Hacking New Gateway Update 29/07/2013

  • Thread starter Thread starter michael18
  • Start date Start date
  • Views Views 133,531
  • Replies Replies 487
  • Likes Likes 2
screw you

its what i get for being over protective and having it redirected to me
mine better come soon -_-


:wub: Not until you buy me dinner first.

In other news, all set and ready to go. They typically drop stuff off here around, noonish. So expect a picture of two then.
 
:wub: Not until you buy me dinner first.

In other news, all set and ready to go. They typically drop stuff off here around, noonish. So expect a picture of two then.

lol well have fun
im going 3DS hunting
(hopefully going to be able to pick up a New Red 3DS for £80 so that will do my testing just fine)
 
:wub: Not until you buy me dinner first.

In other news, all set and ready to go. They typically drop stuff off here around, noonish. So expect a picture of two then.


1475584429_1369867738.jpg


If I don't hear anything from you by 12:02pm I'll consider you dead and buried in gitmo by someone on here who stole it.
 
OK I checked what the installer is doing in an emulator.
1.The installer gets 0x20000 Bytes and set them all to 0
2/3 set the first 0x200 Bytes (unknown src.)
2/3 set the last 0x200 Bytes (the User Settings) (unknown src.)
4 writes the Bytes with Page Program cmds to the ds flash
5 check if the data at 0x1FE00-0x1FFFF match.

here is the dump of the new user settings
B9F21000AE2B2700ED0DDCBA9CF1180090B6100000B0FA0000022000B9F210000090270001000000E1491500386F2700AC821B00DCD518004083270000021000CC480000603D1400B9F210000090270000002B00F9021000F9021000F9021000F9021000F9021000F9021000E14915005100CDC2E1491500209027008C5310000090000058391B00E504210000DA19000075010086DF210000C11A0022DA1D0091FE160000011000BC4C140000002B0000900000E1491500ACEF2200885C100000000E0090032500C0FA1E0091FE16008C531000246B0300603D140000000000000000000000000000000000000000000000000000000000000000000000B88900000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000006E000000000000000000000000000000000000000000000000000000000000005200DAB800000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000B9F2100000FE010000010000E149150000942700FC341300D08C1E008C5310009C9427F0603D140000000000000000000000000000000000000000000000000000000000000000000000CE06



My guess is that the exploit is a to long Message length (110 allowed 26)

add: XD 0xBADC0DED

another guess the second user settings the one with the exploit it contains stack to load the first (stack)
 
  • Like
Reactions: Syphurith
I'm curious how you got that it sets the bytes to 0.

Here's what I got: http://pastebin.com/KZ3B8fie
This is what megazig got: http://codepad.org/ObcdgNKj

As you can see, we agree mostly on everything, except megazig found a couple more patches and I found a weird copy of *0x300 to *0xA00. It's also weird that the address offsets are off by a shift of 2 (0x1FE00 -> 0x3FC00) if you observe the patches written. That may be some 3ds detail I don't know about.
 
I'm curious how you got that it sets the bytes to 0.

Here's what I got: http://pastebin.com/KZ3B8fie
This is what megazig got: http://codepad.org/ObcdgNKj

As you can see, we agree mostly on everything, except megazig found a couple more patches and I found a weird copy of *0x300 to *0xA00. It's also weird that the address offsets are off by a shift of 2 (0x1FE00 -> 0x3FC00) if you observe the patches written. That may be some 3ds detail I don't know about.

Sorry may bad, I thought the emulator would do things different.
 
I'm curious how you got that it sets the bytes to 0.

Here's what I got: http://pastebin.com/KZ3B8fie
This is what megazig got: http://codepad.org/ObcdgNKj

As you can see, we agree mostly on everything, except megazig found a couple more patches and I found a weird copy of *0x300 to *0xA00. It's also weird that the address offsets are off by a shift of 2 (0x1FE00 -> 0x3FC00) if you observe the patches written. That may be some 3ds detail I don't know about.


IIRC some ARM7 RAM areas are mirrored
 
I don't think this is been posted but looks like they got the region lock hacked and made newer games like Mario and Luigi to work:



I'm more excited now than ever, hurry up and hack FW 6 already XD

Edit: I tried installing the blue card software on my Acekard 2i and when it's done I didn't notice any difference in performance running it on my DS lite but it still won't work on my 3DS, I'm already on FW 6 btw, can anyone confirm if it works on Acekard 2i? At least I got a DS lite so I'm not missing on it.
 
It means your going to be sitting on that cart until they release an update that lets you run the gateway flashcart on 6.2.0.12U.


Got it. That's fine. This is the early stage of cards, so I want to wait till there is something more reliable and designed to be as future-proof as possible. In an age where a lot of games have downloadable content (this is the longest thing to circumvent), I don't want to be missing out on extra goodies. I have heard that the underpinnings of what the Gateway card does has been outed, presumably leading the way for others to follow suit, and for Nintendo to get a better idea of what's going on under the hood. Is this true?
 
Got it. That's fine. This is the early stage of cards, so I want to wait till there is something more reliable and designed to be as future-proof as possible. In an age where a lot of games have downloadable content (this is the longest thing to circumvent), I don't want to be missing out on extra goodies. I have heard that the underpinnings of what the Gateway card does has been outed, presumably leading the way for others to follow suit, and for Nintendo to get a better idea of what's going on under the hood. Is this true?


The file they use to activate their exploit got decrypted (or something of the like). It could possibly lead to clones with cheaper prices, yes, but until huge name companies get to work on their own flash cards, you're better off sticking with Gateway for their updates (since they're working on firmware spoofing, region unlocking, and most likely more).

And in regards to Nintendo, I doubt they needed to know about the info release in order to understand Gateway. It's their console, so I'm sure they have plenty of ways to figure out what it does and how.
 

Site & Scene News

Popular threads in this forum