Homebrew [Release] Custom ROP loader HTML

  • Thread starter Thread starter duke_srg
  • Start date Start date
  • Views Views 53,323
  • Replies Replies 165
  • Likes Likes 23
Try to update from the retail card first. Any version between 5.0 and 9.2 will work, you only lose DS profile exploit.
 
Cartridge updates don't include browser file.
That's why I'm still on an old version, I updated using a 4.5 game cartridge (Luigi mansion), and I'm at 4.5.0-5 instead of 4.5.0-7

Some users are still at 4.5.0-0 because they never updated online.


Maybe a reverse-downgrade is possible.
The gateway downgrade pack contains the correct browser version.
Upgrading from 4.5.0-5 to 4.5.0-8 is maybe possible with GW downgrade packs.
Gateway exploit works with 2.x.x

But I don't know all the modified files the downgrade pack contains.
 
Thanks for confirming it works fine.
You installed only the browser cia? (not NVER, you are still on 4.5.0-0 then?)
which version did you choose?

I never installed cia because I don't want to use devmenu, but I guess I'll have to if I want to install the browser only.
 
  • Like
Reactions: Margen67
Yeah, just installed the browser, nothing else - version in System Settings still says 4.5.0-0E
I just asked UpdateCDN to get me stuff up to 4.5.0, so the browser was v2050 from 4.0.0-7, which was 0004003000009D02 for the EUR version.
 
  • Like
Reactions: Cyan
Chiming in here to confirm that this does work on 9.5 (they load, but are not compatible, :/ ). Nice work! Much better than needing to put things on the sdcard on your computer and saves a lot of time in doing so.
 
  • Like
Reactions: Margen67
It now appears that no browser-based ROP loaders work on 9.5.0-23 (update just came out today).
 
,
It now appears that no browser-based ROP loaders work on 9.5.0-23 (update just came out today).
Looks like spider exploit was fixed. There is a small chance that only gadgets offsets was changed.

Ups: Browser version was updated to 1.7585, so at least ROP gadgets offsets was changed. If it crashes with the ROP chain loaded, then we have a chance, if it is not, then most probably the WebKit exploit was finally fixed
 
Just updated index.html to support a bigger ROP payloads. Thanks to MegaSynka to clearify several key things.
However the updated version is not tested at 3DS and only available at Github for now. I'll do the test tonight and update at my site.

More things to come!
 
  • Like
Reactions: Margen67
Just updated index.html to support a bigger ROP payloads. Thanks to MegaSynka to clearify several key things.
However the updated version is not tested at 3DS and only available at Github for now. I'll do the test tonight and update at my site.

More things to come!

If you need to test, tell me :)
I have few consoles at home
 
  • Like
Reactions: Margen67
Updated version proved to work with old short payloads, deployed to the site. Big payload will be tested later when I make one
 
  • Like
Reactions: Margen67
Hey can you try to experiment a little bit with this new exploit that I discovered.

Looks like another Webkit bug. It is not necessary leads to an exploit. Anyway I have no ability to debug such things, only exploiting that is already found by others

2All:
Added AR cheat code loader. Big payload may require a specially formed ROP to align data, will check for more.
 
  • Like
Reactions: Margen67
Updated version proved to work with old short payloads, deployed to the site. Big payload will be tested later when I make one

Why I can't run original build and named ".dat" file on your server? what happened? Is there any limit?
 

Site & Scene News

Popular threads in this forum