From d0ec5bacb5c027267a041d74198e759d1fe268bd Mon Sep 17 00:00:00 2001 From: zoogie Date: Sun, 2 May 2021 14:58:06 -0500 Subject: [PATCH] Readme and cleanup --- Garfield.sav | Bin 36016 -> 0 bytes README.md | 20 +++++++++++++++++++- sploit.py | 44 +++++--------------------------------------- 3 files changed, 24 insertions(+), 40 deletions(-) delete mode 100644 Garfield.sav diff --git a/Garfield.sav b/Garfield.sav deleted file mode 100644 index a04bdace4c9b9dbce51e8f34a8b721001a4b1eda..0000000000000000000000000000000000000000 GIT binary patch literal 0 HcmV?d00001 literal 36016 zcmeEvdwf$>_V3!~oIKiwHhq9;TH4d3h0+!bZNUl^(gZ>uJSyOC5O7Ri*g};E=mcdT zJah^^rVt%z15!n2@HN9IIF7S)?hqM}U3R|}Npes|g`<8Sc(=Kel& z@BL#=y3T&Bz4qQ~ul-*8bVkLBC3Q9R)$=OuteIA^s={O&-aodZJrEw?^? z9W{i9r_QPOOh^icG5F<-j=drtk!d*3MY7RIuX$sMS~-=!f1dc$@P8P8DEHq_+eE#o zg^qzV(_2F^+xN!*Q}KD6q4@O)M*5$`f8u`_|AQZh&-r|LUOCrlZ;lI>^@qy+|2kfa z!T5iaPcB=R*Y!{xW&S`N^Rn{rAzZL1VTecnyLbhN$7QS#<`2nm&LAF9;t$LEs{{1% zM-0gNY31L`Id}cDvi|+DoxVPST8|C?mhds~`bzEO=w)F)RKC_hywk`x$KyP0gJ18+ z;pA=I+j1rPf1kHt=)cQ%Y8~hk&}|R&3E!6HJIhy&f83_OU*DI@4DVlfUOD}6UjzEz ze|m3^|2r@BpzBIyq>ir@VVc03f1~z_yfzKV2-5x`UUOL*lGV%e&h10~@9F;eK8dG4 z6#wY|L43}Jq4?bXuavXir2i^sSK|NW{NmL)BxBtFO8qvMk<0l(=0ANp6fge=;$0~Z zm&pX3)8+Ip=i~n*UEV(p(c1F^>0T+{-_Oer@$2%mB-H; z#Q*EE^snk4_lz8n+XJc}?gxhI>~eYK^7zm4@$Y1~)ja%P*(P=9Grr&VU#Wii_{PHs z;~np3|Cw=)w-Fuq$m8>|kf-^tsxO{TPXCAM>%Th(;C(>2%$U#qQ2)+(!tn}H2Ic_I z@(J?yo_}@@aCzH&33UG%IpTTw{y4+yfImZWDy3eTCda+J|GS*lx8p5ng~!|fI^5Df zJKkQN*5&Po`(LTtJdc<2=)c>4h2w#r;d&jE<$tEWc>L4g9gjaG%m0Yq|H$wAeC2bN ze`WjT^7!9v-$QdAF1kN7=OHqO*LK9rSDbHMN!EG!zm4BIC_nJ|{_{igz;EY~kh_8T z-uGh@EqLc2uPu4{$>2G!8!n?i)TZS@Jf4>y!YdxcdjQ$^A-n~HcpsD`{UF{@`T9bk z7{2y!*vrk;;r$%KI{m-9f+yY_IPleo0{c18K9HBO+n#X=pK)bq0+tQUU!;~%lw;7#{ zp@Sdi5uGI}@6x&s>Y8Iz=N<+SwRCBL=amn2tRebqe<<{6ONH9}Ql;9=O)|A~WpX;E z4c%(k_n8iLFw?wFjdoi%hl`<*p8KgyySllV61uvBw2@|YYbc~aJkj)Sx7oC@OEewo z{x*!`((w-DyK~4-%l+iz9RkI5p>FhQ+W0O0P#Dt;glWkAZI}b)C38y$D{tv|;?-T< zg0`h2Xg=1lBW+hVD{AQy>D_KM9qSfgM!+=5+q$)Mf2V@xc9GoTW^&8MNcmWINN(xU znC|a>1H7spzpJ|%@vCEZbxVeg-FCQ1eyCfdxgAkN`uT8+G@skI%;aHH-QA2n0BHV;LYGQYFzl!>j zOlH4zd`pL5vUY~@4|jc-8NYkk4n~7HA%~ zZ;{L|bff19^Y#Gz8xXHm-q_9K?Y%4>|;e(7wrj4Bh z+MOsHCd$J`?~nM`hj)Su_Dc1l;AbJ}H;f<~~(R8-<9mG~fZaEHHaZ$KE;GbD}w+vsd0V zya46-3h8s6eN~S9Wo_&hOeeZOgFBn%b$ubVxI3kmjehN}?i!R+Xg$&02K;PV-1Voi zEnQytdnsHm>u(wie{C>4c3ex>0fZkI4Bv_H<~e9r0A8;pq0rgu08HJ|WrJx3@b(A! zj^ts*fEj=c?vJ+RM4n7&C(Tn;=NQ^=0og-neAcXvGa zCLo;9)=(#1Xp@m&g2(&Nh6nh|yNKRYO*&EXb=*(e$@>bJU!cG047YQVzo6Vm^IpVp zk>+nRk=D#`e%#$AZDY3rbR|>EM#0qLChdl9-nWSPF26~3bu*2tQ>5|^-WLorwRD80 z9PWxS9qyWTHQI$?1I)p;j687qnW#sJ#&!$37TyNCve54^-Y?NEg{0jnxrkyU+L>S? zO6C0nuj?4J*NH^U%;f42DZUGb0D5h!r89^+m(A-tWBkXuw5Ii)TDz+=+Pul1GqEfy?xm$9RzLutR?FPUa`O63oomdbZ`D?yK!otYl&6lI}PeD!|6 z7`xt2$TKrpI+9Fu3piKg{hk<)ASofgqXS!-vw{|ur&!~G!dlUmW2Ar9OO@j4N& z6Y>1tj}yip#6|u;1^+rC!5;y*yj@}-YUb$+vdbT))w&XW3s18$oF z9!yu>(8*e7c5+%w9?Yx!*|+hA>L7ox4tTqZF&*oY{op_9LR$`b@IUC!In>gjH6?)W zif#=|4NNsmHB2q~#01!*(JxBeU4Bm|WES;s|G%alP&OuSh(o#JP_BV`_+Hs~yZV-| zz&`-Kilpr_qt3#0ImjQh)s9dr>lDzpGftOQbPe$MFzPkF>paSVv7##zbzlN-LVng6 zefq&LzoS2Xuwxwjx$MT6!L#y>kfVG2ITrA$bz`U2uYs&;y43&)pank^w78=;%$rSN z-e?YO^v6KXFsF!=AS)u;8t;!q6Xeo=|7i{CpO2wj7J0rgABhZUkzaYEpJ{m>=Z3>g zL*)ey&;LKd;r!5`yq|#=yxd1QPat=GE_30wI2U8P*a`V@v(}c4y#Ik68-k0u$+&D_ zR;p+IqE5)E8riywjnel#Y*pFQJ}zoeYHEe;RFO%Sn_W)ZgFl z!ZQpsdOsTbiL`fS=jHYcYE(XxXuyd^S=bg#G zQO(Ls9-nNe6N0NQ$h8%=h!iBkFjPhJ;s`6ai)yi}6Q$! zmk{adVgQL?0yq!K{m4@*=1Jg#4kqW>G}_h8!^n>@1H9y8V;uZBFY@y8#E}#VjdX?B z7)&Gp+G{YdjizAgSU&Z(le*PSYF7oR(<({rlz9yXjY65Off;pX$Bb5+6=m-Z&7-u6o-1=3<>`0%9<@&Z>Z-$h%zsFC(UMt@ieKJf}1W; zW|X&}OlJ-Cycp^akR0lHJ~RQbeiQNsm?6JJ+C#xdfF*fz!&tk4HHp+aB6fbW(PP`2H2!S{&KLp!Gh4?b}z z6l%PWFN0)5A0~7C9Nxqt37w|=Gg7zQ&%@q)(~MTAHw*;*J8YJmWR5_7tE6KhTcC4+nF)h`X6P z$CQpKQBS-oO!pyqds-&)G^Vu5rge-ejdkoW7#yQ#8Ufn8(T>reIePX4$LLwvfXuQ? z$EafF&^tmsKkXkCE?a{kqimZ(Z%;4VK7%|guQ9;zekkxFI&nV7ye3`NUXwpUdySN! zy(S?+OO2sa@&X#C!kn6FCPovBC7L+>7jz9wQyg$80lEeWS^*#eB!Cj20H^?JKm;HX z5CzZxh5@1hF#sFrU`$9Q(i$vI=G^Fv6Iz|I)+8y)N=lv8F$1IcejXAhxZr=vNs`(c zr_@>(u1;LNV|APmX+60*T{2iBl(AOrLDPORDu_+`Z1K^>vcB0Ocv&80_IOPPt#!h+ z!elPO_n{?~Z!WfOU24`jW(c*E72%DiL?_Ej9TRnO(wOtUt;zTCn6lX-`Qx0Xtn)t6 zPO@W$0}_o{Wv1kdFp@z>S$4-kv6ixXym}{PedS%>aH?UeCFon=WWoOP%zzn%S!?;& zXQ=%+Kt}EUV~by#&+?kl*0cvXE#op!Lw+>gNJ=ASv^(?1v*6d~DHEw@F!@$XMwR1W z@BU%L(p2<-<*JiXZB^YfmiUvhlNE@WF>MTej*wF{|2DO8>79wUN6PeuF4W^g%ND&X zt;C|H-h)3${zhS3`pvLkCa#XmpU5#LIzv5w1kUHakRmkfbYgyfnlnNeZ#}DGCn6$F z2O<;^!#V=SrDF!^Jq6r9`$B2AQV9(+S0@^20%GLn=@5%qj{)h7+KrQX$vR>AxGS{ftxSQ=$M=lgx_ZF(V7>*M@>^(vR{ z#-g_r=E#c8Ix7oq4Y9O)EuOX%Z(Z{CfS4)xUa5P*(%W{ij5})J!1q%= z(O*O*>bnC}vN{k7h1QYLvH!4xO%|&p^n%xg6e-!h#InxCUAjfiBq82gHp!DfS7SUz%qIQLdMsDTnOI{PZJr@hh7cH1CTMeKg#~V-eJhi%l%PCDMfG_ z+BcSMp!XMOjDnlSB_Zu`cFK(P;HbZ&%{%OgWQmVRwMd;NgrD<7qc z8M{gS^q&`G5?!tEUP~tAtUAOpV@|SsDJSTYGSxojmrxVPf%{lM*u^s0$zjIcKpsua zW2l8^{kgO%H`z%!U;0>{+j8EQOFMF7o%5V7Ly{0>ol9=Z8DAc?cHPqHVmNrR?_*(twaJFXhqRipTSko%xXiQ@KaD#K}I zKjx#REtW^yuwu=42yqTv${|N3-0ZMV>C2Azk3l(`Z4ScIg0q3&mWHzvi@ao_)gE$qyI|^w*k?ew?0Wl-URs1_?ET^%JV@v2eo0j3|rwQU+4^Z6wOsu zrCanQMR;_|W{*yCZ?w?KFU}m+>oA{Dxmoa;ODc~<&sgZ)z?n>pNOZF6%xIX_lVXO# zBQ>`t3i&-1e@qI7~Iz5%6>k~HzIFJ19vU)tl#@+$5+BQ{eO`JO$aY(B1ASt*QVzH0IZ zL?e@{tde<=Iyv!VK+5%X3AyTG)ga!FQ}>V!p=QhwpF|pbjPh-g}VLUt^Wf zyI)bOT9)mUNWMnO)_Yw>kGRXij+1eB)$V1IOxZEs3ySxLQPwD5#WI$+yNbp{`m#3P z9pSc&1ePT4uIfFAIgX+$ux#^Pk!-Tw5{rH_)T6${NRZi>zn)|TWyzm;m(?{{&b*sR z6;+|0oqa7;`4gT?#QeCbyXwOL865kSwfEHKAs<53!nzH6!|yVILLk>oQ~9|gvQ z+kO?&{9Ay@e-7{wE8oO>s;s^}c1SGh!PF-hGArsTg#4~`@n&pm8_!la4r23XKWh~C zVE25hxHZ%>tB*2Av};OTv~dAtGcTnjI(Q2ou*H{Cj^wSiv8O^kKS9fpN!qJD7?plu zQ1*lSckhkJV2x2*Be$Wo_+IN8_EglKP*24rMM{cqm`CM~c1L*xx8O-~UY(ujU7UTD z7o)9vc-SX3o1LWK2NxF^BcJx@T!!d9d`?t}o}YY`U6|7~$J;$!0%k&g3Fs*`ZHu)v zYpgHIoN}$ue7&wQS!gVGPEA+PlUCQ*aXt?QDV8f*w_5(@)6TKyRR;>{mk z`&K{|b_d5WuQKDsfS49GgdP5Sm%8uuW)=b6%a*>s_4njaN!f zMT@3%g{L`%#!bfPplDh_^X5KkY4<9c7Sfi5sl@VRVAIviH!e%`iI^>?E7PNSjFohJ z;kazfGN#bDUSE_!PD{bc!Euo?)JE}P$$fXS(yj2Uquzy-ImRnzD!k(|V|_}`3l{P{ z)HOs&x$DyarzE2$$7LV%u_?a~h-k@fi}GELTj!HJQQ1HC34U&t59UCfmmV#-Q=ZW~ zyR(?jKS}S9JnC%bdrmnvT4T&MYml$AR*y>b34=M_t%`c@tV%qg9ds{)T|H*%W$8$%O>{M{+K2Fk4VMSB!GC3nb}OiFihQ}nOF zW$z zoK!M3nu0s}L}lEGby$yHQ>I%?nM&`(GCm_DpQ3AnB?IN=xHrpFqlf!LndeSQ9jpY@R=$;;6dA@*P9BB;(DCp`F zJz`V4SfUoBMY>G0PA5u>G_9(*XwrCehjqLs6y2^ssuBIXPna;dZsARf5*G}N6~T(W z3$;}^2HU=nf{Xg@#Yo@?2oqTTL4T`lT}X?0F7_(0HV26G0kzE)iApeMu>hp)p`J%C zC{pykFP9CJbYzFr6ycP>&8PkMWRW-M&s%1y{p~WT?#t>>PXllz-`|!+Iq%7i_6ivT zwU*?R#*(-2OtzU#pltG8b4JRTa7H%pUh0+$RTz;LF+J+ZWwcN7P_v~IqjadJ=#qk@ z%n!Vj+3rIPA}2S3`U&62rYL7?w$~>cS}=~zxL_RFwk{?u$HaoST~K<=Y@_ASar3BX z^c-@S!YiQg@*sr*P}moy@M`vNd@XsQyhknKyP$;Gs{yg)i7!|>+O}hb{HSF_8yWRf z;bh}Wn2UQz0E-B1!mb=yRWm~87F|1f3t!_($Z>mA^B-JIYjyFd??Y@0d z-Mo<}*SSZwuj6wev8f4s-*<-6%^6be@pY10^6Y?5M&M#?HFYfnSG-T2QFn-jcLP)9 zlXo%mZ*T9;D)WxZD)A1Z)Pj4g>ao+jF=L8-pZSuUi_Y=UEcEn%8BtMQq=fL^=X!1<@1XtbUfC5maoy1V9fS81I)O{lIC6&Q0)Br%z&MN z_bDW~3n&@$*820&&+-<1=FG^Q*-kDaZT_i-Pwt8|KYn{RW?vC1#fg|Kg?AwCB7aPl z-M7dP`P5uptkZ0WwUqkeEwjCDYu()`r1wZ$MR%He+1R+= zQeA%n_NNxFDNoP$Kbptq#yeQ^ zylOI#aZA-(RheYO8e=Fg?J7EPZ6L~!Nhui1ukGb?+wp;?Ft<{kiG0TM({|;`6Dm(4 zdI^h9>xq79ggefInYmGHZnnl#>UsTQw8u5Ny_QBP&xNp2I7Z>q{dCb!G4I4qgx;#%_DaCJ?C{$4 zke5WOn4|Dne<~r=h|okU^CX*^?EO8vLfB7f)>V*kUd5t-A|uq}y*Mx$(z|z^j;Gbw zy)T-~bDM~qCF4w|V#sweqMI4z0+L2rNh5Z*+JgJ<+pBbw@hVa_3tQvu5l>0f&)4jY zlsVC7r16-mV{a z=iR-md)X-kdF%WiD{hQrRy9R5&)v)>Y0Y9|tR>NxZH@4?)UwQ|HbEYrFFTOp_9)b` zOlkG~J--kAEnrPnVC^?P-{??z$odQx}u6J&~9n zrib}F(n(`eeG#4=HjGx;N-v+cVs8cgmgHs+Gta2HTk3XM#5M`-@==sfdX(*=G@fIU zTdF#$#?!S{0s8@*hZVMx%_Rccin_8+@qV}8!CRKpsMw0l(~zoBxpg3fjIPAhMXZ^E zx{%UypCzMB@Tt(tq_r`RwEael+ANU5^P+xNm@mfq9kwbPWl!|csNKuj6|Z|apALaf z5ts4lKYJA^SAkD226or(uo_oF+M-T zu_M4T#gh@9MRnLWXcOS~73!X0=1oS?%}cC>Rt{Z#!Y6B z&3eJ? z(et+YbwE4$LO`C}8!%1&CZM1ERY0BhMWB3gFrX;)=spin=374OizOZnypR6m=w|GX zccFI)?-r_ND#%zXWeYwEzH?r-GnvK;K4a}+GfplJHem03U`H{`w;airg%;5ONhZwh zW$Yl~K%^|9MBfl;*1Pl#s**^vssy!e)w^7V#D=*P37ca^x}CHkDF5&cf)Mrzg8SbR z@7voRBe)s*Opg#{<};{vm@0QG%tVXmm5gjhvXwmq8B4!q_F?;JHlZP#jOGmNO;*pW znPqg<%#4tXuIiZ)8lx-EmEBM^(`e3iRnCkDPmHdLvN(+%?@hIdF0q!+RIRlS*(7&v zgZim0uB?VPU2itH(n=`OlIc}q^_}76Yw#3rZo>^IMK1EcjUKX$IPOZTv~8w}X^O4o zB@wkTk+F^+Ibt*s(LRTw=@EyNyT$T_FN`~_r1S}0RzopjXSrOX)la|M@JE_tG5S=X zD|;op6G6QwO#Of*{`jfH$#WFjZp6+=gb-_OcE(A3_gKn{Q$|`R*%g=p1bz8oniIk_ z)lYA2$S;kx1wd#_k^l4q&`WLH)`As=y{W%w%5Q*v*t+D!D&*qy9Ar$2km6b^u%!{)!DF z7yJ<(4bTGO011E*03ARN5Yx0+*=tbR`>aLFT9-y)RO34+p`O-$<1$q#Wh;EHwD^Vy z%va-G+Jo^8i?GT#9}o~XlgFphAtD*snvpcJ9g&<>jJ#BR-88r zI=?6<-nDQwGqZzflS+Nw;0B%2dgGt(OpkyatM(Hvt~bXUB2yV)G+n8Ej2 z;$|vo_tIg65e#FyP2lT;CqgcRD@{{2m-H@8X?8frQKg$H))iSQQ@ra|A(tXbM%$mX z^Hrh0)~src={>jxXNhX$Sq)xEfJoTm3Pqe%xzZ@zknxAI&6I3Uv>z<{L$SU=2)DZf z#oW|2yi&?r-YccrhCNmV_GmJ#TKMW*vK-&A5uDjy_F`$Gi$PZQmkw{(X&vqw-Y^pH z=V!f8I<6ttng!eQv$MjscEfLHPiPo!o#5I#i-(D$vRuDLto^`$ZdRu2x#C~XQn<7Y z&&}G4RGur%M7f?VO+dR@R{3e=vZ`k*bE-bWj!;@Ch=WTCetyw_6NF51rK9#QRf`7L zAH(kT`AcVO*=RjYGP7-yEni|ciL!&Iq)~)9S~J2wL3q>5Jj@ze{1~?~Tt=C?Dxa*( z!2VKAWerjY_PgX(k%9*0Z$P{iS}(C#sN#&rgxT6C+@ypGEUhnu{KGrm}KnNt_hw**xgK19&Vg!Bk=i_57}%jcTbf z(HYEVZ@x5;ms-$RIf#3&f57j@@T(j2TjLi{5_`!gl=$XBzZHXci-31S*ssp#8ucRO zqU=9{Us>4iW?$FR6ziGF0_s1wY-uLSU52phz*lh9J3p{&X)#WbGr^%e_$AVKGxskJ zWMa1%dszK@stV|@$Z6!If!G$rP8p0n0a#N@rGEGpK=Z9~16B z(05>1r8cw=-cERX@xv|yMvAB^nCmtY^}*~12mn3~WdhEbp-Yc;HVSs$)|d)Ano35z z?eV@#Eit+VK&}wgAxwll0^uqJBOC0)09t?wK(887Cxj0fFG0vqsKuWcE>(KO(Pc^&i}$~zdD zWl`Rc_89Ds!M+>zG*;e`#>}!Y4gRn{2K#Qn6 z$RFPc8fx#XPO^{vBmn(L$-lE(?R@}xOar=B!Tmq7&9+UqeQ5KC&qcS{nrs{Q-e)nj zjrEq;%54;EJwFE1HON))mGgP}?KXL`$2Q@;g|>M%x7lJ#C2pqBZ!Cpvzd;Xlmw%D% ziKK%?=;KfQ#7|gZhEIZw3xS0bA)^H*xwHHmEPpyV6sigDA}8B#veS0fB<>9!c*XX- z?I~M}EqFjWpq*i{$wrTUuI-e$$QDnfwk_tX2q{~KQaXa~_SN8MZ%|bHCN_*csSuIncH~z;jAz9z9C7m2G2& zQ|Pfbg?&BxEV9{}%|`mtJk1twy`1WMr!2OsNj8q6M=)Rg&^(#)tZxTeZCcbhuTKH> zszBYzXHS>9PDcO=MaZ? z1JLsc%Z?-p0>eXtPjLSc8|{zD!dcGfVKjvlRtdDUvuUE?V%j39NAHah8|m$isfSm}5E_GDMn( z3&X8h(r{}`&NU}TlXmLVh$(EJ4LeDsow#J$aQhARhwUfq+T7<6hg~z3wI{}m))+>c z4dz0uJEFZ)QeRZ>qbF>7N*-A~O+NHE^pnJNHt|LBBo>+}N9m1FMnoqk;xr_02Q*a% zat=KTI*487kC0!^UgwNf+aLR(!#Ai`m9~-8m)m*xYnO#rAe{TDpd-i4yI~I16E}PJ zx7s+ECehhD8>cU@70s7rnP70p%OykBq{1mv*Q}%LoXOWMx{0heOfSM?oj!efNl8gj z(e!QG=FFLM!womixna(ZIgjotDw%V`lTZHgS9_j%`k7~+`}J@3{`UD7_94Pczkm6a z0|)=`$JSR59e(ZgqN1a3y!qC#x8M1b&o@A+Hw-uNOz@1|g135+bN3 zXEM}Pt`nBzOcl&R5q>rylFbv$v>v6oLEvRsApD#y6dKuL;U?k7!p&IlRS1>BL#$e; z5tazI2#=s#ONGjudf`^#Hem;I2)7G6*-Bv*N_VI56TvC07VZ-67S;&WIctS=!Y|o+ zVT14#+a%m0+$;P{_%)j*@G?#p9uOWBel9c$TZP}TyG4;MiTz?od=}%zy<&s7S==K2 zR*V%7i305wcZ;uyYVjDb?iU{ve=fF(I`)MaN$15c#jnJ##c#wO{LYIP@H0uWST1Q* zcFDlDNE6wsQZ)M$#{E{wD@|h+icuJtemas-RSu>6g0-Y9WR$8_YEzX;8KwzfhW+|f z72TLRH+50!{M4IL|0DJ0R69Z(snPUu>MN;7Q{PB^Gxe?1Q>pE#y{YF@KTSQGdLi{< zstY)cfEK{sREb_n{e9~5sRvSzr7}94>P;1ten2-|pQV0@cVFu4G)B2;jx?>X3AT-C z-gLdflykLY&k@)yIZAd1Ojk}dqp_pZMO=}X{*(IX6Y8YX5KpFKceN2C)bMzU# zMz7NwbcT-5SM&{iK^N&fu0*_#qn2LUO>OjN41XQ;IekeN=x^ksr|D(-BmJ75rGs>U z9;0XI722AyEyJB5WTa=jN{6VGo}#LZ>ob0oaZ|?Q^dxCB5;F2Lax#)LD5Ef=iw@Jm zjQJUL8A~$k8RZ%E8Bb7&Kanm&lhKf|DdU%Pj9eMV=_7iN-lebU z1nsAO`jAdhJB}SM(O>8{w2z*n-_lj`ALvE;74^_dw3qhK@96jR0zFSH87=5-1}(9)&WYOzmrefaKXEcQKceos!b0vlG?1J+?G>aX8NYX_Yx2r|_ zurj?}Fb*qCu&ZlzmOif*@AJ?!*OFOFHP8UX;yVF$9UvJX1JVJRfE+;Yel{w>U`P{X z794qgRoSZ26nlK_s*+W+qRjF3n~f_=SIvyKuPR+N2k){wN(+d);_WyGmsXZ$+l}^> z$U&&*u}}eNu$Q$pGNEPzO@)T{YKGVU#tS$I)~YB zExEN=ZFkAHmY4;#{ZYBTBxF+CmzC@&2oD~j0S+A*rU>{-BmAbpy$&l`;`b>evsMDA0UCf7 zkO0sDasbJISFxUyVWtBz0VY5`pa4)Ls;Lkrkx6HUxeY78X)qgEkcwe02KeYzW`|h~ z5U|Fmg;@`909FAQ_FJ7W8vzdiwgYwmHUV&Bdtlo~fqVkg01ZG3NC4;nIe=t<3`hrL z0!)B>Kmni-Uk2RO}?%^Y);cTU^0|%6-+0f5wHWW z3E+ZWzj}7WtcaP5q&z#+Z_zG>_sijS5!+A3JbSj?fjZ&!!0UkXpPzbR0d!%iaeYLh zS+?uU5xTNubGEuo9!Wvr0tHXwEcPPKw6q7QxG%s=&wZ%fk1s<6Up`O4=JQhx##))0 zBI3=lW|sGcZovN+;W&sv%zz%kp?3;deLe;)#{t_yr@G|b=OZ24ojA+2i&;va@NF2& z)jJ$Bg18TpfWC?MPul$yoQ2d@f~ww2K@ZFxoF*@W`6V<6D0mw}w};cD;QcToy#joz z;QPRNmU;0cauTdO{}*Tr-go|U=ChamThVT>9dVFBPwWs}=i6D6fO~Qm&YuCD2GoJeNc&&iyGW?D5j6DQ4;Agj z;H?A5)jk^2eI9)2tA+iG)>Kr#Dhf7jmXr-e6_Wx^hVn{A`u-F*hoe<@V8SA9U* ztD8Y;4eku7XSRZduvOe8~8mk z;0N7n6(k0GY-rP$-=C(ETIC8f#O z=fwS&UctC~mCN{?+9RFS?XK)M;tqxKblOcxWZWi|PEOtQ;n-!BkFsks>|Y1M>2e(07j0Gi9bISZ z^8@+&hj&B~hv(Y`+R8E&Zi!w_J)@RgE4O})`sMUFUU2{Pls!fIS!PS7d8Fo^y`MiH z`7Av=GV=51)1B<$;j>Otb>hP`Hwj<+x=wg_U&eD(XD!lciz9U6R#k@BG}_sqn?fvY zTv4<|^3tOl9ZCm#)aKZS^F~)9yDs>yuw9(Q@;6ulJ_R%h$a68Y2kqzWTk>_m{gnQ* zz2a7d+iI~E%}GDNd*cTkLRX{Y=t)x zr~8y1Ie|_5JRsy>3`ot7Lz{`gN6!8VS{og-S%*^>DuAw0sOP>A%jbtdxV1EM7;esv zKn+l+v4DSoM;j>}ULyz#guRntp7{60`8u|z^`%?ESpOM~D&4ko%6Wx(% z$}&SOL;ukhlI^Jn23l{cO^tpJ+6!pwSHf@oFZk3nfFCj{(Ko1O@-q~1TV$G{Hc8+q z{OYn8oc<8)$Z%dF(?mD0jE34!&$f`VL{%o+BWs&6r(@8J7iILpefxa-)Px<@9% zhk!nSoW}2QXh?xR^Cy>BilSKA&d>5gJ$vC2P6>$ptB~X1bl}|r(C!cQ1VW8zk!70| z;avJ$Ms;aK$s&PGj+CmoAcm z`{V65mEMH;RDF5JyOW164OgclC854>k`J~ zF(}#3!uO9$;q%p?&qMH;)Nd;hQhwBKgTF2`9q;b`=_S+4A}Ri@_(L3UPTprJvzF*< zt>~HiFIj-|<)u(hJMK|k^iILe)(FTpzo&f^cX$hMQcmu|vQSUSr9$}m`&i24;@EaF zY7L1b?coyZza&0GY2+5=@ud@h*$EusR35ND?;l^11M_$AF%^H)ZYpcCJnJ*T=gs~- zflyD^rJOL29}k3#6sa?dnc6lAS}qF8NR8ecOQVWE2#hM$n|WR`ir)`pz}|~D*Q*(t zhv>LWk!<)4>f?35D}Z+a{I2y;0~x-8Jql(rAQQM9Fna;e^D#bzJE#kY3}yf>(Wde{ z*ZBx5Dk!ihaQZeK_L~6;mqd5L+yxk_`*_5i2$%!78Q=s2_ix=hl14m} z(UU+|J?c?KoIpLd-{a559l80Ioke4fY>ME%sZ0rsMN0PGV%Ut7jr&;}{krC;XP~<5 zz1y#M>YDTp*_hbOwl-T6wEezO7klZnvzP29#q^=5G!-drmUr@7=6rm&s5 z=7%kGYB+?hMFqtq7P5ENuhs zW=Tzv#;wrxQ0A$@O$B;9F8k_cg(u=6)x(%C;P%EaN+y;sKExhU?s$B0)U%!Q70^h= zmz$uux+HMMr}jiZQ?2u)J;0haFXrcjzYRQ#x;hxHui@x@p|#o=1z&Ui9Sj>!J%B<`kW+k7jW zE0bf%bZx|#$!(MtX^8h{Wk>kbZ$Fp}t@-TFPA#%1+&mwFu)e>--4(dr8lhu(rfYRh zC7Gr~jQi%~o7NP1_o`U4a%-NmK6{jJCEhY_im{1#PG|P@ZOgMW+p4m!_uASPKnLu7 ze@6BUU*6!20Hb4bAdAnW-+m$aR5%T#yFHMCtF{*cEKQh**>75H_9@V;<#(PY3gh3y zJu6|NFQ6kwfjYAd?bdO=iT)h=b7(H!`@*&eV#Xb|0upeqCl&e$xRZ(7ExY|HqiVuV zYc{DTXx@6vUya?o5 z?{$l2DbbQ9U{0!RqToFjd78>bo@ydeRW|W-=jzql?z2$4dKXVs2Aw*jt7uYgUzmc_ zjq5F}UF}(9;c1gm2}z4ZT*^4DYeuXS&^wUBxt)EnI#IRr570cK;LM9}1U_BdiSza| zTqd}7Flttnr@(Cp>1_eG#>7Xswg$A*jeHgG9&YqK7BB;6>f|4Vb&a4OA7E1+2>^Rc zgfH&-<5wx0#7Bg!iYB(T!bV%W0^*pjd~=`wA^?8-W(3r4tK7?M0`AK--zU5K2#+p4oV`5J(s?S*67ASYSl|%;!SNlvv!M?LTOAw1P7{ zg~t(}P2k#jlPxObWCVOa53s3c6Sbqk!{%(~)0poW9j^}JZvlS0@>C3EpK1?;(`-Y! zs{Qe_)TZJ$GmQM3B+*!V{v%x|F{~eDCTK|gm}^Lh(2)8e{h#v7^nY-a`Cs*aW{mwr zw6}B!(0@{ze10->{UhitmA7=rj-7m8Zv15EUGeXp2?TJpbU-iStO9Oo#J7In2iZPL zttI{ug@|LH*{Peju|xLPcj|HwHf1B?&F>JkC;Xf)rw3h@Nzh^G63p}c+7T@srj+#^ zV)^TSt%j$)xGNQUU60Ex9UHIS(4j$kyG<<}DwKocb3DoXkY7>$q@S4|>ZI}~JDF=i zrxJ0(=`^13-KtlS*B^D6=x4g%i~&6$PyXFA-VQ~y zUDEPzA>tcj_%0f6e?*qB&KZ$4Y;qkoPREITfoX#}PFQh;b)Eh+Xm$^pM=sZkiXsEy zx%?Ypm)rTCX&A8QNMs&>nrXVZHB~irch*$Pw=G{)x1_GBVpZMp+vJjIvdNiI??mng zpSA0sTz{}>{o1vm_R!%#Xl*^dPqwB&OWJ}pVY9GM7YgVK!|roh^n9d)7vY9&;4tt* zRJg=qSyD)$!%YVdHXRPdsA7JKPnJ0gmn>OQs9UR3Ya%1n&LHU$^dnYuMkj0M7o01Y zuO*kix4+kq-LdE?{Zpa^P+h272*QZAWC<;yb?xo#cPAxLvY}www1Nf)&+gi_YlraG za(q0*UpyY^H2oSFWU}|$O&q(mwY48cx+P@63Nl;(?j9%}ECUZO4X99kI!7X^ukXjN zp0sPcYew{86KTn_Z4;Lsqk@?Q&UcR8MJAkx@JDB|+wEXIKnFYU3PXiU5MVO(nZoIF zdl>Zd^(T80P>m*kN)ye zS2%wEkt0W_Z^@E1OP2KUbXr?M4{kht)L&WatgY-HFzrE}Uh6wY))L}`h>s^se~o>B-jVk|T%#OF{|rxm z4KL5yg}ifCl&SS^c zXqjVZo&WO<_K7N(J@x1%&ED8?tkJ zJbkUL+@L-Unp^8pZ@=yS6mEXD_zxP$2c&@aPZR6g>L&sV@A@`Ot{Vn^H#|M?YyV06 zISydjw@+`_)~n;@L_FUBctZVQbIAW2CHEhC5IX4oM#;I${kf?F6$nZA8KA4vVcyAQ zL>C(L4{-;cQ~>wl{@gv_pBnb(^seEriPxB>hT}~&4Y={)y0AM$J%i!gpHt!f6DRhB z{dsBw?uiqJ@Hu@RH586FapF|ic`j19Ck>>_ZBqxsIUdi|P=1HX#q*6l*zm*gxg|LG z#0);%kB1ShI(GDfJJBDu9XoR519N{R?>Er?gted5*B7I|L%Tu0htAV`^r!GH=TT5W~S|fO&B6;28A7 zpVb#a%rJ=I37T4Yr-G*t&w!1;%j;_@R@TTXYO0ps>Zq%)k!RjP%2(7lDpu6+0@{|ZnE#Xd zD^d5t14Dhr-6lcj6rpNi?ZBNa~t?I6oAwqVyl)f zmn-XTK{DSVhBNUU;tjVgyNyfC5~Q_q^~zN>w+_e*;^6tmb7a%_+`Rk=6R#<_w#Z_g zHr+>oH>P4!0l70$UxV@1t_Jvpu%6uoGb^b`(`Md|5ES@?+Q-{ z%|Z+Geaymqo@`Eq+N>7woq0391CRN?7XM3OKJKJ2+2W7F9s>XVJl_MKV(@oip8&9- zI|sT!IrxSxX;>|AK$lmai%Jc_Kfbtqo`N->)li zK#Tu*5VVf{#Ds6yr{j(o|HeGlbX}68WuxF|ajzB~UCfLMH0Lg$Pe6##+ zgo$~s4g8zYSmWW_?+@Tx*$;Hee%vj?evL>kd>oDSAkl_y3H2zpwshbQTqmwI>#4k@ ztNCVp4_QW9*hf-QO9wUu&#o3%b*aO&S9OWjO&cO$SC|L(euf!bovFf#u9#fcHvE%< zPlx4hf_r6GjAhd{eB*74x)JgMx@Om|Znf*@e%0*_eo4Fiw3e3#dE{xx!ULaB`2*cd zzrOQcq^F_<9f+&vd3hL+j(c&zjr`mGy{Qgd_X-vb{67N`dC>8_FvzLs_?cfUw}AFN zeom9g@14F~``0svK#$92aQ(rTRM_wO26SQnnA0c(pCQj3CfVIx5a#pTE+xt)n2zKB z9DwKLE$-y&cip2X|G5j_Vc)>8meyXss~c{=mcUQ#1KqnheRFvyCJ--cv^%>K;D67c z-+1_GT_``wx^4}0FvI(aydJT`cXMKv5d%D?B!zva6C|6`(O&e%_cy`XD%clVBK?EYWXoquc;*Ad6x?VaIlOuhV4jqAu) z;+Berut`7xw-FYgD3PMp6jY^c)Lw~EiQ=FSySImo18FPupITb&k9lw2%)FU-^WHtb zaive-E)??-iS<|jEw{*qkdRP zKRnUH9?P%pBhSE}gPUK!P+oy9HgsHI-P0V@dT$MN_iJqzy<;`t%N)1vX4S ztISezwupYwuJ(@6UNz^3@|8Hwu|U2>?XZ_K$2#!fO5WqPH`txJafJ?kbromBzlEQ- zY%ea^D+k9BuG8)CYI^)S+N`DhpHgO}#tCSm-|E!fadiDS-(RL(^>w}UX8>73EB|X; zdI6> z<$^b#y){diKxY+8PZFlrwP)F2rQd%!{iA(#jB{$)N~S$)6Z}tSAy)sl14Z%0o>%7w zLAHRcBacLfm&>fZXWYUcWbw)Mg@NMSb-7Z*7WAt-SF-HOK_Yd0?6a(^&7JQJ#^-st z7vtUKSgNNE~D=~=>K3$|0`!($WZXX4QEziJF=%=DMA zDS!78bgM(Y+w(K?M}o!ZU86G`$Obi5h|l^EU$I=D8V<4!<3!aqpLTmg+f2`}%`NVC zWt*`!?A+rzg?~zUWwkNkjq)3VTfC&c#Sg!PzFL&K4c_FI{usf#feX)c_$=TTBlxpn zeYYeX(AX!R7i;S)#Z&m3gWO;3E6ElFx7(8AzXUG*Oh(^+A-$n|9@wm?UcRYuyi&e) z{Kt`Ao#1Y@xvbF+27)CVH_&^Mv7#ot=aBbsU@db?)x0i`Jd!IVkykz6v#hTsc+P`I z{;oD^e;~ron(Fm2RQ{$!py z*`tA*c1s$EkPCKmG|1*%zV~tNL0>SHJda-*4!%Ko+c^R~M}k<2+#{)d!C~@TS;{5C z__6^wIjgSi=74bvKEA@e(12y|C!14jHipgZUxA!yimw{d(@`C>=#! zg1seQ$onAghaZGi>K(9%$KjzxW#MTLw%d-*Pu@G~@8r2L?UgqWM|8=iGsW^$>!{z! zb0>EF{-;L$GZ(H?N4#-!uNn_XNNb&Jgk35bwEC8lR;&!9qTg!$jYx|FY-= zr^Y>-va!^9`o|6850KZy3w2(86WEg_dtUe#abt+pTVBwvnE6EIeVfB*(}6=D?gq5#~3y!`xBkBVngp7rHtek>hvq_ zJAXo-l(0+4O}Us`AnR?muxn#hxw6=Q-VNNW8yx1lV(2c( z0)1f&J2ScMykCV2roM9}7v>hCQ#4zNl(CrXh#&D0@HluTU;JTogSlK5U3BdVZ~1~7tcrMZ&Cu&1Zc|jgBEJ`(bT|C?_gnatn{Fn4 z$*n&1HnHJI*p~Hh&L84i5`9*i$9VquUD|c&X$wJD=|2Fy8Y`M3T=LDzc{lZ$^FBw? zgz~D=-pjEIG2%4IRcFyO%vmJKcv0`{R{C=nrp4(S^c9q^Hac?7nc`y^atOkoP3yQ5PSnLc244xh_%A+ z#9PoLnEL*8U|K8DoatA@;~M82_3xTZ_w^9SeIJod-*Df#t ztIF*@;P*M`a@60J{RhUhk>JzBm*`fHqYdGywj(^! zC-u{b8Thj3kmho-F)Qu)o2f?}Q&t^=%_@d;jT^>Vt@I`FRXE4ksD4FWhm9NLDXaM7 zP=uSg<7r~v@?mF)r0M$>L39ITXRk6}xVERJvQ8lSW6-++`sH&(zxWaD;^*(w7ww{R$qd@%H;2-0@U>}lh~D3t zStg^nMYzGWa=L6Hx%?%%oPlC z_;${9BA*~_jA_o1XdfPvub2+U?R^N&TF(uYtBdaZbQHcTPa(s=t@0|v*c!qXNB4W9 zJNkXA&N7}kV+tB_@LS1$C|t{@eHX3=qdLqN!n)dXvx@m>EXs4pV(0%&p2Lak*`(rz zyX7ndepSBT6y(?b`y7XHV=M0?UGyc!kxG4R(0`#2&f%}=+ud^UEk&jddhqxO7G9nu^E8vvRD)k)zfkE4uRU^YF1u z(4;(k*hg45fqhAq*k@9>m6uQX_`-cN_PH^wO)6)s;N;*d-j;t4dgXuBmmigTuLO=e z<=(pl-PPQCY7d@1axahcO69P1Xu9)W9@alvOo1!AmiyY4<_>Z#bD52{*}Td&dOyuI z#nsCDCVnAWw`SAh+q-vuv#V?Cj{CPfvt2RZOg!B?cD0$z?q}LMx9&1}$vkH^bv)kI Jrr#*|`xm1psdE4T diff --git a/README.md b/README.md index b51cb28..132c36b 100644 --- a/README.md +++ b/README.md @@ -1 +1,19 @@ -# lasagnahax \ No newline at end of file +# lasagnahax +- Secondary userland exploit for Garfield Kart EU and US + +# Thanks +- Tuxsh for mentioning the exploitability of this title on discord. +- Tuxsh [Universal Otherapp](https://github.com/TuxSH/universal-otherapp) +- Yellows8 [3ds_ropkit](https://github.com/yellows8/3ds_ropkit) + +# Directions +0) These directions are intended for experienced 3DS homebrew users only. There are more convenient exploits at https://3ds.hacks.guide for the general public. +1) Copy the Garfield.sav release file and overwrite your current save file of the same name. Checkpoint and JKSV can do this. This will erase your save data. +2) Set up [SafeB9SInstaller](https://github.com/d0k3/SafeB9SInstaller/releases) to your SD card. The SafeB9SInstaller.bin file needs to be on the SD root. +3) Make a boot9strap folder and put [boot9strap.firm](https://github.com/SciresM/boot9strap/releases/tag/1.3) and boot9strap.firm.sha inside of it. +4) Boot the game and a. tap the lower left icon b. tap garfield's head (not the X beside his head) c. tap the gear icon. This should load universal-otherapp and then safeB9SInstaller. +5) Proceed with installing boot9strap. You know what to do next since you're the experienced user noted in step 0. + +# Exploit + +Stack smash via long profile name string in savegame.
\ No newline at end of file diff --git a/sploit.py b/sploit.py index ac0785a..af6a7ef 100644 --- a/sploit.py +++ b/sploit.py @@ -8,7 +8,7 @@ POPPC=0x00114aec POP_R0PC=0x0015be1c POP_R1PC=0x00151650 -POP_R0R4PC=0x0010974c #: pop {r0, r1, r2, r3, r4, pc} +POP_R0R4PC=0x0010974c ROP_STR_R0TOR1=0x0013b098 FILE=0x00230800 @@ -23,26 +23,11 @@ OPEN=0x001521f8+4 READ=0x0011df78+4 -SP=0x0ffffcb8 # address of ropkit in bss -#SP=ARCH-6 +SP=0x0ffffcb8 # address of initial rop on stack PC=POPPC -READOP_FIX=0x00121c88 -TERM_FIX=0x0015b480 -#0x0015b480 : mov r0, #0 ; str r0, [r4] ; pop {r4, pc} ; -#0x00121c88 : mov r1, #1 ; str r1, [r0] ; bx lr -#0x00132d10 : mov r0, lr ; pop {r4, r5, r6, r7, r8, sb, sl, pc} -#0x001469e0 : str lr, [r0, #0xc] ; pop {pc} "in deep development on a number of key projects" -#0x0015e8a0 : str lr, [r0, #4] ; nop ; pop {r4, pc} -#0x001007bc : ldmdb r6, {r0, r2, r5, r6, ip, sp, lr, pc} - - -''' -with open("payload.bin","rb") as f: - ropkit=f.read() -with open("otherapp.bin","rb") as f: - otherapp=f.read() -''' +READOP_FIX=0x00121c88 # : mov r1, #1 ; str r1, [r0] ; bx lr +TERM_FIX=0x0015b480 # : mov r0, #0 ; str r0, [r4] ; pop {r4, pc} ; def write32(gadget_addr, file_offset): global filename @@ -111,23 +96,4 @@ def rop(gadget_addr): rop( DEST+0x2e0) rop(POP_R1PC) rop( POPPC) -rop(STACK_PIVOT) -''' -rop(POP_R0PC) -rop( FILENAME-4) -rop(POP_R1PC) -rop( POPPC) -rop(STACK_PIVOT) -''' - - - - -''' -write32(LEVEL_ADDR, 0x1CC, "0a") - -write32(JUMP_ADDR, 0x1720, "0") -write32(STACK_PIVOT, 0x171C, "0") -write32(SP, 0x1738, "0") -write32(PC, 0x1740, "0") -''' +rop(STACK_PIVOT) \ No newline at end of file