Homebrew [33c3] Console Hacking 2016 (3DS/WiiU) talk Dec 27-30: smea, derrek, nedwill, naehrwert

What will Santa Hax bring us this year?

  • Slowhax (arm11 kernelhax)

    Votes: 184 32.1%
  • Soundhax (free primary userland sploit)

    Votes: 183 31.9%
  • Bootrom dump method !!

    Votes: 166 28.9%
  • Something more awesome than the above.

    Votes: 156 27.2%
  • Something nice for the WiiU

    Votes: 178 31.0%
  • Nothing. Ninty will banhammer: 001-1337 "Your use of this speech has been restricted by Nintendo"

    Votes: 80 13.9%
  • This checkbox pleases me

    Votes: 152 26.5%
  • ( ͡° ͜ʖ ͡°)

    Votes: 92 16.0%

  • Total voters
    574
  • Poll closed .

DinohScene

Gay twink catboy
Global Moderator
Joined
Oct 11, 2011
Messages
22,567
Trophies
4
Location
Восторг
XP
22,947
Country
Antarctica
https://fahrplan.events.ccc.de/congress/2016/Fahrplan/events/8344.html

Important details:
Title: Nintendo Hacking 2016: Game Over
Dec 27 (8:30pm German time) 2:30pm EST, 1:30pm CST, 12:30pm MST, 11:30am PST
Room: Saal 2
new info "includes exploits for achieving persistent code execution capabilities and the extraction of secrets from both Wii U and 3DS"

Cheers for sharing.
I just noted down the Nintendo talk, the PS4 talk, the gameboy talk and several other talks.
 

VinsCool

Persona Secretiva Felineus
Global Moderator
Joined
Jan 7, 2014
Messages
14,600
Trophies
4
Location
Another World
Website
www.gbatemp.net
XP
25,228
Country
Canada

Slattz

Easygoing Fairy
Member
Joined
Nov 21, 2015
Messages
1,259
Trophies
1
XP
1,787
Country
Ireland
I honestly think the 3ds wont get a big exploit like a9lh but rather the Wii U will. If there isn't going to be a bootrom dump, it might just be persistent homebrew or something for 3ds. I think the Wii U might get more attention and possible get a coldboot exploit.
 

gkoelho

Well-Known Member
Member
Joined
Apr 16, 2015
Messages
558
Trophies
0
Age
31
XP
346
Country
Brazil
This sounds interesting. Also I think nintendo is planning to expand the 3ds's lifespan so it would be a wonderful time for a bootroom dump. Other than that, there isnt anything that can really change the game aside from keys and a k9hax for 9.2<
 

zoogie

playing around in the end of life
OP
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,000
Country
Micronesia, Federated States of
I'd replace my crappy poll with that if I could. :P Added to OP, nice job.
"persistent code execution capabilities" and "extraction of secrets" imply 3DS bootroms and bootromhax to me. A bootrom exploit is already semi-public (it was discussed on IRC and the like) so I'd say they'll present that.
iirc derrek ruled out the possibility he'd present bootrom stuff on IRC. Need to check my logs.
 
  • Like
Reactions: Alex1234

Aurora Wright

Well-Known Member
Member
Joined
Aug 13, 2006
Messages
1,550
Trophies
3
XP
4,519
Country
Italy
I'd replace my crappy poll with that if I could. :P Added to OP, nice job.

iirc derrek ruled out the possibility he'd present bootrom stuff on IRC. Need to check my logs.
That's weird:
While both have since been the targets of many successful attacks, certain aspects have so far remained uncompromised, including critical hardware secrets.
During this talk, we will present our latest research, which includes exploits for achieving persistent code execution capabilities and the extraction of secrets from both Wii U and 3DS.
There are no "uncompromised hardware secrets" except for the bootrom crypto keys; unless there's some major hardware fail with the AES hardware that allows one to get them without bootrom it has to be bootrom...
 

zoogie

playing around in the end of life
OP
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,000
Country
Micronesia, Federated States of
What was revealed last time they did this conference?
tl'dr
a9lh - self explanatory
memchunkhax2 - downgrades <= 10.3
ntrcardhax - new arm9 sploit <= 10.3. currently needs ak2i and a9 hacked 3ds for flasher.
snshax - userland privilege escalation (am:u). downgrades <=10.1. never implemented.

new browserhax, ironhax part2, menuhax.
That's weird:

There are no "uncompromised hardware secrets" except for the bootrom crypto keys; unless there's some major hardware fail with the AES hardware that allows one to get them without bootrom it has to be bootrom...
Ok, this is what he said (around nov 27 #3dsdev):
[15:10] <Stary[m]> derrek: you know what to do in your ccc talk now
.....
.....
[16:29] <@derrek> yeah no bootrom exploit sry

I guess that doesn't rule out some form of dumping method or other bootrom info.
 
Last edited by zoogie,

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    AncientBoi @ AncientBoi: What the hell was that Syl?