Hacking Post your ideas regarding how to hack the 3DS, here

  • Thread starter Thread starter Vulpes Abnocto
  • Start date Start date
  • Views Views 458,991
  • Replies Replies 1,786
  • Likes Likes 1
i realize this, im asking what it would exactly take and if theres anyway to assist it. if it isnt known exactly what's needed. it makes it harder to find something that can do whats needed
What's needed wouldn't be in any retail game, it's a technique.
http://en.wikipedia.org/wiki/Return-oriented_programming
Which the people working on the 3DS already have working.

Unfortunately there don't seem to be any obvious holes as far as getting useful homebrew working with the freedom we're used to.
 
The thing about exploitation is there is no set thing to look for. Any "traditional" exploit vectors are typically well checked and protected against "typical" exploitation techniques. The art is for exploitation is figuring out how to get the system in question to do something other than it was intended, and then figuring out how to use that to do what you want it to. There is no set technique, you just have to look for anything you can manipulate and subsequently cause "misbehaviour".
 
  • Like
Reactions: pelago
What about using a flash card to launch the DS-mode WiFi settings and modifying it so it tells the 3DS to go back to 3DS-mode upon exit of the DS-mode WiFi settings? I've noticed that in system settings, you can launch the original DS WiFi settings in DS-mode. Upon backing out of it, it sends you back into System Settings. Nintendo obviously modified the code to tell it to go back to 3DS-mode instead of returning to some game. Also, what about trying the same thing ^above^, but with DS Download Play? DS Download Play is supposed to turn off the system upon exit, but Nintendo changed it so it sends you back to 3DS-mode.
 
What about using a flash card to launch the DS-mode WiFi settings and modifying it so it tells the 3DS to go back to 3DS-mode upon exit of the DS-mode WiFi settings? I've noticed that in system settings, you can launch the original DS WiFi settings in DS-mode. Upon backing out of it, it sends you back into System Settings. Nintendo obviously modified the code to tell it to go back to 3DS-mode instead of returning to some game. Also, what about trying the same thing ^above^, but with DS Download Play? DS Download Play is supposed to turn off the system upon exit, but Nintendo changed it so it sends you back to 3DS-mode.
Actually the DS WiFi settings is a DSi-Mode app. In specific circumstances, TWL titles can specify the a title to return to (either system settings or another TWL title). http://3dbrew.org/wiki/NS#Auto-boot
 
When we figure out to dump the OS then the rest will be a lot easier. Some people know how to modify things with a hex editor, just modify the OS and then re-install it.
 
When we figure out to dump the OS then the rest will be a lot easier. Some people know how to modify things with a hex editor, just modify the OS and then re-install it.

Sorry to crush your dreams, but it doesn't work that way, that would be WAY to easy for people to hack, Nintendo isn't that dumb.
EDIT: And just like Poketard said: It's the encryption. As long as it isn't cracked, we can't program any hack now.
 
Why not? Does it not have an OS? Can we not re-install it?
http://wiibrew.org/wiki/Hardware/NAND
Hash checks in read-only hardware that confirm what it's about to boot is signed/valid. And that's just an example for the Wii.

When it comes to video games, they're using modified setups that attempt to guarantee that the same data is being loaded each time. Contrast this with a PC, where the OS being booted (and the MBR on the drive, etc.) are easily modified. The downside of the locked method is that no other OS is going to boot, but Nintendo, etc. don't want you running Linux or anything else on the system in the first place.
 
I know i am a newcomer and a noob and things...

... but i remember about a tool called E3 Flasher, which reprogram the NAND on the PS3 to downgrade.
That give me an idea.

The 3DS "know" how to decrypt the data, so its do have the key deep hidden under encryption.
And we got screwdrivers and experienced people.

What i am trying to say is, we could reprogram the 3DS NAND chip using a tool that look a bit like the E3 2013 E3 Flasher to catch the data in the 3DS that will allow us to decrypt the key.
At first look, it's impossible.
 
I know i am a newcomer and a noob and things...

... but i remember about a tool called E3 Flasher, which reprogram the NAND on the PS3 to downgrade.
That give me an idea.

The 3DS "know" how to decrypt the data, so its do have the key deep hidden under encryption.
And we got screwdrivers and experienced people.

What i am trying to say is, we could reprogram the 3DS NAND chip using a tool that look a bit like the E3 2013 E3 Flasher to catch the data in the 3DS that will allow us to decrypt the key.
At first look, it's impossible.
It's not the encryption key that's decrypted, and finding the decryption key will only allow people to check if a key for encryption they're trying is correct, which is brute-forcing, which is not feasible.
 
in addition. If you got the decryption key at last. you may have ways to continue.
1. use that key to try bruce-forcing. it might (not?) give you that key you demand (and then lead to a self-sign tool .. etc)
2. use decryption key to catch those raw materials and generate pure targets to reverse. may lead to cfw and such things.
(but how to cfw then, if that flashing is not so easily usable to people? yeah)
BTW. IIRC... those already dumpped out the nand flash, checking its file system.
However not finding enough materials (i mean likely to be all encrypted), how can you expect one key inside the nand?
well you can try yourself - i'll be very glad to see mine been proved wrong - since that is "NOT SO DIFFICULT" or even "F*CKING EASY" with a "PROPER READER" according to 3dbrew/ irc. so yellow is still trying to find something in the memory not nand.
 

Site & Scene News

Popular threads in this forum