Difference between revisions of "DSi exploits"

From DSiBrew
Jump to navigation Jump to search
(DSiWareHax is impossible to copy to the NAND with system settings on the latest system version.)
 
(62 intermediate revisions by 17 users not shown)
Line 1: Line 1:
 
This page is dedicated to the listing of exploits for the Nintendo DSi. Anyone may contribute to this list. This page my not, however be deleted in any way, this ensures that that development of this page is not slowed down. Due to the fact that this page has not changed for over a year due to resets, no more resets.
 
This page is dedicated to the listing of exploits for the Nintendo DSi. Anyone may contribute to this list. This page my not, however be deleted in any way, this ensures that that development of this page is not slowed down. Due to the fact that this page has not changed for over a year due to resets, no more resets.
  
== DSi-mode exploits ==
+
== Type of exploits ==
Team Twiizers had relased a DSi-Mode Exploit called [[Sudokuhax]] that loads a homebrew from the SD card in DSi Mode. The exploit requires that you have purchased the Sudoku by EA game. More details and download at: [http://hackmii.com/2011/01/sudokuhax-release/].
+
Here is a general list of all the different types/terms of exploits to know. This is to know the differences of each exploit.
 +
== NTR/NDS-Mode Exploits ==
 +
These are ARM9 exploits that takes over a NDS-mode cartridge. These cartridges (on the back) are labeled as ''NTR''. These type of exploits are very limited since there's no SD or NAND access. They can be used to run a small binary payload making these exploits almost useless.
  
Team Twiizers also have found a DSi-Mode Exploit and have managed to use it to run DSi Mode homebrew. However it has not yet been released. More details at : [http://hackmii.com/2009/07/dsi-mode-homebrew-anyone/] The additional hardware is just required to get a connection to a computer so that things like ram dumps can be created.
+
{| class="wikitable" border="1"
 +
!  Name
 +
!  Description
 +
!  Author
 +
!  Source
 +
|-
 +
| [[FIFA NDS]]
 +
| Every single FIFA game on the Nintendo DS has been exploited.
 +
| Everyone
 +
| [https://github.com/CTurt/Dara CTurt's Source Code]
 +
|-
 +
| [[Bangai-O-Sploit]]
 +
| A ''primary'' entrypoint for the game, ''Bangai-O Spirit'', on the Nintendo DS. This game was successfully exploit through sound.
 +
| smealum
 +
| [https://github.com/smealum/bangai-o-sploit Install]
 +
|-
 +
| [[NDS-ILH-Save-Exploit]]
 +
| "I Love Horses" Nintendo DS save exploit
 +
| [https://github.com/mojobojo/ mojobojo]
 +
| [https://github.com/mojobojo/NDS-ILH-Save-Exploit Install]
 +
|-
 +
| [[ABR-NDS-SaveExploit]]
 +
| A stack smash savegame exploit for the game "Asterix Brain Trainer"
 +
| [https://github.com/WemI0/ Weml0]
 +
| [https://github.com/WemI0/ABR-NDS-SaveExploit Install]
 +
|-
 +
| [[HaxxStation]]
 +
| DS Download Station exploit, allowing one to run any commercial homebrew over from the DS download play application.
 +
| shutterbug2000, Gericom, and Apache Thunder
 +
| [https://github.com/Gericom/dspatch See Here]
 +
|-
 +
| [[BreakingNews]]
 +
| A stack smash savegame exploit for the game "The New York Times: Crossword" resulting from stack buffer overflow (profile slot names).  
 +
| [[User:ChampionLeake|ChampionLeake]]
 +
| [https://github.com/ChampionLeake/BreakingNews/ Install]
 +
|-
 +
| [[NDS-FC2008-Save-Exploit]]
 +
| A savegame exploit for the game "Führerschein Coach 2008".
 +
| [https://github.com/toombaumarkt/ toombaumarkt]
 +
| [https://github.com/toombaumarkt/NDS-FC2008-Save-Exploit Install]
 +
|-
 +
| [[WordJong-Overflow]]
 +
| A buffer overflow exploit for the game WordJong DS (U).
 +
| [https://github.com/Borgars/ Borgars]
 +
| [https://github.com/Borgars/WordJong-Overflow Install]
 +
|-
 +
| [[CorruptedClues]]
 +
| A stack smash savegame exploit for the game "Cate West: The Vanishing Files", resulted by unchecked string sizes from the highscore data.
 +
| [[User:ChampionLeake|ChampionLeake]]
 +
| [https://github.com/ChampionLeake/CorruptedClues Install]
 +
|}
  
 +
== TWL/DSi-Enhanced Cart Exploits ==
 +
These are ARM9 exploits that take over a enhanced DSi-mode cartridge. These cartridges (on the back) are labeled as ''TWL''. Unfortunately they don't have SD or NAND access but can be used to gather console information and maybe find other vulnerabilities. These exploits can also be used for dslink, which can load homebrew applications via internet connections.
  
Wintermute has made available an open source DSi hack. The exploit works on DSi enhanced games, allowing you to run custom code from a save file. Instructions for using the exploit can be found here: [http://drunkencoders.com/2009/08/dsi-hack-update/]
+
{| class="wikitable" border="1"
 +
!  Name
 +
!  Description
 +
!  Author
 +
!  Source
 +
|-
 +
| [[The Biggest Losers]]
 +
| Exploit for The Biggest Loser which runs in DSi mode if you use a real cartridge on a DSi or 3DS system, otherwise, it runs in DS mode.
 +
| st4rk
 +
| [https://github.com/st4rk/The-Biggest-Loser Install]
 +
[https://davejmurphy.com/dslink/ WinterMute's dslink]
 +
|-
 +
| [[Cookhack]]
 +
| DSi Cooking Coach exploit
 +
| WinterMute
 +
| [https://github.com/WinterMute/savesploits/tree/master/cookhack PoC]
 +
[https://davejmurphy.com/dslink/ dslink]
 +
|-
 +
| [[Classichack]]
 +
| DSi Classic Word Games exploit
 +
| WinterMute
 +
| [https://github.com/WinterMute/savesploits/tree/master/classichack PoC]
 +
[https://davejmurphy.com/dslink/ dslink]
 +
|-  
 +
| [[SystemFlaaw]]
 +
| The first DSi exclusive cartridge title to be exploited for the game, SystemFlaw
 +
| zoogie
 +
| [https://github.com/zoogie/SystemFlaaw Install]
 +
|}
  
If you know of DSiWare that has English-only string input,(high-scores, player name, high-scores that use username from system settings, etc) go [[DSiWare_VulnList|here]].
 
  
== DS-mode exploits ==
+
== DSiWare (True DSi-Mode) Exploits ==
 +
These are ARM9 exploits that take over a DSiWare title. They run in the same context that the DSi-Enhanced games do, but with additional SD and NAND access. These exploits are valuable since they can be used to downgrade the console firmware to older versions, or install a persistent exploit such as Unlaunch. You can also run commercial homebrew applications from the SD card. However this doesn't allow any cartridge access.
  
This type of exploit is undesirable because all DSi functionality, such as usage of the [[cameras]], is unavailable to homebrew.
+
{| class="wikitable" border="1"
 +
!  Name
 +
!  Description
 +
!  Author
 +
!  Source
 +
|-
 +
| [[Sudokuhax]]
 +
| One of the first DSiWare exploits for the Nintendo DSi on the game SUDOKU by EA. (You must have the 1st version of this game in order to use the exploit as it was patched.
 +
| TeamTwiizer, yellows8
 +
| [https://github.com/yellows8/dsi/tree/master/exploits/sudokuhax Install]
 +
|-
 +
| [[grtpwn]]
 +
| A Gameloft DSiWare savegame exploit for the game, Guitar Rock Tour!
 +
| yellows8
 +
| [https://github.com/yellows8/dsi/tree/master/exploits/grtpwn Install]
 +
|-
 +
| [[exidiahax]]
 +
| A Gameloft DSiWare savegame exploit for the game, Legend of Exidia!
 +
| yellows8
 +
| [https://github.com/yellows8/dsi/tree/master/exploits/exidiahax Install]
 +
|-
 +
| [[fieldrunhax]]
 +
| A Subatomic Studios DSiWare savegame exploit for the game, FIELDRUNNERS!
 +
| yellows8
 +
| [https://github.com/yellows8/dsi/tree/master/exploits/fieldrunhax Install]
 +
|-
 +
| [[4swordhax]]
 +
| A DSiWare savegame exploit for the game, The Legend of Zelda: Four Swords Anniversary Edition!
 +
| yellows8
 +
| [https://github.com/yellows8/dsi/tree/master/exploits/4swordhax Install]
 +
|-
 +
| [[Flipnote ( ͡° ͜ʖ ͡°)]] and [[ugopwn]]
 +
| A Primary entrypoint for the DSiWare Application, Flipnote Studio! This exploit was first exploit by shutterbug2000. Later, WinterMute and fincs released a stable version of the exploit.
 +
| shutterbug2000, WinterMute, fincs, zoogie
 +
| [https://davejmurphy.com/%CD%A1-%CD%9C%CA%96-%CD%A1/ Install]
 +
|-
 +
| [[UNO*pwn]]
 +
| A DSiWare savegame exploit for the game, UNO, that involves a simple stack buffer overflow within the player's username with the settings functionality of the game!
 +
| [[User:ChampionLeake|ChampionLeake]]
 +
| [https://github.com/ChampionLeake/UNO-pwn Install]
 +
|-
 +
| [[Memory Pit]]
 +
| A primary exploit for the DSi that involves the system application "Camera"! All you need is an SD Card to use this exploit.
 +
| shutterbug2000
 +
| [https://gbatemp.net/threads/memory-pit-a-new-dsi-exploit-for-dsi-camera.539432 Install], [https://github.com/ChampionLeake/BrokenPit Open-source]
 +
|-
 +
| [[petit-compwner]]
 +
| The last string argument of interpreter command "COLSET" is not bounds checked, thus a trivial stack smash can occur if the string is overly long.
 +
| zoogie
 +
| [https://github.com/zoogie/petit-compwner/releases Release]
 +
|-
 +
| [[stylehax]]
 +
| A primary entrypoint, using a use-after-free in Opera 9.50 (which uses WebKit under the hood).
 +
| @0x1337cafe
 +
| [https://github.com/nathanfarlow/stylehax Release], [https://farlow.dev/2023/03/02/hacking-the-nintendo-dsi-browser Writeup]
 +
|}
  
Blasteh (Blasty) has posted a [http://www.youtube.com/watch?v=7QHO7ctWuZ8 video on Youtube] showing code being run in DS mode on the DSi using [http://en.wikipedia.org/wiki/Fifa_08 Fifa '08].
+
== ARM7 Exploits ==
 +
These exploits take over the ARM7 processor. In the DSi, these processor handles critical operations and cryptography operations, among other things. These exploits are extremely rare and there's no concrete targets. The DSi menu (The Launcher) is known to run in the ARM7 context. At the moment there's only one exploit known as RocketLauncher. These exploits allow FULL ACCESS with the DSi launcher.
 +
{| class="wikitable" border="1"
 +
!  Name
 +
!  Description
 +
!  Author
 +
!  Source
 +
|-
 +
| [[RocketLauncher]]
 +
| One of the first ever unlocked ARM7 DSi exploit involving the DS Cart White list in secton 3. This exploit only works on firmwares v1.4!
 +
| ApacheThunder, stuckpixel, NoCash, Gericom, and Normmatt
 +
| [https://github.com/ApacheThunder/RocketLauncher source]
 +
|}
  
== List of ideas for exploitation/hacking of latest dsi version ==
 
Rules
 
  
→Do not remove ideas, only add
+
== Bootcode Exploits ==
  
→Do not delete this section
+
These exploits gain full SCFG_EXT access rights immediately after powering on the system (right before starting the launcher). These exploits are significantly rare and concrete targets can be the launcher's ''title.tmd''. At the moment, nocash's exploit, ''Unlaunch'' is the only known usable exploit.
  
→If your idea is 'epic' mark it with * [only do this if it will certainly work]
+
{| class="wikitable" border="1"
   
+
!  Name
-A simulator/emulator, like the one for ipod [speeds-up exploition development].
+
!  Description
 
+
!  Author
-A costom headphone jack that plugs into computer [usb] and can access dsi files or softmod it using a computer program.
+
! Source
 
+
|-
-Hack a game download from the dsi store . Replace the file thats downloaded from the dsi store, with a dsi exploiting file, plus the game.
+
| [[Unlaunch]]
 
+
| Possibly one of the first bootcode exploit for the Nintendo DSi! This exploit deals with taking advantage of the launcher's "title.tmd" size as it's not checked, allowing esculated permissions!
-A DSi download-play hack.
+
| NoCash
 +
| [https://problemkaputt.de/unlaunch.htm Install & Writeup]
 +
|-
 +
| Unnamed modchip
 +
| A modchip that exlploits the bootROMs of the Nintendo DSi. It enables code execution on both cores before boot ROM lockout.
 +
| PoroCYon
 +
| [https://media.ccc.de/v/37c3-11736-nintendo_hacking_2023_2008 37c3 talk], [https://icosahedron.website/@pcy/111676158956228552 video], [https://github.com/dsi-modchip/guide DIY guide]
 +
|}

Latest revision as of 17:12, 2 December 2024

This page is dedicated to the listing of exploits for the Nintendo DSi. Anyone may contribute to this list. This page my not, however be deleted in any way, this ensures that that development of this page is not slowed down. Due to the fact that this page has not changed for over a year due to resets, no more resets.

Type of exploits

Here is a general list of all the different types/terms of exploits to know. This is to know the differences of each exploit.

NTR/NDS-Mode Exploits

These are ARM9 exploits that takes over a NDS-mode cartridge. These cartridges (on the back) are labeled as NTR. These type of exploits are very limited since there's no SD or NAND access. They can be used to run a small binary payload making these exploits almost useless.

Name Description Author Source
FIFA NDS Every single FIFA game on the Nintendo DS has been exploited. Everyone CTurt's Source Code
Bangai-O-Sploit A primary entrypoint for the game, Bangai-O Spirit, on the Nintendo DS. This game was successfully exploit through sound. smealum Install
NDS-ILH-Save-Exploit "I Love Horses" Nintendo DS save exploit mojobojo Install
ABR-NDS-SaveExploit A stack smash savegame exploit for the game "Asterix Brain Trainer" Weml0 Install
HaxxStation DS Download Station exploit, allowing one to run any commercial homebrew over from the DS download play application. shutterbug2000, Gericom, and Apache Thunder See Here
BreakingNews A stack smash savegame exploit for the game "The New York Times: Crossword" resulting from stack buffer overflow (profile slot names). ChampionLeake Install
NDS-FC2008-Save-Exploit A savegame exploit for the game "Führerschein Coach 2008". toombaumarkt Install
WordJong-Overflow A buffer overflow exploit for the game WordJong DS (U). Borgars Install
CorruptedClues A stack smash savegame exploit for the game "Cate West: The Vanishing Files", resulted by unchecked string sizes from the highscore data. ChampionLeake Install

TWL/DSi-Enhanced Cart Exploits

These are ARM9 exploits that take over a enhanced DSi-mode cartridge. These cartridges (on the back) are labeled as TWL. Unfortunately they don't have SD or NAND access but can be used to gather console information and maybe find other vulnerabilities. These exploits can also be used for dslink, which can load homebrew applications via internet connections.

Name Description Author Source
The Biggest Losers Exploit for The Biggest Loser which runs in DSi mode if you use a real cartridge on a DSi or 3DS system, otherwise, it runs in DS mode. st4rk Install

WinterMute's dslink

Cookhack DSi Cooking Coach exploit WinterMute PoC

dslink

Classichack DSi Classic Word Games exploit WinterMute PoC

dslink

SystemFlaaw The first DSi exclusive cartridge title to be exploited for the game, SystemFlaw zoogie Install


DSiWare (True DSi-Mode) Exploits

These are ARM9 exploits that take over a DSiWare title. They run in the same context that the DSi-Enhanced games do, but with additional SD and NAND access. These exploits are valuable since they can be used to downgrade the console firmware to older versions, or install a persistent exploit such as Unlaunch. You can also run commercial homebrew applications from the SD card. However this doesn't allow any cartridge access.

Name Description Author Source
Sudokuhax One of the first DSiWare exploits for the Nintendo DSi on the game SUDOKU by EA. (You must have the 1st version of this game in order to use the exploit as it was patched. TeamTwiizer, yellows8 Install
grtpwn A Gameloft DSiWare savegame exploit for the game, Guitar Rock Tour! yellows8 Install
exidiahax A Gameloft DSiWare savegame exploit for the game, Legend of Exidia! yellows8 Install
fieldrunhax A Subatomic Studios DSiWare savegame exploit for the game, FIELDRUNNERS! yellows8 Install
4swordhax A DSiWare savegame exploit for the game, The Legend of Zelda: Four Swords Anniversary Edition! yellows8 Install
Flipnote ( ͡° ͜ʖ ͡°) and ugopwn A Primary entrypoint for the DSiWare Application, Flipnote Studio! This exploit was first exploit by shutterbug2000. Later, WinterMute and fincs released a stable version of the exploit. shutterbug2000, WinterMute, fincs, zoogie Install
UNO*pwn A DSiWare savegame exploit for the game, UNO, that involves a simple stack buffer overflow within the player's username with the settings functionality of the game! ChampionLeake Install
Memory Pit A primary exploit for the DSi that involves the system application "Camera"! All you need is an SD Card to use this exploit. shutterbug2000 Install, Open-source
petit-compwner The last string argument of interpreter command "COLSET" is not bounds checked, thus a trivial stack smash can occur if the string is overly long. zoogie Release
stylehax A primary entrypoint, using a use-after-free in Opera 9.50 (which uses WebKit under the hood). @0x1337cafe Release, Writeup

ARM7 Exploits

These exploits take over the ARM7 processor. In the DSi, these processor handles critical operations and cryptography operations, among other things. These exploits are extremely rare and there's no concrete targets. The DSi menu (The Launcher) is known to run in the ARM7 context. At the moment there's only one exploit known as RocketLauncher. These exploits allow FULL ACCESS with the DSi launcher.

Name Description Author Source
RocketLauncher One of the first ever unlocked ARM7 DSi exploit involving the DS Cart White list in secton 3. This exploit only works on firmwares v1.4! ApacheThunder, stuckpixel, NoCash, Gericom, and Normmatt source


Bootcode Exploits

These exploits gain full SCFG_EXT access rights immediately after powering on the system (right before starting the launcher). These exploits are significantly rare and concrete targets can be the launcher's title.tmd. At the moment, nocash's exploit, Unlaunch is the only known usable exploit.

Name Description Author Source
Unlaunch Possibly one of the first bootcode exploit for the Nintendo DSi! This exploit deals with taking advantage of the launcher's "title.tmd" size as it's not checked, allowing esculated permissions! NoCash Install & Writeup
Unnamed modchip A modchip that exlploits the bootROMs of the Nintendo DSi. It enables code execution on both cores before boot ROM lockout. PoroCYon 37c3 talk, video, DIY guide