Hacking rxTools with Signatures patched out!

  • Thread starter Thread starter AHP_person
  • Start date Start date
  • Views Views 337,867
  • Replies Replies 1,545
  • Likes Likes 44
Status
Not open for further replies.
Sounds like a GOOD solution !
Gonna try this out.
Just couple questions, I actually got emunand in 9.8 version using rxtools, I managed to do that by injecting the FBI the way you explained etc..
I understand that I should format it to return back to the 7.1 emunand, but I didn't understand this part : "inject your nand backup into it" does that mean I can restore my 9.8 emunand content? and how can I do that?

"then you can extract your emunand, rename it NAND.bin and inject it to your sysnand" do I do this using the gateway launcher as if I'm restoring my nand ?

Thank you !

"inject your nand backup into it" : I mean extract your current emunand, keep it somewhere safe (and rename it emunand98.bin for example) then inject your original 7.1 nand backup with emunand tool. Like that you won't have to reformat your emunand again.


"then you can extract your emunand, rename it NAND.bin and inject it to your sysnand" : No I mean this :
4. Use rxTools to get your nand xorpad (Decryption Options -> Generate fat16 Xorpad). Put it on the FBI injection folder
5. Open emunand tool, choose extract emunand then choose the FBI injection folder for the destination
6. Execute decrypt.bat
7. Open WinImage.
8. Drag and drop the emuNAND.fat16.bin on the program then click on OK
9. Go to title/0040010/00022300/content for a EU console, title/0040010/00021300/content for a US one, and title/0040010/00020300/content for a JP one.
10. Delete the *.app and the *.tmp from the content folder.
11. Click on Image->Inject then choose the *.app in the content_region folder.
12. Same process for the *.tmd file
13. Save and close WinImage.
14. Execute reencrypt.bat
15. Restore your emunand with emunand tool.
16. Boot on the emunand with rxTools. Select Health & Safety app. FBI should boot instead. :)

(On 7.1 you only need to replace the *.app file, don't touch the *.tmd file)
 
  • Like
Reactions: oumoumad
"inject your nand backup into it" : I mean extract your current emunand, keep it somewhere safe (and rename it emunand98.bin for example) then inject your original 7.1 nand backup with emunand tool. Like that you won't have to reformat your emunand again.


"then you can extract your emunand, rename it NAND.bin and inject it to your sysnand" : No I mean this :


(On 7.1 you only need to replace the *.app file, don't touch the *.tmd file)

Yes that is the method I previously used to be able to install cia on my emunand (the fbi inject method), but here you said inject it to sysnand. how can I do that ? Doesn't that method affect only emunand, I'm sorry if I'm being all noobish here XD there must be just a simple confusion.
 
Like I said when you are sure that everything works fine, extract your 7.1.0-15E emunand, rename it NAND.bin, put it on your sd card, go to the gateway menu and hold up while choosing the downgrade option.
 
  • Like
Reactions: oumoumad
Like I said then you are sure that everything works fine, extact your 7.1.0-15E emunand, rename it NAND.bin, put it on your sd card, go to the gateway menu and hold up while choosing the downgrade option.
Alright, gonna do this and get back to you with the result.
Thank you !!

--------------------- MERGED ---------------------------

- Use devmenu to reinstall the original H&S app. (000400100002230,0 v3077 on 3DNUS)
:)

I put "000400100002230,0" on title ID and 3077 on version and I get "ERROR OCCURED"
"Error downloading title 000400100002230,0 v3077 make sure the entered title ID and versions are correct."
 
Oh man, I can't understand half of what you guys are saying. I'm supposedly one of the best students in my computer science college, but I'm feeling extremely dumb right now as I've read many forum threads about these things, how the ninjihax works, what is the emunand, etc, and I have only a superficial understanding of the exploits. I was going to try to contribute to the scene, but it looks like I'm not good enough even to be an user. Good job you guys, I'm impressed, I'm going to wait for an in depth tutorial to do anything too. Right now I installed a game CIA with pasta to my sysnand, but I'm afraid of bricking it like I almost did with my android phone if I mess with these emunand things on rxtools.
 
Alright, gonna do this and get back to you with the result.
Thank you !!

--------------------- MERGED ---------------------------



I put "000400100002230,0" on title ID and 3077 on version and I get "ERROR OCCURED"
"Error downloading title 000400100002230,0 v3077 make sure the entered title ID and versions are correct."

The comma should be after the 0, my mistake. So the title id is 0004001000022300
 
Oh man, I can't understand half of what you guys are saying. I'm supposedly one of the best students in my computer science college, but I'm feeling extremely dumb right now as I've read many forum threads about these things, how the ninjihax works, what is the emunand, etc, and I have only a superficial understanding of the exploits. I was going to try to contribute to the scene, but it looks like I'm not good enough even to be an user. Good job you guys, I'm impressed, I'm going to wait for an in depth tutorial to do anything too. Right now I installed a game CIA with pasta to my sysnand, but I'm afraid of bricking it like I almost did with my android phone if I mess with these emunand things on rxtools.

I was exactly like you couple weeks ago, I would follow a tutorial with video step by step not understanding a thing worrying if I did something wrong. but eventually you start understanding the purpose of each tool/exploit and how it works etc...
Here : http://wiki.gbatemp.net/wiki/3DS_Hacking_FAQ
that wiki helped me ALOT !
 
Oh man, I can't understand half of what you guys are saying. I'm supposedly one of the best students in my computer science college, but I'm feeling extremely dumb right now as I've read many forum threads about these things, how the ninjihax works, what is the emunand, etc, and I have only a superficial understanding of the exploits. I was going to try to contribute to the scene, but it looks like I'm not good enough even to be an user. Good job you guys, I'm impressed, I'm going to wait for an in depth tutorial to do anything too. Right now I installed a game CIA with pasta to my sysnand, but I'm afraid of bricking it like I almost did with my android phone if I mess with these emunand things on rxtools.

If you're already using pasta, then you don't have to do much :
https://gbatemp.net/threads/how-to-...w-to-rxtools-sig-patched.390624/#post-5530804
 
The comma should be after the 0, my mistake. So the title id is 0004001000022300

Awesome,
Just one question that confuses me when I saw other tutorials,
when I use FBI (H&s) to install the devmenu and sysupdater cias, do I install on SD or on NAND ?
 
I was exactly like you couple weeks ago, I would follow a tutorial with video step by step not understanding a thing worrying if I did something wrong. but eventually you start understanding the purpose of each tool/exploit and how it works etc...
Here : http://wiki.gbatemp.net/wiki/3DS_Hacking_FAQ
that wiki helped me ALOT !


Wow, thank you guys! I'm going to do it then :D!

Edit:
It works <3!
 
Last edited by Sohakes,
I can't find the H&S after injecting the modified emunand :S I even retried the procedure by injecting both the app and tmd file, but still no H&S in the home menu. any idea why ?

Edit : I did everything from start and formated emunand with the classic method this time. I see the health and safety app this time, however when I click it I get the "error has occured pelase save your data in any software currently in use then restart system"
 
Last edited by oumoumad,
I really don't know why it doesn't work, but here's another way if your sysnand and your 9.8 emunand with FBI are still linked :

1. Restore your 9.8 emunand with emunand tool
2. If you haven't done it yet, install another cia installer devmenu/bbm and sysupdater with FBI on your 9.8 emunand.
3. Go to the rxTools menu -> Dumping Options -> Dump nand files -> Emunand -> Ticket.db
4. Backup your 9.8 emunand and restore your sysnand backup to your emunand
5. Go to the rxTools menu -> Injection Options -> Inject nand files -> Emunand -> Ticket.db
6. Boot into your emunand and check if you can boot sysupdater. If yes, just use it to update your emunand to 7.1.0-15E
7. After the update, try to boot into your emunand again. If it works, extract it, rename it NAND.bin and flash it with the gw menu.
 
I really don't know why it doesn't work, but here's another way if your sysnand and your 9.8 emunand with FBI are still linked :

1. Restore your 9.8 emunand with emunand tool
2. If you haven't done it yet, install another cia installer devmenu/bbm and sysupdater with FBI on your 9.8 emunand.
3. Go to the rxTools menu -> Dumping Options -> Dump nand files -> Emunand -> Ticket.db
4. Backup your 9.8 emunand and restore your sysnand backup to your emunand
5. Go to the rxTools menu -> Injection Options -> Inject nand files -> Emunand -> Ticket.db
6. Boot into your emunand and check if you can boot sysupdater. If yes, just use it to update your emunand to 7.1.0-15E
7. After the update, try to boot into your emunand again. If it works, extract it, rename it NAND.bin and flash it with the gw menu.

I managed to boot sysupdater, but now I dunno how to use it to updare using the cia files I downloaded from 3DNUS, I got 3 choices :
(A) update
(Y) downgrade
(B) exit
when I press A I get error
 
Create an updates folder on your sd card root and put all the cias in it. (or just read the readme)
 
wow, haven't checked this scene in a while, does this mean (as a rxtools DS MSET users) i just replace the dat file and POOF i can install devmenu/bbm/fbi and run eShop dumps?!
 
Create an updates folder on your sd card root and put all the cias in it.
Dude, you're awesome !
your method worked very well ! I think rxTools is the best here since it can give all these possibilities.
I finally downgraded my console after I thought it was hopeless !
Merci beaucoup man !!

We need to make a detailed tutorial for all those who are stuck with that fatal error thing. And who knows, this method could help for many other situations.
 
someone help me :(

I tried install fbi in my emunand using fbi_injector method but when I try to install Some CIA's using the FBI is giving this error: database does not exist (0x2b)

tested with my old3ds USA

image below.
283w5y.jpg

2sbsbvd.jpg
 
Do you have access to eShop? Easiest solution is to find a free demo and download it from eShop. It will create the database for you. Otherwise you'll have to create empty import.db and title.db in the Nintendo 3DS\ID0\ID1 folder then visit Data Management and allow it to repair the files.
 
  • Like
Reactions: Gil_PL
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum