Hacking Downgraded emuNAND

dubbz82

Well-Known Member
Member
Joined
Feb 2, 2014
Messages
1,572
Trophies
0
Age
41
XP
1,215
Country
United States
I k
well in there 2.0 b2 there was one check that triggered the brick code in the firm code also there is a way to trigger that brick code in the menu in 2.1 (it is now better obfuscated in 2.1). There are also checks in the firm in 2.1 but I don't know where it ends as it is better obfuscated but I think it end up in the brick install.

add Better safe than sorry


If it did check NAND checksums, every time a new update came out, EmuNAND would break...
 

ichichfly

Well-Known Member
Member
Joined
Sep 23, 2009
Messages
619
Trophies
1
XP
1,076
Country
Gambia, The
I k


If it did check NAND checksums, every time a new update came out, EmuNAND would break...
Well I have no idea why but a part of the checksum was in an array that depends on data that gets loaded from the NAND it is not much but well it looks like that one part is always the same currently I don't know if it stay the same in Data before 4.X also some patches break when the plates are not found (using any other menu Version).

also the NATIVE_FIRM is always loaded form the Launcher.dat
 

dubbz82

Well-Known Member
Member
Joined
Feb 2, 2014
Messages
1,572
Trophies
0
Age
41
XP
1,215
Country
United States
My guess is still worst case scenario, the emuNAND breaks...either way though, it should be an interesting experiment :)
 

Bond697

Dies, died, will die.
Member
Joined
Jun 7, 2009
Messages
350
Trophies
0
Age
39
Location
CT
XP
464
Country
United States
well in there 2.0 b2 there was one check that triggered the brick code in the firm code also there is a way to trigger that brick code in the menu in 2.1 (it is now better obfuscated in 2.1). There are also checks in the firm in 2.1 but I don't know where it ends as it is better obfuscated but I think it end up in the brick install.

add Better safe than sorry


where in their firm code/patches/payloads is there brick code? an address is fine. we found it in the launcher, but i don't recall seeing it in their supplied firm0.
 

Apache Thunder

I have cameras in your head!
Member
Joined
Oct 7, 2007
Messages
4,452
Trophies
3
Age
36
Location
Levelland, Texas
Website
www.mariopc.co.nr
XP
6,855
Country
United States
Does the mmset exploit even exist in the old 1.1 firmware? Some exploits show up as a result of a firmware update, and not necessarily something that crops up on a launch console at release. :P

There's two stages to the current exploit I believe. Even if the msett exploit exists in 1.1, the ROP chain exploit used later to load custom code might not work in that old a firmware. You'd basically be back at square one and have to search for a new exploit all over again. You're better off updating to 4.5 using a retail cart that requires it.

The current 4.5 exploit gives us pretty much all access to the console. Having an older firmware wouldn't give you more unless there's an exploit in the non-rewritable bootrom area (the area that probably stores the private encryption key). But even then, if a method is found to get that key, it could probably be done from 4.5 or newer exploit anyways... :P
 

loco365

Well-Known Member
OP
Member
Joined
Sep 1, 2010
Messages
5,457
Trophies
0
XP
2,927
Does the mmset exploit even exist in the old 1.1 firmware? Some exploits show up as a result of a firmware update, and not necessarily something that crops up on a launch console at release. :P

There's two stages to the current exploit I believe. Even if the msett exploit exists in 1.1, the ROP chain exploit used later to load custom code might not work in that old a firmware. You'd basically be back at square one and have to search for a new exploit all over again. You're better off updating to 4.5 using a retail cart that requires it.

The current 4.5 exploit gives us pretty much all access to the console. Having an older firmware wouldn't give you more unless there's an exploit in the non-rewritable bootrom area (the area that probably stores the private encryption key). But even then, if a method is found to get that key, it could probably be done from 4.5 or newer exploit anyways... :P

I know that it probably won't work on 1.1. I plan to back up 1.1 and upgrade to 4.X, then install an emuNAND with 1.1.
 

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,376
Trophies
4
Location
Space
XP
13,992
Country
Norway
So I managed to score a 1.1.0 3DS on Kijiji the other day, and I'm going to be paying for it next week. I'm thinking on doing the SD NAND mod to back up the 1.1 NAND so I can downgrade to it whenever, however, I'd like to try doing something different as a workaround, if that's possible. What I'd like to do, is set up an emuNAND, then take the emuNAND that the Gateway launcher made (That would have 4.X), and replace it with the 1.1 NAND (Mostly for the OK GO video) I made manually.

Has anyone tried this, and would something like this work properly? Or would the emuNAND break catastrophically?
I don't think anyone has tried it, but it's plausible. I doubt anyone has even thought to try it, as it's not terribly useful.
Some things will definitely be broken, and the emuNAND may not work at all. Gateway's patches most definitely won't work but if you can do without the things those enable (and it doesn't completely break the firmware when they are not working) then it could work for your purposes.

As you would have a hardware NAND dumping setup anyway recovering from a brick caused by Gateway's code like ichfly explained would only be an inconvenience.

But the question is, why? Why would you go through all tha trouble just to watch a video that you can watch right now without any of that hassle? The video's not that great that it's worth keeping and watching over and over.
 

loco365

Well-Known Member
OP
Member
Joined
Sep 1, 2010
Messages
5,457
Trophies
0
XP
2,927
I don't think anyone has tried it, but it's plausible. I doubt anyone has even thought to try it, as it's not terribly useful.
Some things will definitely be broken, and the emuNAND may not work at all. Gateway's patches most definitely won't work but if you can do without the things those enable (and it doesn't completely break the firmware when they are not working) then it could work for your purposes.

As you would have a hardware NAND dumping setup anyway recovering from a brick caused by Gateway's code like ichfly explained would only be an inconvenience.

But the question is, why? Why would you go through all tha trouble just to watch a video that you can watch right now without any of that hassle? The video's not that great that it's worth keeping and watching over and over.

Well, it'd probably be more than just the video, since from there, I can use any firmware for various flashcards as well.
 
  • Like
Reactions: JayRo

loco365

Well-Known Member
OP
Member
Joined
Sep 1, 2010
Messages
5,457
Trophies
0
XP
2,927
Well, I guess with all the hassle that is setting up this emuNAND, I'm just going to stick to keeping an emunand of 4.1. I just picked up the 3DS and I've so far updated it to 2.2U, I don't have any 4.X games besides Animal Crossing, which has 4.5 and won't work with my AK2i.
 

zhdarkstar

Well-Known Member
Member
Joined
Jan 30, 2008
Messages
573
Trophies
1
XP
566
Country
United States
Well, I guess with all the hassle that is setting up this emuNAND, I'm just going to stick to keeping an emunand of 4.1. I just picked up the 3DS and I've so far updated it to 2.2U, I don't have any 4.X games besides Animal Crossing, which has 4.5 and won't work with my AK2i.

I just checked http://3ds.essh.co/ and found a bunch of games that come with 4.1 on them. If you don't have any of those games, then you can go to your local used game store and use a little social engineering to get your 2.2 3DS updated if they have any of the games on the list. All you gotta do is ask them if you could test the cartridge out to make sure that it works properly. Insert cart, update to 4.1, hand cart back to clerk with excuse that you didn't want the game after all.
 

loco365

Well-Known Member
OP
Member
Joined
Sep 1, 2010
Messages
5,457
Trophies
0
XP
2,927
I just checked http://3ds.essh.co/ and found a bunch of games that come with 4.1 on them. If you don't have any of those games, then you can go to your local used game store and use a little social engineering to get your 2.2 3DS updated if they have any of the games on the list. All you gotta do is ask them if you could test the cartridge out to make sure that it works properly. Insert cart, update to 4.1, hand cart back to clerk with excuse that you didn't want the game after all.
I have friends that have 4.1 games, so I'll probably bug them tomorrow.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • BigOnYa @ BigOnYa:
    I went to auction at a mom/pops video game store few months ago that was closing, and bought 11 slims for $200, 1 was DOA but 10 work fine. so hella deal. Already rgh3'ed 8 of them. But most younger kids don't even want anymore, unless it plays stupid "fortnight", or newer shit.
  • K3Nv2 @ K3Nv2:
    Think I'm gonna use my giftcard balance on a nice pair of headphones but $100 is still limited
  • K3Nv2 @ K3Nv2:
    Soundcore q30s are nice but they leak so much sound it sounds like speakers
  • Psionic Roshambo @ Psionic Roshambo:
    Ken spend the 100 on a gun and skii mask, wait for a jogger at the park jewelry money and headphones!
    +1
  • K3Nv2 @ K3Nv2:
    If only Amazon sold guns
    +1
  • K3Nv2 @ K3Nv2:
    Fucking dick heads think it's a bad idea to get a gun 2 days later
    +1
  • BigOnYa @ BigOnYa:
    Wait, I thought you were the dickhe...nvm
    +1
  • K3Nv2 @ K3Nv2:
    I got balls on my chin and two dicks on my forehead sir
    +1
  • BigOnYa @ BigOnYa:
    Sorry, no offense there double dickhead chinballs.
    +1
  • K3Nv2 @ K3Nv2:
    Chicks still love it
    +1
  • BigOnYa @ BigOnYa:
    "Mommy, look, what is that?". "That's your soon to be daddy."
    +1
  • K3Nv2 @ K3Nv2:
    That you'll only see once
    +2
  • Veho @ Veho:
    Double dickhead chinballs is still better than double dickhead eyeballs.
    +1
  • Veho @ Veho:
    As in, the balls will grow in your eye sockets.
  • K3Nv2 @ K3Nv2:
    I paid 5 grand to get them moved to my chin
    +1
  • Veho @ Veho:
    This you?
  • K3Nv2 @ K3Nv2:
    My hair can't be that cool
    +1
  • Veho @ Veho:
    Ah, yes, portrait mode, surely the best way to film a row of people. If only there were some way to fit a wider shot, at the expense of height... if only...
    +1
  • K3Nv2 @ K3Nv2:
    4k portrait mode?
    +1
    K3Nv2 @ K3Nv2: https://youtu.be/Rx-KuevU4h4?si=1MoSvL-y5fFFHf58 Damn kinda sad for Iran +1