Hacking 3DS Firmware has been decrypted

Status
Not open for further replies.

indask8

New Member Forever
Member
Joined
Apr 19, 2007
Messages
987
Trophies
0
Age
37
Location
Look at the Flag...
XP
352
Country
France
Neimod shared the key for the US Nintendo 3DS Camera application on IRC. Not sure what it means... (key for title id 0004001000022400 http://3dbrew.org/wiki/Title_list)

i present you a key, and you must find the lock!
the key is: ********************************
it's 3DS related, and also AES CBC related
...
fuck it, the title is 0004001000021400

Not gonna happen but a tiff exploit like on the good old psp would have been fun.
 

3DSGuy

No longer in scene
Member
Joined
May 22, 2012
Messages
345
Trophies
0
XP
467
Country
United States
Neimod shared the key for the US Nintendo 3DS Camera application on IRC. Not sure what it means... (key for title id 0004001000022400 http://3dbrew.org/wiki/Title_list)

i present you a key, and you must find the lock!
the key is: ********************************
it's 3DS related, and also AES CBC related
...
fuck it, the title is 0004001000021400
Can you un-astrix the key, so we can tell you if it is useful or not.
 

DiNo29

Well-Known Member
Member
Joined
Feb 28, 2007
Messages
293
Trophies
0
Website
Visit site
XP
291
Country
France
*key was here*

He also said he glanced over TWL_FIRM (DSi Firmware) so I guess it means he decrypted that too, but said "it's like MIOS for Wii", "it does not look anything like the actual DSi firmware"
 
  • Like
Reactions: 2 people

JackSakamoto

Bad Ending Guy
Member
Joined
Sep 13, 2009
Messages
161
Trophies
0
Age
27
XP
211
Country
Hmmm.. Is that useful for the moment ? remember Nintendo automatic updates..
Whatever,i hope that's true.
 

3DSGuy

No longer in scene
Member
Joined
May 22, 2012
Messages
345
Trophies
0
XP
467
Country
United States
Okay guys, I now know what this is. The key is definitely real. It is called the 'decrypted title key' for the Nintendo 3DS Camera app. What does that mean? It means that you can decrypt the the NCCH files for the Nintendo 3DS Camera app from their form as they exist on Nintendo's servers to a readable NCCH file. Note that the contents of the NCCH file is still encrypted. What is the relevance of this? Well there are only two way's (I can think of), which the title key could have been obtained:

1/ Decrypted the title key with the 3DS Common Key
2/ Watched the RAM while a system update was performed, and waited until the decrypted title key entered memory.
 
  • Like
Reactions: 3 people

osm70

Well-Known Member
Member
Joined
Apr 17, 2011
Messages
1,243
Trophies
1
XP
2,721
Country
Czech Republic

3DSGuy

No longer in scene
Member
Joined
May 22, 2012
Messages
345
Trophies
0
XP
467
Country
United States
I will ask again.
So what is it good for?
I will say again.
you can decrypt the the NCCH files for the Nintendo 3DS Camera app from their form as they exist on Nintendo's servers to a readable NCCH file.
So could I host custom NUS, connect by DNS spoofing and "update" the camera app to my custom program?
No. You can decrypt the NCCH files for the Nintendo 3DS Camera from nintendo's servers. I never said anything about spoofing
 

osm70

Well-Known Member
Member
Joined
Apr 17, 2011
Messages
1,243
Trophies
1
XP
2,721
Country
Czech Republic
I will ask again.
So what is it good for?
I will say again.
you can decrypt the the NCCH files for the Nintendo 3DS Camera app from their form as they exist on Nintendo's servers to a readable NCCH file.
So could I host custom NUS, connect by DNS spoofing and "update" the camera app to my custom program?
No. You can decrypt the NCCH files for the Nintendo 3DS Camera from nintendo's servers. I never said anything about spoofing
If I can decrypt, cant I also encrypt?
 

3DSGuy

No longer in scene
Member
Joined
May 22, 2012
Messages
345
Trophies
0
XP
467
Country
United States
I will ask again.
So what is it good for?
I will say again.
you can decrypt the the NCCH files for the Nintendo 3DS Camera app from their form as they exist on Nintendo's servers to a readable NCCH file.
So could I host custom NUS, connect by DNS spoofing and "update" the camera app to my custom program?
No. You can decrypt the NCCH files for the Nintendo 3DS Camera from nintendo's servers. I never said anything about spoofing
If I can decrypt, cant I also encrypt?
Not with this key you can't. Plus you'd need to sign it.
 

Ericthegreat

Not New Member
Member
Joined
Nov 8, 2008
Messages
3,455
Trophies
2
Location
Vana'diel
XP
4,279
Country
United States
I will ask again.
So what is it good for?
I will say again.
you can decrypt the the NCCH files for the Nintendo 3DS Camera app from their form as they exist on Nintendo's servers to a readable NCCH file.
So could I host custom NUS, connect by DNS spoofing and "update" the camera app to my custom program?
No. You can decrypt the NCCH files for the Nintendo 3DS Camera from nintendo's servers. I never said anything about spoofing
If I can decrypt, cant I also encrypt?
Not with this key you can't. Plus you'd need to sign it.
Dam I was excited....
 

Sylantemp

Active Member
Newcomer
Joined
Jul 20, 2012
Messages
43
Trophies
0
XP
71
Country
United States

It's a brief explanation of how the NCCH (A type of container used by the 3DS) keys are randomized and individual per-console. This was probably asked to clarify the significance of the key recently released that is associated with the 3DS Camera, which is NOT used for decrypting the app, but is simply used for (Someone please correct me if I'm wrong) downloading the encrypted form from Nintendo servers. If the key HAD been a universal NCCH key, which is what 3dsguy was asking, it may have opened up a lot more options (again, I could be wrong, if anyone who knows better cares to correct me), such as being able to analyze the app header.

Edit: Before someone can take my words out of context, the key released will NOT enable anything hypothetically mentioned above.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    cearp @ cearp: Welcome hazbeans