Commit Graph

28 Commits

Author SHA1 Message Date
orboditilt
1898ab431f Adds a new rop chain. This embedds a small payload into the ROP which gets executed ("wiiuhaxx_searcher"), this payload searchs for a specifc value beginning at a certain address and expects another, bigger payload directly after this value. This "real" payload will then be executed. 2019-01-10 23:27:08 +01:00
orboditilt
9c7073fa3c Fix a warning for a missing variable 2019-01-08 16:00:16 +01:00
orboditilt
0ec1c42452 Flush the source before copying to codegen. 2019-01-08 15:59:06 +01:00
orboditilt
7896f5733e Add a ropchain type to print the payload_srcaddr. 2019-01-08 15:58:34 +01:00
orboditilt
c4affe4294 Add a new ropchain type which places the payloads directly into memory using ROP. 2019-01-08 15:58:02 +01:00
orboditilt
380fec3ef3 Use a fixed size for copy pasting the code to codegen. 2019-01-08 15:56:31 +01:00
orboditilt
869a2de049 Remove option to set a fixed length inside the loader payload. 2019-01-08 15:54:20 +01:00
orboditilt
ca5121d198 Remove $ROPCHAIN_JS_VAR, use the $generatebinrop variable to generate a binary one an convert it manually. 2019-01-08 15:53:10 +01:00
orboditilt
747c771862 Fix a missing $ 2019-01-07 00:38:26 +01:00
orboditilt
f8882d4f93 Added option to change the ouput of the $ROPCHAIN variable 2019-01-07 00:27:08 +01:00
orboditilt
db836324a6 Removed duplicated line 2019-01-07 00:26:39 +01:00
orboditilt
7413f27041 "function wiiuhaxx_generatepayload()" can now take a fixed length variable. 2019-01-07 00:25:33 +01:00
orboditilt
56c594bda7 The variable "payload_size" can now be controlled globally. 2019-01-07 00:23:40 +01:00
orboditilt
e58e1d902a Fix a link in the README 2019-01-06 18:12:03 +01:00
orboditilt
8619b2c680 The makefile now grabs the coreinit.rpl and converts it to an elf. 2019-01-06 18:10:45 +01:00
yellows8
7c346375f9 Updated README. 2016-01-16 11:18:27 -05:00
yellows8
7ae44716bd Updated README for filepaths. 2016-01-12 15:56:24 -05:00
yellows8
887872a12e Updated README. 2016-01-12 14:29:11 -05:00
yellows8
bd3f3e96bc Added 5.4.0 and 5.5.1. 2016-01-12 12:40:39 -05:00
yellows8
393974884a Updated README. 2015-12-24 20:34:06 -05:00
yellows8
80373c0b9a Added proper documentation. Only set ropchainselect to -1 during init when ropchainselect wasn't set to anything previously. Load the codebin filepaths from a cfg file instead of hard-coding them. 2015-12-24 15:58:28 -05:00
yellows8
f4f5cd63dc Do the payload padding automatically instead of requiring the payload to be already aligned. 2015-12-05 00:52:03 -05:00
yellows8
4a4c13af09 Implemented a loader for loading a payload to fixed-addr codegen+0. 2015-12-04 19:03:57 -05:00
yellows8
77f8e10b00 Added a note that OSSetThreadAffinity() returns an error. 2015-12-02 10:29:07 -05:00
yellows8
d9e2308c88 Updated info/etc for ropgen_OSSwitchSecCodeGenMode so that it's more accurate. 2015-12-01 18:59:16 -05:00
yellows8
74ad2b2018 This ROP can now successfully load+run a code binary. Added some functionality used for debugging, etc. 2015-12-01 17:58:56 -05:00
yellows8
7b1c3df757 Implemented the rest of the ROP. This doesn't actually work atm: it crashes when trying to jump to the loaded codebin. 2015-12-01 10:00:37 -05:00
yellows8
426271972c Initial commit. 2015-11-22 13:08:09 -05:00