Hacking New Gateway Update 29/07/2013

profi200

Banned!
Banned
Joined
Sep 3, 2011
Messages
330
Trophies
0
XP
282
Country
Gambia, The
Nope. I'm not one of the Gateway idiots, but i know, how it works. I know, where the vulnerability, which the blue Gateway uses, is. If you don't trust me, ask yellows8 or neimod.
 
  • Like
Reactions: Boy12 and 3DSGuy

Rydian

Resident Furvert™
Member
Joined
Feb 4, 2010
Messages
27,880
Trophies
0
Age
36
Location
Cave Entrance, Watching Cyan Write Letters
Website
rydian.net
XP
9,111
Country
United States
The thing is, people on PS3 scene can play any game up to date with custom game patched. I, personally, don't give a sh** about my numbers in about screen if I can play any game.
That's because some major PS3 cryptography keys are known. It was so big (for something like that to be hacked out) that it hit mainstream media and the guys gave a presentation at a hacking convention.

That is entirely speculation.
No, it's an educated guess. Everything they tell us (especially the mention of the entry point) matches what we've known for a while about 4.x and above, that there's a save data exploit (used as an entrypoint), but the kernel-mode exploit was closed in 5.x.
 

Rytoast

Well-Known Member
Newcomer
Joined
Jul 3, 2013
Messages
65
Trophies
0
Age
45
XP
120
Country
United States
That is entirely speculation.


Besides the very few snippets of information provided through the three news updates, and brief emails here and there, EVERYTHING that's been said and is being said currently about GW3DS since they first made themselves public has been speculation.
 

Coto

-
Member
Joined
Jun 4, 2010
Messages
2,979
Trophies
2
XP
2,565
Country
Chile
Exactly. They are based on 2 vulnerabilities. One is fixed in 5.X and the other works up to 6.1, but if the second is fixed, the blue Gateway becomes useless and it is over. Without the second vulnerabillity a kernelmode exploit is useless, because kernelmode exploits are inside the system. The last chance to get it working then is a savegame exploit, but there are not a good chance to find one, because, there are not so many games with the old savegame encryption and to modifi the savegame, ARM9 code execution is needed (generating AES MAC).


say, you need to feed the binary blob with a correct AES MAC so it can be re-encrypted? sandboxed mode requires some authentication to let run code outside?
 

umdking

Active Member
Newcomer
Joined
Jul 11, 2013
Messages
28
Trophies
0
Age
42
XP
43
Country
Finland
Exactly. They are based on 2 vulnerabilities. One is fixed in 5.X and the other works up to 6.1
so,which one is the kernelmode exploit ? the one still in 6.1 system?or the already patched one?
on 3Dbrew,it seems that they said the kernel one has been patched already,which is more precious than the savedata one.(though,maybe i misunderstood the whole situation)
 

3DSGuy

No longer in scene
Member
Joined
May 22, 2012
Messages
345
Trophies
0
XP
467
Country
United States
say, you need to feed the binary blob with a correct AES MAC so it can be re-encrypted? sandboxed mode requires some authentication to let run code outside?
No, the save encryption for early games is already known so re-encrypting is no problem. But in order to update the savegame AES MAC, the key-scrambler, the savegame's KeyY, and the KeyX for savegames is required. Currently(Except for the savegame's KeyY) only Nintendo and each 3DS knows that. So the only practical way of updating the AES MAC, is via a 3DS with ARM9 code execution.
 
  • Like
Reactions: profi200

Lordmau5

Well-Known Member
Member
Joined
Jul 20, 2013
Messages
152
Trophies
1
Age
26
XP
482
Country
Germany
Did they invent Windows in one day? I guess not.

It takes time for such cards to find exploitable points on the device, so they can do their work.

It's the same with jailbreaking the iDevices.
 
  • Like
Reactions: Boy12

profi200

Banned!
Banned
Joined
Sep 3, 2011
Messages
330
Trophies
0
XP
282
Country
Gambia, The
so,which one is the kernelmode exploit ? the one still in 6.1 system?or the already patched one?
on 3Dbrew,it seems that they said the kernel one has been patched already,which is more precious than the savedata one.(though,maybe i misunderstood the whole situation)
Yes, the kernelmode exploit is already fixed in 5.X. Without a new kernelmode exploit, there is no chance to get it working up to 6.1, because they patch some parts of the firmware in RAM to disable some security. This needs total control.
 
  • Like
Reactions: f0rCe and 3DSGuy

logon

Well-Known Member
Member
Joined
Jun 8, 2008
Messages
128
Trophies
0
XP
188
Country
New Zealand
Sorry if this isn't the place to post this

If i'm correct their are 3 types of 3ds':
-Europe
-USA
-Japanese

The 3ds in Australia have -E at the end of their version
Does that mean European roms would work on the gateway on an Australian 3ds
 

TemplarGR

Gaming expert
Member
Joined
Sep 2, 2011
Messages
394
Trophies
0
XP
312
Country
Greece
Yes, the kernelmode exploit is already fixed in 5.X. Without a new kernelmode exploit, there is no chance to get it working up to 6.1, because they patch some parts of the firmware in RAM to disable some security. This needs total control.


Isn't it possible to install a modified 5.x+ version of firmware on an already hacked 3DS? If you already have total control at 4.5 firmware, isn't it possible to somehow get access to the newer firmware without installing it, examine and modify it, and install the modified version instead of the official one?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Veho @ Veho: I have a number of geriatric relatives.