Hacking How far away from 11.1 dg or cfw?

Deleted member 350372

Well-Known Member
Member
Joined
Jun 15, 2014
Messages
316
Trophies
0
Age
29
Location
boot.firm, New Jersey
XP
388
Country
United States
I believe this is to do with the safe firm not having 11.x title checks and the exploit to get access to safe-firm is k11. And once in the safe-firm you have arm9 access to the system or at least can downgrade titles as the downgrade block isn't there.

*ninja'd a few times
That seems interesting. I thought that NFIRM would block older installations with the minversion at first, even in safe FIRM. But now it makes better sense to me. Just need to be 100% sure before doing anything. My irl friend has 11.2 and I was going to do the DSiWare dg with my cfw 2ds, but I decided to wait it out and see if anything were to come up, AND JUST LIKE THIS, it happened!! Amazing, and heavenly. :$$$$

IMPORTANT TO ALL USERS: DG USING THIS METHOD ASAP WHEN IT RELEASES CUZ NINTENDO WILL LIKELY PATCH THIS OUT WITH 11.3 IN A SHORT AMOUNT OF TIME!
 

Ryccardo

Penguin accelerator
Member
Joined
Feb 13, 2015
Messages
7,696
Trophies
1
Age
28
Location
Imola
XP
6,919
Country
Italy
That seems interesting. I thought that NFIRM would block older installations with the minversion at first, even in safe FIRM.

The recovery mode kernel is way older than 11.x and doesn't have the antidowngrade checks... not that it matters since we're not downgrading titles using the title uninstall/install functions, but flashing another system's nand backup and adapting it to ours (that's a ctrtransfer explained)!
 

Quantumcat

Dead and alive
Member
Joined
Nov 23, 2014
Messages
15,144
Trophies
0
Location
Canberra, Australia
Website
boot9strap.com
XP
11,119
Country
Australia
IMPORTANT TO ALL USERS: DG USING THIS METHOD ASAP WHEN IT RELEASES CUZ NINTENDO WILL LIKELY PATCH THIS OUT WITH 11.3 IN A SHORT AMOUNT OF TIME!
Actually there's no need to hurry. Soundhax is offline so Nintendo can't force you to update to 11.3. You can sit on 11.2 happily for as long as you want (not like when you need browserhax for homebrew - Nintendo can just force you to update to use the browser).
 

WaterBotttle

Well-Known Member
Member
Joined
Dec 19, 2014
Messages
163
Trophies
0
Age
34
XP
307
Country
That seems interesting. I thought that NFIRM would block older installations with the minversion at first, even in safe FIRM. But now it makes better sense to me. Just need to be 100% sure before doing anything. My irl friend has 11.2 and I was going to do the DSiWare dg with my cfw 2ds, but I decided to wait it out and see if anything were to come up, AND JUST LIKE THIS, it happened!! Amazing, and heavenly. :$$$$

IMPORTANT TO ALL USERS: DG USING THIS METHOD ASAP WHEN IT RELEASES CUZ NINTENDO WILL LIKELY PATCH THIS OUT WITH 11.3 IN A SHORT AMOUNT OF TIME!

That's not how it works, https://gbatemp.net/threads/safehax-11-1-2-downgrade-without-dsiware.455456/
 

Ryccardo

Penguin accelerator
Member
Joined
Feb 13, 2015
Messages
7,696
Trophies
1
Age
28
Location
Imola
XP
6,919
Country
Italy
Actually there's no need to hurry. Soundhax is offline so Nintendo can't force you to update to 11.3. You can sit on 11.2 happily for as long as you want (not like when you need browserhax for homebrew - Nintendo can just force you to update to use the browser).
That's the rational answer, but just wait for their brother/cousin/dog to "accidentally" update...
 

Deleted member 350372

Well-Known Member
Member
Joined
Jun 15, 2014
Messages
316
Trophies
0
Age
29
Location
boot.firm, New Jersey
XP
388
Country
United States
Actually there's no need to hurry. Soundhax is offline so Nintendo can't force you to update to 11.3. You can sit on 11.2 happily for as long as you want (not like when you need browserhax for homebrew - Nintendo can just force you to update to use the browser).
I meant as in safefirmlauncherhax being patched in 11.3, not soundhax. Also I was just trying to make sure to announce it just in case people may update to 11.3 and not be alarmed beforehand just as a precautionary.
 

HyperT

Well-Known Member
Member
Joined
Jun 4, 2016
Messages
674
Trophies
0
XP
232
Country
Not exactly.

Firmlaunchhax is the arm9 exploit people use in 9.2, but you need K11 access to patch some K11 function calls (I believe this is for the hooks)
https://yifan.lu/2015/01/17/reversing-gateway-ultra-stage-3-owning-arm9-kernel/

(Incase people didn't know)
There is another version of the firmware called SAFE_MODE_FIRM that is used by the system updater where firmlaunchhax has not been patched. We also need K11 access to boot into this mode (I assume). So the idea is too boot into this firmware run Firmlaunchhax then downgrade using the K9 access we now have to 2.1 and install A9LH.
Yea you're right in terms of the documentation etc. but does the safe-firm act like a normal firm? In which case it wouldn't have the 11.x nfirm title-downgrade-block [even though that fact is irrelevant as this gives an arm9 access exploit right]
 

Ryccardo

Penguin accelerator
Member
Joined
Feb 13, 2015
Messages
7,696
Trophies
1
Age
28
Location
Imola
XP
6,919
Country
Italy
Yea you're right in terms of the documentation etc. but does the safe-firm act like a normal firm? In which case it wouldn't have the 11.x nfirm title-downgrade-block [even though that fact is irrelevant as this gives an arm9 access exploit right]
Your reasoning implies safefirm was updated with the antidowngrade feature of 11.0, which it wasn't (its latest update, ignoring the port to N3DS, was to disable OTP in 3.0)
 

WaterBotttle

Well-Known Member
Member
Joined
Dec 19, 2014
Messages
163
Trophies
0
Age
34
XP
307
Country
Yea you're right in terms of the documentation etc. but does the safe-firm act like a normal firm? In which case it wouldn't have the 11.x nfirm title-downgrade-block [even though that fact is irrelevant as this gives an arm9 access exploit right]
I'm not a expert on the matter but If the downgrade checks were not in place I think you would only be able to install / uninstall titles to the SAFE_FIRM ? Which may be useful I suppose. I don't think there has been to much research into the topic.
 
Last edited by WaterBotttle,

HyperT

Well-Known Member
Member
Joined
Jun 4, 2016
Messages
674
Trophies
0
XP
232
Country
Your reasoning implies safefirm was updated with the antidowngrade feature of 11.0, which it wasn't (its latest update, ignoring the port to N3DS, was to disable OTP in 3.0)
Think you've mis-read I implied that it hasn't been updated [the firmlaunchhax of nfirm was patched with 9.5 - safe-firm wasn't]; and was querying the other implications.
 

WaterBotttle

Well-Known Member
Member
Joined
Dec 19, 2014
Messages
163
Trophies
0
Age
34
XP
307
Country
Think you've mis-read I implied that it hasn't been updated [the firmlaunchhax of nfirm was patched with 9.5 - safe-firm wasn't]; and was querying the other implications.
I see where you are coming from, even without Firmlaunchhax (Assuming the downgrade checks were not in place) we could have *potentially* downgraded/upgraded the necessary titles to enable the Firmlaunchhax then just use safehax.

--------------------- MERGED ---------------------------

I see where you are coming from, even without Firmlaunchhax (Assuming the downgrade checks were not in place) we could have *potentially* downgraded/upgraded the necessary titles to enable the Firmlaunchhax then just used the exploit.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    K3Nv2 @ K3Nv2: Yeah been there had that no fun +1