Hacking GATEWAY 3.2 ULTRA PUBLIC BETA

  • Thread starter Thread starter TheShadowRunner
  • Start date Start date
  • Views Views 213,810
  • Replies Replies 1,328
  • Likes Likes 24
Just a note for developers mainly (and very good news). The msetforboss rop chain on ROPinstaller.nds works for dumping mset RAM memory for both old3ds and new3ds on 9.x (assuming a 4.5 downgraded mset). Use the 4x ram dumper here,
https://github.com/WinterMute/ROPInstaller
(this is the repo N3DS_ropinstaller is based on, included with the app)

with msetforboss 4x chain for old 3ds. It works. I dumped 3MB of mset memory for old3ds (2DS) and n3ds on 9.x.
 
  • Like
Reactions: Margen67
When will be able to get the keys from our own purchased eShop games, inject them to a general release, so we can boot them from sysNAND?

Well, you see, tickets for eShop stuff includes your console id and are signed, so... without Nintendo's private keys, never.
 
Well, you see, tickets for eShop stuff includes your console id and are signed, so... without Nintendo's private keys, never.
Would it be possible to purchase, say zelda from the shop (in emuNAND), dump it with funkyCIA, and install it on sysNAND and then inject the custom save to it?
 
Would it be possible to purchase, say zelda from the shop (in emuNAND), dump it with funkyCIA, and install it on sysNAND and then inject the custom save to it?

It would be actually faster to download the game directly in sysNAND...
Anyway. It is possible. Not easy (at all), but possible.
 
  • Like
Reactions: Margen67
Nope, the game needs to be signed.
Doesn't the eShop generate keys for the game that match your console while it is downloading it?
It would be actually faster to download the game directly in sysNAND...
Anyway. It is possible. Not easy (at all), but possible.
But then you would need to mess with the NAND tickets, no?
 
Would it be possible to purchase, say zelda from the shop (in emuNAND), dump it with funkyCIA, and install it on sysNAND and then inject the custom save to it?
the GW save doesnt work with the eshop version, their save is hardcoded to load the exploit payload at a specific offset on the games save chip.....so even if you install the exploit you would need a cart in with the exploit injected at 0x1E000.....doesnt even need to be zelda :P
 
Well, you see, tickets for eShop stuff includes your console id and are signed, so... without Nintendo's private keys, never.

I was thinking that, and then I thought "Hey, wait. PGP works the other way round." According to the PGP model, to sign/encrypt stuff just for you, Nintendo would use the Public Key for your 3DS. And to validate that key, your console would use the corresponding Private Key, included when the firmware was written. Many key systems allow you to generate the Public Key from the Private Key. I'm not aware of a key system that works the other way round, but I'm no expert on the topic. Maybe today I will learn new things.
 
Doesn't the eShop generate keys for the game that match your console while it is downloading it?
It does but emunand and sysnand are two completely different things. When you're installing something to emunand think of it as if you're installing it on a completely different console.
 
the GW save doesnt work with the eshop version, their save is hardcoded to load the exploit payload at a specific offset on the games save chip.....so even if you install the exploit you would need a cart in with the exploit injected at 0x1E000.....doesnt even need to be zelda :P
Oh, there goes my idea of getting rid of the physical cartrdige...
And CN was taken from the eShop, so, we'll stick with cartridges.
 
I was thinking that, and then I thought "Hey, wait. PGP works the other way round." According to the PGP model, to sign/encrypt stuff just for you, Nintendo would use the Public Key for your 3DS. And to validate that key, your console would use the corresponding Private Key, included when the firmware was written. Many key systems allow you to generate the Public Key from the Private Key. I'm not aware of a key system that works the other way round, but I'm no expert on the topic. Maybe today I will learn new things.

No. Your console id is included in the ticket, (the whole ticket is signed with Nintendo private key), and your 3DS checks if the console id in te ticket is the same than the console id of the console.
 
Oh, there goes my idea of getting rid of the physical cartrdige...
And CN was taken from the eShop, so, we'll stick with cartridges.
well if they re-worked their exploit it *should* be possible to load from a files stored in the save like how CN works by reading "GW3DS.BIN" stored in the save rather than at a specific offset on the save chip
 
edit - is there any need for me to perform this "Install NVRAm installer" option?

That's for the New 3DS. In fact, it's for a hack on the New 3DS where you install the system settings from the old 3DS so that it can use a similar exploit.
 
I can't get DevMenu.3ds to run at all. I've downloaded it from three different places now, but when I run it in GW Mode on sysNAND the screens just go black. Anyone got any theories?

I've still not got this DevMenu.3ds to work in GW Mode in sysNAND. I've tried 4 MicroSD cards of sizes 1GB, 4GB, 32GB and 64GB, all formatted fully with SD Formatter and Windows; and several different copies of DevMenu.3ds. Any other .3ds file works fine, it's just DevMenu that won't.
 

Site & Scene News

Popular threads in this forum