Hacking Binding Of Isaac: Rebirth doesn't appear to work on 9.5 or lower

Ronhero

Too Weird to Live, Too Rare to Die
Member
Joined
Jun 28, 2014
Messages
3,470
Trophies
1
Location
Arizona Bay
Website
127.0.0.1
XP
2,062
Country
United States
Yes you can have the ticket! Not the seed, but the ticket.
With RxTools, dump your ticket.db.

--------------------- MERGED ---------------------------

But wait RxTools Monday update for it

So you're saying n3ds support on monday?

Edit: even with rxtools we still need 9.6+ support
 

Bonovox40

Well-Known Member
Member
Joined
Apr 2, 2003
Messages
579
Trophies
2
XP
1,345
Country
United States
So you're saying n3ds support on monday?

Edit: even with rxtools we still need 9.6+ support

So even with you not able to extract the 9.9 nand w/ the isaac game on it, we're sure it's built w 9/6+ encryption/keys on it? Thought there was a slim chance it could've been built with 9.5 keys on it. Dang.

I guess if it is 9.6, is there anything useful to do w the extracted files? (once u get your 3ds serviced/fixed and can get the files) Or is there nothing else at all we can do until GW or someone figures out the 9.6 keys?
 

Ronhero

Too Weird to Live, Too Rare to Die
Member
Joined
Jun 28, 2014
Messages
3,470
Trophies
1
Location
Arizona Bay
Website
127.0.0.1
XP
2,062
Country
United States
So even with you not able to extract the 9.9 nand w/ the isaac game on it, we're sure it's built w 9/6+ encryption/keys on it? Thought there was a slim chance it could've been built with 9.5 keys on it. Dang.

I guess if it is 9.6, is there anything useful to do w the extracted files? (once u get your 3ds serviced/fixed and can get the files) Or is there nothing else at all we can do until GW or someone figures out the 9.6 keys?

That's not what im saying. I'm saying even with rxtools we need to be on 9.9 emunand for decryption to work hence the need for a hard mod
 

Bonovox40

Well-Known Member
Member
Joined
Apr 2, 2003
Messages
579
Trophies
2
XP
1,345
Country
United States
That's not what im saying. I'm saying even with rxtools we need to be on 9.9 emunand for decryption to work hence the need for a hard mod

Oh, I see. So assuming you get your 3ds fixed next week and such, what's the next steps that we can do w/ GW/cfw limitations?
 

WulfyStylez

SALT/Bemani Princess
Member
Joined
Nov 3, 2013
Messages
1,149
Trophies
0
XP
2,877
Country
United States
Once I dump it I will see if it can be crypto fixed with old 9.5 crypto so it can be fixed for emunand
Shortcut: if the byte at 0x18B in the NCCH is 0x0B, the game uses 9.6+ (secure4, not just seeddb) crypto. I've been meaning to look into this myself, but I don't have the money to buy the game just to check this.
 
D

Deleted-19228

Guest
You forget that Sony has the technical team equivalent to baboons. A company almost to the level of Samsung in offerings that was hacked, costing them trillions.

With encryption and certificates, you can't just willy nilly release a new passphrase and hope for the best. Especially if a previous encryption scheme was in place prior.

why have trillions when we can have...millions?
 
  • Like
Reactions: Maximilious

Bonovox40

Well-Known Member
Member
Joined
Apr 2, 2003
Messages
579
Trophies
2
XP
1,345
Country
United States
Shortcut: if the byte at 0x18B in the NCCH is 0x0B, the game uses 9.6+ (secure4, not just seeddb) crypto. I've been meaning to look into this myself, but I don't have the money to buy the game just to check this.

So best case scenario (thought unlikely) is if that byte does NOT reference 9.6+, then we can eventually cryptofix this for current emunand/fw spoof?
Worst case is it does and we have to wait for GW/cfw to figure out 9.6+?
 

WulfyStylez

SALT/Bemani Princess
Member
Joined
Nov 3, 2013
Messages
1,149
Trophies
0
XP
2,877
Country
United States
So best case scenario (thought unlikely) is if that byte does NOT reference 9.6+, then we can eventually cryptofix this for current emunand/fw spoof?
Worst case is it does and we have to wait for GW/cfw to figure out 9.6+?
The best and worst are flipped for me, but yeah. Also don't expect CFW to ever get those keys without GW getting them first (which is also doubtful.)
 

zoogie

playing around in the end of life
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,000
Country
Micronesia, Federated States of
Shortcut: if the byte at 0x18B in the NCCH is 0x0B, the game uses 9.6+ (secure4, not just seeddb) crypto. I've been meaning to look into this myself, but I don't have the money to buy the game just to check this.
0x18B is 01

here is the plaintext region
[SDK+NINTENDO:CTR_SDK-10_1_1_200_none].
[SDK+NINTENDO:Firmware-02_46_01].
[SDK+NINTENDO:ExtraPad].
[SDK+NINTENDO:IsRunOnSnake].
[SDK+NINTENDO:3DVolume].
[SDK+Mobiclip:DspAdpcmDec_2_0_3].
[SDK+Mobiclip:FastAudioDec_2_0_3].
[SDK+Mobiclip:Deblocker_2_0_3].
[SDK+Mobiclip:ImaAdpcmDec_2_0_3].
[SDK+Mobiclip:MobiclipDec_2_0_3].
[SDK+Mobiclip:MoflexDemuxer_2_0_3].
[SDK+NINTENDO:Ir]....
Don't anybody PM me to upload it lol :lol:
I simply was able to decrypt the first stage -- the seeddb part remains. And since I only have the movable.sed of this updated-without-backup n3ds, I can't do anything else with it.
 
  • Like
Reactions: hippy dave

Ronhero

Too Weird to Live, Too Rare to Die
Member
Joined
Jun 28, 2014
Messages
3,470
Trophies
1
Location
Arizona Bay
Website
127.0.0.1
XP
2,062
Country
United States
0x18B is 01

here is the plaintext region
[SDK+NINTENDO:CTR_SDK-10_1_1_200_none].
[SDK+NINTENDO:Firmware-02_46_01].
[SDK+NINTENDO:ExtraPad].
[SDK+NINTENDO:IsRunOnSnake].
[SDK+NINTENDO:3DVolume].
[SDK+Mobiclip:DspAdpcmDec_2_0_3].
[SDK+Mobiclip:FastAudioDec_2_0_3].
[SDK+Mobiclip:Deblocker_2_0_3].
[SDK+Mobiclip:ImaAdpcmDec_2_0_3].
[SDK+Mobiclip:MobiclipDec_2_0_3].
[SDK+Mobiclip:MoflexDemuxer_2_0_3].
[SDK+NINTENDO:Ir]....
Don't anybody PM me to upload it lol :lol:
I simply was able to decrypt the first stage -- the seeddb part remains. And since I only have the movable.sed of this updated-without-backup n3ds, I can't do anything else with it.

So your saying when I get my n3ds back it should be able to be crypto fixed?
 

Ronhero

Too Weird to Live, Too Rare to Die
Member
Joined
Jun 28, 2014
Messages
3,470
Trophies
1
Location
Arizona Bay
Website
127.0.0.1
XP
2,062
Country
United States
Looks like it. Also, the native firm is 02_46_01 (0x38) which means minimum of 9.0. So the SDK it uses is just right.

I thought this be the case since SDK is determined when the project starts we will just have to deal with the seed bin for a bit but as long as there is people like me this shouldn't be a problem. Fingers crossed by the time SDK 9.6+ comes out we will have the keys
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Psionic Roshambo @ Psionic Roshambo: https://www.youtube.com/watch?v=VpxvzFnWCu0