Homebrew The bootroms

chaoskagami

G̷̘̫̍̈́̊̓̈l̴̙͔̞͠i̵̳͊ţ̸̙͇͒̓c̵̬̪̯̥̳͒͌̚h̵̹̭͛̒̊̽̚
Developer
Joined
Mar 26, 2016
Messages
1,365
Trophies
1
Location
↑↑↓↓←→←→BA
Website
github.com
XP
2,287
Country
United States
That wasn't sarcasm on my part :/ they way you worded that it sounded like you managed to pull bootrom keys

Rei does indeed have devkits. I assume they're hacked, but then again, I don't know.

People seem to underestimate the difficulty of modifying devkits though. Right now, according to people I talk with on #Cakey the most ideal exploit on devkits at the moment is MSET. You can't necessarily a9lh a devkit. The secret sector is different, and the method of calculating keys to clobber is more than likely different.

This is made worse by the large majority of people who have devkits being NDA'd.
 
  • Like
Reactions: Suiginou

dark_samus3

Well-Known Member
Member
Joined
May 30, 2015
Messages
2,372
Trophies
0
XP
2,042
Country
United States
Rei does indeed have devkits. I assume they're hacked, but then again, I don't know.

People seem to underestimate the difficulty of modifying devkits though. Right now, according to people I talk with on #Cakey the most ideal exploit on devkits at the moment is MSET. You can't necessarily a9lh a devkit. The secret sector is different, and the method of calculating keys to clobber is more than likely different.

This is made worse by the large majority of people who have devkits being NDA'd.
the arm9loaderhax keyfinder should do just fine on devkits, actually. The method is essentially the exact same, downgrade to low FW, grab OTP, decrypt secret sector, use the key bruteforcer to find a new key (using the dev FW), encrypt secret sector with new key #2, add stage1 at the proper place and flash it all to the device
 
  • Like
Reactions: N7Kopper

chaoskagami

G̷̘̫̍̈́̊̓̈l̴̙͔̞͠i̵̳͊ţ̸̙͇͒̓c̵̬̪̯̥̳͒͌̚h̵̹̭͛̒̊̽̚
Developer
Joined
Mar 26, 2016
Messages
1,365
Trophies
1
Location
↑↑↓↓←→←→BA
Website
github.com
XP
2,287
Country
United States
the arm9loaderhax keyfinder should do just fine on devkits, actually. The method is essentially the exact same, downgrade to low FW, grab OTP, decrypt secret sector, use the key bruteforcer to find a new key (using the dev FW), encrypt secret sector with new key #2, add stage1 at the proper place and flash it all to the device

Well, straight from the horse's mouth. It's a tad more involved for the first person who decides to try it, but possible.
 

Suiginou

(null)
OP
Member
Joined
Jun 26, 2012
Messages
565
Trophies
0
Location
pc + 8
XP
738
Country
Gambia, The
the arm9loaderhax keyfinder should do just fine on devkits, actually. The method is essentially the exact same, downgrade to low FW, grab OTP, decrypt secret sector, use the key bruteforcer to find a new key (using the dev FW), encrypt secret sector with new key #2, add stage1 at the proper place and flash it all to the device
"dev FW"? NATIVE_FIRM and SAFE_MODE_FIRM are the same across all devices, retail as well as dev, as far as I'm aware.
 

dark_samus3

Well-Known Member
Member
Joined
May 30, 2015
Messages
2,372
Trophies
0
XP
2,042
Country
United States
"dev FW"? NATIVE_FIRM and SAFE_MODE_FIRM are the same across all devices, retail as well as dev, as far as I'm aware.
iirc, dev FW is signed differently, meaning they won't be able to run on retail, and vice versa, which means for a9lh on a dev unit, you'll need to use one of their FWs
 
  • Like
Reactions: HiD

Swiftloke

Hwaaaa!
Member
Joined
Jan 26, 2015
Messages
1,772
Trophies
1
Location
Nowhere
XP
1,508
Country
United States
When this thread isn't just memes and shitposts, I feel like I'm learning stuff. I have little to no knowledge of low-level hardware/software, so this is all a really interesting read. If there's anything to test hardware-wise, I have a O3DS XL that I killed with a failed hardmod, so if that could be of use to anyone, just let me know.
Re-reading this thread I feel the same so let's keep it on topic please ;) I'm really enjoying reading this.
 

Aletron9000

Well-Known Member
Member
Joined
May 10, 2016
Messages
1,716
Trophies
0
Location
Classified
XP
1,610
Country
United States
Ooo so basically give us cias like a month before release due to us being able to decrypt titles

no, more like, you can fully decrypt and encrypt games on a computer
generate encrypted title keys from decrypted title keys without a 3ds
encrypted title keys to decrypted title keys without a 3ds
etc.

I think some slot0x??Key?.bin files
 
Last edited by Aletron9000,

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • realtimesave @ realtimesave:
    I tried to get a slim on a black friday once, but they ran out of stock for the $100 one
  • realtimesave @ realtimesave:
    many ages ago
  • BigOnYa @ BigOnYa:
    You can find them $50-75 nowdays if catch a deal
  • K3Nv2 @ K3Nv2:
    Still remember grabbing this ps4 slim on black Friday for $200 when the msrp was still around 300
    +1
  • BigOnYa @ BigOnYa:
    I went to auction at a mom/pops video game store few months ago that was closing, and bought 11 slims for $200, 1 was DOA but 10 work fine. so hella deal. Already rgh3'ed 8 of them. But most younger kids don't even want anymore, unless it plays stupid "fortnight", or newer shit.
  • K3Nv2 @ K3Nv2:
    Think I'm gonna use my giftcard balance on a nice pair of headphones but $100 is still limited
  • K3Nv2 @ K3Nv2:
    Soundcore q30s are nice but they leak so much sound it sounds like speakers
  • Psionic Roshambo @ Psionic Roshambo:
    Ken spend the 100 on a gun and skii mask, wait for a jogger at the park jewelry money and headphones!
    +1
  • K3Nv2 @ K3Nv2:
    If only Amazon sold guns
  • K3Nv2 @ K3Nv2:
    Fucking dick heads think it's a bad idea to get a gun 2 days later
  • BigOnYa @ BigOnYa:
    Wait, I thought you were the dickhe...nvm
  • K3Nv2 @ K3Nv2:
    I got balls on my chin and two dicks on my forehead sir
    +1
  • BigOnYa @ BigOnYa:
    Sorry, no offense there double dickhead chinballs.
  • K3Nv2 @ K3Nv2:
    Chicks still love it
    +1
  • BigOnYa @ BigOnYa:
    "Mommy, look, what is that?". "That's your soon to be daddy."
    +1
  • K3Nv2 @ K3Nv2:
    That you'll only see once
    +2
  • Veho @ Veho:
    Double dickhead chinballs is still better than double dickhead eyeballs.
  • Veho @ Veho:
    As in, the balls will grow in your eye sockets.
  • K3Nv2 @ K3Nv2:
    I paid 5 grand to get them moved to my chin
    +1
  • Veho @ Veho:
    This you?
  • K3Nv2 @ K3Nv2:
    My hair can't be that cool
    Sonic Angel Knight @ Sonic Angel Knight: JOE! :P