Hacking New Gateway Update 29/07/2013

profi200

Banned!
Banned
Joined
Sep 3, 2011
Messages
330
Trophies
0
XP
282
Country
Gambia, The
Nope. I'm not one of the Gateway idiots, but i know, how it works. I know, where the vulnerability, which the blue Gateway uses, is. If you don't trust me, ask yellows8 or neimod.
 
  • Like
Reactions: Boy12 and 3DSGuy

Rydian

Resident Furvert™
Member
Joined
Feb 4, 2010
Messages
27,880
Trophies
0
Age
36
Location
Cave Entrance, Watching Cyan Write Letters
Website
rydian.net
XP
9,111
Country
United States
The thing is, people on PS3 scene can play any game up to date with custom game patched. I, personally, don't give a sh** about my numbers in about screen if I can play any game.
That's because some major PS3 cryptography keys are known. It was so big (for something like that to be hacked out) that it hit mainstream media and the guys gave a presentation at a hacking convention.

That is entirely speculation.
No, it's an educated guess. Everything they tell us (especially the mention of the entry point) matches what we've known for a while about 4.x and above, that there's a save data exploit (used as an entrypoint), but the kernel-mode exploit was closed in 5.x.
 

Rytoast

Well-Known Member
Newcomer
Joined
Jul 3, 2013
Messages
65
Trophies
0
Age
45
XP
120
Country
United States
That is entirely speculation.


Besides the very few snippets of information provided through the three news updates, and brief emails here and there, EVERYTHING that's been said and is being said currently about GW3DS since they first made themselves public has been speculation.
 

Coto

-
Member
Joined
Jun 4, 2010
Messages
2,979
Trophies
2
XP
2,565
Country
Chile
Exactly. They are based on 2 vulnerabilities. One is fixed in 5.X and the other works up to 6.1, but if the second is fixed, the blue Gateway becomes useless and it is over. Without the second vulnerabillity a kernelmode exploit is useless, because kernelmode exploits are inside the system. The last chance to get it working then is a savegame exploit, but there are not a good chance to find one, because, there are not so many games with the old savegame encryption and to modifi the savegame, ARM9 code execution is needed (generating AES MAC).


say, you need to feed the binary blob with a correct AES MAC so it can be re-encrypted? sandboxed mode requires some authentication to let run code outside?
 

umdking

Active Member
Newcomer
Joined
Jul 11, 2013
Messages
28
Trophies
0
Age
42
XP
43
Country
Finland
Exactly. They are based on 2 vulnerabilities. One is fixed in 5.X and the other works up to 6.1
so,which one is the kernelmode exploit ? the one still in 6.1 system?or the already patched one?
on 3Dbrew,it seems that they said the kernel one has been patched already,which is more precious than the savedata one.(though,maybe i misunderstood the whole situation)
 

3DSGuy

No longer in scene
Member
Joined
May 22, 2012
Messages
345
Trophies
0
XP
467
Country
United States
say, you need to feed the binary blob with a correct AES MAC so it can be re-encrypted? sandboxed mode requires some authentication to let run code outside?
No, the save encryption for early games is already known so re-encrypting is no problem. But in order to update the savegame AES MAC, the key-scrambler, the savegame's KeyY, and the KeyX for savegames is required. Currently(Except for the savegame's KeyY) only Nintendo and each 3DS knows that. So the only practical way of updating the AES MAC, is via a 3DS with ARM9 code execution.
 
  • Like
Reactions: profi200

Lordmau5

Well-Known Member
Member
Joined
Jul 20, 2013
Messages
152
Trophies
1
Age
26
XP
482
Country
Germany
Did they invent Windows in one day? I guess not.

It takes time for such cards to find exploitable points on the device, so they can do their work.

It's the same with jailbreaking the iDevices.
 
  • Like
Reactions: Boy12

profi200

Banned!
Banned
Joined
Sep 3, 2011
Messages
330
Trophies
0
XP
282
Country
Gambia, The
so,which one is the kernelmode exploit ? the one still in 6.1 system?or the already patched one?
on 3Dbrew,it seems that they said the kernel one has been patched already,which is more precious than the savedata one.(though,maybe i misunderstood the whole situation)
Yes, the kernelmode exploit is already fixed in 5.X. Without a new kernelmode exploit, there is no chance to get it working up to 6.1, because they patch some parts of the firmware in RAM to disable some security. This needs total control.
 
  • Like
Reactions: f0rCe and 3DSGuy

logon

Well-Known Member
Member
Joined
Jun 8, 2008
Messages
128
Trophies
0
XP
188
Country
New Zealand
Sorry if this isn't the place to post this

If i'm correct their are 3 types of 3ds':
-Europe
-USA
-Japanese

The 3ds in Australia have -E at the end of their version
Does that mean European roms would work on the gateway on an Australian 3ds
 

TemplarGR

Gaming expert
Member
Joined
Sep 2, 2011
Messages
394
Trophies
0
XP
312
Country
Greece
Yes, the kernelmode exploit is already fixed in 5.X. Without a new kernelmode exploit, there is no chance to get it working up to 6.1, because they patch some parts of the firmware in RAM to disable some security. This needs total control.


Isn't it possible to install a modified 5.x+ version of firmware on an already hacked 3DS? If you already have total control at 4.5 firmware, isn't it possible to somehow get access to the newer firmware without installing it, examine and modify it, and install the modified version instead of the official one?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    Don't know why people get so emotional online just get over it ffs
    +2
  • BigOnYa @ BigOnYa:
    He was the ass of gbatemp, everyone knocked on him, I honestly felt bad, even though I was guilty myself, but he egged it all on himself,
  • BigOnYa @ BigOnYa:
    But he still here, but under dif name, he pm me sometimes still even.
  • K3Nv2 @ K3Nv2:
    It's like they think we'll be in their bed pissing on it the next day
  • BigOnYa @ BigOnYa:
    I feel like gbatemp should make t-shirts or memorabilia to remember the lost ones. I bet the Polly shirts would sell out quick.
  • K3Nv2 @ K3Nv2:
    Nah that could actually bring lawsuits
  • K3Nv2 @ K3Nv2:
    Tempsuits
  • BigOnYa @ BigOnYa:
    PollySuits
  • BigOnYa @ BigOnYa:
    Your correct, Somebody would be guilty and there would be riots, then they storm the gbatemp capitol,
  • K3Nv2 @ K3Nv2:
    Online or not there are still certain rights that judges would have no issue handing out a warrant over
  • K3Nv2 @ K3Nv2:
    Just look at Kim dotcom
  • BigOnYa @ BigOnYa:
    Honestly I'm scared to, from you, but ok, lemme turn on vpn, virtual machine, private browser first
  • K3Nv2 @ K3Nv2:
    Remember that Alexa robot I gifted you
  • K3Nv2 @ K3Nv2:
    And that laptop Webcam you never tapped up
  • BigOnYa @ BigOnYa:
    That robot is here somewhere, I hear it moving around at night, but I haven't seen it for months.
  • BigOnYa @ BigOnYa:
    Oh that laptop I give to ancientboi, so you been watching him for months, and he's been watching you
  • K3Nv2 @ K3Nv2:
    Oh good more than enough material for the fbi
    +2
  • BigOnYa @ BigOnYa:
    Damn its 5 in morn, I gotta Go wake your mum and send her to work. Check ya later.
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    He could make so much money!!! His arm would never get tired lol
    +2
  • S @ salazarcosplay:
    How are yall doing
    +2
  • VXNlcm5hbWU @ VXNlcm5hbWU:
    Just had a pure banger of a sandwich there, was very nice
    +1
    VXNlcm5hbWU @ VXNlcm5hbWU: Just had a pure banger of a sandwich there, was very nice +1