Homebrew [33c3] Console Hacking 2016 (3DS/WiiU) talk Dec 27-30: smea, derrek, nedwill, naehrwert

What will Santa Hax bring us this year?

  • Slowhax (arm11 kernelhax)

    Votes: 184 32.1%
  • Soundhax (free primary userland sploit)

    Votes: 183 31.9%
  • Bootrom dump method !!

    Votes: 166 28.9%
  • Something more awesome than the above.

    Votes: 156 27.2%
  • Something nice for the WiiU

    Votes: 178 31.0%
  • Nothing. Ninty will banhammer: 001-1337 "Your use of this speech has been restricted by Nintendo"

    Votes: 80 13.9%
  • This checkbox pleases me

    Votes: 152 26.5%
  • ( ͡° ͜ʖ ͡°)

    Votes: 92 16.0%

  • Total voters
    574
  • Poll closed .

hacksn5s4

Banned!
Banned
Joined
Aug 12, 2015
Messages
4,332
Trophies
0
XP
1,322
Country
is sound hax kinda unpatchable because they would have to change how it plays the music to fix it and have they ever updated the sound app i don't think so i also don't think they update system titles that are on the home menu with firmware updates mii plaza only gets updated in the app
 
Last edited by hacksn5s4,

DavidRO99

Average Ryzen user.
Member
Joined
Jun 11, 2016
Messages
1,018
Trophies
0
Age
26
Location
your back-door
XP
948
Country
Korea, North
is sound hax kinda unpatchable because they would have to change how it plays the music to fix it and have they ever updated the sound app i don't think so
.... You that they can just update it right? Even if they didnt update it in the past they still can, like they own the damn thing
 

gkoelho

Well-Known Member
Member
Joined
Apr 16, 2015
Messages
558
Trophies
0
Age
31
XP
346
Country
Brazil
No, nothing has changed. It has always been possible ever since the arm9 was pwned. Using sighax is no different to using a9lh, and it opens up no new possibilities. The only difference is that it's easier to install because it does not rely on the OTP hash for encrypting a arm9loader key.

Doesnt bootrom has more access to hardware than arm9? I remember a flow chart of the 3ds architeture that showed something alike it.

Edit: Also arm9 only allow to patch code as its loaded and Sighax can have entire new code and calls permanently.
 
Last edited by gkoelho,

metroid maniac

An idiot with an opinion
Member
Joined
May 16, 2009
Messages
2,088
Trophies
2
XP
2,640
Country
Doesnt bootrom has more access to hardware than arm9? I remember a flow chart of the 3ds architeture that showed something alike it.

Eh sort of, but only to the extent that you can dump the bootrom and OTP as well. It's hard to go much more into detail without tediously correcting all the terminology.
 

hacksn5s4

Banned!
Banned
Joined
Aug 12, 2015
Messages
4,332
Trophies
0
XP
1,322
Country
the problem is theirs no eur old version of sudoku hax so you have to pay more money to downgrade 3ds since you need to buy a bigger game that can fit exdia hax
 
Last edited by hacksn5s4,
  • Like
Reactions: monkey69

einhuman197

Well-Known Member
Member
Joined
Aug 17, 2015
Messages
985
Trophies
0
Location
Inside your bootloader (´◉◞౪◟◉)
XP
771
Country
Germany
the problem is theirs no eur old version of sudoku hax so you have to pay more money to downgrade 3ds since you need to buy a bigger game that can fit exdia hax
Come on you jerk you save hundreds of euros/dollars/whatever with piracy and you cry because you have to buy a 7 euros/dollars/whatever game? Are you kidding me?
 
Last edited by einhuman197,

mathieulh

Well-Known Member
Member
Joined
Feb 28, 2008
Messages
378
Trophies
0
Website
keybase.io
XP
897
Country
France
You do not need luma with sighax, or any CFW at all because signatures will be signed.
You can only forge FIRM signature, and only for boot9 (Process9 isn't vulnerable), this means you can't just forge cia signatures and whatnot so you will still need "CFW". The 3DS isn't a Playstation 3.
 

mathieulh

Well-Known Member
Member
Joined
Feb 28, 2008
Messages
378
Trophies
0
Website
keybase.io
XP
897
Country
France
Could the CtCert be taken from another console, say a Wii or WiiU?
No, well not quite, the CtCert is stored in the OTP area (you just don't see it when dumping your OTP because it's stored in encrypted form), the OTP is copied by boot9 to the ITCM and decrypted, later on the part of the decrypted OTP which does not contain CtCert is wiped by boot9 from memory. This means the original place where the CtCert is stored (assuming you have the means to encrypt it) cannot be overwritten.

It is however possible to read the CtCert from the memory of an exploited unit (or from a decrypted OTP) and overwrite it in another console (in memory) early enough in the boot chain so that the firmware uses it instead of the one that's written in the OTP.

Needless to say you can't just craft your own CtCert for obvious reasons and need a real one generated by Nintendo.

--------------------- MERGED ---------------------------

no one is gonna bruteforce an hash for a patched firmware though. however there will definitely be some kind of payload chainloader i assume.
I agree, a universal loader is the way to go. if just for safety and convenience, something small and straightforward that does not require much (if any) changes over time.
 

Mrrraou

Well-Known Member
Member
Joined
Oct 17, 2015
Messages
1,873
Trophies
0
XP
2,374
Country
France
I agree, a universal loader is the way to go. if just for safety and convenience, something small and straightforward that does not require much (if any) changes over time.
definitely, plus people have already been doing this with k9lh so i assume it to be easy enough, as there's not that much difference between the post-k9l environment and the post-boot9 environment
 
  • Like
Reactions: Gray_Jack

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    K3Nv2 @ K3Nv2: Pissing in a pee bottle