Homebrew So it seems NinjHax does leave traces

  • Thread starter Thread starter drfsupercenter
  • Start date Start date
  • Views Views 11,149
  • Replies Replies 42
  • Likes Likes 1
I tweeted at smea, asking him about this, his response was, how peculiar. Maybe he has no clue, maybe it's something he doesn't want anyone to figure out, something is odd about this though.


Of course he has a clue. :D

Source is available... it loads things from a server, looking at it I can't see where it happens, I might be blind but it doesn't seem to be the complete source, but the names of some of the functions are pretty revealing.

https://github.com/smealum/3ds_hb_menu/tree/master/source

in netloader.c (hmm) and hb.c for instance.
 
Of course he has a clue. :D

Source is available... it loads things from a server, looking at it I can't see where it happens, I might be blind but it doesn't seem to be the complete source, but the names of some of the functions are pretty revealing.

https://github.com/smealum/3ds_hb_menu/tree/master/source

in netloader.c (hmm) and hb.c for instance.

It's not on hbmenu, but during ninjhax initialization itself.
 
Gateway and other flash carts certainly leave traces too, they're just harder for us to see. If you have to send a console back to Nintendo, though, they'll find that evidence quick enough.

Can you elaborate on what sort of traces Gateway leaves?

I know they can tell if you hacked Wii mode on Wii U really easily. Lots of people have had repairs refused (can't even pay to have it repaired) even if they formatted the thing first.

Of course, this is fair, you are violating the warranty when you hack a system. You need to be aware of that going in.
 
you could always set your PC up as a router and use wireshark or similar to sniff the http traffic and see what exactly it's doing if you're curious.
 
Not sure.
If one day your 3DS is... bricked, just fuse it with electricity :)
Nothing will be done by Nintendo.

Jut reminds me something.
Old days of Wii.
A coworker asked me : please hack my Wii, a friend off mine tried he didn't succeed. I agreed. The previous hack was shitty so I bricked the Wii.
The Wii was less than one year old. Got it repaired (exchange) by Nintendo without any problem.

Looking at dead console to see if there was a try to hack it is a loss of time...
 
Can you elaborate on what sort of traces Gateway leaves?

I know they can tell if you hacked Wii mode on Wii U really easily. Lots of people have had repairs refused (can't even pay to have it repaired) even if they formatted the thing first.

Of course, this is fair, you are violating the warranty when you hack a system. You need to be aware of that going in.
I can't give you specifics, because I don't know the specifics. A number of people have attempted to return 3DS systems which Gateway had been used on to Nintendo, however, and even if they removed everything/formatted the NAND back to 4.0-4.5, Nintendo always found a tracer for Gateway somewhere in the software/firmware. Perhaps the one thing that hasn't been tried is formatting the NAND and inserting an SD card which had never had emuNAND installed on it before returning to Nintendo. They might just be using a simple deleted file recovery program.
 
Of course he has a clue. :D

Source is available... it loads things from a server, looking at it I can't see where it happens, I might be blind but it doesn't seem to be the complete source, but the names of some of the functions are pretty revealing.

https://github.com/smealum/3ds_hb_menu/tree/master/source

in netloader.c (hmm) and hb.c for instance.
netloader is just the code for loading .3dsx files over raw TCP sockets. Very handy when devving homebrew and one wants to do a quick test.
 
I can't give you specifics, because I don't know the specifics. A number of people have attempted to return 3DS systems which Gateway had been used on to Nintendo, however, and even if they removed everything/formatted the NAND back to 4.0-4.5, Nintendo always found a tracer for Gateway somewhere in the software/firmware. Perhaps the one thing that hasn't been tried is formatting the NAND and inserting an SD card which had never had emuNAND installed on it before returning to Nintendo. They might just be using a simple deleted file recovery program.
You can't give specifics because there are no specifics. STFU if you can't prove what you're implying.
 
You can't give specifics because there are no specifics. STFU if you can't prove what you're implying.
Wow, hostile. Look around the web, you'll find plenty of people who can attest that they tried to return a 3DS console for repairs to Nintendo, only to have them find some trace of Gateway and tell the person they would not fix it. STFU if you can't find any evidence to the contrary, I suppose.

I'm not "insulting" Gateway, either, I'm a fully satisfied customer of theirs since the time when Gateway only supported a single ROM. But creating a flash cart with this much functionality and this many features that leaves no trace of its presence whatsoever on the system it's installed to? Well, let's just say they're a group of hackers, not a room full of Stephen Hawkings.
 
Guys if someone is interested in, i succefully downloaded the .bin file. It's the file which gets downloaded when you scan the QRcode with cubic ninja. It's named POST5_WEST_4096_4096.bin and it's sized 28kb.

EDIT: Also, i can tell you that it doesn't use internet while loading homebrew launcher, or at least it doesn't connect to any server. Internet access is required to download the file above only.
 
  • Like
Reactions: VinsCool
I just got my warranty repaired 3DS back from Nintendo and they never flagged me for using a DStwo in my 3DS.

Which BTW the DStwo cart is what caused damage to my 3DS cart slot. The bottom lip of the cart's shell separated enough that it got caught between the contacts and caused them to bend when I attempted to remove it from my 3DS - which ironically I was removing the DStwo so I could try Cubic Ninja / Ninjhax out.
 
Gateway and other flash carts certainly leave traces too, they're just harder for us to see. If you have to send a console back to Nintendo, though, they'll find that evidence quick enough.

I can understand it leaving traces in your native NAND (4.x system) but what about inside emuNAND?

Scenario: I do a system transfer from my legit system (the one which is under warranty and I've actually had the touchscreen repaired before with no issue) to my Gateway system and move the NAND over to emuNAND. I boot into Gateway mode and play a ROM of a game I have already played as a legit cartridge. Because it's the same title ID, it doesn't create any weird duplicates in the play log (at least, from what I can tell)

Then I transfer it back after I'm done doing whatever I need to do in the game

From what I can tell, that's "safe", but does anyone have any evidence proving otherwise?

I'd also be curious if cards like the Sky3DS leave any traces behind either. I'm inclined to believe they wouldn't, since it's literally emulating a legit came cartridge, as long as the ROM hasn't been modified, it should be impossible to tell apart from a legit game cartridge.

Guys if someone is interested in, i succefully downloaded the .bin file. It's the file which gets downloaded when you scan the QRcode with cubic ninja. It's named POST5_WEST_4096_4096.bin and it's sized 28kb.

Interesting. How much data did we determine is in one of those QR codes again, wasn't it like 4KB? So I can understand why it has to download more of the stuff from the server, since otherwise you'd have like 10 QR code sets to scan.

I'm inclined to think this is a multi-stage exploit, think of the Wii U browser exploits that were discovered (and subsequently patched before anyone did anything useful with them.) Cubic Ninja is just the "loading platform" if you will, because it provides the QR scanning engine, you then call the web browser somehow and exploit that. Seems weird, but from what I've read, the Gateway exploits have this multi-stage process too, where it uses the MSET exploit to load something, which loads something else, etc.

Seems nothing is simple anymore :P

Unrelated, AlbertoSONIC, have you compiled a .3dsx version of your decimal to binary converter yet? I'm really interested in using that, since it's actually a useful piece of homebrew.
 
I can understand it leaving traces in your native NAND (4.x system) but what about inside emuNAND?

Scenario: I do a system transfer from my legit system (the one which is under warranty and I've actually had the touchscreen repaired before with no issue) to my Gateway system and move the NAND over to emuNAND. I boot into Gateway mode and play a ROM of a game I have already played as a legit cartridge. Because it's the same title ID, it doesn't create any weird duplicates in the play log (at least, from what I can tell)

Then I transfer it back after I'm done doing whatever I need to do in the game

From what I can tell, that's "safe", but does anyone have any evidence proving otherwise?

I'd also be curious if cards like the Sky3DS leave any traces behind either. I'm inclined to believe they wouldn't, since it's literally emulating a legit came cartridge, as long as the ROM hasn't been modified, it should be impossible to tell apart from a legit game cartridge.



Interesting. How much data did we determine is in one of those QR codes again, wasn't it like 4KB? So I can understand why it has to download more of the stuff from the server, since otherwise you'd have like 10 QR code sets to scan.

I'm inclined to think this is a multi-stage exploit, think of the Wii U browser exploits that were discovered (and subsequently patched before anyone did anything useful with them.) Cubic Ninja is just the "loading platform" if you will, because it provides the QR scanning engine, you then call the web browser somehow and exploit that. Seems weird, but from what I've read, the Gateway exploits have this multi-stage process too, where it uses the MSET exploit to load something, which loads something else, etc.

Seems nothing is simple anymore :P

Unrelated, AlbertoSONIC, have you compiled a .3dsx version of your decimal to binary converter yet? I'm really interested in using that, since it's actually a useful piece of homebrew.


I have to update the makefile to support the 3dsx output... I'll release it in an hour (i hope)

EDIT: Updated! Check the related thread!
 
  • Like
Reactions: drfsupercenter
EDIT: Also, i can tell you that it doesn't use internet while loading homebrew launcher, or at least it doesn't connect to any server. Internet access is required to download the file above only.
I never stated it uses the Internet on each launch of ninjhax, just that the browser is used, if you check the daily logs you can see from the date you installed ninjhax to whenever the last time you use ninjhax, the browser is used for 1-6 seconds. Just seems like something is in the browser to make the launch. Or maybe it tries to download the .bin, but picks up that it's all ready installed. I know it doesn't use Internet to works, cause I have my wifi turned off till Majora's Mask comes out. Dying only game in the futur I'm interested in.
 

Site & Scene News

Popular threads in this forum