[Release] BootRom Dumper (A9LH Only!)

Supster131

(づ。◕‿‿◕。)づ *:・゚✧
OP
Member
Joined
Jan 19, 2016
Messages
3,315
Trophies
1
Location
My Computer
XP
2,758
Country
United States
EDIT: Yes, of course this was an April Fools joke, lol. The story I gave was bullshit obviously :P Only truth to it was that mid-kid and Aurora helped me create this (they pretty much did all the work, I just changed a bit of the text). So huge thanks to them for making this possible! As promised, I will release the source for it (I don't know why anyone would want it though). It's based on Aurora's SafeA9LHinstaller.

[Source] https://mega.nz/#!8Is0GYwR!hl-Bo8NdQoXAWFvZgql_YMqpgjgucDIX8CqpBKrG50w

ORIGINAL POST:
After a long while of testing and debugging, this was finally made possible. A bootrom dumper for the 3DS!
lTXVAC1h.jpg

This project started a few weeks ago. I was over on #cakey and was asked by mid-kid if I can help him out on something. I agreed. He told me he was working on something that would change the world. He sent me an early build of the bootrom dumper and it bricked my 2DS. Fortunately I have a hardmod for it. We continued testing, but it simply wouldn't want to work. A few days later I asked Aurora for some help. She was kind enough to lend a hand. She was able to find the correct offsets of the bootrom and even integrate screen-init to the payload (due to some people using her fork of A9LH. So yes, you can use this on any fork of A9LH). Finally, a few days ago Aurora and mid-kid got the dumper to work. You should have seen their reactions, they were almost going insane. As for what the bootrom can be used for, I wasn't told. I was simply told I had the rights to share this.

We tried making this work with 9.2 sysNAND, but it simply wouldn't work. It would freeze the system and create a corrupted file. So we opted to keep it A9LH only, since there's flaw in that the bootrom reads from a special SD card used at the factory. We originally dumped it that way, but we found that it was inefficient and risky. After some trial and error a safer way to dump the bootrom was found. Unfortunately we still couldn't to get it to work with HBL as the bootrom would have already been locked at that point.

Also, due to the request of mid-kid and Aurora, I cannot share the source code for this at the moment. They still need some time to clean up and polish the code. They told me they will most likely release the source for it in a day or two.

Download link: https://mega.nz/#!tRdxBKIC!Yk_w3zpfJ9bcGhVSKa_MpsQC3Q58Gfj86nEf6U2qW6w

Shout out to @mid-kid and @Aurora Wright for making this possible!
Shout out to @daxtsu and icecream for helping me test this!

Edit: Thanks to @astronautlevel for making the first ever bootrom exploit. It's similar to A9LH.
I've gotten an implementation of bootromloaderhax working with this!

Instructions:
1. Use @Supster131's tool to dump your bootloader
2. Copy the bootrom.bin to the /bootrom/ folder on your SD
3. Run this arm9loaderhax.bin
4. Profit!

https://mega.nz/#!K8AlGSrL!CFwOEtQnLfcFxwq3j-8QyyI9PuD_lDRQmMTR8wKruyo
 
Last edited by Supster131,

astronautlevel

Well-Known Member
Member
Joined
Jan 26, 2016
Messages
4,128
Trophies
2
Location
Maryland
Website
ataber.pw
XP
5,008
Country
United States
Whats it used for?
Theoretically, dumping the boot rom would grant us the last NCCH, which would grant us the ability to fully encrypt and decrypt NANDs.

Also, if there was any vulnerability in the bootloader, it would grant us full system access a lot easier than a9lh.
 

Faru

Well-Known Member
Member
Joined
Nov 13, 2015
Messages
148
Trophies
0
XP
174
Country
United States
Regardless if this is an April Fools joke or not, I'm downloading this shit anyway!

I wonder what we could do with this..
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • BigOnYa @ BigOnYa:
    I don't trust the free ones, but ipvanish I've used for couple years now, n like
  • Psionic Roshambo @ Psionic Roshambo:
    I wonder if they could get CPUs to run that hot then use the heat to power a steam turbine to power the CPUs....
  • BigOnYa @ BigOnYa:
    Good idea, or at least power the GPU
  • Psionic Roshambo @ Psionic Roshambo:
    It's not the movies or games downloads that I would worry about, like breaking into networks, downloading encrypted things, spying on network traffic. I have seen so many "Top Secret" seals on files when I was a kid
  • Psionic Roshambo @ Psionic Roshambo:
    I was obsessed with finding UFOs, a surprising amount of US files where stashed on computers in other countries, China back in the early 90s omg sooo much
  • BigOnYa @ BigOnYa:
    Yea that crazy, I've never tried hack into anything, I just pirate, and my ISP have send me 3-4 letters, so had to VPN it
  • Psionic Roshambo @ Psionic Roshambo:
    Ship to ship communication software for the Navy although without access to the encrypting chips it was mostly useless
  • Psionic Roshambo @ Psionic Roshambo:
    I bet now a 4090 could probably crack it? Hmmm maybe not even back then I'm pretty sure they where using like 1024 bit encryption
  • Psionic Roshambo @ Psionic Roshambo:
    Yayyy the one set finished 324GBs lol
  • Psionic Roshambo @ Psionic Roshambo:
    Compressed....
  • Psionic Roshambo @ Psionic Roshambo:
    I wonder how many years that would have taken on a 56K modem lol
  • Psionic Roshambo @ Psionic Roshambo:
    18000 hours lol
  • Psionic Roshambo @ Psionic Roshambo:
    750 days lol
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    So Internet is very much faster now lol
  • BigOnYa @ BigOnYa:
    "Time Remaining- 2 years, 9 girlfriends, 6 hairstyles, please standby..."
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    I remember one time I downloaded like a 500MB ISO file on 56K and that literally took like 2 days
  • Psionic Roshambo @ Psionic Roshambo:
    I had some sort of resume thing, I remember the software had chains
  • Psionic Roshambo @ Psionic Roshambo:
    Damned if I can't remember.the name though
  • Psionic Roshambo @ Psionic Roshambo:
    Some sort of download management app
  • BigOnYa @ BigOnYa:
    Ok good chatting, I'm off to the bar, to shoot some pool, nighty night.
    +1
  • BakerMan @ BakerMan:
    hey psi
  • BakerMan @ BakerMan:
    i call your girl lyndon the way she b on my johnson
    BakerMan @ BakerMan: i call your girl lyndon the way she b on my johnson