In this video, I explore the use of security vulnerabilities in Mario Kart Wii and the Wii's embedded operating system to alter the game's code on an unmodified console.
An unedited video of the payload execution starting from factory reset can be found here: Full Recording of RCE Exploit
Here is a write-up on how you can try out a demo script: https://pastebin.com/fUqRhady
Thanks to:
shutterbug2000: Twitter: shutterbug20002
Seeky: @seekyct and https://github.com/SeekyCt
Wiimm: @wiimm1 and https://github.com/Wiimm
Leseratte: @leseratte and https://github.com/Leseratte10
_____________________________
Twitter: Twitter: tasmalleo
Twitch: Twitch: tasmalleo
Join my Discord! Discord: discord
Intro/Outro by TheSneakySpy: Twitter: TheSneakySpy and thesneakyspy
Check out Mario Kart Wii TASes: https://mkwtas.com
In this video, I explore the use of security vulnerabilities in Mario Kart Wii and the Wii's embedded operating system to alter the game's code on an unmodified console.
An unedited video of the payload execution starting from factory reset can be found here: Full Recording of RCE Exploit
Here is a write-up on how you can try out a demo script: https://pastebin.com/fUqRhady
Thanks to:
shutterbug2000: Twitter: shutterbug20002
Seeky: @seekyct and https://github.com/SeekyCt
Wiimm: @wiimm1 and https://github.com/Wiimm
Leseratte: @leseratte and https://github.com/Leseratte10
_____________________________
Twitter: Twitter: tasmalleo
Twitch: Twitch: tasmalleo
Join my Discord! Discord: discord
Intro/Outro by TheSneakySpy: Twitter: TheSneakySpy and thesneakyspy
Check out Mario Kart Wii TASes: https://mkwtas.com
It's also worth noting that every single Wii game ever released has this buffer overrun in it. It's a fundamental flaw in the networking library they used. So you could actually mess with literally any WFC-enabled Wii game in this manner - assuming you can get them logged in, your mileage may vary depending on required IOS.