Hacking [WIP] KARL3DS - Kernel access on N3DS via Ninjhax + Loadcode

  • Thread starter Thread starter Rokkubro
  • Start date Start date
  • Views Views 937,200
  • Replies Replies 4,457
  • Likes Likes 43
Status
Not open for further replies.
So with BRM would KARL install .cia's of games that came preinstalled on certain 3ds/2ds systems? ("Legit" cia, sm3dl, pokemon xy/oras, ect.) I've been wrapped up in this scene for months now and invested $160 on a 4.5 old3DS, all I want to do is play a randomized ORAS and XY without buying a gateway. (I literally own all 4 versions, this isn't about piracy.)


You have access to all services. So you write some code to install a CIA using AM. BGRM works through HB menu now, and would let you install legit (and only legit) CIAs.

yes, legit cia will work
 
  • Like
Reactions: Margen67
Damn, completely defeats the purpose then. v.v

When will I be able to play a randomized 6th gen pokemon game? D: I don't wanna buy a gateway.
 
  • Like
Reactions: Margen67
I guess there's not much we really need to protect since it's obvious how we're pulling it off.
1) install old MSET. Not going into how to do this atm since it was actually more work than I had thought when I started. There's no risk of bricking by doing this, though.
2) Install a ROP chain into your DS profile which matches the version of your mset.

Beyond that is all the code (ROP) I had to port to actually get code execution. You can't use this for 4.5 launcher.dats or anything, either. Those use exploits which have been patched to gain more control over the system.

How can i install old MSET? what is the file name?
 
  • Like
Reactions: Margen67
I busted my ass figuring out the best way to reinstall and downgrade system titles. The final solution ended up being simpler than I thought, though. There's no version spoofing. Version spoofing breaks signatures, and thus won't work on sysnand. We'll have it packaged nicely so users don't have to deal with much technical stuff and have nice UX.


May I ask if you used BigRedMenu? It lets you delete system titles so I think that if you just deleted the "new" mset, you could just install the old one... The console would think it was just a newly installed title, right?

Sorry for asking, I know you have better things to do, other than answering my question.
 
  • Like
Reactions: codychaosx
You fail to realize that an entry point/exploit is being worked on since November of 2014. They might be the first ones to publicly announced the MSET comeback but I wouldn't bet a single penny they were the first ones to actually discover how this is done. In the end GW's probably gonna release an update involving MSET before KARL even sees the light of day only to be called thieves... Why? Because by your logic of someone went public with a discovery that would mean they're the first to discover this and everybody else is just a copycat. People should be more sceptical about stuff :rolleyes:


I didn't fail to realize anything, just a little light humor. GW has yes, probably been sitting on this one, especially as it may still be unpatched.

My point is, it's public-ish now, and it'll be proper public soon enough so they won't need to worry about 'burning' an exploit, maybe soon enough people on higher firmwares can migrate off the Loz/CN launcher grind.

tony_2018
You're the biggest douche on this site by far, do you ever read your own posts?
What about it?
If they have an update for their card, everybody's happy. What about that?

Anyhow, my question still stands, could this MSET work on saaaay, 7.x or 8.x as well as 9.x?
 
  • Like
Reactions: codychaosx
I didn't fail to realize anything, just a little light humor. GW has yes, probably been sitting on this one, especially as it may still be unpatched.

My point is, it's public-ish now, and it'll be proper public soon enough so they won't need to worry about 'burning' an exploit, maybe soon enough people on higher firmwares can migrate off the Loz/CN launcher grind.

tony_2018
You're the biggest douche on this site by far, do you ever read your own posts?
What about it?
If they have an update for their card, everybody's happy. What about that?

Anyhow, my question still stands, could this MSET work on saaaay, 7.x or 8.x as well as 9.x?


Thats a question to you and you can't even answer? So that makes me a douche because you failed to answer a question? ROFLMAO.
 
Thats a question to you and you can't even answer? So that makes me a douche because you failed to answer a question? ROFLMAO.


You didn't read my reply? Unreal, the answer was there, read it again, and again and again and again till you spot. Go fetch your glasses.

Here:
What about it? (says tony)
If they have an update for their card, everybody's happy. (my answer)

The original question was rhetorical (look it up), think of it as a little joke (again, look it up) or piece of humor (google is your friend).
 
People need to stop complaining about things. The only thing we should complain about is why I'm so awesome! :ha:

i hope people are smart enough to not take this seriously..
 
  • Like
Reactions: Margen67
mset from 6.2.0 is hardly a "new" exploit that can be "burned".

I hope that mset isn't a required exploit, since I do like the ability to run DS games.

I wonder whether it is possible for the ARM11 kernel to hard-reset the ARM9 in a manner that doesn't also hard-reset the ARM11. The ARM11 would do firmlaunchhax immediately. This would allow exiting DS/DSi/AGB mode without unloading KARL3DS...
 
I wonder whether it is possible for the ARM11 kernel to hard-reset the ARM9 in a manner that doesn't also hard-reset the ARM11. The ARM11 would do firmlaunchhax immediately. This would allow exiting DS/DSi/AGB mode without unloading KARL3DS...

Even Nintendo doesn't try to recover from AGB_FIRM and TWL_FIRM. They just have the MCU trigger a complete reset and throw everything out the window, essentially.

Also it's likely Gateway doesn't want to re-enable mset hax because it's kind of... dirty? That's what I figured the reason was. That and their arm11 hax barely even exist.
 
  • Like
Reactions: VinsCool
Even Nintendo doesn't try to recover from AGB_FIRM and TWL_FIRM. They just have the MCU trigger a complete reset and throw everything out the window, essentially.

Also it's likely Gateway doesn't want to re-enable mset hax because it's kind of... dirty? That's what I figured the reason was. That and their arm11 hax barely even exist.

Since the NCCH is fixed with another key (So I've heard) it would need arm9hax in said firmware to retrieve it? Is there not a way to do that right now or is there other ways? (I am only repeating what I've heard so I'm pretty stupid so explain if you'd like!)
 
Since the NCCH is fixed with another key (So I've heard) it would need arm9hax in said firmware to retrieve it? Is there not a way to do that right now or is there other ways? (I am only repeating what I've heard so I'm pretty stupid so explain if you'd like!)
It does need arm9hax in 9.6 to retrieve NCCH KeyX for 0xB
There is a vuln in 9.6 crypto, but for FIRM, not for NCCH
 
  • Like
Reactions: Psi-hate
It does need arm9hax in 9.6 to retrieve NCCH KeyX for 0xB

You need arm9hax (or something) to USE the new NCCH crypto keyslot. You need bootromhax to actually dump its keyX.
Also, the new NCCH crypto has exactly nothing to do with legacy FIRMs.
 
You need arm9hax (or something) to USE the new NCCH crypto keyslot. You need bootromhax to actually dump its keyX.
Also, the new NCCH crypto has exactly nothing to do with legacy FIRMs.

Yes, sorry
Since we could generate NCCH KeyX before, I was confused
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum