Um...you would create a security flaw
Um...you would create a security flaw
@ Nintendo No, I wasn't actually trying to notify anyone.Let's ask Nintendo!
Just had an idea about downgrading... We can't downgrade (unless we delete the old firmware) because of the system check, right ? So what about customizing a vulnerable firmware (like 9.2) changing its sysver to 10.4 or whatever, it should bypass the check and thus install the firmware, because it is technically newer than the current console firmware
So we would have a 9.2 fimrware exploits with a 10.4 sysver...

The client 3ds does the check there, since the host 3ds doesn't (and shouldn't) have access to the other console's securityhmmm, if you upgrade through dlp, which system does the check?
oh, well then just hack the dlp on the host so the check always passes, and sends older FW to the clientThe client 3ds does the check there, since the host 3ds doesn't (and shouldn't) have access to the other console's security
Eh what? I just said the client checks... And I guess vice versa too... Basically each system does its own check on any update CIAs that are passed to itoh, well then just hack the dlp on the host so the check always passes, and sends older FW to the client
EDIT: got ahead of myself
is there a basic routine of how the check happens?
is the host responsible for the location of the fw it sends?
Not sure if that too useful, seen as how any custom romFS can already be done with hans and not needing dlpHere's something that 'might' be possible:
Apparently dlp can send custom romfs files to an unhacked client, if this is true, it opens a whole new world of homebrew entrypoints!
Some examples that could be possible:
Rename an MK7 track name to cause a buffer overflow (if there aren't any protections against it, 'toad circuit' could become 'toad circuit0x7c4/rop'), resulting in rop access and from there, allow access to homebrew.
Or you could cause an overflow in the character names (mario becomes mario0x2c/rop)
It doesn't have to be mario kart (I'm not even sure if MK7 accesses the sd), you could literally edit any text/value you wanted in nearly any dlp game and send it to another console.
I haven't tested any of the above yet, I'm just saying there could be some unexplored attack vectors in the dlp protocol.
edit: MK7 does access the sdcard for ghost data etc...
If it was possible, it would be able to transfer the exploit to another system, allowing a console to share hax.Not sure if that too useful, seen as how any custom romFS can already be done with hans and not needing dlp
No. The NDS one has RSA checks (it had from the beginning). But maybe that a vuln in a game that is sent could be found. But it would be pretty useless anyway.One should note that the download play application allows you to access two different modes. For 3DS or NDS games.
If there's a vulnerability in the firmware that's used in the NDS mode (download play) then...![]()
