I have decided to think outside the box and send some malformed packages to the WiFi stack, and lo and behold, I managed to crash the 3DS. What's better is that there is some uninitialized memory space which is preserved across reboots - as long as you don't power off the device - and from there I could run some code with kernel privileges.
I know, I know, video proof or it didn't happen. Here is the video proof, enjoy:
http://www.youtube.com/watch?v=aGxoB-rEwtg
I know, I know, video proof or it didn't happen. Here is the video proof, enjoy:
http://www.youtube.com/watch?v=aGxoB-rEwtg