Hacking Is al9h really that secure?

annoyingcalc

Well-Known Member
OP
Member
Joined
Mar 16, 2014
Messages
164
Trophies
0
Age
29
XP
239
Country
United States
I've been reading about how Al9h + Luma3DS should be able to survive updates, but what about if Nintendo was really trying to remove it? I mean, it seems to me like the "arm9loaderhax.bin" on the SD card or NAND will run every start up. What stops Nintendo from modifying these files? I heard about there being write protection to the FIRM, but I haven't heard of anything that stops them from modifying files on the SD card. What if they made something that every shutdown deleted arm9loaderhax.bin (Making you have to plugin the SD card to your computer every time you want to boot up) or even worse, replace it with their own file that could delete all "not acceptable" content on the SD including EmuNAND. Of course we could patch this out, but this would require a patch to be made. Everyone who updated (who may or may not have a recent backup) would lose all of their stuff. (Assuming Nintendo wants to take a Gateway approach to things)



Or am I completely wrong and would this not work?
 

Jayro

MediCat USB Dev
Developer
Joined
Jul 23, 2012
Messages
12,950
Trophies
4
Location
WA State
Website
ko-fi.com
XP
16,941
Country
United States
They wouldn't be doing this if they were going to kill off the 3DS, so we might even get another Pokemon gen down the road. Hopefully it will be exclusive to the N3DS, and really take advantage of all the hardware. I feel Sun and Moon almost did that.
 

wormdood

pirate booty inspector
Member
Joined
Jan 3, 2014
Messages
5,256
Trophies
2
Age
38
Location
behind a parental advisory sticker
XP
4,190
Country
United States
i think they have a way to shut it down now just haven't implemented it yet because you would just downgrade and that would be the reason for removing all the dsi downgrade games/the bounty (potentially collecting up all the new hacks) so they can keep you out once they shut you out


#big n is coming for you
 
Last edited by wormdood,

wormdood

pirate booty inspector
Member
Joined
Jan 3, 2014
Messages
5,256
Trophies
2
Age
38
Location
behind a parental advisory sticker
XP
4,190
Country
United States
I'm surprised they haven't started un-A9LHing systems with 11.0 to be honest. If hackers can do it, Nintendo can eventually undo it.
thats what im talking about but if they are gonna do it efficiently they gotta wait until they shut down the new hacks slowhax ect. that most you tempers keep blabbing on about like they don't monitor this site among others
 

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,076
Country
United States
If Nintendo knew how to get rid of it they wouldn't of made a bug bounty trying to bribe hackers for a solution.
They're fishing for 33c3 speakers, nothing more. All the other bullshit they posted is just a guise. Think about it. They posted this just a couple weeks before a major ARM11 kexploit is announced as well as other major findings. They're hoping that at least one major speaker is gonna take the bait.
 

Jayro

MediCat USB Dev
Developer
Joined
Jul 23, 2012
Messages
12,950
Trophies
4
Location
WA State
Website
ko-fi.com
XP
16,941
Country
United States
Let's hope the dev's don't take the money and sell us out... And if a dev does sell us out, they should have their GBATemp account perma-banned if they're a member here.
 

ceelo

Well-Known Member
Member
Joined
Mar 9, 2008
Messages
309
Trophies
0
XP
1,105
Country
United States
Let's hope the dev's don't take the money and sell us out... And if a dev does sell us out, they should have their GBATemp account perma-banned if they're a member here.

Whoa whoa now, that could be overkill /s.

Anyway if I recall correctly, I think the safe bit about a9lh is that it starts before the payloads load, so Nintendo can't really do anything about it as its there before whatever Nintendo would have to load. Like bootmii on wii.
 

Gray_Jack

Well-Known Member
Member
Joined
Jan 13, 2016
Messages
732
Trophies
0
XP
407
Country
A9LH exploitation uses flaws in the hardware, it can never be patched without hardware revision. If I'm not mistaken, all we need is the right key to jump to the hax payload write inside the FIRM0 and loaded in the ARM9 memory.

If nintendo modify the arm9loaderhax.bin payload inside the SD to uninstall the A9LH implementation, we can always install it again (although it will not be easy, since we need hardmod, DSi Downgrade or bruteforce to reinstall it) and even if ninty patch hardmode FIRM downgrade and DSi Downgrade, the bruteforce method will always be alive (although it's much, much more complicated than any other method, and that's why it's not in the Plailect guide)
 

Jayro

MediCat USB Dev
Developer
Joined
Jul 23, 2012
Messages
12,950
Trophies
4
Location
WA State
Website
ko-fi.com
XP
16,941
Country
United States
A9LH exploitation uses flaws in the hardware, it can never be patched without hardware revision. If I'm not mistaken, all we need is the right key to jump to the hax payload write inside the FIRM0 and loaded in the ARM9 memory.

If nintendo modify the arm9loaderhax.bin payload inside the SD to uninstall the A9LH implementation, we can always install it again (although it will not be easy, since we need hardmod, DSi Downgrade or bruteforce to reinstall it) and even if ninty patch hardmode FIRM downgrade and DSi Downgrade, the bruteforce method will always be alive (although it's much, much more complicated than any other method, and that's why it's not in the Plailect guide)
I think a major hardware revision would need to be made with e-fuses in the NAND or somewhere for them to block the NAND hardmod downgrades. Like, if a user attempts one, the console would brick, for example.
 

Goombi

my_crypto = meme_crypto
Member
Joined
Jun 1, 2014
Messages
144
Trophies
0
Location
RnVja1lvdU15RHVkZQ
Website
www.goombi.fr
XP
178
Country
France
I'm surprised they haven't started un-A9LHing systems with 11.0 to be honest. If hackers can do it, Nintendo can eventually undo it.
To un-A9LH you need the OTP. And you also need it to detect tempered secret sector. So what's left to detect A9LH'd console? arm9loaderhax.bin is on SD card and an arbitrary name. So we're left with FIRM0 (which is tempered and kept outdated) and FIRM1 (kept outdated). So at best they can detect it by checking FIRM partitions but can't "un-A9LH" (because of the tempered key). And I think bricking consoles is out of question.
 

Gray_Jack

Well-Known Member
Member
Joined
Jan 13, 2016
Messages
732
Trophies
0
XP
407
Country
I think a major hardware revision would need to be made with e-fuses in the NAND or somewhere for them to block the NAND hardmod downgrades. Like, if a user attempts one, the console would brick, for example.

It's very possible to patch hardmod downgrade, for instance, with the 10.4 update the system won't boot using 9.0 NATIVE_FIRM, it made obligatory to use th 10.4 NATIVE_FIRM or above.
If they do that again, let's say 1.X.X update they do that again, making impossible to the system to boot with 10.4 NATIVE_FIRM (the one we use to be able to downgrade hardmod and DSi) and making mandatory the use of 11.0/11.1/11/2 or above to boot the system, making impossible to do hardmod downgrade and DSi downgrade
 

ScarletDreamz

[Debug Mode]
Member
Joined
Feb 16, 2015
Messages
3,967
Trophies
1
Location
/dev/sda1
XP
4,380
Country
United States
Yeah, keep talking, keep giving nintendo ideas on how to screw us lol.

Let's hope the dev's don't take the money and sell us out... And if a dev does sell us out, they should have their GBATemp account perma-banned if they're a member here.
Why? because he worked his ass off reverse engineering and exploiting, and decided to make some money out of that?
 

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,076
Country
United States
But doesn't that NAND restore also restore the secret sector? On O3DS you are right since the normal FIRM does not use that sector. I need to check what happens under normal a9l exec with tampered key.
No. With Hourglass9, yes; A9LH is preserved during a restore. With Decrypt9, it has to be specifically told to retain A9LH after a restore.
 

Gray_Jack

Well-Known Member
Member
Joined
Jan 13, 2016
Messages
732
Trophies
0
XP
407
Country
Yeah, keep talking, keep giving nintendo ideas on how to screw us lol.

They did it once, it's not like they don't know this, they are just waiting the "right time" to do that (thought ninty was never time wise xD A bunch of failures 'cause they have ideas way ahead of it's time and too much holes in the system because they waited too much to patch it)
 
  • Like
Reactions: Quantumcat

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • Xdqwerty @ Xdqwerty:
    also gonna install twilight menu in my r4 flashcard
  • Psionic Roshambo @ Psionic Roshambo:
    One thing that just occurred to me.... The sound on the 2600 sucked less back then the harsh sound we hear now is from infinitely better speakers we have now, back when the 2600 was new speakers produced a almost muffled sound, like CRTs made old graphics look slightly better.
  • Psionic Roshambo @ Psionic Roshambo:
    I wonder if I could recommend that to some emulation devs that perhaps the sound could use some smoothing out to simulate those old TVs
  • Psionic Roshambo @ Psionic Roshambo:
    I think a few of the early systems could benefit from that, at least up to the 8 bit generation, by the 16 bit generation I think TVs had gotten a lot better in almost every way
  • Xdqwerty @ Xdqwerty:
    i dont have an sd card adapter but I have an usb sd card adapter
  • K3Nv2 @ K3Nv2:
    Old people games
  • Xdqwerty @ Xdqwerty:
    its not the one that comes with the r4
  • Xdqwerty @ Xdqwerty:
    doesnt work (my flashcard is from r4isdhc.com)
  • Xdqwerty @ Xdqwerty:
    might install ysmenu first
  • Psionic Roshambo @ Psionic Roshambo:
    Try Wood firmware
  • Psionic Roshambo @ Psionic Roshambo:
    For your R4
  • Psionic Roshambo @ Psionic Roshambo:
    It's old but it's the best firmware out for DS stuff
  • Xdqwerty @ Xdqwerty:
    it says it only works for the original R4, R4i Gold (r4ids.cn), R4iDSN (r4idsn.com) and Acekard R.P.G.
  • Xdqwerty @ Xdqwerty:
    nvm it does support mine
  • Xdqwerty @ Xdqwerty:
    but why choose it over ysmenu @Psionic Roshambo?
  • Xdqwerty @ Xdqwerty:
    bc im stupid?
  • Xdqwerty @ Xdqwerty:
    yea ik im stupid
  • Xdqwerty @ Xdqwerty:
    good night
  • Psionic Roshambo @ Psionic Roshambo:
    Just give it a try, but honestly if you have a 3DS you can play DS games without a card just off the internal SD card
  • Psionic Roshambo @ Psionic Roshambo:
    Slightly slower loading but a bit more convenient
  • BakerMan @ BakerMan:
    guys, my fuckin headphones have an out of place speaker
  • K3Nv2 @ K3Nv2:
    Did you try wearing them?
    B @ btjunior: @Xdqwerty 16