[Defcon] Smea to give 3DS security talk and release free arm9 exploit chain on August 11

dc-25-logo.jpg


(complete video of the talk - uploaded Oct. 22, 2018)

UPDATE (10-23-18): This hack was patched on 11.8 and was never publicly implemented
Please use Frogminer -> Free B9S cfw, works on 11.8, covers all major regions

(disclosure: Frogminer is my hack, but it serves the same purpose smeahax originally promised, so it's relevant here)


It looks like our old 3DS scene pal @smealum has returned to the limelight! Famous for his groundbreaking Ninjhax, Ironhax, and Tubehax userland exploits, and the udsploit kernel11 hax, Smea is back and better than ever with a total of four new exploits set to be revealed this Saturday at Defcon 26 in Las Vegas! So if you never got on the CFW bandwagon (full control of your 3DS with all the implied benefits), you'd better come and tune in with us this Saturday at 11:00 am PT sharp!​

Slides and Additional Videos


MHAX userland
ROHAX2 priv. escalation
ZHAX kernel11
TWLHAX arm9

(please wait for the guide to be updated for instructions)
^ skeletonwaiting.gif

DkV77xzUcAACLnW.jpg


 
Last edited by zoogie,
Joined
Jan 1, 2018
Messages
7,292
Trophies
2
XP
5,946
Country
United States
How does NTRBoot not work for you? It's a bootrom expoit, there's no reason why it shouldn't work

Honestly I am more confused by the notion that NTRBoot isn't working for them. There's literally no reason for it not to be working if they did everything right

Here are two cases of ntrboot failure. Absolutely beyond a doubt user error was not the issue. Extremely rare, but it can happen.
 
  • Like
Reactions: Insane

Insane

Well-Known Member
Member
Joined
May 8, 2018
Messages
144
Trophies
0
XP
2,390
Country
Germany
But for him it is, because he cannot buy a flashcart or do online shopping in his country at all (e.g. Uruguay, Philipines). So no user error, but inability to get the hardware required. (Hence the proposal of hard-mod).
 
Last edited by Insane,
Joined
Jan 1, 2018
Messages
7,292
Trophies
2
XP
5,946
Country
United States
But for him it is, because he cannot buy a flashcart or do online shopping in his country at all (Mexico would be my guess for a country like that). So no user error, but inability to get the hardware required. (Hence the proposal of hard-mod).

Oh, that I read. We can't do much to help him with restrictions on acquiring hard goods.

I just wanted to inform that the ntrboot method is not failproof. I think I read one or two other accounts here, but those 3DS users never followed up with verifying end results on their ntrboot attempts.
 
  • Like
Reactions: Insane

Insane

Well-Known Member
Member
Joined
May 8, 2018
Messages
144
Trophies
0
XP
2,390
Country
Germany
Oh, that I read. We can't do much to help him with restrictions on acquiring hard goods.

I just wanted to inform that the ntrboot method is not failproof. I think I read one or two other accounts here, but those 3DS users never followed up with verifying end results on their ntrboot attempts.

Which is good mentioning! I just wanted to put the hardmod option out there, as I assume, that he/she can get this done at a random repair shop with a proper manual. At least with a hardmod nand backup he/she the chance of bricking due to user error are lower, as the backup can be restored without a booting 3ds.

I must say: I hacked like 15 3ds with the NTRBOOT method and never had an issue (okay I also did not have an issue with the "no downgrade" method when hacking the 3 new 3ds)
 
  • Like
Reactions: TurdPooCharger

jimmyj

Official founder of altariaism. Copyright jimmyj
Member
Joined
May 26, 2017
Messages
1,485
Trophies
1
Location
Hyrule
XP
1,632
Country
United Kingdom
why is it not being implemented though? I don't need it but it's nice for someone who can't buy a ntrboot cart
 
  • Like
Reactions: NoNAND

Blue

Well-Known Member
Member
Joined
Oct 2, 2015
Messages
2,606
Trophies
2
XP
1,060
Country
United Kingdom
For those still waiting around for this, I suggest just trying this instead.
https://jisagi.github.io/FrogminerGuide/

Totally free cfw on latest firm for all major regions US,EU,JP.

If you still want to hold out for twlhax etc.; be my guest, but no one is working on it to my knowledge.
Nice! Didn't know this was a thing, I had CFW for a while got banned on Sun/Moon early, uninstalled B9S and updated it and tried to sell it then neglected it for a few months. Luckily the ban didn't affect eshop so I can still get SteelDiver.
 
  • Like
Reactions: zoogie

Ryab

Well-Known Member
Member
Joined
Aug 9, 2017
Messages
3,239
Trophies
1
XP
4,472
Country
United States
Nice! Didn't know this was a thing, I had CFW for a while got banned on Sun/Moon early, uninstalled B9S and updated it and tried to sell it then neglected it for a few months. Luckily the ban didn't affect eshop so I can still get SteelDiver.
they most likely NNID banned you thats why
 

Blue

Well-Known Member
Member
Joined
Oct 2, 2015
Messages
2,606
Trophies
2
XP
1,060
Country
United Kingdom
they most likely NNID banned you thats why
Oh I messed up... I formatted it now (cause it kept giving connection errors) so I lost the NNID, now because of the NNID ban I can't link a new one. And Steel Diver requires a NNID to be installed :hateit:
 

Insane

Well-Known Member
Member
Joined
May 8, 2018
Messages
144
Trophies
0
XP
2,390
Country
Germany
why is it not being implemented though? I don't need it but it's nice for someone who can't buy a ntrboot cart

Well I believe the requirements for the exploit are: can't buy an NTRBoot card (which to be honest, you can get on nearly every street corner for 15$ or use your old DS card for that purpose) AND doesn't know anybody with an ntrboot card, cannot solder (otherwise we'd hardmod it) and on top of that did not update to 11.8. So I guess those 2 guys are out of luck.
 

SRKTiberious

Well-Known Member
Member
Joined
Sep 4, 2014
Messages
240
Trophies
0
Age
41
XP
404
Country
United States
So, I read through the frogminer tutorial, and the Steelminer bit seems to rely on someone else either getting a movable_part1 or for brute-forcing.

Is there a 'self-sufficient' method available? One where you can retrieve your own movable_part1.sed and brute-forcing it yourself?
 

zoogie

playing around in the end of life
OP
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,000
Country
Micronesia, Federated States of
So, I read through the frogminer tutorial, and the Steelminer bit seems to rely on someone else either getting a movable_part1 or for brute-forcing.

Is there a 'self-sufficient' method available? One where you can retrieve your own movable_part1.sed and brute-forcing it yourself?
The way the guide words it makes the process sound like a "social" experience when in practice it's really very automatic.
You put your info into this site https://bruteforcemovable.com/ and a few minutes later it spits out your movable.sed.
It's pretty easy.

You can bruteforce your own movable.sed but that process requires your own PC with a discrete GPU and a decent amount of computer literacy.
I would recommend the automatic way to almost everybody.
 

The Catboy

GBAtemp Official Catboy™: Boywife
Member
Joined
Sep 13, 2009
Messages
27,947
Trophies
4
Location
Making a non-binary fuss
XP
39,338
Country
Antarctica
why did smea leave it incomplete ?
Most likely because he actually already sold the code to Nintendo and chances are this is what he was allowed release. Literally just a shot in the dark, based on some evidence and speculation.
 
Last edited by The Catboy,
  • Like
Reactions: jimmyj

jimmyj

Official founder of altariaism. Copyright jimmyj
Member
Joined
May 26, 2017
Messages
1,485
Trophies
1
Location
Hyrule
XP
1,632
Country
United Kingdom
Most likely because he actually already sold the code Nintendo and chances are this is what he was allowed release. Literally just a shot in the dark, based on some evidence and speculation.
well I suppose frogminer will save all the other people and not twl hax anymore
 

zoogie

playing around in the end of life
OP
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,000
Country
Micronesia, Federated States of
First post updated with a youtube video of Smea's 3ds talk.

A reminder that what's shown in the video is still patched on latest firm and still not in a usable state.
But don't despair; if you want completely free cfw on latest firmware, this is still available: https://jisagi.github.io/FrogminerGuide/
 
Last edited by zoogie,

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    K3Nv2 @ K3Nv2: Like for micro