Homebrew [Question]: Soundhax -> Safehax -> FastHax?

ScarletDreamz

[Debug Mode]
OP
Member
Joined
Feb 16, 2015
Messages
3,967
Trophies
1
Location
/dev/sda1
XP
4,380
Country
United States
Hello;

I just wanted to ask, since Soundhax its a primary entrypoint, thats the easy part, so indeed its a ARM11 Userland Exploit.

If so, where its fasthax located? i do understand how the overflow works also the malloc and the syscalls, the only thing is, where is fasthax loaded and located on the structure of the sdcard? is it the new boot.3dsx? or is it the arm11.bin?

I just need some clarification on this.

Regards~
 
Last edited by ScarletDreamz,

GerbilSoft

Well-Known Member
Member
Joined
Mar 8, 2012
Messages
2,395
Trophies
2
Age
35
XP
4,271
Country
United States
Soundhax is an ARM11 userspace exploit. Fasthax is an ARM11 kernel exploit, which is then used to launch SAFE_MODE_FIRM for safehax.

The current version of Safehax listed in Plailect's guide has fasthax built-in. There's no separate file for it.
 
  • Like
Reactions: Texascfdad

metroid maniac

An idiot with an opinion
Member
Joined
May 16, 2009
Messages
2,089
Trophies
2
XP
2,688
Country
The 3DS has two processes, ARM11 and ARM9.
Soundhax owns the ARM11 userland, Fasthax owns the ARM11 kernel space, and Safehax owns the ARM9.

Safehax and fasthax are two different exploits, but they're bundled together into a single executable you can run from any homebrew entrypoint (i.e. anywhere you have userland privileges already).
This executable is the safehax.3dsx file located in this download. The boot.3dsx at the 3DS root is the Homebrew Launcher's menu and the arm11.bin and arm9.bin located on the SD root are safea9lhinstaller and the exploits needed to run it.
 
  • Like
Reactions: Texascfdad

NexoCube

Well-Known Member
Member
Joined
Nov 3, 2015
Messages
1,222
Trophies
0
Age
29
Location
France
XP
1,340
Country
France
safehax will launch arm9.bin on the SDCard, usually you want it to be Decrypt9 to start using 3ds.guide (ctrtransfer 2.1.0)
 

ScarletDreamz

[Debug Mode]
OP
Member
Joined
Feb 16, 2015
Messages
3,967
Trophies
1
Location
/dev/sda1
XP
4,380
Country
United States
So what its the procedure after safehax its triggered? can someone clarify me that?

Safehax -> Fasthax -> arm9?
OR
(Safehax+Fasthax) -> arm9?

Difference betweens those its the fasthax running with safehax, or fasthax executed as a different process inside the safehax.
 

metroid maniac

An idiot with an opinion
Member
Joined
May 16, 2009
Messages
2,089
Trophies
2
XP
2,688
Country
So what its the procedure after safehax its triggered? can someone clarify me that?

Safehax -> Fasthax -> arm9?
OR
(Safehax+Fasthax) -> arm9?

Difference betweens those its the fasthax running with safehax, or fasthax executed as a different process inside the safehax.

It's back to front. You need to pwn the arm11 kernel before you can pwn the arm9, so it's fasthax and then safehax.
I believe that executable does safehax as soon as it finishes fasthax,
 

ScarletDreamz

[Debug Mode]
OP
Member
Joined
Feb 16, 2015
Messages
3,967
Trophies
1
Location
/dev/sda1
XP
4,380
Country
United States
You are totally right, since fasthax its the kernel exploit for arm11. totally forgot about it..

So it will be Soundhax (Arm11 Userland Exploit) -> Fasthax (Arm11 Kernel Exploit) -> Safehax (Arm9 Kernel Exploit).
 
Last edited by ScarletDreamz,

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    That poor film crew
    +1
  • yeager1239 @ yeager1239:
    can someone help me ripping a song from a GBA game that isn't supported by Sappy, Sorry if this isn't the right place to ask im new here
  • SnowStormAkikaze @ SnowStormAkikaze:
    Just watch the movies trailer on IMDB it look really fun but I don't know why the review score is only 5.5 :/
  • K3Nv2 @ K3Nv2:
    Are you a J lo fan
  • SnowStormAkikaze @ SnowStormAkikaze:
    No, but the movie look fun XD
  • BigOnYa @ BigOnYa:
    @yeager1239 read thru here and if not answered, create a thread and ask https://gbatemp.net/forums/nintendo-gba.339/
  • Psionic Roshambo @ Psionic Roshambo:
    Your supposed to tell them about Google lol
  • K3Nv2 @ K3Nv2:
    Or be a dick and use LGTFY
  • BigOnYa @ BigOnYa:
    Yea you right... Google browser sucks ass, but they're search engine is pretty good.
    +1
  • K3Nv2 @ K3Nv2:
    Ask Jeeves it
    +1
  • K3Nv2 @ K3Nv2:
    I never realized askejeves is just ask.com now lol
  • BigOnYa @ BigOnYa:
    Damn, McDonalds burgers are as small as White castle burgers nowdays , but cost double.
  • BigOnYa @ BigOnYa:
    And the meat patty is almost as thin as the slice of cheese.
  • K3Nv2 @ K3Nv2:
    Use the app always bogos just buy weight loss injections
  • BigOnYa @ BigOnYa:
    I don't normally eat there,in fact been years, but wifey took grandkids, and brought back a cheese burger for me, so lame, and expensive.
  • BigOnYa @ BigOnYa:
    We had Raising Canes chicken for the first time other night, damn that was good. That sauce was what makes it.
  • BigOnYa @ BigOnYa:
    That is messed up.
  • BigOnYa @ BigOnYa:
    I was asked to leave a casino in Vegas years ago, because somebody asked me for change for $20 and I made change for them. The casino claimed it was against they're rules and I had to leave. I feel Karma got them back cause the casino was torn down couple years ago.
    +1
  • K3Nv2 @ K3Nv2:
    Did master chief tell you directly
    +1
  • BigOnYa @ BigOnYa:
    I sent them SARS blankets as revenge, lol
  • AncientBoi @ AncientBoi:
    @BigOnYa gimme change for a $20 pls. :):evil:
    +1
  • K3Nv2 @ K3Nv2:
    You can have his Sars blanket because he cares about you
    +1
  • K3Nv2 @ K3Nv2:
    I don't but he does
    K3Nv2 @ K3Nv2: I don't but he does