back

Nintendo Hacking 2016

Game Over

If you suspend your transcription on amara.org, please add a timestamp below to indicate how far you progressed! This will help others to resume your work!

Please do not press “publish” on amara.org to save your progress, use “save draft” instead. Only press “publish” when you're done with quality control.

Video duration
01:01:19
Language
English
Abstract
This talk will give a unique insight of what happens when consoles have been hacked already, but not all secrets are busted yet.
This time we will not only focus on the Nintendo 3DS but also on the Wii U, talking about our experiences wrapping up the end of an era.
We will show how we managed to exploit them in novel ways and discuss why we think that Nintendo has lost the game.

As Nintendo's latest game consoles, the 3DS and Wii U were built with security in mind.
While both have since been the targets of many successful attacks, certain aspects have so far remained uncompromised, including critical hardware secrets.
During this talk, we will present our latest research, which includes exploits for achieving persistent code execution capabilities and the extraction of secrets from both Wii U and 3DS.

Basic knowledge of embedded systems, CPU architectures and cryptography is recommended, though we will do our best to make this talk accessible and enjoyable to all.
We also recommend watching the recording of last year's C3 talk called "Console Hacking - Breaking the 3DS".

Talk ID
8344
Event:
33c3
Day
1
Room
Saal 2
Start
8:30 p.m.
Duration
01:00:00
Track
Security
Type of
lecture
Speaker
derrek
nedwill
naehrwert
Talk Slug & media link
33c3-8344-nintendo_hacking_2016

Talk & Speaker speed statistics

Very rough underestimation:
134.1 wpm
708.3 spm
While speaker(s) speak(s):
137.4 wpm
726.6 spm
154.5 wpm
805.6 spm
119.7 wpm
637.6 spm
156.2 wpm
831.9 spm
100.0% Checking done100.0%
0.0% Syncing done0.0%
0.0% Transcribing done0.0%
0.0% Nothing done yet0.0%
  

Work on this video on Amara!

Talk & Speaker speed statistics with word clouds

Whole talk:
134.1 wpm
708.3 spm
kernelbasicallybootrompretty3dsusermodethingboot1nicecodebootaddressfirmwaretimerexploitsizememorywiinintendocalltimeexceptionstuffkeyboot0signatureramapplausesyscallinstructionstartobjectjumpsyscallspointvectorsfunctiondatainterestingexecutionflashbytesfreetalkhashheadersetvectorcontrol
While speakers speak:
137.4 wpm
726.6 spm
kernelbasicallybootromprettyusermodethingboot13dsniceaddressbootcodetimerexploitsizefirmwarememorycalltimeexceptionnintendostuffkeyboot0wiisyscallinstructionsignatureramstartsyscallsdatafunctionpointjumpbytesobjectinterestingflashvectorsfreesetheaderhashvectorsafebugssecondoverwrite
nedwill:
154.5 wpm
805.6 spm
timerkernelprettyobjectfreecallheap3dsuserthingsetcontroltimelookedstackvtablebugsexploitspacegoodbunchmemoryreturnfunctionaddresssyscallspulsesecondbasicallyhomebrewfindgamestuffbrowsermallocsizetotallychunkwritepointpivotnegativepointingthreadrangeyearsystemeasyexploitslatest
derrek:
119.7 wpm
637.6 spm
bootrombasicallyboot1firmwareboot3dsexceptionboot0keyramsignaturecodeprettyflashsizevectorsmemoryheadernintendointerestingvectorhashstuffjumpdatapaddingthingnicenandinstructionarm9wiifileimagersaasn.1safecourseexploitresetbootromsprotectedtriggerearlydumpparserbugkeysunprotectedsections
naehrwert:
156.2 wpm
831.9 spm
kernelmodeuseraddresssyscallnicestartthingexploitiosusyscallscodemessagebytestitlewiitimerequestentriesoverwritenumberbootguystalkhoperunningmechanismcalledcallsubmitbufferbasicallybytefunctionpointexecutionqueueconsoletodaypowerpcsafehardsecondrelevantentryphysicalvirtualhexcontrolfull