www.chadsoft.co.uk
XP
339
Country
Just the PPC. For the record I know I sound like a complete arsehole in the video, but that's because it's part of a livestream in which we were being incredibly sarcastic. What's not shown is about an hour of me calling myself the biggest loser ever because the exploit wasn't working ;)
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BigOnYa @ BigOnYa:
    6/10 rating on steam
  • Psionic Roshambo @ Psionic Roshambo:
    I would like a Predator game "Kill Team" it takes place in the Jungle of the first movie, your team is sent to hunt the predator, using current tech drones and a trained team. Set traps use strategy to hunt and trap or kill the predator.
  • BigOnYa @ BigOnYa:
    Ill stick with my Battlefield. Yea a predator hunting game like that would be cool. Esp if you can be Arnold and say "Get to da choppa"
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Maybe Arnold could do a cameo voice acting, he is the one briefing you on the mission
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Honestly surprised they didn't make a tie in game for Predators that movie was awesome
  • Psionic Roshambo @ Psionic Roshambo:
    I was kinda sad the Yakuza guy died sword fighting a predator lol
  • Psionic Roshambo @ Psionic Roshambo:
    The Russian guy went out like a boss
  • Psionic Roshambo @ Psionic Roshambo:
    Double claymores to the face definitely kill a predator lol
  • BigOnYa @ BigOnYa:
    I went today and looked at a motorcycle someone was selling. I get there and the battery on it was dead, so the guy grabbed a battery charger and hooked it up. He plugged it into the wall, and the motorcycle sparked and started smoking. Come to find out the bike uses a 6 volt battery and the guy had the charger set to 12v. I said sorry to the dude and walked away. I felt bad for him tho.
  • Psionic Roshambo @ Psionic Roshambo:
    Sounds like it would be an exciting ride....
  • Psionic Roshambo @ Psionic Roshambo:
    Not sure I would want something on fire between my legs
  • BigOnYa @ BigOnYa:
    He ruined it basically. Sad cause it was a decent old bike. It would take more money to rewire the bike than it was worth tho.
  • Psionic Roshambo @ Psionic Roshambo:
    Yeah I'm sure at minimum the starter was fried
  • Psionic Roshambo @ Psionic Roshambo:
    Alternator and battery
  • BigOnYa @ BigOnYa:
    Prob alot of fried parts. It was still smoking when I left.
  • K3Nv2 @ K3Nv2:
    I would've said show me how it rides
  • Psionic Roshambo @ Psionic Roshambo:
    I always wanted one of those Smart Cars with a Hyabusa motor in it.
  • K3Nv2 @ K3Nv2:
    I'm getting sick and tired of cheap ass baking pans now
  • BigOnYa @ BigOnYa:
    I think it be cool to have one that would fit in my pickup truck bed, then I could put down ramps n drive it off.
  • K3Nv2 @ K3Nv2:
    Used this one 5 times already impossible to clean
  • BigOnYa @ BigOnYa:
    @K3Nv2 I didn't know Sonic serves they food in baking pans.
  • Psionic Roshambo @ Psionic Roshambo:
    Condoms are only meant to be used once Ken lol
    Psionic Roshambo @ Psionic Roshambo: Condoms are only meant to be used once Ken lol