Hacking Crediar just Released 3DSaveTool!

pachura

Well-Known Member
Member
Joined
Dec 9, 2006
Messages
566
Trophies
0
XP
240
Country
Tagg7 said:
Hold on... how did they figure out how to extract the XOR cipher? If implemented properly, a XOR key (especially 512(!) byte) should be computationally uncrackable. Sloppy security implementation yet again from Nintendo.
If you know both the unencrypted and the encrypted content, it is trivial to extract the XOR key.
Maybe they were able to do it because every save file has identical header ? There was a screenshot from some hex editor showing a file starting with characters "SAV" ...
 

Slowking

Well-Known Member
Member
Joined
Dec 31, 2006
Messages
1,403
Trophies
0
XP
260
Country
Germany
pachura said:
If you know both the unencrypted and the encrypted content, it is trivial to extract the XOR key.
Maybe they were able to do it because every save file has identical header ? There was a screenshot from some hex editor showing a file starting with characters "SAV" ...
Crediar said it was because the saves contain a lot of zeros. I guess that's to be expected if you have a fixed save file size but games that don't have much save data. Nintendo should really have filled that up with garbage data, or you know, used something secure like AES. XD
 

Slowking

Well-Known Member
Member
Joined
Dec 31, 2006
Messages
1,403
Trophies
0
XP
260
Country
Germany
Keva said:
I'm not sure I understand the full implications of this but how close are we to seeing "hello world"?
Weeeell. You still need to understand how shit works first and then you need a buffer overflow in the savegame parsing of a game.
Since the 3DS is pretty close in structure to Wii and DSi the hackers might know enough to get some code executed with only an exploit in a game, without knowing too much else about the console. But I can't say for sure.
Ofcourse it is hard to find an exploit if you are not in the system yet, since you can't watch what is happening when the game reads saves.

Anyway it will still take some time. The 3DS saves are now at the stage where Wii and DSi saves were from the beginning.

That is ofcourse assuming that the 3DS doesn't run things in a hypervisor that checks if all executed code is properly signed, like the 360. But seeing how shoddy the save file security is, it probably doesn't.
 

notmeanymore

Well-Known Member
Member
Joined
Nov 29, 2009
Messages
2,700
Trophies
1
XP
711
Country
United States
I hope if a Buffer overflow is discovered, it's only announced and made public in May. Which would allow for 2 great possibilities:
1. Nintendo doesn't fix it in the May update because they simply didn't know in time.
2. Nintendo preempts us and fixes it before it's even announced(which would let people who are still pre-May update stay hackable, if willing to sacrifice eShop and the other features).
 

jan777

motion control..? srsly? so 2008. 3DS is teh bombz
Member
Joined
Jan 4, 2008
Messages
2,835
Trophies
1
Age
29
XP
878
Country
TehSkull said:
I hope if a Buffer overflow is discovered, it's only announced and made public in May. Which would allow for 2 great possibilities:
1. Nintendo doesn't fix it in the May update because they simply didn't know in time.
2. Nintendo preempts us and fixes it before it's even announced(which would let people who are still pre-May update stay hackable, if willing to sacrifice eShop and the other features).

Well, they could fix it with a June update.
 

Relys

^(Software | Hardware) Exploit? Development.$
Member
Joined
Jan 5, 2007
Messages
878
Trophies
1
XP
1,239
Country
United States
Ugh, it's getting kind of annoying to read these completely clueless messages about hacking over and over again. There's only like three people over the course of the last week that have posted on this forum that know what they're talking about. The rest are a bunch of pirates (you), who keep using big hacker words like buffer overflow without having the vaguest clue what it actually means.
 

Fear Zoa

Still Alive
Member
Joined
Jun 18, 2009
Messages
1,437
Trophies
0
Age
30
Location
Maryland
XP
505
Country
United States
Relys said:
Ugh, it's getting kind of annoying to read these completely clueless messages about hacking over and over again. There's only like three people over the course of the last week that have posted on this forum that know what they're talking about. The rest are a bunch of pirates (you), who keep using big hacker words like buffer overflow without having the vaguest clue what it actually means.
That and everyone keeps asking if they should buy ridge racer....
 
D

Deleted_171835

Guest
Relys said:
Ugh, it's getting kind of annoying to read these completely clueless messages about hacking over and over again. There's only like three people over the course of the last week that have posted on this forum that know what they're talking about. The rest are a bunch of pirates (you), who keep using big hacker words like buffer overflow without having the vaguest clue what it actually means.
After a while, you come to expect this kind of stuff from GBAtemp.
 

Rydian

Resident Furvert™
Member
Joined
Feb 4, 2010
Messages
27,880
Trophies
0
Age
36
Location
Cave Entrance, Watching Cyan Write Letters
Website
rydian.net
XP
9,111
Country
United States
Relys said:
Ugh, it's getting kind of annoying to read these completely clueless messages about hacking over and over again. There's only like three people over the course of the last week that have posted on this forum that know what they're talking about. The rest are a bunch of pirates (you), who keep using big hacker words like buffer overflow without having the vaguest clue what it actually means.
BolweevilWhy are we so consistently surprised when people are wrong about things? Being wrong is part of the learning process.

Nobody is expected to know everything, especially things that don't concern them, or directly affect their lives. They have no need to.

Misconceptions about trivial things are extremely common, and they persist when people who know better would rather make fun of them behind their backs instead of correct them so that next time the subject comes up they can avoid making the same mistake.

People only know what they're told. They fill in the gaps by guessing. It's normal. We've all done it at some point in our lives.
Buffer/stack overflow attacks are what's commonly discussed, most save exploits use them (or hunts start by looking for them), and the PS3's initial public hacking was due to one, so that's what's in most people's minds. If you're tired of people not knowing things, attempt to fix it instead of shut them up. Having a curiosity about these things is a good thing, and it's not like the big names in the hacking scene came out of the womb knowing the stuff they do. People need to start somewhere.

If you're willing to write a guide on this type of thing (such as Wololo's guides for the PSP scene attempt to do) I for one would welcome it, and would be willing to help you format it properly (or re-word things if needed) to make the guide as newbie-friendly as possible (and of course get it stickied in the appropiate forum). After all, the proper approach to the lack of education is education.

Otherwise quit'yer'bitchin'kthx.
 

Xuphor

I have lied to all of you. I am deeply sorry.
Banned
Joined
Jul 14, 2007
Messages
1,681
Trophies
0
Age
36
Location
USA
XP
1,470
Country
United States
Relys said:
Ugh, it's getting kind of annoying to read these completely clueless messages about hacking over and over again. There's only like three people over the course of the last week that have posted on this forum that know what they're talking about. The rest are a bunch of pirates (you), who keep using big hacker words like buffer overflow without having the vaguest clue what it actually means.

That is why I just read these type of threads. Check my post history, I post a lot, but never in true hacking threads, unless something like this comes up.
There are some people like me (just pirates, not hackers), that post in almost every thread EXCEPT these, unless a stereotype is thrown in our faces.

So please, there are some people like me here, who admit they know next to nothing about hacking and just read these threads without posting, so don't lump all us into the one category of useless spammers, thank you.
yaynds.gif
 

RNorthex

Well-Known Member
Member
Joined
Nov 22, 2010
Messages
443
Trophies
0
XP
209
Country
United States
Xuphor said:
Relys said:
Ugh, it's getting kind of annoying to read these completely clueless messages about hacking over and over again. There's only like three people over the course of the last week that have posted on this forum that know what they're talking about. The rest are a bunch of pirates (you), who keep using big hacker words like buffer overflow without having the vaguest clue what it actually means.

That is why I just read these type of threads. Check my post history, I post a lot, but never in true hacking threads, unless something like this comes up.
There are some people like me (just pirates, not hackers), that post in almost every thread EXCEPT these unless a stereotype is thrown in our faces.

So please, there are some people like me here, who admit they know next to nothing about hacking and just read these threads without posting, so don't lump all us into the one category of useless spammers, thank you.
yaynds.gif

almost the same
i mean, i don't really post anything, just because i got basic knowledge[can somewhat understand what's going on]
and dun wanna write stupid things

and i welcome any explanation as well, it would be a shame not to be a pro hacker after i finish studying programming in university xD
atm i'm still stuck watching failoverflow's ps3 hack explanation

so, not all of us will ask if we should buy ridge racer
biggrin.gif
 

KazoWAR

Well-Known Member
Member
Joined
Aug 12, 2008
Messages
1,952
Trophies
1
Age
35
Location
Winter Haven
XP
2,134
Country
United States
This could be good news for getting some kind of 3DS Mode homebrew running. If a save exploit is ever discovered in a 3DS game. It wont end like to Sudoku since there are already millions of copies of the game in circulation.
 

junn

.
Member
Joined
Sep 12, 2009
Messages
387
Trophies
0
Location
.
Website
flic.kr
XP
207
Country
United States
Cyan said:
Zorua said:
spiritofcat said:
Won't run on my computer, complains about not being able to find msvcp100.dll

Download it from this website and copy it to the same directory as the tool.
It's not enough :/
I put the .dll in the same folder as the .exe, and now I have another error:

Entry point not found.
??1_NonReentrantPPLLockHolder@details@Concurrency@@QAE@XZ can't be found in the dynamic library MSVCR100.dll

(the MSVCR100.dll is the one provided in Crediar's archive).
I'm on Windows XP SP2, .net 3.5
got the same problem.
manually registering the dll doesn't work for me.
the fix is,install the Microsoft Visual C++ 2010 Redistributable Package.
http://www.microsoft.com/downloads/en/deta...23-37bf0912db84
3dsavetool.png
 

Slowking

Well-Known Member
Member
Joined
Dec 31, 2006
Messages
1,403
Trophies
0
XP
260
Country
Germany
A Gay Little Catboy said:
I really hope this can't be used for cheating
Ofcourse it can. Unless they change the encryption, there will be a new pokesave once Pokemon3D is out, for example.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • AncientBoi @ AncientBoi:
    ooowwww a new way for me to beat NFS 510 :D @SylverReZ
    +1
  • SylverReZ @ SylverReZ:
    @AncientBoi, Yeah, believe you can do PSP games as well. But a Pi5 is much powerful in comparison.
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    Not sure about other models of Pi4 but the Pi 4 B with 8GBs OCed to 2Ghz handles PSP really great except like 1 game I found and it is playable it just looks bad lol Motor Storm Arctic something or other.
  • Psionic Roshambo @ Psionic Roshambo:
    Other games I can have turned up to like 2X and all kinds of enhancements, Motorstorm hmmm nope 1X and no enhancements lol
  • Veho @ Veho:
    Waiting for Anbernic's rg[whatever]SP price announcement, gimme.
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    I will admit that one does seem more interesting than the usual Ambernic ones, and I already liked those.
  • Veho @ Veho:
    I dread the price point.
    +1
  • Veho @ Veho:
    This looks like one of their premium models, so... $150 :glare:
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    To me that seems reasonable.
  • Psionic Roshambo @ Psionic Roshambo:
    I mean since basically all the games are errmmm free lol
  • Veho @ Veho:
    I mean yeah sure but the specs are the same as a $50 model, it's just those pesky "quality of life" things driving up the price, like an actually working speaker, or buttons that don't melt, and stuff like that.
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    I think all in my Pi 4 was well north of 200 bucks 150ish for the Pi 4 the case the fancy cooler, then like 70 for the 500GB MicroSD then like 70 for the Xbox controller. But honestly it's a nice set up I really enjoy and to me was worth every penny. (even bought more controllers for 2 or 4 player games.) hmmm have never played any 2 player games yet :(
  • Veho @ Veho:
    Yeah that's what I hate about the RPi, it's supposedly $30 or something but it takes an additional $200 of accessories to actually turn it into a working something.
  • Psionic Roshambo @ Psionic Roshambo:
    yes that's the expensive part lol
  • Veho @ Veho:
    I mean sure it's flexible and stuff but so is uremum but it's fiddly.
  • Psionic Roshambo @ Psionic Roshambo:
    Yeah a lot of it I consider a hobby, using Batocera I am constantly adjusting the collection adding and removing stuff, scraping the artwork. Haven't even started on some music for the theme... Also way down the road I am considering attempting to do a WiiFlow knock off lol
  • Veho @ Veho:
    I want everything served on a plate plz ktnx, "work" is too much work for me.
  • Veho @ Veho:
    Hmm, with that in mind, maybe a complete out-the-box solution with all the games collected, pacthed and optimized for me would be worth $150 :unsure:
  • Psionic Roshambo @ Psionic Roshambo:
    Yeah it's all choice and that's a good thing :)
  • Bunjolio @ Bunjolio:
    animal crossing new leaf 11pm music
  • Bunjolio @ Bunjolio:
    avatars-kKKZnC8XiW7HEUw0-KdJMsw-t1080x1080.jpg
    wokey d pronouns
  • SylverReZ @ SylverReZ:
    What its like to do online shopping in 1998: https://www.youtube.com/watch?v=vwag5XE8oJo
    SylverReZ @ SylverReZ: What its like to do online shopping in 1998: https://www.youtube.com/watch?v=vwag5XE8oJo