Hacking Pokemon Bank not working on emunand

masterzero

Well-Known Member
Member
Joined
Apr 20, 2007
Messages
624
Trophies
0
XP
492
Country
games that need 7.0 will need time to come out ? since I guess they couldn't change the update they need working in mid development ? or can they?
 
  • Like
Reactions: 1 person

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
Would it be possible to just change the flag for 7.x keys, if the FW is patched to accept modified files

Or are the 7.x keys actually used to decrypt the game/apps
 

mathieulh

Well-Known Member
Member
Joined
Feb 28, 2008
Messages
378
Trophies
0
Website
keybase.io
XP
897
Country
France
Would it be possible to just change the flag for 7.x keys, if the FW is patched to accept modified files

Or are the 7.x keys actually used to decrypt the game/apps

It's obviously used to decrypt the container, you can't just hope for the NATIVE_FIRM to decrypt content that requires a key it can't access.
 

profi200

Banned!
Banned
Joined
Sep 3, 2011
Messages
330
Trophies
0
XP
282
Country
Gambia, The
And now it begins. No flashcard company can do a shit against that. They would need to decap the SoC, which i don't think they will do. The part of the NATIVE_FIRM, which generates the key for that, is in internal memory and therefore not even a RAM dumping setup do a shit here.

Nintendo did his homework this time. As long, as the system is secure against exploits, there is no chance. Currently it doesn't look like there is anything exploitable...
 

xextil

Active Member
Newcomer
Joined
Mar 12, 2007
Messages
38
Trophies
0
XP
216
Country
And now it begins. No flashcard company can do a shit against that. They would need to decap the SoC, which i don't think they will do. The part of the NATIVE_FIRM, which generates the key for that, is in internal memory and therefore not even a RAM dumping setup do a shit here.

Nintendo did his homework this time. As long, as the system is secure against exploits, there is no chance. Currently it doesn't look like there is anything exploitable...

Why not? They have enough money for that, and if they do it, they could find new exploits and make more money.
 

mathieulh

Well-Known Member
Member
Joined
Feb 28, 2008
Messages
378
Trophies
0
Website
keybase.io
XP
897
Country
France
And now it begins. No flashcard company can do a shit against that. They would need to decap the SoC, which i don't think they will do. The part of the NATIVE_FIRM, which generates the key for that, is in internal memory and therefore not even a RAM dumping setup do a shit here.

Nintendo did his homework this time. As long, as the system is secure against exploits, there is no chance. Currently it doesn't look like there is anything exploitable...

Actually, you don't need to dump the generated key from ram, if you can read/write to memory all you need is to gain code execution by patching instructions before the ones that clear the keyslot is executed, then you simply use your own code to generate the key and output it to wherever.

That's assuming you do have a working hardware RAM setup.

Of course it's not as easy as it looks.

Also since you cannot read the initial keyslot set by the bootrom (or the bootrom itself), you will need to keep generating new keys that Nintendo might add through future NATIVE_FIRM.
That doesn't seem much of a showstopper though, assuming you have the right setup to generate one already.

You should keep in mind that as long as you do get ARM9 code execution, you can read/write the content of the internal memory as well and there is code running off the external RAM before NATIVE_FIRM is executed, so it doesn't seem far fetched.
 

profi200

Banned!
Banned
Joined
Sep 3, 2011
Messages
330
Trophies
0
XP
282
Country
Gambia, The
Actually, you don't need to dump the generated key from ram, if you can read/write to memory all you need is to gain code execution by patching instructions before the ones that clear the keyslot is executed, then you simply use your own code to generate the key and output it to wherever.

That's assuming you do have a working hardware RAM setup.

No, you can do, what you want. You have no access to internal memory and therefore you can not patch anything. The NATIVE_FIRM is running in internal memory. If you have code execution through the RAM haxx, it is already to late.

Why not? They have enough money for that, and if they do it, they could find new exploits and make more money.

^ They don't really care about their customers. I bet they have enough money, so they could run off, if they want.
 

Steena

Well-Known Member
Member
Joined
Sep 13, 2009
Messages
647
Trophies
0
XP
763
Country
Italy
Given GW's constant delays I'd say it's pretty safe to assume that they won't be able to find a workaround for the aforementioned issue within the month (if ever, according to some of the more negative perspectives), so, for those that care about pokebank and are on emunand, you won't get to use your free month unless you use another 3DS.
 

misterb98

Moral Gateway User. Wat.
Member
Joined
Aug 24, 2010
Messages
449
Trophies
0
XP
290
Country
United States
The only way I can see to get around this problem is for someone to make a CFW (which is far, FAR away). It would need to be based off of 7.X and yet be able to run unsigned code.

Its going to be a LOOOOOONG wait.


That is unless an exploit is found for 7.X+, lol.
 

tyons

Well-Known Member
Member
Joined
Jul 11, 2012
Messages
657
Trophies
1
XP
282
Country
Italy
[...] so, for those that care about pokebank and are on emunand, you won't get to use your free month unless you use another 3DS.

or, if someone can confirm that it would work, do the following:

mount the hardware mod;
backup the 4.x realnand;
update realnand to 7.x;
download the pokebank;
transfer the pokes from BW/BW2 to the global link (and I assume we don't need the X/Y cartridge at all to do it);
backup the 7.x realnand for the future;
restore the 4.x realnand;
enter X/Y in emunand and transfer the pokes into the game.
 

tyons

Well-Known Member
Member
Joined
Jul 11, 2012
Messages
657
Trophies
1
XP
282
Country
Italy
I thought we could do it just with the normal games. I don't know how the pokebank software works, that's the problem.

edit: ok I searched and probably we have to move the pokes from the bank's boxes to the game's ones, so yeah, that method doesn't work...

come onnn pokecheck guyssss!!! >_>
 

Arras

Well-Known Member
Member
Joined
Sep 14, 2010
Messages
6,318
Trophies
2
XP
5,430
Country
Netherlands
The only way I can see to get around this problem is for someone to make a CFW (which is far, FAR away). It would need to be based off of 7.X and yet be able to run unsigned code.

Its going to be a LOOOOOONG wait.


That is unless an exploit is found for 7.X+, lol.
And then Nintendo releases 8.x which uses a different key and fixes the exploit :P
Can some one check the us pokebank app now that it's out?
It's almost guaranteed to have the same issue considering it came out after the EU one.
or, if someone can confirm that it would work, do the following:

mount the hardware mod;
backup the 4.x realnand;
update realnand to 7.x;
download the pokebank;
transfer the pokes from BW/BW2 to the global link (and I assume we don't need the X/Y cartridge at all to do it);
backup the 7.x realnand for the future;
restore the 4.x realnand;
enter X/Y in emunand and transfer the pokes into the game.
You would be able to transfer from BW2->Bank yeah, but Bank->XY requires Bank to read the XY save data. If said save data was created with 4.X chances are very high it will read as corrupt on 7.1 realNAND, and even if it doesn't, after you save the save file will be corrupt on 4.X. And then there's the protection that prevents you from messing with save files that may trigger if you restore NAND.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Psionic Roshambo @ Psionic Roshambo:
    I just want a Pokemon Hell Raiser fan game 😭
  • K3Nv2 @ K3Nv2:
    Anyone wanna play with my joydock
  • BigOnYa @ BigOnYa:
    Biomutant looks cool tho, may have to try that
  • Quincy @ Quincy:
    Usually when such a big title leaks the Temp will be the first to report about it (going off of historical reports here, Pokemon SV being the latest one I can recall seeing pop up here)
  • K3Nv2 @ K3Nv2:
    I still like how a freaking mp3 file hacks webos all that security defeated by text yet again
  • BigOnYa @ BigOnYa:
    They have simulators for everything nowdays, cray cray. How about a sim that shows you playing the Switch.
  • K3Nv2 @ K3Nv2:
    That's called yuzu
    +1
  • BigOnYa @ BigOnYa:
    I want a 120hz 4k tv but crazy how more expensive the 120hz over the 60hz are. Or even more crazy is the price of 8k's.
  • K3Nv2 @ K3Nv2:
    No real point since movies are 30fps
  • BigOnYa @ BigOnYa:
    Not a big movie buff, more of a gamer tbh. And Series X is 120hz 8k ready, but yea only 120hz 4k games out right now, but thinking of in the future.
  • K3Nv2 @ K3Nv2:
    Mostly why you never see TV manufacturers going post 60hz
  • BigOnYa @ BigOnYa:
    I only watch tv when i goto bed, it puts me to sleep, and I have a nas drive filled w my fav shows so i can watch them in order, commercial free. I usually watch Married w Children, or South Park
  • K3Nv2 @ K3Nv2:
    Stremio ruined my need for nas
  • BigOnYa @ BigOnYa:
    I stream from Nas to firestick, one on every tv, and use Kodi. I'm happy w it, plays everything. (I pirate/torrent shows/movies on pc, and put on nas)
  • K3Nv2 @ K3Nv2:
    Kodi repost are still pretty popular
  • BigOnYa @ BigOnYa:
    What the hell is Kodi reposts? what do you mean, or "Wut?" -xdqwerty
  • K3Nv2 @ K3Nv2:
    Google them basically web crawlers to movie sites
  • BigOnYa @ BigOnYa:
    oh you mean the 3rd party apps on Kodi, yea i know what you mean, yea there are still a few cool ones, in fact watched the new planet of the apes movie other night w wifey thru one, was good pic surprisingly, not a cam
  • BigOnYa @ BigOnYa:
    Damn, only $2.06 and free shipping. Gotta cost more for them to ship than $2.06
  • BigOnYa @ BigOnYa:
    I got my Dad a firestick for Xmas and showed him those 3rd party sites on Kodi, he loves it, all he watches anymore. He said he has got 3 letters from AT&T already about pirating, but he says f them, let them shut my internet off (He wants out of his AT&T contract anyways)
  • K3Nv2 @ K3Nv2:
    That's where stremio comes to play never got a letter about it
  • BigOnYa @ BigOnYa:
    I just use a VPN, even give him my login and password so can use it also, and he refuses, he's funny.
  • BigOnYa @ BigOnYa:
    I had to find and get him an old style flip phone even without text, cause thats what he wanted. No text, no internet, only phone calls. Old, old school.
    BigOnYa @ BigOnYa: I had to find and get him an old style flip phone even without text, cause thats what he wanted...