Hacking Post your ideas regarding how to hack the 3DS, here

  • Thread starter Thread starter Vulpes Abnocto
  • Start date Start date
  • Views Views 458,487
  • Replies Replies 1,786
  • Likes Likes 1
i made a new topic for it anyways but i said that if you havent yet downloaded the ambassador certificate
then go to e-shop ,settings, the to where you download the nes games for the ambassador program ,and click where it says re download to download the ambassador certificate for the 1st time then right after it finishes mthe 3ds will ask you something ,but i forgot what it is, anyways ignore it turn off the 3ds and tak out the sd card and make a 1:1 copy of it ,then send it to someone with a 3ds not in the program and have them put a copy of you sd card image on their sd card and put it in their 3ds and see if they get the certificate on their 3ds, after i said yes to whatever it asked it said altering system data do not turn off system,i wonder if you copy the sd before that and put sd with it on there in another 3ds if it will add the ambassador program, also after you do that make another 1:1 image of the sd card after you do click yes to what it asks , but before you go to the main menu and open the little present icon it puts there,try both of the sd images in a 3ds without the ambassador program and see if it will add it to the other 3ds
 
I don't understand the point of creating a worthless sticky. If someone makes a thread which violates forum rules, the thread should be removed and the user warned. Where is the logic behind creating a giant thread of forum violations?
 
totalnoob its impossible to copy data from one 3ds to another unless you do the system transfer which will move your ambassador progrram to his ds
 
totalnoob617 said:
i made a new topic for it anyways but i said that if you havent yet downloaded the ambassador certificate
then go to e-shop ,settings, the to where you download the nes games for the ambassador program ,and click where it says re download to download the ambassador certificate for the 1st time then right after it finishes mthe 3ds will ask you something ,but i forgot what it is, anyways ignore it turn off the 3ds and tak out the sd card and make a 1:1 copy of it ,then send it to someone with a 3ds not in the program and have them put a copy of you sd card image on their sd card and put it in their 3ds and see if they get the certificate on their 3ds, after i said yes to whatever it asked it said altering system data do not turn off system,i wonder if you copy the sd before that and put sd with it on there in another 3ds if it will add the ambassador program, also after you do that make another 1:1 image of the sd card after you do click yes to what it asks , but before you go to the main menu and open the little present icon it puts there,try both of the sd images in a 3ds without the ambassador program and see if it will add it to the other 3ds
The problem with the copy is that it's not encrypted. The system wouldn't accept anything that isn't signed/encrypted by Nintendo. Also, that's if you can make an unencrypted copy. That doesn't happen normally. A system pausing is actually taking the time to encrypt it in memory before it writes it to a file. That's how encryption works. Saving it to a file before encrypting it would be slower, because it would still write to the file, then read the file, encrypt the data, then rewrite the file with the encrypted data. So it's highly doubtful you could copy it.
 
Urza said:
I don't understand the point of creating a worthless sticky. If someone makes a thread which violates forum rules, the thread should be removed and the user warned. Where is the logic behind creating a giant thread of forum violations?

Which rule is being violated by people speculating and putting forth their ideas?
I'm simply bringing them all into a single location.
 
Urza said:
I don't understand the point of creating a worthless sticky. If someone makes a thread which violates forum rules, the thread should be removed and the user warned. Where is the logic behind creating a giant thread of forum violations?
Dupe threads are against the rules (and every baseless theory can be considered a dupe of the others), not hacking theories threads
tongue.gif


By creating this thread, we're placing all the dupe threads in a single thread, thus removing the rule violation
wink.gif
 
well i said it was a long shot , but you dont know if you dont try, you learn by trial and error and from making mistakes ,i just was wondering what the hell it is doing after you download the certificate and then click yes to what it asks you, and then when it say altering system data dont turn off , i dont think it did that after i downloaded the games , just the certificate, but i also downloaded some or all the games first, so you dont need to download the cert to download the games, so maybe it is just useless anyways ,but who knows , im really not sure what its for,just seems to be taking up a slot on the menu for noting ,since i could download the nes games before downloading it
 
About the copying of Ambassador games. Does anyone know how the writing is done? My idea of it is:
3DS reads data that belongs to each individual 3DS > Writes encrypted data to SD card containing data specific to the individual > Signs > Verifies
The second and third step could be the same, I don't know.

If it does not work that way, not sure which way it would if it didn't, but, what if you had wires coming from the SD card pins to another SD card outside of the 3DS that are write-only. It'd write the exact same data to the second card. Though if the data being written to the SD card is for the individual 3DS this would not work.

Just an idea.
 
I'm probably way off, but if it may be possible to get the unencrypted ambassador program, would it be possible getting the encryption code by comparing the unencrypted version to the encrypted version?
 
FireGrey said:
I'm probably way off, but if it may be possible to get the unencrypted ambassador program, would it be possible getting the encryption code by comparing the unencrypted version to the encrypted version?
I'd assume so yes, but it'd take a lot of time doing cryptography, though that's not out of the question. What is in question is how you would the obtain unencrypted data. I'm pretty sure that the data would be encrypted before being sent off to anywhere else for storage.
 
What if we were to *puts on tinfoil hat* modify a 3ds cartridge so we can access the data stored on it with a computer and replace the existing files with the files from anothers.
 
Forgive me if this has been posted before. To refrain from sounding like a complete noob, I'll say right now that I have little or no knowledge about this subject, I'm just throwing this out there.

I've seen people post ideas about attempting to inject code by using a proxy to download a modded firmware to the 3DS. This could be a good idea imo if you just took out the mods. Download a 100% legit firmware to the 3DS and find some way to use the computer/proxy as a scanner as it goes through to the 3DS. Again, I have no real knowledge here, but in theory it could reveal some clues as to how the 3DS manages its encryption.

Furthermore, would it not be possible to trick the NUS servers, (I'm assuming that's still where all this is kept) into thinking your computer is a 3DS, in a way tricking the firmware into revealing the encryption keys?

Again, I have very little knowledge on this subject, I'm just making a suggestion. Feel free to troll me now.
tongue.gif
 
A rumor was floating around that the 3DS might get an addon with a second circlepad. I was extremely critical and skeptical about it, but to my horror it appears that the rumor may be true afterall.

Here's the thing. This controller isn't just serving as an alternative with the same input channel as the first one. It's a separate controller altogether and will be handled as such. Unless Nintendo thought this far ahead and already planned and hardcoded the controller data into the 3DS when they made it, it is very possible that the 3DS gets the "code" telling it how to handle the controller from the addon itself.

This would mean that Nintendo actually left a coding door open in the 3DS by which physical addons can interface with it, and if you can insert code from outside to recognize and handle an extra pad, there's no reason not to be able to insert hacking code aswell. Ofcourse some encryption may be present, but maybe this door is less well guarded than the cartridge slot.
 
Probably not, there will most likely be a required update to use the add-on, just like all the wii hardware addons. Even if it did allow for installing drivers from the hardware somehow, they will surely be signed, and we have no way of signing executables.
 
Supercool330 said:
Probably not, there will most likely be a required update to use the add-on, just like all the wii hardware addons. Even if it did allow for installing drivers from the hardware somehow, they will surely be signed, and we have no way of signing executables.

That, or it will be a game specific interface read by the cartridge.
 
  • Like
Reactions: MrMarco
I read on a topic that got closed about an idea to remove the SD card when it's running things. This is a stupid idea i admit, but it reminded me of the first PSP hacks that involved swapping memory sticks out to load homebrew. This was possible, though, because the system had no security in it's 1.00 firmware in the initial Japanese release. Being that we have no way to develop homebrew for 3DS at the moment, this is just a null issue, but maybe there might be a chance we could toy with the possibilities. Maybe have somebody give someone else a copy of their version of a game, say Excitebike for example, load it up on your system and then swap out the card with their copy of the game. If it continues to run then we've made some serious progress.

EDIT: Another Idea. Every game that's run on this system loads up with a "Nintendo 3DS" logo before the game is booted. Has anyone tried swapping methods when this occurs? I know there isn't any "custom" code we can inject with this method, but has anyone tried renaming files and moving games around between folders? Let's say, if 3DS is similar to other systems that read encryption info and load at that time, we might be able to boot Zelda and then swap out for another card with Mario Land that's been renamed to Zelda's file naming structure. Then it might load Mario instead? I hate to promote piracy, but this might be a feasible method to load games you didn't buy from the eshop. This is all assuming that the encryption is read at boot. If they may have implemented a system to routinely check for a valid game throughout it's time running then this method is bunk. I seriously doubt they've made a system like that.
 
First of all, Nintendo isn't Sony. They don't usually introduce major security holes in their software.

Next, the 'Nintendo 3DS' screen while loading games is most likely there just to distract the user while the data is being decrypted, verified and copied to RAM. If you removed the cart/sdcard while data is being loaded, the system would notice it, either 'hey, no more data is arriving, the card was most likely taken out' or an IRQ is triggered by hardware when the card is removed. Unless you're quick enough to switch the cards between two accesses (don't say it is impossible, I saw Chuck Norris do that and it worked. Chuck Norris could also obtain the common key by just looking at the device).

Admitting you manage to swap the cards at the right time, the 3DS is now reading contents you want it to read. What do you put in the card? Data has to be encrypted and signed.

Also, why are you promoting piracy and saying you hate to do that? This is like stealing your neighbour's car and going 'aw, i hate to promote car theft'. It's like you're trying to hide the warez kiddie that is inside you.
 

Site & Scene News

Popular threads in this forum