Hacking 3DS Hacking Ideas: Post Your Ideas Here!

Superuser

New Member
Newbie
Joined
Aug 29, 2013
Messages
1
Trophies
0
Age
34
Location
Purcellville, Virginia
XP
41
Country
United States
I'm new to hacking devices, but perhaps there is a way to use spotpass to run an exploit. I can attempt to log my router and wait for a spot pass request to come in. I'll check out if I can somehow send back some data to the console. There's a method to my madness, however. If spotpass messages are not encrypted, perhaps you can somehow run your own code (considering the system probably has rw access for notifications)

Just a theory, though.
 

UltraMew

GBATemp's Mew PRETENDING TO BE FOXI4 4 A DAY
Banned
Joined
Aug 7, 2013
Messages
861
Trophies
0
Location
Flying a blue hedgehog around
Website
www.reddit.com
XP
212
Country
United States
I'm new to hacking devices, but perhaps there is a way to use spotpass to run an exploit. I can attempt to log my router and wait for a spot pass request to come in. I'll check out if I can somehow send back some data to the console. There's a method to my madness, however. If spotpass messages are not encrypted, perhaps you can somehow run your own code (considering the system probably has rw access for notifications)

Just a theory, though.
Nice idea... Doubt it'll work. Get some more posts though.
 

JackW

New Member
Newbie
Joined
Aug 31, 2013
Messages
1
Trophies
0
Age
35
XP
54
Country
Is the encryption at the hardware level? Because if it was at the firmware level, presumably if you were able to flash a custom firmware you'd be able to do whatever you like, wouldn't you? And of course assuming there was a way to flash the 3DS without running signed code.
 

liban100

Well-Known Member
Newcomer
Joined
May 25, 2011
Messages
93
Trophies
0
Location
London
XP
87
Country
United States
Random question but do you guys think that Gateway releasing Firmware Spoofing has got anything to do with emo kid 68 discovering that the Gateway Installer stopped the update message?
 

subplay

Member
Newcomer
Joined
Nov 24, 2009
Messages
10
Trophies
0
XP
99
Country
Just a thought, I dont know if anyone has bought this up, there is alot of pages.. But if it is games people want to play? I wonder if there is a way to reverse engineer the game cartridges instead of this hand held? surely you could get pokemon lets say and dump the rom, is there a way that the write protect could be disabled you think, so you could upload a rom onto the part of the chip where the rom lies and will then work with the key? I know it sounds stupid, its just a thought..
 

JuanGomezFernand

Member
Newcomer
Joined
Mar 31, 2012
Messages
9
Trophies
0
XP
33
Gateway certificates are jumped by 3ds.

In the gateway code exploit, the ctr gateway have a key and copied to the 3ds rom, cause a hole to secure licenses to operate third-party home applications.
 

Rydian

Resident Furvert™
OP
Member
Joined
Feb 4, 2010
Messages
27,880
Trophies
0
Age
36
Location
Cave Entrance, Watching Cyan Write Letters
Website
rydian.net
XP
9,111
Country
United States
Is the encryption at the hardware level? Because if it was at the firmware level, presumably if you were able to flash a custom firmware you'd be able to do whatever you like, wouldn't you? And of course assuming there was a way to flash the 3DS without running signed code.
Well seeing as the NAND dumps people have made are encrypted and per-3DS, I assume so?

Random question but do you guys think that Gateway releasing Firmware Spoofing has got anything to do with emo kid 68 discovering that the Gateway Installer stopped the update message?
People realized that the Gateway installer stopped the update message like within a week of it's release, whereas firmware spoofing didn't come along until version 1.1 or whatever of the Gateway installer.

Just a thought, I dont know if anyone has bought this up, there is alot of pages.. But if it is games people want to play? I wonder if there is a way to reverse engineer the game cartridges instead of this hand held? surely you could get pokemon lets say and dump the rom, is there a way that the write protect could be disabled you think, so you could upload a rom onto the part of the chip where the rom lies and will then work with the key? I know it sounds stupid, its just a thought..
The ROM being Read-Only is hardware. Like DVDs you get from the store with a movie on them. You can't physically re-write the data on there.

Now, if you're talking about just remaking the games into a new cart... that's bootlegging, and people have done it with 3DS games for a while before the Gateway came out. They just realized nobody wants to buy a bootleg if you can only have a single game on each bootleg forever period.

Is there no Way like by the iPhone through the dfu mode or something like that?
The closest example on a game system would be the PSP's pandora/service thing, but that died less than halfway through the PSP's lifetime and we haven't seen anything like it since for downgrading.

Even with people finding out how to dump and restore the NAND, they can only downgrade to a dump that they themselves made on an earlier firmware on that exact 3DS.
 

uherrera

Member
Newcomer
Joined
Nov 19, 2008
Messages
20
Trophies
0
XP
168
Country
United States
How about cloning a 3ds via the 3ds transfer utility so that purchasing a game on one console enables it on the other one as well?
 

Rydian

Resident Furvert™
OP
Member
Joined
Feb 4, 2010
Messages
27,880
Trophies
0
Age
36
Location
Cave Entrance, Watching Cyan Write Letters
Website
rydian.net
XP
9,111
Country
United States
How about cloning a 3ds via the 3ds transfer utility so that purchasing a game on one console enables it on the other one as well?
Uhhh. You'd need to do a NAND backup on the one 3DS with the games, then update both to the latest firmware and do the transfer (the transfer is NOT directly from one 3DS to the other, it's done via Nintendo's servers), then when it's done restore the old NAND backup on the 3DS that had the games.

But then you'd end up with one 3DS that can never update or go online (or it'll realize it shouldn't have the games and disable them), and another one that's updated on the latest firmware and can't use the gateway or whatever other 4.x stuff might come out.
 

keven3477

Fresh Prince of Lemonade
Member
Joined
Jul 12, 2012
Messages
953
Trophies
0
Location
Somewhere i can never find.
XP
1,212
Country
United States
how about makin a custom firmware disconect the internet not the router of a conection, use a program like usendmii that makes the custom firmware downloadable while its not conected to real wiifi and at the specific site the 3ds picks its firmware from, and download a hacked firmware from home.
 

Rydian

Resident Furvert™
OP
Member
Joined
Feb 4, 2010
Messages
27,880
Trophies
0
Age
36
Location
Cave Entrance, Watching Cyan Write Letters
Website
rydian.net
XP
9,111
Country
United States
how about makin a custom firmware disconect the internet not the router of a conection, use a program like usendmii that makes the custom firmware downloadable while its not conected to real wiifi and at the specific site the 3ds picks its firmware from, and download a hacked firmware from home.
It doesn't matter how you give the firmware update to the 3DS, the 3DS will see that it wasn't made/signed by Nintendo and refuse to do anything with it.
 

Kupie

Well-Known Member
Member
Joined
Jun 9, 2013
Messages
320
Trophies
1
Age
31
XP
906
Country
United States
It doesn't matter how you give the firmware update to the 3DS, the 3DS will see that it wasn't made/signed by Nintendo and refuse to do anything with it.


Hopefully we can crack into the 3DS code through software (the Gateway can run homebrew and such... why can't it dump some Hashes and encryption keys?) then find some 'Master Key' of sorts.

There have been some signing bugs for past systems (Trucha, anyone?) which means a bug could also be found in the signing process for the 3DS. Never give up hope, anyone!
 

excalibrax

Active Member
Newcomer
Joined
Aug 2, 2012
Messages
33
Trophies
0
XP
74
Country
United States
I don't know if its been suggested before, I don't know much but I did have an idea. Would it be possible to find out how the nintendo server for downloading games hosts and servers files. And then emulate that with your computer so your router redirects it to a website you are hosting. Then you could post games up there for you to download to the 3ds and it would encrypt it at that point with the 3ds itself.

At the moment I doubt that nintendo is hosting files for games encrypted for everyones system at once it has to be a generic software thats transfered to the system itself( or so i believe).

This way we might be able to load games or homebrew on the 3ds without actually changing any of the files on the handheld at all.

It's a crazy idea, but it might be a more doable idea than others.
 

jastolze

Well-Known Member
Member
Joined
May 2, 2012
Messages
385
Trophies
0
Age
32
XP
695
Country
United States
Hopefully we can crack into the 3DS code through software (the Gateway can run homebrew and such... why can't it dump some Hashes and encryption keys?) then find some 'Master Key' of sorts.

There have been some signing bugs for past systems (Trucha, anyone?) which means a bug could also be found in the signing process for the 3DS. Never give up hope, anyone!
Do you remember when one of the PSP hackers allowed us to run unsigned code on the PSP? Well, it was near the end of the PSP's Lifespan, but it eventually happened. As a result of this, we can run custom games and apps without the need for CFW or Homebrew loaders. Hopefully, the Vita will be cracked soon, so that we have access to that extra ram and GPU. I really want to run Quake 3 on the Vita! :D
 

Rydian

Resident Furvert™
OP
Member
Joined
Feb 4, 2010
Messages
27,880
Trophies
0
Age
36
Location
Cave Entrance, Watching Cyan Write Letters
Website
rydian.net
XP
9,111
Country
United States
Hopefully we can crack into the 3DS code through software (the Gateway can run homebrew and such... why can't it dump some Hashes and encryption keys?) then find some 'Master Key' of sorts.
The key to encrypt/sign isn't in the 3DS, only the key to decrypt/check. Only Nintendo has the signing keys.

There have been some signing bugs for past systems (Trucha, anyone?) which means a bug could also be found in the signing process for the 3DS. Never give up hope, anyone!
Yeah, this is generally how it's done. Most of the time systems are hacked without the encryption/signing keys.

I don't know if its been suggested before, I don't know much but I did have an idea. Would it be possible to find out how the nintendo server for downloading games hosts and servers files. And then emulate that with your computer so your router redirects it to a website you are hosting. Then you could post games up there for you to download to the 3ds and it would encrypt it at that point with the 3ds itself.

At the moment I doubt that nintendo is hosting files for games encrypted for everyones system at once it has to be a generic software thats transfered to the system itself( or so i believe).

This way we might be able to load games or homebrew on the 3ds without actually changing any of the files on the handheld at all.

It's a crazy idea, but it might be a more doable idea than others.
Custom files won't do anything unless signed, and you need the keys, and Nintendo signs stuff before sending it out, so logging won't get it.
 

excalibrax

Active Member
Newcomer
Joined
Aug 2, 2012
Messages
33
Trophies
0
XP
74
Country
United States
Custom files won't do anything unless signed, and you need the keys, and Nintendo signs stuff before sending it out, so logging won't get it.

So is it signed for that specific 3ds before its sent out? or could you intercept the signed file and then use that on everyone else's system.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    K3Nv2 @ K3Nv2: Lol rappers still promoting crypto