Line 54: |
Line 54: |
| | | | | |
| | {{User|PoroCYon}} | | | {{User|PoroCYon}} |
| + | |- |
| + | | [[stage1]] hash verification code is vulnerable to fault injection |
| + | | The [[stage1]] code that verifies the first two SHA1 hashes in the RSA signature appendix (the header hash and the "hash of hashes" redundancy hash) is constructed in such a way that they can be both bypassed with a single injected fault. This makes it possible to exploit both bootroms using a a modchip |
| + | | |
| + | | |
| + | | 2022 |
| + | | nov/dec 2023, see [https://media.ccc.de/v/37c3-11736-nintendo_hacking_2023_2008 37c3 talk] |
| |} | | |} |
| | | |