Hacking 3DS 6.3 Exploit Found

tHciNc

Total Random
Member
Joined
Jan 14, 2006
Messages
861
Trophies
1
XP
1,705
Country
New Zealand
His new exploit doesnt allow kernelmode, all his previous work that is being referred to is using the 4.x KernelMode, using the mset hack for entry, this is entirely different, read what he wrote

What it is, what it isn’t


If you’ve read my (now really old and outdated) article on 3DS hacking, you’ll recall that for a number of reasons, hacking the console happened by chaining multiple exploits with one another. The most widely used hack (used by flashcart teams, myself and a number of other people) reliies on not one but two completely distinct exploits : the mset DS user settings exploit, which gives us arm11 usermode ROP capabilities, through which a FIRM vuln is exploited to obtain arm9 code exec. This last part was fixed with firmware version 5.0, and it’s the real critical part : while there’s a pretty high number of games that could potentially be exploited through saves to do usermode ROP, it’s useless if you don’t have another exploit to chain that gives you code exec capabilities. This is where ssspwn comes in; it essentially replaces the FIRM exploit we had on 4.5 and lets us execute arbitrary code. That’s why the video looks similar to the one I’d done when I got 4.5 code exec : the first stage exploit used is the same, just fine tuned to work on 6.3.

What does that mean ? Simply that because the two exploits are completely separate, there’s no reason to believe that just because the mset bug was fixed in 7.0, so was ssspwn. That’s right; ssspwn has yet to be plugged by Nintendo, and could in theory give us code exex on latest firmware version. This isn’t the case yet because we haven’t really looked for a new entrypoint, but that’s the next step.

Generally speaking, the thing that’s been stopping me (and others) from releasing working exploits has been the fact that they might be used for piracy. Fortunately, that should not be a factor in this case, as by its very nature, ssspwn can not by itself allow piracy. That’s right, it’s the sweet spot that gives us just enough to get awesome homebrew code running in arm11 user mode, but not enough to break the system bad enough to let anyone do whatever the hell they want.
 
  • Like
Reactions: the_randomizer

lambstone

No. Nyet. 不. Non. Nein.
Banned
Joined
Aug 14, 2011
Messages
614
Trophies
0
XP
310
Country
Console hacking really is dead!

Well. You know how there were environmentalists and extreme environmentalists(aka tree hugging hippies?)

Hacking consoles have evolved in such a similar way. The basic premise still exists but it has... transcended its original intention of unlock the devices to their full/every potential.
 

YoshiInAVoid

Banned!
Banned
Joined
Jan 10, 2011
Messages
560
Trophies
1
Website
google.com
XP
465
Country
ssspwn can not by itself allow piracy. That’s right, it’s the sweet spot that gives us just enough to get awesome homebrew code running in arm11 user mode, but not enough to break the system bad enough to let anyone do whatever the hell they want.
Sounds like this exploit wont be able to install custom apps, use redNAND, or allow for piracy (though I'm just guessing). My 4.5 system wont suddenly lose value :)
 

daicon

Well-Known Member
Member
Joined
Feb 16, 2014
Messages
290
Trophies
1
Age
38
XP
313
Country
United States
Help me understand please: What can be done WITHOUT kernel access? I understand that somehow means not being able to play backups, but what else does it mean? Basically: What can userland do and not do?

Second question: Is it the nature of the exploit that's blocking kernel access or is it some form of DRM that's being implemented?
 

lambstone

No. Nyet. 不. Non. Nein.
Banned
Joined
Aug 14, 2011
Messages
614
Trophies
0
XP
310
Country
Help me understand please: What can be done WITHOUT kernel access? I understand that somehow means not being able to play backups, but what else does it mean? Basically: What can userland do and not do?

Second question: Is it the nature of the exploit that's blocking kernel access or is it some form of DRM that's being implemented?

W/O Kernel Access would mean something like limited modifications to the 3DS. Userland probably just allow you to run Homebrew apps which in my opinion is significantly limited. Region free probably requires kernel access.
 

Oxybelis

Well-Known Member
Member
Joined
Jan 10, 2010
Messages
350
Trophies
0
XP
383
Country
W/O Kernel Access would mean something like limited modifications to the 3DS. Userland probably just allow you to run Homebrew apps which in my opinion is significantly limited. Region free probably requires kernel access.
Not limited modifications. None. You need to launch exploit every time to run homebrew.
 

daicon

Well-Known Member
Member
Joined
Feb 16, 2014
Messages
290
Trophies
1
Age
38
XP
313
Country
United States
W/O Kernel Access would mean something like limited modifications to the 3DS. Userland probably just allow you to run Homebrew apps which in my opinion is significantly limited. Region free probably requires kernel access.
So basically, just what everyone was fearing?

Could you give an example?

From what I understand: A translated game could not exist? Or a romhack? Or even a third-party(as in not smea) backup loader (even if it had some form of verification like Devolution?). Is CFW possible (as in not having to constantly run the exploit through DS profile). Will we be able to have custom "channels" as shown off? Will we be able to inject roms into VC? Running GBA games through the native hardware? NAND emulation for accessing new games and Eshop?
 

Oxybelis

Well-Known Member
Member
Joined
Jan 10, 2010
Messages
350
Trophies
0
XP
383
Country
So basically, just what everyone was fearing?

Could you give an example?

From what I understand: A translated game could not exist? Or a romhack? Or even a third-party(as in not smea) backup loader (even if it had some form of verification like Devolution?). Is CFW possible (as in not having to constantly run the exploit through DS profile). Will we be able to have custom "channels" as shown off? Will we be able to inject roms into VC? Running GBA games through the native hardware? NAND emulation for accessing new games and Eshop?
Nothing like this can be done without kernel exploit.
 
  • Like
Reactions: Nightwish

daicon

Well-Known Member
Member
Joined
Feb 16, 2014
Messages
290
Trophies
1
Age
38
XP
313
Country
United States
Nothing like this can be done without kernel exploit.
Well.. that sounds awful. What IS going to be allowed? Like.. playing some student's coding homework version of Asteroids? Smea's Portal DS? I guess, maybe, DOOM on the go would be cool..
the thing is, its only a matter of time until someone finds a way to acses the kernel
With the way the scene has been struggling to gather momentum, I doubt anyone will really have interest in it.
ssspwn sounds like a pointless failure. Am I missing something here?
 
  • Like
Reactions: Kargaroc

kyogre123

Mexican Pride
Member
Joined
Sep 23, 2013
Messages
2,920
Trophies
0
Age
34
XP
1,347
Country
Mexico
Well.. that sounds awful. What IS going to be allowed? Like.. playing some student's coding homework version of Asteroids? Smea's Portal DS? I guess, maybe, DOOM on the go would be cool..

With the way the scene has been struggling to gather momentum, I doubt anyone will really have interest in it.
ssspwn sounds like a pointless failure. Am I missing something here?

Without kernel mode, you can only "play games". Games will never change the way the system works. I think that's simple enough.
 

daicon

Well-Known Member
Member
Joined
Feb 16, 2014
Messages
290
Trophies
1
Age
38
XP
313
Country
United States
Without kernel mode, you can only "play games". Games will never change the way the system works. I think that's simple enough.
What makes those games different from commercial 3DS roms?

And how do we play games if we can't add a channel to the 3DS homescreen?
 

lambstone

No. Nyet. 不. Non. Nein.
Banned
Joined
Aug 14, 2011
Messages
614
Trophies
0
XP
310
Country
Without kernel mode, you can only "play games". Games will never change the way the system works. I think that's simple enough.

Yes. Sounds about right.

You can play homemade tetris, homemade connect four, maybe a gallery app. Stuff like this. The awesome stuff like hacking the firmware, changing background colours, region free, etc etc will be impossible.
 

Issac

Iᔕᔕᗩᑕ
Supervisor
Joined
Apr 10, 2004
Messages
7,025
Trophies
3
Location
Sweden
XP
7,349
Country
Sweden
I was thinking about updating my 6.2 (or 6.0 or whatever it is I have) sometime soon just because I didn't want to be bothered to update each time I start my console... maybe I should wait for that anyway ^_^
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • SylverReZ @ SylverReZ:
    @Sonic Angel Knight, Is that SAK I see. :ninja:
  • BigOnYa @ BigOnYa:
    What a weird game
  • K3Nv2 @ K3Nv2:
    Yeah I wanted to see shards of the titanic
  • BigOnYa @ BigOnYa:
    I kept thinking jaws was gonna come up and attack
  • K3Nv2 @ K3Nv2:
    Jaws is on a diet
  • K3Nv2 @ K3Nv2:
    Damn power went out
  • BigOnYa @ BigOnYa:
    Ok xdqwerty, your little bro prob tripped On the cord and unplugged you
  • K3Nv2 @ K3Nv2:
    Ya I'm afraid of the dark hug me
  • BigOnYa @ BigOnYa:
    Grab and hold close your AncientBoi doll.
  • K3Nv2 @ K3Nv2:
    Damn didn't charge my external battery either
  • BigOnYa @ BigOnYa:
    Take the batteries out of your SuperStabber3000... Or is it gas powered?
  • K3Nv2 @ K3Nv2:
    I stole batteries from your black mamba
    +1
  • K3Nv2 @ K3Nv2:
    My frozen food better hold up for an hour I know that
  • BigOnYa @ BigOnYa:
    Or else gonna be a big lunch and dinner tomorrow.
  • BigOnYa @ BigOnYa:
    Did you pay your power bill? Or give all yo money to my wife, again.
  • K3Nv2 @ K3Nv2:
    Oh good the estimated time is the same exact time they just said
    +1
  • BigOnYa @ BigOnYa:
    Load up your pc and monitor, and head to a McDonalds dining room, they have free WiFi
  • K3Nv2 @ K3Nv2:
    Sir please watch your porn in the bathroom
    +2
  • BigOnYa @ BigOnYa:
    No sir we can not sell you anymore apple pies, after what you did with the last one.
  • K3Nv2 @ K3Nv2:
    We ran out
  • HiradeGirl @ HiradeGirl:
    for your life
    +1
  • K3Nv2 @ K3Nv2:
    My life has no value my fat ass is staying right here
    K3Nv2 @ K3Nv2: My life has no value my fat ass is staying right here