ROBChain/homebrew/common_defines.py
Maschell dcf3bf5204 Implement a rop chain which loads another ropchain via the network.
Untested, copy pasted from the mario kart 8 exploit (rop gadgets address are meant to be used on EUR v1.1.7)
2020-03-06 19:51:36 +01:00

21 lines
549 B
Python

AF_INET = 2
SOCK_STREAM = 1
IPPROTO_TCP = 6
KERN_HEAP = 0xFF200000
KERN_HEAP_PHYS = 0x1B800000
STARTID_OFFSET = 0x08
METADATA_OFFSET = 0x14
METADATA_SIZE = 0x10
KERN_DRVPTR = 0xFFEAB530
KERNEL_ADDRESS_TABLE = 0xFFEAB7A0
KERN_SYSCALL_TBL_1 = 0xFFE84C70 # unknown
KERN_SYSCALL_TBL_2 = 0xFFE85070 # works with games
KERN_SYSCALL_TBL_3 = 0xFFE85470 # works with loader
KERN_SYSCALL_TBL_4 = 0xFFEAAA60 # works with home menu
KERN_SYSCALL_TBL_5 = 0xFFEAAE60 # works with browser (previously KERN_SYSCALL_TBL)
ADDRESS_main_entry_hook = 0x0101c56c