Homebrew [RELEASE] TWLTool - DSi downgrading, save injection, etc multitool

Apache Thunder

I have cameras in your head!
Member
Joined
Oct 7, 2007
Messages
4,431
Trophies
3
Age
36
Location
Levelland, Texas
Website
www.mariopc.co.nr
XP
6,799
Country
United States

mb2010

Well-Known Member
Newcomer
Joined
Jan 12, 2015
Messages
63
Trophies
0
Age
34
XP
156
Country
Can't seem to successfully decrypt my nand. I've got both the cid and console id but can't access the nand after decryption. I must be doing something wrong.
 

WhoAmI?

PASTA's dirty animal
Member
Joined
Mar 15, 2015
Messages
1,276
Trophies
0
Location
Poké Ball
Website
lavanoid.github.io
XP
1,279
Country
Does anyone think it's possible to exploit Pokemon Black2/White2? It's a DSi Capable game card... Was wondering if that could be used... Where would someone start if they wanted to exploit this game? I mean it was a popular game. If someone exploited it, more people would likely be able to get homebrew on their DSi as well :)

Uh. You think someone could copy and paste this so Wulfy can see? I think she muted me... I'll ask her in a PM but I doubt she'll reply (I used to nag her a lot. Bet she got pissed with me >.< She's so awesome though! 0~0)
 

VinsCool

Persona Secretiva Felineus
Global Moderator
Joined
Jan 7, 2014
Messages
14,600
Trophies
4
Location
Another World
Website
www.gbatemp.net
XP
25,207
Country
Canada
I'm thinking it's a short too, since it happens whenever, not just at the menu. I tried cleaning it but nothing changed. It looked clean in the first place as well.

--------------------- MERGED ---------------------------


In case this hasn't been solved yet, your T61 might have a Lenovo smartcard reader. That communicates through USB.
The card reader seems to be either Ricoh R5C843 or Ricoh R5C847, both communicates through PCI.

EDIT: Datasheet: http://www.e-devices.ricoh.co.jp/en/products/product_pcif/pcc/5c843/index.html
http://www.e-devices.ricoh.co.jp/en/products/product_pcif/pcc/5c847/index.html

It's likely that this device doesn't abstract memory card communications, since the OS needs specific drivers for it.
So, does that mean my card reader is compatible with cid dump?
 

Gadorach

Electronics Engineering Technologist
Member
Joined
Jan 22, 2014
Messages
970
Trophies
0
Location
Canada
XP
956
Country
Canada
btw, @Gadorach , any idea if there's any way to fix that problem with my DSi?
My guess is there's some debris, or an accidental solder joint, on the board. It could be on the R/L trigger lines themselves. It's really sounding like a short though, so look over both the board and disassemble the triggers. With any luck, you'll find what's causing the problem. I wish I could give you a more detailed answer, but I'd really need to have the console in my hands to do that.
 

Gadorach

Electronics Engineering Technologist
Member
Joined
Jan 22, 2014
Messages
970
Trophies
0
Location
Canada
XP
956
Country
Canada
Hey so we're able to extract the right things from the DSi to use no$gba's DSi Emulation, correct? http://problemkaputt.de/gba.htm
Definitely, but even better, thanks to that link, I now can make a pinout for the NAND Mod on the DSi without removing any screws from the mainboard at all. PS, the missing pin was CLK, and it's on either side of R113, just above the CPU heatsink/RFI shield.

Also, I just ordered a ton of 0402 SMD resistors to repair broken DSi's where people did stupid things, like solder to the RA4 resister array. I also got the values for the DSi XL, and the 2DS/3DS/XL and New 3DS/XL.

0402 is pretty microscopic though, so they aren't really meant for hand placement. BUUUUUUUT, I'll make it work. Nothing a little solder paste and a reflow station can't solve.

Is there a "soft" way to dump the NAND?
Technically, it would be possible to dump it through a DSiWare exploit, but the trouble is that you first need to have one installed, so the order's wrong. Plus, Team Twiizers intentionally disabled NAND access in their DSiWare hacks, so that would have to be re-enabled first.
 
Last edited by Gadorach,

gudenau

Largely ignored
Member
Joined
Jul 7, 2010
Messages
3,882
Trophies
2
Location
/dev/random
Website
www.gudenau.net
XP
5,386
Country
United States
Definitely, but even better, thanks to that link, I now can make a pinout for the NAND Mod on the DSi without removing any screws from the mainboard at all. PS, the missing pin was CLK, and it's on either side of R113, just above the CPU heatsink/RFI shield.


Technically, it would be possible to dump it through a DSiWare exploit, but the trouble is that you first need to have one installed, so the order's wrong. Plus, Team Twiizers intentionally disabled NAND access in their DSiWare hacks, so that would have to be re-enabled first.
I do have sodukuhax 1.
 

zoogie

playing around in the end of life
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,000
Country
Micronesia, Federated States of
Definitely, but even better, thanks to that link, I now can make a pinout for the NAND Mod on the DSi without removing any screws from the mainboard at all. PS, the missing pin was CLK, and it's on either side of R113, just above the CPU heatsink/RFI shield.


Technically, it would be possible to dump it through a DSiWare exploit, but the trouble is that you first need to have one installed, so the order's wrong. Plus, Team Twiizers intentionally disabled NAND access in their DSiWare hacks, so that would have to be re-enabled first.
The exploit save files in the OP are in plaintext. They're FAT archives like the nand itself.
 

Gadorach

Electronics Engineering Technologist
Member
Joined
Jan 22, 2014
Messages
970
Trophies
0
Location
Canada
XP
956
Country
Canada
The exploit save files in the OP are in plaintext. They're FAT archives like the nand itself.
That's true, but don't look at me, I don't know how to do it, ha ha
I'm a hardware man first, and a software man second.

Further, someone would need to write an app to read and write the NAND from within a DSiWarehax environment, and no one has done that just yet.
 

VinsCool

Persona Secretiva Felineus
Global Moderator
Joined
Jan 7, 2014
Messages
14,600
Trophies
4
Location
Another World
Website
www.gbatemp.net
XP
25,207
Country
Canada
The exploit save files in the OP are in plaintext. They're FAT archives like the nand itself.
So technically, it may be possible to modify and allow nand access through software exploits, if any new is found in the meantime?
 
  • Like
Reactions: Margen67

piratesephiroth

I wish I could read
Member
Joined
Sep 5, 2013
Messages
3,453
Trophies
2
Age
103
XP
3,233
Country
Brazil
Last edited by piratesephiroth,
  • Like
Reactions: Margen67

zoogie

playing around in the end of life
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,000
Country
Micronesia, Federated States of
We're still missing the last of the coveted DSiwareHaxx savegames people. The special game that no longer exists in the eshop is:
Guitar Rock Tour. (EU or US)
I've attached a slight modification of dsi_srl_extract that can dump a modified TAD's (the dsiware's bin file that is exported from your DSi) save whereas the normal version bails when it sees a wrong checksum.

Instructions:
Install the "Grtpwn" on Guitar Rock Tour using directions from here. Then just drag and drop, share the save, and be loved by all. :D
 

Attachments

  • dsi_sav_extract.zip
    57.8 KB · Views: 1,228
Last edited by zoogie,

Apache Thunder

I have cameras in your head!
Member
Joined
Oct 7, 2007
Messages
4,431
Trophies
3
Age
36
Location
Levelland, Texas
Website
www.mariopc.co.nr
XP
6,799
Country
United States
Reverse adapters that convert SD to microSD do exist:

http://www.amazon.com/Bplus-B1912A-...7976988&sr=8-4&keywords=SD+to+MicroSD+Adapter

Kinda obscure and expensive though. You could either solder your nand mod cable directly to that or just make a standard nand mod adapter and use this for your phone when ever you want to use the phone.

But literally you only need to use it once to get the CID and once you have it, that's it. I think it's not cost effective unless you are running a DSi NAND modding service. :P

I don't know if Android gives you low level access to the MicroSD slot on the phone. Android is linux based. So perhaps it can if the app you install has the permissions for it perhaps.

That and I can see using this on a n3DS if you really hate using MicroSD cards. :P

You can probably carve out a small slit for the cable and and attach the top end to back of the top screen. It would be ghetto as all hell, but it would work. :P
 
  • Like
Reactions: Margen67 and nastys

WulfyStylez

SALT/Bemani Princess
OP
Member
Joined
Nov 3, 2013
Messages
1,149
Trophies
0
XP
2,877
Country
United States
The exploit save files in the OP are in plaintext. They're FAT archives like the nand itself.
The saves (all?) have checksums you'd need to figure out first. The easier route would just be to have your homebrew app set keys itself on init, then anything would work.
 
  • Like
Reactions: zoogie

Duo8

Well-Known Member
Member
Joined
Jul 16, 2013
Messages
3,613
Trophies
2
XP
3,026
Country
Vietnam
Reverse adapters that convert SD to microSD do exist:

http://www.amazon.com/Bplus-B1912A-...7976988&sr=8-4&keywords=SD+to+MicroSD+Adapter

Kinda obscure and expensive though. You could either solder your nand mod cable directly to that or just make a standard nand mod adapter and use this for your phone when ever you want to use the phone.

But literally you only need to use it once to get the CID and once you have it, that's it. I think it's not cost effective unless you are running a DSi NAND modding service. :P

I don't know if Android gives you low level access to the MicroSD slot on the phone. Android is linux based. So perhaps it can if the app you install has the permissions for it perhaps.

That and I can see using this on a n3DS if you really hate using MicroSD cards. :P

You can probably carve out a small slit for the cable and and attach the top end to back of the top screen. It would be ghetto as all hell, but it would work. :P
A cheaper one: http://www.dx.com/p/sd-to-microsd-transflash-card-converter-module-27001#.VbXPzpNEH0o

Oh and I was able to read the CID without root. You don't even need an app for this.
 
  • Like
Reactions: Margen67 and nastys

loco365

Well-Known Member
Member
Joined
Sep 1, 2010
Messages
5,457
Trophies
0
XP
2,927
Does anyone think it's possible to exploit Pokemon Black2/White2? It's a DSi Capable game card... Was wondering if that could be used... Where would someone start if they wanted to exploit this game? I mean it was a popular game. If someone exploited it, more people would likely be able to get homebrew on their DSi as well :)

Uh. You think someone could copy and paste this so Wulfy can see? I think she muted me... I'll ask her in a PM but I doubt she'll reply (I used to nag her a lot. Bet she got pissed with me >.< She's so awesome though! 0~0)
I doubt that White/Black/White 2/Black 2 can be exploited anyway. Game Freak writes very clean and tidy code, and their save data has checksums out the ass.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    SylverReZ @ SylverReZ: People are gonna find loopholes around clan tags and make inappropriate names.