Homebrew Another Web Browser Freeze

loco365

Well-Known Member
OP
Member
Joined
Sep 1, 2010
Messages
5,457
Trophies
0
XP
2,927
Note I'm not using the word "hack" because I doubt it will lead to one, but I was testing out crap on my forum earlier, and one of the drop-down menus crashed it! I thought it was fluke, so I tried it again. Same result! It locked my 3DS up! So, I crashed it for a 3rd time, and pulled out the SD card. Nothing happened. Want instructions?

1. Visit my forum. You DO NOT have to register. http://rhonline.co.cc (and it's safe- don't worry)
2. Browse to the bottom of any page. There is a drop-down menu that says English (American). Tap it. The system should lock up.

I don't think it will lead to an exploit, but I also don't think it uses the same code that is on 3dspwn.webs.com. I'll see if I can get the code for that menu later on.

btw I found out the word "crapper" is in the 3DS dictionary. lol
 

Quincy

Your own personal guitarist :3
Member
Joined
Nov 13, 2008
Messages
1,609
Trophies
1
Age
29
Location
Your house
Website
youtek.net
XP
1,229
Country
Netherlands
Team Fail said:
Note I'm not using the word "hack" because I doubt it will lead to one, but I was testing out crap on my forum earlier, and one of the drop-down menus crashed it! I thought it was fluke, so I tried it again. Same result! It locked my 3DS up! So, I crashed it for a 3rd time, and pulled out the SD card. Nothing happened. Want instructions?

1. Visit my forum. You DO NOT have to register. http://rhonline.co.cc (and it's safe- don't worry)
2. Browse to the bottom of any page. There is a drop-down menu that says English (American). Tap it. The system should lock up.

I don't think it will lead to an exploit, but I also don't think it uses the same code that is on 3dspwn.webs.com. I'll see if I can get the code for that menu later on.

btw I found out the word "crapper" is in the 3DS dictionary. lol
Pulling out the SD card does nothing? Congrats, you just found a COMPLETE system locker
laugh.gif
. Maybe because the browser runs on the OS ARM11.
 

synce

だいこんちゃんのだいふぁん
Member
Joined
Nov 5, 2009
Messages
537
Trophies
0
XP
574
Country
Comoros
Hey something's better than nothing.. Hopefully we can make some progress before the new Love Plus. Goddamn region lock
 

loco365

Well-Known Member
OP
Member
Joined
Sep 1, 2010
Messages
5,457
Trophies
0
XP
2,927
synce said:
Hey something's better than nothing.. Hopefully we can make some progress before the new Love Plus. Goddamn region lock
I'd love to play imports. XD

Anyways, I did a bit more research. And, like 3dspwn, it ISN'T a complete crash. If you have suspended software beforehand, and then remove the SD card, it will say, "The SD card has been removed. Press the Home button." just like the Metroid one.
 

lismati

Speedrunner in practice
Member
Joined
Feb 24, 2010
Messages
373
Trophies
1
Age
26
Location
Yes.
Website
www.wiiplanet.info
XP
659
Country
Poland
Only part of the code was released. I highly doubt the freeze you found will lead to anything, but I'm not a hacker so...
I think that browser hack (if released) would be like payload injection, not a freeze.
 

yifan_lu

@yifanlu
Member
Joined
Apr 28, 2007
Messages
663
Trophies
0
XP
1,671
Country
United States
"3dspwn.webs.com" I can't believe someone took the browser crash I found that I clearly stated is not useful and made a site out of it. I wouldn't spend too much time on the browser. It was outsourced to netfront which used the webkit engine. You would have a better change "exploiting" netfront as webkit is pretty widely used and developed, a hack that would allow control of the system would make any computer using chrome/safari, iPhone, and android phones aviable to be hacked.
 

DeadlyFoez

XFlak Fanboy
Banned
Joined
Apr 12, 2009
Messages
5,920
Trophies
0
Website
DeadlyFoez.zzl.org
XP
2,875
Country
United States
Geirskogul said:
You're not going to be hacking the 3DS with the browser, period. Good effort, though.
You should not go far as to say that. The browser is most likely where the first exploit will take place, but to really gain access to the system there needs to be 2 exploits done, 1 on the browser and 1 for the system itself. Getting the combination of them both to work will be a huge feat in itself especially with no real core knowledge of how the system runs. But it will be the internet browser exploit that will allow people to dumpo the ran with specific contents in it that give hints to how the rest of the system works.
 

Geirskogul

Member
Newcomer
Joined
Aug 25, 2011
Messages
13
Trophies
0
XP
3
Country
United States
DeadlyFoez said:
Geirskogul said:
You're not going to be hacking the 3DS with the browser, period. Good effort, though.
You should not go far as to say that. The browser is most likely where the first exploit will take place, but to really gain access to the system there needs to be 2 exploits done, 1 on the browser and 1 for the system itself. Getting the combination of them both to work will be a huge feat in itself especially with no real core knowledge of how the system runs. But it will be the internet browser exploit that will allow people to dumpo the ran with specific contents in it that give hints to how the rest of the system works.
The browser is run in a sandbox, and no exploit will allow access to direct hardware tasks and processes. Not trying to be pessimistic, but it will not happen through the browser.
 

chyyran

somehow a weeb now.
Developer
Joined
Dec 10, 2009
Messages
2,845
Trophies
1
Location
here
Website
ronnchyran.com
XP
1,076
Country
Canada
yifan_lu said:
"3dspwn.webs.com" I can't believe someone took the browser crash I found that I clearly stated is not useful and made a site out of it. I wouldn't spend too much time on the browser. It was outsourced to netfront which used the webkit engine. You would have a better change "exploiting" netfront as webkit is pretty widely used and developed, a hack that would allow control of the system would make any computer using chrome/safari, iPhone, and android phones aviable to be hacked.
I made the site simply to host the crashing code, because the original site went down. It's there cause it's there, doesn't have to be useful.
 

DeadlyFoez

XFlak Fanboy
Banned
Joined
Apr 12, 2009
Messages
5,920
Trophies
0
Website
DeadlyFoez.zzl.org
XP
2,875
Country
United States
Geirskogul said:
DeadlyFoez said:
Geirskogul said:
You're not going to be hacking the 3DS with the browser, period. Good effort, though.
You should not go far as to say that. The browser is most likely where the first exploit will take place, but to really gain access to the system there needs to be 2 exploits done, 1 on the browser and 1 for the system itself. Getting the combination of them both to work will be a huge feat in itself especially with no real core knowledge of how the system runs. But it will be the internet browser exploit that will allow people to dumpo the ran with specific contents in it that give hints to how the rest of the system works.

The browser is run in a sandbox, and no exploit will allow access to direct hardware tasks and processes. Not trying to be pessimistic, but it will not happen through the browser.

I also believe that the browser is run in a sandbox... but do YOU have any proof of it? It certainly is possible for the hacking to happen through the browser even if in a sandbox, but like I said there would also need to be an exploit in the sandbox which is completely possible knowing how nintendo does it's coding.
QUOTE(Geirskogul @ Sep 14 2011, 08:38 PM) QUOTE(Pippin666 @ Sep 14 2011, 10:57 PM)
Browser + Sandbox, how does one know for sure if the 3DS is not hacked or documented ??

Pip'
You don't have to fucking hack something to know it's boundaries.
Right, you don't have to hack something to know it's boundaries IF it is already well documented, but the 3DS is not publicly well documented, so we are stuck with hacking it to find out.

I take it that you don't have much experience with hacking or coding and that you must be trolling or a script kiddy that thinks he knows all.
 

loco365

Well-Known Member
OP
Member
Joined
Sep 1, 2010
Messages
5,457
Trophies
0
XP
2,927
DeadlyFoez said:
Geirskogul said:
DeadlyFoez said:
Geirskogul said:
You're not going to be hacking the 3DS with the browser, period. Good effort, though.
You should not go far as to say that. The browser is most likely where the first exploit will take place, but to really gain access to the system there needs to be 2 exploits done, 1 on the browser and 1 for the system itself. Getting the combination of them both to work will be a huge feat in itself especially with no real core knowledge of how the system runs. But it will be the internet browser exploit that will allow people to dumpo the ran with specific contents in it that give hints to how the rest of the system works.
The browser is run in a sandbox, and no exploit will allow access to direct hardware tasks and processes. Not trying to be pessimistic, but it will not happen through the browser.
I also believe that the browser is run in a sandbox... but do YOU have any proof of it? It certainly is possible for the hacking to happen through the browser even if in a sandbox, but like I said there would also need to be an exploit in the sandbox which is completely possible knowing how nintendo does it's coding.
I do too, but all apps run on the 3DS have a way to go back to the 3DS mode via the home button. I think, that if it is done correctly and a loophole around the home button is found, anything can boot into 3DS mode.
 

DeadlyFoez

XFlak Fanboy
Banned
Joined
Apr 12, 2009
Messages
5,920
Trophies
0
Website
DeadlyFoez.zzl.org
XP
2,875
Country
United States
Ok, let me just add in this bit of info to put it into perspective about the whole 'sandbox' dilemma.

A few years ago a researcher had found a way to run some code inside of a virtual machine that cause malicious code to be run inside the host OS. Although this is comparing apples to oranges, a virtual machine is certainly one form of sandboxing. All that there needs to be is just one possible exploit in the sandbox and for someone to find it and then unsigned code can be run. It is not an easy task, especially on the 3DS, but I would not be surprised if that is how the first exploit becomes publicly available.
 

ninjaapple

Well-Known Member
Newcomer
Joined
Oct 2, 2010
Messages
97
Trophies
0
XP
102
Country
Chad
DeadlyFoez said:
Ok, let me just add in this bit of info to put it into perspective about the whole 'sandbox' dilemma.

A few years ago a researcher had found a way to run some code inside of a virtual machine that cause malicious code to be run inside the host OS. Although this is comparing apples to oranges, a virtual machine is certainly one form of sandboxing. All that there needs to be is just one possible exploit in the sandbox and for someone to find it and then unsigned code can be run. It is not an easy task, especially on the 3DS, but I would not be surprised if that is how the first exploit becomes publicly available.

hah that would be funny!
the sandbox is meant to stop exploiting the program and having direct access to the system.
if they found an exploit in the sandbox itself hah!
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Materia_tofu @ Materia_tofu:
    im not a very bright individual, but we live and we learn
  • SylverReZ @ SylverReZ:
    @Materia_tofu, We do learn a lot from plenty of talented individuals.
  • Materia_tofu @ Materia_tofu:
    this is true! i learned how to make soundfont remixes from a friend back in 2021
    +1
  • BakerMan @ BakerMan:
    Update on my brother: He's home now, tired and hungry, obviously, but other than that, seems to be doing fine.
    +2
  • Veho @ Veho:
    That's a relief to hear. Do you know what happened?
  • SylverReZ @ SylverReZ:
    @BakerMan, Any idea what happened? I hope that your brother's doing good.
  • BakerMan @ BakerMan:
    Well, from what I've heard from my parents, he had a seizure last night, perhaps an epileptic episode, fucking died, had a near death experience, my dad called the paramedics, they showed up, took him to the hospital, and he woke up covered in tubes, and started complaining.
  • BakerMan @ BakerMan:
    He couldn't eat until after his MRI, when he had a bomb pop.
  • BakerMan @ BakerMan:
    What matters now is that he's doing alright.
  • Veho @ Veho:
    But you still don't know what it was?
  • Veho @ Veho:
    Has he had seizures before?
  • The Real Jdbye @ The Real Jdbye:
    apparently stress can cause seizures, my brother had one during a test once
  • The Real Jdbye @ The Real Jdbye:
    never had one before that, and never had one since
  • Redleviboy123 @ Redleviboy123:
    Question about game texture chanching Do i need an own game id?
  • The Real Jdbye @ The Real Jdbye:
    @Veho for those that want to
    experience being sonic the hedgehog
  • Veho @ Veho:
    Ah, you mean
    furries.
  • The Real Jdbye @ The Real Jdbye:
    well, sonic fans are a whole separate thing from furries
  • The Real Jdbye @ The Real Jdbye:
    like bronys
  • The Real Jdbye @ The Real Jdbye:
    sonic porn is too weird even for me
  • Dumpflam @ Dumpflam:
    bruh
  • Dumpflam @ Dumpflam:
    guys how do i delete a post
  • The Real Jdbye @ The Real Jdbye:
    you don't
  • The Real Jdbye @ The Real Jdbye:
    you can report it and request deletion
    The Real Jdbye @ The Real Jdbye: you can report it and request deletion