Homebrew [33c3] Console Hacking 2016 (3DS/WiiU) talk Dec 27-30: smea, derrek, nedwill, naehrwert

What will Santa Hax bring us this year?

  • Slowhax (arm11 kernelhax)

    Votes: 184 32.1%
  • Soundhax (free primary userland sploit)

    Votes: 183 31.9%
  • Bootrom dump method !!

    Votes: 166 28.9%
  • Something more awesome than the above.

    Votes: 156 27.2%
  • Something nice for the WiiU

    Votes: 178 31.0%
  • Nothing. Ninty will banhammer: 001-1337 "Your use of this speech has been restricted by Nintendo"

    Votes: 80 13.9%
  • This checkbox pleases me

    Votes: 152 26.5%
  • ( ͡° ͜ʖ ͡°)

    Votes: 92 16.0%

  • Total voters
    574
  • Poll closed .
D

Deleted User

Guest
how i feel about this thread right now
wake_me_up_when_i_care_by_porgonz-d87y1ps.jpg
 

Mrrraou

Well-Known Member
Member
Joined
Oct 17, 2015
Messages
1,873
Trophies
0
XP
2,374
Country
France
Gateway can't replace the home menu on NAND. My point is that we could possibly no longer require a third party mechanism in order to install modified titles to NAND.
what the fuck
and we already kind of do, wtf do you think Luma does already
it's possible without sighax, please learn wtf you are talking about before saying so much shit omg
 

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,077
Country
United States
So what is this UnbanMii you speak of and how does it work?
It's an ARM9 binary that loads the CTCert and DeviceID into the ITCM (ARM9 RAM) of a banned console in order to ban it. This doesn't totally make the source system useless, but it definitely means that they can't both go online together.

--------------------- MERGED ---------------------------

what the fuck
and we already kind of do, wtf do you think Luma does already
it's possible without sighax, please learn wtf you are talking about before saying so much shit omg
*facepalm* You seem to have a problem with comprehension.
 
  • Like
Reactions: Deleted User

I_AM_L_FORCE

Unban me from Discord
Member
Joined
Feb 19, 2015
Messages
1,064
Trophies
0
Age
23
Location
London
XP
1,537
Country
United Kingdom
It's an ARM9 binary that loads the CTCert and DeviceID into the ITCM (ARM9 RAM) of a banned console in order to ban it. This doesn't totally make the source system useless, but it definitely means that they can't both go online together.

--------------------- MERGED ---------------------------


*facepalm* You seem to have a problem with comprehension.
Could the CtCert be taken from another console, say a Wii or WiiU?
 

gnmmarechal

Well-Known Member
Member
GBAtemp Patron
Joined
Jul 13, 2014
Messages
6,043
Trophies
2
Age
25
Location
https://gs2012.xyz
Website
gs2012.xyz
XP
6,012
Country
Portugal
Exactly, which is why nobody has released it. In a moralistic sense, nobody wants to sacrifice a system, especially if they don't own it.

--------------------- MERGED ---------------------------


If we had the ability to sign everything ourselves (which would be a tedious process), then what would be the need for a custom firmware in that regard?
Actually, THAT would be a custom firmware. Luma, Corbenik, etc. are not CFWs, though that is the most used term. They just patch things and then boot.

Sent from my cave of despair where I collect souls
 
  • Like
Reactions: Gray_Jack

Mrrraou

Well-Known Member
Member
Joined
Oct 17, 2015
Messages
1,873
Trophies
0
XP
2,374
Country
France
Actually, THAT would be a custom firmware. Luma, Corbenik, etc. are not CFWs, though that is the most used term. They just patch things and then boot.

Sent from my cave of despair where I collect souls
no one is gonna bruteforce an hash for a patched firmware though. however there will definitely be some kind of payload chainloader i assume.
 

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,077
Country
United States
Could the CtCert be taken from another console, say a Wii or WiiU?
We don't know. We don't have the resources to test this, but it'd most likely cause bigger issues with NIM.

Actually, THAT would be a custom firmware. Luma, Corbenik, etc. are not CFWs, though that is the most used term. They just patch things and then boot.

Sent from my cave of despair where I collect souls
I know, and I was gonna edit my post because this is a really semantic thing, but I got caught up in replies.
 
  • Like
Reactions: gnmmarechal

gnmmarechal

Well-Known Member
Member
GBAtemp Patron
Joined
Jul 13, 2014
Messages
6,043
Trophies
2
Age
25
Location
https://gs2012.xyz
Website
gs2012.xyz
XP
6,012
Country
Portugal
no one is gonna bruteforce an hash for a patched firmware though. however there will definitely be some kind of payload chainloader i assume.
It'd be cool, though. Payload chainloader.... I suppose a replacement for A9LH?

Sent from my cave of despair where I collect souls
 

gnmmarechal

Well-Known Member
Member
GBAtemp Patron
Joined
Jul 13, 2014
Messages
6,043
Trophies
2
Age
25
Location
https://gs2012.xyz
Website
gs2012.xyz
XP
6,012
Country
Portugal
not that cool. because you'd have to update it manually all the time before updating and stuff.
and pretty much.
I mean, it'd be cool to just say "it is possible and has been done".

Sent from my cave of despair where I collect souls
 

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,077
Country
United States
not that cool. because you'd have to update it manually all the time before updating and stuff.
and pretty much.
Yeah, but this has always been the case with everything; even Android requires user flashed items to be reflashed after a ROM update. This would honestly be no different than the PSP other than the user being required to replace their custom titles with the stock ones in order to properly receive OTA updates.
 

caitsith2

Well-Known Member
Member
Joined
Jan 16, 2004
Messages
350
Trophies
2
Age
43
Location
a secret location 93 million miles from the sun
Website
www.caitsith2.com
XP
2,476
Country
Canada
Depending on the sighax bug, it might be possible that the one "signature" will be universal for any custom firmware binary, due to the fact as the 33c3 talk explained, the pointer is being set to the fixed address of the calculated SHA256 hash. If this address is in fact the same, regardless of the firmware binary being loaded, then that sighax signature will work for pretty much anything.
 

Apache Thunder

I have cameras in your head!
Member
Joined
Oct 7, 2007
Messages
4,453
Trophies
3
Age
36
Location
Levelland, Texas
Website
www.mariopc.co.nr
XP
6,862
Country
United States
Depending on the sighax bug, it might be possible that the one "signature" will be universal for any custom firmware binary, due to the fact as the 33c3 talk explained, the pointer is being set to the fixed address of the calculated SHA256 hash. If this address is in fact the same, regardless of the firmware binary being loaded, then that sighax signature will work for pretty much anything.

No. You'd have to bruteforce a new sig for every new FIRM you make. There is no one sig for all with the type of RSA sig checking bootrom does. Perhaps you can instead make a chainloader that you don't really have to update very often but that's the best you can do without having to make new sigs for every update to your CFW.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Psionic Roshambo @ Psionic Roshambo:
    Sentinel of the stary skies
  • K3Nv2 @ K3Nv2:
    Ds is 20 years old this year
  • Psionic Roshambo @ Psionic Roshambo:
    So MJ no longer wants to play with it?
  • K3Nv2 @ K3Nv2:
    He put it down when the 3ds came out
  • SylverReZ @ SylverReZ:
    @K3Nv2, RIP Felix does great videos on the PS3 yellow-light-of-death.
  • Jayro @ Jayro:
    Eventhough the New 3DS XL is more powerful, I still feel like the DS Lite was a more polished system. It's a real shame that it never got an XL variant keeping the GBA slot. You'd have to go on AliExpress and buy an ML shell to give a DS phat the unofficial "DS Lite" treatment, and that's the best we'll ever get I'm afraid.
    +1
  • Jayro @ Jayro:
    The phat model had amazingly loud speakers tho.
    +1
  • SylverReZ @ SylverReZ:
    @Jayro, I don't see whats so special about the DS ML, its just a DS lite in a phat shell. At least the phat model had louder speakers, whereas the lite has a much better screen.
    +1
  • SylverReZ @ SylverReZ:
    They probably said "Hey, why not we combine the two together and make a 'new' DS to sell".
  • Veho @ Veho:
    It's a DS Lite in a slightly bigger DS Lite shell.
    +1
  • Veho @ Veho:
    It's not a Nintendo / iQue official product, it's a 3rd party custom.
    +1
  • Veho @ Veho:
    Nothing special about it other than it's more comfortable than the Lite
    for people with beefy hands.
    +1
  • Jayro @ Jayro:
    I have yaoi anime hands, very lorge but slender.
  • Jayro @ Jayro:
    I'm Slenderman.
  • Veho @ Veho:
    I have hands.
  • BakerMan @ BakerMan:
    imagine not having hands, cringe
    +1
  • AncientBoi @ AncientBoi:
    ESPECIALLY for things I do to myself :sad:.. :tpi::rofl2: Or others :shy::blush::evil:
    +1
  • The Real Jdbye @ The Real Jdbye:
    @SylverReZ if you could find a v5 DS ML you would have the best of both worlds since the v5 units had the same backlight brightness levels as the DS Lite unlockable with flashme
  • The Real Jdbye @ The Real Jdbye:
    but that's a long shot
  • The Real Jdbye @ The Real Jdbye:
    i think only the red mario kart edition phat was v5
  • BigOnYa @ BigOnYa:
    A woman with no arms and no legs was sitting on a beach. A man comes along and the woman says, "I've never been hugged before." So the man feels bad and hugs her. She says "Well i've also never been kissed before." So he gives her a kiss on the cheek. She says "Well I've also never been fucked before." So the man picks her up, and throws her in the ocean and says "Now you're fucked."
    AncientBoi @ AncientBoi: :O:ohnoes::lol::rofl::rofl2: