ROM Hack [Release] ExInjector - Inject original exheaders into repacked roms

  • Thread starter Thread starter piratesephiroth
  • Start date Start date
  • Views Views 123,899
  • Replies Replies 343
  • Likes Likes 29
Here's the bat code I used. The game's files were in a subfolder called 'extracted' (exefs files were in the folder extracted\exefs). Makerom.exe and ExInjector.exe were in a subfolder called 'tools'.
Code:
tools\makerom -f ncch -target t -desc app:3 -rsf POKEMONY.rsf -logo extracted\logo.bin -romfs extracted\xored_romfs.bin -exheader extracted\xored_exheader.bin -code extracted\exefs\code.bin -icon extracted\exefs\icon.bin -banner extracted\exefs\banner.bin -alignwr -o POKEMONY.CXI
tools\exinjector -rom POKEMONY.cxi -exheader extracted\xored_exheader.bin -sd -fwspoof
tools\makerom -f cia -target t -content POKEMONY.cxi:0:0 -o POKEMONY.cia

Now for the rsf, apart from the obvious ProductCode, UniqueID, etc, you must set:

For CardInfo:
MediaSize: 2GB
MediaType: Card2
CardDevice: None

For Option:
MediaFootPadding: true
Are you tested it on 4.5 CFW or Gateway? I used your settings and it still crashes for me when trying to manually save progress.
 
Are you tested it on 4.5 CFW or Gateway? I used your settings and it still crashes for me when trying to manually save progress.
I tested it using Gateway's 4.5 emunand. Booted it holding 'up' on the dpad, to remove fw spoofing.

I'll test with CFW and report the results.
 
I tested it using Gateway's 4.5 emunand. Booted it holding 'up' on the dpad, to remove fw spoofing.

I'll test with CFW and report the results.
Doesn't work on CFW though.

I also installed 1.2 update - game stucks on red waves, after repacking update cia with patched exheader's kernel version it loads fine and show version as 1.2.. But still crashes system when trying to save.
 
Doesn't work on CFW though.

I also installed 1.2 update - game stucks on red waves, after repacking update cia with patched exheader's kernel version it loads fine and show version as 1.2.. But still crashes system when trying to save.

lolwot, I try to run the game I installed with Gateway on the CFW and it tells me to download from the eshop again. Maybe I made the backup before installing the game.
 
I got my Euro version of Fire Emblem to run with liomajor's 1.04 tools. I used the original exheader, made it region free, and spoofed 4.x firmware. I'll try Bravely Default next. I don't think anyone's tried it on the CFW yet..

Edit: No go with BD. NCCH decryptor doesn't support 4GB games it seems.

Edit 2: I was using an outdated version of the decryptor. Now to install this HUGE 3.3GB cia file. This will probably take over an hour...

Edit 3: 97% installed..
 
So im always getting this message when using liomajors tools what am i doing wrong ?
QrTVoCw.png
[spoiler/]
 
So im always getting this message when using liomajors tools what am i doing wrong ?
QrTVoCw.png
[spoiler/]
You didn't decrypt something... or you may be using -target p....
The problem is the ncch aes key. It shouldn't be trying to load that.
 
Even with a fresh dump, my romfs is only 1,911,160,832 bytes.

We are talking about Hatsune Miku - Project Mirai 2 or 1???

Update 4:
Supports firmware spoofing, so more games can run on the CFW's 4.X NAND.
Any game that works with Gateway's firmware spoofing should work in the CFW as well.
Thanks, Riku, for the idea.

Your exinjector seems not to work properly.

I compared my created .cxi with the backup i created before running exinjector.

Both have the same md5 with or without -sd / -fwspoof

I still had your previous version without -fwspoof, compared, same md5.
 
We are talking about Hatsune Miku - Project Mirai 2 or 1???



Your exinjector seems not to work properly.

I compared my created .cxi with the backup i created before running exinjector.

Both have the same md5 with or without -sd / -fwspoof

I still had your previous version without -fwspoof, compared, same md5.
It will only patch unencrypted roms (-target t). If even zero key encryption is found, nothing will be patched.
 
but the .cxi is not encrypted o.O

Code:
..\makerom -f cxi -target t -desc ecapp:3 -rsf NSMB.rsf -romfs xored_romfs.bin -exheader xored_exh.bin -code exefs/code.bin -icon exefs/icon.bin -banner exefs/banner.bin -o MARIOTEST.CXI
..\exinjector -rom MARIOTEST.[B]CXI[/B] -exheader xored_exh.bin [B]-sd[/B]
..\makerom -f cia -target t -content MARIOTEST.CIA:0:0 -o MARIOTEST.CIA
 
ctrtool output unchanged "Attack of the Friday Monsters! A Tokyo Tale.cxi"

Code:
NCCH:
Header:                 NCCH
Signature:              AD3A80347FB3899BE964897C62E54671C24F07BE1FCE3EEE939ACE4907B70443
                        A75089256FB5934B588968739E9FA0621699DD53B55FCCE50ED3CA7FCDB7783A
                        9D87624FB105C6AEA3F7A102A8F242A61F01C1F90026E8D8B43A128C5FCBD5D2
                        97018D324AACB6017A1510D52781FF880CB5891EF9E5F99B59957CA03B7FDFFE
                        BC8A5FF98A6B9CA65644C0A8F9F168349456B33BBEBFDA36B7937B423D86CDE6
                        E1FBD3A6745BD4842C05862E56D21D6C109C2D4A91658A8AC8E4BA54BC83F3FF
                        591E9F2F6D83EA73838DE6C4CCE2897304B6D413150BC1186775F8B2B35DF073
                        67EC02B5270AC83EE65C99B8F5DD65995B25FDDD386F3A701A2E4A4B55233609
Content size:           0x0b17f000
Partition id:           00040000000e7600
Maker code:             4648
Version:                0002
Program id:             00040000000e7600
Logo hash:              2A98C49D919E254E15DC213CAB47A800ED63B248DCD43119E8FB82D9E62AE51C
Product code:           CTR-N-JKEE
Exheader size:          00000400
Exheader hash:          93BD28BA7B8C3E2DFC14A006A9693B4F0206E0607DF95EACEF4F70A52443DA3A
Flags:                  0500030100000000
 > Mediaunit size:      0x200
 > Crypto key:          None
 > Form type:           Executable content
 > Content type:        Application
 > Content platform:    CTR
Plain region offset:    0x00000000
Plain region size:      0x00000000
Logo offset:            0x00000a00
Logo size:              0x00002000
ExeFS offset:           0x00002a00
ExeFS size:             0x0011d800
ExeFS hash region size: 0x00000200
RomFS offset:           0x00121000
RomFS size:             0x0b05e000
RomFS hash region size: 0x00000200
ExeFS Hash:             2A6849808F53C3F93EC83731934FF7DD9208B053C05CE29E31F6759102CD56BA
RomFS Hash:             1702EA17599E455BB9A222209018ED44D9B237DBDA9F3BF0F387E77196219E5A

Extended header:
Signature:              BE0477AC542FF3BDF1108D02B150CB00BA21C4CE26ED0D6AE34D4F9F8182BC5A
                        AA7BABCC7351F7940270CC547A5BFFC97368E136739E4309E7C9D99446948EE0
                        E1C1139BC05AAADAD74B1FF0190DA42B6095AD0EE11886938270263440DBD7DC
                        41C9F6A1A494A750F4A0C38C6A8288485324F65BA9DA3370107B2FA32A3CACC8
                        164CE6B7161DE1A4976261D2702240E16C0E8E7AB09447B171BF17359FBFC14A
                        5BEEF67AAD737D619BCA5C4428FE68E2005DB3043640D841C4EE49FEDBB7D925
                        45B311DFCAA44872BA5B01FE337A8CDB248DED4D1B202C36C77132C6749B8673
                        440349BAA49E6104E6C621C7645230172723512CC7C11312DF5C4AB53AB19A65

NCCH Hdr RSA Modulus:   CAC588C7F12A092B7649C0A835751082C2B5E5B2E9C81888F39889BF9DE6E40B
                        715DDD3F138271F2ED318699D947FEC57A7593E1F86DC63D9BE11599E1C2E05C
                        384B35A24D3EE2CEFBB308A3DD0C2631849227C88A8EC883A86CA7A339719EF1
                        349101DF114A9CF98BF92F46440A7238F38B6D233389BF6634A786E6ADF2DEF9
                        AB16A140EED8F76CDC0092CB3149FC266424088FC660FF1EE3F0DDFB6D0D0F49
                        7CAD03EC9F6358FA46DFA2640ECC8557E72C617F59B8627D590EF684969942B0
                        398380B5522E073F92E39EF547EBA7D7D415F1228232BE2AD08C01CC30A91196
                        F6E92BEA0EF82D0DB191D51A9451B98539B0AF9F549E99E146E56FE25F4B4E23
Name:                   AFM:TT00
Flag:                   03 [compressed][sd app]
Remaster version:       0000
Code text address:      0x00100000
Code text size:         0x0016520C
Code text max pages:    0x00000166 (0x00166000)
Code ro address:        0x00266000
Code ro size:           0x00015058
Code ro max pages:      0x00000016 (0x00016000)
Code data address:      0x0027C000
Code data size:         0x0001B234
Code data max pages:    0x0000001C (0x0001C000)
Code bss size:          0x0001CAD8
Code stack size:        0x00004000
Dependency:             0004013000002402
Dependency:             0004013000001502
Dependency:             0004013000003402
Dependency:             0004013000001602
Dependency:             0004013000002602
Dependency:             0004013000001702
Dependency:             0004013000001802
Dependency:             0004013000002702
Dependency:             0004013000002802
Dependency:             0004013000001a02
Dependency:             0004013000003202
Dependency:             0004013000001b02
Dependency:             0004013000001c02
Dependency:             0004013000001d02
Dependency:             0004013000002902
Dependency:             0004013000001e02
Dependency:             0004013000003302
Dependency:             0004013000001f02
Dependency:             0004013000002002
Dependency:             0004013000002b02
Dependency:             0004013000003502
Dependency:             0004013000002c02
Dependency:             0004013000002d02
Dependency:             0004013000002102
Dependency:             0004013000003102
Dependency:             0004013000002202
Dependency:             0004013000003702
Dependency:             0004013000002e02
Dependency:             0004013000002302
Dependency:             0004013000002f02
Savedata size:          1M
Jump id:                00040000000e7600
Program id:             00040000000e7600 
Core version:           0x2
System mode:            0x0
Ideal processor:        0 
Affinity mask:          1 
Main thread priority:   48 
Ext savedata id:        0x00000e76
System savedata id 1:   0x00000000 
System savedata id 2:   0x00000000 
OtherUserSaveDataId1:   0x00000
OtherUserSaveDataId2:   0x00000
OtherUserSaveDataId3:   0x00000
Accessible Savedata Ids:
Other Variation Saves:  Inaccessible
Access info:            00000000000000
Other attributes:       00
Mapping static address: 0x1F000000 (RO)
Mapping static address: 0x1F600000 (RO)
Mapping static address: 0x1FF50000 (RW)
Mapping static address: 0x1FF58000 (RW)
Mapping static address: 0x1FF70000 (RW)
Mapping static address: 0x1FF78000 (RW)
Kernel flags:           
 > Allow debug:         YES
 > Force debug:         NO
 > Allow non-alphanum:  NO
 > Shared page writing: NO
 > Privilege priority:  NO
 > Allow main() args:   NO
 > Shared device mem:   NO
 > Runnable on sleep:   NO
 > Special memory:      NO
 > Memory type:         APPLICATION
Handle table size:      0x200
Kernel release version: 2.32
Allowed systemcalls:    0x01, 0x02, 0x03, 0x06, 0x08, 0x09, 0x0A, 0x0B
                        0x0C, 0x0F, 0x11, 0x13, 0x14, 0x15, 0x16, 0x17
                        0x18, 0x19, 0x1A, 0x1B, 0x1C, 0x1D, 0x1E, 0x1F
                        0x20, 0x21, 0x22, 0x23, 0x24, 0x25, 0x27, 0x28
                        0x29, 0x2A, 0x2B, 0x2C, 0x2D, 0x2E, 0x2F, 0x30
                        0x31, 0x32, 0x35, 0x36, 0x37, 0x38, 0x39, 0x3A
                        0x3B, 0x3C, 0x3D
Allowed interrupts:     none
ARM9 Desc. version:     0x2
Mount NAND fs:          NO
Mount NAND RO write fs: NO
Mount NAND TWL fs:      NO
Mount NAND W fs:        NO
Mount CARD SPI fs:      NO
Use SDIF3:              NO
Create seed:            NO
Use CARD SPI:           NO
SD Application:         YES
Use Direct SDMC:        NO
Service access:         APT:U
Service access:         $hioFIO
Service access:         $hostio0
Service access:         $hostio1
Service access:         ac:u
Service access:         boss:U
Service access:         cam:u
Service access:         cecd:u
Service access:         cfg:u
Service access:         dlp:FKCL
Service access:         dlp:SRVR
Service access:         dsp::DSP
Service access:         frd:u
Service access:         fs:USER
Service access:         gsp::Gpu
Service access:         hid:USER
Service access:         http:C
Service access:         mic:u
Service access:         ndm:u
Service access:         news:u
Service access:         nwm::UDS
Service access:         ptm:u
Service access:         pxi:dev
Service access:         soc:U
Service access:         ssl:C
Service access:         y2r:u
Service access:         ldr:ro
Service access:         ir:USER
Service access:         nim:aoc
Service access:         am:app
Reslimit category:      00

ExeFS:
Section name:           .code
Section offset:         0x00000200
Section size:           0x000ef6fc
Section hash:           8E1080E38A7B91FE18C2EB037417CB5B978DF597619156519FE9E4092B017BD3
Section name:           banner
Section offset:         0x000efa00
Section size:           0x000284c8
Section hash:           8FA5A9673F5219337CC27E982AC5AD5A5D9798ACFA2D87C6D49FEDEC1F03AEAF
Section name:           icon
Section offset:         0x00118000
Section size:           0x000036c0
Section hash:           8E0659D8EF0A18C8EA7C3CBBE0AF916876C63A2FCD078525138C1227F7C08FDF
Section name:           logo
Section offset:         0x0011b800
Section size:           0x00002000
Section hash:           2A98C49D919E254E15DC213CAB47A800ED63B248DCD43119E8FB82D9E62AE51C
 

Site & Scene News

Popular threads in this forum