Homebrew ARM9Loader -- Technical Details and Discussion

  • Thread starter Thread starter Selver
  • Start date Start date
  • Views Views 579,213
  • Replies Replies 4,025
  • Likes Likes 42
Now do it on an n3ds... i dare you! :P haha

--------------------- MERGED ---------------------------

Well I'm calling it a day with this... the n3ds process is a pain in my ass.
2 failed attempts at booting a frankenNAND 2.2 lol
Lovely black screens :(
Pretty sure I'm not missing anything....

Meh, you'll get it going eventually :)
 
Meh, you'll get it going eventually :)
Nope it just refuses to boot the frankenNAND. :(
It turns on but that's about it...
Anyway here's the process i was told and am following... someone chime in if something is missing...

Make a NAND backup
Create a CTRNAND FAT16 xorpad using Decrypt9
Create another CTRNAND FAT16 xorpad using keyslot 0x4 instead of 0x5
Downgrade to 1.0/2.x
Dump your NAND using the hardmod
Extract CTRNAND from it
Xor the dump with the 0x5 xorpad, then xor the result of that with the 0x4 xorpad
Reinject the final result into the NAND dump
Swap the NCSD header (first 0x200 bytes) of the NAND dump with one from an O3DS NAND dump
Flash finished NAND.bin back to your system
It should now boot to 1.0/2.x
 
Nope it just refuses to boot the frankenNAND. :(
It turns on but that's about it...
Anyway here's the process i was told and am following... someone chime in if something is missing...
If I were you I'd generate the XORpad and then use 3DSFAT16tool to get the decrypted contents, then use it to reencrypt it to the 4.x keyslot (if that isn't what you're doing)
 
Last edited by dark_samus3,
If I were you I'd generate the XORpad and then use 3DSFAT16tool to get the decrypted contents, then use it to all reencrypt it to the 4.x keyslot (if that isn't what you're doing)

So, has anyone branched Decrypt9 to add the option to generate BOTH keyslot 0x4 and keyslot 0x5 xorpads?

I'm amazed at the amazing work done, and quick time from concept to realization just how powerful this is (direct Arm9 coldboot).
 
If I were you I'd generate the XORpad and then use 3DSFAT16tool to get the decrypted contents, then use it to reencrypt it to the 4.x keyslot (if that isn't what you're doing)
Yeah i was using 3DSFAT16Tool and padxorer to do it all.

--------------------- MERGED ---------------------------

So, has anyone branched Decrypt9 to add the option to generate BOTH keyslot 0x4 and keyslot 0x5 xorpads?

I'm amazed at the amazing work done, and quick time from concept to realization just how powerful this is (direct Arm9 coldboot).
Yeah d0k3 added it earlier. no extra branch needed. :)
 
So, has anyone branched Decrypt9 to add the option to generate BOTH keyslot 0x4 and keyslot 0x5 xorpads?

I'm amazed at the amazing work done, and quick time from concept to realization just how powerful this is (direct Arm9 coldboot).
yeah, it's already in d0k3's fork (just hasn't been released yet)
 
I wouldn't say progressing lol
Can't get a9lh to boot anything on my o3ds and n3ds refuses to boot frankenNAND. haha :P
But still an experience all the same. :)
Well you're all getting closer :P Question, on your n3ds nand, what process have you gone through?
 
I wouldn't say progressing lol
Can't get a9lh to boot anything on my o3ds and n3ds refuses to boot frankenNAND. haha :P
But still an experience all the same. :)
So wait, are you messing with the XORpad AFTER you downgrade or BEFORE you downgrade? Before isn't recommended, after is what you should be doing...
 
Success! Downgraded with sysupdater without fail to 2.xU. Time to dump my OTP. By the way, guys. Since arm9loaderhax works on 10.5, could I just update after getting my OTP and install it on 10.5?
 
So wait, are you messing with the XORpad AFTER you downgrade or BEFORE you downgrade? Before isn't recommended, after is what you should be doing...
After downgrade of course. They were created before though.

Well you're all getting closer :P Question, on your n3ds nand, what process have you gone through?
This process... https://gbatemp.net/threads/arm9loader-technical-details-and-discussion.408537/page-17#post-6077644 probably missing something no doubt.
 
I'm assuming you can't just downgrade you emunand to 1.0 to dump the OTP? Also there is a N3DS exclusive method I heard about in which you don't have to downgrade at all (so no brick risk) to get the OTP. Please correct me if I'm wrong. All these developments are so exciting!
 
Success! Downgraded with sysupdater without fail to 2.xU. Time to dump my OTP. By the way, guys. Since arm9loaderhax works on 10.5, could I just update after getting my OTP and install it on 10.5?
Yep, and as long as you never update NATIVE_FIRM you can continue to update sysNAND to the latest FW and then just use the corresponding firmware.bin

--------------------- MERGED ---------------------------

I'm assuming you can't just downgrade you emunand to 1.0 to dump the OTP? Also there is a N3DS exclusive method I heard about in which you don't have to downgrade at all (so no brick risk) to get the OTP. Please correct me if I'm wrong. All these developments are so exciting!
Well the problem is the protection bit is already set, so booting <3.0 firm is useless... Also, this isn't really known, but you need extra hardware and about 2-3 DAYS for the key bruteforce to work (take that from shinyquag and dazzozo, not me)
 
  • Like
Reactions: mungry
Well the problem is the protection bit is already set, so booting <3.0 firm is useless... Also, this isn't really known, but you need extra hardware and about 2-3 DAYS for the key bruteforce to work (take that from shinyquag and dazzozo, not me)

Hmmmm well now is probably the time to get a hard mod done on my N3DS hahaa...
 

Site & Scene News

Popular threads in this forum