Homebrew My Experimentation with the DS Profile Exploit

  • Thread starter Thread starter fierce waffle
  • Start date Start date
  • Views Views 24,566
  • Replies Replies 86
  • Likes Likes 8
phDacnGh.jpg

CRCs are working.

congrats on accomplishing nothing using someone else's code.
 
  • Like
Reactions: Hozu, tyons and NEP
plutooo and lightenup were the first, who managed it. They did it completely without any doc about the NVRAM ROP. They said "we figured it out by staring at the NVRAM payload.". To be honest, we had a doc about all gadgets. The only problem left, was to find a way to dump memory to reverse the Launcher.dat ROP (the doc only described, what the NVRAM ROP-gadgets do).

So just to be clear, the 2 people you mentioned managed to figure out the gateway exploit by doing nothing but look at the NVRAM ROP chain? They had no RAM dump or anything else? And you managed to do the same thing separately(eventually culminating in you being able to dump RAM without having a RAM dump to start with), but with a document (possibly provided by the first 2 guys) that generally outlined what the ROP chain pieces did?

Is that all correct? I believe it, I just wanted to make sure I have it 100% right.
 
Is that all correct? I believe it, I just wanted to make sure I have it 100% right.

That's correct, but the document was not from them. Someone uploaded it to help another team. I better say not who, because i don't want to piss on others vehicle :tpi:

Anyway, a part of this document was pasted month's ago on #3dsdev and someone pasted it again 2 days ago.
 
That's correct, but the document was not from them. Someone uploaded it to help another team. I better say not who, because i don't want to piss on others vehicle :tpi:

Anyway, a part of this document was pasted month's ago on #3dsdev and someone pasted it again 2 days ago.


Interesting, thank you. I'll have to see if I can track that down somewhere. I've actually managed to make a little progress on how the NVRAM ROP chain works, myself. I'd love to see if my observations match up with it.
 
Good jooooob, finally someone working on it publicly. I would be also interested in working on this. What asm does 3DS use ? arm asm?
 
Ah haven't done that in a while. I mostly reverse stuff on Windows and Linux with x64 asm and x86 asm.
Any irc channel or such where we could talk. I got flashcart and 4.5 3DS at home but no Gateway.
 
guys, don't forget that waffle copied everything from someone else. read the previous page.
 
Yes so what, at least he is working on something.

I would say exactly the same if he didn't change "gateway" into "fakeway" and made other minor changes in order to fool us (or at least the less expereinced ones).
 
Jackalus
You need to do it yourself. Go with waffle or do your own stuff ;) I don't work on that stuff alone, even if it looks like.
(And to be honest, why do you think, if we talk privately, i give you all my stuff? I only share stuff with peoples, which got code execution working.)
 
If you do your own stuff or do it with others in a team, no problem, but don't expect others just share their stuff, only because someone came and asked for. I know the potential of piracy of this exploit. It is very easy to run ROMs from the SD card with this. I don't want this to happen, otherwise i had already released all my stuff ;)

My 2 cents.
 
That's enough offtopic.
Jackalus, stop replying to him and do what you want. Hypocrite or scientific mind, it won't change anything.

If this thread is done talking about the exploit and how it works, I'll close it.
If you want to argument about piracy and morals, go to IRC.
 

Site & Scene News

Popular threads in this forum