Hacking 3DS unbricking progress

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
They really should give them for free, they got people's consoles bricked, they should pay for the fix....I doubt it though....probs sell it for a nice fat profit.....same should apply for gateway users who got bricked....gateway should supply the fix to them for free
 

krisztian1997

Well-Known Member
OP
Member
Joined
Dec 14, 2013
Messages
370
Trophies
0
Age
27
XP
300
Country
Romania
3ds XL only?

Finding one of the pins on 3ds is much harder, so you cant make a pogo pin setup to do that...

They really should give them for free, they got people's consoles bricked, they should pay for the fix....I doubt it though....probs sell it for a nice fat profit

with my or bkifft's code on it. good job bkifft with that code, now lets hope that my code works too and someone can reverse engineer the launcher and find how the password is generated
 
  • Like
Reactions: gamefan5

krisztian1997

Well-Known Member
OP
Member
Joined
Dec 14, 2013
Messages
370
Trophies
0
Age
27
XP
300
Country
Romania
Now everyone have the proof for the brick code. The eMMC controller doesn't lock itself by "magic".
Any progress with the bricking code or you gave up trying to reverse engineer it ? The way how the password was generated would be the most helpful thing right now, then we could help angryrusiankid to unbrick his console
 

Deleted member 313057

Well-Known Member
Newcomer
Joined
Aug 23, 2012
Messages
74
Trophies
0
Website
commentblock.com
XP
193
Country
United States
Finding one of the pins on 3ds is much harder, so you cant make a pogo pin setup to do that...

Can you not use the pins on the other side of the mobo?

CLK:

3dsDump2.jpg
 

krisztian1997

Well-Known Member
OP
Member
Joined
Dec 14, 2013
Messages
370
Trophies
0
Age
27
XP
300
Country
Romania
The problem is, the AES engine and CID is used to generate the password and the key is stored in the Launcher.dat.
The key used for locking the eMMC is stored in the launcher.dat ? and if the internal AES engine is used to generate the locking key, then all what we can do is to force erase...

Can you not use the pins on the other side of the mobo?

CLK:

3dsDump2.jpg

Do you think that it would be posible to touch that pin with a pogo pin ? it looks so super small
 

R4iFanboi

Well-Known Member
Newcomer
Joined
Dec 18, 2013
Messages
52
Trophies
0
Age
34
XP
90
Country
United States
^Not trying to show you down but I think it's technically possible. We will still have to use a little bit of solder though.

Making that small circle bigger by applying some solder might do the trick. Actually, I think there are conductive stickers available, that too, in circled sizes.

Btw, congrats to you guys for achieving this! Welldone!
 

krisztian1997

Well-Known Member
OP
Member
Joined
Dec 14, 2013
Messages
370
Trophies
0
Age
27
XP
300
Country
Romania
^Not trying to show you down but I think it's technically possible. We will still have to use a little bit of solder though.

Making that small circle bigger by applying some solder might do the trick. Actually, I think there are conductive stickers available, that too, in circled sizes.

Btw, congrats to you guys for achieving this! Welldone!

Or without solder by using some pins like those but smaller ones http://dangerousprototypes.com/wp-content/media/2013/02/IMG_1796.jpg, but this will work only if my code works on arduino, otherwise you will need a raspberry pi and its gonna be harder to make an solderless unbricker
 

Ennea

Well-Known Member
Member
Joined
Oct 5, 2013
Messages
114
Trophies
0
Age
32
XP
163
Country
Gambia, The
One more question regarding NAND dumps: I believe it was profi who said that the dump generated by Gateway's (and the other's) Launcher.dat is actually altered in some way, and therefore can't be used as a replacement to a "real" dump. However, I think somebody else also said they used a dump generated by Gateway's code, and it worked just fine. So.. what is it, now?
 

Kane49

Well-Known Member
Member
Joined
Nov 4, 2013
Messages
446
Trophies
0
Age
36
XP
343
Country
Gambia, The

kyogre123

Mexican Pride
Member
Joined
Sep 23, 2013
Messages
2,920
Trophies
0
Age
34
XP
1,347
Country
Mexico
One more question regarding NAND dumps: I believe it was profi who said that the dump generated by Gateway's (and the other's) Launcher.dat is actually altered in some way, and therefore can't be used as a replacement to a "real" dump. However, I think somebody else also said they used a dump generated by Gateway's code, and it worked just fine. So.. what is it, now?

The NAND dump used for EmuNAND has a different encryption, however the dump generated by the "NAND backup" option is just a copy and can be used to reflash the 3DS NAND.

I don't fully understand the purpose of having different encryptions, I also recall users saying that they managed to inject a regular NAND backup to the emuNAND "partition" and it was successfully loaded by GW's launcher.
 

Ennea

Well-Known Member
Member
Joined
Oct 5, 2013
Messages
114
Trophies
0
Age
32
XP
163
Country
Gambia, The
The NAND dump used for EmuNAND has a different encryption, however the dump generated by the "NAND backup" option is just a copy and can be used to reflash the 3DS NAND.

I don't fully understand the purpose of having different encryptions, I also recall users saying that they managed to inject a regular NAND backup to the emuNAND "partition" and it was successfully loaded by GW's launcher.

Alright, thank you for the information.
 

Ante0

Well-Known Member
Member
Joined
Jan 20, 2014
Messages
210
Trophies
0
Age
38
XP
199
Country
Nevermind me.

Good job guys, hope mine gets bricked so I can use my raspberry for anything besides a streaming box xD
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BakerMan
    I rather enjoy a life of taking it easy. I haven't reached that life yet though.
    BakerMan @ BakerMan: damn