Homebrew safefirmraunchhax - new Arm9 exploit discussion

  • Thread starter Thread starter uyjulian
  • Start date Start date
  • Views Views 66,439
  • Replies Replies 531
  • Likes Likes 18

Does the exploit work for you?


  • Total voters
    48

uyjulian

Homebrewer
Member
Joined
Nov 26, 2012
Messages
2,572
Reaction score
1,073
Trophies
2
Location
United States
Website
sites.google.com
XP
4,811
Country
United States
https://3dbrew.org/wiki/3DS_System_Flaws said:
The fix for firmlaunchhax was only applied to NATIVE_FIRM in 9.5.0-X, leaving SAFE_FIRM exploitable. With ARM11-kernel execution, one can trigger FIRM-launch in to SAFE_FIRM, do Kernel9 <=> Kernel11 sync and then repeat the original attack on SAFE_FIRM instead.
Other place to talk: http://gbatemp.net/threads/safehax-11-1-2-downgrade-without-dsiware.455456/

Apparently this exploit was 「leaked」 and that 「many people know about it」. Also, apparently, it was going to be released at 「the _real_ EoL」. These are some things I saw people talk about on an IRC channel. Please be careful about this information. My opinion on this, is that this is going to probably be the last arm9 exploit ever released before the 3DS' End-of-Life, since the 「inside people」 don't really want to share.

Please visit https://3ds.guide/ for updated softmod instructions that use this exploit.
 
Last edited by uyjulian,
I agree, you should implement the exploit and provide a download link for us :)
glad to have an agreeing person

--------------------- MERGED ---------------------------

lmao this is not even a real release yet xD
kinda figured that

--------------------- MERGED ---------------------------

bored as hell
cant wait for fasthax to be released officially
 
Does SAFE_FIRM load anything on startup?
....If this only works on >9.5 then why its worth discussing about it? It won't change the fact that ALL the payloads are made for the 9.2 ARM9 exploit...
No, the point is it that it works on all firmware.
 
....If this only works on >9.5 then why its worth discussing about it? It won't change the fact that ALL the payloads are made for the 9.2 ARM9 exploit...
It's K9-less ARM9 code. Payloads like Decrypt9 don't care about your system firmware, all they care about is running with privileges on the ARM9 processor. It doesn't matter if its running on 1.0, 2.1, 4.x, 9.2, 10.4 (ntrcardhax) or 11.2.

As long as the entrypoint remains at 0x23F00000 and that screens are set up properly, in the end, the firmware version doesn't even matter.
 
It's K9-less ARM9 code. Payloads like Decrypt9 don't care about your system firmware, all they care about is running with privileges on the ARM9 processor. It doesn't matter if its running on 1.0, 2.1, 4.x, 9.2, 10.4 (ntrcardhax) or 11.2.

As long as the entrypoint remains at 0x23F00000 and that screens are set up properly, in the end, the firmware version doesn't even matter.
Ye, i just woke up so, i already "removed" the dumb stuff i said lol sorry
 
btw to anyone reading this thread (holy crap 60 people!) there's no implementation of this yet. the end result will be 11.2 becoming "the new 9.2", but until an implementation is made you'll have to wait ¯\_(ツ)_/¯
 
so does this mean that arm9loaderhax can be installed safe with 9.5 and now we don't have to downgrade to 2.1 to do this when it comes out?
 

Site & Scene News

Popular threads in this forum