Homebrew AES key scrambler

Dazzozo

KRAZOA PALACE
Member
Joined
Feb 24, 2015
Messages
292
Trophies
0
Website
dazzozo.com
XP
910
Country
Ok, I didn't know that, this seemed like an obvious thing to do, given that it's cleared by Kernel9, as you run code earlier, you can just read the actual OTP hash used in the decryption of the nand keystore.

Sure you didn't just look at 3dbrew recent changes? :P

--------------------- MERGED ---------------------------

Besides, that attack is far harder to pull off than downgrading to use the 2.X OTP flaw.
 
  • Like
Reactions: Syphurith

mathieulh

Well-Known Member
Member
Joined
Feb 28, 2008
Messages
378
Trophies
0
Website
keybase.io
XP
897
Country
France
Sure you didn't just look at 3dbrew recent changes? :P

Not since this morning, I am about to check now xD

--------------------- MERGED ---------------------------

Besides, that attack is far harder to pull off than downgrading to use the 2.X OTP flaw.

Hum... seems easier to me, as the NAND requires "invasive" changes to run the older FIRM and the NCSD header is signed.

UPDATE: You are right, it was recently added to 3dbrew xD
That's a very interesting read by the way.
 
Last edited by mathieulh,

Dazzozo

KRAZOA PALACE
Member
Joined
Feb 24, 2015
Messages
292
Trophies
0
Website
dazzozo.com
XP
910
Country
Not since this morning, I am about to check now xD

--------------------- MERGED ---------------------------



Hum... seems easier to me, as the NAND requires "invasive" changes to run the older FIRM and the NCSD header is signed.

Well that sure sounds like you don't know what you're talking about.
 

RednaxelaNnamtra

Well-Known Member
Member
Joined
Dec 8, 2011
Messages
1,209
Trophies
1
XP
3,348
Country
Germany
I added the slot0x11key9.6.bin generation to my key generator.
Don't know if its the best name for the key.
 

Attachments

  • Simple-128bit-Key-Generator.zip
    10.3 KB · Views: 452

Xenon Hacks

Well-Known Member
Member
Joined
Nov 13, 2014
Messages
7,414
Trophies
1
Age
30
XP
4,687
Country
United States
Question about OTP is there a way to dump your console's key from your own Nand dump? Also let's say it can be done what fun things could one do on a N3DS or is there something deeper than that on boot?
 

zecoxao

Well-Known Member
Member
Joined
Dec 25, 2013
Messages
379
Trophies
1
Age
33
XP
1,703
Country
Question about OTP is there a way to dump your console's key from your own Nand dump? Also let's say it can be done what fun things could one do on a N3DS or is there something deeper than that on boot?
nand dump shouldn't contain perconsole keys, i think. if you dump the otp with the kernel 9 flaw documented on wiki, however, you can easily decrypt your nand :)
 

Suiginou

(null)
OP
Member
Joined
Jun 26, 2012
Messages
565
Trophies
0
Location
pc + 8
XP
738
Country
Gambia, The
Well the fruits of this labor are emerging.
https://github.com/delebile/arm9loaderhax/

(and yes I struggled google-fuing a relevant thread lol)
Oh shit. Things are on fire now. At a quick glance, it seems to read 0x4000 bytes from NAND 0x0B800000 (stage1, i.e., this code must fit into the size difference of firm0/firm1) into address 0x08006000. That one then does some weird magic with ARM11, loads sd:/arm9loaderhax.bin into 0x23F00000 and jumps there.
 
  • Like
Reactions: zoogie

Psi-hate

GBATemp's Official Psi-Hater
Member
Joined
Dec 14, 2014
Messages
1,749
Trophies
1
XP
3,413
Country
United States
Judging by the readme, all we need is our own OTP.bin? I'm sure the other setup files are obtainable online from the looks of it. (Unless we need to get our own console NATIVE_FIRMs and keys). If you can downgrade and dump your OTP.BIN then is it possible to find the other setup files online and build the hax from there?
 
Last edited by Psi-hate,

Suiginou

(null)
OP
Member
Joined
Jun 26, 2012
Messages
565
Trophies
0
Location
pc + 8
XP
738
Country
Gambia, The
Judging by the readme, all we need is our own OTP.bin? I'm sure the other setup files are obtainable online from the looks of it (unless we need to dump our own Native _Firms). If you can downgrade and dump your OTP.BIN then is it possible to find the other setup files online and build the hax from there?
Yep, the other firmware things should all still be on the CDN. OTP dumping is super hard currently, though. The downgrade effectively requires a hardmod on N3DS. On O3DS, you'll still have a bad time finding a 2.1 dump with browser (if you want to ARM9 from browser; else you can just use cubic ninja).
 

Psi-hate

GBATemp's Official Psi-Hater
Member
Joined
Dec 14, 2014
Messages
1,749
Trophies
1
XP
3,413
Country
United States
Yep, the other firmware things should all still be on the CDN. OTP dumping is super hard currently, though. The downgrade effectively requires a hardmod on N3DS. On O3DS, you'll still have a bad time finding a 2.1 dump with browser (if you want to ARM9 from browser; else you can just use cubic ninja).
If N3DS requires a hardmod, I may as well get it done sooner than later. Also, how would someone get the downgraded N3DS to run in the first place? I haven't seen anyone explain that yet.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    Psionic Roshambo @ Psionic Roshambo: Taylor Swift death metal AI cover please lol