Homebrew [33c3] Console Hacking 2016 (3DS/WiiU) talk Dec 27-30: smea, derrek, nedwill, naehrwert

What will Santa Hax bring us this year?

  • Slowhax (arm11 kernelhax)

    Votes: 184 32.1%
  • Soundhax (free primary userland sploit)

    Votes: 183 31.9%
  • Bootrom dump method !!

    Votes: 166 28.9%
  • Something more awesome than the above.

    Votes: 156 27.2%
  • Something nice for the WiiU

    Votes: 178 31.0%
  • Nothing. Ninty will banhammer: 001-1337 "Your use of this speech has been restricted by Nintendo"

    Votes: 80 13.9%
  • This checkbox pleases me

    Votes: 152 26.5%
  • ( ͡° ͜ʖ ͡°)

    Votes: 92 16.0%

  • Total voters
    574
  • Poll closed .

zoogie

playing around in the end of life
OP
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,000
Country
Micronesia, Federated States of
TL;DR Summary of Talk:
  • Soundhax - Excellent, convenient, and free userland primary that hacks the built in sound application with just an MP3 on the sd card. Will be released soon according to nedwill.
  • Fasthax - New arm11 kernel expoit (like memchunkhax, waithax, etc.) also by nedwill. Works on latest firm and should be released soon just like Soundhax. Should allow nfirm downgrading on latest firm when more advanced dsiware injection techniques are released very soon.
  • Method to dump arm9 bootrom detailed by derrek. Hash given as proof. The same technique has been worked on for months already by #Cakey devs, so this will likely take quite a bit more time for a public dump to show up. One benefit of bootrom dumping is faster PC based crypto stuff instead of slow 3ds methods. The second benefit is the next exploit:
  • Sighax - The big one. Flaw discovered in the bootrom's RSA parsing process of the 3ds's firmware partition. This will allow us to sign our own custom firm and no more having to do risky downgrades and 100 step guides to get the OTP. Unfortunately, we need a bootrom dump to implement this and that is an issue, see above bullet point for why. You will also still need a way to actually write to system NAND, and even k11 hax usually isn't enough for that. Hardmod is also an option, but it's expensive and inconvenient. That should always be an option, at least, given sighax itself is unpatchable without hardware revision.
  • Method to dump arm11 bootrom and hash of it given by derrek. This isn't considered important.
(skip yt video ahead to 20:00 for 3ds part of the speech - full talk at link below)

https://media.ccc.de/v/33c3-8344-nintendo_hacking_2016


Last year, this very event produced groundbreaking new 3ds hacks such as arm9loaderhax and memchunkhax2 that really shook up the scene. What will happen this year?
Looks like our 32c3 friend derrek will return, but this time tagging along will be fresh new talent nedwill and Nintendo/Sony scene veteran naehrwert. Gonna be big, so stay tuned!
Day: 2016-12-27
Start time: 20:30 (German time)
Duration: 01:00
Room: Saal 2
Track: Security
Language: en

lecture: Nintendo Hacking 2016
Game Over
game_over_1.png

This talk will give a unique insight of what happens when consoles have been hacked already, but not all secrets are busted yet. This time we will not only focus on the Nintendo 3DS but also on the Wii U, talking about our experiences wrapping up the end of an era. We will show how we managed to exploit them in novel ways and discuss why we think that Nintendo has lost the game.


As Nintendo's latest game consoles, the 3DS and Wii U were built with security in mind.
While both have since been the targets of many successful attacks, certain aspects have so far remained uncompromised, including critical hardware secrets.

During this talk, we will present our latest research, which includes exploits for achieving persistent code execution capabilities and the extraction of secrets from both Wii U and 3DS.

Basic knowledge of embedded systems, CPU architectures and cryptography is recommended, though we will do our best to make this talk accessible and enjoyable to all. We also recommend watching the recording of last year's C3 talk called "Console Hacking - Breaking the 3DS".

opRmcM0.png

LG4Dfi6.png

Courtesy of Julian20
Update6: Jan. 09 - WiiU Summary point removed. Nobody cares.
Update5: Dec. 27 - Youtube recording posted, thanks @Sasori
Update5: Dec. 27 - Event complete
Update4: Dec. 27 - Smealum sighting
Update3: Dec. 26 - Countdown added courtesy of@gnmmarechal
Update2: Dec. 22 - Video links added.
Update1: Dec. 17 - 33c3 Bingo courtesy of @Suiginou
Update0: Dec. 15 - Event date/time and other details.


:arrow: Source
 
Last edited by zoogie,

Alex658

Well-Known Member
Member
Joined
Jun 4, 2010
Messages
1,206
Trophies
1
Age
29
Location
Colombia
XP
1,194
Country
Colombia
This speech last year was what allowed me to finally downgrade my 9.4 second 3ds back into a hackable state :)
Good times.

They really think nintendo has lost the game? They must have something pretty powerful/unpatchable to think that. Because a9lh is already released and nintendo hasn't been able to patch it yet, they must be talking about something else then.
 

Vappy

Well-Known Member
Member
Joined
May 23, 2012
Messages
1,508
Trophies
2
XP
2,613
Country
Neat, but what are the benifits of being able to dump and have bootroms?
https://www.reddit.com/r/3dshacks/c..._the_bootrom/d2alk5r/?st=ivsu8ing&sh=e5654253
topkeknosnek said:
At least the following:
  1. If there's any vulnerabilities in there, it's an even earlier entrypoint that likely won't depend on an OTP dump and risky downgrades.
  2. Every currently missing key. With that, we can call it a day and just use PCs for all 3DS-related crypto. rip xorpads, rip Decrypt9, rip everything that sucks
  3. Easier emulation due to keys; decryption of titles using a 3DS is no longer necessary. I'm looking at you, XDS.
 

Vappy

Well-Known Member
Member
Joined
May 23, 2012
Messages
1,508
Trophies
2
XP
2,613
Country
I believe nedwill's already said he planned to release musichax and slowhax after 33c3, but I could never find a direct quote from him, just other people saying he said it. I'm pretty confident they've got some cool surprises in store, not necessarily as a direct release but certainly for information, since the Wii U and 3DS were both pretty thoroughly covered in previous years. Maybe that elusive boot1 fail0verflow couldn't quite get.
Shame that marcan's potential PS4 presentation apparently isn't happening, supposedly because it was applied for with the same presentation name as this one.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Veho @ Veho:
    I have hands.
  • BakerMan @ BakerMan:
    imagine not having hands, cringe
    +1
  • AncientBoi @ AncientBoi:
    ESPECIALLY for things I do to myself :sad:.. :tpi::rofl2: Or others :shy::blush::evil:
    +1
  • The Real Jdbye @ The Real Jdbye:
    @SylverReZ if you could find a v5 DS ML you would have the best of both worlds since the v5 units had the same backlight brightness levels as the DS Lite unlockable with flashme
  • The Real Jdbye @ The Real Jdbye:
    but that's a long shot
  • The Real Jdbye @ The Real Jdbye:
    i think only the red mario kart edition phat was v5
  • BigOnYa @ BigOnYa:
    A woman with no arms and no legs was sitting on a beach. A man comes along and the woman says, "I've never been hugged before." So the man feels bad and hugs her. She says "Well i've also never been kissed before." So he gives her a kiss on the cheek. She says "Well I've also never been fucked before." So the man picks her up, and throws her in the ocean and says "Now you're fucked."
    +2
  • BakerMan @ BakerMan:
    lmao
  • BakerMan @ BakerMan:
    anyways, we need to re-normalize physical media

    if i didn't want my games to be permanent, then i'd rent them
    +1
  • BigOnYa @ BigOnYa:
    Agreed, that why I try to buy all my games on disc, Xbox anyways. Switch games (which I pirate tbh) don't matter much, I stay offline 24/7 anyways.
    +1
  • AncientBoi @ AncientBoi:
    I don't pirate them, I Use Them :mellow:. Like I do @BigOnYa 's couch :tpi::evil::rofl2:
    +1
  • cearp @ cearp:
    @BakerMan - you can still "own" digital media, arguably easier and better than physical since you can make copies and backups, as much as you like.

    The issue is DRM
    +1
  • cearp @ cearp:
    You can buy drm free games / music / ebooks, and if you keep backups of your data (like documents and family photos etc), then you shouldn't lose the game. but with a disk, your toddler could put it in the toaster and there goes your $60

    :rofl2:
  • cearp @ cearp:
    still, I agree physical media is nice to have. just pointing out the issue is drm
    +1
  • rqkaiju2 @ rqkaiju2:
    i like physical media because it actually feels like you own it. thats why i plan on burning music to cds
  • cearp @ cearp:
    It's nice to not have to have a lot of physical things though, saves space
    +1
  • AncientBoi @ AncientBoi:
    Nor clothes 🤮 . Saves on time, soap, water and money having to wash them. :D
  • SylverReZ @ SylverReZ:
    @rqkaiju2, Physical media is a great source for archiving your data, none of that cloud storage shiz.
    +1
  • AncientBoi @ AncientBoi:
    [squeezes @SylverReZ onto a physical media, then archives you in my old stuff box] :tpi::rofl2::tpi:
    +1
  • BakerMan @ BakerMan:
    guys, should i change my pfp to one of these or keep it the same?
    iu

    iu

    (i guess i could change it to one of my other pfps too, but i just want to see what you guys think first)
  • SylverReZ @ SylverReZ:
    @BakerMan, Up to you.
    SylverReZ @ SylverReZ: @BakerMan, Up to you.