Difference between revisions of "DSiWare VulnList"
Jump to navigation
Jump to search
m (Moved bookworm to finished section.) |
|||
Line 33: | Line 33: | ||
! Status | ! Status | ||
! Description | ! Description | ||
− | |||
− | |||
− | |||
− | |||
− | |||
|- | |- | ||
| Escapee Go | | Escapee Go | ||
Line 62: | Line 57: | ||
| High-Scores, names via settings | | High-Scores, names via settings | ||
| Has ASCII high-scores with null terminated strings, no string bugs. | | Has ASCII high-scores with null terminated strings, no string bugs. | ||
+ | |- | ||
+ | | Bookworm | ||
+ | | High-scores and word list | ||
+ | | Has ASCII null-terminated high-score list names and null-terminated word list strings. ( No crash, just nice very high scores, and very long words displayed. ) | ||
|- | |- | ||
| Dracula | | Dracula |
Revision as of 19:19, 21 November 2010
This lists DSiWare that might have vulnerabilities, like strcpy or sprintf from savedata. If you know of DSiWare that has English-only string(high-scores, player name, high-scores that use username from system settings, etc) input, mention it on IRC EFNet #dsidev. Or contact yellowstar 6 at gmail dot com.
DSiWare savedata is extracted and modified with these tools: https://github.com/neimod/dsi
For these lists status "None" means code reversing engineering for the DSiWare wasn't started. Status "Started" means code reversing engineering for that DSiWare was started. Status "Done" means code reverse engineering was finished.
DSiWare that can be crashed
Name | Input type(s) | Status | Description |
---|---|---|---|
Dark Void Zero | High-Scores | Done | No limit on length of drawn record names, no vuln with high-scores. The level var from savedata doesn't have any bounds check, this is used with array indexes. This is not exploitable since the array structs only contain char* strings and other fields, and that var is used with level class init. Level class init fail is most likely the cause of the crash which isn't exploitable, level paths are determined by if statements and the level object is used uninitialized when the level var is out-of-bounds. |
Frogger Returns | High-scores | Started | Has ASCII null-terminated high-scores. Manged to crash this game. The high-score draw function uses strcpy to copy the records' name to a static buffer, it's unknown if this is exploitable. |
DSiWare with incomplete analysis
Name | Input type(s) | Status | Description |
---|---|---|---|
Escapee Go | None | Started | Has high-scores without names, scores are ASCII null-terminated strings. Managed to semi-crash this, but system reset still worked so this probably isn't exploitable. |
Legends of Exidia | Player name | None | Has ASCII player name in one file, and UCS-2 player name in a profile file. ( Even though checksum was figured out, the game does further data validtion, and deleted the hacked save. ) |
DSiWare with finished analysis
Name | Input type(s) | Description |
---|---|---|
Arcade Hoops Basketball | High-Scores, names via settings | Has ASCII high-scores with null terminated strings, no string bugs. |
Bookworm | High-scores and word list | Has ASCII null-terminated high-score list names and null-terminated word list strings. ( No crash, just nice very high scores, and very long words displayed. ) |
Dracula | No manual input | Savedata contains ASCII high-scores from DSi username, and ASCII perks/powerups. High-scores doesn't have string bugs. |
Paul's Shooting Adventure | High-Scores | Records are entered when you complete the game, names are ASCII strings null-terminated. Not exploitable. |
DSiWare that probably don't have vulnerabilities
Name | Input type(s) | Description |
---|---|---|
24/7 Solitaire | None | No high-scores or string input. |
Aquia: Art Style Series | None | No strings |
Brain Age Express: Arts & Letters | None | No strings in savedata. |
Brain Age Express: Math | None | No strings in savedata. |
Dr. Mario Express | None | No strings |
FIZZ | High-scores | Savedata contains ASCII high-scores, but all the high-scores are contained in the same string without a null terminator. A vuln is unlikely. |
Gene Labs | None | Small savedata with no strings. |
Paper Airplane Chase | None | The size of both files in the savedata are only 8 bytes, no strings. |
Photo Clock | None | Small savedata, no strings at all. |
Photo Dojo | Handwritten character name via stylus | Savedata only contains .jpg files and some tiny "save"/"info" files. |
WarioWare: Snapped | None | No high-scores or string input. |