Hacking DSi hacking method?

cracker

Nyah!
OP
Member
Joined
Aug 24, 2005
Messages
3,619
Trophies
1
XP
2,213
Country
United States
I was just reading through other threads on the progress of DSi hacking and something occurred to me. I don't have a DSi so I can't do any of the testing myself. :/ I am thinking that it might be possible to add code to boot a flash cart by injecting code into the decrypted download play ROM and then re-encrypting it and sending it from a DS/Lite. Has anyone attempted this?
 

playallday

Group: GBAtemp Ghost
Member
Joined
May 23, 2008
Messages
3,767
Trophies
1
Location
[@N@[)@
Website
Visit site
XP
494
Country
Canada
I was thinking to use the hack we know about (or some do
frown.gif
) and use it to boot the slot-1. Just my idea.
 

cracker

Nyah!
OP
Member
Joined
Aug 24, 2005
Messages
3,619
Trophies
1
XP
2,213
Country
United States
It never hurts to have more than one type of exploit.
smile.gif
I was just sharing an idea for those who have the means to attempt hacking the DSi. It wouldn't be good for the longterm because you would always need a DS/Lite to boot it up but it might be useful for some type of firmware meddling and figuring out how to get games to boot, etc.
 

cracker

Nyah!
OP
Member
Joined
Aug 24, 2005
Messages
3,619
Trophies
1
XP
2,213
Country
United States
That's basically what I meant. Instead of the demo or multiplayer sharing it would execute code to bypass the check and boot the flash cart up.
 

gamefreakfatty

Active Member
Newcomer
Joined
Dec 28, 2006
Messages
28
Trophies
0
XP
227
Country
United States
Not sure if it helps, but a post i did in another thread:

gamefreakfatty said:
Okay, I don't know if this has been brought up before or not. From what I know, R4DS/M3Simply, other carts of the time, and more modern carts all used the same NoPass method to get the DS/DSL to boot them up without the need of another (legit/licensed) game. This (NoPass) method was discovered/developed/designed/whatever by the developer of no$gba and the other nocash projects, Martin. He dumped the BIOS (or whatever code was used) for the DS (or DSL) and managed to find the code that is used to determine whether or not the inserted cartridge is a legit/licensed one. Honestly, I probably don't know enough to help out with the situation, although I thought I would put this out there as a possibility.


Here are some things that might help:

Does anyone know if the (known/public?) method was missing part of the routine which was not necessarily used in the DS/DSL units but is now used in the DSi?

Has anyone attempted, or better yet, successfully dumped the BIOS (or whatever code is was previously dumped) in a form usable for disassembly and analysis of the code?


If we manage to dump the same portion of the code that Martin (developer of the nocash projects) dumped previously, we may be able to analyze the code and determine how the routine (for headers or whatever is used to determine whether or not the cart is legit) works.


That's just my 2 cents. Hope it helps, and good luck on getting this all sorted out!

-gamefreakfatty
 

Normmatt

Former AKAIO Programmer
Member
Joined
Dec 14, 2004
Messages
2,161
Trophies
1
Age
33
Website
normmatt.com
XP
2,193
Country
New Zealand
cracker said:
I was just reading through other threads on the progress of DSi hacking and something occurred to me. I don't have a DSi so I can't do any of the testing myself. :/ I am thinking that it might be possible to add code to boot a flash cart by injecting code into the decrypted download play ROM and then re-encrypting it and sending it from a DS/Lite. Has anyone attempted this?

We can't re-encrypt them, we don't know Nintendo's private key.
 

cracker

Nyah!
OP
Member
Joined
Aug 24, 2005
Messages
3,619
Trophies
1
XP
2,213
Country
United States
Normmatt said:
cracker said:
I was just reading through other threads on the progress of DSi hacking and something occurred to me. I don't have a DSi so I can't do any of the testing myself. :/ I am thinking that it might be possible to add code to boot a flash cart by injecting code into the decrypted download play ROM and then re-encrypting it and sending it from a DS/Lite. Has anyone attempted this?

We can't re-encrypt them, we don't know Nintendo's private key.

Hmmm yeah that would prove a problem. :/ (I don't know much about encryption/decryption... Does it show?
ph34r.gif
)
 

cracker

Nyah!
OP
Member
Joined
Aug 24, 2005
Messages
3,619
Trophies
1
XP
2,213
Country
United States
That would require a corrupted FAT table on the SD card or something. As for the flash cart it would probably need its code overwritten and rendered useless besides being able to boot the DS into a different mode.
blink.gif
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    SylverReZ @ SylverReZ: @salazarcosplay, Good.