Hacking Official [Release] CakesFW

Torx

Active Member
Newcomer
Joined
Jan 6, 2015
Messages
25
Trophies
0
XP
81
Country
Does ninjhax 2.0/2.1 use a new boot.3dsx as Ive been launching the boot.3dsx from ninjhax 1.1 on tubehax?
 

Zap Rowsdower

Well-Known Member
Member
Joined
Jan 17, 2015
Messages
456
Trophies
0
Location
I don't go map findin' behindin'
XP
2,366
Country
Canada
Does ninjhax 2.0/2.1 use a new boot.3dsx as Ive been launching the boot.3dsx from ninjhax 1.1 on tubehax?
You cannot launch a 1.1b boot.3dsx using a 2.0 exploit. Now what you could do if you're so determined is do what I did and modify your 1.1b payload to load a file other than boot.3dsx, (then Ninjhax 2.0 could still load the boot.3dsx) but I wouldn't call it easy to do.
 
  • Like
Reactions: Zidapi

3xkrazy

Well-Known Member
Member
Joined
Jun 2, 2013
Messages
299
Trophies
0
XP
279
Country
United States
You cannot launch a 1.1b boot.3dsx using a 2.0 exploit. Now what you could do if you're so determined is do what I did and modify your 1.1b payload to load a file other than boot.3dsx, (then Ninjhax 2.0 could still load the boot.3dsx) but I wouldn't call it easy to do.

Could you share your code?
 
  • Like
Reactions: Zidapi

hippy dave

BBMB
Member
Joined
Apr 30, 2012
Messages
9,868
Trophies
2
XP
29,030
Country
United Kingdom
You cannot launch a 1.1b boot.3dsx using a 2.0 exploit. Now what you could do if you're so determined is do what I did and modify your 1.1b payload to load a file other than boot.3dsx, (then Ninjhax 2.0 could still load the boot.3dsx) but I wouldn't call it easy to do.
Yes please share, I could really use this :)
 

Zap Rowsdower

Well-Known Member
Member
Joined
Jan 17, 2015
Messages
456
Trophies
0
Location
I don't go map findin' behindin'
XP
2,366
Country
Canada
This is kind of OT, (PM me for questions. I don't want to muddy the thread) but here's how I did it. You have to decrypt your extracted payload with blowfish.py after making this change,
ret=cipher(S,P,l,r,0) --> ret=cipher(S,P,l,r,1)
and it's hardcoded to load blowfish_processed.bin (google for a pastebin)
There will be a number of 'boot.3dsx' instances in the file output to hex edit, and when that's done you change the code back to 0, and reverse the command line arguments
and then you'll have your edited payload ready to be injected.
 

Zidapi

Well-Known Member
Member
Joined
Dec 1, 2002
Messages
3,112
Trophies
3
Age
42
Website
Visit site
XP
2,681
Country
This is kind of OT, (PM me for questions. I don't want to muddy the thread) but here's how I did it. You have to decrypt your extracted payload with blowfish.py after making this change,
ret=cipher(S,P,l,r,0) --> ret=cipher(S,P,l,r,1)
and it's hardcoded to load blowfish_processed.bin (google for a pastebin)
There will be a number of 'boot.3dsx' instances in the file output to hex edit, and when that's done you change the code back to 0, and reverse the command line arguments
and then you'll have your edited payload ready to be injected.
Great work! Create a new thread for this and we shall crown you king (for as long as we see fit).
 
  • Like
Reactions: Ronhero and klear

flarn2006

Well-Known Member
Member
Joined
Apr 6, 2014
Messages
394
Trophies
0
Age
30
XP
523
Country
United States
My bad, I misread that as "We won't share code" and managed to overlook the link to the github repo.

Disregard my earlier post, please allow me to applaud your work.

Edit: lol responses to edited responses to edited posts
Now I'm curious; what did your posts say before?
 

Zap Rowsdower

Well-Known Member
Member
Joined
Jan 17, 2015
Messages
456
Trophies
0
Location
I don't go map findin' behindin'
XP
2,366
Country
Canada
Great work! Create a new thread for this and we shall crown you king (for as long as we see fit).
Quiet down everyone, your "king" has something to say.
...lol :P
The newest NH2.0 boot.3dsx is actually backwards compatible, meaning that you can use a 1.1b payload to load those 1.1 exclusive apps.
 

Cindakil

Well-Known Member
Newcomer
Joined
Apr 14, 2014
Messages
92
Trophies
0
XP
140
Country
Serbia, Republic of
Hi!

I have a N3DS 9.0 with emunand created.
MSET Downgraded.
Gateway Flashcard

But I lost my cubic ninja, is there any way to get access to gateway menu or RX, or Cakes... ??
 

b1l1s

Well-Known Member
Member
Joined
May 2, 2015
Messages
151
Trophies
0
XP
161
Country
Malaysia
Hi!

I have a N3DS 9.0 with emunand created.
MSET Downgraded.
Gateway Flashcard

But I lost my cubic ninja, is there any way to get access to gateway menu or RX, or Cakes... ??
If you already have mset downgraded you can just use the blue cart(I don't own GW but I think this is the one) to install the ROP that you need, be it for GW, rxTools or CakesFW.
 

thaikhoa

Well-Known Member
Member
Joined
Sep 16, 2008
Messages
2,236
Trophies
1
XP
2,590
Country
Australia
If you already have mset downgraded you can just use the blue cart(I don't own GW but I think this is the one) to install the ROP that you need, be it for GW, rxTools or CakesFW.

@173210 has done experimental plugin module for CakesFW. Do you have any idea about that? Screenshot plugin? :D
 

Cindakil

Well-Known Member
Newcomer
Joined
Apr 14, 2014
Messages
92
Trophies
0
XP
140
Country
Serbia, Republic of
I dumped and decrypted my Sysnand partitions (with Decrypt9) and now I have FIRM0.bin, Firm1.bin and CTRNAND.bin.

How I can obtain firmkey.bin and firmware.bin??

PS: Is a New3DS 9.2

Im lost :(


EDIT: I THINK that I get the correct firmkey.bin but I'm not sure what firmware.bin I have to use. They say me "Failed to decrypt the firmware.bin" :(
 
Last edited by Cindakil,

Cavioe

Well-Known Member
Member
Joined
May 28, 2015
Messages
308
Trophies
0
Age
52
XP
190
Country
United States
I dumped and decrypted my Sysnand partitions (with Decrypt9) and now I have FIRM0.bin, Firm1.bin and CTRNAND.bin.

How I can obtain firmkey.bin and firmware.bin??

PS: Is a New3DS 9.2

Im lotst :(

Easiest way is to go to that 3ds iso site and get it from there.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Bunjolio @ Bunjolio:
    my school has a chrome extension called light speed filter agent and it legit blocks YouTube pfps since the file cdn(I think aka yt3.ggpht.com) is classed as mature
  • Bunjolio @ Bunjolio:
    mhm
  • Bunjolio @ Bunjolio:
    they have other stuff like goguardian too
  • SylverReZ @ SylverReZ:
    Ours mainly relied on the router, I believe.
  • Bunjolio @ Bunjolio:
    our school network and chrome policies block stuff too
  • Bunjolio @ Bunjolio:
    alot of yt to mp3 sites are blocked by light speed for "Security"
  • SylverReZ @ SylverReZ:
    It was easy to bypass some of the restrictions, as one of the admins left a registry key in the administrative shares drive, which allowed me to get around the blocking of some sites.
  • Bunjolio @ Bunjolio:
    tf does tta mean
  • Bunjolio @ Bunjolio:
    yeah this is chrome os
  • Bunjolio @ Bunjolio:
    cant do shit
  • SylverReZ @ SylverReZ:
    @Bunjolio, Wdym 'TTA'?
  • Bunjolio @ Bunjolio:
    that* as in why yt to mp3 sites are blocked for security
  • SylverReZ @ SylverReZ:
    @Bunjolio, Remember when YouTubetoMP3 was a thing back in the 2010s?
  • SylverReZ @ SylverReZ:
    Until YT updated some stuffs and broke the website.
  • Bunjolio @ Bunjolio:
    I was 2 in 2010
  • SylverReZ @ SylverReZ:
    Oh lol
  • Bunjolio @ Bunjolio:
    lol
  • SylverReZ @ SylverReZ:
    This was in the Minecraft-era.
  • AncientBoi @ AncientBoi:
    lol Bun rockin out at 2 :rofl2:
  • BakerMan @ BakerMan:
    same tbh
  • AncientBoi @ AncientBoi:
    ♫ Mama hully gully, Papa hully gully, Baby hully gully too:rofl2:
  • AncientBoi @ AncientBoi:
    Oh god, I really am old. lol
    AncientBoi @ AncientBoi: Oh god, I really am old. lol