Hacking seedminer (single system DSiWare injection)

If you are planning on using seedminer, do you have a dedicated graphics card in your PC?

  • Yes!

    Votes: 205 44.9%
  • No

    Votes: 105 23.0%
  • What's dedicated graphics?

    Votes: 35 7.7%
  • I'm a cat, we can just guess our movable.sed through feline intuition

    Votes: 112 24.5%

  • Total voters
    457
  • This poll will close: .

Marenthyu

Well-Known Member
Member
Joined
Feb 13, 2018
Messages
289
Trophies
0
Age
25
XP
165
Country
Germany
It's a New 3DS and it's received a system transfer from BOTH. I've also used Figgy's SeedHelper and I've been in the brute-forcing step forever.
The New 3DS has never been hacked before.
It's never been sent to Nintendo.
There's only one id0 in sdmc://Nintendo

Link to my movable_part1.sed: ufile.io/3egzb
Screenshots below that my help understand the situation.
It having received a system transfer makes it a lot harder to brute force.

I bet zoogie's messaged you already or will reply here when they can.
 

Totorido

New Member
Newbie
Joined
Apr 3, 2018
Messages
3
Trophies
0
Age
31
XP
31
Country
Italy
Hello!
This is my ID0: c0f631f9c486bace9589deb979dfc052
My friend code is: 2191-7768-4637
Can someone provide me the movable_part1.sed, or movable.sed (both are ok, i can bruteforce it)?
Thank you in advance!
 

AC/DS

Well-Known Member
Member
Joined
Nov 20, 2008
Messages
176
Trophies
0
XP
267
Country
In order to download the DSi ware game for SeedMiner my New 3DSXL wants to update firmware to allow me to use eShop.
I'm currently on 11.4.0-37, should I allow it to update? It is brand new, never hacked. I have no idea what version of firmware it will update to... Sorry if a n00b question, have not been here in ages.
 

zoogie

playing around in the dsiware
OP
Developer
Joined
Nov 30, 2014
Messages
8,380
Trophies
2
XP
13,604
Country
Micronesia, Federated States of
In order to download the DSi ware game for SeedMiner my New 3DSXL wants to update firmware to allow me to use eShop.
I'm currently on 11.4.0-37, should I allow it to update? It is brand new, never hacked. I have no idea what version of firmware it will update to... Sorry if a n00b question, have not been here in ages.
11.4 is identical to the latest, 11.6, in terms of hacking. And you can do seedminer on 11.6.
 

Hunter

i'ma stuffup the board
Former Staff
Joined
Nov 20, 2003
Messages
2,645
Trophies
0
Age
41
Location
Melbourne, Australia
Website
www.bundleupdates.com
XP
2,404
Country
Australia
So I'm having a problem with Seedminer. I'm using an R9 390 w/ 8GB VRAM and my offset is at the 2400s. I've triple checked my id0 and I've had different people get my movable_part1.sed with confirmations saying there is nothing wrong with it. I've had others brute force it for me with the same results with the offset just going up (Right now it's in the 2400s) and no movable.sed file. I've ran out of options and was recommended to come here. Can anyone help me?

F/C: 3755-1765-7006
id0: a2af7e877b1c1b18413892909fa125b6
and @zoogie

I have had 2 people with 2000-4000 offsets that havnt been able to get hits
both formatted and got hits within 50 offsets, so formatting may be an option
 
  • Like
Reactions: zoogie

zoogie

playing around in the dsiware
OP
Developer
Joined
Nov 30, 2014
Messages
8,380
Trophies
2
XP
13,604
Country
Micronesia, Federated States of
and @zoogie

I have had 2 people with 2000-4000 offsets that havnt been able to get hits
both formatted and got hits within 50 offsets, so formatting may be an option
Quoting from what I said in the discord #dev channel:
nintendo hb discord said:
zoogie - btw - the cause of the un-seedminerable systems. The LFCS in the config savegame (low 5 bytes) isn't synced with LFCS of the the movable.sed keyy like in the seedminerable systems - which ruins the brute force. I still have no idea what causes this. All 3 systems I've seen are: new3ds's with an old3ds msed. Don't know how that might play into it. Another of these systems was bought used and another sent to nintendo. Again, not sure if a factor.

zoogie - I have a suspicion that homebrew sys formats might be the culprit behind the unsynced LFCSs, but I'm probably wrong.
I think what happens here is that when you do a proper system format, the config savegame gets updated with the system's real LFCS. I'm really starting to lean to the possiblity that homebrew system formats don't call the function that updates the config savegame, thus, that's what probably causing the mismatched and unminable keyy's. Need to test to confirm this though.

Another obvious reason for a mismatched LFCS. Unbanning (this changes the first half of the movable.sed keyy so the 1/5 proportion doesn't hold true anymore). System formatting will likely revert to your system's fallback LFCS which will unscrew it up.
 
Last edited by zoogie,
  • Like
Reactions: Marenthyu

Hunter

i'ma stuffup the board
Former Staff
Joined
Nov 20, 2003
Messages
2,645
Trophies
0
Age
41
Location
Melbourne, Australia
Website
www.bundleupdates.com
XP
2,404
Country
Australia
Quoting from what I said in the discord #dev channel:

I think what happens here is that when you do a proper system format, the config savegame gets updated with the system's real LFCS. I'm really starting to lean to the possiblity that homebrew system formats don't call the function that updates the config savegame, thus, that's what probably causing the mismatched and unminable keyy's. Need to test to confirm this though.

Another obvious reason for a mismatched LFCS. Unbanning (this changes the first half of the movable.sed keyy so the 1/5 proportion doesn't hold true anymore). System formatting will likely revert to your system's fallback LFCS which will unscrew it up.
strange thing is, both of the ones I did, were New3DS not Old3DS/transfers just very weird, but they got done in the end, thats all that counts :)
 
  • Like
Reactions: zoogie

MrJason005

√2
Member
Joined
Nov 26, 2014
Messages
2,521
Trophies
0
Location
Κάπου
XP
1,584
Country
Greece
just spent 57 minutes bruteforcing an LFCS for someone with a banned 3DS using the mii method, and then an additional 15 minutes bruteforcing the movable.sed
people if you can, get someone to add you instead! don't wait around
 

Attachments

  • movable_part1.sed.zip
    4 KB · Views: 339

Driley97

Member
Newcomer
Joined
Apr 5, 2018
Messages
5
Trophies
0
Age
23
XP
28
Country
United States
I’m getting a new 2ds xl and want to install crew on it. I have a computer that can handle the brute force and I can get a dsi Ware game. I need someone who could help me with the part that I need a friend. I am getting it tonight, so I should in theory be able to do the hack tomorrow. If anybody is willing to help I would greatly appreciate it.
 

volexity

New Member
Newbie
Joined
Apr 6, 2018
Messages
1
Trophies
0
Age
20
XP
21
Country
Australia
(PLEASE HELP)
as soon as i launch my Seedminer_Launcher it freezes for a bit everything looks good then it will come up with Error: Out of Recourses

--------------------- MERGED ---------------------------

just spent 57 minutes bruteforcing an LFCS for someone with a banned 3DS using the mii method, and then an additional 15 minutes bruteforcing the movable.sed
people if you can, get someone to add you instead! don't wait around
if you could help me you'd be amazing
 

reix

New Member
Newbie
Joined
Apr 6, 2018
Messages
1
Trophies
0
Age
42
XP
32
Country
Austria
Hi I'm using a Mac OS System and just compiled both of the programs for it. It's attached if someone else is interested in brute forcing on Mac OS :)
Thanks for the great work!

The archive just contains the modded python script (the start command is not available on Mac OS, so I used the equivalent) and the compiled (and modified) binaries for bfcl and seedminer.
The changed sources are added in bfCL-mac-os-patched-sources.zip and seedminer-mac-os-patched-sources.zip.

To start on Mac OS open terminal and change into the extracted directory, then run the same python commands as for windows.

Brute force on GPU didn't work on my Intel GPU, but it worked very well on my AMD :)
 

Attachments

  • seedminer-mac-os.zip
    132.6 KB · Views: 317
  • bfCL-mac-os-patched-sources.zip
    40.9 KB · Views: 299
  • seedminer-mac-os-patched-sources.zip
    4.9 KB · Views: 302
Last edited by reix,
  • Like
Reactions: zoogie

dan80315

Well-Known Member
Member
Joined
Jun 30, 2009
Messages
420
Trophies
0
Age
31
Location
USA
XP
264
Country
United States
Q. Could Nintendo patch this?
A. Yes, certainly at least the dsiware injection. Now that it's a primary, they might consider it more of a priority to fix than when it was just used for dsiware transfer hax (3ds.guide). That doesn't account for the possibility of additional dsiware savehax games, however. The movable.sed vuln itself will be a bit more difficult to patch since it's pretty deeply built into the security infrastructure of the 3ds. They could at least make it harder to fish out the LFCS from userland and below.



Does this mean that if I use this method my 3DS can potentially be reverted to stock settings in the future by a patch? Or just that new people wont be able to use this method anymore but the ones who did keep their 3DS as is?
 

Hunter

i'ma stuffup the board
Former Staff
Joined
Nov 20, 2003
Messages
2,645
Trophies
0
Age
41
Location
Melbourne, Australia
Website
www.bundleupdates.com
XP
2,404
Country
Australia
Q. Could Nintendo patch this?
A. Yes, certainly at least the dsiware injection. Now that it's a primary, they might consider it more of a priority to fix than when it was just used for dsiware transfer hax (3ds.guide). That doesn't account for the possibility of additional dsiware savehax games, however. The movable.sed vuln itself will be a bit more difficult to patch since it's pretty deeply built into the security infrastructure of the 3ds. They could at least make it harder to fish out the LFCS from userland and below.



Does this mean that if I use this method my 3DS can potentially be reverted to stock settings in the future by a patch? Or just that new people wont be able to use this method anymore but the ones who did keep their 3DS as is?
they can patch the exploit to gain CFW, but once CFW is installed, it wont get patched out
 
  • Like
Reactions: zoogie
General chit-chat
Help Users
    Noctosphere @ Noctosphere: I want a gun to kill all guns, then make this gun commit suicide