Homebrew 'ntrcardhax' / downgrading questions

Kitlith

Well-Known Member
OP
Newcomer
Joined
Jan 29, 2016
Messages
93
Trophies
0
Location
Trapped between a rock and a hard place
Website
kitl.pw
XP
218
Country
United States

dark_samus3

Well-Known Member
Member
Joined
May 30, 2015
Messages
2,372
Trophies
0
XP
2,042
Country
United States
I do wish XDS had more documentation, though, telling us what it does. It apparently can't run commercial games, so I kind of doubt that it could boot from an encrypted NAND dump. I could certainly be wrong, though. That would be exciting.
DEcrypted, not ENcrypted ;)
 

Kitlith

Well-Known Member
OP
Newcomer
Joined
Jan 29, 2016
Messages
93
Trophies
0
Location
Trapped between a rock and a hard place
Website
kitl.pw
XP
218
Country
United States
DEcrypted, not ENcrypted ;)
Well, derp then. Seems a *bit* more likely. Still don't know anything about it. Not opposed to finding out, especially if it would work for this. xD

EDIT: It looks like XDS does a high-ish level emulation of Process9. *shrugs*
AGAIN: Yeah, it looks like XDS only simulates arm11. So...
 
Last edited by Kitlith,
  • Like
Reactions: dark_samus3

Aroth

Well-Known Member
Member
Joined
Apr 14, 2015
Messages
2,066
Trophies
0
Age
37
XP
891
Country
United States
Guys, a quick offtopic question; up to what firmware does browserhax work without the browser nag? And is there any way to bypass the nag?

The nag was added with 10.0.0-27, however game carts that contain 9.9 also contain a stubbed browser that requires you to update the console via the internet (aka system settings) in order for it to work again.

If I remember correctly, there was a way to bypass it as long as you haven't already tried to open the browser yet (might be possible even with the browser already nagging, idk).

That said, this should only really be a problem for you if you are on 10.4 because if you are on 10.3 or lower you should just downgrade to 9.2 and switch to cfw/emunand. If you are already on 10.4 you should probably just update to 10.5.

--------------------- MERGED ---------------------------

Keep in mind that even on 10.4 or 10.5 you can still downgrade to 9.2 if you have a hard mod to use for dumping/flashing the nand chip.
 

Syphurith

Beginner
Member
Joined
Mar 8, 2013
Messages
641
Trophies
0
Location
Xi'an, Shaanxi Province
XP
364
Country
Switzerland
A wild idea just popped up. Kinds of weird. The original image that produced the special commands 'B/BL/..' for us is not broken if decrypted correctly. After it gets execution, it re-encrypt and re-decrypt it to good, patch it on the fly, and it gets launched. It would also probably produces some holes for dumps that can be touched after re-exploit.

173210 merely comes here. You can find him at twitter. He tried to use DSTWO+ SDK to create the 'hardware' which reacts to wrong request as 0x4000 when ARM11 boom. However his one is lost, thus stopping him from going further with it, currently.
I do wonder if someone replace the encrypted FIRM0/FIRM1 with the older exploitable version (<10.4) and with 10.5 Title in CTRNAND, would it be exploitable?
 

Aroth

Well-Known Member
Member
Joined
Apr 14, 2015
Messages
2,066
Trophies
0
Age
37
XP
891
Country
United States
I do wonder if someone replace the encrypted FIRM0/FIRM1 with the older exploitable version (<10.4) and with 10.5 Title in CTRNAND, would it be exploitable?

I assume you mean flashing an encrypted 10.2 firm0/firm1 partition to the nand chip?

This can and HAS been done by several people over the last 36 hours in another thread. It requires a hardmod and I think access to an exploited 3ds on 9.2 that can generate xorpads for the firm partition, but the general gist is that you take an the encrypted 10.4 firm0/firm1 from your console, xor it against a decrypted 10.4 firm0/firm1, then use the result to encrypt a decrypted firm0/firm1 with your console's key. You then patch the encrypted 10.2 firm0/firm1 into the clean nand.bin you dumped from your 10.4/10.5 system, then flash the entire thing back to your nand chip.

The result is a 10.4 or 10.5 system software running on top of a 10.2 firm, making the entire system vulnerable to mch2 again and allowing you to downgrade to 9.2.

The big hurdle is that it requires a hard mod to dump/flash the nand, and it is only useful for us because Nintendo fucked up and only iterated the revision number when they patched mch2. If they had iterated the version number and updated the home menu to check for the iterated version number then the entire process would fail and result in a brick.
 

Syphurith

Beginner
Member
Joined
Mar 8, 2013
Messages
641
Trophies
0
Location
Xi'an, Shaanxi Province
XP
364
Country
Switzerland
--------------------- MERGED ---------------------------
I wanna multiple people dump his own FIRM0/FIRM1 parition in both encrypted/decrypted form. The decrypted form of those could be the same as other that having the same FIRM version. Although i don't know how that decrypted FIRM0/FIRM1 is generated when FIRM is updated. If this is true, just dump the original, and have the same FIRM in decrypted form - you can then get your own FIRM0/FIRM1 xorpad. Also, the kernel launched in FIRM. Not much ways to brick it legally (orz).
--------------------- MERGED ---------------------------
@Apache Thunder I wonder if we should also stock the decrypted form of FIRM..
--------------------- MERGED ---------------------------
Okey i know now this could also be partially blocked, using KernelVersion flag for system modules and HomeMenu...
 
Last edited by Syphurith,

dark_samus3

Well-Known Member
Member
Joined
May 30, 2015
Messages
2,372
Trophies
0
XP
2,042
Country
United States
I assume you mean flashing an encrypted 10.2 firm0/firm1 partition to the nand chip?

This can and HAS been done by several people over the last 36 hours in another thread. It requires a hardmod and I think access to an exploited 3ds on 9.2 that can generate xorpads for the firm partition, but the general gist is that you take an the encrypted 10.4 firm0/firm1 from your console, xor it against a decrypted 10.4 firm0/firm1, then use the result to encrypt a decrypted firm0/firm1 with your console's key. You then patch the encrypted 10.2 firm0/firm1 into the clean nand.bin you dumped from your 10.4/10.5 system, then flash the entire thing back to your nand chip.

The result is a 10.4 or 10.5 system software running on top of a 10.2 firm, making the entire system vulnerable to mch2 again and allowing you to downgrade to 9.2.

The big hurdle is that it requires a hard mod to dump/flash the nand, and it is only useful for us because Nintendo fucked up and only iterated the revision number when they patched mch2. If they had iterated the version number and updated the home menu to check for the iterated version number then the entire process would fail and result in a brick.
You should link us to this thread ;)
 

Kitlith

Well-Known Member
OP
Newcomer
Joined
Jan 29, 2016
Messages
93
Trophies
0
Location
Trapped between a rock and a hard place
Website
kitl.pw
XP
218
Country
United States
Well, I'm downgrading from 9.9 to 9.2 today. I've removed the update nag, it currently has wifi turned off, I've verified the sha1sum and md5sum of the downgrade pack. I've checked that it's the right region and version of 3DS. Just need to use FTBrony to transfer safeSysUpdater and the downgrade pack, and then I'm clear to go.
 

Shadowtrance

Well-Known Member
Member
Joined
May 9, 2014
Messages
2,493
Trophies
0
Location
Hervey Bay, Queensland
XP
1,807
Country
Well, I'm downgrading from 9.9 to 9.2 today. I've removed the update nag, it currently has wifi turned off, I've verified the sha1sum and md5sum of the downgrade pack. I've checked that it's the right region and version of 3DS. Just need to use FTBrony to transfer safeSysUpdater and the downgrade pack, and then I'm clear to go.
Why on earth would you transfer the downgrade cia pack which is 100+ Mb over dodgy FTP instead of taking the card out and plugging it into the pc and copying?

Anyways, good luck. :)
 

Kitlith

Well-Known Member
OP
Newcomer
Joined
Jan 29, 2016
Messages
93
Trophies
0
Location
Trapped between a rock and a hard place
Website
kitl.pw
XP
218
Country
United States
Why on earth would you transfer the downgrade cia pack which is 100+ Mb over dodgy FTP instead of taking the card out and plugging it into the pc and copying?

Anyways, good luck. :)
Because my SD card reader is even more dodgy. Seriously, I can barely get it working sometimes. Anyway, I transferred it all, it's all good according to safeSysUpdater. Blasted pink dots...
 

Psi-hate

GBATemp's Official Psi-Hater
Member
Joined
Dec 14, 2014
Messages
1,750
Trophies
1
XP
3,433
Country
United States
Because my SD card reader is even more dodgy. Seriously, I can barely get it working sometimes. Anyway, I transferred it all, it's all good according to safeSysUpdater. Blasted pink dots...
Yeah, safesysupdater is an ass. I downgraded my friend's N3DS and his brother's O3DS a couple days ago. N3DS took like 5 tries to get passed the pink dots and the O3DS went first try. :P
 

Kitlith

Well-Known Member
OP
Newcomer
Joined
Jan 29, 2016
Messages
93
Trophies
0
Location
Trapped between a rock and a hard place
Website
kitl.pw
XP
218
Country
United States
Yeah, safesysupdater is an ass. I downgraded my friend's N3DS and his brother's O3DS a couple days ago. N3DS took like 5 tries to get passed the pink dots and the O3DS went first try. :P
It took several more times than that.

So, I got past the pink dots... and now it seems to be stuck during 'Checking update integrity...' on '/updates/0004001000021B00.cia'

Am I safe to reboot/reset or am I doomed? I don't think so, because it's checking the update integrity right now, but... I don't want to reset just yet just in case...
 

Psi-hate

GBATemp's Official Psi-Hater
Member
Joined
Dec 14, 2014
Messages
1,750
Trophies
1
XP
3,433
Country
United States
It took several more times than that.

So, I got past the pink dots... and now it seems to be stuck during 'Checking update integrity...' on '/updates/0004001000021B00.cia'

Am I safe to reboot/reset or am I doomed? I don't think so, because it's checking the update integrity right now, but... I don't want to reset just yet just in case...
As long as it hasn't installed anything, it's alright. Go ahead and reset it but hope that it doesn't freeze on the installation part. (It's very unlikely for it to freeze anyway so don't be too afraid as it's quite rare that sysupdater freezes). If it softbricks if it screws up, you should be able to update to 10.5 via the recovery menu and downgrade from there via a hardmod by injecting a 10.2 NATIVE_FIRM into your 10.5 nand-dump. Don't worry, no matter the result, you will be able to downgrade one way or another (unless you got the unfortunate event of a full brick which is very unlikely as most full bricks from sysupdater are from corrupted or wrong files).
 
Last edited by Psi-hate,

Kitlith

Well-Known Member
OP
Newcomer
Joined
Jan 29, 2016
Messages
93
Trophies
0
Location
Trapped between a rock and a hard place
Website
kitl.pw
XP
218
Country
United States
If it softbricks if it screws up, you should be able to update to 10.5 via the recovery menu and downgrade from there via a hardmod by injecting a 10.2 NATIVE_FIRM into your 10.5 nand-dump. Don't worry, no matter the result, you will be able to downgrade one way or another (unless you got the unfortunate event of a full brick which is very unlikely as most full bricks from sysupdater are from corrupted or wrong files).
Well, it hasn't been bricked in any form... yet... I just need to get it working again. So, if I don't get it working before I get home, I'm going to download the version of sysUpdater from the simple downgrading thread and use that: hopefully it has a better launch rate. ._.
 

Psi-hate

GBATemp's Official Psi-Hater
Member
Joined
Dec 14, 2014
Messages
1,750
Trophies
1
XP
3,433
Country
United States
Well, it hasn't been bricked in any form... yet... I just need to get it working again. So, if I don't get it working before I get home, I'm going to download the version of sysUpdater from the simple downgrading thread and use that: hopefully it has a better launch rate. ._.
I'm sure both has the same launch rate. SafeSysupdater is literally just the normal memchunkhax2 with checks and all that extra stuff so using the first version wouldn't do anything else but result in a worse chance of success.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BigOnYa @ BigOnYa:
    Biomutant looks cool tho, may have to try that
  • Quincy @ Quincy:
    Usually when such a big title leaks the Temp will be the first to report about it (going off of historical reports here, Pokemon SV being the latest one I can recall seeing pop up here)
  • K3Nv2 @ K3Nv2:
    I still like how a freaking mp3 file hacks webos all that security defeated by text yet again
  • BigOnYa @ BigOnYa:
    They have simulators for everything nowdays, cray cray. How about a sim that shows you playing the Switch.
  • K3Nv2 @ K3Nv2:
    That's called yuzu
    +1
  • BigOnYa @ BigOnYa:
    I want a 120hz 4k tv but crazy how more expensive the 120hz over the 60hz are. Or even more crazy is the price of 8k's.
  • K3Nv2 @ K3Nv2:
    No real point since movies are 30fps
  • BigOnYa @ BigOnYa:
    Not a big movie buff, more of a gamer tbh. And Series X is 120hz 8k ready, but yea only 120hz 4k games out right now, but thinking of in the future.
  • K3Nv2 @ K3Nv2:
    Mostly why you never see TV manufacturers going post 60hz
  • BigOnYa @ BigOnYa:
    I only watch tv when i goto bed, it puts me to sleep, and I have a nas drive filled w my fav shows so i can watch them in order, commercial free. I usually watch Married w Children, or South Park
  • K3Nv2 @ K3Nv2:
    Stremio ruined my need for nas
  • BigOnYa @ BigOnYa:
    I stream from Nas to firestick, one on every tv, and use Kodi. I'm happy w it, plays everything. (I pirate/torrent shows/movies on pc, and put on nas)
  • K3Nv2 @ K3Nv2:
    Kodi repost are still pretty popular
  • BigOnYa @ BigOnYa:
    What the hell is Kodi reposts? what do you mean, or "Wut?" -xdqwerty
  • K3Nv2 @ K3Nv2:
    Google them basically web crawlers to movie sites
  • BigOnYa @ BigOnYa:
    oh you mean the 3rd party apps on Kodi, yea i know what you mean, yea there are still a few cool ones, in fact watched the new planet of the apes movie other night w wifey thru one, was good pic surprisingly, not a cam
  • BigOnYa @ BigOnYa:
    Damn, only $2.06 and free shipping. Gotta cost more for them to ship than $2.06
  • BigOnYa @ BigOnYa:
    I got my Dad a firestick for Xmas and showed him those 3rd party sites on Kodi, he loves it, all he watches anymore. He said he has got 3 letters from AT&T already about pirating, but he says f them, let them shut my internet off (He wants out of his AT&T contract anyways)
  • K3Nv2 @ K3Nv2:
    That's where stremio comes to play never got a letter about it
  • BigOnYa @ BigOnYa:
    I just use a VPN, even give him my login and password so can use it also, and he refuses, he's funny.
  • BigOnYa @ BigOnYa:
    I had to find and get him an old style flip phone even without text, cause thats what he wanted. No text, no internet, only phone calls. Old, old school.
    K3Nv2 @ K3Nv2: @BigOnYa...