3 ms·
It's an almost stock Tegra X1 reference system. The hacks that got access to the system recently started with a Tegra backdoor/debug option Nvidia and Nintendo
by amaranth 9y ago
It's an almost stock Tegra X1 reference system. The hacks that got access to the system recently started with a Tegra backdoor/debug option Nvidia and Nintendo apparently forgot about.
https://www.youtube.com/watch?v=Ec4NgWRE8ik https://www.youtube.com/watch?v=Ec4NgWRE8ik
- ReverseCold 9y agoVideo TL;DW: - Launch hidden web browser through WiFi Web Auth or the Japanese version of PuyoPuyo Tetris. - Connect to MITM'd WiFi hotspot that has a webkit exploit. - Gain userspace access. - Exploit preload (pl:u) service, it has an array out of bounds read. - Exploit SM service by forgetting to initialize it with your PID, therefore it thinks you are PID 0. - The whole Kernel is mapped into userspace for some reason, can be used as ASLR bypass. - Search Tegra manual for "bypass SMMU" - follow instructions, bypass kernel using the GPU. (35:00, oversimplified here) - Change certain parts of DRAM, PMC, etc, and during wakeup TrustZone will execute whatever. This is fixed past v1.0.0.
- roblabla 9y agoThe Kernel being mapped in userspace isn't actually used in any of the current hacks though. ROhan, the only implemented and public way to get userland Arbitrary Code Execution, uses ASLR leaks in both Webkit and SDB. Kernel being mapped in userspace is interesting for save hacks though, which would allow us to escape out of the webkit process (webkit is limited to 700MB of ram, so escaping into a game process is very much interesting). The SMMU bypass is not usable outside of 1.0.0 for Kernel ACE. They have a carveout that denies DMA access to builtins and kernel, the problem is that in 1.0.0, the Kernel would allocate some objects outside of that carveout. It does allow ACE in any other process though.