Changes

Jump to navigation Jump to search
Removing direct links to the pirate forum
Line 12: Line 12:  
!  Source
 
!  Source
 
|-
 
|-
| FIFA NDS
+
| [[FIFA NDS]]
 
| Every single FIFA game on the Nintendo DS has been exploited.
 
| Every single FIFA game on the Nintendo DS has been exploited.
 
| Everyone
 
| Everyone
 
| [https://github.com/CTurt/Dara CTurt's Source Code]
 
| [https://github.com/CTurt/Dara CTurt's Source Code]
 
|-
 
|-
| Bangai-O-Sploit
+
| [[Bangai-O-Sploit]]
 
| A ''primary'' entrypoint for the game, ''Bangai-O Spirit'', on the Nintendo DS. This game was successfully exploit through sound.
 
| A ''primary'' entrypoint for the game, ''Bangai-O Spirit'', on the Nintendo DS. This game was successfully exploit through sound.
 
| smealum
 
| smealum
 
| [https://github.com/smealum/bangai-o-sploit Install]
 
| [https://github.com/smealum/bangai-o-sploit Install]
 
|-
 
|-
| NDS-ILH-Save-Exploit
+
| [[NDS-ILH-Save-Exploit]]
 
| "I Love Horses" Nintendo DS save exploit
 
| "I Love Horses" Nintendo DS save exploit
 
| [https://github.com/mojobojo/ mojobojo]
 
| [https://github.com/mojobojo/ mojobojo]
 
| [https://github.com/mojobojo/NDS-ILH-Save-Exploit Install]
 
| [https://github.com/mojobojo/NDS-ILH-Save-Exploit Install]
 
|-
 
|-
| ABR-NDS-SaveExploit
+
| [[ABR-NDS-SaveExploit]]
 
| A stack smash savegame exploit for the game "Asterix Brain Trainer"
 
| A stack smash savegame exploit for the game "Asterix Brain Trainer"
 
| [https://github.com/WemI0/ Weml0]
 
| [https://github.com/WemI0/ Weml0]
 
| [https://github.com/WemI0/ABR-NDS-SaveExploit Install]
 
| [https://github.com/WemI0/ABR-NDS-SaveExploit Install]
 
|-
 
|-
| HaxxStation
+
| [[HaxxStation]]
 
| DS Download Station exploit, allowing one to run any commercial homebrew over from the DS download play application.
 
| DS Download Station exploit, allowing one to run any commercial homebrew over from the DS download play application.
 
| shutterbug2000, Gericom, and Apache Thunder
 
| shutterbug2000, Gericom, and Apache Thunder
| [https://gbatemp.net/threads/haxxstation-ds-download-station-exploit.473648/ See Here]
+
| [https://github.com/Gericom/dspatch See Here]
 
|-
 
|-
| BreakingNews
+
| [[BreakingNews]]
 
| A stack smash savegame exploit for the game "The New York Times: Crossword" resulting from stack buffer overflow (profile slot names).  
 
| A stack smash savegame exploit for the game "The New York Times: Crossword" resulting from stack buffer overflow (profile slot names).  
 
| [[User:ChampionLeake|ChampionLeake]]
 
| [[User:ChampionLeake|ChampionLeake]]
 
| [https://github.com/ChampionLeake/BreakingNews/ Install]
 
| [https://github.com/ChampionLeake/BreakingNews/ Install]
 +
|-
 +
| [[NDS-FC2008-Save-Exploit]]
 +
| A savegame exploit for the game "Führerschein Coach 2008".
 +
| [https://github.com/toombaumarkt/ toombaumarkt]
 +
| [https://github.com/toombaumarkt/NDS-FC2008-Save-Exploit Install]
 
|}
 
|}
      
== TWL/DSi-Enhanced Cart Exploits ==
 
== TWL/DSi-Enhanced Cart Exploits ==
Line 53: Line 57:  
!  Source
 
!  Source
 
|-
 
|-
| The Biggest Losers
+
| [[The Biggest Losers]]
 
| Exploit for The Biggest Loser which runs in DSi mode if you use a real cartridge on a DSi or 3DS system, otherwise, it runs in DS mode.
 
| Exploit for The Biggest Loser which runs in DSi mode if you use a real cartridge on a DSi or 3DS system, otherwise, it runs in DS mode.
 
| st4rk
 
| st4rk
Line 59: Line 63:  
[https://davejmurphy.com/dslink/ WinterMute's dslink]
 
[https://davejmurphy.com/dslink/ WinterMute's dslink]
 
|-
 
|-
| Cookhack
+
| [[Cookhack]]
 
| DSi Cooking Coach exploit
 
| DSi Cooking Coach exploit
 
| WinterMute
 
| WinterMute
Line 65: Line 69:  
[https://davejmurphy.com/dslink/ dslink]
 
[https://davejmurphy.com/dslink/ dslink]
 
|-
 
|-
| Classichack
+
| [[Classichack]]
 
| DSi Classic Word Games exploit
 
| DSi Classic Word Games exploit
 
| WinterMute
 
| WinterMute
Line 71: Line 75:  
[https://davejmurphy.com/dslink/ dslink]
 
[https://davejmurphy.com/dslink/ dslink]
 
|-  
 
|-  
| SystemFlaaw
+
| [[SystemFlaaw]]
 
| The first DSi exclusive cartridge title to be exploited for the game, SystemFlaw
 
| The first DSi exclusive cartridge title to be exploited for the game, SystemFlaw
 
| zoogie
 
| zoogie
Line 78: Line 82:       −
== DSiWare(True DSi-Mode) Exploits ==
+
== DSiWare (True DSi-Mode) Exploits ==
 
These are ARM9 exploits that take over a DSiWare title. They run in the same context that the DSi-Enhanced games do, but with additional SD and NAND access. These exploits are valuable since they can be used to downgrade the console firmware to older versions, or install a persistent exploit such as Unlaunch. You can also run commercial homebrew applications from the SD card. However this doesn't allow any cartridge access.
 
These are ARM9 exploits that take over a DSiWare title. They run in the same context that the DSi-Enhanced games do, but with additional SD and NAND access. These exploits are valuable since they can be used to downgrade the console firmware to older versions, or install a persistent exploit such as Unlaunch. You can also run commercial homebrew applications from the SD card. However this doesn't allow any cartridge access.
   Line 87: Line 91:  
!  Source
 
!  Source
 
|-
 
|-
| Sudokuhax
+
| [[Sudokuhax]]
 
| One of the first DSiWare exploits for the Nintendo DSi on the game SUDOKU by EA. (You must have the 1st version of this game in order to use the exploit as it was patched.
 
| One of the first DSiWare exploits for the Nintendo DSi on the game SUDOKU by EA. (You must have the 1st version of this game in order to use the exploit as it was patched.
 
| TeamTwiizer, yellows8
 
| TeamTwiizer, yellows8
 
| [https://github.com/yellows8/dsi/tree/master/exploits/sudokuhax Install]
 
| [https://github.com/yellows8/dsi/tree/master/exploits/sudokuhax Install]
 
|-
 
|-
| grtpwn
+
| [[grtpwn]]
 
| A Gameloft DSiWare savegame exploit for the game, Guitar Rock Tour!
 
| A Gameloft DSiWare savegame exploit for the game, Guitar Rock Tour!
 
| yellows8
 
| yellows8
 
| [https://github.com/yellows8/dsi/tree/master/exploits/grtpwn Install]
 
| [https://github.com/yellows8/dsi/tree/master/exploits/grtpwn Install]
 
|-
 
|-
| exidiahax
+
| [[exidiahax]]
 
| A Gameloft DSiWare savegame exploit for the game, Legend of Exidia!
 
| A Gameloft DSiWare savegame exploit for the game, Legend of Exidia!
 
| yellows8
 
| yellows8
 
| [https://github.com/yellows8/dsi/tree/master/exploits/exidiahax Install]
 
| [https://github.com/yellows8/dsi/tree/master/exploits/exidiahax Install]
 
|-
 
|-
| fieldrunhax
+
| [[fieldrunhax]]
 
| A Subatomic Studios DSiWare savegame exploit for the game, FIELDRUNNERS!
 
| A Subatomic Studios DSiWare savegame exploit for the game, FIELDRUNNERS!
 
| yellows8
 
| yellows8
 
| [https://github.com/yellows8/dsi/tree/master/exploits/fieldrunhax Install]
 
| [https://github.com/yellows8/dsi/tree/master/exploits/fieldrunhax Install]
 
|-
 
|-
| 4swordhax
+
| [[4swordhax]]
 
| A DSiWare savegame exploit for the game, The Legend of Zelda: Four Swords Anniversary Edition!
 
| A DSiWare savegame exploit for the game, The Legend of Zelda: Four Swords Anniversary Edition!
 
| yellows8
 
| yellows8
 
| [https://github.com/yellows8/dsi/tree/master/exploits/4swordhax Install]
 
| [https://github.com/yellows8/dsi/tree/master/exploits/4swordhax Install]
 
|-
 
|-
| Flipnote( ͡° ͜ʖ ͡°) or ugopwn
+
| [[Flipnote ( ͡° ͜ʖ ͡°)]] and [[ugopwn]]
 
| A Primary entrypoint for the DSiWare Application, Flipnote Studio! This exploit was first exploit by shutterbug2000. Later, WinterMute and fincs released a stable version of the exploit.
 
| A Primary entrypoint for the DSiWare Application, Flipnote Studio! This exploit was first exploit by shutterbug2000. Later, WinterMute and fincs released a stable version of the exploit.
 
| shutterbug2000, WinterMute, fincs, zoogie
 
| shutterbug2000, WinterMute, fincs, zoogie
 
| [https://davejmurphy.com/%CD%A1-%CD%9C%CA%96-%CD%A1/ Install]
 
| [https://davejmurphy.com/%CD%A1-%CD%9C%CA%96-%CD%A1/ Install]
 
|-
 
|-
| UNO*pwn
+
| [[UNO*pwn]]
 
| A DSiWare savegame exploit for the game, UNO, that involves a simple stack buffer overflow within the player's username with the settings functionality of the game!
 
| A DSiWare savegame exploit for the game, UNO, that involves a simple stack buffer overflow within the player's username with the settings functionality of the game!
 
| [[User:ChampionLeake|ChampionLeake]]
 
| [[User:ChampionLeake|ChampionLeake]]
 
| [https://github.com/ChampionLeake/UNO-pwn Install]
 
| [https://github.com/ChampionLeake/UNO-pwn Install]
 
|-
 
|-
| MemoryPit
+
| [[Memory Pit]]
 
| A primary exploit for the DSi that involves the system application "Camera"! All you need is an SD Card to use this exploit.
 
| A primary exploit for the DSi that involves the system application "Camera"! All you need is an SD Card to use this exploit.
| shutterbug2000
+
| shutterbug2000, [[User:ChampionLeake|ChampionLeake]]
| [https://gbatemp.net/threads/memory-pit-a-new-dsi-exploit-for-dsi-camera.539432/ See Here]
+
| [https://github.com/ChampionLeake/BrokenPit See Here]
 
|-
 
|-
| petit-compwner
+
| [[petit-compwner]]
 
| The last string argument of interpreter command "COLSET" is not bounds checked, thus a trivial stack smash can occur if the string is overly long.
 
| The last string argument of interpreter command "COLSET" is not bounds checked, thus a trivial stack smash can occur if the string is overly long.
 
| zoogie
 
| zoogie
 
| [https://github.com/zoogie/petit-compwner/releases Release]
 
| [https://github.com/zoogie/petit-compwner/releases Release]
 +
|-
 +
| [[stylehax]]
 +
| A primary entrypoint, using a use-after-free in Opera 9.50 (which uses WebKit under the hood).
 +
| @0x1337cafe
 +
| [https://github.com/nathanfarlow/stylehax Release], [https://farlow.dev/2023/03/02/hacking-the-nintendo-dsi-browser Writeup]
 
|}
 
|}
   Line 141: Line 150:  
!  Source
 
!  Source
 
|-
 
|-
| RocketLauncher
+
| [[RocketLauncher]]
 
| One of the first ever unlocked ARM7 DSi exploit involving the DS Cart White list in secton 3. This exploit only works on firmwares v1.4!
 
| One of the first ever unlocked ARM7 DSi exploit involving the DS Cart White list in secton 3. This exploit only works on firmwares v1.4!
 
| ApacheThunder, stuckpixel, NoCash, Gericom, and Normmatt
 
| ApacheThunder, stuckpixel, NoCash, Gericom, and Normmatt
| [https://gbatemp.net/threads/announcing-rocketlauncher-the-first-exploit-with-unlocked-arm7.476288/ Writeup]
+
| [https://github.com/ApacheThunder/RocketLauncher source]
 
|}
 
|}
      −
== Bootcode Exploits: ==
+
== Bootcode Exploits ==
    
These exploits gain full SCFG_EXT access rights immediately after powering on the system (right before starting the launcher). These exploits are significantly rare and concrete targets can be the launcher's ''title.tmd''. At the moment, nocash's exploit, ''Unlaunch'' is the only known usable exploit.
 
These exploits gain full SCFG_EXT access rights immediately after powering on the system (right before starting the launcher). These exploits are significantly rare and concrete targets can be the launcher's ''title.tmd''. At the moment, nocash's exploit, ''Unlaunch'' is the only known usable exploit.
Line 158: Line 167:  
!  Source
 
!  Source
 
|-
 
|-
| Unlaunch
+
| [[Unlaunch]]
 
| Possibly one of the first bootcode exploit for the Nintendo DSi! This exploit deals with taking advantage of the launcher's "title.tmd" size as it's not checked, allowing esculated permissions!
 
| Possibly one of the first bootcode exploit for the Nintendo DSi! This exploit deals with taking advantage of the launcher's "title.tmd" size as it's not checked, allowing esculated permissions!
 
| NoCash
 
| NoCash
 
| [https://problemkaputt.de/unlaunch.htm Install & Writeup]
 
| [https://problemkaputt.de/unlaunch.htm Install & Writeup]
 
|-
 
|-
| ARM7 boot ROM code execution
+
| Unnamed modchip
| A method of dumping the ARM7 boot ROM by obtaining unsigned code execution while the ARM7 boot ROM is running, inspired by the [https://www.3dbrew.org/wiki/3DS_System_Flaws#Hardware vector-glitch hack on the 3DS], which has the same vulnerability. Not applicable to the ARM9, sadly.
+
| A modchip that exlploits the bootROMs of the Nintendo DSi. It enables code execution on both cores before boot ROM lockout.
 
| PoroCYon
 
| PoroCYon
| [https://events.hackerspace.gent/en/newline2021/public/events/72 Presentation]
+
| [https://media.ccc.de/v/37c3-11736-nintendo_hacking_2023_2008 37c3 talk], [https://icosahedron.website/@pcy/111676158956228552 video], [https://github.com/dsi-modchip/guide DIY guide]
 
|}
 
|}

Navigation menu