Hacking Would it be possible to exploit DS Download Play as an entrypoint for wireless homebrew?

Kordru

Well-Known Member
OP
Newcomer
Joined
Oct 9, 2019
Messages
45
Trophies
0
XP
222
Country
United Kingdom
Is it possible to use the DS Download Play feature on the DS(lite) as an entrypoint to loading homebrew on the system without the use of R4 cards?
I've had this idea for a long time, and it seems very plausible to me.
I was thinking that I could spoof an exploit as a legitimate program, allowing it to run wirelessly. I've seen similar exploits with the 3ds, so I believe something identical could be done on the DS(lite).
The exploited DS Download software could be hosted from a computer (or even a phone!) and spoof the device as a beacon for the DS to connect to.
Maybe we could modify those DS Download Stations they used back in the day?
 

DanTheManMS

aka Ricochet Otter
Member
Joined
Jun 2, 2007
Messages
4,449
Trophies
1
Age
33
Location
Georgia
XP
725
Country
United States
Before I say anything, note I have not at all looked into the Haxxstation. Just wanted to comment on the OP's question.

What's funny, Kordru, is that you're not at all far off from what actually happened in the very first days of DS Homebrew. It's gonna be hard to explain concisely since most of the online resources I'd normally link to are now gone, so I'll try to keep this brief.

Originally there were no slot-1 flash carts like the R4. Early DS homebrew was done by flashing a traditional slot-2 GBA flash cart with a DS binary file, then tricking the DS into booting from slot-2 somehow. There were two major ways this trickery was done.

The first was a hardware solution called PassMe where you'd plug the PassMe into slot-1, an official DS game cartridge into the PassMe, and it would use the official cart's authentication to boot the system and then hijack code execution to slot-2 instead.

The other way was called WifiMe. This used a very specific model Ralink wifi adapter popular at the time, specifically because it had the ability to broadcast unmodified raw wifi packets. You'd run the server program and it would start acting like a Download Play station running on your computer. This program used a hacked version of the official Super Mario 64 DS "download play" rom that somehow passed the DS's security check (never did learn how they managed that). You'd load up the Download Play section on the DS, start downloading from your computer, and then the hacked SM64DS rom redirected code execution to slot-2, essentially acting as a wireless version of the PassMe.

However, note that both of these methods still require a slot-2 GBA flash cart with the DS file of your choice flashed to it. This would soon change however:

Once you got either of those methods working at least once, you could have the DS run flashme.nds to install FlashMe, the replacement firmware for the DS. This required you to use an insulated metal tool to short the metal contacts of a specific part underneath the battery cover. Once done, FlashMe acted identical to the regular DS firmware except that it removed the security check for Download Play files. This meant you could now send over ANY file less than 4MB in size, not just the officially-signed Nintendo demo images. Great for quickly testing and debugging your homebrew programs. This right here is what I imagine you're thinking of.

The ability to do this became less and less useful over time, as DS homebrew moved in a direction where devices suddenly started having SD cards and filesystems and overcoming the 4MB filesize limit. This method won't work for most current DS homebrew programs for that reason, as they're expecting a filesystem that doesn't exist when it's just a standalone *.nds file loaded into RAM. Maybe with the "fcsr" fake filesystem builder thing it might be possible but this post is already long enough without speculating.
 
  • Like
Reactions: Kordru
General chit-chat
Help Users
  • No one is chatting at the moment.
  • K3N1 @ K3N1:
    No lousy dial up connection needed
  • K3N1 @ K3N1:
    Some of it was already 3D also
  • The Real Jdbye @ The Real Jdbye:
    time to google
  • The Real Jdbye @ The Real Jdbye:
    "earliest example of porn"
    An ivory statuette of a well-endowed woman discovered in Germany suggests that humanity's earliest art might have been of the erotic variety. Digging in a cave near Stuttgart last fall, University of Tübingen archaeologist Nicholas Conard unearthed what he says is the most ancient representation of a human female yet found--and, at more than 35,000 years old, one of the oldest sculptures ever discovered.
  • The Real Jdbye @ The Real Jdbye:
    but that isn't really porn, this might be the earliest actual porn https://www.dailymail.co.uk/science...-carved-north-west-China-4-000-years-ago.html
  • The Real Jdbye @ The Real Jdbye:
    and indeed, stone carving
  • K3N1 @ K3N1:
    Did you just post porn?
  • The Real Jdbye @ The Real Jdbye:
    eh, this is so tame that i'd consider it SFW
  • The Real Jdbye @ The Real Jdbye:
    it's no worse than the statue of david
  • The Real Jdbye @ The Real Jdbye:
    which is widely considered a masterpiece of art
  • K3N1 @ K3N1:
    Yeah but that's art not porn
  • Veho @ Veho:
    It depends on where you live.
  • Veho @ Veho:
    In Murrica it's considered hardcore porn.
  • K3N1 @ K3N1:
    Isn't it now what site you're on these days and you'll instantly be slayed if it's Twitter?
  • The Real Jdbye @ The Real Jdbye:
    i've seen lots of porn on twitter
  • K3N1 @ K3N1:
    Yes but it mostly involves trying to get someone cancelled
  • Veho @ Veho:
    Twitter doesn't give a fuck any more, the only thing that will get you banned there is criticizing Musk.
  • Skelletonike @ Skelletonike:
    Tbf, there's too much censorship nowadays.
  • K3N1 @ K3N1:
    Hate censorship hurt feelings
  • K3N1 @ K3N1:
    Life might be like a box of chocolates but it sure doesn't taste like it
  • Veho @ Veho:
    Censorship hurts my feefees.
  • Veho @ Veho:
    I can't even say we need to exterminate the lesser races without some pearl clutching woke librul getting mad at me.
  • K3N1 @ K3N1:
    I can't even say chocolate without being called a racist
    K3N1 @ K3N1: https://youtube.com/shorts/c0Ge8Xq_aLA?feature=share