Hacking Virtual console and eshop Roms

UraKn0x

Official senpai
Member
Joined
Mar 20, 2014
Messages
370
Trophies
0
XP
735
Country
France
Has anyone tried to run one of BBB's eshop dumps? They're packed using retail encryption. Could work on Sky3DS...

No, they are not. These dumps are decrypted (signed with 00 key). If they were encrypted using retail encryption it would be possible to sign homebrew code and run it on Sky3DS.
 

AHP_person

Well-Known Member
Member
Joined
Nov 2, 2014
Messages
364
Trophies
0
XP
518
Country
United States
I'm pretty sure the bbb dumps use retail encryption, since eshop copies are encrypted twice (once with retail encryption and once with movable.sed), all bbb did was remove the movable.sed encryption and throw the cxis into a rom. It's not hard to use retail encryption (since you can generate the keys with the VOiD Decryptor), the problem is the rsa signatures aren't properly signed. Retail copies all have proper rsa signatures.
 

UraKn0x

Official senpai
Member
Joined
Mar 20, 2014
Messages
370
Trophies
0
XP
735
Country
France
The used signature process uses asymmetric keys, so even if you can decrypt it, you cannot re-encrypt it back if you modified the content. If that was that simple it would be pretty easy to decrypt 3DS ROMs from your PC... Unfortunately it's not.
 

AHP_person

Well-Known Member
Member
Joined
Nov 2, 2014
Messages
364
Trophies
0
XP
518
Country
United States
The used signature process uses asymmetric keys, so even if you can decrypt it, you cannot re-encrypt it back if you modified the content. If that was that simple it would be pretty easy to decrypt 3DS ROMs from your PC... Unfortunately it's not.

Rom encryption uses symmetric 128bit AES CTR keys, thus the XORpads. As I said; the problem is the rsa signatures aren't properly signed.
 

UraKn0x

Official senpai
Member
Joined
Mar 20, 2014
Messages
370
Trophies
0
XP
735
Country
France
Rom encryption uses symmetric 128bit AES CTR keys, thus the XORpads. As I said; the problem is the rsa signatures aren't properly signed.

Ah, you may be right. But still, Sky3DS cannot play eshop dumps. I guess they do not use the same file format as retail games...
 

piratesephiroth

I wish I could read
Member
Joined
Sep 5, 2013
Messages
3,453
Trophies
2
Age
103
XP
3,233
Country
Brazil
No, they are not. These dumps are decrypted (signed with 00 key). If they were encrypted using retail encryption it would be possible to sign homebrew code and run it on Sky3DS.
RcvRZRd.png

00 key, eh? You might be talking about some of their VC pokemon games.

I'm talking about their latest releases, like this one, 3D Sonic
They all use retail encryption on the CCI.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    SylverReZ @ SylverReZ: @salazarcosplay, I'm good. Thanks.