Hacking [WIP] KARL3DS - Kernel access on N3DS via Ninjhax + Loadcode

  • Thread starter Thread starter Rokkubro
  • Start date Start date
  • Views Views 936,813
  • Replies Replies 4,457
  • Likes Likes 43
Status
Not open for further replies.
Isn't flashing back bootrom possible? (not implying ROM here, but isn't similar to ROM we have on PC as BIOS, read-only but flashable?). If we check the SoC datasheet maybe there are some lines that allows serial flashing or something?...
Sure, just give me a few minutes to check around Nintendo's website for a downloadable PDF :P

I really doubt the 3ds's SOC bootrom is writable, hardware or software, anyway.
 
  • Like
Reactions: WulfyStylez
Don't wanna argue as I'm just asking without knowing much about the hardware itself, I'm aware that its Nintendo own SoC, but a similar ones might be existing with similar pinouts... They might have already blocked reflashing by setting a hard bit, but this is Nintendo we talking about who might have missed that...
 
Don't wanna argue as I'm just asking without knowing much about the hardware itself, I'm aware that its Nintendo own SoC, but a similar ones might be existing with similar pinouts... They might have already blocked reflashing by setting a hard bit, but this is Nintendo we talking about who might have missed that...

Bootroms are always mask ROMs, or write-protected flash if they're quite large. The 3DS bootrom is more than likely a mask rom though. While it's large (128kb), it's not *that* large. You would never hook up anything but read lines to a flash bootrom anyways.
As for SoC similarities - you won't find anything. The 3DS silicon is unique as hell, given it's got three (we think) CPU cores on it, several hardware crypto engines, and probably a lot of interface logic as well. It's got a small footprint, too, so its pinout will be super unique given all of the previous things.
 
Bootroms are always mask ROMs, or write-protected flash if they're quite large. The 3DS bootrom is more than likely a mask rom though. While it's large (128kb), it's not *that* large. You would never hook up anything but read lines to a flash bootrom anyways.
As for SoC similarities - you won't find anything. The 3DS silicon is unique as hell, given it's got three (we think) CPU cores on it, several hardware crypto engines, and probably a lot of interface logic as well. It's got a small footprint, too, so its pinout will be super unique given all of the previous things.
All of this makes me feel that the price of a 3DS is justified.
 
However, if someone decap a New 3DS CPU, it would be WAY more useful for us that he dump the OTP registers.
 
  • Like
Reactions: Margen67
Quote from the end "At this point, we're really just getting started."
And they were searching for O3DS bootrom BTW
 
Well you'd also have the keyX's for everything so you'd be able to do other stuff from that. I'd sooner look for a hardware exploit which could get me a full bootrom dump than a decapping though.

At least I can assure you that :
-remapping a region protected by REG_SYSPROT9 give only zeros
-REG_SYSPROT9 is brute-force resistant and won't allow any changes, even previously allowed ones
 
You said that we might be able to access eshop on Karl without being on latest firmware. Are we going to be able to perform a system transfer from an (old/new)3DS in the latest firmware to a New3DS running Karl (sysnand <9.2) ?
 
You said that we might be able to access eshop on Karl without being on latest firmware. Are we going to be able to perform a system transfer from an (old/new)3DS in the latest firmware to a New3DS running Karl (sysnand <9.2) ?
Its been mentioned previously that they hope to implement something that will allow system transfers without the update requirement.
 
*sigh*......folks no piracy discussion means NO piracy discussion including the impacts of security on piracy and calling sky users assholes. This thread is for the developers to post updates and for people to post suggestions and beg for more updates :P
 
rrgh, I'm not rushing the KARL3DS team, but man the SSB4 DLC's coming so soon and I've been holding out on updating to use KARL.
 
↑ Same, forums have been quiet lately. Guess that's a good sign, we gonna see some awesome releases soon.
 
  • Like
Reactions: Margen67
So hows the downgraded MSET going? Is it booting every single time? Also, do you need to restore your NAND to update your Sysnand with a downgraded MSET?
 
So hows the downgraded MSET going? Is it booting every single time? Also, do you need to restore your NAND to update your Sysnand with a downgraded MSET?

Yup, it's been at pretty much 100% since the day after I posted the video of it working. You don't need to restore NAND to downgrade mset.
 
  • Like
Reactions: Margen67
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum