Hacking New Gateway Update 29/07/2013

  • Thread starter Thread starter michael18
  • Start date Start date
  • Views Views 133,531
  • Replies Replies 487
  • Likes Likes 2
Nope. I'm not one of the Gateway idiots, but i know, how it works. I know, where the vulnerability, which the blue Gateway uses, is. If you don't trust me, ask yellows8 or neimod.
 
  • Like
Reactions: Boy12 and 3DSGuy
The thing is, people on PS3 scene can play any game up to date with custom game patched. I, personally, don't give a sh** about my numbers in about screen if I can play any game.
That's because some major PS3 cryptography keys are known. It was so big (for something like that to be hacked out) that it hit mainstream media and the guys gave a presentation at a hacking convention.

That is entirely speculation.
No, it's an educated guess. Everything they tell us (especially the mention of the entry point) matches what we've known for a while about 4.x and above, that there's a save data exploit (used as an entrypoint), but the kernel-mode exploit was closed in 5.x.
 
That is entirely speculation.


Besides the very few snippets of information provided through the three news updates, and brief emails here and there, EVERYTHING that's been said and is being said currently about GW3DS since they first made themselves public has been speculation.
 
Exactly. They are based on 2 vulnerabilities. One is fixed in 5.X and the other works up to 6.1, but if the second is fixed, the blue Gateway becomes useless and it is over. Without the second vulnerabillity a kernelmode exploit is useless, because kernelmode exploits are inside the system. The last chance to get it working then is a savegame exploit, but there are not a good chance to find one, because, there are not so many games with the old savegame encryption and to modifi the savegame, ARM9 code execution is needed (generating AES MAC).


say, you need to feed the binary blob with a correct AES MAC so it can be re-encrypted? sandboxed mode requires some authentication to let run code outside?
 
Exactly. They are based on 2 vulnerabilities. One is fixed in 5.X and the other works up to 6.1
so,which one is the kernelmode exploit ? the one still in 6.1 system?or the already patched one?
on 3Dbrew,it seems that they said the kernel one has been patched already,which is more precious than the savedata one.(though,maybe i misunderstood the whole situation)
 
say, you need to feed the binary blob with a correct AES MAC so it can be re-encrypted? sandboxed mode requires some authentication to let run code outside?
No, the save encryption for early games is already known so re-encrypting is no problem. But in order to update the savegame AES MAC, the key-scrambler, the savegame's KeyY, and the KeyX for savegames is required. Currently(Except for the savegame's KeyY) only Nintendo and each 3DS knows that. So the only practical way of updating the AES MAC, is via a 3DS with ARM9 code execution.
 
  • Like
Reactions: profi200
Did they invent Windows in one day? I guess not.

It takes time for such cards to find exploitable points on the device, so they can do their work.

It's the same with jailbreaking the iDevices.
 
  • Like
Reactions: Boy12
so,which one is the kernelmode exploit ? the one still in 6.1 system?or the already patched one?
on 3Dbrew,it seems that they said the kernel one has been patched already,which is more precious than the savedata one.(though,maybe i misunderstood the whole situation)
Yes, the kernelmode exploit is already fixed in 5.X. Without a new kernelmode exploit, there is no chance to get it working up to 6.1, because they patch some parts of the firmware in RAM to disable some security. This needs total control.
 
  • Like
Reactions: f0rCe and 3DSGuy
Sorry if this isn't the place to post this

If i'm correct their are 3 types of 3ds':
-Europe
-USA
-Japanese

The 3ds in Australia have -E at the end of their version
Does that mean European roms would work on the gateway on an Australian 3ds
 
Yes, the kernelmode exploit is already fixed in 5.X. Without a new kernelmode exploit, there is no chance to get it working up to 6.1, because they patch some parts of the firmware in RAM to disable some security. This needs total control.


Isn't it possible to install a modified 5.x+ version of firmware on an already hacked 3DS? If you already have total control at 4.5 firmware, isn't it possible to somehow get access to the newer firmware without installing it, examine and modify it, and install the modified version instead of the official one?
 

Site & Scene News

Popular threads in this forum