Hacking Regarding 3DS Save Decryption progress...

shadowofchaos

Well-Known Member
OP
Newcomer
Joined
Jun 23, 2014
Messages
67
Trophies
0
XP
125
Country
United States
I think everyone here that has an interest in save hacking has at least heard of the Cyber Save Editor.

AoJcOQl.jpg


And we all know that's region locked.

Hello, GBATemp, I'm shadowofchaos. If you've looked up FE Awakening on Youtube, you've probably seen my weeaboo stupidity and videos.

I've always had an interest in save hacking the game.
As I have the Japanese version of the game, I decided to get the Cyber Save Editor in hopes of it being supported, due to the "Advanced Mode" that lets you use their decrypted save server side and input your own custom codes. This is unlike Datel Powersaves which ONLY let you use codes that they have made.

Supported games here: http://www.cybergadget.co.jp/code/4544859055553/geme/

With that said, their game support is pretty much crap mostly consisting of really niche games no one in the English speaking 3DS communities have ever heard of.
It is now 2014 and still nothing for Fire Emblem.

I have lurked the forums and have seen really small breakthroughs in saves from time to time...

Such as this thread: http://gbatemp.net/threads/decrypt-re-encrypt-saves-for-most-games-sort-of.364522/

For which gateway users can mess around with decrypted saves when forcing the ROM to use the old save method. Though I'm not really sure what you can do with that, and there's the issue with all my 3DSs being updated.

...but I saw this post:
Oh, I see how this works. It's essentially a rom hack that modifies the header and tells the 3DS to use an older save method, so when it saves, it saves in a way we can decrypt. In theory, couldn't one use this method, with both a decrypted save and an encrypted original version, XOR them together (Or even just a small portion of the file) and get the decryption keys for the newer games so someone can decrypt their game's save without having to do this?

Not sure, as I'm not that savvy. However, I think the only way that would work is if both the encrypted original and decrypted new save had the exact same game progress.

Since I happened to have a Bravely Default: For the Sequel cartridge I tried using advanced mode.
2u7Rz7m.png


The decrypted save had more than one "file" or section:
IGhpCCi.png

kNw6DuR.png


Unfortunately, you cannot export the files or copy to your clipboard. All you can do is edit on the program.

But I went and opened up Cheat Engine and copied the data from there via the memory viewer. And yes I did check for the lengths and see if the data matched up.

Since I'm not actually THAT tech savvy at all, I guess I'm just providing a save that is encrypted (backed up with the Cyber Save Editor and R4i Save Dongle) and decrypted to see if this will be useful to anyone who actually knows what they're doing.

Thank you very much for your time, GBAtemp.

I attached the zip file with the saves to this post.

Here are links to it just in case it didn't upload properly:
Dropbox
Mediafire

Though, the one that links to my dropbox might die eventually due to moving around files when organizing that folder.
 

Attachments

  • Bravely Default For the Sequel Encrypted and Decrypted Saves.zip
    1.3 MB · Views: 169

shadowofchaos

Well-Known Member
OP
Newcomer
Joined
Jun 23, 2014
Messages
67
Trophies
0
XP
125
Country
United States
Blimey is this the oldest news this year!:lol:

Heheh. Well about the Cyber Save Editor, yes.

But I've never seen anyone actually contribute an encrypted and decrypted card1 save using the new save method in this forum.

Either that or I haven't browsed the forums enough.
 

Relys

^(Software | Hardware) Exploit? Development.$
Member
Joined
Jan 5, 2007
Messages
878
Trophies
1
XP
1,239
Country
United States

Quicksilver88

Well-Known Member
Member
Joined
Jan 26, 2013
Messages
618
Trophies
1
Age
54
XP
753
Country
United States
Shadow.....

I appreciate your efforts, but it seems like no one is willing or able to do anything for the community on game saves. In the last Gateway update news they said they were working on something with game saves that is supposed to be awesome. All I have been wishing for is the ability to move retail saves to and from GW.

I bought a Datel with the hopes that someone in the community would write some apps for it so we could use it like a r4 dongle and create a raw dump. The Datel creates a raw type file but somehow must tag the image because the file size is like 1kb bigger than it should be. Then we have the issue of some games only using 128Kb eeprom when GW always creates a 512kb file. I compared save files thinking on a game using 128kb save that GW must just have all null data (in their 512kb file) after the first 128kb, but from what I could tell that was not the case.

We now have 3 sets of un-decrypted save keys though with the 2.x key, the 6.x key, and now the recent 7.x key. Supposedly certain 'people' know how to decrypt 2.x keyed games but won't share because of their outstanding moral fiber (sarcasm). I have said this before and taken some heat for it but the 3DS scene is somewhat weak. Without GW very little of consequence would be getting done.
 

ichichfly

Well-Known Member
Member
Joined
Sep 23, 2009
Messages
619
Trophies
1
XP
1,075
Country
Gambia, The
Yes it looks like there are some cheater that know how to decrypt 6.x saves and 7.x NCCH. I don't. I still can cheat (but only on a 3DS with a firm file that is below 5.0) (I can cheat online but I only cheat offline). Well the main reason why they don't share it is because of the risk of getting banned when everyone can cheat and it is harder to spoof because they may run out of IDs (the one that are included in the 3DS dumps) and they are hated by most of the community. Datel makes money so they won't tell you as well. The home-brew won't tell you because it can lead to piracy or cheating.

ADD : you need access to a hacked 3DS AES engine the decrypt the 2.x saves and for the 6.x saves you need access to a hacked 3DS AES engine with a firm 6.x or later
 

shadowofchaos

Well-Known Member
OP
Newcomer
Joined
Jun 23, 2014
Messages
67
Trophies
0
XP
125
Country
United States
Yes it looks like there are some cheater that know how to decrypt 6.x saves and 7.x NCCH. I don't. I still can cheat (but only on a 3DS with a firm file that is below 5.0) (I can cheat online but I only cheat offline). Well the main reason why they don't share it is because of the risk of getting banned when everyone can cheat and it is harder to spoof because they may run out of IDs (the one that are included in the 3DS dumps) and they are hated by most of the community.

The only thing I really want to do is mess around in a single player game.
With literally no online features besides downloading DLC.

ADD : you need access to a hacked 3DS AES engine the decrypt the 2.x saves and for the 6.x saves you need access to a hacked 3DS AES engine with a firm 6.x or later

I doubt I, or anyone I know will have access to that.

I mean there are tutorials EVERYWHERE when it comes to Gateway.
But not with things like that.

You are describing a known-plaintext attack (https://en.wikipedia.org/wiki/Known-plaintext_attack) which doesn't work on modern ciphers. Do you know what cipher the save file is encrypted with? In other words, it depends on the cipher Nintendo choose for it's encryption algorithm and it's implementation.

Here's some further reading material on the subject:
https://security.stackexchange.com/...on-key-given-the-plaintext-and-its-ciphertext


And I am the last person that can contribute anything to this effort other than what I already have. Which is pretty much nothing.
I didn't pay attention that much in Internet Security class.

Well, I guess my contribution is crap, then.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: Ohkay