Hacking CFW on downgraded SysNAND - Thread

  • Thread starter Thread starter ChrisX930
  • Start date Start date
  • Views Views 14,242
  • Replies Replies 67
  • Likes Likes 4
Managed to get the 4.x CFW installed on a downgraded XL from 9.2.
Cubic Ninja refuses to load off of it as a CIA, however.
 
Where you able to install CIA and devmenu?

Both DevMenu and BigBlueMenu installed fine and dandy (the *.db trick didn't work; luckily I backed up my eShop titles).
Tested Cubic Ninja first, but I either get an error about the SD card being removed, a black screen, or the splash screen hanging.

Did you use the red Gateway card? Do other CIA files work? TBH, I'm not going to try this till a noob friendly guide is made.

While I do have it, I didn't use it one bit (defective cart, so I can't really use it). Haven't delved with cia's yet, but they do install.
Used https://gbatemp.net/threads/4-x-only-cia-cfw-complete-guide.373532/page-11#post-5145746

And a tip: CFW seems to not launch if you don't let your home menu fully load up.
 
Both DevMenu and BigBlueMenu installed fine and dandy (the *.db trick didn't work; luckily I backed up my eShop titles).
Tested Cubic Ninja first, but I either get an error about the SD card being removed, a black screen, or the splash screen hanging.



While I do have it, I didn't use it one bit (defective cart, so I can't really use it). Haven't delved with cia's yet, but they do install.
Used https://gbatemp.net/threads/4-x-only-cia-cfw-complete-guide.373532/page-11#post-5145746

And a tip: CFW seems to not launch if you don't let your home menu fully load up.

Have other CIA games worked though? If they have I'll try it out.
 
Both DevMenu and BigBlueMenu installed fine and dandy (the *.db trick didn't work; luckily I backed up my eShop titles).
Tested Cubic Ninja first, but I either get an error about the SD card being removed, a black screen, or the splash screen hanging.



While I do have it, I didn't use it one bit (defective cart, so I can't really use it). Haven't delved with cia's yet, but they do install.
Used https://gbatemp.net/threads/4-x-only-cia-cfw-complete-guide.373532/page-11#post-5145746

And a tip: CFW seems to not launch if you don't let your home menu fully load up.

Two more things did you do all this without using any type of flash card or gateway card and can you write up a simple tutorial on your steps either here or by making a new thread.
 
Two more things did you do all this without using any type of flash card or gateway card and can you write up a simple tutorial on your steps either here or by making a new thread.

Just follow the steps in the thread that he/she linked to.
 
Hey guys, just wanted to ask. Is it normal that when I move my icons around on 9.4 emuNAND, they get moved around on 4.5 sysNAND too, and vice-versa?
I'm pretty sure they were unlinked before I downgraded.

EDIT: Oh god sorry, wrong thread!! D :
 
Have other CIA games worked though? If they have I'll try it out.

Retail games? Getting ready to make my own CIA, so I'll report back if it works.
Homebrew? BlargSNES, GameYob, and CitrAGB all works.

Two more things did you do all this without using any type of flash card or gateway card and can you write up a simple tutorial on your steps either here or by making a new thread.

You must have some form of DS flashcart (you might get lucky and use a Gateway-encrypted launcher.dat and use the browser exploit to load it if you're on 4.5, but I, for the hell of it, tried to use GW2.7's launcher.dat and it consistently failed). Other than that, you still need a flashcart (at least it's a DS flashcart, and on 4.x of all system versions).

Basically, I:
- backed up system's SD card
- downgraded (obviously)
- configured the microSD card for the blue card (using 3.0.1's blue card files) to install the mset exploit
- used the blue card
- formatted emuNAND
- copied Launcher_GW.dat to the root of the system's SD card (renamed as Launcher.dat)
- used emuNAND tool to back up the emuNAND (not necessarily a backup, but it's needed for making redNAND; you can use your 4.x NAND backup if you want)
- used drag_emunand_here.bat (in the linked post) to create redNAND
- used emuNAND_tool to inject redNAND into emuNAND
- copied system's SD card's backup back up onto the SD card (since the *.db trick failed for me)
- went into DS Profile to trigger the exploit (while holding L) to boot into redNAND with the ctrserver going on a limb it's called that, since there's ctrclient
- used wnetwatcher to find my system's IP (I configured a static IP, but I did that after the emuNAND backup)
- executed run.bat with corrected parameters
- enjoyed the DevMenu/BigBlueMenu goodness

Needed the Palatine's CFW pack, emuNAND_tool, and the redNAND maker (drag_emunand_here). No need for win32diskimager or hex editing.
 
Just out of curiosity I tried running Gateway's 2.7 Launcher using their browser exploit and it also didn't launch. So the 3.0 launcher and browser exploit are definitely using something new and incompatible with previous Launcher.dat files.
 
dude, look into your boot.bin.
Here's the part I mean


and goeanify.x10host.com is down, it seems


EDIT: Downloaded the files from govanify.com, created a server with the same length of characters, edited boot.bin with hex editor. nothing changed, god damned. thought i found the problem

You made a new nand backup of your 4.x firmware in hex editor instead of reusing the nand backup used when downgrading right? That could be the problem.
 
Retail games? Getting ready to make my own CIA, so I'll report back if it works.
Homebrew? BlargSNES, GameYob, and CitrAGB all works.



You must have some form of DS flashcart (you might get lucky and use a Gateway-encrypted launcher.dat and use the browser exploit to load it if you're on 4.5, but I, for the hell of it, tried to use GW2.7's launcher.dat and it consistently failed). Other than that, you still need a flashcart (at least it's a DS flashcart, and on 4.x of all system versions).

Basically, I:
- backed up system's SD card
- downgraded (obviously)
- configured the microSD card for the blue card (using 3.0.1's blue card files) to install the mset exploit
- used the blue card
- formatted emuNAND
- copied Launcher_GW.dat to the root of the system's SD card (renamed as Launcher.dat)
- used emuNAND tool to back up the emuNAND (not necessarily a backup, but it's needed for making redNAND; you can use your 4.x NAND backup if you want)
- used drag_emunand_here.bat (in the linked post) to create redNAND
- used emuNAND_tool to inject redNAND into emuNAND
- copied system's SD card's backup back up onto the SD card (since the *.db trick failed for me)
- went into DS Profile to trigger the exploit (while holding L) to boot into redNAND with the ctrserver going on a limb it's called that, since there's ctrclient
- used wnetwatcher to find my system's IP (I configured a static IP, but I did that after the emuNAND backup)
- executed run.bat with corrected parameters
- enjoyed the DevMenu/BigBlueMenu goodness

Needed the Palatine's CFW pack, emuNAND_tool, and the redNAND maker (drag_emunand_here). No need for win32diskimager or hex editing.

ok so you can instal .cia on the rednand now, but which ones will run ? any retail game .cias? all retail game .cias? , only ones that require lower fw? which ones?
 
OKay, now I was able to went back into the System Menu while using the renamed launcher_GW.dat from Palantine CFW.
The Buttomscreen flickered white and black and after ~4seconds I was back in the Main Menu (Held down "L" while starting DS Profile and boot).
Now I tried to use the run.exe (with the IP of the 3DS) but there's: "ctrclient: failed to connect". Why?
Do I need to open some specific Ports first?
 
Just out of curiosity I tried running Gateway's 2.7 Launcher using their browser exploit and it also didn't launch. So the 3.0 launcher and browser exploit are definitely using something new and incompatible with previous Launcher.dat files.
It's my understanding that the Launcher_GW.dat that is used in the setup process is gateway's 1.0 launcher. The one that all the clones used. It was only after this that they began obfuscating efficiently.

If someone more knowledgeable can either confirm, deny or expand on what I've said that's be great. I've absorbed so much information about all of this stuff over the last few months. I'm bound to get my wires crossed every so often.
 
OKay, now I was able to went back into the System Menu while using the renamed launcher_GW.dat from Palantine CFW.
The Buttomscreen flickered white and black and after ~4seconds I was back in the Main Menu (Held down "L" while starting DS Profile and boot).
Now I tried to use the run.exe (with the IP of the 3DS) but there's: "ctrclient: failed to connect". Why?
Do I need to open some specific Ports first?

It sounds like emuNAND booted correctly, which is strange, because booting with the Gateway launcher didn't work for me. I had to use the super unstable launcher, but after 30-40 resets, it all finally worked. Just to be sure, I suggest making some folders on your SYSnand in order for you to tell the difference between the two, and to indicate to you that it didn't work. As far as installing the cia goes, that happened to me at first too. It turns out that the IP address I got from sysNAND is different from the IP address in emuNAND/CFW. You'll need to make sure that IP address is right first.
 

Site & Scene News

Popular threads in this forum