Hacking Permanent Custom Firmware?

Huntereb

Well-Known Member
Member
Joined
Sep 1, 2013
Messages
3,234
Trophies
0
Website
lewd.pics
XP
2,446
Country
United States
Hey guys, none of this external thinking. We shouldn't be biting the hand that feeds us!

In order for anything to happen, we need a way of signing software that the system will think is legitimate firmware. 0-Key encryption is far from usable here, and it's the only thing we've got for recompiling software.
 

SSG Vegeta

Well-Known Member
Member
Joined
Jul 25, 2013
Messages
683
Trophies
1
XP
1,432
Country
United States
thanks, is this as deep as the answer goes, however?

You could install Emunand to the system itself using the usb mod but it'll limit your system because certain games don't work of course that might all change in the future that's as close as CFW gets on the 3DS
 

yusuo

Well-Known Member
Member
Joined
Oct 19, 2006
Messages
3,504
Trophies
2
Age
38
XP
6,174
Country
United Kingdom
This was discussed literally 2 days ago, do we need to make a new thread for every idiot who cant be bothered to read the damn forums. Mods I beg you please lock this
 

Vappy

Well-Known Member
Member
Joined
May 23, 2012
Messages
1,508
Trophies
2
XP
2,613
Country
You could install Emunand to the system itself using the usb mod but it'll limit your system because certain games don't work of course that might all change in the future that's as close as CFW gets on the 3DS

Then it'd just be a standard 8.x console, or whatever version firmware your emuNAND was on. No Gateway patches are applied to it on boot, so not sure what the point would be.
 
  • Like
Reactions: Huntereb

Huntereb

Well-Known Member
Member
Joined
Sep 1, 2013
Messages
3,234
Trophies
0
Website
lewd.pics
XP
2,446
Country
United States
Signing software is not the same to encrypting it.

0-Key encryption is as far as we've gotten, though. Won't be able to run anything on any system by itself like that unless we can get it to recognize files with that encryption method as legitimate, like what Gateway's launcher does. The issue is that any software we install to the system that is illegitimately encrypted and signed won't run on a normal system. Installing what we're able to do now to a 3DS would be a good way of bricking it.
 

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
as has already been said the only way its happening is with a bootloader exploit,a way to sign content and encrypt it properly or through some sort of black magic, tbh the current setup is pretty good, could be worse like needing to trigger a save exploit every time you want to use it, at least the current method remains on the console so you dont need to carry a specific cart around at all time
 
  • Like
Reactions: Huntereb

SSG Vegeta

Well-Known Member
Member
Joined
Jul 25, 2013
Messages
683
Trophies
1
XP
1,432
Country
United States
Then it'd just be a standard 8.x console, or whatever version firmware your emuNAND was on. No Gateway patches are applied to it on boot, so not sure what the point would be.

But that doesn't mean that you can't install an upgraded Emunand
 

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
But that doesn't mean that you can't install an upgraded Emunand
what he is saying is emunand is just a updated nand.....so why bother installing when its pretty much the same as just updating your console, there is no real difference between emunand and sysnand except where they are stored......all the patches that gateway apply are applied based on the 4.x exploit, if you where to install it to your sysnand, that means there is no 4.x base to run the patches....so its a stock 8.x nand
 

drfsupercenter

Flash Cart Aficionado
Member
Joined
Mar 26, 2008
Messages
1,909
Trophies
1
XP
1,163
Country
United States
I'm thinking - theoretically you could do it, but we'd need more hacking knowledge.

If you have a NAND flasher... theoretically you could flash some other NAND to it. If somebody figures out how to break the "chain of trust" as someone referred to it earlier in this thread... you could theoretically load a CFW that way. Think something like how CyanogenMod works on cellphones - you use the stock bootloader but then edit the code so it boots your custom thing instead of stock.

Granted, that's super generic terminology, but it's about all I'm able to use. I don't know anything about the 3DS inner workings, but given that you can already flash between 4.x and emuNAND on the same unit, I'm sure someday you'll be able to flash a modded one too.

Even if, let's say - you have to boot it using the 4.x kernel exploit to install your .cia files, then take the emuNAND and flash it back to stock?
 

Vappy

Well-Known Member
Member
Joined
May 23, 2012
Messages
1,508
Trophies
2
XP
2,613
Country
Yeah it's easy enough to flash the modified NAND image to the console, it's getting it to load that's the problem.
Some months ago, gaasedelen was in the initial stages of attempting a decap of the 3DS SoC. The project got put on hold, was said to resume in August but no mention of it since. Someone could maybe ask if he wants to carry on with it, seems like currently the strongest possibility of getting something useful in this area.
 

DinohScene

Gay twink catboy
Global Moderator
Joined
Oct 11, 2011
Messages
22,561
Trophies
4
Location
Восторг
XP
22,893
Country
Antarctica
Yeah it's easy enough to flash the modified NAND image to the console, it's getting it to load that's the problem.
Some months ago, gaasedelen was in the initial stages of attempting a decap of the 3DS SoC. The project got put on hold, was said to resume in August but no mention of it since. Someone could maybe ask if he wants to carry on with it, seems like currently the strongest possibility of getting something useful in this area.

bunnie I think also was attempting to decap it.
 

Vappy

Well-Known Member
Member
Joined
May 23, 2012
Messages
1,508
Trophies
2
XP
2,613
Country
No reason for them to. The exploit was already documented enough on 3dbrew that they could make something of it. Or maybe they paid off someone who'd already done the base work. Who knows. :P
bunnie I think also was attempting to decap it.

bunnie or bunnei? Cause one's the guy working on Citra, the other is ex-Xbox hacker turned laptop designer, I'd be surprised if he was taking a sudden renewed interest in console hacking.
 

DinohScene

Gay twink catboy
Global Moderator
Joined
Oct 11, 2011
Messages
22,561
Trophies
4
Location
Восторг
XP
22,893
Country
Antarctica
bunnie or bunnei? Cause one's the guy working on Citra, the other is ex-Xbox hacker turned laptop designer, I'd be surprised if he was taking a sudden renewed interest in console hacking.

Nay I misread it on gaasedelen his blog.
It's a different Andrew then bunnie.
 

Deleted member 333767

Well-Known Member
Member
Joined
Aug 20, 2013
Messages
1,932
Trophies
2
XP
1,473
I think OP is getting a bit ahead of themselves here.

Currently we have kernel access (MSET exploit, Gateway etc.) which is one privilege level above 'userland' (i.e. SSSpwn)

Until we can have CFW we still need to breakthough (and this purely speculation here) the hypervisor which is a step up in privilege from the Kernel.

After that currently impossible task, we need another privilege escalation to, what famous hacker Yifanlu states as "the holy grail, the final boss" or the bootloader.

Once one has tinkered with the device to this stage the 3DS with be "hacked" in every definition of the term. Were talking like maybe 5-10 years from now.

Come on budding hackers, get to work! :yaysp:
 
  • Like
Reactions: sj33

SonyUSA

We're all mad here
Editorial Team
Joined
May 12, 2006
Messages
1,780
Trophies
2
XP
5,637
Country
United States
CFW can be written to the 3ds, that's not the issue. The issue is the boot rom will fail the sig check and the system will not boot. No way to modify the boot rom because it's not writable, and cfw will never match the correct signature of a nintendo fw.
 
  • Like
Reactions: Huntereb

andre104623

Well-Known Member
Member
Joined
Apr 9, 2014
Messages
680
Trophies
0
Age
37
Location
Philadelphia, PA
XP
417
Country
United States
CFW on 3ds will happen because it has most likely been done. Smea has stated that ssspwn can not run any backups just because he only supports homebrew. But that does not mean it can't with some work. If you run ssspwn on 4.1-4.5 3ds you surely could get backups to run if you can get them running off the SD card of the 3ds. This is one of the big reasons smea won't release ssspwn because he knows someone will mod his work for backups. Look at the ps3 psjailbreak, they came out with there dongle to play backups and homebrew and even it was a dongle it was software that hacked the ps3 then geohot came out with his "Homebrew only" CFW that lasted about a week till backups were running. The 3ds is going down a very similar road we have hardware flashcard's that all relay on software hacks to work. If someone figures out how to run games from the 3ds's SD card the flashcards are dead

If you think about it we already have a "lite" CFW of sort. The emu-nand can run backups 'super smash" and I just got a gateway and back 9 months ago I had emu-nand on my r4i deluxe and to only thing it was for is e-shop. Now gateway can run homebrew and backups in 8.1 fw on emunand but still 8.1 so if you think about its kind-of like CFW
 
  • Like
Reactions: cvskid

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • BigOnYa @ BigOnYa:
    Biomutant looks cool tho, may have to try that
  • Quincy @ Quincy:
    Usually when such a big title leaks the Temp will be the first to report about it (going off of historical reports here, Pokemon SV being the latest one I can recall seeing pop up here)
  • K3Nv2 @ K3Nv2:
    I still like how a freaking mp3 file hacks webos all that security defeated by text yet again
  • BigOnYa @ BigOnYa:
    They have simulators for everything nowdays, cray cray. How about a sim that shows you playing the Switch.
  • K3Nv2 @ K3Nv2:
    That's called yuzu
    +1
  • BigOnYa @ BigOnYa:
    I want a 120hz 4k tv but crazy how more expensive the 120hz over the 60hz are. Or even more crazy is the price of 8k's.
  • K3Nv2 @ K3Nv2:
    No real point since movies are 30fps
  • BigOnYa @ BigOnYa:
    Not a big movie buff, more of a gamer tbh. And Series X is 120hz 8k ready, but yea only 120hz 4k games out right now, but thinking of in the future.
  • K3Nv2 @ K3Nv2:
    Mostly why you never see TV manufacturers going post 60hz
  • BigOnYa @ BigOnYa:
    I only watch tv when i goto bed, it puts me to sleep, and I have a nas drive filled w my fav shows so i can watch them in order, commercial free. I usually watch Married w Children, or South Park
  • K3Nv2 @ K3Nv2:
    Stremio ruined my need for nas
  • BigOnYa @ BigOnYa:
    I stream from Nas to firestick, one on every tv, and use Kodi. I'm happy w it, plays everything. (I pirate/torrent shows/movies on pc, and put on nas)
  • K3Nv2 @ K3Nv2:
    Kodi repost are still pretty popular
  • BigOnYa @ BigOnYa:
    What the hell is Kodi reposts? what do you mean, or "Wut?" -xdqwerty
  • K3Nv2 @ K3Nv2:
    Google them basically web crawlers to movie sites
  • BigOnYa @ BigOnYa:
    oh you mean the 3rd party apps on Kodi, yea i know what you mean, yea there are still a few cool ones, in fact watched the new planet of the apes movie other night w wifey thru one, was good pic surprisingly, not a cam
  • BigOnYa @ BigOnYa:
    Damn, only $2.06 and free shipping. Gotta cost more for them to ship than $2.06
  • BigOnYa @ BigOnYa:
    I got my Dad a firestick for Xmas and showed him those 3rd party sites on Kodi, he loves it, all he watches anymore. He said he has got 3 letters from AT&T already about pirating, but he says f them, let them shut my internet off (He wants out of his AT&T contract anyways)
  • K3Nv2 @ K3Nv2:
    That's where stremio comes to play never got a letter about it
  • BigOnYa @ BigOnYa:
    I just use a VPN, even give him my login and password so can use it also, and he refuses, he's funny.
  • BigOnYa @ BigOnYa:
    I had to find and get him an old style flip phone even without text, cause thats what he wanted. No text, no internet, only phone calls. Old, old school.
    K3Nv2 @ K3Nv2: @BigOnYa...