Hacking Want to learn how to find exploit

delicator

Member
OP
Newcomer
Joined
Mar 10, 2010
Messages
23
Trophies
0
XP
186
Country
France
Yes, I know, it's a bit large :)

But, I'm a dev, I'm curius, and I want to learn.

I read wiki and topic in here.

I search precise info about method to search somethink like save exploit, like zelda for 3ds, or even old one like Zelda on wii, or some lego game.

Have you some link or ressources ?

Thanks


edit : reading now http://3dbrew.org/wiki/Savegames
http://dsibrew.org/wiki/DSiWare_VulnList
 
  • Like
Reactions: sonic2756

CIAwesome526

Im ugly and im proud
Member
Joined
Mar 25, 2014
Messages
1,242
Trophies
0
Location
The Lake, Kalos Region
XP
906
Country
United States
It's not that simple. Maybe you can start by finding different ways to crash your 3DS, but you'll have to modify something first. Maybe d what gateway did and modify some saves, spider exploit is done and patched, so no servers made to crash your ds. It's not easy, or else everyone would do it.
 

Duo8

Well-Known Member
Member
Joined
Jul 16, 2013
Messages
3,613
Trophies
2
XP
3,032
Country
Vietnam
"Find an exploit" is too broad. You'll at least want to devise some feasible attack vector first, then try to follow it.
 

delicator

Member
OP
Newcomer
Joined
Mar 10, 2010
Messages
23
Trophies
0
XP
186
Country
France
"Find an exploit" is too broad. You'll at least want to devise some feasible attack vector first, then try to follow it.
Yes,
I will like search in forged save type of attack

In the cubic ninja, it's by QRcode, so I imagine, some function decode and parse the QR, with a vulnerability in memory managment or similar
 

delicator

Member
OP
Newcomer
Joined
Mar 10, 2010
Messages
23
Trophies
0
XP
186
Country
France
It's not that simple. Maybe you can start by finding different ways to crash your 3DS, but you'll have to modify something first. Maybe d what gateway did and modify some saves, spider exploit is done and patched, so no servers made to crash your ds. It's not easy, or else everyone would do it.
I think about modify amiibo data (I read it with my phone to see what inside ^^), but amiboo are read only in game, and I don't have retail game using amiibo on 3ds. And why not see what it can be done with custom theme for n3ds
 

Duo8

Well-Known Member
Member
Joined
Jul 16, 2013
Messages
3,613
Trophies
2
XP
3,032
Country
Vietnam
Yes,
I will like search in forged save type of attack

In the cubic ninja, it's by QRcode, so I imagine, some function decode and parse the QR, with a vulnerability in memory managment or similar
If you want to exploit saves remember that only old games (pre 2.x) can have its save decrypted and reencrypted. And you can only inject a ROP chain.
I suggest disassembling the game's binary to see how the save is read, since we don't have a complete emulator yet.

As for ninjhax, the QR code is also a ROP chain.
 
  • Like
Reactions: delicator

delicator

Member
OP
Newcomer
Joined
Mar 10, 2010
Messages
23
Trophies
0
XP
186
Country
France
amiibo data is encrypted
I have 5 fields : type of tag, techno available, serial number, ATQA and SAK, when I tried to read memory, the app I'm using can support this type of tag.
But, it's mostly by curiosity, it's my child link amiibo for smash bros, I can't damage it ^^

I'll be reading about save game, it's good start I think
 

Duo8

Well-Known Member
Member
Joined
Jul 16, 2013
Messages
3,613
Trophies
2
XP
3,032
Country
Vietnam
I have 5 fields : type of tag, techno available, serial number, ATQA and SAK, when I tried to read memory, the app I'm using can support this type of tag.
But, it's mostly by curiosity, it's my child link amiibo for smash bros, I can't damage it ^^

I'll be reading about save game, it's good start I think
Amiibo data is encrypted, signed and write protected (varies between pages).
Someone disassembled the amiibo module: https://www.reddit.com/r/amiibros/comments/328hqz/amiibo_encryption_reverseengineering/
 

delicator

Member
OP
Newcomer
Joined
Mar 10, 2010
Messages
23
Trophies
0
XP
186
Country
France
If you want to exploit saves remember that only old games (pre 2.x) can have its save decrypted and reencrypted. And you can only inject a ROP chain.
I suggest disassembling the game's binary to see how the save is read, since we don't have a complete emulator yet.

As for ninjhax, the QR code is also a ROP chain.

For the other reader of the thread (and me of course ^^) http://en.wikipedia.org/wiki/Return-oriented_programming

For the old game, what changed ? The signature/cryting method ?
Can I find a list of before/after game ?
 

Duo8

Well-Known Member
Member
Joined
Jul 16, 2013
Messages
3,613
Trophies
2
XP
3,032
Country
Vietnam
For the other reader of the thread (and me of course ^^) http://en.wikipedia.org/wiki/Return-oriented_programming

For the old game, what changed ? The signature/cryting method ?
Can I find a list of before/after game ?
Very old 3DS games have a flaw that allows you to calculate the decrypted data. More info here http://3dbrew.org/wiki/Savegames#Repeating_CTR_Fail
Those may or may not have the data signed. I don't remember. If they do then you need a hacked 3DS to sign the save.
As for the version, your best bet is to check the game's SDK version.
 
  • Like
Reactions: delicator

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Psionic Roshambo @ Psionic Roshambo:
    Also a food allergy study would be a good idea
  • K3Nv2 @ K3Nv2:
    Turns out you can't sprinkle methamphetamine on McDonald's French fries
    +1
  • ZeroT21 @ ZeroT21:
    they wouldn't be called french fries at that point
    +1
  • ZeroT21 @ ZeroT21:
    Probably just meth fries
    +1
  • K3Nv2 @ K3Nv2:
    White fries hold up
    +1
  • The Real Jdbye @ The Real Jdbye:
    @K3Nv2 sure you can
  • BakerMan @ BakerMan:
    why tf do people hate android users? is it the video quality? just because "AnDrOiD = pOoR" bc they don't cost an arm and a leg like iphones do?
    +1
  • BakerMan @ BakerMan:
    i won't be turned off by an iphone, but don't pick on me for having an android, that's just how this shit should work
  • ZeroT21 @ ZeroT21:
    Should say more what these kind of android users say bout nokia 3310 users
  • BigOnYa @ BigOnYa:
    I've owned both iPhone and Androids over the years. Both are just as good, other than Apples higher price. I'm currently on Android, Samsung S21 I think, and very happy with it.
  • K3Nv2 @ K3Nv2:
    Got my 60 minute steps in whew
    +2
  • BigOnYa @ BigOnYa:
    I get mine in everyday, going back n forth to the fridge for a beer.
    +1
  • K3Nv2 @ K3Nv2:
    6,000 steps in so far legs almost broke getting off
    +1
  • K3Nv2 @ K3Nv2:
    Your mind gets in a werid pattern of just finishing then when you're done you're like I need a soda
  • BigOnYa @ BigOnYa:
    You get a "walkers" high?
  • K3Nv2 @ K3Nv2:
    Not really I just use to love building up a sweat
  • BigOnYa @ BigOnYa:
    Funny, that's what uremum always says
  • K3Nv2 @ K3Nv2:
    Yeah and people that take viagra think they have a big dick
    +1
  • K3Nv2 @ K3Nv2:
    You cant fix one insult edit for another edit you pog
  • BigOnYa @ BigOnYa:
    Nuh I'm on my tablet n it always auto corrects me
  • K3Nv2 @ K3Nv2:
    Heorin and uremum do have close quarters
  • Sonic Angel Knight @ Sonic Angel Knight:
    BIG CHICKEN :P
    K3Nv2 @ K3Nv2: https://youtu.be/q855tNpvDoQ?si=Tl57KMjiVjyBherB +1