Hacking [PoC] 3DS Region Changing + proof

cearp

瓜老外
OP
Developer
Joined
May 26, 2008
Messages
8,728
Trophies
2
XP
8,520
Country
Tuvalu
cearp, do you have an estimate of how many people have been able to make the eShop work on region changed systems? Either via the emuNAND swap trick or just luck?

And... you probably DON'T know this, but... do you know if any of those people had systems with preinstalled games?

estimate? i really don't know, i don't speak to everyone sorry :)
 
  • Like
Reactions: tony_2018

happydance

Well-Known Member
Member
Joined
Jul 16, 2009
Messages
598
Trophies
0
XP
349
Country
USA eshop work + USA NNID=A SDSD card
USA eshop work+no NNID=B SDSD card(Bridge)
EUR no eshop+EUR NNID=C SDSD card
1.A card is properly identified ESHOP
2.In other B card, run eshop an error number 110
3.Shutdown
4.Run C card, run the eshop EUR
You can log in to work! ! !

can any one help me with this steps? I can't seem to get this steps to work and always gets "error code 005-5602" on the 4th step and "error code: 011-3136" on the 2nd step. Does this steps still applies on 9.7 emunand to make eshop work?

My setup
1. Card A = linked to sysnand, Emunand 9.7 NNID linked [USA]
2. Card B = linked to sysnand, Emunand 9.7 no NNID [USA] -> error code: 011-3136
3.Shutdown
4. Card C = unlinked to sysnand, Emunand 9.7 NNID linked [EUR] -> error code 005-5602 on eshop

as instructed I also deleted all the titles on the emuNAND using FBI and installed the CIA (tried both UpdateCDN and 3DSNUS) of the right region using and tried both sysUpdater_0.3 and Devmenu, inject Secure_info_a and reformatted the region changed Emunand [EUR] twice before updating to 9.7 using rx mode (rxtool) and linked [EUR] NNID

anything wrong with the steps I've done?
 

Wowfunhappy

Well-Known Member
Member
Joined
May 14, 2008
Messages
578
Trophies
0
XP
420
Country
United States
can any one help me with this steps? I can't seem to get this steps to work and always gets "error code 005-5602" on the 4th step and "error code: 011-3136" on the 2nd step. Does this steps still applies on 9.7 emunand to make eshop work?

My setup
1. Card A = linked to sysnand, Emunand 9.7 NNID linked [USA]
2. Card B = linked to sysnand, Emunand 9.7 no NNID [USA] -> error code: 011-3136
3.Shutdown
4. Card C = unlinked to sysnand, Emunand 9.7 NNID linked [EUR] -> error code 005-5602 on eshop

as instructed I also deleted all the titles on the emuNAND using FBI and installed the CIA (tried both UpdateCDN and 3DSNUS) of the right region using and tried both sysUpdater_0.3 and Devmenu, inject Secure_info_a and reformatted the region changed Emunand [EUR] twice before updating to 9.7 using rx mode (rxtool) and linked [EUR] NNID

anything wrong with the steps I've done?

In the USA eShop (the one you do have access to), are there any titles in your download history that you didn't actually buy? Stuff that came with your 3DS, for example?
 

chronoqz

Member
Newcomer
Joined
Apr 8, 2015
Messages
8
Trophies
0
Age
36
XP
63
Country
United States
i have the same problem, i will try use as brige (sd card B) a emunand with the target region without NNID in order to get the error.
 

Wowfunhappy

Well-Known Member
Member
Joined
May 14, 2008
Messages
578
Trophies
0
XP
420
Country
United States
yes there is, my 3ds is a super Mario bundle that has a preinstall game on it when I bought it.
I suspect that this is the cause of the problem. It's the same thing that stops the eShop from working on region-changed New 3DS's.

If true, I'm afraid that there is no solution, and won't be because it's an issue with Nintendo's servers.
 

chronoqz

Member
Newcomer
Joined
Apr 8, 2015
Messages
8
Trophies
0
Age
36
XP
63
Country
United States
I suspect that this is the cause of the problem. It's the same thing that stops the eShop from working on region-changed New 3DS's.

If true, I'm afraid that there is no solution, and won't be because it's an issue with Nintendo's servers.
f**k i just realize that my 3ds is mario and luigis bundle, so im screwed?
 

Sliter

Well-Known Member
Member
Joined
Dec 7, 2013
Messages
3,264
Trophies
0
Location
ᕕ( ᐛ )ᕗ
XP
1,797
Country
Brazil
cearp i had some fun testing some things out with my emuNAND.

My 9.4.0 emuNAND already has NNID and you need internet/actual
fw to remove it, so i thought about a way to remove it without internet.

NNID is listed in: \data\<your unique id>\sysdata\00010038 > 00000000

It was pretty simple to do it and here it is how i did it:

1. I extracted my fat16 xorpad using launcher.dat from 3DS_Multi_Decryptor
2. Dumped emuNAND.bin using emuNANDTool
3. Extracted emunand.fat16.bin
4. xor'ed emunand.fat16.bin
5. Mounted emunand.fat16.bin.out with WinImage
6. Browsed to \data\<your unique id>\sysdata\00010038
7. Replaced 00000000 with another one i've extracted the same way that never had nnid
8. Renamed emunand.fat16.bin.out to test.bin
9. xor'ed test.bin
10. Injected test.bin.out into emunand.fat16.bin with HxD
11. Injected emunand.fat16.bin @ offset B930000 with HxD
12. Injected my new emunand.fat16.bin into my SD Card using emuNANDTool

Eh, voila, after booting into emuNAND NNID was gone :)

I could have switched out or deleted any other files i wanted,
maybe this will help your research ^_^

EDIT:

Wifi Data is located with SSID and readable Password in:
\data\<your unique id>\sysdata\00010017

Foldernames (on Dashboard) are located in:
\data\<your unique id>\sysdata\00020098
can I ask a more detailed how to? I really don't know how to do half of what are there x3x (actually I only know how to dump emuNAnd... :v )
 

itazchu

New Member
Newbie
Joined
Nov 5, 2013
Messages
4
Trophies
0
XP
122
Country
Indonesia
need to clarify this, so everytime we want to connect to another region nnid emunand we need to log in to empty nnid on card B right? and is it okay if I restore my sysnand to 9.2 after the whole process and use my main nnid on 9.2 sysnand?
 
Last edited by itazchu,

Justin20020

Well-Known Member
Member
Joined
Jun 22, 2015
Messages
813
Trophies
0
Age
30
XP
2,683
Country
Germany
On the video was the first fw on 9.4 eur. Later you can update/downgrade via CHN to 9.3? Is it with 9.5 via ninjhax possible to downgrade by this method on 9.2?
 

cearp

瓜老外
OP
Developer
Joined
May 26, 2008
Messages
8,728
Trophies
2
XP
8,520
Country
Tuvalu
I've got a question regarding region change.

Let's say if I were to change the Letter in the Secure info, the U or J or E to K,
would it change my connection to Korean?

Or is there more encrypted data in the remainder of the secureinfo that is used to validate the connection?
that is exactly how simple it is.
although it is not a 'letter', it is just a numerical value.
but yes, the secureinfo also has a signature so it will no longer be valid if you edit it. so you will need a cfw to ignore the incorrect signature etc
 
  • Like
Reactions: Queno138

Queno138

Ravens
Member
Joined
Sep 18, 2010
Messages
2,425
Trophies
0
Location
Luigi's Dark Mansion
XP
1,070
Country
Senegal
that is exactly how simple it is.
although it is not a 'letter', it is just a numerical value.
but yes, the secureinfo also has a signature so it will no longer be valid if you edit it. so you will need a cfw to ignore the incorrect signature etc

Oh oh!

Which CFW allows that, and which value could I simply change?
(Let's say to Korean? I'm not entirely interested in Eshop use, but rather just going online)
 
D

Deleted User

Guest
NEW -

A nice video showing off a JPN console region changed to all regions! (I had to get some help to build a launcher.dat for iQue)
The method is by me but I gave it to tanglangxia at duowan and he tested it lots, and had some fun! (He made the video, it's his)

--------

Ok, so whilst everyone had a ticket for the hype train... here is a video that is showing my JPN 3DS loading JPN emunand on one sd card, then changing the sd card and loading up a different sd card to an EUR emunand.
It wasn't so super simple to achieve, and the result is not 100% perfect, but it is good progress!
I won't share the program I made to do this just yet, because it is not ready for 'public release'. But, it is nice to share progress and things :)

(I had this yesterday, but I took the video today - it has nothing to do with GW's new launcher, I just updated to it before I took the video, all that is really required is 4.5 and a ds mode flashcart)
http://v.youku.com/v_show/id_XODY4NjMwNjEy.html
(sorry about the youku link, it's the best i can do with my internet at the moment)

thanks to enler for sharing some filesystem code with me, without it i would not have been able to have done this!

--if someone wants to make a mirror of the video on youtube, i would appreciate it!

I apologize if I'm missing something obvious. So the region is now being determined by which SD card is in? Like how a vita determines what region it is?

i.e. Insert a JPN 3DS SD card in a US system and it detects it as JPN
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    DinohScene @ DinohScene: ahh nothing beats a coffee disaronno at work