Hacking [Fake/Wrong] 3DS Firmware has been dumped!

Status
Not open for further replies.

pistone

Well-Known Member
Member
Joined
Feb 18, 2010
Messages
503
Trophies
0
Age
35
Location
in your heart...coz secretly you love me !!!!
XP
232
Country
Albania
let the exploit and then homebrew begin !
smile.gif
shy.gif
 

pokefan92

Well-Known Member
OP
Newcomer
Joined
May 29, 2009
Messages
80
Trophies
0
XP
222
Country
hunter291 said:

thanks, I didn't realize.

For the rest of the folks... what about reading the topics and not complaining? yes, it was a mistake but it is too easy to solve... some of you guys just enjoy crying in forums. Read the webs and stop acting like a 5-year-old boy.
 

ManFranceGermany

Atheist, Socialist and pro EU!
Member
Joined
Nov 14, 2010
Messages
624
Trophies
0
XP
39
Country
Gambia, The
as the guy in the supercard forum said, its useless, as everyting is still encrypted and just the titel and parts of the updates are decrypted. beside, we had dumps of the fw before with same results. And if u wanna brute-force an 4000x AES key, than good luck!
 

evandixon

PMD Researcher
Developer
Joined
May 29, 2009
Messages
1,725
Trophies
1
Website
projectpokemon.org
XP
2,325
Country
United States
You do realise that the firmware for the DSi has been mapped like that for years and we just recently got a hack that is now no longer an exploit, and the Cyclo DSi. (I don't think the Cyclops one had anything to do with the firmware, but if it did, then it took a long time for it to be released).
So, the 3DS firmware being dumped isn't really impressive news.
 

WiiUBricker

News Police
Banned
Joined
Sep 19, 2009
Messages
7,827
Trophies
0
Location
Espresso
XP
7,485
Country
Argentina
Not again this guy >.>

This is nothing new and complete useless as all files of the "dump"can be downloaded straight from Nintendos servers.
 

RNorthex

Well-Known Member
Member
Joined
Nov 22, 2010
Messages
443
Trophies
0
XP
209
Country
United States
and so the title is misleading too
the actual firmware itself is not dumped

it's like if sy releases a game and a patch, you get the patch and call it a dumped game....there are differences bro
i don't know how many of these topics were already made, but i think it's time to include it in the sticky "when" topic
 

TheDreamLord

Well-Known Member
Member
Joined
Jun 8, 2011
Messages
939
Trophies
0
Age
24
Location
Ireland
Website
darkraino1.zymichost.com
XP
476
Country
chao1212 said:
Top link doesn't work, bottom is from webs.
QUOTEThe 3ds firmware 2.10-3 has been dumped

Post Last Edit by Plop23 at 26-6-2011 22:26


Post Last Edit by Plop23 at 26-6-2011 22:25


for developers I think it's good news, it's a french apparently having pseudo Upsilon, which dumped the firmware 3ds, he also apparently decrypt, thanks to this can we hope to have a bet a day of DSTWO for the launch of 3ds backups?
the structure of the firmware:
Structure des metadata

_Header
DEBUT | |LONGUEUR |DESCRITPION
RSA 2048|RSA 4096 | |
0x000 | 0x000 |4 |Signature type
0x004 | 0x004 |256 / 512 |Signature
0x104 | 0x204 |60 |Padding modulo 64
0x140 | 0x240 |64 |Issuer
0x180 | 0x280 |1 |Version
0x181 | 0x281 |1 |ca_crl_version
0x182 | 0x282 |1 |signer_crl_version
0x183 | 0x283 |1 |Padding modulo 64
0x184 | 0x284 |8 |System Version
0x18C | 0x28C |8 |Title ID
0x194 | 0x294 |4 |Title type
0x198 | 0x298 |2 |Group ID
0x19A | 0x29A |62 |reserved
0x1D8 | 0x2D8 |4 |Access rights
0x1DC | 0x2DC |2 |Title version
0x1DE | 0x2DE |2 |Number of Contents
0x1E0 | 0x2E0 |64 |Content Records
0x220 | 0x320 |40 |Padding modulo 64
0x248 | 0x348 |4 |Boot content
0x252 | 0x352 |4 |Banner content
0x256 | 0x356 |4 |Banner size
0x260 | 0x360 |32 |Hash

_Content Records
DEBUT |LONGUEUR |DESCRIPTION
0x00 |4 |Content ID
0x04 |32 |SHA-256 Hash

_Certificates
DEBUT |LONGUEUR |DESCRIPTION
0x000 |4 |Signature type
0x004 |* |Signature
0x104 |64 |Issuer
0x124 |4 |Tag
0x128 |64 |Name
0x168 | |Key


Exemple de Code Source pour Programme.
================================================================================
============================
typedef struct {
u32 cid; // Content ID
u8 hash[0x20]; // SHA-256 hash
} content_record; // Taille: 0x24 bytes

enum sig_type {
RSA_2048_SHA256 = 0x00010004,
RSA_4096_SHA256 = 0x00010003,
RSA_2048_SHA1 = 0x00010001,
RSA_4096_SHA1 = 0x00010000
};

typedef struct {
u32 sig_type;
u8 sig
; // * = Taille de la Signature
u8 fill1[60];
u8 issuer[64]; // Root-CA%08x-CP%08x
u8 version;
u8 ca_crl_version;
u8 signer_crl_version;
u8 fill2;
u64 sys_version;
u64 title_id;
u32 title_type;
u16 group_id; // Editeur
u8 reserved[62];
u32 access_rights;
u16 title_version;
u16 num_contents;
content_record contents[0x40];
u8 padding[0x28];
u32 boot_content;
u32 banner_content;
u32 banner_size;
u8 hash[0x20]; /* Inconnu */
} tmd;

//Le tmd est alors suivi par une chaîne de certificats.
typedef struct {
u32 sig_type;
u8 sig
; // * = Taille de la Signature
u8 issuer[64];
u32 tag; // Identifie ce qui est signé.
u8 name[64]; // Nom de chose étant signée.
u8 key[...];
} certificate;
================================================================================
============================
Source: 3DBrew
(sorry for mistakes, i'm french and I use the google translation)
Thats whats on top one
tongue.gif
 

Zerosuit connor

Baby I'm Back ♥
Member
Joined
Sep 17, 2010
Messages
1,848
Trophies
1
Location
Eorzea
XP
703
Country
For gods sake. It's not like its going to be exploited tomorrow guys. Yeah, They ""Dumped" the "firmware"". It's not even that big an achievement, as stated before the dsi firmware was mapped out ages ago how long did it take to hack? Answer: Years.
rolleyes.gif
rolleyes.gif
rolleyes.gif
rolleyes.gif
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Psionic Roshambo @ Psionic Roshambo: https://www.youtube.com/watch?v=A0FyqCEfD0E