Homebrew RAM editing glitch on any 3DS, might lead to an exploit?

Roboman

Well-Known Member
Member
Joined
Jan 7, 2016
Messages
313
Trophies
0
Age
28
XP
748
Country
United States
I think we can acess arbitrary ram well outside what.this glitch directly allows. What if you change a variable pointer to ram outside the area 0x087E8CECto 0x0CAF8D20 in process 0x29? Arbitrarily writing any data anywhere in rw data is extremely powerful and I think should almost always be able to lead to rop.
 

Seriel

Doing her best
Member
Joined
Aug 18, 2015
Messages
3,298
Trophies
3
Age
24
Location
UK
XP
6,038
Country
United Kingdom
So, a program used to help people learn code, could be exploited to actually run homebrew code. lol :rofl2:
To be fair this was inevitable, they give you the power to run custom code, you just need to break out of those restrictions.
 

MartinDocNewland

Searching for the truth
Member
Joined
Jul 7, 2012
Messages
594
Trophies
0
XP
491
Country
20160630_193609-640x360.jpg
I have a EUR N3DS on Luma3DS with A9HL on latest firmware running smileBASIC 3.3.1 and it doesn't work. All I get is ok afterwards and that's it

Edit:

Here is a photo
 
Last edited by MartinDocNewland,

Trinitro21

Well-Known Member
OP
Member
Joined
Oct 14, 2015
Messages
133
Trophies
0
Location
Userland
XP
206
Country
United States
I have a EUR N3DS on Luma3DS with A9HL on latest firmware running smileBASIC 3.3.1 and it doesn't work. All I get is ok afterwards and that's it

Edit:

Here is a photo
It did work, but you can't see what it did because you didn't offset the layer.
Try these inputs:
Code:
XSCREEN 2
BGSCREEN 0,134217728,16
BGOFS 0,6400*16,0
That sets the screen up, sets the glitch up, and then shows you an interesting bit. You can try other offsets in the third command if you want to explore.
 
  • Like
Reactions: MartinDocNewland

seijinshu

...
Member
Joined
Jan 6, 2016
Messages
483
Trophies
0
Location
...
XP
248
Country
United States
It did work, but you can't see what it did because you didn't offset the layer.
Try these inputs:
Code:
XSCREEN 2
BGSCREEN 0,134217728,16
BGOFS 0,6400*16,0
That sets the screen up, sets the glitch up, and then shows you an interesting bit. You can try other offsets in the third command if you want to explore.
Definitely look promising.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • AncientBoi
  • BakerMan
    I rather enjoy a life of taking it easy. I haven't reached that life yet though.
  • Psionic Roshambo @ Psionic Roshambo:
    Pokemon Black I played that one a lot
  • K3Nv2 @ K3Nv2:
    Honestly never messed with Pokémon on ds much
  • mthrnite @ mthrnite:
    I played pokemon once, was bored, never tried again
  • Psionic Roshambo @ Psionic Roshambo:
    Oh Dragon Quest IX
  • K3Nv2 @ K3Nv2:
    Spent like 5 hours on switch one never touched it again
  • Psionic Roshambo @ Psionic Roshambo:
    Sentinel of the stary skies
  • K3Nv2 @ K3Nv2:
    Ds is 20 years old this year
  • Psionic Roshambo @ Psionic Roshambo:
    So MJ no longer wants to play with it?
  • K3Nv2 @ K3Nv2:
    He put it down when the 3ds came out
  • SylverReZ @ SylverReZ:
    @K3Nv2, RIP Felix does great videos on the PS3 yellow-light-of-death.
  • Jayro @ Jayro:
    Eventhough the New 3DS XL is more powerful, I still feel like the DS Lite was a more polished system. It's a real shame that it never got an XL variant keeping the GBA slot. You'd have to go on AliExpress and buy an ML shell to give a DS phat the unofficial "DS Lite" treatment, and that's the best we'll ever get I'm afraid.
    +1
  • Jayro @ Jayro:
    The phat model had amazingly loud speakers tho.
    +1
  • SylverReZ @ SylverReZ:
    @Jayro, I don't see whats so special about the DS ML, its just a DS lite in a phat shell. At least the phat model had louder speakers, whereas the lite has a much better screen.
    +1
  • SylverReZ @ SylverReZ:
    They probably said "Hey, why not we combine the two together and make a 'new' DS to sell".
  • Veho @ Veho:
    It's a DS Lite in a slightly bigger DS Lite shell.
    +1
  • Veho @ Veho:
    It's not a Nintendo / iQue official product, it's a 3rd party custom.
    +1
  • Veho @ Veho:
    Nothing special about it other than it's more comfortable than the Lite
    for people with beefy hands.
    +1
  • Jayro @ Jayro:
    I have yaoi anime hands, very lorge but slender.
  • Jayro @ Jayro:
    I'm Slenderman.
  • Veho @ Veho:
    I have hands.
  • BakerMan @ BakerMan:
    imagine not having hands, cringe
    +1
  • AncientBoi @ AncientBoi:
    ESPECIALLY for things I do to myself :sad:.. :shy::blush::evil:.... :tpi::rofl2:
    AncientBoi @ AncientBoi: ESPECIALLY for things I do to myself :sad:.. :shy::blush::evil:.... :tpi::rofl2: