Hacking [WIP] KARL3DS - Kernel access on N3DS via Ninjhax + Loadcode

Status
Not open for further replies.

WulfyStylez

SALT/Bemani Princess
Member
Joined
Nov 3, 2013
Messages
1,149
Trophies
0
XP
2,867
Country
United States
Read my post again. It doesn't break any signatures. Each individual file inside of the .CIA (there are usually SEVERAL) is signed by NUS. With a valid signature. Spoofing the version just spoofs the version on the header of the .CIA itself. The .CIA NEVER has a valid signature when 3DNUS creates it, spoofing or not, because nobody has the signing keys.

As I said, I've done the whitelist by myself with 3DNUS and spoofing and none of my consoles are bricked. And of course I did it to SYSNAND. There is zero point of doing it on EMUNAND because at that point, you've already been able to launch an exploit and playing DS games with the blue card simply will not work on emunand.

A CIA is a container for a bunch of signed data. Version numbers lie in the TMD and ticket, so modifying them will break signatures. The reason that DS whitelist breaking thing works is because the 3DS uses a fallback whitelist when it can't load the newer one from ctrnand.

Also there's only one TWL_FIRM for N3DS, and MSET doesn't break the ability to play DS and DSi stuff from emunand.
 

Hashtastrophe

Wizard
Member
Joined
Jan 12, 2015
Messages
442
Trophies
0
Location
Yes that kind of wizard.
XP
445
Country
Canada
...Also there's only one TWL_FIRM for N3DS, and MSET doesn't break the ability to play DS and DSi stuff from emunand.

So DSi games are going to be a working, usable thing in KARL? Does it still force a reset into sysnand or did you guys get that fixed? Now I can finally play that one DSi game that I have installed and maybe some actual physical carts provided I can even find them.
 

WulfyStylez

SALT/Bemani Princess
Member
Joined
Nov 3, 2013
Messages
1,149
Trophies
0
XP
2,867
Country
United States
So DSi games are going to be a working, usable thing in KARL? Does it still force a reset into sysnand or did you guys get that fixed? Now I can finally play that one DSi game that I have installed and maybe some actual physical carts provided I can even find them.

We don't have anything to announce for that first part juuust yet (I've been distracted as heck). I will say that the forced reset is unavoidable, though.
 

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
Read my post again. It doesn't break any signatures. Each individual file inside of the .CIA (there are usually SEVERAL) is signed by NUS. With a valid signature. Spoofing the version just spoofs the version on the header of the .CIA itself. The .CIA NEVER has a valid signature when 3DNUS creates it, spoofing or not, because nobody has the signing keys.

As I said, I've done the whitelist by myself with 3DNUS and spoofing and none of my consoles are bricked. And of course I did it to SYSNAND. There is zero point of doing it on EMUNAND because at that point, you've already been able to launch an exploit and playing DS games with the blue card simply will not work on emunand.
........go try with something other than the whitelist.......the whitelist can be left broken and the 3ds will not be bricked, give it a try with TWL_FIRM........see how far it gets you ;)
 

Hashtastrophe

Wizard
Member
Joined
Jan 12, 2015
Messages
442
Trophies
0
Location
Yes that kind of wizard.
XP
445
Country
Canada
We don't have anything to announce for that first part juuust yet (I've been distracted as heck). I will say that the forced reset is unavoidable, though.
Yeah, I figured the reset wasn't going to change. No big deal though, just boot back into emunand. I'd put that in a readme though if it makes it into release. That way you can say you warned them when they inevitably update their sysnand.
 

Apache Thunder

I have cameras in your head!
Member
Joined
Oct 7, 2007
Messages
4,426
Trophies
3
Age
36
Location
Levelland, Texas
Website
www.mariopc.co.nr
XP
6,792
Country
United States
urherenow's post is false and misleading and should be deleted. Someone will attempt to spoof a version of TWL or some other critical CIA and install it to sysnand and get a brick. It should be well known by now that changing the version string does break the signature and it only works with the DS Cart Whitelist because the 3DS doesn't need it to boot properly it has a fall back code for that one. Something else like TWL will either brick the console or brick TWL which will cause DS/DSi games to no longer boot. Even legit ones.
 

tony_2018

Well-Known Member
Member
Joined
Jan 3, 2014
Messages
3,107
Trophies
0
XP
1,012
Country
United States
Read my post again. It doesn't break any signatures. Each individual file inside of the .CIA (there are usually SEVERAL) is signed by NUS. With a valid signature. Spoofing the version just spoofs the version on the header of the .CIA itself. The .CIA NEVER has a valid signature when 3DNUS creates it, spoofing or not, because nobody has the signing keys.

As I said, I've done the whitelist by myself with 3DNUS and spoofing and none of my consoles are bricked. And of course I did it to SYSNAND. There is zero point of doing it on EMUNAND because at that point, you've already been able to launch an exploit and playing DS games with the blue card simply will not work on emunand.


If you're saying it works than show us the PoC.
 

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
urherenow's post is false and misleading and should be deleted. Someone will attempt to spoof a version of TWL or some other critical CIA and install it to sysnand and get a brick. It should be well known by now that changing the version string does break the signature and it only works with the DS Cart Whitelist because the 3DS doesn't need it to boot properly it has a fall back code for that one. Something else like TWL will either brick the console or brick TWL which will cause DS/DSi games to no longer boot. Even legit ones.
its a struggle sometimes to get people to stop posting BS as if its FACT!
if people havent tried something, dont just say its safe....then again who am i to argue if people feeling like bricking their own system
 

WulfyStylez

SALT/Bemani Princess
Member
Joined
Nov 3, 2013
Messages
1,149
Trophies
0
XP
2,867
Country
United States
I've been following this for a while now. There's a rumor of 9.5 support coming in the future? True or no?
9.5 is already supported. 9.6 is supported on old3DS, and we have 9.6's New 3DS NATIVE_FIRM decrypted for research reasons. We won't be able to support 9.6+ until new system hax arrive one way or another, though.

Also I proved that person is really super wrong, let's just leave it at that.
 
  • Like
Reactions: Margen67

Oishikatta

Well-Known Member
Member
Joined
Oct 30, 2014
Messages
971
Trophies
0
XP
603
Country
United States
9.5 is already supported. 9.6 is supported on old3DS, and we have 9.6's New 3DS NATIVE_FIRM decrypted for research reasons. We won't be able to support 9.6+ until new system hax arrive one way or another, though.

Also I proved that person is really super wrong, let's just leave it at that.


I think they were asking about 9.5 sysnand, but you mean emunand right?
 

WulfyStylez

SALT/Bemani Princess
Member
Joined
Nov 3, 2013
Messages
1,149
Trophies
0
XP
2,867
Country
United States
A little status update: We now have ARM11 kernel exec working 100% of the time from mset! We had to pretty much remake bootstrap from scratch to get it to work, and I made sure to make it super portable so we can port to spider very quickly in the future. The next thing to do is port firmlaunch-hax stuff to this, and we'll be done!
 

Xenon Hacks

Well-Known Member
Member
Joined
Nov 13, 2014
Messages
7,414
Trophies
1
Age
30
XP
4,687
Country
United States
A little status update: We now have ARM11 kernel exec working 100% of the time from mset! We had to pretty much remake bootstrap from scratch to get it to work, and I made sure to make it super portable so we can port to spider very quickly in the future. The next thing to do is port firmlaunch-hax stuff to this, and we'll be done!

Can we run use our Gateway cards while using this?
*please dont hurt me*
 

urherenow

Well-Known Member
Member
Joined
Mar 8, 2009
Messages
4,777
Trophies
2
Age
48
Location
Japan
XP
3,677
Country
United States
urherenow's post is false and misleading and should be deleted. Someone will attempt to spoof a version of TWL or some other critical CIA and install it to sysnand and get a brick. It should be well known by now that changing the version string does break the signature and it only works with the DS Cart Whitelist because the 3DS doesn't need it to boot properly it has a fall back code for that one. Something else like TWL will either brick the console or brick TWL which will cause DS/DSi games to no longer boot. Even legit ones.
I've done more than the white list. I also did the Nintendo zone list. I can say with 100% certainty that neither of those cause a brick (I did it to both O3DS and N3DS so I can play DS games with the blue card, and I can use Nintendo Zone with an SSID of attwifi). I'll edit the other post until I experiment with TWL. But I have no clue why anybody would want to spoof TWL (it's probably just a bad example) or how changing the .CIA version would break more than is already broken. The files are not downloaded as a .CIA. 3DNUS packs them into a .CIA and doesn't use a valid signing key to do so.
 

Death78793

What is this, a first person shooter?
Member
Joined
Jan 16, 2015
Messages
251
Trophies
0
Age
28
XP
379
Country
A little status update: We now have ARM11 kernel exec working 100% of the time from mset! We had to pretty much remake bootstrap from scratch to get it to work, and I made sure to make it super portable so we can port to spider very quickly in the future. The next thing to do is port firmlaunch-hax stuff to this, and we'll be done!

Holy crap you guys are fast! This would take anyone else months of work to get done! I'm genuinely impressed!
printf_s("Have a cookie");
getchar();
 
  • Like
Reactions: Margen67
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Sicklyboy @ Sicklyboy: I could claw back 14tb by only doing 2 parity disks but I feel like with 13 disks in the RAID...