Homebrew ARM9Loader -- Technical Details and Discussion

  • Thread starter Thread starter Selver
  • Start date Start date
  • Views Views 579,206
  • Replies Replies 4,025
  • Likes Likes 42
I'm assuming you can't just downgrade you emunand to 1.0 to dump the OTP?

Correct. The processor has a memory region that is only readable at initial boot. Once a bit is set, the memory region is no longer readable until reboot (back to bootrom). Thus, because emuNAND does not reload bootrom, the memory region remains unreadable.

Also there is a N3DS exclusive method I heard about in which you don't have to downgrade at all (so no brick risk) to get the OTP.
The N3DS exclusive method I am aware of is brute-force, and requires a hardmod. Currently, it might still be faster than downgrading from 9.2, due to the number of soft-bricks. :) However, it is not recommended for anyone not ready to do some reverse engineering.
 
  • Like
Reactions: mungry
My only problem is that I don't have the proper files to dump my OTP. Could someone hand me some files?
 
I wouldn't say progressing lol
Can't get a9lh to boot anything on my o3ds and n3ds refuses to boot frankenNAND. haha :P
But still an experience all the same. :)
maybe arm9loader sets something up, the normal 3ds firmware has problems with, why it refuses do firmlaunch on o3DS. Maybe a key or something.
 
Does anyone know if you can use OOT, after downgrade to 2.x, with a sysnand format then the A+B+X+Y+R launch into OOT and exploit to dump OTP
 
Does anyone know if you can use OOT, after downgrade to 2.x, with a sysnand format then the A+B+X+Y+R launch into OOT and exploit to dump OTP
oot3dhax only has ARM9 support for 3.0-4.5. It could maybe work, if someone ported it down, but probably more effort than it's worth.
 
oot3dhax only has ARM9 support for 3.0-4.5. It could maybe work, if someone ported it down, but probably more effort than it's worth.
This. Browser is the way to go 100%, requires no fuckery other than loading a certain website with some files on the SD card
 
This. Browser is the way to go 100%, requires no fuckery other than loading a certain website with some files on the SD card
I'm not sure if the 2.x I'm running has the proper 2.x browser. I have browser version 1.7455. Does the browser version matter or can I run the browser exploit for 2.x even without the real 2.x browser?
 
Nope it just refuses to boot the frankenNAND. :(
It turns on but that's about it...
Anyway here's the process i was told and am following... someone chime in if something is missing...
alright, here's what's missing: you need the NCSD header from an o3ds NAND injected in place of your NAND's for the NATIVE_FIRM to recognize it
 
Finally dumped my OTP.bin. Turns out I needed to create a blank OTP.bin before running the payload lmao
 

Site & Scene News

Popular threads in this forum