Hacking I bricked a 3DS while trying to inject A9LH FIRM0&1 over B9S FIRM's

  • Thread starter Deleted User
  • Start date
  • Views 3,739
  • Replies 17
D

Deleted User

Guest
OP
Hey, I made a huge fuck-up, since I was able to switch Boot9Strap back to Arm9LoaderHax by restoring a NAND with A9LH just for testing, then restored other NAND with B9S again, works fine.

So I decided to do a quickest way, backup B9S'd firm0.bin and firm1.bin using Decrypt9WIP and renamed to FIRM0_B9S.bin and FIRM1_B9S.bin to not get confused, I also used GodMode9 and mounted a NAND backup that is A9LH and exported both firm's to files9 folder, renamed as frim0_a9lh.bin and frim1_a9lh.bin.

I went back to Decrypt9WIP, did a Partition Inject, selected frim0_a9lh.bin for FIRM0 and frim1_a9lh.bin for FIRM1, both were succeeded. Pressed START to reboot


and boom, black screen. :(

I am unable to load any payloads, .bin or .firm, tried holding SELECT on boot won't open up Luma3DS config for me. http://imgur.com/JjqDQFO

My 3DS is now a useless piece of shit...unless I have a NAND backup which I do. I don't know how to Hardmod some shit.
 
Last edited by ,

Kyousak

Also known as VVSKartell
Member
Joined
Nov 1, 2016
Messages
284
Trophies
0
Location
Tegra X1
XP
471
Country
United States
Luckily for you, all you need to do is to get a hardmod and Sighax your 3ds again

--------------------- MERGED ---------------------------

Or just restore a NAND backup.
Thanks to SigHax you dont even need a NAND Backup. If it was A9LH you would be fcked without a backup
 

N7Kopper

Lest we forget... what Nazi stood for.
Member
Joined
Aug 24, 2014
Messages
975
Trophies
0
Age
30
XP
1,293
Country
United Kingdom
That was smart. I'm going to assume that you forgot that A9LH works by mangling the FIRM0 keys in a very specific way so that they decrypt to garbage that jumps to arbitrary code execution while exploiting the fact that bootrom doesn't clear FIRM0 out of memory before loading FIRM1 if FIRM0 fails for any reason.

Just replacing the files without replicating this specific mangling would, in the best case scenario, remove your hacks.
 
D

Deleted User

Guest
OP
That was smart. I'm going to assume that you forgot that A9LH works by mangling the FIRM0 keys in a very specific way so that they decrypt to garbage that jumps to arbitrary code execution while exploiting the fact that bootrom doesn't clear FIRM0 out of memory before loading FIRM1 if FIRM0 fails for any reason.

Just replacing the files without replicating this specific mangling would, in the best case scenario, remove your hacks.
Damn, I was so dumb, I thought replacing is just simple, then resulted in bootloader getting confused.
 

RHOPKINS13

Geek
Member
Joined
Jan 31, 2009
Messages
1,353
Trophies
2
XP
2,616
Country
United States
Thanks to SigHax you dont even need a NAND Backup. If it was A9LH you would be fcked without a backup

Meh, you still need a NAND Backup. Pretty sure any method of recovery without a NAND backup is going to involve distributing copyrighted code. Perhaps if you have another 3DS you can use the data from that to "legally" fix your bricked 3DS, but I'd say in either case not having a NAND backup is a really bad idea, unless you're only interested in launching homebrew payloads directly from sighax :P
 

I_AM_L_FORCE

Unban me from Discord
Member
Joined
Feb 19, 2015
Messages
1,064
Trophies
0
Age
23
Location
London
XP
1,537
Country
United Kingdom
Meh, you still need a NAND Backup. Pretty sure any method of recovery without a NAND backup is going to involve distributing copyrighted code. Perhaps if you have another 3DS you can use the data from that to "legally" fix your bricked 3DS, but I'd say in either case not having a NAND backup is a really bad idea, unless you're only interested in launching homebrew payloads directly from sighax :P
All he'd need are Sighaxed firms and perhaps a CTRnand transfer, both publicly available.
 

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,252
Trophies
4
Location
Space
XP
13,805
Country
Norway
Meh, you still need a NAND Backup. Pretty sure any method of recovery without a NAND backup is going to involve distributing copyrighted code. Perhaps if you have another 3DS you can use the data from that to "legally" fix your bricked 3DS, but I'd say in either case not having a NAND backup is a really bad idea, unless you're only interested in launching homebrew payloads directly from sighax :P
He should be able to just reinstall b9s again with a hardmod, no NAND backup needed.
 
  • Like
Reactions: Kyousak

RHOPKINS13

Geek
Member
Joined
Jan 31, 2009
Messages
1,353
Trophies
2
XP
2,616
Country
United States
All he'd need are Sighaxed firms and perhaps a CTRnand transfer, both publicly available.

Said CTRNANDs contain copyrighted Nintendo code. It may be "publicly available" mainly via torrent, but it still can be considered piracy.

He should be able to just reinstall b9s again with a hardmod, no NAND backup needed.

As far as I know, he'd also have to remove A9LH. In this case, perhaps it is possible for him to recover without a backup. But if something corrupts his NAND and he needs to use a CTRNAND, that's piracy.

And can we all agree that even if recovery without a NAND backup is possible, not having one is still a bad idea, especially if you have data you want to make sure you don't lose?
 

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,252
Trophies
4
Location
Space
XP
13,805
Country
Norway
Said CTRNANDs contain copyrighted Nintendo code. It may be "publicly available" mainly via torrent, but it still can be considered piracy.



As far as I know, he'd also have to remove A9LH. In this case, perhaps it is possible for him to recover without a backup. But if something corrupts his NAND and he needs to use a CTRNAND, that's piracy.

And can we all agree that even if recovery without a NAND backup is possible, not having one is still a bad idea, especially if you have data you want to make sure you don't lose?
B9S overwrites A9LH, so that's not a problem.
AFAIK the reason he bricked is the secret_sector.bin is not overwritten with the A9LH one. It's possible it could be unbricked by just flashing the A9LH secret_sector.bin as well but it's easier to flash B9S.
 
D

Deleted User

Guest
OP
AFAIK the reason he bricked is the secret_sector.bin is not overwritten with the A9LH one. It's possible it could be unbricked by just flashing the A9LH secret_sector.bin as well but it's easier to flash B9S.
Geeeez... you're right. I forgot to include that file, even NAND header >_<
I didn't have a chance to dump it, so I'm outta luck.
 
Last edited by ,
D

Deleted User

Guest
OP
Bad news, I attempted to hardmod it with my dad, and it is completely fucked up now :( DiskImager won't show up Drive Letter for 3DS, too much burn on NAND pinout/spot from soldering pen.

NUO20vO.jpg

EsIlk70.jpg

and video
 
Last edited by ,

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    K3Nv2 @ K3Nv2: https://youtu.be/IihvJBjUpNE?si=CsvoEbwzNKFf0GAm cool