Homebrew Possible to trigger an exploit through the QR code reader?

HakJobbr

New Member
OP
Newbie
Joined
Dec 25, 2015
Messages
1
Trophies
0
Age
57
XP
51
Country
United States
I did research and determined that a buffer overflow (or underflow) is possible by tampering with a QR code. A QR code can store about 7k character, but I think it is possible to stuff a whole script inside a QR. I highly doubt the 3DS's QR code reader can even read 7k characters to begin with. So, is it possible to trigger an exploit through the reader itself?
 

Uziskull

Picture may not be real
Member
Joined
Nov 15, 2015
Messages
269
Trophies
0
Location
Somewhere, probably
XP
261
Country
Portugal
Hey, that seems like an alright idea. It probably won't work, since messing with QR seems to be a common 3DS hacking practice and nobody ever came up with a triggerable exploit through it, but how about you try that out and tell us the results?
 
  • Like
Reactions: The9thBit

shaneod

Well-Known Member
Member
Joined
Mar 3, 2011
Messages
348
Trophies
0
XP
427
Country
I think he meant outside of any games, using just the system QR scanner on the Camera app.
Oh, right. My bad.
I'm sure somebody would have thought of this at some point or another. The system itself would have been the first target, and in particular the QR scanner since there have been a bunch of exploits involving it in various games.
 

Uziskull

Picture may not be real
Member
Joined
Nov 15, 2015
Messages
269
Trophies
0
Location
Somewhere, probably
XP
261
Country
Portugal
Oh, right. My bad.
I'm sure somebody would have thought of this at some point or another. The system itself would have been the first target, and in particular the QR scanner since there have been a bunch of exploits involving it in various games.
Yeah, that's what I mentioned before. But still, OP, feel free to try something out and report your findings :)
 

DarkFlare69

Well-Known Member
Member
Joined
Dec 8, 2014
Messages
5,147
Trophies
2
Location
Chicago
XP
4,749
Country
United States
Oh, right. My bad.
I'm sure somebody would have thought of this at some point or another. The system itself would have been the first target, and in particular the QR scanner since there have been a bunch of exploits involving it in various games.
I thought of this a couple years ago and asked some people who knew what they were doing and they said probably not.

Anyway, the QR reader doesn't really "import" (I guess this is the wrong term) any data, all it does is displays a URL. Ninjhax actually tried to put the data from the QR code into the game, as a level.
 
  • Like
Reactions: Deleted-236924

Jack_Sparrow

Ruthless Pirate
Banned
Joined
Nov 17, 2015
Messages
852
Trophies
0
Age
37
Location
The Black Pearl
Website
www.nintendo.com
XP
495
Country
United States
I thought of this a couple years ago and asked some people who knew what they were doing and they said probably not.

Anyway, the QR reader doesn't really "import" (I guess this is the wrong term) any data, all it does is displays a URL. Ninjhax actually tried to put the data from the QR code into the game, as a level.
Exactly this is how MenuHax (Or browserhax? There are too many hax) Works
 

Seriel

Doing her best
Member
Joined
Aug 18, 2015
Messages
3,297
Trophies
3
Age
24
Location
UK
XP
5,982
Country
United Kingdom
afaik, the only (discovered) entrypoint left in the home menu is the notifications applet.
due to an out-of-bounds array index, you can actually ROP from the news module
Anyone thought about working on that some more? :P
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: https://gbatemp.net/profile-posts/163064/