Hacking Official [Source Release] ReiNand CFW

usernametaken

Well-Known Member
Member
Joined
May 13, 2015
Messages
1,276
Trophies
0
Age
34
XP
646
Country
United States
So many people think that FBI has reinand rop and im not sure why, since ROP code at somepoint has to call reinand.dat and read the rop in that. FBI is most likely for GW's Launcher.dat .. The ROP .nds thing is in the OP. Just need to compile. And I think I put it in the pre-compiled release too.

FBI does have reinand ROP in it now. It's not listed, but it's there.

Install various MSET ROP chains, including encrypted Gateway 4.x, decrypted Gateway 4.x, N3DS Gateway 9.x, rxTools 4.x, MsetForBoss 4.x, and MsetForBoss 6.x.

https://gbatemp.net/threads/release-fbi-open-source-cia-installer.386433/
 

itsthenavy

Well-Known Member
Member
Joined
Sep 3, 2015
Messages
102
Trophies
0
Age
31
XP
175
Country
United States
So many people think that FBI has reinand rop and im not sure why, since ROP code at somepoint has to call reinand.dat and read the rop in that. FBI is most likely for GW's Launcher.dat .. The ROP .nds thing is in the OP. Just need to compile. And I think I put it in the pre-compiled release too.
FBI does have reinand ROP in it now. It's not listed, but it's there.



https://gbatemp.net/threads/release-fbi-open-source-cia-installer.386433/
Was about to cite just that. Makes me think something is wrong with FBI's ROP installer for the past few versions since I've tried 1.4.8 and 1.4.11 to no avail. I don't happen to have my NDS flashcart on me since I moved recently or else I'd try to install the rop by that method. I might just have to wait until I can get it again, unless a solution can be worked out. I'm curious to find out at which point this is breaking down. I'm highly interested in this.

EDIT: Looks like my case isn't isolated. Though they could be missing something else, it's the same way of crashing.
EDIT2: Might have found the problem. I'm going to build FBI myself and see if it fixes things
 
Last edited by itsthenavy,

usernametaken

Well-Known Member
Member
Joined
May 13, 2015
Messages
1,276
Trophies
0
Age
34
XP
646
Country
United States
@Reisyukaku sorry to bother you about this and you've been probably asked this many times, but will booting to sysnand on reinand be coming soon.

Booting into ReiSys is already a thing.
With the latest version just hold down [ B ] as you press start at the splash screen. *I just hold B until home menu pops up, idk if it's required*
 
  • Like
Reactions: obs123194

Reisyukaku

Onii-sama~
OP
Developer
Joined
Feb 11, 2014
Messages
1,534
Trophies
2
Website
reisyukaku.org
XP
5,422
Country
United States
Booting into ReiSys is already a thing.
With the latest version just hold down [ B ] as you press start at the splash screen. *I just hold B until home menu pops up, idk if it's required*
its just a conditional statement near the press start condition, which is handled after splash screen loads but before anything else so once you see the splash screen go black, you can let go of B.
 
  • Like
Reactions: usernametaken

Sonansune

Well-Known Member
Member
Joined
Jul 2, 2015
Messages
3,734
Trophies
1
XP
2,142
Country
Canada
Is it just me or shouldn't there be no comma at the end of each dimension of the 2D char array? "0x98}" as opposed to "0x98,}" I can't actually build FBI at the moment to test this, but you think the compiler would at least complain about this.
i have exactly same situation =.=
9.1 n3dsll, fbi from 1.4.7 unofficial to 1.4.11, rop installer seems not really working on fbi....
 

itsthenavy

Well-Known Member
Member
Joined
Sep 3, 2015
Messages
102
Trophies
0
Age
31
XP
175
Country
United States
i have exactly same situation =.=
9.1 n3dsll, fbi from 1.4.7 unofficial to 1.4.11, rop installer seems not really working on fbi....
Glad to know I'm not alone in this. I'm going to try building FBI for myself after I get all the dependencies where they belong to see if I can't get it to work. You'll be the first to know.
 

Reisyukaku

Onii-sama~
OP
Developer
Joined
Feb 11, 2014
Messages
1,534
Trophies
2
Website
reisyukaku.org
XP
5,422
Country
United States
Is it just me or shouldn't there be no comma at the end of each dimension of the 2D char array? "0x98}" as opposed to "0x98,}" I can't actually build FBI at the moment to test this, but you think the compiler would at least complain about this.
It is odd, but all the other arrays are like that so i doubt its the problem. But idk, I'll mess with it later if no one finds a solution.
 

itsthenavy

Well-Known Member
Member
Joined
Sep 3, 2015
Messages
102
Trophies
0
Age
31
XP
175
Country
United States
I've used FBI 4.11 to install Reinand ROP without a problem on my 9.0.0-23(U)
Is there any reasonable way to tell if the ROP is installed, save the MSET exploit actually loading the CFW? Something is wrong somewhere, obviously, and it's not an isolated issue. So far we know this:

  • It effects two Reinand users with Japanese region N3DS (given that Ericjwg used "N3DSLL").
  • It effects one rxTools user with O3DS of unknown region.
  • Of these, the firmwares are 9.2.0-20J, one is 9.1, and the last is 6.2.
  • The CFW will not launch from the DS profile, but will launch fine from the Homebrew Menu.
 

usernametaken

Well-Known Member
Member
Joined
May 13, 2015
Messages
1,276
Trophies
0
Age
34
XP
646
Country
United States
Is there any reasonable way to tell if the ROP is installed, save the MSET exploit actually loading the CFW? Something is wrong somewhere, obviously, and it's not an isolated issue. So far we know this:

  • It effects two Reinand users with Japanese region N3DS (given that Ericjwg used "N3DSLL").
  • It effects one rxTools user with O3DS of unknown region.
  • Of these, the firmwares are 9.2.0-20J, one is 9.1, and the last is 6.2.
  • The CFW will not launch from the DS profile, but will launch fine from the Homebrew Menu.

Nothing on the user level to indicate an installed ROP other than the ROP telling you it installed.

So far it's looking like it might be an issue with just the Jap consoles(?)
I'm going to reinstall ROP with FBI 4.11 again just to make sure.
 

itsthenavy

Well-Known Member
Member
Joined
Sep 3, 2015
Messages
102
Trophies
0
Age
31
XP
175
Country
United States
I just tested FBI 1.4.11 and the rop worked for me. I'm using the small white N3DS region swapped from JP to US, as per usual.
Yeah, tested again with 1.4.11 (My bad, thought it was 4.11).
No problems here as usual.
This is getting odder and odder. Surely there must be some very simple thing I am missing. It's definitely not reiNand.dat I know that is on my root. my JP N3DS isn't region swapped, though.

EDIT: I installed the N3DS Gateway 9.X ROP from FBI 1.4.11 to see if it was FBI that was the problem, but it launched the Gateway Launcher.dat still on my SD card when I performed the exploit. I wonder why it won't launch reiNand.dat though...
 
Last edited by itsthenavy,

Reisyukaku

Onii-sama~
OP
Developer
Joined
Feb 11, 2014
Messages
1,534
Trophies
2
Website
reisyukaku.org
XP
5,422
Country
United States
This is getting odder and odder. Surely there must be some very simple thing I am missing. It's definitely not reiNand.dat I know that is on my root. my JP N3DS isn't region swapped, though.

EDIT: I installed the N3DS Gateway 9.X ROP from FBI 1.4.11 to see if it was FBI that was the problem, but it launched the Gateway Launcher.dat still on my SD card when I performed the exploit. I wonder why it won't launch reiNand.dat though...
Hah, welcome to the quirkiness of the 3DS. Some things are just unexplainable. Like how only europeans have problems with reinand in general.

Anyways, if CN launches it, then yea, its not the CFW or location of it.. CN is just a means of gaining arm9 and i basically use a brahma like setup to read reinand.dat into ram and execute at 0x12000 or w/e i currently have the entrypoint set to. MSET on the other hand, uses the dsprofile to gain arm9 by writing the rop loader to the dsprofile via flash card. I assume this is the rop FBI uses, precisely (More specifically, the dsprofile rop manipulates system settings API to read rop from reinand.dat, and that rop is what gains arm9).

That aside, if CN works, its not the CFW itself, and if MSET works for some its not FBI thats a problem. Have you tried using the rop installer i have on git? Does the FBI rop just crash back to homemenu with that white popup box?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    K3Nv2 @ K3Nv2: Well start walking towards them +1