Hacking Why you deserve a 5.5 kernel exploit, but also why you can't have one

Selver

13,5,1,14,9,14,7,12,5,19,19
Member
Joined
Dec 22, 2015
Messages
219
Trophies
0
XP
426
Country
By the way, is 9.2U really still the firmware to be on, since I have OoTHax now and my BrowserHax still works on my 9.2U 2DS?

It's the right starting point, as it enables you to take a backup of you sysNAND (critical if you don't trust its reliability) and be able to backup.

However, you might also want to read up on more recent developments.
In December 2015 at CCCC in Germany, initial details of bugs in Arm9Loader were disclosed.
See https://gbatemp.net/threads/arm9loader-technical-details-and-discussion.408537/.

If you follow that thread's first post (and its sub-parts), you will discover that these Arm9Loader bugs cascaded into a significant security vulnerability, such that code execution was achieved even before the official 3DS firmware. Moreover, while initially limited to N3DS, it was later applied successfully to O3DS also.

This was a large combination of exploits and previously known vulnerabilities increasing the reliability of exploits. But really, that thread (at least via the first post links) has quite a bit of the information.

TLDR; Multiple CFW of users' choice are now available, which execute even before any official firmware, with 99% of the data on SysNAND, and low likelihood that this can be fixed by any updated later-released firmware.

At this time, the only aspects of 3DS that I believe remain secure relate to BOOTROM-set crypto keys.
 
  • Like
Reactions: Jayro

Jayro

MediCat USB Dev
Developer
Joined
Jul 23, 2012
Messages
12,999
Trophies
4
Location
WA State
Website
ko-fi.com
XP
17,087
Country
United States
It's the right starting point, as it enables you to take a backup of you sysNAND (critical if you don't trust its reliability) and be able to backup.

However, you might also want to read up on more recent developments.
In December 2015 at CCCC in Germany, initial details of bugs in Arm9Loader were disclosed.
See https://gbatemp.net/threads/arm9loader-technical-details-and-discussion.408537/.

If you follow that thread's first post (and its sub-parts), you will discover that these Arm9Loader bugs cascaded into a significant security vulnerability, such that code execution was achieved even before the official 3DS firmware. Moreover, while initially limited to N3DS, it was later applied successfully to O3DS also.

This was a large combination of exploits and previously known vulnerabilities increasing the reliability of exploits. But really, that thread (at least via the first post links) has quite a bit of the information.

TLDR; Multiple CFW of users' choice are now available, which execute even before any official firmware, with 99% of the data on SysNAND, and low likelihood that this can be fixed by any updated later-released firmware.

At this time, the only aspects of 3DS that I believe remain secure relate to BOOTROM-set crypto keys.
Thanks. The first time I booted up the Gateway launcher, I backed up my virgin 9.2U sysnand. Rxmode and emunand won't work for me, the 2DS just hangs. But I can reboot into pasta patch mode and stuff works. Just wish I could cold boot it into that mode.
 

sys64738

Well-Known Member
Member
Joined
Dec 23, 2013
Messages
156
Trophies
1
Age
47
XP
2,086
Country
Hungary
I think hackers/exploit devs waiting for NX is released.
I remember as Smea announced Ninjhax he has too waited to release it as New 3DS came out.
 

Yami Anubis ZX

Well-Known Member
Member
Joined
Mar 20, 2016
Messages
208
Trophies
0
Age
37
XP
587
Country
United States
At first I wanted the exploit but now that I've thought about it, I think he should release the exploit a year or so from now considering console NX will be coming this year, that way, when he releases it, Nintendo won't patch it because they will be dedicating resources and such to console NX, why would they wanna patch Wii U.

I never really knew Nintendo updated firmware automatically, when the system is shut down, I thought I would be on a good exploitable firmware cause I haven't had mine on for months, oh well, when I realized that, I just deleted my Wifi connection, so that my firmware stays on an exploitable firmware.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Psionic Roshambo @ Psionic Roshambo:
    Ironic this was posted today lol
  • BigOnYa @ BigOnYa:
    I think the tv series has boasted play of, I did see they said playing of it Is up, way more than norm
    +1
  • BigOnYa @ BigOnYa:
    I've been playing the next gen version on Series X all day, I love it. :wub:
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Downloading some random stuff, damn almost 400GBs in like 4 hours lol
  • Psionic Roshambo @ Psionic Roshambo:
    Gonna be over 1TB this month.... damn lol
  • Xdqwerty @ Xdqwerty:
    good night
    +1
  • BigOnYa @ BigOnYa:
    At least you have some fast speeds. What a drag that used to be, I remb downloading 1 pic back in the day, and seeing line by line show
    +1
  • BigOnYa @ BigOnYa:
    Nighty night.
  • BigOnYa @ BigOnYa:
    Or worse, you downloading something, and someone calls your phone and interupts the download, good ole AOL. Of course that's before most you guys even were born yet.
  • Psionic Roshambo @ Psionic Roshambo:
    Lol I think my first modem was 48K but it had some sort of firmware or software update that let me get 56K
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    I had EarthLink lol
  • Psionic Roshambo @ Psionic Roshambo:
    A bunch of NetZero accounts that I used for things... Lol
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    So glad I'm not in prison lol
  • BigOnYa @ BigOnYa:
    Yea marriage is a bitch sometimes...
  • Psionic Roshambo @ Psionic Roshambo:
    I legit think they passed the cyber terrorism laws from some of my hmm pranks lol
  • Psionic Roshambo @ Psionic Roshambo:
    I knocked the east coast backbone of EarthLink offline for like 6 hours one time, was on the news and everything well I mean I wasn't on the news.... Just they where having "technical difficulties" lol
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Was just one single custom packet. I miss when Internet security was an afterthought lol almost all modems and network hardware operated in promiscuous mode.
  • Psionic Roshambo @ Psionic Roshambo:
    Now these days they do sanity checks.... The source IP can't also be the destination IP lol
  • Psionic Roshambo @ Psionic Roshambo:
    They did end up using some of my stuff in the first Gulf war though lol
  • BakerMan @ BakerMan:
    GUYS I JUST COMMENTED A YOUR MOM JOKE ON A GACHA YT COMMUNITY POST (the algorithm has cursed me in terms of community posts, bc I fuck around on that sort of community post, just commenting and being a jackass)
    +1
  • BakerMan @ BakerMan:
    IT FELT SO GOOD
    +1
  • BakerMan @ BakerMan:
    the OP made a couple vocaloid characters, and the post had the caption "Guess who I did 💙💛❤️

    hint: they're from vocaloid"
    +1
  • BakerMan @ BakerMan:
    to which I responded:
    "Guess who I did 💙💛❤️

    hint: it's uremum"
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    I studied IPV6 if they hadn't passed the cyber terrorism laws omg.... In theory I have some awesome pranks but I'm afraid to test them lol
    Psionic Roshambo @ Psionic Roshambo: I studied IPV6 if they hadn't passed the cyber terrorism laws omg.... In theory I have some...