Hacking CVE-2016-4657 walk-through and intro to browser exploitation

  • Thread starter Deleted User
  • Start date
  • Views 30,893
  • Replies 62
  • Likes 3

AecdArmy

Biscuit#0001
Member
Joined
Jan 4, 2016
Messages
505
Trophies
0
Age
21
Location
The Ninty Ninja HQ
Website
mariebot.tech
XP
605
Country
Australia
Yes, it's a proof of concept, but a critical part of the proof is seeing that the length changed, and I'm not reaching that alert. So this makes me curious exactly what his setup was, if he was reliably having success.

Edit: Okay, now if I set up my server with his exact files freshly unzipped from his github master (not just poc1.html but also his index.html which redirects to it), then I am able to get to the end of the PoC reliably.

Same thing when im using it on my domain instead of localhosting it.
 

ehnoah

Well-Known Member
Member
Joined
Oct 9, 2012
Messages
918
Trophies
0
XP
781
Country
Netherlands
New
Well I understood absolute nothing :D But it was informative and I watched it til the End :X

So the exploit give us access to the Memory Range of the Web Browser? Like we can access 100 MB of the RAM? From there we can try go deeper?
 

gluffl

New Member
Newbie
Joined
Jun 10, 2014
Messages
3
Trophies
0
XP
104
Country
really bad, this was published. now it's a matter of hours or a few days, until it's fixed. IT's also really easy for Nintendo to fix it, just updating a few files of the webkit.
 

ehnoah

Well-Known Member
Member
Joined
Oct 9, 2012
Messages
918
Trophies
0
XP
781
Country
Netherlands
I don't own a Switch (yet). Really really bad, the exploit was made public until an useful hack was developed...

Well that is the reason why I think about buy switch now and keep it. But since there is lot of Hardware Protection I doubt we get any useful without wire cables to the board.
 

empulse

New Member
Newbie
Joined
Oct 27, 2008
Messages
3
Trophies
0
XP
185
Country
United States
Think it was released because there is more coming, has advanced further. already have seen 2 diff emulators load -- no gameplay, but they loaded.
 

koffieleut

Well-Known Member
Member
Joined
Jan 22, 2009
Messages
686
Trophies
1
Age
39
Location
probably at home
XP
1,896
Country
Netherlands
I loved the part where he stated that he was just a noob. On that point I thought that I would understand what he was saying about the code.... I understood like 5% of the story :wacko:
 

McHaggis

Fackin' Troller
Member
Joined
Oct 24, 2008
Messages
1,749
Trophies
0
XP
1,466
Country
The Switch notices and recovers from the exception much like the 3DS used to for non-exploitable vulnerabilities, so I'm skeptical as to how useful this is.
 
  • Like
Reactions: peteruk

studio1b

Well-Known Member
Member
Joined
Mar 14, 2009
Messages
146
Trophies
1
Age
43
Location
NEW YORK CITY
XP
444
Country
United States
this is just the start and this is a great tool that will lead to alot of stuff.

right now we are looking for aes key for dfu mode.

but with this we might be able to hit something that gives us the info we need
to everyone that keeps saying a hack will make they devs run away this is not true at all. every console get a hacked and only effects Sales of the console. so more and more people will buy the console. and just beause some one runs backups don't mean they don't buy games
 

yeddish

Active Member
Newcomer
Joined
Feb 2, 2016
Messages
25
Trophies
0
Age
45
XP
146
Country
United States
Does fiddler work with this? And what about the public dns's for browsing?
Fiddler will work. It has many of the same basic features that Burp Suite has. Burp Suite is better, though, IMO. It also has a basic free version that will do what is needed for this hack. I would recommend giving it a look.

EDIT: Also, the public DNS works for me for browsing.
 
Last edited by yeddish,

hitodesu

Well-Known Member
Member
Joined
Mar 10, 2017
Messages
136
Trophies
0
Age
25
XP
259
Country
United States
Fiddler will work. It has many of the same basic features that Burp Suite has. Burp Suite is better, though, IMO. It also has a basic free version that will do what is needed for this hack. I would recommend giving it a look.

EDIT: Also, the public DNS works for me for browsing.
If you went to the CVE page on that with the public DNS, did it do a successful run through?
 

chaoskagami

G̷̘̫̍̈́̊̓̈l̴̙͔̞͠i̵̳͊ţ̸̙͇͒̓c̵̬̪̯̥̳͒͌̚h̵̹̭͛̒̊̽̚
Developer
Joined
Mar 26, 2016
Messages
1,365
Trophies
1
Location
↑↑↓↓←→←→BA
Website
github.com
XP
2,287
Country
United States

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Xdqwerty @ Xdqwerty:
    I only drank alcohol once and it was by accident
  • Xdqwerty @ Xdqwerty:
    I didnt know it was beer, it was on a juice bottle
  • SylverReZ @ SylverReZ:
    Yeah, I'm addicted to smoking, sadly. It's very addictive but I wish I didn't start.
  • K3Nv2 @ K3Nv2:
    May just order a 5700g for a nas/emulation set up tbh
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, atleast you were asleep on 4/20
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, you played that Mario flash game called Mario 63?
  • SylverReZ @ SylverReZ:
    @Xdqwerty, No, but I've seen it on Vinesauce's stream.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, that game is one of the reasons i met newgrounds bc the full versión of it is in that site
  • Xdqwerty @ Xdqwerty:
    Also somebody is remaking it
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, the other game where I found newgrounds is new york shark
    +1
  • SylverReZ @ SylverReZ:
    Spoke to Tom Fulp the other day, if he can find his old Newgrounds site content like the mini Flash animations from the 2000's that played on the portal.
  • SylverReZ @ SylverReZ:
    So far no response, but he did say that he'll find them. Wayback Machine doesn't have em.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, atleast the 1999 versión of pico's school is avaliable (the difference between it, the 2006 versión and the 2016 versión is that the speed of the game depends of the speed of your computer and that it had the og soundtrack)
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Another being Pico VS Bear, the original 1999 version before Jim Henson filed a DMCA takedown.
    +1
  • Xdqwerty @ Xdqwerty:
    The 2006 versión was made when the flash portal was made
  • SylverReZ @ SylverReZ:
    Many people thought it was lost, but was discovered that he hid it on the same page.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, although the "secrets" system where the game was has been removed. Also pico vs uberkids had a netplay versión that was shutdown, although the swf file has been found
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Nope. There are two download buttons on the same page, where you can download the original under a file called "bear.exe". "bear2.exe", however, is the updated game in a Flash projector. P.s. this was on the archived Pico page from 2000.
  • SylverReZ @ SylverReZ:
    @Xdqwerty, That's been there for a long time, too. People who search for lost media don't look hard enough lmao.
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, also the pico 2 demos used to be only for the newgrounds patrons but they are on internet archive too (https://archive.org/download/picos_school_2)
    +1
  • Xdqwerty @ Xdqwerty:
    Iirc the demos were removed from newgrounds in 2022
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, or well only the demo with mindchamber's style was on newgrounds
    +1
    Xdqwerty @ Xdqwerty: @SylverReZ, or well only the demo with mindchamber's style was on newgrounds +1