Homebrew [Theory] Possible method to downgrade from 11.0 without hardmod/DSiWare

Is this possible?


  • Total voters
    65
  • Poll closed .
Status
Not open for further replies.

metroid maniac

An idiot with an opinion
Member
Joined
May 16, 2009
Messages
2,088
Trophies
2
XP
2,647
Country
It used to be possible to downgrade with arm11 kernel exploits, but it's not anymore. In the 11.0 update, Nintendo added a list that's stored in arm9 that prevents files from a lower firmware from being installed, and the only way around the list is by exploiting the arm9 kernel which would make downgrading pointless. You can read more about it here: https://gbatemp.net/threads/why-the...simple-explanation-for-the-rest-of-us.441373/

That's a much cheaper and dirtier fix than I anticipated.
Rather than actually fix the ARM11 kernel exploit, Nintendo just hardcoded a blacklist of titles that may not be installed.
I guess then that legit CIAs can be installed on 11.0/11.1?
 

el_gonz87

Well-Known Member
Member
Joined
Aug 24, 2016
Messages
1,559
Trophies
0
Age
37
XP
868
Country
United States
ARM11 kernel exploit is how current downgrades to 9.2 work.

I also thought briefly about other ways of exploiting DSiWare - Petit Computer is similar to Smile BASIC and has QR scanning. It seems exploitable from that, but the real hackers would need to get on that.

Didn't 11.0 patch it so that the ARM11 update has to cross-check with a list that's part of ARM9? So downgrades from 11.0 need ARM9 access, which would nullify the reason for even downgrading.
 

ADS3500

Well-Known Member
Member
Joined
Jul 27, 2016
Messages
330
Trophies
0
XP
286
Country
Canada
That's a much cheaper and dirtier fix than I anticipated.
Rather than actually fix the ARM11 kernel exploit, Nintendo just hardcoded a blacklist of titles that may not be installed.
I guess then that legit CIAs can be installed on 11.0/11.1?
Signed CIAs can't be installed on 11.x because there isn't a public arm11 kernel exploit on 11.x. The main reason why one hasn't been released is because it isn't possible to downgrade with them anymore, so people are probably saving them to release with an arm9 kernel exploit.
 
  • Like
Reactions: gnmmarechal

metroid maniac

An idiot with an opinion
Member
Joined
May 16, 2009
Messages
2,088
Trophies
2
XP
2,647
Country
Signed CIAs can't be installed on 11.x because there isn't a public arm11 kernel exploit on 11.x. The main reason why one hasn't been released is because it isn't possible to downgrade with them anymore, so people are probably saving them to release with an arm9 kernel exploit.

I guess that the blacklist was added in addition to patching the exploit then.
 

Aletron9000

Well-Known Member
Member
Joined
May 10, 2016
Messages
1,716
Trophies
0
Location
Classified
XP
1,609
Country
United States
to downgrade to 9.2 from 11.0 without a hardmod or dsiware downgrade, an arm9 exploit is needed not just arm11.

BTW, I think someone already found an arm11 exploit on 11.1, but it is useless because we need arm9 to bypass the minimum version list

edit: ninja'd
 

Swiftloke

Hwaaaa!
Member
Joined
Jan 26, 2015
Messages
1,772
Trophies
1
Location
Nowhere
XP
1,506
Country
United States
Ugh not this again.
The 3DS won't just install an older update, especially not with this method. On older versions, we have to delete system titles because the arm9 will prevent installing older versions of existing files. (But not titles that don't exist. Downgraders would delete a title then install the older version of it, and since updates are Legit CIAs it's fine with it.) Since the update server will never delete older titles, this isn't going to work.
It especially won't work on 11.0, due to the minimum version check. Even if the server deleted titles, the arm9 would still prevent the installation.
Changing the version that appears on the title would break the signature, and it would be a non-Legit CIA (which needs an arm9 exploit).
I would also like to know how does 3DS updates work :mellow:
http://yifan.lu/2015/03/23/nintendo-3ds-system-updater/
what if we could do a FrankinFirm that has 1.10 Firm but every thing else as a 9.2 files
The sysmodules (9.2 files in your scenario) would break the console, as NATIVE_FIRM expects a minimum version for sysmodules, currently the 9.6 version.
That's a much cheaper and dirtier fix than I anticipated.
Rather than actually fix the ARM11 kernel exploit, Nintendo just hardcoded a blacklist of titles that may not be installed.
I guess then that legit CIAs can be installed on 11.0/11.1?
Sure, as long as you have an arm11 kernel exploit.
 
  • Like
Reactions: Quantumcat

gnmmarechal

Well-Known Member
Member
GBAtemp Patron
Joined
Jul 13, 2014
Messages
6,040
Trophies
2
Age
25
Location
https://gs2012.xyz
Website
gs2012.xyz
XP
6,001
Country
Portugal
ARM11 kernel exploit is how current downgrades to 9.2 work.

I also thought briefly about other ways of exploiting DSiWare - Petit Computer is similar to Smile BASIC and has QR scanning. It seems exploitable from that, but the real hackers would need to get on that.
As I've stated before, 11.0 introduced a title version list that can only be bypassed with an ARM9 kernel exploit.
 

Giodude

GBAtemp's official rock
Member
Joined
May 17, 2015
Messages
5,094
Trophies
1
Age
23
Location
New York
XP
2,761
Country
United States
Well what if you're on say 6.2, and you wanted to update to 9.2, could this be used? I have arm9loaderhax but it's an interesting thought
 

dpad_5678

Ape weak on own. Ape strong in unity.
Member
Joined
Nov 19, 2015
Messages
2,219
Trophies
1
XP
2,880
Country
United States
With all the new patches/checks 11.0 introduced, it's not even worth it anymore to try to find a traditional downgrade. At least not now.

For most people chances are that you have a CFW / CFW'able system and/or the money and/or skills to get a hard mod.
 
D

Deleted User

Guest
I've been thinking about this thing:
3DS takes files for upgrade from internet, right?
If we redirect the search to a custom site (such as tubehax) we can made that 3DS believes that the downgrade files (9.2/10.7) are 11.1.0-34 files
Is this possible?
(Sorry for my English, I'm Italian :P)
Not possible due to native_firm being changed around and updated by Nintendo which blocks out the ability to downgrade hardmodlessly without bricking.
 

C0mm4nd_

Aspirant Wii U homebrew dev :P
OP
Member
Joined
Oct 9, 2016
Messages
697
Trophies
0
Website
127.0.0.1
XP
540
Country
Italy
What about a miihax as primary ARM11 Userland exploit? It uses QR Codes (like 90% of primary hax)
*Edit* Dumb idea :\
 
Last edited by C0mm4nd_,
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Xdqwerty
    what are you looking at?
  • BakerMan
    I rather enjoy a life of taking it easy. I haven't reached that life yet though.
    SylverReZ @ SylverReZ: @AncientBoi, https://www.youtube.com/watch?v=7jUWpmU-X8k