Exploiting DNS response parsing on the Wii U
garyodernichts.blogspot.com
garyodernichts.blogspot.com
Since the Nintendo servers shut down, hacks have been the only way to play Wii games online - and this one is by far the easiest to use. Just change your DNS servers and you can play online again!
https://wiimmfi.de/patcher/dnspatch
There’s still a thriving Mario Kart Wii scene because of this! You can play Mario Kart online basically any time. I’d bet there are hundreds of players online right now (really brings home just how large the human population is…). Here are the current online stats: https://wiimmfi.de/stat?m=8
When you try to connect to the Nintendo WFC using this DNS server, the DNS redirects your login request to Wiimmfi instead. Wiimmfi then uses a specially crafted SSL certificate which some games consider valid due to an IOS bug, and then lets you go online.
After you are online, Wiimmfi is using a different bug in Mario Kart Wii in order to send and execute the rest of the Mario-Kart-specific Wiimmfi patches to your game, which is what happens during the loading screen when you are online.
Pretty interesting that they made the same naive implementation mistakes when it comes to message compression and the bytewise pointers resolution.
A simple fix for that is something like only accepting pointers that point to a lower position and never to a higher one, to prevent stack overflows and buffer overflows for the parsed label arrays.
Wouldn't the simpler fix be to perform bounds checking before writing to any buffer?
That said, I'd guess this is related to the use of string/array deserialization facilities that are either more general than the DNS parser or were copy/pasted from a domain that makes different assumptions re: the safety and inbound data provenance.
At the very least (beyond the extra TCP DNS fields) you need to ignore/drop the two UDP DNS requests the Wii U makes before failing to TCP.
See https://github.com/GaryOderNichts/DNSpresso#instructions
So, how does the author got hold of Wii's code, is it publicly available or was it some kind of reverse engineering?
After reverse engineering parts of the Wii Us' NET stack for another project I was working on, I realized it's using a modified version of NicheStack.
That part of the code was reproduced from the author’s understanding of the assembly.Since a lot of embedded devices these days rely on software like Webkit they typically have a firmware release zip somewhere for license compliance
It wouldn't surprise me if Nintendo went back and fixed something that wouldn't make sense like this.