[Release] BootRom Dumper (A9LH Only!)

Supster131

(づ。◕‿‿◕。)づ *:・゚✧
OP
Member
Joined
Jan 19, 2016
Messages
3,315
Trophies
1
Location
My Computer
XP
2,758
Country
United States
EDIT: Yes, of course this was an April Fools joke, lol. The story I gave was bullshit obviously :P Only truth to it was that mid-kid and Aurora helped me create this (they pretty much did all the work, I just changed a bit of the text). So huge thanks to them for making this possible! As promised, I will release the source for it (I don't know why anyone would want it though). It's based on Aurora's SafeA9LHinstaller.

[Source] https://mega.nz/#!8Is0GYwR!hl-Bo8NdQoXAWFvZgql_YMqpgjgucDIX8CqpBKrG50w

ORIGINAL POST:
After a long while of testing and debugging, this was finally made possible. A bootrom dumper for the 3DS!
lTXVAC1h.jpg

This project started a few weeks ago. I was over on #cakey and was asked by mid-kid if I can help him out on something. I agreed. He told me he was working on something that would change the world. He sent me an early build of the bootrom dumper and it bricked my 2DS. Fortunately I have a hardmod for it. We continued testing, but it simply wouldn't want to work. A few days later I asked Aurora for some help. She was kind enough to lend a hand. She was able to find the correct offsets of the bootrom and even integrate screen-init to the payload (due to some people using her fork of A9LH. So yes, you can use this on any fork of A9LH). Finally, a few days ago Aurora and mid-kid got the dumper to work. You should have seen their reactions, they were almost going insane. As for what the bootrom can be used for, I wasn't told. I was simply told I had the rights to share this.

We tried making this work with 9.2 sysNAND, but it simply wouldn't work. It would freeze the system and create a corrupted file. So we opted to keep it A9LH only, since there's flaw in that the bootrom reads from a special SD card used at the factory. We originally dumped it that way, but we found that it was inefficient and risky. After some trial and error a safer way to dump the bootrom was found. Unfortunately we still couldn't to get it to work with HBL as the bootrom would have already been locked at that point.

Also, due to the request of mid-kid and Aurora, I cannot share the source code for this at the moment. They still need some time to clean up and polish the code. They told me they will most likely release the source for it in a day or two.

Download link: https://mega.nz/#!tRdxBKIC!Yk_w3zpfJ9bcGhVSKa_MpsQC3Q58Gfj86nEf6U2qW6w

Shout out to @mid-kid and @Aurora Wright for making this possible!
Shout out to @daxtsu and icecream for helping me test this!

Edit: Thanks to @astronautlevel for making the first ever bootrom exploit. It's similar to A9LH.
I've gotten an implementation of bootromloaderhax working with this!

Instructions:
1. Use @Supster131's tool to dump your bootloader
2. Copy the bootrom.bin to the /bootrom/ folder on your SD
3. Run this arm9loaderhax.bin
4. Profit!

https://mega.nz/#!K8AlGSrL!CFwOEtQnLfcFxwq3j-8QyyI9PuD_lDRQmMTR8wKruyo
 
Last edited by Supster131,

astronautlevel

Well-Known Member
Member
Joined
Jan 26, 2016
Messages
4,128
Trophies
2
Location
Maryland
Website
ataber.pw
XP
5,008
Country
United States
Whats it used for?
Theoretically, dumping the boot rom would grant us the last NCCH, which would grant us the ability to fully encrypt and decrypt NANDs.

Also, if there was any vulnerability in the bootloader, it would grant us full system access a lot easier than a9lh.
 

Faru

Well-Known Member
Member
Joined
Nov 13, 2015
Messages
148
Trophies
0
XP
174
Country
United States
Regardless if this is an April Fools joke or not, I'm downloading this shit anyway!

I wonder what we could do with this..
 

Site & Scene News

Popular threads in this forum

eof

General chit-chat
Help Users
    Psionic Roshambo @ Psionic Roshambo: The ST version honestly looks like they at least tried lol