Sign in

garyodernichts.bsky.social

@garyodernichts.bsky.social
322 followers 34 following 21 posts
PostsRepliesMedia
garyodernichts.bsky.social @garyodernichts.bsky.social · 13/11/2025
I wrote a blog post about the security of the STM32H730 microcontroller used in the Nintendo Alarmo. There's a vulnerability that allows dumping the protected secure bootloader of the STM32H730. You can read more about it here: garyodernichts.blogspot.com/2025/11/priv...
garyodernichts.blogspot.com
Privileged Arbitrary Code Execution on STM32H73XXX microcontrollers
This is somewhat of a follow-up to the Nintendo Alarmo blog post from last year. This time the blog post is about the security of the STM32H...
0211
Reposted by @garyodernichts.bsky.social
Arisotura @arisotura.bsky.social · 03/09/2025
now with sound!!!!! I had to change the audio amplifier's config to make it run at 32KHz (instead of the standard 48KHz). heh
3141
Reposted by @garyodernichts.bsky.social
David Buchanan @retr0.id · 05/06/2025
here's a framebuffer graphics demo (this has no practical purpose and I can't prove I'm not just like, playing a youtube video or something)
301281266
garyodernichts.bsky.social @garyodernichts.bsky.social · 24/03/2025
I spoke too soon heh... Nintendo released a new Alarmo update a few hours ago. The new update contains a new 2ndloader where the signature is properly checked in USB mode. If you want to modify your Alarmo without soldering, stay on v2.0.0!
Update notification from my update webhook.Screenshot from ghidra showing the now proper signature check.
07813
garyodernichts.bsky.social @garyodernichts.bsky.social · 08/03/2025
Nintendo is still shipping Alarmos without signature checks in the 2ndloader. I assumed they might do something for the wide retail release, but it looks like they don't really care (for now).
0140
garyodernichts.bsky.social @garyodernichts.bsky.social · 27/02/2025
Wii U fun facts: While reverse engineering the Wii U's USB Host Stack (UHS) I noticed several fun quirks in their descriptor code. One of them was even exploitable (UDPIH), but there are some others that I have never mentioned before. This thread contains some of the minor ones I still remember.
2202
garyodernichts.bsky.social @garyodernichts.bsky.social · 02/11/2024
After my last post, it was pretty clear what everyone wanted to see on the Alarmo. So, here it is - Doom running on the Nintendo Alarmo!
410446
garyodernichts.bsky.social @garyodernichts.bsky.social · 30/10/2024
It's possible to run custom code on the Nintendo Alarmo via USB - without opening it up! More details in the blog post here: garyodernichts.blogspot.com/2024/10/look... #nintendo #hacking
13414
garyodernichts.bsky.social @garyodernichts.bsky.social · 20/10/2024
Here's a simplified overview of what I figured out about the Nintendo Alarmo boot process so far.
Diagram which shows the Nintendo Alarmo boot process
1152
garyodernichts.bsky.social @garyodernichts.bsky.social · 20/10/2024
I kind of forgot about Bluesky and now I have over 50 followers out of nowhere. I guess I should start posting some more things over here!
1130
garyodernichts.bsky.social @garyodernichts.bsky.social · 28/10/2023
Ever wanted to exploit DNS response parsing on the Wii U? I have just released DNSpresso! You can find the technical write-up here: garyodernichts.blogspot.com/2023/10/expl...
garyodernichts.blogspot.com
Exploiting DNS response parsing on the Wii U
It's annual Wii U exploit time! 😄 Image of the Wii U connection test screen on the GamePad. After reverse engineering parts of the Wii Us' ...
062
garyodernichts.bsky.social @garyodernichts.bsky.social · 14/10/2023
wii u
3175