ROM Hack [Release] 3DS_CTR_Decryptor-VOiD

piratesephiroth

I wish I could read
Member
Joined
Sep 5, 2013
Messages
3,453
Trophies
2
Age
103
XP
3,233
Country
Brazil
I not understanding some parts. Now can decrypt nand yes? Possible to create nand for forced downgrade? If not why not?
Wel, that's something I would like to understand too.
Yeah we can dump NANDs and decrypt and encrypt back the FAT16 partition, where most of the stuff is stored... But it seems we can't decrypt the firmware partition, and that's what would be relevant for a downgrade.
 
  • Like
Reactions: Ryanrocks462

Relys

^(Software | Hardware) Exploit? Development.$
OP
Member
Joined
Jan 5, 2007
Messages
878
Trophies
1
XP
1,239
Country
United States
New version of the multitool thing:
https://www.sendspace.com/file/hnqb4b

Xorpad generation speed is roughly twice as fast as the current version! ~3.55MB/s, up from ~1.8MB/s.

I haven't thoroughly tested it, though. So please test all aspects of it.


New update:
1. Committed sbJFn5r's experimental changes to the git repo.
2. Merged einstein95 PR to implement padding via rsf in CDNto3DS.py: https://github.com/Relys/3DS_Multi_Decryptor/pull/1
3. Merged idunoe's PR to support CIA building in CDNto3DS.py: https://github.com/Relys/3DS_Multi_Decryptor/pull/2
4. Uploaded applestash's fork of Project_CTR to git and changed readme files to redirect there: https://github.com/Relys/Project_CTR
 

Vappy

Well-Known Member
Member
Joined
May 23, 2012
Messages
1,508
Trophies
2
XP
2,613
Country
Wel, that's something I would like to understand too.
Yeah we can dump NANDs and decrypt and encrypt back the FAT16 partition, where most of the stuff is stored... But it seems we can't decrypt the firmware partition, and that's what would be relevant for a downgrade.

To decrypt the NAND you need control over ARM9. But if you have that, you don't have any real reason to downgrade. Unless you can somehow use one 3DS to decrypt the NAND of another on a higher firmware, I'm not sure how helpful downgrading would be.
 

piratesephiroth

I wish I could read
Member
Joined
Sep 5, 2013
Messages
3,453
Trophies
2
Age
103
XP
3,233
Country
Brazil
To decrypt the NAND you need control over ARM9. But if you have that, you don't have any real reason to downgrade. Unless you can somehow use one 3DS to decrypt the NAND of another on a higher firmware, I'm not sure how helpful downgrading would be.
Yeah but I wonder... Gateway has total control over the emunand and it's possible to make a system transfer from a real system to the emunand... So if we coud grab the necessary data from this transfered emunand and decrypt the firmware partition, could't we modify it (downgrade as necessary) and flash it back to the original system via a hardware mod? (implying the original info isn't lost in the transfer)
 
  • Like
Reactions: Ryanrocks462

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
Yeah but I wonder... Gateway has total control over the emunand and it's possible to make a system transfer from a real system to the emunand... So if we coud grab the necessary data from this transfered emunand and decrypt the firmware partition, could't we modify it (downgrade as necessary) and flash it back to the original system via a hardware mod? (implying the original info isn't lost in the transfer)
you would need xorpads from the original 3ds too or you couldn't encrypt back to the original 3ds's unique encryption, and you can only obtain them via arm9 control.....i think the only real stuff you might be able to do is maybe make a custom emunand.....maybe like changing region, but again now we can install title updates from other regions....the use would be rather limited
 

Vappy

Well-Known Member
Member
Joined
May 23, 2012
Messages
1,508
Trophies
2
XP
2,613
Country
IF someone were able to reverse the hidden hardware crypto, and IF you had a way to dump the appropriate per-console keys without needing a Process9 exploit, it might be possible, but those are both very big 'if's and the amount of time and effort it'd require is probably comparable to just finding a new kernel exploit.
 
  • Like
Reactions: drwhojan

drwhojan

Well-Known Member
Member
Joined
Jul 14, 2009
Messages
4,196
Trophies
1
Age
45
Location
Where I Am!
XP
1,702
Country
United Kingdom
IF someone were able to reverse the hidden hardware crypto, and IF you had a way to dump the appropriate per-console keys without needing a Process9 exploit, it might be possible, but those are both very big 'if's and the amount of time and effort it'd require is probably comparable to just finding a new kernel exploit.


I would be very happy just to have my own encryption decryption 3DS key :) , I sure hope they come up with a way to extract this!.

But as you say very big If's :yay: , But the program you would have to edit to add you're key , so it would decrypt and encrypt you're files ..

EDIT: Na not hit 100 page :lol:
 

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
New update:
1. Committed sbJFn5r's experimental changes to the git repo.
2. Merged einstein95 PR to implement padding via rsf in CDNto3DS.py: https://github.com/Relys/3DS_Multi_Decryptor/pull/1
3. Merged idunoe's PR to support CIA building in CDNto3DS.py: https://github.com/Relys/3DS_Multi_Decryptor/pull/2
4. Uploaded applestash's fork of Project_CTR to git and changed readme files to redirect there: https://github.com/Relys/Project_CTR
so is there any plans to fix the romfs issues with makerom, or is it just to keep this available
 
  • Like
Reactions: Hiccup

Huntereb

Well-Known Member
Member
Joined
Sep 1, 2013
Messages
3,234
Trophies
0
Website
lewd.pics
XP
2,446
Country
United States
SciresM Man, I still haven't even beat this game yet. The only "hack" I've done is repacking the game as version 9.9.9 so that the updates don't effect me.

Has anyone noticed that you can't show Hoopa in trades at all anymore? Blame the 1.1 update and Nintendo trying to hide secrets. :P
 

AHP_person

Well-Known Member
Member
Joined
Nov 2, 2014
Messages
364
Trophies
0
XP
518
Country
United States
So. This is the improved way to hack your 3ds alternatively. Because I'm looking forward to doing so

All this can do it decrypt your files. If you want to edit things directly, I'm pretty sure there are checks that need to be patched. I know Gateway disables checks on roms and most CIAs, but I'm not so sure about NAND. You can probably do a little testing by messing with the NAND and injecting it into EmuNAND.
 

PokeChampion

Well-Known Member
Member
Joined
Apr 5, 2014
Messages
324
Trophies
0
Age
26
XP
132
Country
United States
All this can do it decrypt your files. If you want to edit things directly, I'm pretty sure there are checks that need to be patched. I know Gateway disables checks on roms and most CIAs, but I'm not so sure about NAND. You can probably do a little testing by messing with the NAND and injecting it into EmuNAND.
Well. I took back that Micro SD Card holder and SD card. But unless there are other exploits. I still have my 4 GB SD card left. So
 

liomajor

Well-Known Member
Member
Joined
Jun 10, 2008
Messages
1,468
Trophies
0
XP
1,373
Country
United States
Is it possible to receive a full update and build up a 3ds/cia including it for offline purpose?

Code:
0004001
 
JPN            USA            EUR
00020000       00021000       00022000

I already have extracted my ticket keys and downloaded the file (v9.2.0-20E), but its only 5 MB and seems only a part of it.
 

einstein95

Well-Known Member
Member
Joined
Aug 31, 2013
Messages
230
Trophies
0
Age
29
XP
312
Country
New Zealand
Is it possible to receive a full update and build up a 3ds/cia including it for offline purpose?

Code:
0004001
 
JPN            USA            EUR
00020000      00021000      00022000

I already have extracted my ticket keys and downloaded the file (v9.2.0-20E), but its only 5 MB and seems only a part of it.
Wouldn't it be better to just decrypt the update partition from a 9.2.0-20E game?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • K3Nv2 @ K3Nv2:
    I'll reformat and have a 3tb raid0 m. 2 at least
    +1
  • K3Nv2 @ K3Nv2:
    Lmao that sold out fast
    +1
  • Veho @ Veho:
    Yeet the cat.
    +1
  • K3Nv2 @ K3Nv2:
    Good idea
    +1
  • The Real Jdbye @ The Real Jdbye:
    i thought everybody knew cocktails are like 75% ice
  • Veho @ Veho:
    Yeah but not like this.
  • Veho @ Veho:
    It's not like they're complaining that their Slurpee is 99% ice or something, but if the cocktail calls for "shot of vodka, shot of vermouth, shot of gin, shot of Campari, three shots of juice, squirt of lemon" and ends up being a thimbleful of booze, that's a problem.
  • The Real Jdbye @ The Real Jdbye:
    the funny thing is cocktails in norway are only allowed to have 1 20ml shot of booze
  • The Real Jdbye @ The Real Jdbye:
    so..... yeah
  • The Real Jdbye @ The Real Jdbye:
    we're used to only having a thimbleful of booze
  • Veho @ Veho:
    Booo.
  • The Real Jdbye @ The Real Jdbye:
    same thing if you want whisky on the rocks or something, you can't get a double
  • The Real Jdbye @ The Real Jdbye:
    but you could buy as many shots of whisky (or anything else) as you want and ask for a glass of ice and pour them in
  • The Real Jdbye @ The Real Jdbye:
    it's dumb
  • Veho @ Veho:
    Maybe.
  • Veho @ Veho:
    There was a comparison of the number of Ibuprofen poisonings before and after they limited the maximum dosage per box or per pill (i'll look that up). No limit on the number of boxes you can still buy as many as you want, so people argued it was pointless.
  • Veho @ Veho:
    But the number of (accidental) poisonings dropped because drinking an entire package of ibuprofen pills went from "I need a new liver" to "I need a new box of Ibuprofen".
  • Veho @ Veho:
    Here we have ketoprofen that used to be prescription-only because of the risk of toxic dosages, but then they halved the dose per pill and sell them in bottles of six pills apiece instead of twenty and it doesn't need a prescription any more. Yes you can buy more than one bottle but people simply don't.
  • Psionic Roshambo @ Psionic Roshambo:
    Usually accidentally overdose of ibuprofen here is from people taking like cold medicine then ibuprofen for a headache and the combination is over what they need
    Veho @ Veho: https://imgur.com/gallery/QQkYnQu