Hacking CVE-2016-4657 walk-through and intro to browser exploitation

  • Thread starter Deleted User
  • Start date
  • Views 29,569
  • Replies 62
  • Likes 3

AecdArmy

Biscuit#0001
Member
Joined
Jan 4, 2016
Messages
505
Trophies
0
Age
20
Location
The Ninty Ninja HQ
Website
mariebot.tech
XP
595
Country
Australia
Yes, it's a proof of concept, but a critical part of the proof is seeing that the length changed, and I'm not reaching that alert. So this makes me curious exactly what his setup was, if he was reliably having success.

Edit: Okay, now if I set up my server with his exact files freshly unzipped from his github master (not just poc1.html but also his index.html which redirects to it), then I am able to get to the end of the PoC reliably.

Same thing when im using it on my domain instead of localhosting it.
 

ehnoah

Well-Known Member
Member
Joined
Oct 9, 2012
Messages
920
Trophies
0
XP
781
Country
Netherlands
New
Well I understood absolute nothing :D But it was informative and I watched it til the End :X

So the exploit give us access to the Memory Range of the Web Browser? Like we can access 100 MB of the RAM? From there we can try go deeper?
 

gluffl

New Member
Newbie
Joined
Jun 10, 2014
Messages
3
Trophies
0
XP
94
Country
really bad, this was published. now it's a matter of hours or a few days, until it's fixed. IT's also really easy for Nintendo to fix it, just updating a few files of the webkit.
 

ehnoah

Well-Known Member
Member
Joined
Oct 9, 2012
Messages
920
Trophies
0
XP
781
Country
Netherlands
I don't own a Switch (yet). Really really bad, the exploit was made public until an useful hack was developed...

Well that is the reason why I think about buy switch now and keep it. But since there is lot of Hardware Protection I doubt we get any useful without wire cables to the board.
 

empulse

New Member
Newbie
Joined
Oct 27, 2008
Messages
3
Trophies
0
XP
185
Country
United States
Think it was released because there is more coming, has advanced further. already have seen 2 diff emulators load -- no gameplay, but they loaded.
 

koffieleut

Well-Known Member
Member
Joined
Jan 22, 2009
Messages
668
Trophies
1
Age
38
Location
probably at home
XP
1,700
Country
Netherlands
I loved the part where he stated that he was just a noob. On that point I thought that I would understand what he was saying about the code.... I understood like 5% of the story :wacko:
 

McHaggis

Fackin' Troller
Member
Joined
Oct 24, 2008
Messages
1,749
Trophies
0
XP
1,466
Country
The Switch notices and recovers from the exception much like the 3DS used to for non-exploitable vulnerabilities, so I'm skeptical as to how useful this is.
 
  • Like
Reactions: peteruk

studio1b

Well-Known Member
Member
Joined
Mar 14, 2009
Messages
146
Trophies
1
Age
42
Location
NEW YORK CITY
XP
444
Country
United States
this is just the start and this is a great tool that will lead to alot of stuff.

right now we are looking for aes key for dfu mode.

but with this we might be able to hit something that gives us the info we need
to everyone that keeps saying a hack will make they devs run away this is not true at all. every console get a hacked and only effects Sales of the console. so more and more people will buy the console. and just beause some one runs backups don't mean they don't buy games
 

yeddish

Member
Newcomer
Joined
Feb 2, 2016
Messages
23
Trophies
0
Age
44
XP
129
Country
United States
Does fiddler work with this? And what about the public dns's for browsing?
Fiddler will work. It has many of the same basic features that Burp Suite has. Burp Suite is better, though, IMO. It also has a basic free version that will do what is needed for this hack. I would recommend giving it a look.

EDIT: Also, the public DNS works for me for browsing.
 
Last edited by yeddish,

hitodesu

Well-Known Member
Member
Joined
Mar 10, 2017
Messages
136
Trophies
0
Age
24
XP
249
Country
United States
Fiddler will work. It has many of the same basic features that Burp Suite has. Burp Suite is better, though, IMO. It also has a basic free version that will do what is needed for this hack. I would recommend giving it a look.

EDIT: Also, the public DNS works for me for browsing.
If you went to the CVE page on that with the public DNS, did it do a successful run through?
 

chaoskagami

G̷̘̫̍̈́̊̓̈l̴̙͔̞͠i̵̳͊ţ̸̙͇͒̓c̵̬̪̯̥̳͒͌̚h̵̹̭͛̒̊̽̚
Developer
Joined
Mar 26, 2016
Messages
1,365
Trophies
1
Location
↑↑↓↓←→←→BA
Website
github.com
XP
2,248
Country
United States
General chit-chat
Help Users
  • Skelletonike @ Skelletonike:
    link doesn't work
    +2
  • Skelletonike @ Skelletonike:
    1H left, such a slow week.
  • Sonic Angel Knight @ Sonic Angel Knight:
    Okay, I had spaghetti :P
  • SylverReZ @ SylverReZ:
    Hope they made lots of spaget
  • K3N1 @ K3N1:
    Chill dog
  • SylverReZ @ SylverReZ:
    Chilli dog
  • Skelletonike @ Skelletonike:
    Damn, I'm loving the new zelda.
  • xtremegamer @ xtremegamer:
    loving the new zelda, i started a game, it was so fucking good, so i
    am waiting on my friend to get home so we can start a new one together
  • Skelletonike @ Skelletonike:
    I just dislike that they don't let me choose the voices before the game starts. Happened with botw as well, had to change to japanese and restart.
  • K3N1 @ K3N1:
    But the important question is can you choose gender
  • Skelletonike @ Skelletonike:
    Same way you can choose Gerald's gender.
  • Skelletonike @ Skelletonike:
    *Geralt, damn autocorrect.
  • Psionic Roshambo @ Psionic Roshambo:
    But can he be trans? Lol
  • K3N1 @ K3N1:
    Zelda transforms into link
  • Psionic Roshambo @ Psionic Roshambo:
    Link I'm not the princess your looking for.... *Pulls a crying game*
  • K3N1 @ K3N1:
    *skirt up* it's exactly what I always wanted
  • Skelletonike @ Skelletonike:
    Just scanned all my zelda amiibos, took a while but didn't get anything that cool, did get the lon lon ranch hylian fabrics though.
  • Skelletonike @ Skelletonike:
    It was pretty funny when I scanned wolf link and got a shit load of meat.
  • K3N1 @ K3N1:
    @Skelletonike, btw I ran that custom for mgs4 on the deck I'm amazed it got that far in game
  • K3N1 @ K3N1:
    Plug in*
  • K3N1 @ K3N1:
    Your favorite activity
    K3N1 @ K3N1: Your favorite activity