Hacker Newsnew | past | comments | ask | show | jobs | submitlogin
Oracle of Ages and Seasons – Link Cable Vulnerabilities (drenn1.github.io)
58 points by mkeeter on April 27, 2021 | hide | past | favorite | 7 comments


CVEs pending

I really hope that's a joke and the conclusion is satire... but knowing some people in the "security industry", I'm not so sure.


Lol, I think the people who wouldn't joke about that in this context would have followed an N day responsible disclosure window. That would mean that the CVEs would have already been fully filed by the time we saw a public blog post.


Sometimes the best satire is satire that keeps you guessing.


This is a neat find, but it's unfortunate that a RCE/ACE like this is so limited by the Game Boy Color itself. Most of the interesting electronics are in the cartridge, which can already be replaced by something that runs arbitrary code anyways.

It would be neat if this could be used to exploit an emulator or an adapter (e.g. GBA link for GameCube) and get ACE on something more powerful/inaccessible.

Congrats on the WR, though.


It's possible to do ACE in Super Mario World on the SNES, and it's long been used to beat the game in under a minute. Recently a team used the exploit to play Super Mario Bros. They ported SMB to the SNES, and then used ACE to load the port into memory and run it. It's super impressive.

https://www.youtube.com/watch?v=BpYmVj9AvqQ


> unfortunate that a RCE/ACE like this is so limited by the Game Boy Color itself

a) I would say fortunate; in fact, I think in hindsight this was one cool thing about having single-purpose, non-networked devices: security can genuinely not matter for some of them

b) At a hobbyist level you can do lots of cool tricks with exploits like these, for example: https://www.youtube.com/watch?v=aYQpl8Jj6Yg


Elsewhere in HN posts today about GameBoy game vulnerabilities, this DARPA press release from last week: https://news.ycombinator.com/item?id=27000282




Guidelines | FAQ | Lists | API | Security | Legal | Apply to YC | Contact

Search: