Hacking Possibly a new exploit?

14Par

Member
OP
Newcomer
Joined
Apr 17, 2021
Messages
14
Trophies
0
Age
25
XP
77
Country
United States
Would it be possible to run code to the switch from Super Smash Bros. Ultimate with a custom game replay (probably not video)? I know you can move videos from smash from the sd card, what about replays or custom replays with data to execute code? Since its an app it has full access to the RAM unlike system apps like the album.
 

lolcatzuru

Well-Known Member
Member
Joined
Apr 20, 2012
Messages
1,464
Trophies
1
XP
2,252
Country
United States
Would it be possible to run code to the switch from Super Smash Bros. Ultimate with a custom game replay (probably not video)? I know you can move videos from smash from the sd card, what about replays or custom replays with data to execute code? Since its an app it has full access to the RAM unlike system apps like the album.


My guess is that it probably wouldn't be possible, as the firmware blocks unsigned code. However if you could enter RCM somehow, maybe.
 

SciresM

Developer
Developer
Joined
Mar 21, 2014
Messages
974
Trophies
3
Age
33
XP
8,317
Country
United States
Would it be possible to run code to the switch from Super Smash Bros. Ultimate with a custom game replay (probably not video)? I know you can move videos from smash from the sd card, what about replays or custom replays with data to execute code? Since its an app it has full access to the RAM unlike system apps like the album.

No, this is not how hacking works, and the switch uses ASLR so memory corruption bugs are useless in non-scripting engines.

Smash bros replays are not a scripting engine.

Also, generally, hacking userland games/applets isn't particularly difficult, it's just pointless because it doesn't enable homebrew because the rest of the OS is secure.

My guess is that it probably wouldn't be possible, as the firmware blocks unsigned code. However if you could enter RCM somehow, maybe.

Entering RCM is trivial on all devices (just short the relevant pins), but this has no security/exploit implications because RCM is secure/not bugged on patched Erista units and Mariko units.
 
Last edited by SciresM,
Joined
Sep 9, 2019
Messages
904
Trophies
1
Location
Switch scene
Website
github.com
XP
2,663
Country
Korea, North
No, this is not how hacking works, and the switch uses ASLR so memory corruption bugs are useless in non-scripting engines.

Smash bros replays are not a scripting engine.

Also, generally, hacking userland games/applets isn't particularly difficult, it's just pointless because it doesn't enable homebrew because the rest of the OS is secure.



Entering RCM is trivial on all devices (just short the relevant pins), but this has no security/exploit implications because RCM is secure/not bugged on patched Erista units and Mariko units.
I keep seeing the no homebrew thing come up because hos is secure but why would that block userland homebrew if someone gains ace in a game? I know lots of homebrew needs full access to services but not everything does. Before b9s I loved playing with userland homebrew on the 3DS, would something like that not be possible on the Switch (excluding fw 3.0.0 since that had access to all services via ro:han)?

Edit: Specifically what I'm asking is what part of hos prevents you from running homebrew in userland unless you can get privileged code execution?
 
Last edited by CompSciOrBust,

SciresM

Developer
Developer
Joined
Mar 21, 2014
Messages
974
Trophies
3
Age
33
XP
8,317
Country
United States
I keep seeing the no homebrew thing come up because hos is secure but why would that block userland homebrew if someone gains ace in a game? I know lots of homebrew needs full access to services but not everything does. Before b9s I loved playing with userland homebrew on the 3DS, would something like that not be possible on the Switch (excluding fw 3.0.0 since that had access to all services via ro:han)?

Edit: Specifically what I'm asking is what part of hos prevents you from running homebrew in userland unless you can get privileged code execution?

You cannot get ACE in a game.

You can get ROP.

The ability to run arbitrary code requires compromising Loader, FS, RO, or the kernel, all of which are secure.
 

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,042
Trophies
2
Age
29
Location
New York City
XP
13,477
Country
United States
Would it be possible to run code to the switch from Super Smash Bros. Ultimate with a custom game replay (probably not video)? I know you can move videos from smash from the sd card, what about replays or custom replays with data to execute code? Since its an app it has full access to the RAM unlike system apps like the album.
Unless you're an experienced hacker, you're not going to discover an exploit by randomly suggesting ideas.
 
  • Like
Reactions: ciaomao

thesjaakspoiler

Well-Known Member
Member
Joined
Nov 20, 2018
Messages
1,013
Trophies
0
Age
124
XP
1,545
Country
Afghanistan
Would it be possible to run code to the switch from Super Smash Bros. Ultimate with a custom game replay (probably not video)? I know you can move videos from smash from the sd card, what about replays or custom replays with data to execute code? Since its an app it has full access to the RAM unlike system apps like the album.
SmashBros is also running inside a secure sandbox, just like the Album app.
What you need is a bug/exploit in the kernel functions that SmashBros uses.
Atmosphere CFW maker MScires said that he thinks everything is pretty much patched at this moment so chances of finding something will be quite difficult.
But as we have seen with the PS3/PS4 it sometimes just takes a while before someone finds something.
 

Deleted member 560282

Well-Known Member
Newcomer
Joined
May 27, 2021
Messages
89
Trophies
0
XP
365
Country
Mexico
Would it be possible to run code to the switch from Super Smash Bros. Ultimate with a custom game replay (probably not video)? I know you can move videos from smash from the sd card, what about replays or custom replays with data to execute code? Since its an app it has full access to the RAM unlike system apps like the album.
No, this is not the Wii anymore
 
  • Like
Reactions: ToxicRadio

soup1

Active Member
Newcomer
Joined
Sep 26, 2020
Messages
38
Trophies
0
XP
218
Country
United Kingdom
SmashBros is also running inside a secure sandbox, just like the Album app.
What you need is a bug/exploit in the kernel functions that SmashBros uses.
Atmosphere CFW maker MScires said that he thinks everything is pretty much patched at this moment so chances of finding something will be quite difficult.
But as we have seen with the PS3/PS4 it sometimes just takes a while before someone finds something.
what do you mean by sandbox?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • HiradeGirl @ HiradeGirl:
    I got stuck in some part.
  • HiradeGirl @ HiradeGirl:
    Anyone played that game?
  • Sicklyboy @ Sicklyboy:
    Only one I played was the DBZ trading card game game on the GBA
  • K3Nv2 @ K3Nv2:
    Sparking zero is looking pretty good but not $70 good
  • HiradeGirl @ HiradeGirl:
    okay
  • BakerMan @ BakerMan:
    isn't sparking zero supposed to be accurate to their canon power too?
  • BakerMan @ BakerMan:
    meaning unlike dbfz a weaker character like nappa wouldn't stand a chance against someone stronger like broly
  • BakerMan @ BakerMan:
    aaalllright then, i guess i should hit the hay
  • K3Nv2 @ K3Nv2:
    People are complaining about flying in it I'm like wut that's half of what it is
    +1
  • BigOnYa @ BigOnYa:
    Surprise surprise, @HiradeGirl is back today
  • BigOnYa @ BigOnYa:
    Alright @SylverReZ you win, lets go double or nothing.
  • cearp @ cearp:
    good morning
    +2
  • O @ Olqase93:
    Hi, I need help whit my r4 r4itt new please
  • AncientBoi @ AncientBoi:
    🛌 Shhhhhhh
  • DinohScene @ DinohScene:
    homebrew your DSi and forgo the flashcard with NDS bootstrap or something along those lines
    +1
  • DinohScene @ DinohScene:
    it allows utilisation of the SD card for ROM storage
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Get a 3DS and do the same 🥰
  • AncientBoi @ AncientBoi:
    Nah. Just get a 3rd [3000 series] gen PSP.
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    I like PSP on my Pi lol
  • Psionic Roshambo @ Psionic Roshambo:
    Gameboy Advanced SP emulator or GASP for short lol
  • RedColoredStars @ RedColoredStars:
    Finally got an appointment with an ENT, but it's not for another month. It's already been 4- days of loud ringing in my left ear, substantial pain on left side of my neck and left side on the back of my head. Doctors here at the regular clinic put me on a couple different meds for a month that did absolutely nothing, then they told me there's nothing more they can do for me despite being in pain and my ear sounding like im underwater and ringing.
  • RedColoredStars @ RedColoredStars:
    Then three chiropractor appointments which also didn't help at all so i didn't go to the 4th. Been trying to get ahold of this ENT clinic out of town for a week and finally got an appointment set up. But its not til the 17th of July so I have to suffer all this shit for nearly another month.
  • RedColoredStars @ RedColoredStars:
    I hope relief from all of this is on the way because I've felt so defeated and severaly lacking in sleep because of the pain and ringing.
    RedColoredStars @ RedColoredStars: I hope relief from all of this is on the way because I've felt so defeated and severaly lacking...