Homebrew Unlaunch DSi | First public bootcode exploit for DSi

bennyman123abc

Well-Known Member
Member
Joined
Mar 21, 2013
Messages
920
Trophies
1
Age
22
Location
Alton, IL
XP
1,208
Country
United States
I checked his forum thread. It appears his mitigation for the issue was to write protect flag the tmd file. (which appearently Nintendo's apps will obey?). Would still like to see him open source this at some point though....
I second this. Perhaps someone else (Like Apache) could contribute help and make the exploit a bit more stable.
 

Apache Thunder

I have cameras in your head!
Member
Joined
Oct 7, 2007
Messages
4,426
Trophies
3
Age
36
Location
Levelland, Texas
Website
www.mariopc.co.nr
XP
6,792
Country
United States
Seems 0.6 can still result in bricks. Launcher SRL needs the write protect flag too. But this one is recoverable. Seems exploit still works because Stage2 doesn't even get far enough along to check that the SRL even exists. TMD file is loaded first.

Makes sense since TMD file determines file name of the .app file. It's how it would know what file name to expect for the .app. ;)
 
  • Like
Reactions: TheLegendofMario

bennyman123abc

Well-Known Member
Member
Joined
Mar 21, 2013
Messages
920
Trophies
1
Age
22
Location
Alton, IL
XP
1,208
Country
United States
Seems 0.6 can still result in bricks. Launcher SRL needs the write protect flag too. But this one is recoverable. Seems exploit still works because Stage2 doesn't even get far enough along to check that the SRL even exists. TMD file is loaded first.

Makes sense since TMD file determines file name of the .app file. It's how it would know what file name to expect for the .app. ;)
So, you're saying that a brick in this case would be soft-recoverable? If so, I consider that stable! I mean, look at the way A9LH used to be! As long as the brick was recoverable through software methods, it wasn't really a brick!
 

Deleted member 381889

Guide Writer
Member
Joined
Jan 29, 2016
Messages
2,035
Trophies
1
XP
4,420
Any pictures?
WIN_20180424_10_37_58_Pro.jpg

Source: DSiBrew Discord
dunno if it's real or not
 
Last edited by Deleted member 381889,

ThisIsDaAccount

Well-Known Member
Member
Joined
Apr 8, 2016
Messages
1,158
Trophies
0
XP
944
Country
United States
Was scrolling through that discord and found it just as you posted. Fake tmd/Tiks apparently.
The tiks are basically the same for all DSiWare on one console, so that's not really too hard to make for homebrew apps. That said, I wonder how the tmds work without checks- would just copying one from another app work or maybe some hex editing to add the appropriate short ID?

Regardless, I'll be adding instructions to TempNand as soon as I figure it out
 

Mnecraft368

I hate my name.
OP
Member
Joined
Aug 8, 2015
Messages
1,763
Trophies
0
XP
3,310
Country
United Kingdom
The tiks are basically the same for all DSiWare on one console, so that's not really too hard to make for homebrew apps. That said, I wonder how the tmds work without checks- would just copying one from another app work or maybe some hex editing to add the appropriate short ID?

Regardless, I'll be adding instructions to TempNand as soon as I figure it out
Unlaunch bypasses checks...
 

ThisIsDaAccount

Well-Known Member
Member
Joined
Apr 8, 2016
Messages
1,158
Trophies
0
XP
944
Country
United States
Unlaunch bypasses checks...
I know it does but the tmd still has information in it besides stuff for checks, such as what the .app file will be called and, maybe, what title ID the app is to not confuse it with other apps in the home menu.

Even without checks, that information still has to be there
 

Mnecraft368

I hate my name.
OP
Member
Joined
Aug 8, 2015
Messages
1,763
Trophies
0
XP
3,310
Country
United Kingdom
I know it does but the tmd still has information in it besides stuff for checks, such as what the .app file will be called and, maybe, what title ID the app is to not confuse it with other apps in the home menu.

Even without checks, that information still has to be there
http://dsibrew.org/wiki/Title_metadata
Have fun reverse engineering it then.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Psionic Roshambo @ Psionic Roshambo: https://www.youtube.com/watch?v=BjK2lPBzGzo