Hacking 3DS Hacking Ideas: Post Your Ideas Here!

  • Thread starter Thread starter Rydian
  • Start date Start date
  • Views Views 105,951
  • Replies Replies 420
  • Likes Likes 18
Heres an idea while we (We as in General Console Hacking scene ( psp, ds, ps3 blah blah blah blah)) have used in the past the tiff exploit which really is not usful anymore to execute code or create an exploit point...
Why not use the video player as a way... But Dark you yell at me it has a proprietary format with no exploit!!! while yes this is true (starting from that format) we forget we can convert our movies to that format... so what about injecting code into a movie converting it (may require a converter from the scene that ignores the code and converts it regardless not sure :S ) and attempting to run / play the file. ( on PC wma file used to always have virus injected into them and media player would still play it and *Cough* Destroy your pc) fact is video files and audio file have this ability more then the tiff file question is can it be applied to the 3ds in some form? either audio or video... or the videos audio channel.
 
impossible. When converting your video, the converter will notice there`s a problem with it and stop the conversion. The only way to launch a modded video would be with the youtube application hack to launch anykind of video.
 
Heres an idea while we (We as in General Console Hacking scene ( psp, ds, ps3 blah blah blah blah)) have used in the past the tiff exploit which really is not usful anymore to execute code or create an exploit point...
Why not use the video player as a way... But Dark you yell at me it has a proprietary format with no exploit!!! while yes this is true (starting from that format) we forget we can convert our movies to that format... so what about injecting code into a movie converting it (may require a converter from the scene that ignores the code and converts it regardless not sure :S ) and attempting to run / play the file. ( on PC wma file used to always have virus injected into them and media player would still play it and *Cough* Destroy your pc) fact is video files and audio file have this ability more then the tiff file question is can it be applied to the 3ds in some form? either audio or video... or the videos audio channel.

It's not proprietary. It's just some common video format, but in 3D.
Also, we could just get a random video that the 3DS would read and inject code into it directly. No "converter" is needed.
Problem is, it is likely the 3DS camera app can already handle "corrupted" files like this.
Only hope is that amazingly badly-coded YouTube app.
 
  • Like
Reactions: cloud1250000
It's not proprietary. It's just some common video format, but in 3D.
Also, we could just get a random video that the 3DS would read and inject code into it directly. No "converter" is needed.
Problem is, it is likely the 3DS camera app can already handle "corrupted" files like this.
Only hope is that amazingly badly-coded YouTube app.

It is possible to run video's outside youtube from the youtube app. So you would only need a vid with injected code to try and see if it works. The app is based on the browser of the 3ds and supports .mp4 with H264 video. To play the video you only need to create a HTML5 page and put the vid between <video>
 
I'm curious as to if this has any application to the 3DS. 3DS uses RSA encryption yes?

RSA Key Extraction via Low-Bandwidth Acoustic Cryptanalysis

This was used to exploit laptops, but nothing in there says a 3DS would by any more immune then a laptop. Unless the lower power consumption of the 3DS makes this more difficult? I would think it would be easier since there's no fans or other moving parts in the 3DS that operate while the console is powered up.
 
I'm curious as to if this has any application to the 3DS. 3DS uses RSA encryption yes?

RSA Key Extraction via Low-Bandwidth Acoustic Cryptanalysis

This was used to exploit laptops, but nothing in there says a 3DS would by any more immune then a laptop. Unless the lower power consumption of the 3DS makes this more difficult? I would think it would be easier since there's no fans or other moving parts in the 3DS that operate while the console is powered up.

I did bring this up a few months back. It's difficult because the 3DS uses a low power SoC instead of a full CPU like in the example. Not to mention it's hard to pull off.
 
I'm not a programmer and have no experience at all but would it be possible to use DLC from a game to launch an exploit, using it to redirect access to the SD card, and launch from there.

If Launching from 3ds home-brew from there, unless corrected, you could do so without the need to use an exploit on regular ds firmware, removing the need to relaunch when using ds mode, right?

If the idea has been presented, and debunked, I apologize for sounding foolish.
 
I'm not a programmer and have no experience at all but would it be possible to use DLC from a game to launch an exploit, using it to redirect access to the SD card, and launch from there.

If Launching from 3ds home-brew from there, unless corrected, you could do so without the need to use an exploit on regular ds firmware, removing the need to relaunch when using ds mode, right?

If the idea has been presented, and debunked, I apologize for sounding foolish.

You don't launch exploits. You make use of it, exploits are found not created. You can't just say to use a DLC to launch an exploit. It's like trying to cook something by freezing it.
 
  • Like
Reactions: pelago
You don't launch exploits. You make use of it, exploits are found not created. You can't just say to use a DLC to launch an exploit. It's like trying to cook something by freezing it.

Thanks for the clarification. I meant to say find an exploit similar to how to installing the Home-brew channel on Wii, using DLC in place of a letterbomb.
 
Thanks for the clarification. I meant to say find an exploit similar to how to installing the Home-brew channel on Wii, using DLC in place of a letterbomb.

DLCs are as secure as normal titles. And normal titles are very secure.

When the firmware gets decrypted and stored somewhere (nand?), can't we dump it from there?

Dump what? We can already dump NAND but encrypted.
 
Well, you can dump part of it if it's loaded into memory.
Okay, and would it be possible to modify a small part of the firmware to f.e. disable a rom decryptor/legitimacy check jump? Would this allow running homebrew/hacks/fan translations (maybe even from the sd card)?
 

Site & Scene News

Popular threads in this forum