WiFiPWN research

Discussion in '3DS - Homebrew Development and Emulators' started by I_AM_L_FORCE, Dec 30, 2016.

  1. I_AM_L_FORCE
    OP

    I_AM_L_FORCE Unban me from Discord

    Member
    4
    Feb 19, 2015
    United Kingdom
    London
    So.
    It has been known for a while now that the DS WiFi settings .app file can be replaced with an exploitable DSiware game, and can then be launched through system settings.

    In the wake of Slow/Fasthax being released we have gained Kernel access on arm11, which has led to people being able to install DSiware saves, legit CIAs ect.

    What we do not know is if it is possible to access the TWLN partition of the NAND through just arm11 Kernel access, if it is in fact possible we can overwrite DS WiFi settings with say fieldrunners or sudoku, and then run the downgrade.

    Thoughts, anyone?
     
    proflayton123, Xenon Hacks and iAqua like this.
  2. iAqua

    iAqua

    Member
    9
    GBAtemp Patron
    iAqua is a Patron of GBAtemp and is helping us stay independent!

    Our Patreon
    Dec 7, 2015
    Antarctica
    Might be possible, I'll look into it.
    don't expect any implementations from me if anything exists.
     
    Last edited by iAqua, Dec 31, 2016
    CaptainSwag101 and Kvnrdrguez like this.
  3. I_AM_L_FORCE
    OP

    I_AM_L_FORCE Unban me from Discord

    Member
    4
    Feb 19, 2015
    United Kingdom
    London
    Into accessing TWLN from arm11?
     
    Kvnrdrguez likes this.
  4. CeeDee

    CeeDee I'm A Chump

    Member
    14
    GBAtemp Patron
    CeeDee is a Patron of GBAtemp and is helping us stay independent!

    Our Patreon
    May 4, 2014
    United States
    If we could access NAND through ARM11, we wouldn't need DSiWare.
     
  5. THEELEMENTKH

    THEELEMENTKH -

    Member
    7
    May 31, 2016
    Italy
    Italian summer island
    Looks really interesting imo
     
    Kvnrdrguez likes this.
  6. I_AM_L_FORCE
    OP

    I_AM_L_FORCE Unban me from Discord

    Member
    4
    Feb 19, 2015
    United Kingdom
    London
    We're talking about the TWLN partition here, which is already accessible by bugging AMPXI.
     
  7. CeeDee

    CeeDee I'm A Chump

    Member
    14
    GBAtemp Patron
    CeeDee is a Patron of GBAtemp and is helping us stay independent!

    Our Patreon
    May 4, 2014
    United States
    If that's the case, couldn't we exploit any DSiWare, the same way the current transfer method does?
     
    Kvnrdrguez likes this.
  8. I_AM_L_FORCE
    OP

    I_AM_L_FORCE Unban me from Discord

    Member
    4
    Feb 19, 2015
    United Kingdom
    London
    Very true.

    — Posts automatically merged - Please don't double post! —

    Then the only other way to use DS WiFi settings is to find an actual crash/bug in the app itself?
     
  9. Yepi69

    Yepi69 Jill-sandwiched

    Member
    7
    Nov 29, 2010
    Portugal
    Behind you
    I have a friend's 11.2 o3DSXL right here using the newly uploaded soundhax entrypoint, would love to see this work.
    Nintendo from Europe has removed the exploitable DSiWare games needed to downgrade the damn thing.
     
    Kvnrdrguez likes this.
  10. I_AM_L_FORCE
    OP

    I_AM_L_FORCE Unban me from Discord

    Member
    4
    Feb 19, 2015
    United Kingdom
    London
  11. proflayton123

    proflayton123 Sakura思い

    Member
    10
    Jan 11, 2016
    Japan
    日本
    This is a nice concept
     
  12. DarkSynopsis

    DarkSynopsis GBAtemp Fan

    Member
    3
    Oct 15, 2014
    New Zealand
    New Zealand
    Don't you need ARM9 to replace .app, I mean if we could do that already we wouldn't need to transfer the DSiWare titles from another system, could just inject .app.
     
  13. RednaxelaNnamtra

    RednaxelaNnamtra GBAtemp Advanced Fan

    Member
    6
    Dec 8, 2011
    Germany
  14. Mrrraou

    Mrrraou GBAtemp Advanced Maniac

    Member
    10
    Oct 17, 2015
    France
    TWLN cannot be accessed from ARM11 without the signed exheader of an app that has access to it, afaik. And no retail apps have access to this (mostly for security reasons), to my knowledge.

    You should document yourself more before making threads like this.
     
    Kvnrdrguez likes this.
  15. Arubaro

    Arubaro Soulspace Guardian

    Member
    4
    Sep 4, 2015
    I would say... that works if you're on a version up to 9.2, hence, you can run decrypt9?
     
  16. proflayton123

    proflayton123 Sakura思い

    Member
    10
    Jan 11, 2016
    Japan
    日本

    Refer to the above :)
     
  17. Mrrraou

    Mrrraou GBAtemp Advanced Maniac

    Member
    10
    Oct 17, 2015
    France
    You should read it too. "Required exheader FS access info bitmask: 0x100"
     
  18. KanterZ

    KanterZ YouTuber, Modder. I also do SOFTMOD Services

    Member
    2
    Oct 9, 2015
    Philippines
    This is really nice. I'll wait for it.
     
    Kvnrdrguez likes this.
  19. I_AM_L_FORCE
    OP

    I_AM_L_FORCE Unban me from Discord

    Member
    4
    Feb 19, 2015
    United Kingdom
    London
    What about system settings, or DS download play for that matter, don't they both access TWLN?
     
  20. Mrrraou

    Mrrraou GBAtemp Advanced Maniac

    Member
    10
    Oct 17, 2015
    France
    MSET does not (and why would it?), and DS DLP is not a CTR app.
     
Loading...
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.
    Dismiss Notice