NTRBoot Released!

It's here!
ntrboot_checklist_2.png

Info


@Normmatt has created a way to run B9S .firm files from bootrom via a DSi Flashcard and a magnet! This works on every 3DS on any firmware version.

For installation without a PC, user @TheCyberQuake has created a pack which will automatically install B9S and copy over essential starter homebrew from the flashcard's SD to the 3DS's. This will mainly be used for PC-less B9S installations. If you have a PC with you, use 3ds.guide. Read more here: https://gbatemp.net/threads/481141/

How does this work?


This works because of a flaw in the bootrom. Before the bootrom boots the NAND, it checks to see if Start+Select+X is held down, and if the shell is closed. If these requirements are met, it will boot an NDS cartridge from the bootrom. This give that cartridge bootrom access. You might be wondering how you'd hold down buttons while the shell is closed, and why you need a magnet. If you put a magnet in a specific spot on the 3DS, it will go into sleep mode. Using this, you can boot the NDS cartridge with the buttons held down while in sleep mode! Using a reflashable flashcard, you can boot B9SInstaller using the flashcard, and easily install it on your 3DS.
The 2DS doesn't need a magnet since a switch puts it to sleep instead of a magnet.

What does this mean?


  1. Any 3DS model on any firmware can be hacked with minimal effort
  2. You can unbrick any 3DS model from any type of brick.
    - Remember, you don't need a NAND backup for this. Just do a CTRTransfer.
    - This does not apply to MCU bricks.
  3. Even consoles with fried NAND, or even the NAND chip physically removed, can use this
This is incredibly impressive stuff, and will most likely be released soon! edit: now!

FAQ


Q: Can Nintendo patch this?
A: Nope! Not without a new hardware revision.

Q: My flashcard is blocked by my firmware! Can I still use this?
A: Yes! The flashcard blacklist is not enabled on the bootrom.

Q: Why can't this work with my flashcard?
A: The installation requires you to flash NTRBoot to the flashcard's nand. Most DS flashcards, such as the original R4, have a ROM, which is not flashable.

Q: Can I install NTRBoot on my flashcard without another 3DS system?
A: If you can run NDS roms on your 3DS with it, then yes. If it's blocked on your 3DS version, then you'll need another 3DS system to use it.

Q: Will my 3DS flashcard work?
A: No, only the NDSi flashcards listed above.

Q: Will any other flash cards work?
A: Only the ones listed in the OP. However keep in mind that flashcards such as the DSTT, Supercard DS2 and R4 SDHC Dualcore are planned to be supported in the future.

Q: I tried to do this with my cartridge and it didn't work?
A: It doesn't work with regular DS cards.

Q: Can I unbrick from a ____ brick?
A: Considering the card has access to the bootrom, yes! This can unbrick any brick (except MCU), unless you've taken a knife to the motherboard.

Q: Can I install B9S on the latest firmware with this?
A: Again, since the card has access to the bootrom, you can do this easily! Just plug in your flashcard, boot up using the magnet and button combination, and install.

Q: Does this work on the New Nintendo 2DS XL?
A: Yes!

:arrow: Release
:arrow: Guide
:arrow: Free NTRBoot Flashing
:arrow: Free B9S Installations

Here is SciresM's post about this

Please see SciresM's presentation on bootromhax.
 
Last edited by Deleted member 381889,

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
Someone here talked about this?
I dont know if writte the site adress where this its written is againt rules because that i only copy paste the test inside it... if u want find the site just copy paste all text on Google... lmao.

The ntrboothax exploit will require the following:
  • A DS / DSi flashcart
    • Exact flashcart compatibility will be added when this exploit is released
  • A small magnet
    • Note that this is only required on folding style 3DSs, not 2DSs
    • This is because the exploit requires your device to enter sleep mode while still having access to the buttons
    • The magnet should be able to trigger your device’s sleep mode by holding it on or around the ABXY buttons
  • One of the following methods of installing ntrboothax to your flashcart:
    • A Powersaves
    • Another 3DS or 2DS already running some kind of custom firmware (such as boot9strap or arm9loaderhax)
I would imagine at least some cards would be flashavle via a normal .nds ran from the card itself, the same as most flashcards updates already, unless the program for flashing them is unable to be made/ran in nds format for some weird reason

This is not claiming to have any prior knowledge but I would imagine it wouldn't be much harder to design the tool to run like a normal firmware update so then no extra hardware would be necessary as long as the flash card runs on 11.4
 
Last edited by gamesquest1,

Snooli

Well-Known Member
Member
Joined
May 25, 2017
Messages
188
Trophies
0
Age
25
XP
151
Country
DStwo and AK2i have flashing built-in and were normaly updated by running something on the console/card itself.
It is unknown whether flashing the firmware to something that is not a normal flash card would brick the card if dobe this way.

--------------------- MERGED ---------------------------

Someone here talked about this?

I dont know if writte the site adress where this its written is againt rules because that i only copy paste the test inside it... if u want find the site just copy paste all text on Google... lmao.

The ntrboothax exploit will require the following:
  • A DS / DSi flashcart
    • Exact flashcart compatibility will be added when this exploit is released
  • A small magnet
    • Note that this is only required on folding style 3DSs, not 2DSs
    • This is because the exploit requires your device to enter sleep mode while still having access to the buttons
    • The magnet should be able to trigger your device’s sleep mode by holding it on or around the ABXY buttons
  • One of the following methods of installing ntrboothax to your flashcart:
    • A Powersaves
    • Another 3DS or 2DS already running some kind of custom firmware (such as boot9strap or arm9loaderhax)
This is WIP page from 3ds.guide I have already posted a link to it before.
 

George Styles

New Member
Newbie
Joined
Apr 19, 2016
Messages
1
Trophies
0
Age
48
XP
74
Country
Regarding the r4i rts 3ds cart (which I have).

Looking at

http://r4i-sdhc.com/downloade.asp

it has instructions for upgrading the card - i assume that is flashing the internal firmware.

Ive also looked inside the downloadable zip, and there is a file called

flash.r4i

which im guessing is the thing that is flashed onto the internal flash of the card during the update.

I read that to work for this hax, you have to be able to change the banner of the flashcart - i read somewhere that at some point the "fake" game changed from meteriod (?) to bomberman flash (which is what mine reports as on the 3ds). I also read that the encryption keys needs to be changable - no idea if that is a given if the fake title can be changed...

Its also possible that the firmware is signed, which would put a stop to this...

I did a 'strings' on that file, but found no reference to bomberman :(

All this might or might not suggest that this card could be used...

I want to know, because my (not new) 3dsxl (which was previously AL9H'ed and then BS9'ed) had to be flashed back to my original backup (which luckly i kept) before being sent off to Nintendo for repair... im assuming that it will come back with the latest firmware flashed, and hence not be hackable without either this hax or a hardmod. I do have another B9S'ed new 3dsxl, but as i understand it that is the one combinination that cannot work (hacked new 3ds -> non hacked old 3ds).

I believe the hardmod on the old one is easier tho, since all the connection points are on the 'top' of the board as you disassemble, so there is no need to flip the board.

Im expecting my old 3ds back this week (just got nintendo email saying they are fixing it today)
 

BL4Z3D247

GBAtemp Stoner
Member
Joined
Oct 22, 2008
Messages
1,942
Trophies
0
Age
39
Location
I'm so high, I don't even know!
XP
1,229
Country
United States
I do have another B9S'ed new 3dsxl, but as i understand it that is the one combinination that cannot work (hacked new 3ds -> non hacked old 3ds).

I believe the hardmod on the old one is easier tho, since all the connection points are on the 'top' of the board as you disassemble, so there is no need to flip the board.
That's correct, you can only system transfer from a O3DS to a N3DS.

It is easier to hardmod O3DSes due to the contact points being in the front. The connection points on a 2DS(considered an O3DS) however are in the back though so technically not all "O3DSes" are that easy to hardmod. Granted even though you have to flip the main board of the 2DS, the contact points are still a hell of a lot easier to solder than N3DSes. But I've done a RAM upgrade on an OG XBOX before so everything pretty much seems easy to me now. ^_^
 

Snooli

Well-Known Member
Member
Joined
May 25, 2017
Messages
188
Trophies
0
Age
25
XP
151
Country
That's correct, you can only system transfer from a O3DS to a N3DS.

It is easier to hardmod O3DSes due to the contact points being in the front. The connection points on a 2DS(considered an O3DS) however are in the back though so technically not all "O3DSes" are that easy to hardmod. Granted even though you have to flip the main board of the 2DS, the contact points are still a hell of a lot easier to solder than N3DSes. But I've done a RAM upgrade on an OG XBOX before so everything pretty much seems easy to me now. ^_^
I feel for you. I have done some SMD chip soldering too, so my N3DS Hardmod didn't feel that hard. Yet I am still sitting here waiting for this to be released, because my stupid card reader bricked the damn thing.

--------------------- MERGED ---------------------------

Update on 3ds.guide.
Ntrboothax placeholder page is now publicly available for example from here.
Still no new info regarding flashcards though...
 
  • Like
Reactions: hurrz and BL4Z3D247

BL4Z3D247

GBAtemp Stoner
Member
Joined
Oct 22, 2008
Messages
1,942
Trophies
0
Age
39
Location
I'm so high, I don't even know!
XP
1,229
Country
United States
I feel for you. I have done some SMD chip soldering too, so my N3DS Hardmod didn't feel that hard. Yet I am still sitting here waiting for this to be released, because my stupid card reader bricked the damn thing.

--------------------- MERGED ---------------------------

Update on 3ds.guide.
Ntrboothax placeholder page is now publicly available for example from here.
Still no new info regarding flashcards though...
Yeah, I have a bricked 2DS sitting here too, I was going to hardmod it this weekend if this didn't release though. We'll see. Work picked up for me so I haven't had the energy to do it or else it would already be back online. Lol.
 
D

Deleted User

Guest
Update on 3ds.guide.
Ntrboothax placeholder page is now publicly available for example from here.
Still no new info regarding flashcards though...
That doesn't mean its near release though. It very well could be.

That just says that the devs have chosen the name ntrboothax (even if temporarily) and are communicating with Plailect about how the exploit will be set up.
 
  • Like
Reactions: Alex1234 and hurrz

Diego788

Well-Known Member
Member
Joined
Jun 27, 2014
Messages
441
Trophies
0
Location
Santiago, Chile
XP
1,389
Country
Chile
i bought my friend's DSi XL xd
my flashcard (r4igold.cc) is capable of flashing a firmware from a .nds file to the r4
i really hope that ntrboothax is compatible with my flashcard :<

18985327_764300080361978_1187181178_n.jpg 19021520_764300087028644_549539067_n.jpg 19021556_764300137028639_1526677811_n.jpg19021755_764300157028637_28338963_n.jpg

I think it's for flashing the firmware to the flashcart using HBL on an already hacked console.

wait what? HBL? :0
i thought that when ntrboothax is released we'll need to flash the firmware from the flashcard itself....
 

RedBlueGreen

Well-Known Member
Member
Joined
Aug 10, 2015
Messages
2,026
Trophies
1
XP
2,538
Country
Canada
i bought my friend's DSi XL xd
my flashcard (r4igold.cc) is capable of flashing a firmware from a .nds file to the r4
i really hope that ntrboothax is compatible with my flashcard :<

View attachment 89375 View attachment 89376 View attachment 89377View attachment 89378



wait what? HBL? :0
i thought that when ntrboothax is released we'll need to flash the firmware from the flashcard itself....
There's a possibility that we'll be able to use the homebrew launcher to flash the firmware apparently.
 

Snooli

Well-Known Member
Member
Joined
May 25, 2017
Messages
188
Trophies
0
Age
25
XP
151
Country
It would be cool if we could do that. You could than CFW anything using a flashcard and CubicNinja or FreakyForms.

--------------------- MERGED ---------------------------

There's a possibility that we'll be able to use the homebrew launcher to flash the firmware apparently.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    SylverReZ @ SylverReZ: @salazarcosplay, Morning