*facepalm* missed that part in the process you posted...Yep did that (as per the process i posted earlier)... i have both o3ds and n3ds remember.![]()
*facepalm* missed that part in the process you posted...Yep did that (as per the process i posted earlier)... i have both o3ds and n3ds remember.![]()
Hrm... just a dumb question, did you try taking the SD card out on the lower firm?Yep did that (as per the process i posted earlier)... i have both o3ds and n3ds remember.![]()

Yup. No dice. Just powers up and goes nowhere. Black screens...Hrm... just a dumb question, did you try taking the SD card out on the lower firm?

Did you get anything to actually LOAD though?Got arm9loaderhax installed! This is lovely! Thank you everyone who helped.
Not yet. Not sure how to make my own payload (The people as #cakey were telling me how but I don't grasp the simple fundamentals for I don't have knowledge in that area..) so I'd need someone to get me a payload to do something like load cakefw.Did you get anything to actually LOAD though?![]()
According to MassExplosion213, any CakeHax payload should work extracted from 0x12000 onward, so here's Cakes.dat given that very treatment, just remake to arm9loadhax.bin. You'll probably want the config set to autoboot, unless you want to blindly flick through the menusNot yet. Not sure how to make my own payload (The people as #cakey were telling me how but I don't grasp the simple fundamentals for I don't have knowledge in that area..) so I'd need someone to get me a payload to do something like load cakefw.![]()
So I put this in the root, correct?According to MassExplosion213, any CakeHax payload should work extracted from 0x12000 onward, so here's Cakes.dat given that very treatment, just remake to arm9loadhax.bin. You'll probably want the config set to autoboot, unless you want to blindly flick through the menus![]()
yep, renamed to arm9loadhax.bin ofcSo I put this in the root, correct?![]()
Did that and for some reason, the 3ds still shuts down in a split second.yep, renamed to arm9loadhax.bin ofc
sorry, arm9loaderhax.binDid that and for some reason, the 3ds still shuts down in a split second.
Yeah, got that done just now. Hopefully I can get this emunand runningsorry, arm9loaderhax.bin

Well it's arm9loaderhax.... the arm9loader binary is at the beginning of the n3ds firms so, yeah, n3ds firms are kinda needed since, ya know, without them there's nothing to hackHas anyone done this successfully on a o3DS? I think I read before to use all the same files as the n3DS which sounded funny to me since it includes the n3DS firmware files but hey I have a hardmod so I tried it anyway. It doesn't work. First the homebrew to install doesn't work just freezes at some screen about preparing the arm9 (without changing anything since the 3DS still works after a reboot)
So I tried manually installing the files in a nand.bin image (using knowledge from playing around with the 10.5-10.3 downgrade to replace the firm partitions and be properly encrypted and a hex editor for the other two files)
That just boots straight to the blue bootrom screen which is no good but better then I expected from using n3DS firm partitions.
There's only a certain number of keys on the 3DS, and all of them have been made public, and the way these keys are written, they can't be changed or updated by software. The only fix is to change the hardware, and even if they come out with a new hardware revision, that still leaves every current N3DS exploitable forever.1) I watched the 32C3 conference video and understand that by finding out certain keys you can get arm9 access and that nintendo did an apparently terrible job fixing it but wouldnt it be possible that they could change the ways keys are handled in a future firmware update and block this exploit?
Arm9loaderhax runs before even the 3DS kernel starts. If you brick your sysNAND, you can still run ARM9 payloads, so it's easy to restore a backup, or even reinstall a new upgrade pack.2) Does coldboot arm9 mean that you could install unsigned cias directly to the 3ds instead of using emunand and isnt this dangerous considering you dont have an emunand to fall back on?
CN and OoT aren't used to downgrade, sysUpdater is used to downgrade. CN and OoT are used to execute code with enough privileges to run ARM9 code once you've downgraded to 2.x, because currently there's no other way to do so (though that may change very soon). Ironfall won't work on lower firmwares because the game depends on newer firmwares.3) If I understand correctly cubic ninja and oot are used to downgrade to <3.0 as the other exploits arent available on lower FW so some devs are trying to find another entrypoint. I have ironfall and i know its been patched on higher FW and id like to know why the game wouldnt work on a lower FW (If you didnt do a system format before downgrading of course)
1) This isn't really about finding keys... also given that they don't have any other secret sectors (which MUST be installed at the factory) no this isn't patchableNoob here, just wanted to understand some stuff about arm9loaderhax explained as noob friendly as possible:
1) I watched the 32C3 conference video and understand that by finding out certain keys you can get arm9 access and that nintendo did an apparently terrible job fixing it but wouldnt it be possible that they could change the ways keys are handled in a future firmware update and block this exploit?
2) Does coldboot arm9 mean that you could install unsigned cias directly to the 3ds instead of using emunand and isnt this dangerous considering you dont have an emunand to fall back on?
3) If I understand correctly cubic ninja and oot are used to downgrade to <3.0 as the other exploits arent available on lower FW so some devs are trying to find another entrypoint. I have ironfall and i know its been patched on higher FW and id like to know why the game wouldnt work on a lower FW (If you didnt do a system format before downgrading of course)