Hacking Can 3DS downgrade to firmware 10.1 max?

  • Thread starter Thread starter Viris
  • Start date Start date
  • Views Views 36,485
  • Replies Replies 180
  • Likes Likes 1
Status
Not open for further replies.
Developer @17321 said there was a possible downgrade some time ago in 9.9, he didn't lie neither, there was a possibility which turned to be unusable at the end.

What I mean is, he may not be lying about the *possibility*, that doesn't make it a reality.
well the main issue for firmware downgrade is mainly how to downgrade the firm in itself, since AM services don't allow for downgrading and you can't uninstall firm to then install a lower version of firm, so that may have been his problem ^^'
 
On twitter it says this will possibly work on 10.3 :D. I LIKE! *Starts clapping and disables internet on 3DSes*
 
you can't uninstall firm to then install a lower version of firm

You can with process9 exploit

"
When a title is *already* installed, Process9 will compare the installed title-version with the title-version being installed. When the one being installed is older, Process9 would return an error.

However, this can be bypassed by just deleting the title first via the service command(s) for that: with the title removed from the Title_Database, Process9 can't compare the input title-version with anything. Hence, titles can be downgraded this way."
 
Last edited by MasterLel,
You can with process9

"
When a title is *already* installed, Process9 will compare the installed title-version with the title-version being installed. When the one being installed is older, Process9 would return an error.

However, this can be bypassed by just deleting the title first via the service command(s) for that: with the title removed from the Title_Database, Process9 can't compare the input title-version with anything. Hence, titles can be downgraded this way."
doesn't that require ARM9 accesto do so ? could have sworn
 
explain the svcBackdoor then

He doesn't have to (and he isn't going to) explain how his stuff works, if you and someone else are ballsy enough to throw this kind of claims around you should have proof to backup what you are saying...

You have to prove him wrong not otherwise :dry:
 
He doesn't have to (and he isn't going to) explain how his stuff works, if you and someone else are ballsy enough to throw this kind of claims around you should have proof to backup what you are saying...

You have to prove him wrong not otherwise :dry:
You don't know why do I say that. He will understand.

--------------------- MERGED ---------------------------

svc-mode code could get pxi:am9 or patch am:net to downgrade NATIVE_FIRM, and with svcBackdoor it's not a problem.
 
He doesn't have to (and he isn't going to) explain how his stuff works, if you and someone else are ballsy enough to throw this kind of claims around you should have proof to backup what you are saying...

You have to prove him wrong not otherwise :dry:

Mrrraou just has to post the dissassembly of a portion of *hax 2.5 code. As doing this is straightforward, he doesn't need to do so.
 
As seen twice in the 2.5 payload:
Code:
ROM:000054D8                 SVC             0x7B ; '{'
And 0x7B is for svcBackdoor
(and this is used)
 
Last edited by Mrrraou,
The payload has access to CreateMemoryBlock (0x1E), MapMemoryBlock (0x1F) and UnmapMemoryBlock (0x20) too (and more). But according to 3dbrew, these three ones are accessible from most processes.
Applications normally only have access to SVCs <=0x3D, however not all SVCs <=0x3D are accessible to the application. The majority of the SVCs accessible to applications are unused by the application.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum