Homebrew safefirmraunchhax - new Arm9 exploit discussion

Does the exploit work for you?


  • Total voters
    48

Olmectron

Well-Known Member
Member
Joined
Dec 31, 2012
Messages
2,657
Trophies
2
Age
31
Location
A game
XP
3,855
Country
Mexico
So is it is a useable release or a PoC?
Needs Fasthax to work on 11.2 first.

Once Fasthax is working on stable release, this will be able to be compiled to gain ARM9 access.

For now, this means you could use Decrypt9 on 11.2 to CTRNAND Transfer 2.1, then install A9LH from there. No need to downgrade to 9.2 anymore. As soon as fasthax stable is working and this gets compiled with it.
 
Last edited by Olmectron,

imRed

Well-Known Member
Newcomer
Joined
Sep 1, 2016
Messages
47
Trophies
0
Age
34
XP
80
Country
Netherlands
Doesnt waithax (slowhax, w/e) get the same privilages on 11.0 and 11.1? Why wait for fasthax then?
 

WaterBotttle

Well-Known Member
Member
Joined
Dec 19, 2014
Messages
163
Trophies
0
Age
34
XP
307
Country
I could be wrong here as I have not reviewed firmlaunch-hax implementations much, but I believe MiniPasta (or just Brahma) gives us a very good starting point, as most of it is already implemented. What would need to be done is: (1) Swap in fasthax, (2) modify firm_reboot() as needed (sync, SAFE_FIRM launch), (3) replace payload... I think thats it?
Yes that's pretty much correct. Firmlaunchhax is the arm9 exploit people use in 9.2, but you need K11 access to patch some K11 function calls (I believe this is for the hooks)
https://yifan.lu/2015/01/17/reversing-gateway-ultra-stage-3-owning-arm9-kernel/

(Incase people didn't know)
There is another version of the firmware called SAFE_MODE_FIRM that is used by the system updater where firmlaunchhax has not been patched. We also need K11 access to boot into this mode (I assume). So the idea is too boot into this firmware run Firmlaunchhax then downgrade using the K9 access we now have to 2.1 and install A9LH.
 

Eastonator12

Well-Known Member
Member
Joined
Aug 16, 2016
Messages
630
Trophies
0
Age
23
XP
999
Country
United States
interesting if it works.
It's not hard to build this stuff. Quick tutorial: Download and install DevKitPro. Go on the github project you'd like to build. There should be a Download button on the right, click it, put it on your desktop. Open the file you downloaded, should be a makefile in it, along with other folders. Now, shift-click in the folder, and click "open command window here". Then just type "make" in cmd (no quotes). If all went well, the file it made should be in the root of the folder you ran the command in. Please let me know if I'm wrong
 
  • Like
Reactions: Skyshadow101

Zan'

2F88744FEED717856386400A44BBA4B9CA62E76A32C715D4F
Member
Joined
Oct 8, 2015
Messages
387
Trophies
0
Age
32
XP
271
Country
Just trying to understand this, lol.

I'm a bit confused as to when this is supposed to be done. I assume that this is done after we get control from the function hooked at 0xFFF84D90? Here's what I'm reading.



After it's installed then yes, the OTP lock wouldn't have been set. However, you can't write it without arm9 access in the first place. You're left with a chicken-egg problem.
Correct.
SigHax it not something that let's you install anything or sign anything. It's simply a precisely malformed signature that exploits the bad verification of the BootROM to have a valid checkout on anything signed with this "sighax" signature.
You will need to create a firm with this signature and write it to the FIRM0, which you need Arm9 Access to.
SigHax would make the 9.2 -> 2.1 downgrade unnecessary, since 9.2 had Arm9 access and with that you can install SigHax FIRM. (And then gain otp just for the fun).
11.2 etc. only have Arm11 Access (currently) which is not enough to get a SigHax FIRM installed.

To get cfw without downgrading from 11.2 you'd need a Userland entrypoint (Soundhax/Any HBL entrypoint), then get Arm11 Access (Fasthax/Waithax) and follow this up by a way to gain Arm9 Access (safefirmlaunchhax).
Now use the Arm9 Access to install the SigHax FIRM and gain cfw boot from BootROM.
(Alternate would be OTPLess A9LH Install for N3DS or 2.1 CTRInject method to aquire OTP and install A9LH)
 
Last edited by Zan',
  • Like
Reactions: Earth97

TheOverseer

Well-Known Member
Newcomer
Joined
Sep 23, 2016
Messages
59
Trophies
0
Age
30
XP
153
Country
United States
Not sure who feels the wait for 40 minutes on a O3DS for a possible brick :)

Hm. I mean...it kind of depends on who has hardmods, technically.

But the possible brick shouldn't be a deterrent to people who would test it with fasthax, right? Considering a brick would still brick on fasthax...

I do get the waiting issue though. Uggu. I'd test it myself, but I can't, because firmpatched Luma A9LH will act as if it had ARM9 anyway...right?
 

proflayton123

The Temp Loaf'
Member
Joined
Jan 11, 2016
Messages
6,032
Trophies
1
Age
24
Location
日本
Website
www.facebook.com
XP
3,235
Country
Japan
Hm. I mean...it kind of depends on who has hardmods, technically.

But the possible brick shouldn't be a deterrent to people who would test it with fasthax, right? Considering a brick would still brick on fasthax...

I do get the waiting issue though. Uggu. I'd test it myself, but I can't, because firmpatched Luma A9LH will act as if it had ARM9 anyway...right?

Fasthax is more viable (tomorrow onwards) this is a start though
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Xdqwerty @ Xdqwerty:
    sigh
  • Xdqwerty @ Xdqwerty:
    @a_username_that_isnt_cool, could you change your username?
  • Xdqwerty @ Xdqwerty:
    i guess not...
  • Xdqwerty @ Xdqwerty:
    yawn
  • Xdqwerty @ Xdqwerty:
    anybody here?
  • P @ PKNate:
    nope
  • BakerMan @ BakerMan:
    fun fact: 7 years by lukas graham, supermassive black hole by muse, and megalomania all have the same bpm
  • BakerMan @ BakerMan:
    girls just wanna have fun and renai circulation also share the same tempo as the few i said before
  • Xdqwerty @ Xdqwerty:
    @BakerMan, megalomania the live a live song?
  • BakerMan @ BakerMan:
    wait no, megalovania*
  • BakerMan @ BakerMan:
    my bad
  • K3Nv2 @ K3Nv2:
    I don't forgive you
  • BigOnYa @ BigOnYa:
    The nerve of that guy, gosh.
  • K3Nv2 @ K3Nv2:
    Yeah expecting me to forgive gtfo
  • Psionic Roshambo @ Psionic Roshambo:
    But how could the Dr have known you didn't want to be circumcized?
  • K3Nv2 @ K3Nv2:
    He didn't you just wanted your dick to be fondled
    +1
  • K3Nv2 @ K3Nv2:
    Watching dune 2 it's eh
  • Psionic Roshambo @ Psionic Roshambo:
    Dune one sucked
  • Psionic Roshambo @ Psionic Roshambo:
    The original with Patrick Stewart was Great
  • K3Nv2 @ K3Nv2:
    A sexual psycopath that love pain where have I heard that before
  • BigOnYa @ BigOnYa:
    In your high school diary?
  • K3Nv2 @ K3Nv2:
    No but your wife let's me read her diary the word psychopath comes up more than sexual
    +1
    K3Nv2 @ K3Nv2: No but your wife let's me read her diary the word psychopath comes up more than sexual +1