Hacking [PSA]Verify ALL .nsp and .xci files regardless of where they come from, even homebrew

sj33

Well-Known Member
OP
Member
Joined
Oct 22, 2013
Messages
4,072
Trophies
2
XP
4,728
Country
Japan
It seems that this needs to be emphasised now more than ever. The current .nsp installers do NOT verify if what you are installing contains malicious code. Hopefully they will eventually, but at this point people have to take it into their own hands.

Some people see it at a simple matter of common sense, but it is not that simple. It doesn't matter if it is a pirated game or homebrew, a reliable source or a shady site - installing an .nsp file without verifying it is folly, regardless of who made it. Brickers are designed to look legitimate to the untrained eye, otherwise they would not be effective.

People MUST do the following.

1. Verify any .nsp file they install using Hactool https://gbatemp.net/threads/release-hactoolgui-a-very-simple-gui-for-hactool.499526/

2
. Make a backup of your CURRENT firmware using hekate. You only need to back up the boot0/1 and SYS partitions and you should be able to compress this to around 1GB or so. Store it on your computer and a cloud service such as Google Drive just in case.
 

Tripa

Member
Newcomer
Joined
Nov 3, 2018
Messages
15
Trophies
0
Age
44
XP
156
Country
Brazil
How can Hactool verify malicious code?
Idk if that's possible...
Backups however are an absolute must.
And people must be triple aware when Smash launches bc the internet will be flooded with malwares.
Anyways, LGP malware could be easily fixed with a backup.
But without, it's a hard brick.
 

sj33

Well-Known Member
OP
Member
Joined
Oct 22, 2013
Messages
4,072
Trophies
2
XP
4,728
Country
Japan
It’s not that hactool will detect malicious code, it will simply show more details about the file to give a better idea of its origin. It’s not a foolproof way, make s bsckup too.
 

Frexxos

Well-Known Member
Member
Joined
Apr 27, 2015
Messages
428
Trophies
0
Age
43
XP
2,483
Country
Germany
... But for now its best grabbing a scene release. Check MD5 matches to source file & who the uploader is.

That wat some jerks did... they named the game like a official scene release, the game was also the right size (not md5 checked) only in windows shown. Of course everyone thought "hey a nice leak" and boom - bricked!

Never go for first release/leak/link to something. Wait if someone can confirm. Check who is the uploader? How many uploads does he have? someone with only 1-2 posts is probably a faker.
 
  • Like
Reactions: proffk

Arras

Well-Known Member
Member
Joined
Sep 14, 2010
Messages
6,318
Trophies
2
XP
5,421
Country
Netherlands
For homebrew, is checking even effective? Someone could just take an open source homebrew, add brick code to it, recompile and it would be indistinguishable from a real one.
 

fixingmytoys

Well-Known Member
Member
Joined
Jan 4, 2018
Messages
536
Trophies
0
XP
884
Country
Australia
I wish the “backup” was dumped on the USB hard drive that would make it so much easer then have to clear and setup a big enough SD CARD
 

IHOP

Well-Known Member
Member
Joined
Jul 11, 2018
Messages
133
Trophies
0
Age
25
XP
586
Country
United States
As a warning, the current "leak" of Super smash Bros Ultimate is brickware
Obviously any game "leaked" a month before release is going to be brickware. Use common sense, if you think you're the first one to find a leaked copy of a game on some fourm, chances are if it was real everyone would be talking about it/ be playing it.
 

noahc3

Well-Known Member
Member
Joined
Oct 17, 2015
Messages
123
Trophies
0
XP
1,288
Country
Canada
How can Hactool verify malicious code?
Idk if that's possible...
Backups however are an absolute must.
And people must be triple aware when Smash launches bc the internet will be flooded with malwares.
Anyways, LGP malware could be easily fixed with a backup.
But without, it's a hard brick.

It checks if the NCA's are signed correctly. If they are signed correctly, then they are official from Nintendo. Otherwise, they have been modified.

Even XCI's converted to NSP's and visa-versa should verify correctly with hactool afaik, but will fail if any of the NCA's are modified and resigned with an unofficial key.
 

Ashura66

Well-Known Member
Member
Joined
Feb 1, 2016
Messages
1,768
Trophies
0
Age
37
Location
Under my bed
XP
1,687
Country
Portugal
Obviously any game "leaked" a month before release is going to be brickware. Use common sense, if you think you're the first one to find a leaked copy of a game on some fourm, chances are if it was real everyone would be talking about it/ be playing it.

That's not always the case, early leaks DO happen, at least for PC games. Not with so much time in advance granted but they still happen. And the only reason i mentioned it is because i know some people lack common sense so might as well warn them. Also this particular brickware, i have NO idea why it was made, other than just for kicks. The Pikachu one had a specific purpose
 

NoSmokingBandit

Well-Known Member
Member
Joined
Jan 17, 2009
Messages
451
Trophies
0
XP
648
Country
United States
Bro its like finding a sandwhich on the bathroom floor, eating it, then thinking you did nothing wrong when you die of dehydration via cholera. I'm not trying to victim-blame here, but at a certain point you have to be responsible for the risks you take, and if one of those risks is downloading 'modified' homebrew by some script kiddie named "xXxDarkLordSatanxXx" off discord you probably need to learn a lesson the hard way.
 

GTRagnarok

Member
Newcomer
Joined
Apr 21, 2009
Messages
21
Trophies
1
XP
1,771
Country
United States
I followed a guide when I got started a few months ago and dumped these files. It comes to 2.62 GB in total and the two boot files are 4MB each. Is this a sufficient backup or do I need the whole rawnand.bin?
l3tgenH.png
 
Last edited by GTRagnarok,

jeverden

Member
Newcomer
Joined
Nov 19, 2018
Messages
8
Trophies
0
Age
39
XP
89
Country
United States
Do you use the -y option? I'm getting Invalid NCA Header! Are keys correct? Grabbing some from torrents and want to make sure they are clean. Is their a risk if I install NSP files to an SD card only?
 

jeverden

Member
Newcomer
Joined
Nov 19, 2018
Messages
8
Trophies
0
Age
39
XP
89
Country
United States
Is there a list of checksums for NSP files that can be compared? I can't get hactool to work for the life of me. I know I've dumped keys correctly but I presume from this error it's related to keys dumped. As far as I can tell CDN downloader doesn't work anymore or I would risk a ban using my own keys? I could probably live with a ban if it wasn't 100% guaranteed if I just grabbed a few files.
 

Ian095

Well-Known Member
Member
Joined
Jun 25, 2018
Messages
381
Trophies
0
XP
839
Country
United Kingdom
I'd just recommend to anyone attempting to install Smash Bros in two weeks... Backup first. I don't know how I've always managed to avoid brick code guess I can count myself lucky but as said somewhere above there's going to be absolutely tons of fake Smash Bros NSPs no doubt.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    NinStar @ NinStar: CRAZY HAMBURGER