Hacking Emunand 9.6+ on N3DS

Ailuros27

Well-Known Member
OP
Member
Joined
Apr 7, 2015
Messages
732
Trophies
0
XP
421
Country
United States
I hate to keep creating new threads, but since the site's search feature won't let me search strings shorter than five characters I don't know what to do. Google never seems to give very relevant results even when limited to this domain.

My question is this: After Smealum's appearance at that hacking conference, I thought I remembered word going around that some of the info they revealed could theoretically be used to solve the problem of emunand only going up to 9.5 on the New 3DS? Was that info mistaken, and if not, then does anyone know if someone is confirmed to be working on that? I don't expect a release date or anything, but it would be nice to know the prospects of that happening, and if anyone is actively working on it.
 

Quantumcat

Dead and alive
Member
Joined
Nov 23, 2014
Messages
15,144
Trophies
0
Location
Canberra, Australia
Website
boot9strap.com
XP
11,094
Country
Australia
I hate to keep creating new threads, but since the site's search feature won't let me search strings shorter than five characters I don't know what to do. Google never seems to give very relevant results even when limited to this domain.

My question is this: After Smealum's appearance at that hacking conference, I thought I remembered word going around that some of the info they revealed could theoretically be used to solve the problem of emunand only going up to 9.5 on the New 3DS? Was that info mistaken, and if not, then does anyone know if someone is confirmed to be working on that? I don't expect a release date or anything, but it would be nice to know the prospects of that happening, and if anyone is actively working on it.
We will find out when Gateway release their promised update supporting 10.3. If their update actually supports 10.3 then it is likely the 9.6+ issue is solved. If they just provide a way to downgrade then it won't be solved. As far as I know nobody is working on it except possibly Gateway (they always keep their hand close to their chest so we never know what they're really doing until they release stuff).
 

Tony_93

Well-Known Member
Member
Joined
Jun 13, 2015
Messages
2,457
Trophies
1
Location
California
XP
2,436
Country
United States
We will find out when Gateway release their promised update supporting 10.3. If their update actually supports 10.3 then it is likely the 9.6+ issue is solved. If they just provide a way to downgrade then it won't be solved. As far as I know nobody is working on it except possibly Gateway (they always keep their hand close to their chest so we never know what they're really doing until they release stuff).

I don't know why, but I feel that their "10.3 support" is a downgrade method too.

I think I'll wait for their downgrade method if that's the case.

The one from 9.2 to 4.x was pretty reliable.
 

Quantumcat

Dead and alive
Member
Joined
Nov 23, 2014
Messages
15,144
Trophies
0
Location
Canberra, Australia
Website
boot9strap.com
XP
11,094
Country
Australia
I don't know why, but I feel that their "10.3 support" is a downgrade method too.

I think I'll wait for their downgrade method if that's the case.

The one from 9.2 to 4.x was pretty reliable.
Hopefully the same thing happens now that happened in 2014/15 - first was a downgrade method, then a month or so later the firmware you could downgrade from was actually supported without downgrade.
 

Ailuros27

Well-Known Member
OP
Member
Joined
Apr 7, 2015
Messages
732
Trophies
0
XP
421
Country
United States
But it is theoretically possible with the kind of kernel access memchunkhax2 has and the info from the conference, right?
 

Tony_93

Well-Known Member
Member
Joined
Jun 13, 2015
Messages
2,457
Trophies
1
Location
California
XP
2,436
Country
United States
Smea and the guys talked about how they did to get a common key using the wii u, get another from the 8.1J N3DS and brute force the key generator.

But they didn't share methods and tools used...

So, I think having someone replicating all that successfully from scratch again requires a godly knowledge the average people around here doesn't have...
 

Ailuros27

Well-Known Member
OP
Member
Joined
Apr 7, 2015
Messages
732
Trophies
0
XP
421
Country
United States
Oh. I thought they released that info. Or that I heard someone had knew of a way to get said keys if they sacrificed an N3DS.
 
D

Deleted-236924

Guest
But it is theoretically possible with the kind of kernel access memchunkhax2 has and the info from the conference, right?
memchunkhax2 gives you ARM11 but you also need ARM9 for full access.
GW may be able to get ARM9 by exploiting ntrcardhax.
 
  • Like
Reactions: Tony_93

Quantumcat

Dead and alive
Member
Joined
Nov 23, 2014
Messages
15,144
Trophies
0
Location
Canberra, Australia
Website
boot9strap.com
XP
11,094
Country
Australia
Oh. I thought they released that info. Or that I heard someone had knew of a way to get said keys if they sacrificed an N3DS.
*pictures people in Pacific Islander clothing dancing around a marble slab with an N3DS tied to it, surrounded by tiki torches, with one guy wearing a big headdress holding a knife chanting to the gods to give him the Holy Knowledge of the Keys*
 

Xenon Hacks

Well-Known Member
Member
Joined
Nov 13, 2014
Messages
7,414
Trophies
1
Age
30
XP
4,687
Country
United States
Smea and the guys talked about how they did to get a common key using the wii u, get another from the 8.1J N3DS and brute force the key generator.

But they didn't share methods and tools used...

So, I think having someone replicating all that successfully from scratch again requires a godly knowledge the average people around here doesn't have...
We will have 10.3 eventually http://gbatemp.net/threads/aes-key-scrambler.406951/
 
D

Deleted User

Guest
*pictures people in Pacific Islander clothing dancing around a marble slab with an N3DS tied to it, surrounded by tiki torches, with one guy wearing a big headdress holding a knife chanting to the gods to give him the Holy Knowledge of the Keys*

Not sure if bizarre ritual or sequel to Super Mario Sunshine....
 

Ailuros27

Well-Known Member
OP
Member
Joined
Apr 7, 2015
Messages
732
Trophies
0
XP
421
Country
United States
Thank you all. I've already downgraded my old 3DS and am using it to feel out how best to set things up when I finally downgrade my N3DS XL with all my stuff on it. Now I'll wait for KTM just to idiot proof things a bit more, and then downgrade. I can still play 9.6+ legit games on my O3DS' emunand, so I think I'll go for it once KTM is released.
 

Aroth

Well-Known Member
Member
Joined
Apr 14, 2015
Messages
2,066
Trophies
0
Age
37
XP
891
Country
United States
I hate to keep creating new threads, but since the site's search feature won't let me search strings shorter than five characters I don't know what to do. Google never seems to give very relevant results even when limited to this domain.

My question is this: After Smealum's appearance at that hacking conference, I thought I remembered word going around that some of the info they revealed could theoretically be used to solve the problem of emunand only going up to 9.5 on the New 3DS? Was that info mistaken, and if not, then does anyone know if someone is confirmed to be working on that? I don't expect a release date or anything, but it would be nice to know the prospects of that happening, and if anyone is actively working on it.

But it is theoretically possible with the kind of kernel access memchunkhax2 has and the info from the conference, right?

No. Not gonna happen. Mch2 only gives arm11 access and by the time that arm11 is even initialized the keys have been cleared from the part of the memory we can access. In order to get the keys we need arm9, and likely access to it very early in the boot cycle as the keys are cleared almost as soon as arm9 is initialized.

So there's not much hope of being able to play legit cartridges on a downgraded N3DS any time soon, then?

Not without GW no.

--------------------- MERGED ---------------------------

Aren't 9.6+ games firmware spoofed so you wouldn't need emunand past 9.5?

They can be, but I think the person in question was talking about playing from the cart.
 
D

Deleted-236924

Guest
They can be, but I think the person in question was talking about playing from the cart.
If your cfw uses a much higher native_firm with firmlaunch then it should work fine no?
Or can cfw somehow not firmlaunch a native_firm above 9.5?

I know that rxTools 3.0 supports N3DS as well as O3DS, and cdn_firm.py generates the same firmware.bin regardless of if you use an O3DS or an N3DS. At least it does on 9/28 nightly, I know with later nightlies they started changing the way firmware files worked and all.

Does 9/28 nightly work with N3DS or was N3DS support added much later when they changed the way firm worked?

Cause if the same firmware.bin can be used for firmlaunch on both O3DS and N3DS then it should allow you to run a game from a cartridge without it telling you it needs to update no?
 
Last edited by ,

Aroth

Well-Known Member
Member
Joined
Apr 14, 2015
Messages
2,066
Trophies
0
Age
37
XP
891
Country
United States
What do you mean by "not without GW"? Do you mean the physical card, or them actually doing the grunt work?

The physical cart. Part of what GW's software does is spoof the kernel version so that the check done by the exheader passes. Reinand and rxTools do not do this, which is why when you try to run a cia (or updated cia) that "requires" a firmware above 9.5 the game hangs on the 3DS logo. I am 99% sure the same would happen with a retail cart even if the CFW you use manages to patch the service call that decides whether to prompt to install the update on the cart.

--------------------- MERGED ---------------------------

If your cfw uses a much higher native_firm with firmlaunch then it should work fine no?
Or can cfw somehow not firmlaunch a native_firm above 9.5?

No one can launch the 9.6+ native_firm for the N3DS because we don't have the keys needed to decrypt it.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    NinStar @ NinStar: It will actually make it worse