Homebrew [IDEA] Exploit? probably Not though

  • Thread starter Thread starter DeoNaught
  • Start date Start date
  • Views Views 3,427
  • Replies Replies 33
not to be that Ass but its been explained Multiple times,

"There Is No Exploit/It IS Not Possible!"

I'm sorry, I hope this isn't shitposting. To make up for it;
since the host console is hacked cant we disable sig check, or are you saying the target system will check sig.
Yeah, it's the target that does sig checks. Why did you think the client being hacked would change anything? The target it still unmodified, and therefore it will still check signatures.
yeah i know, threads like this dont really contribute anything really, im sure those who would be able to actually make such an exploit would already have good enough knowlage of the system to be aware of what possible routes they have to explore


basically it will not work how you are thinking, the actual executable that is sent to the other 3DS MUST be signed, the only "in" is via the rom assets that are sent being able to trigger a exploit in the signed and unmodified executable, its not just as simple as making a devmenu cia file and sending it over or something as silly as that
Wait, so it's not just something special with MK7/NES? We could, in theory, load any ROM Hacks over Download Play if the ROM Hack in question set it up properly? Wow, didn't know that!
 
  • Like
Reactions: DutchyDutch
I'm not talking about download play but in general.
its obviously over yourhead but while crash 90% doesnt mean an exploit. Start looking at the Source code to various Open Source Released Exploits to start but considering you dont understand How Download play works it's going to be rather Difficult but Good Luck!
 

I'm sorry, I hope this isn't shitposting. To make up for it;

Yeah, it's the target that does sig checks. Why did you think the client being hacked would change anything? The target it still unmodified, and therefore it will still check signatures.

Wait, so it's not just something special with MK7/NES? We could, in theory, load any ROM Hacks over Download Play if the ROM Hack in question set it up properly? Wow, didn't know that!

i think it depends on the game, but afaik its only really the main exefs that is send over initially, the romfs (afaik) is sent on the fly as needed so they dont really get checked on the client side
 
its obviously over yourhead but while crash 90% doesnt mean an exploit. Start looking at the Source code to various Open Source Released Exploits to start but considering you dont understand How Download play works it's going to be rather Difficult but Good Luck!
I know for a fact a crash doesn't mean an exploit, I'm not that NOOBISH
 
i think it depends on the game, but afaik its only really the main exefs that is send over initially, the romfs (afaik) is sent on the fly as needed so they dont really get checked on the client side
Huh! Interesting! So the ROMfs isn't signed at all, because it's loaded on the fly and would take processing power to check? Very interesting! Neat little oversight on Nintendo's part.
 
I know for a fact a crash doesn't mean an exploit, I'm not that NOOBISH
Reread that Post before ignoring it " it IS a place to start " just 90% the time its just Garbage, Not usable or Error Correcting Code that Causes the System to error to prevent data Loss. and Debugging these Will give you Some Starting knowlage in what you need. (hence Why i Said its a place to start and you can start by Debugging Existing Exploits as well. it'd give insight how these were done and what they're doing.
 
Huh! Interesting! So the ROMfs isn't signed at all, because it's loaded on the fly and would take processing power to check? Very interesting! Neat little oversight on Nintendo's part.
well it would kinda make sense, you cant really expect to send over a 2GB romfs just so the client can check its signatures, especially when multiplayer features are usually using only a small selection of files, i guess they could have made a multiplayer only romfs and sent that, but that then means devs have to use up more space for a second romfs, and every time people want to play DLP they are forced to wait for the whole romfs to be sent over and stored on the SD card for checking.....basically its a understandable setup, the executable section is all verified so at that point the only risk is that the game was exploitable itself, you cant just run anything willy nilly, and its still limited to only userland, so without further exploits it would still only be homebrew
 
Last edited by gamesquest1,
  • Like
Reactions: Swiftloke
Both 3DS's need a custom firmware to send data. @ihaveamac has confirmed this with his very hard work with Splatood.

BUT, maybe there is a bug within Download Play that Ninty didn't think of patching (Ex. How IOSUHAX is able to work :O )
 
to send arbitrary code to another stock console you would need several signatures and signing keys. I don't know how many keys exactly, but you have a signature in the ticket, tmd, ncch header, and exheader. good luck trying to sign all of these.

best you can probably do is find an exploit in a DLP child for a game.
 
  • Like
Reactions: Swiftloke

Site & Scene News

Popular threads in this forum