Hacking GATEWAY 3.2 ULTRA PUBLIC BETA

zoogie

playing around in the end of life
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,000
Country
Micronesia, Federated States of
Just a note for developers mainly (and very good news). The msetforboss rop chain on ROPinstaller.nds works for dumping mset RAM memory for both old3ds and new3ds on 9.x (assuming a 4.5 downgraded mset). Use the 4x ram dumper here,
https://github.com/WinterMute/ROPInstaller
(this is the repo N3DS_ropinstaller is based on, included with the app)

with msetforboss 4x chain for old 3ds. It works. I dumped 3MB of mset memory for old3ds (2DS) and n3ds on 9.x.
 
  • Like
Reactions: Margen67

motezazer

Well-Known Member
Member
Joined
Feb 6, 2015
Messages
1,214
Trophies
0
Age
24
XP
1,442
Country
France
When will be able to get the keys from our own purchased eShop games, inject them to a general release, so we can boot them from sysNAND?

Well, you see, tickets for eShop stuff includes your console id and are signed, so... without Nintendo's private keys, never.
 

motezazer

Well-Known Member
Member
Joined
Feb 6, 2015
Messages
1,214
Trophies
0
Age
24
XP
1,442
Country
France
Would it be possible to purchase, say zelda from the shop (in emuNAND), dump it with funkyCIA, and install it on sysNAND and then inject the custom save to it?

It would be actually faster to download the game directly in sysNAND...
Anyway. It is possible. Not easy (at all), but possible.
 
  • Like
Reactions: Margen67

MrJason005

√2
Member
Joined
Nov 26, 2014
Messages
2,521
Trophies
0
Location
Κάπου
XP
1,609
Country
Greece
Nope, the game needs to be signed.
Doesn't the eShop generate keys for the game that match your console while it is downloading it?
It would be actually faster to download the game directly in sysNAND...
Anyway. It is possible. Not easy (at all), but possible.
But then you would need to mess with the NAND tickets, no?
 

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
Would it be possible to purchase, say zelda from the shop (in emuNAND), dump it with funkyCIA, and install it on sysNAND and then inject the custom save to it?
the GW save doesnt work with the eshop version, their save is hardcoded to load the exploit payload at a specific offset on the games save chip.....so even if you install the exploit you would need a cart in with the exploit injected at 0x1E000.....doesnt even need to be zelda :P
 

retrospect

Well-Known Member
Member
Joined
May 17, 2008
Messages
571
Trophies
1
XP
1,194
Country
Well, you see, tickets for eShop stuff includes your console id and are signed, so... without Nintendo's private keys, never.

I was thinking that, and then I thought "Hey, wait. PGP works the other way round." According to the PGP model, to sign/encrypt stuff just for you, Nintendo would use the Public Key for your 3DS. And to validate that key, your console would use the corresponding Private Key, included when the firmware was written. Many key systems allow you to generate the Public Key from the Private Key. I'm not aware of a key system that works the other way round, but I'm no expert on the topic. Maybe today I will learn new things.
 

MrJason005

√2
Member
Joined
Nov 26, 2014
Messages
2,521
Trophies
0
Location
Κάπου
XP
1,609
Country
Greece
the GW save doesnt work with the eshop version, their save is hardcoded to load the exploit payload at a specific offset on the games save chip.....so even if you install the exploit you would need a cart in with the exploit injected at 0x1E000.....doesnt even need to be zelda :P
Oh, there goes my idea of getting rid of the physical cartrdige...
And CN was taken from the eShop, so, we'll stick with cartridges.
 

motezazer

Well-Known Member
Member
Joined
Feb 6, 2015
Messages
1,214
Trophies
0
Age
24
XP
1,442
Country
France
I was thinking that, and then I thought "Hey, wait. PGP works the other way round." According to the PGP model, to sign/encrypt stuff just for you, Nintendo would use the Public Key for your 3DS. And to validate that key, your console would use the corresponding Private Key, included when the firmware was written. Many key systems allow you to generate the Public Key from the Private Key. I'm not aware of a key system that works the other way round, but I'm no expert on the topic. Maybe today I will learn new things.

No. Your console id is included in the ticket, (the whole ticket is signed with Nintendo private key), and your 3DS checks if the console id in te ticket is the same than the console id of the console.
 

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
Oh, there goes my idea of getting rid of the physical cartrdige...
And CN was taken from the eShop, so, we'll stick with cartridges.
well if they re-worked their exploit it *should* be possible to load from a files stored in the save like how CN works by reading "GW3DS.BIN" stored in the save rather than at a specific offset on the save chip
 

retrospect

Well-Known Member
Member
Joined
May 17, 2008
Messages
571
Trophies
1
XP
1,194
Country
I can't get DevMenu.3ds to run at all. I've downloaded it from three different places now, but when I run it in GW Mode on sysNAND the screens just go black. Anyone got any theories?

I've still not got this DevMenu.3ds to work in GW Mode in sysNAND. I've tried 4 MicroSD cards of sizes 1GB, 4GB, 32GB and 64GB, all formatted fully with SD Formatter and Windows; and several different copies of DevMenu.3ds. Any other .3ds file works fine, it's just DevMenu that won't.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Jayro @ Jayro:
    The phat model had amazingly loud speakers tho.
    +1
  • SylverReZ @ SylverReZ:
    @Jayro, I don't see whats so special about the DS ML, its just a DS lite in a phat shell. At least the phat model had louder speakers, whereas the lite has a much better screen.
    +1
  • SylverReZ @ SylverReZ:
    They probably said "Hey, why not we combine the two together and make a 'new' DS to sell".
  • Veho @ Veho:
    It's a DS Lite in a slightly bigger DS Lite shell.
    +1
  • Veho @ Veho:
    It's not a Nintendo / iQue official product, it's a 3rd party custom.
    +1
  • Veho @ Veho:
    Nothing special about it other than it's more comfortable than the Lite
    for people with beefy hands.
    +1
  • Jayro @ Jayro:
    I have yaoi anime hands, very lorge but slender.
  • Jayro @ Jayro:
    I'm Slenderman.
  • Veho @ Veho:
    I have hands.
  • BakerMan @ BakerMan:
    imagine not having hands, cringe
    +1
  • AncientBoi @ AncientBoi:
    ESPECIALLY for things I do to myself :sad:.. :tpi::rofl2: Or others :shy::blush::evil:
    +1
  • The Real Jdbye @ The Real Jdbye:
    @SylverReZ if you could find a v5 DS ML you would have the best of both worlds since the v5 units had the same backlight brightness levels as the DS Lite unlockable with flashme
  • The Real Jdbye @ The Real Jdbye:
    but that's a long shot
  • The Real Jdbye @ The Real Jdbye:
    i think only the red mario kart edition phat was v5
  • BigOnYa @ BigOnYa:
    A woman with no arms and no legs was sitting on a beach. A man comes along and the woman says, "I've never been hugged before." So the man feels bad and hugs her. She says "Well i've also never been kissed before." So he gives her a kiss on the cheek. She says "Well I've also never been fucked before." So the man picks her up, and throws her in the ocean and says "Now you're fucked."
    +1
  • BakerMan @ BakerMan:
    lmao
  • BakerMan @ BakerMan:
    anyways, we need to re-normalize physical media

    if i didn't want my games to be permanent, then i'd rent them
    +1
  • BigOnYa @ BigOnYa:
    Agreed, that why I try to buy all my games on disc, Xbox anyways. Switch games (which I pirate tbh) don't matter much, I stay offline 24/7 anyways.
  • AncientBoi @ AncientBoi:
    I don't pirate them, I Use Them :mellow:. Like I do @BigOnYa 's couch :tpi::evil::rofl2:
    +1
  • cearp @ cearp:
    @BakerMan - you can still "own" digital media, arguably easier and better than physical since you can make copies and backups, as much as you like.

    The issue is DRM
  • cearp @ cearp:
    You can buy drm free games / music / ebooks, and if you keep backups of your data (like documents and family photos etc), then you shouldn't lose the game. but with a disk, your toddler could put it in the toaster and there goes your $60

    :rofl2:
  • cearp @ cearp:
    still, I agree physical media is nice to have. just pointing out the issue is drm
  • rqkaiju2 @ rqkaiju2:
    i like physical media because it actually feels like you own it. thats why i plan on burning music to cds
    rqkaiju2 @ rqkaiju2: i like physical media because it actually feels like you own it. thats why i plan on burning...