Hacking Inject ROP of homebrew menu/xxxCFW/xxxNAND into Help & Safety app?

riverscn

Active Member
OP
Newcomer
Joined
Apr 8, 2015
Messages
27
Trophies
0
Age
35
XP
111
Country
Switzerland
FBI H&S injection is possible now, at least on an O3DS.
So has any one tried to inject a ROP into H&S? That would make entering an existing homebrew easier.

p.s. Is there a way to inject FBI into H&S in a N3DS, since as we know rxtools can't run on a N3DS……
 
Last edited by riverscn,
  • Like
Reactions: thaikhoa

riverscn

Active Member
OP
Newcomer
Joined
Apr 8, 2015
Messages
27
Trophies
0
Age
35
XP
111
Country
Switzerland
Nope, breaks signatures (and you can't really 'inject' a ROP). And for FBI inject on N3DS, I see no reason why it wouldn't work.
I found some tutorials only applied on an O3DS. N3DS has different Titles/.. structure and maybe different versions of H&S files. I failed to find out how to do it.
Would you share a tutorial which works on a N3DS?
For the 'ROP inject' thing, what is the difference between a ROP and FBI app?
Thank you for your information! :)

--------------------- MERGED ---------------------------

rxTools can run on N3DS. But you can try this: https://gbatemp.net/threads/release...ect-generator-jpn-usa-eur-chn-kor-twn.391525/
You still need signature patching to run it though

You can't inject a ROP but you can use Sudokuhax to install ROPs: https://gbatemp.net/threads/tutorial-new-installing-sudokuhax-on-3ds-4-x-9-2.388621/
I follow the tutorial and I have a EUR N3DS, but there is no title\000400010\00022300\content\ . FW 9.2
 

samiam144

Régulier
Member
Joined
Aug 19, 2007
Messages
2,875
Trophies
0
XP
1,742
Country
Canada
I follow the tutorial and I have a EUR N3DS, but there is no title\000400010\00022300\content\ . FW 9.2
The N3DS have different title IDs. One of the 0's are replaced with a "2"

Can you look for 200400010 and/or 20022300? You should ask in that thread because it should be possible to inject over the N3DS version of the H&S app
 

nop90

Well-Known Member
Member
Joined
Jan 11, 2014
Messages
1,556
Trophies
0
Location
Rome
XP
3,036
Country
Italy
For the 'ROP inject' thing, what is the difference between a ROP and FBI app?
Thank you for your information! :)

You can't inject a ROP in a system app slot but you could inject a custom app that loads a rop chain in the stack and executes it.

The only problem is that such an app wold be unsigned (like FBI) and to run it you will need an entrypoint to patch the signature check first.

But if you have such entrypoint you can already hack your 3ds.

Got the point?
 

xXDungeon_CrawlerXx

Well-Known Member
Member
Joined
Jul 29, 2015
Messages
2,092
Trophies
1
Age
28
Location
Liverpool
XP
3,718
Country
since as we know rxtools can't run on a N3DS……
this is a lie :(
wp_000879ausg1.jpg
 

riverscn

Active Member
OP
Newcomer
Joined
Apr 8, 2015
Messages
27
Trophies
0
Age
35
XP
111
Country
Switzerland
You can't inject a ROP in a system app slot but you could inject a custom app that loads a rop chain in the stack and executes it.

The only problem is that such an app wold be unsigned (like FBI) and to run it you will need an entrypoint to patch the signature check first.

But if you have such entrypoint you can already hack your 3ds.

Got the point?
Got. ROP is only executed by a certain app which can be launched before homebrew(e.g. MSET/ninjahax/tubehax/...). A leak is necessary.
 

bache

Well-Known Member
Member
Joined
Sep 28, 2009
Messages
694
Trophies
1
XP
515
Country
The closest thing you you can do is to inject SudokuHax into your Nintendo DS WiFi connection settings, and use the homebrew menu in that to run each ROP installer.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    ShdwTakashi @ ShdwTakashi: pineapple belong on pizza? The answer is yes until proven otherwise