WiFiPWN research

Discussion in '3DS - Homebrew Development and Emulators' started by I_AM_L_FORCE, Dec 30, 2016.

  1. I_AM_L_FORCE
    OP

    I_AM_L_FORCE Unban me from Discord

    Member
    919
    293
    Feb 19, 2015
    London
    So.
    It has been known for a while now that the DS WiFi settings .app file can be replaced with an exploitable DSiware game, and can then be launched through system settings.

    In the wake of Slow/Fasthax being released we have gained Kernel access on arm11, which has led to people being able to install DSiware saves, legit CIAs ect.

    What we do not know is if it is possible to access the TWLN partition of the NAND through just arm11 Kernel access, if it is in fact possible we can overwrite DS WiFi settings with say fieldrunners or sudoku, and then run the downgrade.

    Thoughts, anyone?
     
    proflayton123, Xenon Hacks and iAqua like this.


  2. iAqua

    iAqua GBAtemp Addict

    Member
    GBAtemp Patron
    iAqua is a Patron of GBAtemp and is helping us stay independent!

    Our Patreon
    2,747
    2,244
    Dec 7, 2015
    Antarctica
    Might be possible, I'll look into it.
    don't expect any implementations from me if anything exists.
     
    Last edited by iAqua, Dec 31, 2016
    CaptainSwag101 and Kvnrdrguez like this.
  3. I_AM_L_FORCE
    OP

    I_AM_L_FORCE Unban me from Discord

    Member
    919
    293
    Feb 19, 2015
    London
    Into accessing TWLN from arm11?
     
    Kvnrdrguez likes this.
  4. CeeDee

    CeeDee hm?~

    Member
    3,822
    5,373
    May 4, 2014
    United States
    somewhere
    If we could access NAND through ARM11, we wouldn't need DSiWare.
     
  5. THEELEMENTKH

    THEELEMENTKH AN ANGRY GIRAFFE!

    Member
    930
    586
    May 31, 2016
    Spain
    Hell
    Looks really interesting imo
     
    Kvnrdrguez likes this.
  6. I_AM_L_FORCE
    OP

    I_AM_L_FORCE Unban me from Discord

    Member
    919
    293
    Feb 19, 2015
    London
    We're talking about the TWLN partition here, which is already accessible by bugging AMPXI.
     
  7. CeeDee

    CeeDee hm?~

    Member
    3,822
    5,373
    May 4, 2014
    United States
    somewhere
    If that's the case, couldn't we exploit any DSiWare, the same way the current transfer method does?
     
    Kvnrdrguez likes this.
  8. I_AM_L_FORCE
    OP

    I_AM_L_FORCE Unban me from Discord

    Member
    919
    293
    Feb 19, 2015
    London
    Very true.

    — Posts automatically merged - Please don't double post! —

    Then the only other way to use DS WiFi settings is to find an actual crash/bug in the app itself?
     
  9. Yepi69

    Yepi69 Vivid and busy gamer

    Member
    2,421
    1,018
    Nov 29, 2010
    Portugal
    Behind you
    I have a friend's 11.2 o3DSXL right here using the newly uploaded soundhax entrypoint, would love to see this work.
    Nintendo from Europe has removed the exploitable DSiWare games needed to downgrade the damn thing.
     
    Kvnrdrguez likes this.
  10. I_AM_L_FORCE
    OP

    I_AM_L_FORCE Unban me from Discord

    Member
    919
    293
    Feb 19, 2015
    London
  11. proflayton123

    proflayton123 Undeclared Shitposter 2.1

    Member
    5,799
    2,161
    Jan 11, 2016
    Japan
    日本
    This is a nice concept
     
  12. DarkSynopsis

    DarkSynopsis GBAtemp Fan

    Member
    399
    235
    Oct 15, 2014
    New Zealand
    New Zealand
    Don't you need ARM9 to replace .app, I mean if we could do that already we wouldn't need to transfer the DSiWare titles from another system, could just inject .app.
     
  13. RednaxelaNnamtra

    RednaxelaNnamtra GBAtemp Advanced Fan

    Member
    748
    637
    Dec 8, 2011
    Germany
  14. Mrrraou

    Mrrraou GBAtemp Advanced Maniac

    Member
    1,869
    2,167
    Oct 17, 2015
    France
    TWLN cannot be accessed from ARM11 without the signed exheader of an app that has access to it, afaik. And no retail apps have access to this (mostly for security reasons), to my knowledge.

    You should document yourself more before making threads like this.
     
    Kvnrdrguez likes this.
  15. Arubaro

    Arubaro Soulspace Guardian

    Member
    1,669
    470
    Sep 4, 2015
    I would say... that works if you're on a version up to 9.2, hence, you can run decrypt9?
     
  16. proflayton123

    proflayton123 Undeclared Shitposter 2.1

    Member
    5,799
    2,161
    Jan 11, 2016
    Japan
    日本

    Refer to the above :)
     
  17. Mrrraou

    Mrrraou GBAtemp Advanced Maniac

    Member
    1,869
    2,167
    Oct 17, 2015
    France
    You should read it too. "Required exheader FS access info bitmask: 0x100"
     
  18. KanterZ

    KanterZ YouTuber, Modder. I also do SOFTMOD Services

    Member
    319
    98
    Oct 9, 2015
    This is really nice. I'll wait for it.
     
    Kvnrdrguez likes this.
  19. I_AM_L_FORCE
    OP

    I_AM_L_FORCE Unban me from Discord

    Member
    919
    293
    Feb 19, 2015
    London
    What about system settings, or DS download play for that matter, don't they both access TWLN?
     
  20. Mrrraou

    Mrrraou GBAtemp Advanced Maniac

    Member
    1,869
    2,167
    Oct 17, 2015
    France
    MSET does not (and why would it?), and DS DLP is not a CTR app.