Homebrew WiFiPWN research

I_AM_L_FORCE

Unban me from Discord
OP
Member
Joined
Feb 19, 2015
Messages
1,064
Trophies
0
Age
23
Location
London
XP
1,537
Country
United Kingdom
So.
It has been known for a while now that the DS WiFi settings .app file can be replaced with an exploitable DSiware game, and can then be launched through system settings.

In the wake of Slow/Fasthax being released we have gained Kernel access on arm11, which has led to people being able to install DSiware saves, legit CIAs ect.

What we do not know is if it is possible to access the TWLN partition of the NAND through just arm11 Kernel access, if it is in fact possible we can overwrite DS WiFi settings with say fieldrunners or sudoku, and then run the downgrade.

Thoughts, anyone?
 

iAqua

Member
Joined
Dec 7, 2015
Messages
2,848
Trophies
1
Location
XP
2,476
Country
United Kingdom
So.
It has been known for a while now that the DS WiFi settings .app file can be replaced with an exploitable DSiware game, and can then be launched through system settings.

In the wake of Slow/Fasthax being released we have gained Kernel access on arm11, which has led to people being able to install DSiware saves, legit CIAs ect.

What we do not know is if it is possible to access the TWLN partition of the NAND through just arm11 Kernel access, if it is in fact possible we can overwrite DS WiFi settings with say fieldrunners or sudoku, and then run the downgrade.

Thoughts, anyone?
Might be possible, I'll look into it.
don't expect any implementations from me if anything exists.
 
Last edited by iAqua,

I_AM_L_FORCE

Unban me from Discord
OP
Member
Joined
Feb 19, 2015
Messages
1,064
Trophies
0
Age
23
Location
London
XP
1,537
Country
United Kingdom
If that's the case, couldn't we exploit any DSiWare, the same way the current transfer method does?
Very true.

--------------------- MERGED ---------------------------

Then the only other way to use DS WiFi settings is to find an actual crash/bug in the app itself?
 

Yepi69

Jill-sandwiched
Member
Joined
Nov 29, 2010
Messages
2,862
Trophies
2
Age
28
Location
Behind you
XP
1,776
Country
Portugal
I have a friend's 11.2 o3DSXL right here using the newly uploaded soundhax entrypoint, would love to see this work.
Nintendo from Europe has removed the exploitable DSiWare games needed to downgrade the damn thing.
 
  • Like
Reactions: Kvnrdrguez

Mrrraou

Well-Known Member
Member
Joined
Oct 17, 2015
Messages
1,873
Trophies
0
XP
2,374
Country
France
TWLN cannot be accessed from ARM11 without the signed exheader of an app that has access to it, afaik. And no retail apps have access to this (mostly for security reasons), to my knowledge.

You should document yourself more before making threads like this.
 
  • Like
Reactions: Kvnrdrguez

proflayton123

The Temp Loaf'
Member
Joined
Jan 11, 2016
Messages
6,032
Trophies
1
Age
24
Location
日本
Website
www.facebook.com
XP
3,211
Country
Japan
TWLN cannot be accessed from ARM11 without the signed exheader of an app that has access to it, afaik. And no retail apps have access to this (mostly for security reasons), to my knowledge.

You should document yourself more before making threads like this.


If its possible open NAND TWL FS writable, while being able to acces the title folders through https://www.3dbrew.org/wiki/Filesystem_services#Archives,
it could be possible to do, what we did manualy in this tutorial from arm11:
https://gbatemp.net/threads/tutorial-new-installing-sudokuhax-on-3ds-4-x-9-2.388621/

Refer to the above :)
 

I_AM_L_FORCE

Unban me from Discord
OP
Member
Joined
Feb 19, 2015
Messages
1,064
Trophies
0
Age
23
Location
London
XP
1,537
Country
United Kingdom
TWLN cannot be accessed from ARM11 without the signed exheader of an app that has access to it, afaik. And no retail apps have access to this (mostly for security reasons), to my knowledge.

You should document yourself more before making threads like this.
What about system settings, or DS download play for that matter, don't they both access TWLN?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    The Real Jdbye @ The Real Jdbye: sure, it can be hands free