Hacking GW multirom demo

mathieulh

Well-Known Member
Member
Joined
Feb 28, 2008
Messages
378
Trophies
0
Website
keybase.io
XP
897
Country
France
Because i don't care for piracy hardware. The FPGA is used since year's. Where do you think come all the DS flashcard clones from? I bet they don't all have their own FPGA firmware and the possibility of flashing some DS flashcards to other flashcards confirms, they use the firmware from other clone companys. It's not like everything is super secure, only because they promise this in their datasheet. Even hardware is not always secure, so let's shut up and see, what happens. You will be surprised, how fast clone company's can clone.


So for you FPGA == DS/3DS flashcard == Piracy ? That's a rather narrow minded perspective if you don't mind my opinion.

As to how the previous DS cards were cloned, it most likely had nothing to do with the FPGA security and more to do with leaks (from factory workers and whatnot), because someone uses a secure hardware profile doesn't mean he is safe from the human error element.

Though some "secure" FPGA have been proven to be failing to actually be as secure as advertised in the past. **cough**XILINX**couch**.
 

qUaK3R

Well-Known Member
Newcomer
Joined
Apr 17, 2007
Messages
84
Trophies
0
XP
272
Country
you should paint your nails and do a youtube of the gateway bricking , but no hairy knuckles !

I don't know how I could brick a gateway.. :P and I couldn't even brick my 3DS, since I only use GW and, 1.2 xD

And I barely have hair in my hands. They're too pretty.
 

Breadwin

Well-Known Member
Newcomer
Joined
Jan 14, 2014
Messages
56
Trophies
0
XP
75
Country
United States
hand model .. you numb... when she looks that good.


Scousers think anything looks good aslong as they have big eyebrows ,here i found a pic of your bird on online

tumblr_ly4bizruYe1rnec27o1_500.jpg


LMFAO

P.S Only joking no harm intended
 

codezer0

Gaming keeps me sane
Member
Joined
Jul 14, 2009
Messages
3,576
Trophies
2
Location
The Magic School Bus
XP
4,538
Country
United States
Is it safe to even consider a Gateway 3DS card at this point?

Also, how much do one of these actually cost? I know when I did a cursory look on Amazon, one seller on there was trying to charge the ridiculous sum of $240 for the Gateway card, which I know has to be a "we don't want the business" price.
 

escherbach

Well-Known Member
Member
Joined
Dec 26, 2013
Messages
271
Trophies
0
XP
263
Country
Where did they say there is no brick code? They never denied it.



You would not understand it like the most of the users here (low level ASM stuff) so you are bound again to what the users say, which understand it. So it's useless.

Are you kidding me? I gave everyone the info and saved some users a lot of money and stress. You can see the fact on the forum. But i know already, what will happen. You try to proof shit like with the ARM9, where you have no proof yourself.

They clearly say in response to 1 "there is no bricking" and in response to 2 "it never happened"

And, FYI I have been involved on hacking arm based systems in the past and I would quite easily understand some disassembly - but if they could find the actual so called brick() routine it would be easy enough to reveal it. They obviously found some code to do with emunand and maybe some code to prevent stuff working on modified launchers (a checksum test) put 2 and 2 together and got 7
 

mathieulh

Well-Known Member
Member
Joined
Feb 28, 2008
Messages
378
Trophies
0
Website
keybase.io
XP
897
Country
France
They clearly say in response to 1 "there is no bricking" and in response to 2 "it never happened"

And, FYI I have been involved on hacking arm based systems in the past and I would quite easily understand some disassembly - but if they could find the actual so called brick() routine it would be easy enough to reveal it. They obviously found some code to do with emunand and maybe some code to prevent stuff working on modified launchers (a checksum test) put 2 and 2 together and got 7
Not to kill your optimism, but it's actually there, they hid it cleverly by running it as MIPS instructions running on top of a CPU emulator, itself running from an ARM9 payload.

It is triggered when any of many specific checksums fail. The code itself uses various undocumented eMMC commands in conjunction to the AES hw engine. There is no practical use for these commands in the gateway firmware, other than to trigger the brick.

I could just paste the assembly here but:

1. You wouldn't understand any of it
2. I don't care nearly enough
3. There is going to be a "new" 3dslink/r4i 3ds gold/orange3DS... firmware within the next 24 hours of me doing it and I am certainly not going to do their work for them.
4. Anything that puts a halt to piracy can't be such a bad thing as far as I am concerned.
5. I would probably post it anyway just to shut people up if it wasn't for points 3 and 4
 

profi200

Banned!
Banned
Joined
Sep 3, 2011
Messages
330
Trophies
0
XP
282
Country
Gambia, The
They clearly say in response to 1 "there is no bricking" and in response to 2 "it never happened"
Lol, and where do they say anything about the code? You missed the context.

And, FYI I have been involved on hacking arm based systems in the past and I would quite easily understand some disassembly - but if they could find the actual so called brick() routine it would be easy enough to reveal it. They obviously found some code to do with emunand and maybe some code to prevent stuff working on modified launchers (a checksum test) put 2 and 2 together and got 7
You not even was able to do anything, i told you. I said you should check the CPU ID, instead you claim to know better. If everyone say it's ARM9, then it is. Even well known scene members would tell you it's ARM9. Do they all lie because of a such unimportant thing?

That's not just plaintext ARM disassembly, it's obfuscated MIPS similar code running in a CPU emulator. I know already, what comes now. How have we done it then? Maybe we have something to emulate the code and output, what the code doe's on the hardware/registers? (and to the other reader's: No, it's not a real 3DS emulator. It's made to emulate ARM9 code, but it will never be a real 3DS emulator).

You claim to understand things, but you don't. I put you on my ignore list and everything is fine.

€:
We run the entire code in the emulator, not just the MIPS code. That would be dumb.
 
  • Like
Reactions: mathieulh

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    K3Nv2 @ K3Nv2: Att is displaying prices like it's an ingredients list now lol