Homebrew nds-constrain't - Taking advantage of a flaw in the Nintendo DS(i) SSL library

Ericthegreat

Not New Member
Member
Joined
Nov 8, 2008
Messages
3,455
Trophies
2
Location
Vana'diel
XP
4,298
Country
United States
I'm not familiar with those hacks, never cared for spotpass.

The reason why MAC address filtering is not recommended as a security measure is because they can be sniffed and spoofed.

I wasn't talking WEP vs MAC but, again, in general and in the context of open wifi.
Time to get tendonitis with MKDS.
 
  • Like
Reactions: Kioku and Zense

KazoWAR

Well-Known Member
Member
Joined
Aug 12, 2008
Messages
1,952
Trophies
1
Age
35
Location
Winter Haven
XP
2,134
Country
United States
Right but it doesnt need any devices to set a DNS? Am I missing something? The other methods only require you to set a DNS Too
You can set a DNS, and try to connect to a custom server, but the game will refuse it since its uses SSL. you need to patch the game to remove SSL. This tricks the game into accepting the SSL connection even though its not official server.
 
  • Like
Reactions: Tarmfot and PRAGMA

barronwaffles

Well-Known Member
Member
Joined
May 15, 2014
Messages
344
Trophies
0
XP
1,150
Country
Syria
Right but it doesnt need any devices to set a DNS? Am I missing something? The other methods only require you to set a DNS Too

The previous methods also required either a cheat device or flash cart, this exploit removed that requirement.

No game supports WPA. I do believe there are mobile hotspot applications that allow you to make a WEP connection (same with PC versions)

DSi titles and the few DSi-enhanced DS games support WPA.

As for the rest of the post - the majority of 'guest' networks are isolated, protecting the rest of your network from intrusion.
If you're capable of configuring the network further then rate limiting and reducing the radio power level to something suitable is advisable.
 
  • Like
Reactions: Zense

Kwyjor

Well-Known Member
Member
Joined
May 23, 2018
Messages
4,323
Trophies
1
XP
4,466
Country
Canada
I suppose this means the old Pokemon GTS (the one that could give you any arbitrary Pokemon just by connecting) will be up and running again too.

A silly question, but someone's bound to ask: are we next going to see a DSi eshop that will allow installation of software to an unmodified DSi? Or would that be too nuts?
 

PRAGMA

Well-Known Member
Member
Joined
Dec 29, 2015
Messages
2,258
Trophies
1
Location
Ireland
Website
github.com
XP
5,039
Country
Ireland
Well god damn, it worked (Using an Emulator):
https://streamable.com/5w0zh
(Theres me connecting - it takes a good 2 minutes, i timed it)

a8AEuzJ.png


Not kicking me out of Mystery Gift! :O The server owner should make us all a free mystery gift (not anything too powerful, maybe the Shaymin ticket for D/P/Pt since we never officially got it yet we were meant to, would be AMAZING)

WAIT WHAT THE FUCK!

https://streamable.com/8bwd8
v7EJgua.png

Took again about a minute, but it WORKED!!!!
HOLY DARN

!!!!!!!!!
https://streamable.com/h2ngu
kxQSeiv.png


3gHC2XF.png


TUTORIAL:
https://gbatemp.net/threads/how-to-...cation-original-hardware-and-emulator.522676/
 
Last edited by PRAGMA,

seseiSeki

Well-Known Member
Member
Joined
Sep 26, 2016
Messages
208
Trophies
0
Age
27
XP
2,269
Country
Germany
I recently discovered Final Fantasy Crystal Chronicles - Echoes of Time. I can't wait to play it with my friends.
One question though. Does this work on the Wii too? I think Final Fantasy Crystal Chronicles - Echoes of Time is probably the only game that supports cross play between Wii and DS.
 
  • Like
Reactions: Tarmfot and Kioku

Zense

Well-Known Member
Member
Joined
Apr 20, 2008
Messages
1,977
Trophies
2
XP
4,322
Country
Italy
I recently discovered Final Fantasy Crystal Chronicles - Echoes of Time. I can't wait to play it with my friends.
One question though. Does this work on the Wii too? I think Final Fantasy Crystal Chronicles - Echoes of Time is probably the only game that supports cross play between Wii and DS.
I actually finished that whole game through the alt-wfc servers on DS without any problems. Did it 2-player though. Don't know if any more players would lead to problems.
 
Last edited by Zense,

Cyan

GBATemp's lurking knight
Former Staff
Joined
Oct 27, 2002
Messages
23,749
Trophies
4
Age
46
Location
Engine room, learning
XP
15,662
Country
France
Are the Wii, WiiU and Switch vulnerable too ?
are their CA flag to allow intermediate cert set to true or false ?

How dangerous it can be for people using a DNS to filter nintendo's url if the server can chain-crypt (and therefore decrypt, right?) the transmitted SSL data? the DNS server acts as MITM?
 

Larsenv

Dr. Wii, Ph.D
Member
Joined
Sep 28, 2013
Messages
872
Trophies
2
Website
larsenv.xyz
XP
3,313
Country
United States
Are the Wii, WiiU and Switch vulnerable too ?
are their CA flag to allow intermediate cert set to true or false ?

How dangerous it can be for people using a DNS to filter nintendo's url if the server can chain-crypt (and therefore decrypt, right?) the transmitted SSL data? the DNS server acts as MITM?

No, they are not vulnerable. Nor is 3DS.
 
Last edited by Larsenv,
  • Like
Reactions: banjo2 and Cyan

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,351
Trophies
4
Location
Space
XP
13,939
Country
Norway
Some modern routers fix some of the wep exploits, so it goes back to being really slow to hack.

If your router supports guest mode then it's pretty safe to use wep and manually change your key regularly.

You may be able to come up with firewall rules so that even if someone does hack your key, then all they could use it for is playing ds games.
I would just suggest to isolate the guest network from the rest of the network, and to turn it off whenever it's not in use. Obviously use MAC address filtering as well. A lot of routers won't even let you set WEP these days though leaving the only option an open network. Not that it makes a whole lot of difference if all you're using it for is WFC. Anyone that wants to get in will get in either way, it'll just take them longer if it's WEP. Changing MAC address is a 2 second job and can be done on most devices, even smartphones.
No, they are not vulnerable. Nor is 3DS.

Also, please try our DNS if you want, it works pretty well: 164.132.44.106
What's different about WFC on the Wii that makes it not vulnerable? Just different SSL code on the Wii side?
 
Last edited by The Real Jdbye,

MarKSlasH

Active Member
Newcomer
Joined
Jun 24, 2009
Messages
27
Trophies
1
XP
1,051
Country
Brazil
I recently discovered Final Fantasy Crystal Chronicles - Echoes of Time. I can't wait to play it with my friends.
One question though. Does this work on the Wii too? I think Final Fantasy Crystal Chronicles - Echoes of Time is probably the only game that supports cross play between Wii and DS.

It is actually possible to play between DS and Wii version of the game over Wiimmfi.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Psionic Roshambo @ Psionic Roshambo: Lol