Hacking ROP from within IOS_USB (5.5.1)

NexoCube

Well-Known Member
Member
Joined
Nov 3, 2015
Messages
1,222
Trophies
0
Age
29
Location
France
XP
1,340
Country
France
http://pastebin.com/zZhkTX2B

Here is my own IOS_Write32 exploitation, i haven't tested it yet, i'll try with the IOSU_Shutdown(1) syscall

EDIT: There's some little error like at the EOF, i wrote "return ret" instead of "return return_value" and i redeclared ctr after i have performed the IOCTL, i'll fix it once i've tested it ou with the shutdown syscall :P
 
Last edited by NexoCube,

SciresM

Developer
Developer
Joined
Mar 21, 2014
Messages
974
Trophies
3
Age
33
XP
8,314
Country
United States
http://pastebin.com/zZhkTX2B

Here is my own IOS_Write32 exploitation, i haven't tested it yet, i'll try with the IOSU_Shutdown(1) syscall

EDIT: There's some little error like at the EOF, i wrote "return ret" instead of "return return_value" and i redeclared ctr after i have performed the IOCTL, i'll fix it once i've tested it ou with the shutdown syscall :P

Did...did you just copy my implementation of the arbitrary write when literally the first post in this thread contains code that uses the write to get ROP? Hell, you even copied my MEM1 constant with a weird comment about how "it's the only way i managed for it to work".


That comment doesn't even make sense because you can use anywhere in MEM1 if you adjust the pointers, or else just use a temporary allocated buffer on the fly. And the write is just a means to get ROP, so this was outdated as of the second the first post in this thread got made.


What the fuck was the point?
 
Last edited by SciresM,

NexoCube

Well-Known Member
Member
Joined
Nov 3, 2015
Messages
1,222
Trophies
0
Age
29
Location
France
XP
1,340
Country
France
Did...did you just copy my implementation of the arbitrary write when literally the first post in this thread contains code that uses the write to get ROP? Hell, you even copied my MEM1 constant with a weird comment about how "it's the only way i managed for it to work".


That comment doesn't even make sense because you can use anywhere in MEM1 if you adjust the pointers, or else just use a temporary allocated buffer on the fly. And the write is just a means to get ROP, so this was outdated as of the second the first post in this thread got made.


What the fuck was the point?

Yeah, i stole some info with the stuff i got around and about the MEM1 constants, i have a modified libwiiu lib

upload_2016-10-16_13-24-19.png


upload_2016-10-16_13-24-28.png


And i'm sorry you took it like this but i didn't mean to stole your stuff and tell people this is mine !
And thanks you ! You're "ios_write32"pastebin helped me understanding how it works, like really !

And can you tell me please where the SysCall_0x15 address is ? (not the "UND #0x150") The real function, not the handler !

--------------------- MERGED ---------------------------

NexoCube(TM).
nexposed
 
Last edited by NexoCube,

rw-r-r_0644

Well-Known Member
Member
Joined
Jan 13, 2016
Messages
351
Trophies
0
Age
22
XP
741
Country
Italy
Just FIY, saying "syscall 0x15" isn't enough. There's IOS-USB syscall 0x15, IOS-MCP syscall 0x15, IOS-KERNEL syscall 0x15, ...
 

EclipseSin

Ignorant Wizard
Member
Joined
Apr 1, 2015
Messages
2,063
Trophies
1
Age
35
Location
221b Baker Street
XP
1,737
Country
United Kingdom
STMFD SP!, {R4-R6,LR} ; Store Block to Memory
SUB SP, SP, #4 ; Rd = Op1 - Op2
MOV R3, #0 ; Rd = Op2
ADD R4, SP, #0x14+var_10 ; Rd = Op1 + Op2
STR R3, [R4,#-4]! ; Store to Memory
MOV R5, R0 ; Rd = Op2
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • NicoXChan @ NicoXChan:
    Hello there :)
    +1
  • BigOnYa @ BigOnYa:
    Holla
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Dinoh scene is on the scene!
  • Psionic Roshambo @ Psionic Roshambo:
    So don't be mean and keep it clean!
    +1
  • DinohScene @ DinohScene:
    murdering teal and purple in HOMM3
    +2
  • K3Nv2 @ K3Nv2:
    Nah Dinoh psi wants you to destroy his booty
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Ken stop projecting lol
    +2
  • K3Nv2 @ K3Nv2:
    Start rubbing
  • K3Nv2 @ K3Nv2:
    I wonder how many people end up falling in love from customer service
  • Xdqwerty @ Xdqwerty:
    Don't f#ck in front of everyone, geez
  • BigOnYa @ BigOnYa:
    Uremum has the best customer service
    +2
  • K3Nv2 @ K3Nv2:
    Ow 100hp hit out a billion
  • BigOnYa @ BigOnYa:
    That's ironic, last time I went to uremum, I had to take a number, and it was 100
    +1
  • K3Nv2 @ K3Nv2:
    Yes just shows how important you are to her unlike urewife where I can even get ahold her by pager
    +1
  • BigOnYa @ BigOnYa:
    Freaking 97 degrees here now, even my dog went out and turned right back around, like nope!
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Yeah it's a bit warm outside
    +1
  • K3Nv2 @ K3Nv2:
    Florida already misses the hurricanes
  • Psionic Roshambo @ Psionic Roshambo:
    One is supposedly forming in the gulf lol
  • K3Nv2 @ K3Nv2:
    Tell Florida citizens meth is a ac unit in the mouth
  • BigOnYa @ BigOnYa:
    Psi, Did you get any Flooding near you, or is it all south?
  • K3Nv2 @ K3Nv2:
    Why do we need back yard pools it's Florida
    K3Nv2 @ K3Nv2: Why do we need back yard pools it's Florida