Wii Browser Exploit Found

Opium

PogoShell it to me ™
OP
Former Staff
Joined
Dec 22, 2002
Messages
8,202
Trophies
0
Age
35
Location
Australia
Website
www.gbatemp.net
XP
1,151
Country
Australia








Wii Browser Exploit Found

Opera browser exploit crashes Wii







An Opera browser exploit has been found which crashes the Wii and supposedly would allow the execution of code. No code has yet been run but you can try out the exploit for yourself by pointing your Wii browser to this link.




After details about new Opera vulnerabilities were released, one was tested that crashed the Wii. Here's what the founder, lbradeen, says about the exploit:


QUOTE said:
I saw the new Opera vulnerabilities disclosed yesterday and decided to try them out on my Wii. It seems that the Wii is vulnerable to the createSVGTransformFromMatrix vulnerability as it crashes the system. The disclosure describes the vulnerability as being able to be used to execute code. Don't update your Wii's any time soon!!!


Although this is certainly interesting we advise you not to get too excited, nothing has been done with this exploit so far.



icon11.gif
lbradeen's Website
 

Opium

PogoShell it to me ™
OP
Former Staff
Joined
Dec 22, 2002
Messages
8,202
Trophies
0
Age
35
Location
Australia
Website
www.gbatemp.net
XP
1,151
Country
Australia
It is nice to see that some forms of exploits are being found
smile.gif


I tried out the exploit myself, what it seemed to do was freeze the Opera browser. It no longer responded and the Mouse pointer disappeared and no input from the Wiimote worked. I dunno, perhaps this crash can be exploited.
 

Opium

PogoShell it to me ™
OP
Former Staff
Joined
Dec 22, 2002
Messages
8,202
Trophies
0
Age
35
Location
Australia
Website
www.gbatemp.net
XP
1,151
Country
Australia
Have you seen how much space is available for new channels? Nobody is going to want a wii with just the weather channel so they can run homebrew

To the end user running homebrew code through a browser crash isn't the ultimate goal here. If indeed this browser crash can allow people to run their own homebrew code then they may be able to access Wii system files. Things like dumping the firmware and whatnot are not out of the realm of possibility. From that other exploits can be found.

But this is just speculation of course, providing that the browser crash can actually let you run code.
 

DaRk_ViVi

Sending you back... to the future!
Member
Joined
Apr 13, 2004
Messages
1,110
Trophies
2
Age
36
Location
Asti, Italy
Website
www.darkvivi.it
XP
1,985
Country
Italy
It would be nice to allow new channels to be installed on the Wii, like a "Wii Backup Channel" and "GC Backup Channel" or a "*Insert Homebrew name here* Channel".

Who cares about "Weather Channel"? XD
 

accolon

Well-Known Member
Member
Joined
Oct 29, 2003
Messages
206
Trophies
0
XP
281
Country
Gambia, The
According to heise Security, Opera Software "argues that it is not easy to exploit the heap overflow consistently". "Attackers can specially call the function createSVGTransformFromMatrix to have the browser execute code with the user's rights."

Because of Opera's architecture, using buffer or heap overflows was never very successful with this browser. Additionally, nobody knows what rights the Wii Opera has. Since it does not seem to have access to the flash memory and SD slot (you can't save/load data), it might be hard to use this exploit for anything, even if you could execute your own code.
 

Scorpei

Well-Known Member
Member
Joined
Aug 21, 2006
Messages
1,295
Trophies
0
Website
scorpei.com
XP
263
Country
Netherlands
According to heise Security, Opera Software "argues that it is not easy to exploit the heap overflow consistently". "Attackers can specially call the function createSVGTransformFromMatrix to have the browser execute code with the user's rights."

Because of Opera's architecture, using buffer or heap overflows was never very successful with this browser. Additionally, nobody knows what rights the Wii Opera has. Since it does not seem to have access to the flash memory and SD slot (you can't save/load data), it might be hard to use this exploit for anything, even if you could execute your own code.
Hmm, doesn't it have acces to its own save file? I noticed there was a save file for the browser.....If it does, and if it's big enough and (I like variables
tongue.gif
) it has the proper rights, it should be feasable?

*additional question: Is the browser Wii locked? Can one exchange the binaries between Wii's?
 

flai

Androgynous Apparently :)
Member
Joined
Sep 30, 2006
Messages
850
Trophies
0
Website
Visit site
XP
72
Country
Hmm, I'll give this a go just now.

EDIT - Does work, but expect to see a plethora of Wii viruses in the near future...
 

Scorpei

Well-Known Member
Member
Joined
Aug 21, 2006
Messages
1,295
Trophies
0
Website
scorpei.com
XP
263
Country
Netherlands
General chit-chat
Help Users
    Skelletonike @ Skelletonike: :gun::gun::gun: