Hacking Old 3ds device Demo

CrispyYoshi

Well-Known Member
Member
Joined
Mar 20, 2010
Messages
1,540
Trophies
1
XP
1,092
Country
United States
OTP.bin at 256 bytes


no files

--------------------- MERGED ---------------------------




code bin = 37.716 ok

load bin =7.900 ok

otp bin ? not files
This is not good... Can you try at least 3 more times to ensure that it isn't working? Perhaps it might have been a mistake... Or perhaps your demo unit doesn't have an OTP at all!

Your 3DS Demo Unit might have its OTP in a different location, doesn't have the information we're trying to find, or is incompatible with the current software we use. We could also try updating it and downgrading it to dump the OTP the method everyone else does, but not only might that not be necessary but I am also worried about bricking your system from a system update...

This is beyond my skill level and you have a couple of options:

- Keep trying to dump your OTP.bin using that code.bin and load.bin
- Report the issue to someone like the creator of OTPHelper: https://gbatemp.net/members/d0k3.29073/ or Plailect: https://gbatemp.net/members/plailect.381978/
- Attempt to update to 4.x, hope it doesn't brick, update to 9.2, hope it doesn't brick, downgrade to 2.1, hope it doesn't brick, and hope you can dump your OTP.bin using the method everyone else does. (Not recommended to try blindly)
 

Clector

Well-Known Member
Member
Joined
Mar 15, 2016
Messages
1,076
Trophies
0
Location
Not here
XP
446
Country
Bangladesh
Weird, since if you can"t. I thought as said the better would be to contact with someone that can and want to help you, with checking why you can"t get your OTP and if is safe to update to 4.x via cartdrige without risk.
 

Swiftloke

Hwaaaa!
Member
Joined
Jan 26, 2015
Messages
1,770
Trophies
0
Location
Nowhere
XP
1,436
Country
United States
This is not good... Can you try at least 3 more times to ensure that it isn't working? Perhaps it might have been a mistake... Or perhaps your demo unit doesn't have an OTP at all!

Your 3DS Demo Unit might have its OTP in a different location, doesn't have the information we're trying to find, or is incompatible with the current software we use. We could also try updating it and downgrading it to dump the OTP the method everyone else does, but not only might that not be necessary but I am also worried about bricking your system from a system update...

This is beyond my skill level and you have a couple of options:

- Keep trying to dump your OTP.bin using that code.bin and load.bin
- Report the issue to someone like the creator of OTPHelper: https://gbatemp.net/members/d0k3.29073/ or Plailect: https://gbatemp.net/members/plailect.381978/
- Attempt to update to 4.x, hope it doesn't brick, update to 9.2, hope it doesn't brick, downgrade to 2.1, hope it doesn't brick, and hope you can dump your OTP.bin using the method everyone else does. (Not recommended to try blindly)
I was afraid of this... I'm surprised the nand dump even worked.
 

Swiftloke

Hwaaaa!
Member
Joined
Jan 26, 2015
Messages
1,770
Trophies
0
Location
Nowhere
XP
1,436
Country
United States
A. Did you get your OTP?
B. Listen. @CrispyYoshi, you shouldn't have told him to do that. Demo units are different from standard consoles, as is obvious considering A. The lack of an OTP B. The odd NAND... It's likely that, though the console boots, it won't work properly as the demo hardware expects something different than what it was given... I believe that Nintendo has special update software for demo units, I've actually seen an employee installing one on a Wii U. Can you still access Cubic Ninja, @enes eyibil? If so, we might be able to help you fix your 3DS. You have made a proper NAND dump [I believe] so if you can get into CN we should be able to help you reinstall that NAND, to fix your DS.
 
  • Like
Reactions: Deleted-379826

enes eyibil

Well-Known Member
OP
Member
Joined
Mar 26, 2016
Messages
155
Trophies
0
Age
33
XP
275
Country
A. Did you get your OTP?
B. Listen. @CrispyYoshi, you shouldn't have told him to do that. Demo units are different from standard consoles, as is obvious considering A. The lack of an OTP B. The odd NAND... It's likely that, though the console boots, it won't work properly as the demo hardware expects something different than what it was given... I believe that Nintendo has special update software for demo units, I've actually seen an employee installing one on a Wii U. Can you still access Cubic Ninja, @enes eyibil? If so, we might be able to help you fix your 3DS. You have made a proper NAND dump [I believe] so if you can get into CN we should be able to help you reinstall that NAND, to fix your DS.
https://mega.nz/#!u0w0xYzC!psDl3vK5XP2MIL8QX3ThOSUi4-EzoemBVmwTfEbmJ_A
https://mega.nz/#!HwoxTLYa!YNgqbGU53slZJR3UseRhTP-QBcJ_DtqZPFzrYR5YUbI

I don't have a Wii U

browser error the internet browser will become available once you update your system via the internet

go-gateway-3ds.com exploit downgrade ?

what should I do?

cubic ninja rq code notting :(
 

CrispyYoshi

Well-Known Member
Member
Joined
Mar 20, 2010
Messages
1,540
Trophies
1
XP
1,092
Country
United States
browser error the internet browser will become available once you update your system via the internet

go-gateway-3ds.com exploit downgrade ?

what should I do?

cubic ninja rq code notting :(
A. Did you get your OTP?
B. Listen. @CrispyYoshi, you shouldn't have told him to do that. Demo units are different from standard consoles, as is obvious considering A. The lack of an OTP B. The odd NAND... It's likely that, though the console boots, it won't work properly as the demo hardware expects something different than what it was given... I believe that Nintendo has special update software for demo units, I've actually seen an employee installing one on a Wii U. Can you still access Cubic Ninja, @enes eyibil? If so, we might be able to help you fix your 3DS. You have made a proper NAND dump [I believe] so if you can get into CN we should be able to help you reinstall that NAND, to fix your DS.
I went to bed! I think with a proper NAND dump it should be possible to restore back to the system, possibly through system settings. What I am unsure is if the current software we use will allow them to do that.

enes eybil, does your System Settings function properly and can you enter Other Settings->Profile->DS Profile and see if it works? If it does, you may be able to get out of your situation without a hardmod, but it might require special/tailored software to work.

With that said, I do not think anything strange happened with that system update: Pokemon has 6.x firmware and it was expected that you would not be able to use your browser: I told you to update to 4.1, not 6.x! Thankfully though, there are still methods to work with 6.x MSET ROP. You'll want to use your Gateway Blue Card to install Decrypt9 6.x or RxTools 6.x to DS Profile.

EDIT: To be specific, I do not think we have lost anything valuable here. Unfortunately, this will mean that you will need to downgrade to 2.1 like everyone else in order to get that OTP.bin, which will take a while to do. However, even if we did have access to reading/writing the NAND again, I would suggest making another NAND.bin backup to check the filesize before we write anything to it. I would also suggest dumping your NAND FAT16 XORPADs if you manage to get in Decrypt9, because those are also very useful to have.

If I had to guess, demo units are just regular 3DSes with a smaller NAND with tailored software installed on them (and we've backed that up already, as NAND.img). However, it is probably very risky to attempt to install any software updates due to the lack of space on the NAND: It may not have enough room to install everything, and it could end up not installing some vital parts of the operating system to function properly (resulting in a brick)
 
Last edited by CrispyYoshi,

d0k3

3DS Homebrew Legend
Member
Joined
Dec 3, 2004
Messages
2,786
Trophies
1
XP
3,875
Country
Germany
First, congrats on the 100th post!
Second, that QR code won't work anymore. This is out of my hands now, I have no idea what you should do. @d0k3 @Aurora Wright @smealum @TuxSH Any ideas? This console is extremely valuable :/
You're just tagging everyone that could help? At least post a complete description of the problem. What tools were used, what lead to it, what doesn't work...
 
  • Like
Reactions: astronautlevel

CrispyYoshi

Well-Known Member
Member
Joined
Mar 20, 2010
Messages
1,540
Trophies
1
XP
1,092
Country
United States
You're just tagging everyone that could help? At least post a complete description of the problem. What tools were used, what lead to it, what doesn't work...
This person has a 3ds Demo Unit from Gamestop which was initially on 1.0.0U [Demo Unit]. They used CN to dump their NAND but wasn't able to use the OTP.bin dumper I used to help someone else a month or two ago. Then, they decided to update to 6.x using Pokemon Y, and, despite how thankful I am they didn't brick, now they're stuck on 6.x without a web browser (as expected)

If I had to guess, they could probably use Decrypt9 via MSET ROP to restore the NAND, but I don't know how easily compatible that will be with their system. It's also worth noting that their NAND.img dump appears to be 792,606,208 bytes. (Someone else happens to have this size too)

They also are in possession of a Gateway Red Card and Blue Card: Perhaps they could install the ROP with the blue card? I'm worried that could be dangerous to try, but I'm not actually sure how that works.

EDIT: We also haven't dumped any Xorpads yet. In addition to the NAND.img, they seem to also have some interesting files: http://imgur.com/TE3jRFE
 
Last edited by CrispyYoshi,

d0k3

3DS Homebrew Legend
Member
Joined
Dec 3, 2004
Messages
2,786
Trophies
1
XP
3,875
Country
Germany
This person has a 3ds Demo Unit from Gamestop which was initially on 1.0.0U [Demo Unit]. They used CN to dump their NAND but wasn't able to use the OTP.bin dumper I used to help someone else a month or two ago. Then, they decided to update to 6.x using Pokemon Y, and, despite how thankful I am they didn't brick, now they're stuck on 6.x without a web browser (as expected)

If I had to guess, they could probably use Decrypt9 via MSET ROP to restore the NAND, but I don't know how easily compatible that will be with their system. It's also worth noting that their NAND.img dump appears to be 792,606,208 bytes. (Someone else happens to have this size too)

They also are in possession of a Gateway Red Card and Blue Card: Perhaps they could install the ROP with the blue card? I'm worried that could be dangerous to try, but I'm not actually sure how that works.

EDIT: We also haven't dumped any Xorpads yet. In addition to the NAND.img, they seem to also have some interesting files: http://imgur.com/TE3jRFE
The NAND dump should be redone, in any case. This looks very fishy. And yes, the GW MSET ROP with D9s Launcher.dat should be the best option to go from there.
 

enes eyibil

Well-Known Member
OP
Member
Joined
Mar 26, 2016
Messages
155
Trophies
0
Age
33
XP
275
Country
I went to bed! I think with a proper NAND dump it should be possible to restore back to the system, possibly through system settings. What I am unsure is if the current software we use will allow them to do that.

enes eybil, does your System Settings function properly and can you enter Other Settings->Profile->DS Profile and see if it works? If it does, you may be able to get out of your situation without a hardmod, but it might require special/tailored software to work.

With that said, I do not think anything strange happened with that system update: Pokemon has 6.x firmware and it was expected that you would not be able to use your browser: I told you to update to 4.1, not 6.x! Thankfully though, there are still methods to work with 6.x MSET ROP. You'll want to use your Gateway Blue Card to install Decrypt9 6.x or RxTools 6.x to DS Profile.

EDIT: To be specific, I do not think we have lost anything valuable here. Unfortunately, this will mean that you will need to downgrade to 2.1 like everyone else in order to get that OTP.bin, which will take a while to do. However, even if we did have access to reading/writing the NAND again, I would suggest making another NAND.bin backup to check the filesize before we write anything to it. I would also suggest dumping your NAND FAT16 XORPADs if you manage to get in Decrypt9, because those are also very useful to have.

If I had to guess, demo units are just regular 3DSes with a smaller NAND with tailored software installed on them (and we've backed that up already, as NAND.img). However, it is probably very risky to attempt to install any software updates due to the lack of space on the NAND: It may not have enough room to install everything, and it could end up not installing some vital parts of the operating system to function properly (resulting in a brick)
what do you suggest ?
how to make the transaction you need ?

--------------------- MERGED ---------------------------

The NAND dump should be redone, in any case. This looks very fishy. And yes, the GW MSET ROP with D9s Launcher.dat should be the best option to go from there.
gentlemen, what should I do now ? :)
 
  • Like
Reactions: CrispyYoshi
General chit-chat
Help Users
    Psionic Roshambo @ Psionic Roshambo: Seasons in the abyss lol