Homebrew ARM9Loader -- Technical Details and Discussion

  • Thread starter Thread starter Selver
  • Start date Start date
  • Views Views 579,233
  • Replies Replies 4,025
  • Likes Likes 42
Did you get anything to actually LOAD though? :P
Not yet. Not sure how to make my own payload (The people as #cakey were telling me how but I don't grasp the simple fundamentals for I don't have knowledge in that area..) so I'd need someone to get me a payload to do something like load cakefw. :P
 
Not yet. Not sure how to make my own payload (The people as #cakey were telling me how but I don't grasp the simple fundamentals for I don't have knowledge in that area..) so I'd need someone to get me a payload to do something like load cakefw. :P
According to MassExplosion213, any CakeHax payload should work extracted from 0x12000 onward, so here's Cakes.dat given that very treatment, just remake to arm9loadhax.bin. You'll probably want the config set to autoboot, unless you want to blindly flick through the menus :P
 

Attachments

According to MassExplosion213, any CakeHax payload should work extracted from 0x12000 onward, so here's Cakes.dat given that very treatment, just remake to arm9loadhax.bin. You'll probably want the config set to autoboot, unless you want to blindly flick through the menus :P
So I put this in the root, correct? :P
 
Has anyone done this successfully on a o3DS? I think I read before to use all the same files as the n3DS which sounded funny to me since it includes the n3DS firmware files but hey I have a hardmod so I tried it anyway. It doesn't work. First the homebrew to install doesn't work just freezes at some screen about preparing the arm9 (without changing anything since the 3DS still works after a reboot)

So I tried manually installing the files in a nand.bin image (using knowledge from playing around with the 10.5-10.3 downgrade to replace the firm partitions and be properly encrypted and a hex editor for the other two files)

That just boots straight to the blue bootrom screen which is no good but better then I expected from using n3DS firm partitions.
 
Has anyone done this successfully on a o3DS? I think I read before to use all the same files as the n3DS which sounded funny to me since it includes the n3DS firmware files but hey I have a hardmod so I tried it anyway. It doesn't work. First the homebrew to install doesn't work just freezes at some screen about preparing the arm9 (without changing anything since the 3DS still works after a reboot)

So I tried manually installing the files in a nand.bin image (using knowledge from playing around with the 10.5-10.3 downgrade to replace the firm partitions and be properly encrypted and a hex editor for the other two files)

That just boots straight to the blue bootrom screen which is no good but better then I expected from using n3DS firm partitions.
Well it's arm9loaderhax.... the arm9loader binary is at the beginning of the n3ds firms so, yeah, n3ds firms are kinda needed since, ya know, without them there's nothing to hack :P
 
Noob here, just wanted to understand some stuff about arm9loaderhax explained as noob friendly as possible:

1) I watched the 32C3 conference video and understand that by finding out certain keys you can get arm9 access and that nintendo did an apparently terrible job fixing it but wouldnt it be possible that they could change the ways keys are handled in a future firmware update and block this exploit?

2) Does coldboot arm9 mean that you could install unsigned cias directly to the 3ds instead of using emunand and isnt this dangerous considering you dont have an emunand to fall back on?

3) If I understand correctly cubic ninja and oot are used to downgrade to <3.0 as the other exploits arent available on lower FW so some devs are trying to find another entrypoint. I have ironfall and i know its been patched on higher FW and id like to know why the game wouldnt work on a lower FW (If you didnt do a system format before downgrading of course)
 
1) I watched the 32C3 conference video and understand that by finding out certain keys you can get arm9 access and that nintendo did an apparently terrible job fixing it but wouldnt it be possible that they could change the ways keys are handled in a future firmware update and block this exploit?
There's only a certain number of keys on the 3DS, and all of them have been made public, and the way these keys are written, they can't be changed or updated by software. The only fix is to change the hardware, and even if they come out with a new hardware revision, that still leaves every current N3DS exploitable forever.
2) Does coldboot arm9 mean that you could install unsigned cias directly to the 3ds instead of using emunand and isnt this dangerous considering you dont have an emunand to fall back on?
Arm9loaderhax runs before even the 3DS kernel starts. If you brick your sysNAND, you can still run ARM9 payloads, so it's easy to restore a backup, or even reinstall a new upgrade pack.
3) If I understand correctly cubic ninja and oot are used to downgrade to <3.0 as the other exploits arent available on lower FW so some devs are trying to find another entrypoint. I have ironfall and i know its been patched on higher FW and id like to know why the game wouldnt work on a lower FW (If you didnt do a system format before downgrading of course)
CN and OoT aren't used to downgrade, sysUpdater is used to downgrade. CN and OoT are used to execute code with enough privileges to run ARM9 code once you've downgraded to 2.x, because currently there's no other way to do so (though that may change very soon). Ironfall won't work on lower firmwares because the game depends on newer firmwares.
 
Noob here, just wanted to understand some stuff about arm9loaderhax explained as noob friendly as possible:

1) I watched the 32C3 conference video and understand that by finding out certain keys you can get arm9 access and that nintendo did an apparently terrible job fixing it but wouldnt it be possible that they could change the ways keys are handled in a future firmware update and block this exploit?

2) Does coldboot arm9 mean that you could install unsigned cias directly to the 3ds instead of using emunand and isnt this dangerous considering you dont have an emunand to fall back on?

3) If I understand correctly cubic ninja and oot are used to downgrade to <3.0 as the other exploits arent available on lower FW so some devs are trying to find another entrypoint. I have ironfall and i know its been patched on higher FW and id like to know why the game wouldnt work on a lower FW (If you didnt do a system format before downgrading of course)
1) This isn't really about finding keys... also given that they don't have any other secret sectors (which MUST be installed at the factory) no this isn't patchable

2) yes, it does mean installing CIAs on sysNAND (which is already possible btw)... also since we can launch other payloads so early we can just restore NAND.bin files even if the system is totally broken by just replacing the arm9loaderhax.bin on the SD card with something that can restore NAND backups (like Decrypt9)

3) The devs are finding exploits in the browser, so given that we can choose what we have when we downgrade we can easily have browser once it's figured out (they've gotten further along already) also ironfall won't boot on anything lower than 9.5 iirc ( I know for sure it won't boot on 9.4 or below it's just 9.5 I'm not sure about)
 
  • Like
Reactions: TaintedByte

Site & Scene News

Popular threads in this forum