Hacking [WIP] KARL3DS - Kernel access on N3DS via Ninjhax + Loadcode

Status
Not open for further replies.

motezazer

Well-Known Member
Member
Joined
Feb 6, 2015
Messages
1,214
Trophies
0
Age
24
XP
1,442
Country
France
1. My friend, 3dbrew says:




If bootrom was dumped, they would know exactly when ARM9 memory get initialized -> this means bootrom is not dumped?

We can't know when its initialized, because we can't know how much time the instructions take to execute.
In the Decaf Fundraiser page, it's clearly stated that the bootrom was dumped.

2. I not talking about disable NAND, I talking 2 physical NAND which can be switched by HW mod. Maybe there are other ways to do it, but this is my simple idea
Can you swap hard disks while the OS is running?

EDIT : excuse me, this was not this flaw that allowed bootrom dumping for core scene members.
 

guitarheroknight

1.6180339887
Member
Joined
Nov 9, 2014
Messages
2,822
Trophies
1
Age
33
Location
Grand Line
XP
4,418
Country
Norway
I would like to believe that this is still to be released. Karl is several steps above GW and RXTOOLS in terms of features and knowledge. There's so much that they can't throw away.
Funny you should mention it since KARL is the only team with no results so far :rolleyes:



Aaanyway is this HW mod something like the RGH on the 360?
 
  • Like
Reactions: Margen67

motezazer

Well-Known Member
Member
Joined
Feb 6, 2015
Messages
1,214
Trophies
0
Age
24
XP
1,442
Country
France
Funny you should mention it since KARL is the only team with no results so far :rolleyes:



Aaanyway is this HW mod something like the RGH on the 360?

No. It's something like a electromagnetic transmitter (the objective is to inject a fault in the CPU).

To KARL3DS team :
on 3dbrew, yellows8 asks you if you successfully exploited this hax.
 
  • Like
Reactions: Margen67

Psi-hate

GBATemp's Official Psi-Hater
Member
Joined
Dec 14, 2014
Messages
1,750
Trophies
1
XP
3,432
Country
United States
If they hadn't had any success, then that'd mean that they didn't break the encryption on the 9.6 demo, which they did. :P
 
  • Like
Reactions: Margen67

proruskii

Member
Newcomer
Joined
May 14, 2015
Messages
15
Trophies
0
Age
42
XP
79
Country
Serbia, Republic of
Look here: http://3dbrew.org/wiki/3DS_System_Flaws#arm9loader

Starting with 9.6.0-X a new set of NAND-based keys were introduced. However, they forgot to add a verification block to verify that the new key read from NAND is correct. This was an issue from the very beginning with the original sector+0 keydata, however the below is only possible with the sector+0x10 keydata.
Thus, by writing an incorrect key to NAND you can make arm9loader decrypt ARM9 kernel as garbage and then jump to it.
This allows an hardware-based NAND-attack where you can boot into an older exploited firmware, fill all memory with NOP sleds/jump-instructions, and then reboot into executing garbage. By automating this process eventually you'll find some garbage that jumps to your code.
This should give you very early ARM9 code execution (pre-ARM9 kernel). For example, you can dump RSA keyslots with this and calculate the 6.x save, and 7.x NCCH keys. This cannot be used to recover keys initialized by arm9loader itself. This is due to it wiping the area used for its stack during NAND sector decryption and keyslot init. Due to FIRMs on both Old and New 3DS using the same RSA data, this can be exploited on Old3DS as well, but only if one already has the actual plaintext normalkey from New3DS NAND sector 0x96 offset0 and has dumped the OTP area of the Old3DS.

With this trick you can run a9 code with N3DS 9.6 AES keys not cleared! This mean you can decrypt any 9.6 N3DS title... But you can only do it if you have NAND mod. I hope I make sense
 
  • Like
Reactions: Margen67

motezazer

Well-Known Member
Member
Joined
Feb 6, 2015
Messages
1,214
Trophies
0
Age
24
XP
1,442
Country
France
Look here: http://3dbrew.org/wiki/3DS_System_Flaws#arm9loader



With this trick you can run a9 code with N3DS 9.6 AES keys not cleared! This mean you can decrypt any 9.6 N3DS title... But you can only do it if you have NAND mod. I hope I make sense

No. You have to replace the true generation key with garbage to make this working, so the 9.6 keys would be garbage and not the true keys.
 
  • Like
Reactions: Margen67

Just3DS

Well-Known Member
Member
Joined
Jan 31, 2015
Messages
440
Trophies
0
XP
237
Country
Well it is a good thing that bootrom (or keys) isn't shared publically, because if it is then big N would move on to their next iteration of DS console and we will never be able to see anymore titles on 3DS.
 

DSpider

Well-Known Member
Member
Joined
Mar 14, 2015
Messages
566
Trophies
0
XP
1,307
Country
Romania
Well it is a good thing that bootrom (or keys) isn't shared publically, because if it is then big N would move on to their next iteration of DS console and we will never be able to see anymore titles on 3DS.

The PS3 private keys were discovered in 2010 and made public at the beginning of 2011, and then the developers continued to release games on the damn thing even 5 years later.
 
  • Like
Reactions: Margen67

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
but they didn't paint their fingernails red sooo no points for that.
top 3 3ds hack video's
1. Gateway - for starting it all
2. QQ3DS - for trying so desperately to out shine gateway's red nails
3. SonyUSA - For proving you can still try to paint your nails in an earthquake

....everyone else should be ashamed of themselves
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    @Psionic Roshambo, Was the pot farmer in San andreas
  • Psionic Roshambo @ Psionic Roshambo:
    I tell people I wrestled a 5 foot alligator and they get this smile like this guy is full of shit lol the reality is I am sad it got away.... I wanted a pet alligator lol
  • BigOnYa @ BigOnYa:
    You live in Florida, so I believe it, you guys are crazy.
  • Psionic Roshambo @ Psionic Roshambo:
    At the time I would have probably fed it people lol
  • Psionic Roshambo @ Psionic Roshambo:
    Seriously cocaine not even once lol
  • BigOnYa @ BigOnYa:
    Not even once, but 100's of times
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    My girlfriend at the time, she had me stay up with her all night because some how the crazy bitch had spent like 12 hours snorting 2 8 balls, didn't use any water (gotta clean your nose) so she had so much crusted in her nose I was sure she was gonna blow up her heart. I mean this was the stuff right off the boat so absolutely pure. ugghh so annoying
  • Psionic Roshambo @ Psionic Roshambo:
    Also doing like 320 dollars worth of coke in half a day lol damn it
  • Psionic Roshambo @ Psionic Roshambo:
    hmmm 360 even lol
  • Psionic Roshambo @ Psionic Roshambo:
    Well I was getting a discount so 320 is probably right
  • BigOnYa @ BigOnYa:
    That is cheap, I used to pay $100 for a tine.
  • Psionic Roshambo @ Psionic Roshambo:
    Tine? One gram?
  • BigOnYa @ BigOnYa:
    Sixteenth
  • Psionic Roshambo @ Psionic Roshambo:
    Also it was literally out of a kilo when I got it off the boat so absolutely pure
  • Psionic Roshambo @ Psionic Roshambo:
    Holy shiz that's a lot
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    I was getting 3.5 Grams for 320 could have stepped on it and doubled my money easy lol
    +1
  • BigOnYa @ BigOnYa:
    I'd be afraid to it nowdays, my heart would explode prob. I just stick beers n buds nowdays.
  • Psionic Roshambo @ Psionic Roshambo:
    I would get to drive from tarpon springs to like Miami a thousand bucks lol do that twice a week and back in 92 that was good money
  • Xdqwerty @ Xdqwerty:
    @BigOnYa,
    @Psionic Roshambo what are you guys talking about?
  • Psionic Roshambo @ Psionic Roshambo:
    Blew it on women and muscle cars lol
    +1
  • BigOnYa @ BigOnYa:
    @Xdqwerty Hamster food, its pricey nowadays to keep PCs running.
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    I don't do anything except cigarettes and gotta stop eventually lol
    +1
  • BigOnYa @ BigOnYa:
    I'd do surplus again if could find, and I was outside camping/fishing, and had a cooler full of beer.
    BigOnYa @ BigOnYa: I'd do surplus again if could find, and I was outside camping/fishing, and had a cooler full of...