Profile cover photo
Profile photo
Rudolf Marek
161 followers
161 followers
About
Rudolf Marek's posts

Post has attachment

Post has attachment
If you are in New York, Washington or Balitimore in April don't miss Jára Cimrman, the forgotten Czech (fictional) genius and his performances. It starts tomorrow in New York and it is free of charge.

More on http://cimrman-in-america.com/

Post has attachment

Post has attachment

Post has attachment

Keyshuffling Attack for Persistent Early Code Execution in the Nintendo 3DS Secure Bootchain

https://github.com/Plailect/keyshuffling

Abstract

We demonstrate an attack on the secure bootchain of the Nintendo 3DS in order to gain early code execution. The attack utilizes the block shuffling vulnerability of the ECB cipher mode to rearrange keys in the Nintendo 3DS's encrypted keystore. Because the shuffled keys will deterministically decrypt the encrypted firmware binary to incorrect plaintext data and execute it, and because the device's memory contents are kept between hard reboots, it is possible to reliably reach a branching instruction to a payload in memory. This payload, due to its execution by a privileged processor and its early execution, is able to extract the hash of hardware secrets necessary to decrypt the device's encrypted keystore and set up a persistant exploit of the system.



Post has attachment

Post has attachment

Post has attachment

Post has attachment
Wait while more posts are being loaded