Hacking Could "Downgrade Play" be possible?

I pwned U!

I am pleased to beat you!
OP
Member
Joined
Jun 14, 2013
Messages
927
Trophies
3
Age
28
Website
gbatemp.net
XP
684
Country
United States
I have a friend who did not receive the news in time about not updating past 9.2.0. He is currently at 9.4.0.

After reading these threads about Download Play updates and installing older system title .cia files with spoofed versions to SysNAND not causing failed signature checks and allowing a 3DS to boot up properly, it made me wonder, could a ROM rebuilt with a 9.2.0 update (spoofed as one with higher versions of the titles with patched exploits using a program such as 3DNUS) and a local multiplayer mode allow me to downgrade his 3DS over Download Play with a spoofed "update?" Or would changing the update partition (even with properly signed firmware) change the game's signature and prevent his 3DS from detecting the game and/or installing the "update?"

If someone with NAND hardmods and more than one 3DS could test this out, that would be very helpful!
 
  • Like
Reactions: The Cringe

NyaakoXD

( ͡° ͜ʖ ͡°)
Member
Joined
Dec 16, 2013
Messages
1,858
Trophies
2
Location
In your closet...
XP
3,663
Country
United States
Welp, nothing he can do about it now. If he had a 3DS with a USB hardmod and backed up his NAND before updating to 9.4, then he might be able to flash it back to the previous firmware he was on.
Best bet is to get another 3DS that is on a lower firmware.
 
  • Like
Reactions: Margen67

ground

Well-Known Member
Member
Joined
Mar 22, 2007
Messages
907
Trophies
0
XP
597
Country
Netherlands

TimeMuffin

Well-Known Member
Newcomer
Joined
Dec 16, 2014
Messages
75
Trophies
0
Location
Cyberspace
XP
136
Country
I have a friend who did not receive the news in time about not updating past 9.2.0. He is currently at 9.4.0.

After reading these threads about Download Play updates and installing older system title .cia files with spoofed versions to SysNAND not causing failed signature checks and allowing a 3DS to boot up properly, it made me wonder, could a ROM rebuilt with a 9.2.0 update (spoofed as one with higher versions of the titles with patched exploits using a program such as 3DNUS) and a local multiplayer mode allow me to downgrade his 3DS over Download Play with a spoofed "update?" Or would changing the update partition (even with properly signed firmware) change the game's signature and prevent his 3DS from detecting the game and/or installing the "update?"

If someone with NAND hardmods and more than one 3DS could test this out, that would be very helpful!


Only 3 things your friend can do now.

1) Get a Sky3DS
2) Swap out motherboards from one on ebay
3) Wait for Gateway to support higher firmware but that might be a while if ever.
 

NCDyson

Hello Boys...
Member
Joined
Nov 9, 2009
Messages
278
Trophies
1
XP
319
Country
United States
hmm i don't think that is how it works..... you can grab signatures from other games and hey still would be valid.

Uh, no, that is how it works. It's the whole reason you can't run devmenu, homebrew or hacked roms on sky3ds without an exploitable game. The signatures tell the system that the data is legit and that it's okay to execute the code. If you change the data, the key becomes invalid, and the console refuses to run the code.
 

ground

Well-Known Member
Member
Joined
Mar 22, 2007
Messages
907
Trophies
0
XP
597
Country
Netherlands
Uh, no, that is how it works. It's the whole reason you can't run devmenu, homebrew or hacked roms on sky3ds without an exploitable game. The signatures tell the system that the data is legit and that it's okay to execute the code. If you change the data, the key becomes invalid, and the console refuses to run the code.
Yeah i got that, but what i meant is that signatures can be created by ourself, we are also able to modify content in roms and run it.

example:
With the old gw fw we were able to modify rom contents and run it, but gw didn't patch the signature patch. So it technically it should be possible to add some own .cia's to an rom i think. The reason devmenu didn't work was because it was signed for developers 3ds's i thought .
 

Jasin

Active Member
Newcomer
Joined
Dec 10, 2013
Messages
36
Trophies
0
Age
45
XP
148
Country
United States
You can create your own signature but the 3DS will know it isn't a valid nintendo signature and reject it. If it was that easy. Someone could take over googles SSL cert.

But if you do that an go to https://www.google.com your browser will tell you it's not valid. Gateway might not care about the sig. But nintendo's firmware updater does.
 
  • Like
Reactions: ground

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    BigOnYa @ BigOnYa: My wife's doctor prescribed her a ointment for kne pain