PDA

View Full Version : Exploit in Wii Flash Player



wraggster
July 14th, 2007, 21:14
A security bulletin released 4 days ago by Adobe, tells us that the Flash Player used by the Internet Channel can be exploited to execute arbitrary code because of an input validation error in flash. This might be a opening for hackers to create some kind of homebrew launcher, and Nintendo has to pay to get a unaffected version of the Flash player from Adobe. This means that this security hole might not be patched as fast as the last one. Official bullentin (http://www.adobe.com/support/security/bulletins/apsb07-12.html)

via Wiili.org (http://www.wiili.org/index.php/Main_Page)

DPyro
July 14th, 2007, 21:38
Sweet, let the hacking begin! :D

splodger15
July 14th, 2007, 21:59
I look forward to seeing some homebrew now

ExcruciationX
July 14th, 2007, 23:29
Wii homebrew!

kcajblue
July 14th, 2007, 23:38
thats cool.
itll be better to see more wii homebrew stuff.

Anonymous D
July 14th, 2007, 23:45
lets hope wii homebrew advances on gc homebrew unlike wii games *coughs*

edit : i vote lua player! lol

steve520
July 15th, 2007, 01:16
Its your time to shine hackers lets get some homebrew on the Wii.

bmemike
July 15th, 2007, 02:28
I'd much rather get an update so I know that someone won't be an ass and brick my Wii opposed to an ugly hack (that could be easily patched in the future) for some sparse homebrew.

We simply need a more reliable way to run unsigned code than some flash hole.

philr359
July 15th, 2007, 02:32
I'd much rather get an update so I know that someone won't be an ass and brick my Wii opposed to an ugly hack (that could be easily patched in the future) for some sparse homebrew.

We simply need a more reliable way to run unsigned code than some flash hole.

You've got a point there. This is the first good opportunity, but still I'm waiting for an SD hack to start getting into Wii homebrew

ICE
July 15th, 2007, 02:48
lol so wait. adobe told us theres an exploit so no one had to look? can anyone say dumb??

DPyro
July 15th, 2007, 04:01
It's no different than security companies saying theres holes in Windows...

LilSwish722
July 15th, 2007, 04:13
OF COURSE THERES HOLES IN WINDOWS! See me personally, I think the wholes are intentional...hence the name WINDOWS.

But as to the hack, I'm hopin to run some homebrew on my Wii

prophecy
July 15th, 2007, 05:44
You've got a point there. This is the first good opportunity, but still I'm waiting for an SD hack to start getting into Wii homebrew

i would personally trust this new exploit more than the sd launcher. theres more people out there faking the sd launcher than a flash launcher. just search google theres THOUSANDS of pages about that. plus nintendo probably thought that the sd card would be the first to be hacked so they fixed all the security flaws for the sd drive.

TheLucster
July 15th, 2007, 08:38
Silly Nintendo for not including bug fixes in their contract with Adobe....

Anonymous D
July 15th, 2007, 13:15
they probably have bug fixes , but it wont be as simple as bug fixes for the pc, itll have tpo be tested and all

shadowprophet
July 15th, 2007, 13:28
I cant wait to see what becomes of this.

Anonymous D
July 15th, 2007, 19:44
wasnt there a web browser hole before and no one used it? might have been pc opera though i cnt rly remember

splodger15
July 15th, 2007, 20:07
Yeh but it was patched

mickshake
July 16th, 2007, 01:37
ive been following homebrew on consoles since I got a dreamcast years ago. I've never had anything to offer the homebrew community until now. I've been coding flash since flash 4. I'll be trying every method I know as far as loading data from external sources. If I come across anything weird I'll hand it off to the rest of the brains out there. If anyone wants to share their methods of buffer overflow etc on previous consoles/systems.. I'll shoot all the data I can to flash

What a great day for Wii homebrew!

splodger15
July 16th, 2007, 07:19
^ ^
You could have a try at this Mick there must be a way after the code has excuted you will need to get something to the screen like Hello World

But considering this exploit is in the Flash Player I may look into learning Flash plus I have always wanted another challenge on a different console then the PSP

souLLy
July 16th, 2007, 10:21
It may or may not turn into anything but I'm not gonna be in any rush to update my console from now on.

Details of the exploit are here: http://www.securityfocus.com/archive/1/473655

shadowprophet
July 16th, 2007, 12:56
If we could just open the door to true wii homebrew, This could mean the door to perfect working emulation for several retro consoles.
Imagine paper mario on your wii, without being milked into having to pay for the same game twice.
I would assume the roms would still need to be digitaly signed with whatever crazy new nity signitures are out there though.
unless the homebrew scene saw fit to make its own nes,snes,pc engine, ect emus for the wii.
still, if we can even get java working on the wii, Thats a good step forward.

splodger15
July 16th, 2007, 17:32
I think it is the modchips that killed Wii homebrew we need a leaked Wii SDK then we might get somewere or if someone can reverse engineer it.

PS: Thanks for that link souLLy

Man
July 16th, 2007, 18:47
Iv got my modchip, and run GC homebrew, and im quite happy. But wii homebrew could be awsome

BlueCrab
July 16th, 2007, 19:19
we need a leaked Wii SDK then we might get somewere or if someone can reverse engineer it.A leaked Wii SDK is certainly NOT what we need. It'll just lead to the same situation that occurred with Xbox homebrew, where everything just uses that SDK (and nobody ever bothers to make a worthy replacement).

splodger15
July 16th, 2007, 20:22
Yes but it will come in handy wont it now. What do you reckon we need I think hackers every other console has one but the Wii seems to have been purchased a side

IamAbe
July 18th, 2007, 20:38
A leaked Wii SDK is certainly NOT what we need. It'll just lead to the same situation that occurred with Xbox homebrew, where everything just uses that SDK (and nobody ever bothers to make a worthy replacement).

who has time to make an sdk that already exists?? i was pretty happy with the xbox scene, who cares if we use the official sdk or not

*Layzie*
July 19th, 2007, 21:44
wow id like to see some homebrew on wii for definate

Gold Line
July 19th, 2007, 21:45
homebrew on my wii would be a dream come true

mickshake
July 20th, 2007, 01:48
I started trying different methods of loading data into flash looking for weird behavior..
loadMovie, loadMovieNum, sendAndLoad.. nothing unusual happened.

Then I came across this:
http://www.mindedsecurity.com/en/labs/advisories/flash_remote_flv_exec

Now I really don't know much about overflows but this report gives a fair amount of detail. So I'm here with XVI32 and a few flv files sending the hacked datatype through an flv player without much to report.

I'm still looking for an flv file with a more similar pattern (none of the flv files I have contain the "framerate" var so I can get a little more into it.. if anyone knows much about the structure of an FLV file, thats apparently where we start.

I don't claim to know much at all about this sort of thing, I'm just a determined flash developer ready to give it all I've got!

mickshake
July 20th, 2007, 02:05
I've manage to crash flash... mmm good news?

mickshake
July 20th, 2007, 03:41
and now I've managed to have the wii freeze once the file is loaded... it's just sitting there waiting for a nice tall glass of ice cold homebrew.

ok who wants me to pass the torch?

IndianCheese
July 20th, 2007, 04:32
LMFAO This reminds me of the Flash Professional buffer overflow I found that I never told anyone about...

IndianCheese
July 20th, 2007, 04:58
BTW I found a link to a PoC of the exploit. Go here on your Wii browser:

http://www.henke37.cjb.net/misc/flv/flash_flv_9.0.45.0_exp.html

No, it's not a virus. I got it from here:
http://www.wiili.org/index.php/Executing_Our_Code/Flv_vuln

brasssmunky
July 20th, 2007, 06:45
bwahahahaha, i tried it, my wii froze...
im thinking this is a good thing ready for an exploit.

splodger15
July 20th, 2007, 07:11
Just need a program to run after the exploit has been exceuted