Dump xorpad of an installed .cia on RX3D 7.10-16U?

Discussion in '3DS - ROM Hacking, Translations and Utilities' started by manpaint, Oct 17, 2015.

  1. manpaint
    OP

    manpaint GBAtemp Regular

    Member
    237
    31
    Aug 20, 2014
    Canada
    I know for decrypt9 but apparently is only decrypting game card and i want to decrypt triforce hero demo.
     
  2. Asia81

    Asia81 In my Ecchi World <3

    Member
    5,147
    2,565
    Nov 15, 2014
    France
    Albi
    decrypt9 and sdpadgen with sdinfo.bin at the root of your sd card
     
  3. manpaint
    OP

    manpaint GBAtemp Regular

    Member
    237
    31
    Aug 20, 2014
    Canada
    I dont find the two other files.
     
  4. gudenau

    gudenau Largely ignored

    Member
    GBAtemp Patron
    gudenau is a Patron of GBAtemp and is helping us stay independent!

    Our Patreon
    3,300
    1,253
    Jul 7, 2010
    United States
    /dev/random
    Could you elaborate on how you generate said files?
     
  5. Asia81

    Asia81 In my Ecchi World <3

    Member
    5,147
    2,565
    Nov 15, 2014
    France
    Albi
    Install the Demo in your EmuNand (by dowloading from eShop).
    Use Decrypt9, go in EmuNand Tool (not the windows tool, it's in D9), dump the tickets.
    Dowload FunkyCIA2. Put the tickets_emu.db here.
    Open a CMD here and write:
    Code:
    python FunkyCIA2.py ticket_emu.db -title 0004000000182300
    Wait. Go in the cia folder, and take 0004000000182300.cia.
    Install it in your SysNand (with Pasta or another CFW in SysNand).
    Take the .app from the SysNand folder:
    G:\Nintendo 3DS\<ID1>\<ID2>\title\00040000\00182300\content\00000000.app
    Now dl my pack: https://gbatemp.net/threads/tutoria...d-3ds-roms-run-xy-oras-without-update.383055/
    Open th bat, write: sd -> d9 -> Now enter the path of your SysNand after the two ID folders (Make sure you have Python 2.7.7). For me it's:
    Code:
    G:\Nintendo 3DS\0537bed45e5fa36fb6427f70c2ef5a47\d61400f547802878534c313600035344
    Wait.
    Now put the sdinfo.bin t the root of your SD Card.
    Open Decrypt9 and use SD Padgen.
    Wait, a bunch of xorpads will be generated (or not).
    Take all xorpads with 0004000000182300 in the name.
    Delete all other xorpads
    Put .xorpads, .app in the same folder (my pack ?) and use padgen:
    Code:
    padxorer.exe FILENAME.app XORPADNAME.xorpad
    
    Or use my bat and write pad.
    Now you got FILENAME.app.out.
    Drag&Drop FILENAME.app.out on ctrKeyGen_Decrypt9.py.
    Copy the files slot0x25KeyX.bin and ncchinfo.bin at the root of you SD Card.
    Open Decrypt9 and use NCCH Padgen.
    Wait while creating Xorpads files.
    Once all Xorpads are generated, put your SD Card back into your PC, copy all Xorpads with your TitleID and the word in the folder of my pack.
    Launch HackingToolkit.bat, write SDK7 and follow.
     
  6. manpaint
    OP

    manpaint GBAtemp Regular

    Member
    237
    31
    Aug 20, 2014
    Canada
    I get nothing when i do the command (also my .cia is not downloaded from eshop)

    Edit: I found another of your tutorial to decrypt cia but i need /movable.sed for use decrypt9
     
    Last edited by manpaint, Oct 18, 2015
  7. gudenau

    gudenau Largely ignored

    Member
    GBAtemp Patron
    gudenau is a Patron of GBAtemp and is helping us stay independent!

    Our Patreon
    3,300
    1,253
    Jul 7, 2010
    United States
    /dev/random
    I think that is in the nand; so dump the nand, decrypt the fat16 partition, mount the image, then find movable.sed.
     
  8. The Real Jdbye

    The Real Jdbye Always Remember 30/07/08

    Member
    GBAtemp Patron
    The Real Jdbye is a Patron of GBAtemp and is helping us stay independent!

    Our Patreon
    12,486
    5,461
    Mar 17, 2010
    Norway
    Alola
    I don't think that will work because the Triforce Heroes demo uses seeddb so the decryption process is slightly different.
     
  9. I8UrMum
    This message by I8UrMum has been removed from public view by Veho, Oct 18, 2015, Reason: This is an English speaking forum.
    Oct 18, 2015
  10. Shadowtrance

    Shadowtrance GBAtemp Addict

    Member
    2,488
    1,517
    May 9, 2014
    Hervey Bay, Queensland
    Yep it's in the nand, and you don't really need to do it that way anymore (unless you want to), Decrypt9 can directly dump moveable.sed from the 3ds (in d0k3's version at least, in my version soon too once i figure out and fix some bugs). :)
     
  11. manpaint
    OP

    manpaint GBAtemp Regular

    Member
    237
    31
    Aug 20, 2014
    Canada
    What is the process?
     
  12. gudenau

    gudenau Largely ignored

    Member
    GBAtemp Patron
    gudenau is a Patron of GBAtemp and is helping us stay independent!

    Our Patreon
    3,300
    1,253
    Jul 7, 2010
    United States
    /dev/random
    The method above, with a seedb file.
     
    Last edited by gudenau, Oct 18, 2015