Hacking 3DS update process analyzed

Status
Not open for further replies.

OuHiroshi

Member
Newcomer
Joined
Mar 27, 2011
Messages
15
Trophies
0
XP
121
Country
United States
xdixonx said:
WiiBricker said:
We need the 3DS common key.

Well if we know what we're looking for it's a start I guess... worst case scenario is that the key takes years to find, much like the ps3.

The first software exploit on the Wii was a stack overflow on the horse name in Zelda. So let's hope there will be something like that on the 3DS.
 

Nollog

Well-Known Member
Member
Joined
Oct 10, 2008
Messages
2,964
Trophies
0
XP
1,327
Country
Ireland
Cyan said:
save files are un-transfearable.
You can't even copy a save to another SD card and use it on your own 3DS.
You also can't make backups of your savefile to restore later, the console keeps tracks of the last used time of every files, so no possibility to overwrite it with another (older or newer) save file.
You have to share the entire "Nintendo 3ds" folder to make sharing save game possible, but I think the saves are locked to the console.
3DS Transfer will allow this in May.
 

MakiManPR

Banned!
Banned
Joined
Apr 6, 2010
Messages
989
Trophies
0
XP
177
Country
This thread is really interesting
I have a question Have you used any flashcart to see if the 3DS send something extra or something different to Nintendo and/or viceversa
 

Schlupi

Gbatemp's Official Earthbound Maniac™
Member
Joined
Aug 31, 2007
Messages
3,985
Trophies
0
Age
32
Location
Rozen Queen Co, Chicago Branch
Website
Starmen.net
XP
735
Country
United States
Why is it that EVERYTIME I try to update it, it stays at the "Updating..." screen without progress in the bar? I turned it off fearing to brick it (I lost a PSP Go to the FW updating related brick) and it worked fine after, but I hope I can update it without this happening every damn time.

My connections is great, it's not the problem (WEP, and SFIV3D works perfectly laggless playing hundreds of matches) can anybody tell me what the issue is? There is a launch day USA update right?

Anybody have a solution/comment on this?
 

MakiManPR

Banned!
Banned
Joined
Apr 6, 2010
Messages
989
Trophies
0
XP
177
Country
Maybe is yours cuz I updated successfully with the progress bar, I guess it still have the store warranty if so take it there
 

Schlupi

Gbatemp's Official Earthbound Maniac™
Member
Joined
Aug 31, 2007
Messages
3,985
Trophies
0
Age
32
Location
Rozen Queen Co, Chicago Branch
Website
Starmen.net
XP
735
Country
United States
MakiManPR said:
Maybe is yours cuz I updated successfully with the progress bar, I guess it still have the store warranty if so take it there

I tried it again just now, and it worked fine. >:(

I guess there was just s server issue/overload or something.

I now have my Ok Go video.
biggrin.gif


I was happy to see some of the cheesy "Pop out at you" effect, to be honest. When the dog came at the screen I was a little startled lol. Playing Street Fighter does not give any of that lol.
 
D

Deleted User

Guest
Schlupi said:
Why is it that EVERYTIME I try to update it, it stays at the "Updating..." screen without progress in the bar? I turned it off fearing to brick it (I lost a PSP Go to the FW updating related brick) and it worked fine after, but I hope I can update it without this happening every damn time.

My connections is great, it's not the problem (WEP, and SFIV3D works perfectly laggless playing hundreds of matches) can anybody tell me what the issue is? There is a launch day USA update right?

Anybody have a solution/comment on this?
Well, I had this problem too but I just left it for a while, and it worked. It took ages and was stuck without progress but randomly it did "progress", I'd say after about... 10 minutes on my PAL 3DS.

It's ridiculous really.
 

notmeanymore

Well-Known Member
Member
Joined
Nov 29, 2009
Messages
2,700
Trophies
1
XP
711
Country
United States
Schlupi said:
Why is it that EVERYTIME I try to update it, it stays at the "Updating..." screen without progress in the bar? I turned it off fearing to brick it (I lost a PSP Go to the FW updating related brick) and it worked fine after, but I hope I can update it without this happening every damn time.

My connections is great, it's not the problem (WEP, and SFIV3D works perfectly laggless playing hundreds of matches) can anybody tell me what the issue is? There is a launch day USA update right?

Anybody have a solution/comment on this?
It took me a solid 5 minutes to update. How long did you wait, like 30 seconds? lol
 

Knyaz Vladimir

3DS Hacker
Member
Joined
Apr 18, 2009
Messages
556
Trophies
0
Age
28
Location
Unconfirmed
Website
Visit site
XP
78
Country
Canada
Cyan said:
1 - I don't think there are UserID data in the file. I think it's only encrypted with my own public key, so it will work and be decrypted only on my console.

That makes sense in many ways for Nintendo's anti-piracy policy. They'd want you to be able to play only games that are for your own console, and until we find a way to make the system recognize any savefile, we're kind of stuck. If custom channels existed on the 3DS, you couldn't do shite, because they'd have patched bannerbomb early on.

2 - Even the video is encrypted. There's no significant pattern (video, multiple jpeg or audio). the file header is ...G>[email protected].>.3, and is different for every files.

No shit. The video is 3D, it's obviously encrypted in a different manner. Why would people think otherwise is beyond me. If we can get a second video dump and analyze the two together, we might figure out something from this. Too bad, I don't have a 3DS.

3 - They have a lot of space now, I don't remember exactly but I think it's 1.5GB.

Around so, I can't answer for sure.

My comments to the statement way above is in the quote. And in bold. Amazing.

Anyway, time for irony- the first two exploits we find is Link's name in OoT (because Nintendo fixed Epona's name, but broke Link's in return, bad Ninty!) and the Star Wars exploit that I'm too lazy to research and make a witty comment about.

That's my statement, I'll go drink my tea before being horribly mutilated by a doctor because I'm getting surgery done. And I'm without a laptop.
 

ichichfly

Well-Known Member
Member
Joined
Sep 23, 2009
Messages
619
Trophies
1
XP
1,075
Country
Gambia, The
pachura said:
1. You're writing that "you've dumped the files, but can't share them". So you do have them on your computer ? Are you afraid that publishing these files would somehow reveal your UserID or something ?

lol download it yourself http://nus.cdn.c.shop.nintendowifi.net/ccs...025000/00000000

they are encrypted so don't expect that you can see anything

ADD: you may can use this to only update a part of your 3DS

ADD2: mutch spam in here lol so i make some more spam

ADD3: the file is also on the DSi update/DSiware server why?

ADD4: i also get a connection to nppl.c.app.nintendowifi.net:443 (pingable) as well as nasc.nintendowifi.net:443 (not pingabel) and some 2 to .a248.e.akamai.net:443
 

Knyaz Vladimir

3DS Hacker
Member
Joined
Apr 18, 2009
Messages
556
Trophies
0
Age
28
Location
Unconfirmed
Website
Visit site
XP
78
Country
Canada
ichichfly said:
pachura said:
1. You're writing that "you've dumped the files, but can't share them". So you do have them on your computer ? Are you afraid that publishing these files would somehow reveal your UserID or something ?

lol download it yourself http://nus.cdn.c.shop.nintendowifi.net/ccs...025000/00000000

they are encrypted so don't expect that you can see anything

ADD: you may can use this to only update a part of your 3DS

ADD2: mutch spam in here lol so i make some more spam

ADD3: the file is also on the DSi update/DSiware server why?

ADD4: i also get a connection to nppl.c.app.nintendowifi.net:443 (pingable) as well as nasc.nintendowifi.net:443 (not pingabel) and some 2 to .a248.e.akamai.net:443

How do you find this stuff?

Looking at it through a hex editor, I can't see a way to decode it as of yet. It's interesting, to say the least. Using Translhextion for HEX editing.

EDIT1: What I truly know:
File name and path: D :\*****\3DS HACKING0000000
File size: 15763968 bytes = 15394 kilobytes.

Number of hexdump lines: 788199.

EDIT2: Reading it through OEM, I see a lot of DE bytes. But I doubt that it's the encoding.

EDIT3: Seached for said string, not found. Searched for G>. and found the HEX offset 0x27C0, 0xA6A0, 0x2A995, and so on because I'm only 3% in the file. Still no luck. Anyone else want to help out?
 

Thulinma

Computer Magician
Developer
Joined
Nov 24, 2005
Messages
122
Trophies
1
Age
36
Location
Leiden, The Netherlands
Website
www.thulinma.com
XP
543
Country
Netherlands
Knyaz Vladimir said:
No shit. The video is 3D, it's obviously encrypted in a different manner. Why would people think otherwise is beyond me. If we can get a second video dump and analyze the two together, we might figure out something from this. Too bad, I don't have a 3DS.

Normally I am quite quiet on these forums, but I couldn't resist writing a response to this blatant ignorance:
Video is not encrypted but encoded. 3D video is encoded exactly the same way 2D video is, so you would indeed be able to see a "normal" video header if the content were sent plain. Obviously the 3DS uses the same method of getting files from the Nintendo servers as the DSi and Wii do (after all, why would you change a working system) - and files are sent encrypted to the system. So, what you have here is an encrypted file, containing "standard" encoded video. Just because it's 3D doesn't mean it is magic and needs special encryption or whatever. Decrypting all this will be trivial once the common key is found (and it will be found, it is after all stored in every 3DS system for decrypting this stuff) since the tools for it already exist and the process is well documented. However, decrypting this stuff will not be very useful. You still need the private key to make anything the 3DS would accept, and chances are this key will never be found. It wasn't ever found for the Wii, after all. We didn't end up needing it, though, and we probably won't need it for the 3DS either.


On a different note - I do wonder what 3D video standard (side by side? over and under? two streams? alternating frames? etc) and format (MKV? AVI? MP4?) Nintendo decided to use. I can't wait to convert my collection of 3D movies for proper watching on 3DS :-)
 

Knyaz Vladimir

3DS Hacker
Member
Joined
Apr 18, 2009
Messages
556
Trophies
0
Age
28
Location
Unconfirmed
Website
Visit site
XP
78
Country
Canada
Aw, crap- I meant 3D video is encoded a different way. I'm not sure how the 3DS works, but there are many ways on how it runs. It's encypted specially for 3DS, not because of it being 3D. Sorry for any misunderstandings, English is my third language.

Also, as a side note- I think the video is 800x240 and... I'm not sure what video format it is. If we can transfer a video saved by the 3DS onto a SD Card (maybe in May), then we'll get somewhere.
 

ichichfly

Well-Known Member
Member
Joined
Sep 23, 2009
Messages
619
Trophies
1
XP
1,075
Country
Gambia, The
Knyaz Vladimir said:
If we can transfer a video saved by the 3DS onto a SD Card (maybe in May), then we'll get somewhere.

I don`t think so because i think nintendo will encrypt them,too.


I think we need the SD-Key not the common key.

ADD: The QR Code for mii are not encrypted and can be readed easy by the PC have fun.
 

Nollog

Well-Known Member
Member
Joined
Oct 10, 2008
Messages
2,964
Trophies
0
XP
1,327
Country
Ireland
ichichfly said:
some 2 to .a248.e.akamai.net:443
The Akamai
HD Network
A revolutionary new approach to delivering HD video online that offers unmatched scale, quality and a highly interactive video viewing experience across Flash, Silverlight and to the iPhone.
View the demo
http://www.akamai.com/index.html

MOST INTERESTING. Most.
 

Knyaz Vladimir

3DS Hacker
Member
Joined
Apr 18, 2009
Messages
556
Trophies
0
Age
28
Location
Unconfirmed
Website
Visit site
XP
78
Country
Canada
ichichfly said:
Knyaz Vladimir said:
If we can transfer a video saved by the 3DS onto a SD Card (maybe in May), then we'll get somewhere.

I don`t think so because i think nintendo will encrypt them,too.


I think we need the SD-Key not the common key.

ADD: The QR Code for mii are not encrypted and can be readed easy by the PC have fun.
MPO and JPGs are used by the 3DS. So are MP3s.

I'll just twiddle my thumbs and scream in pain. (Damn surgery, the freezing wore off)
 

WB3000

Well-Known Member
Member
Joined
Apr 5, 2007
Messages
674
Trophies
1
Website
wb3000.co.nr
XP
471
Country
United States
The content system appears to be similar to the Wii and DSi systems (once again). The server used is the same as the DSi server, however there are changes to the tmd file format that prevent a lot of tools from working (including all my NUSD builds). You can read more about the tmd changes here. There is also code available to read the tmd information from this new format.

If you put any of those titleIds into NUSD, the tmd will be fetched but content information will be incorrect and consequently contents will 404. Should time permit, NUSD could be extended to 3DS support as well.

QUOTE said:
The Akamai
HD Network

I'm fairly sure that it just one of Akamai's services, and that Nintendo has been using Akamai for general distribution for quite awhile.

QUOTEI think we need the SD-Key not the common key.

Both keys are useful for different things. Stuff like gamesaves and other encrypted things require the SD Key to make changes. I'm not positive, but I believe that the idea behind savegame exploits is 1) get sd key 2) decrypt gamesave and insert exploit changes 3) re-encrypt with SDkey and distribute.

All of these files you are getting from NUS are useless in their current state. Do not waste your time examining the video file, or any of the others. Once the common key is released, these files can be decrypted and will probably be very easy to extract video, etc.
 

Knyaz Vladimir

3DS Hacker
Member
Joined
Apr 18, 2009
Messages
556
Trophies
0
Age
28
Location
Unconfirmed
Website
Visit site
XP
78
Country
Canada
Okay, I dropped the video file. I still have it, though, if need be.

So, how are we supposed to find the common key? My idea is trying to figure out an exploit, but without a decrypter, we're kind of screwed over. So, let's think of ideas on obtaining said key as fast as possible, and just so I can have my 3DS be a remote for my Wii. (using it as a keyboard and mouse, imo)
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • SylverReZ @ SylverReZ:
    @Bunjolio, Proxy sites, not very effective.
  • Bunjolio @ Bunjolio:
    if ur on a Chromebook and cant change jack about the laptop that's what I gotta use
  • SylverReZ @ SylverReZ:
    One of the sites that weren't blocked on the school's network was some file uploading sites. I would upload some games, write down the URL and take it to school one day.
  • Bunjolio @ Bunjolio:
    lol
  • SylverReZ @ SylverReZ:
    I did it when the teachers werent looking ofc. I even managed to take in a USB stick that wasn't allowed.
  • Bunjolio @ Bunjolio:
    my school has a chrome extension called light speed filter agent and it legit blocks YouTube pfps since the file cdn(I think aka yt3.ggpht.com) is classed as mature
  • Bunjolio @ Bunjolio:
    mhm
  • Bunjolio @ Bunjolio:
    they have other stuff like goguardian too
  • SylverReZ @ SylverReZ:
    Ours mainly relied on the router, I believe.
  • Bunjolio @ Bunjolio:
    our school network and chrome policies block stuff too
  • Bunjolio @ Bunjolio:
    alot of yt to mp3 sites are blocked by light speed for "Security"
  • SylverReZ @ SylverReZ:
    It was easy to bypass some of the restrictions, as one of the admins left a registry key in the administrative shares drive, which allowed me to get around the blocking of some sites.
  • Bunjolio @ Bunjolio:
    tf does tta mean
  • Bunjolio @ Bunjolio:
    yeah this is chrome os
  • Bunjolio @ Bunjolio:
    cant do shit
  • SylverReZ @ SylverReZ:
    @Bunjolio, Wdym 'TTA'?
  • Bunjolio @ Bunjolio:
    that* as in why yt to mp3 sites are blocked for security
  • SylverReZ @ SylverReZ:
    @Bunjolio, Remember when YouTubetoMP3 was a thing back in the 2010s?
  • SylverReZ @ SylverReZ:
    Until YT updated some stuffs and broke the website.
  • Bunjolio @ Bunjolio:
    I was 2 in 2010
  • SylverReZ @ SylverReZ:
    Oh lol
  • Bunjolio @ Bunjolio:
    lol
  • SylverReZ @ SylverReZ:
    This was in the Minecraft-era.
    Bunjolio @ Bunjolio: a