Hacking [WIP] KARL3DS - Kernel access on N3DS via Ninjhax + Loadcode

  • Thread starter Thread starter Rokkubro
  • Start date Start date
  • Views Views 936,826
  • Replies Replies 4,457
  • Likes Likes 43
Status
Not open for further replies.
could you patch out signature checks, install mset 4.5 with version set to 9001 then update sysnand?

And how do you patch definitively sig checks? You can't.
There is a way to downgrade MSET (delete newer one and install old one), but it won't survive an update (if you spoof version, you break sig)
Even if this is the case, MSET exploit is just an entrypoint. You need system flaws after that
 
Question: how's the stability p.lanned to be on KARL? My Gateway is constantly freezing/kicking back errors and booting me back to sysnand when I start up legit games. I'd love it if KARL was at least a little more stable...
 
Question: how's the stability p.lanned to be on KARL? My Gateway is constantly freezing/kicking back errors and booting me back to sysnand when I start up legit games. I'd love it if KARL was at least a little more stable...

Never had problems. Do you use a 2DS?
 
*shrug* If it's a Gateway-specific issue, I'll just check myself out of this thread and go to a GW one to see if anyone knows. I just thought this was normal with Gateways. Sorry about that, Karl devs!
 
And how do you patch definitively sig checks? You can't.
There is a way to downgrade MSET (delete newer one and install old one), but it won't survive an update (if you spoof version, you break sig)
Even if this is the case, MSET exploit is just an entrypoint. You need system flaws after that

gateway do it in emunand, is it not possible in sysnand?

also, if it worked for one title it'd work for them all.
 
gateway do it in emunand, is it not possible in sysnand?

also, if it worked for one title it'd work for them all.

It's not possible in sysNAND because the signatures for the FIRM in NAND are checked on boot. Failed signatures = failed boot. So an exploit is required in order to boot our own FIRM after boot while not checking the signatures.
 
ah.

I always just assumed gateway didn't want to give us something permanent so they could sell cards.
 
It's not possible in sysNAND because the signatures for the FIRM in NAND are checked on boot. Failed signatures = failed boot. So an exploit is required in order to boot our own FIRM after boot while not checking the signatures.

What even checks the very first signatures on boot? is it the bootrom? and if so, is that something we could hack, or is it read only?
 
Yes, it's bootrom
In bootrom, we have ROM, which means : Read Only Memory

If the bootrom was dumped, couldnt we in theory do a hard mod to redirect the bootrom from an external source? (kind of like how we have hard mods to read from NAND)
In theory, couldn't we wire the 3DS to read from an external bootrom? (one that we modify)
 
  • Like
Reactions: Margen67
If the bootrom was dumped, couldnt we in theory do a hard mod to redirect the bootrom from an external source? (kind of like how we have hard mods to read from NAND)
In theory, couldn't we wire the 3DS to read from an external bootrom? (one that we modify)

bootrom is within CPU, so...
 
If the bootrom was dumped, couldnt we in theory do a hard mod to redirect the bootrom from an external source? (kind of like how we have hard mods to read from NAND)
In theory, couldn't we wire the 3DS to read from an external bootrom? (one that we modify)
Would require extensive reverse engineering. Also assuming it's not part of the SoC, in which case all bets are off unless you have a scanning electron microscope.
 
Would require extensive reverse engineering. Also assuming it's not part of the SoC, in which case all bets are off unless you have a scanning electron microscope.
I can just imagine...

Scan the entire SOC, decap, analyze, and completely reverse the SOC from the reconstructed layers. Partial-decap of a second SOC chip, just enough to access the top layers. Laser the bootrom to "reprogram" it through hard cuts. Cap the modified SOC, and reinstall it to the 3DS mainboard...

Yeah...........

Not happening, unless you're a business owner of, at the very least, Datel.
 
  • Like
Reactions: Subtle Demise
Would require extensive reverse engineering. Also assuming it's not part of the SoC, in which case all bets are off unless you have a scanning electron microscope.

The bootroms are part of the SoC. Even GW doesn't want to put the money toward decapping and getting scans of that 45nm hell. Pretty much all you can gain from a dumped bootrom is the ability to look at early crypto code and find flaws, and maaaaaybe get around hard reboots by running a modified bootrom from ITCM or something (do not quote me on that.) Scans would let you deduce the hardware keygen mechanism too, but you'd need to pay someone a lot of money to find and analyze that bit of silicon.
Bootrom stuff is generally a fruitless effort, but who knows? Maybe someone will find something useful in the bootroms' first halves.
 
The bootroms are part of the SoC. Even GW doesn't want to put the money toward decapping and getting scans of that 45nm hell. Pretty much all you can gain from a dumped bootrom is the ability to look at early crypto code and find flaws, and maaaaaybe get around hard reboots by running a modified bootrom from ITCM or something (do not quote me on that.) Scans would let you deduce the hardware keygen mechanism too, but you'd need to pay someone a lot of money to find and analyze that bit of silicon.
Bootrom stuff is generally a fruitless effort, but who knows? Maybe someone will find something useful in the bootroms' first halves.

Well you'd also have the keyX's for everything so you'd be able to do other stuff from that. I'd sooner look for a hardware exploit which could get me a full bootrom dump than a decapping though.
 
Isn't flashing back bootrom possible? (not implying ROM here, but isn't similar to ROM we have on PC as BIOS, read-only but flashable?). If we check the SoC datasheet maybe there are some lines that allows serial flashing or something?...
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum