Hacking [Suspended] ARM11 kernel access project

Status
Not open for further replies.
Joined
Feb 15, 2015
Messages
1,464
Trophies
0
XP
1,099
Country
United States
Announcement: Project (publicly) suspended!

Work will still be going on behind the scenes, but with the extensive work needed to RE things and this thread becoming crap, I need to clarify this. You will get something when we get somewhere. PM me if you need me. Could a mod lock this thread?
 
Last edited by MassExplosion213,

Intronaut

A star maker
Member
Joined
Nov 18, 2014
Messages
772
Trophies
0
Age
30
XP
1,005
Country
Chile
Great!

As I said before, this would allow fw spoofing, legit CIA installation and full system downgrade( according to shinyquagsire, and N3DS users will be only able to do it as far as they are bellow 9.5)

best luck for you!
 
  • Like
Reactions: Margen67
Joined
Aug 10, 2015
Messages
369
Trophies
0
XP
489
Country
Canada
Great!

As I said before, this would allow fw spoofing, legit CIA installation and full system downgrade( according to shinyquagsire, and N3DS users will be only able to do it as far as they are bellow 9.5)

best luck for you!

For Old3DS it will able for 9.9.0-26U users ?
 
  • Like
Reactions: Margen67

Intronaut

A star maker
Member
Joined
Nov 18, 2014
Messages
772
Trophies
0
Age
30
XP
1,005
Country
Chile
Wait what's going on? What did I miss?

Basically, all you need to install .cias is ARM11 kernel access. But these can only be signed .cias, ARM9 kernel is needed for unsigned .cias. There is downgrading protection with system apps and normal apps, however it's flawed: You can delete an app and then install it directly afterwards, effectively making these protections void. Thus the MSET downgrade hack was formed. So in theory, if you had ARM11 kernel access you could do this remove->install trick on all system apps and modules, including the NATIVE_FIRM title. To remedy the two stored straight on the NAND used by the bootloader, you actually already have the xorpads needed for those. If you know what version you're already on, you can use that NATIVE_FIRM image to retrieve an xorpad for it, and use that xorpad to write an older NATIVE_FIRM (note, these are still signed FIRM images here). This probably isn't possible though for the N3DS, due the fact that the 9.6 and up NATIVE_FIRM binaries are stuck behind new encryption. You could at least though return some usermode exploits I suppose.

You might say though, why not just write the NATIVE_FIRM only? This could maybe work for a few firmware versions with minimal updates relying on new stuff in the FIRM, but if the firmware introduced any significant changes it will most likely fail to work.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    Ancientboi slept with Charles Babbage for a pc
    +1
  • AncientBoi @ AncientBoi:
    And his was BIG 😱
  • K3Nv2 @ K3Nv2:
    20kbps connection
    +1
  • SylverReZ @ SylverReZ:
    @AncientBoi, That's what she said. :rofl2:
    +1
  • K3Nv2 @ K3Nv2:
    Actually they say 400 years ago 1cm was pretty average so Juan wouldn't feel left out
    +2
  • ZeroT21 @ ZeroT21:
    oh my...
  • K3Nv2 @ K3Nv2:
    Ffs officials are closed on juneteenth guess it's fairly new became federal in 21:rofl2:
  • BigOnYa @ BigOnYa:
    I figured you'd be down at the parade anyways.
  • K3Nv2 @ K3Nv2:
    Nah I still own slaves just ask ancientboi his nicknames mister slave
    +1
  • BigOnYa @ BigOnYa:
    Poor Lemmiwinks...
  • ModernSithLord @ ModernSithLord:
    @BigOnYa Great episode, camp of tolerance
    +1
  • BigOnYa @ BigOnYa:
    Thanks, we try to make every episode, special.
    +1
  • K3Nv2 @ K3Nv2:
    I saw a $15 south park bundle box at Walmart kinda wish I bought it
    +2
  • ModernSithLord @ ModernSithLord:
    I remember seeing the movie when I was young, made me swear up a storm when I got home. lol
    +1
  • K3Nv2 @ K3Nv2:
    I'm gonna buy it if I see it there tomorrow
  • BigOnYa @ BigOnYa:
    That beanie will look good on you, Kentman
  • K3Nv2 @ K3Nv2:
    It would look better on urewife it would be like boning myself
  • BigOnYa @ BigOnYa:
    Started a new game last night called "The Quarry", pretty damn good. Feels/ looks like a movie. About a summer camp where local town folks go crazy and hunt down the campers.
  • K3Nv2 @ K3Nv2:
    I beat it when it first came out good playback ability
    +1
  • BigOnYa @ BigOnYa:
    What's crazy is I have 3tb in my SeriesX , and its almost full. Of course with some of these games being over 150gb each, it don't take long.
  • BigOnYa @ BigOnYa:
    I wish gamepass sold 12 month cards (with a discount), instead of 3 month only.
    Xdqwerty @ Xdqwerty: Hi