Misc CTcerts, Device IDs, and itcm.mem

TiM127

Active Member
OP
Newcomer
Joined
Sep 26, 2016
Messages
32
Trophies
0
Age
21
XP
126
Country
United States
Soooooooo... :hateit:

It's well known at this point that @Joom has evolved to a higher level of intelligence than the rest of us and that only he and a select group of people can unhyperban their 3dses. There's a mystery payload that will automatically inject the CTcert and the DeviceID into the itcm.mem file in the 3ds's memory, as seen here.

But there are two ways to get a CTcert, by using dd on the itcm.mem file,
Code:
dd if=itcm.mem of=CTCert.bin bs=1 skip=14360 count=104
dd if=itcm.mem of=DeviceID.bin bs=1 skip=14340 count=4
or, as with the only CTcert I can use for this, with Eshop Debugger.

But these two files are fundamentally different. I copied my own dirty CTcert with eshop debugger and with itcm.mem and couldn't find any similarities in the hexeditor, at least not with my non-code centered brain. (Information I tried to use to help me find similarities can be found here.)

Are they encoded completely differently? If so, is there a fathomable way to convert one to another? I can only guess the Eshop Debugger's version of the CTcert comes with a ton of extra data that isn't found in itcm.mem, since it's almost 4 times the size. But that fact doesn't help converting the ECDSA signature. (Which I can only guess is the part of the CTcert I'd care about)

The DeviceID makes no sense either.
 
  • Like
Reactions: GilgameshArcher

Joom

 ❤❤❤
Member
Joined
Jan 8, 2016
Messages
6,067
Trophies
1
Location
US
Website
mogbox.net
XP
6,077
Country
United States
Just for the record, I didn't write the code or anything. It was pieced together from information available on 3dbrew. I just helped test and debug. The coder doesn't want to be known, so I guess I'm just the publicist or whatever. Also, it's no mystery payload. It's just a modified version of Luma, but any B9S payload used as the boot payload can work. Anyway, your device ID is used to verify your console and model with the Nintendo Network services. This is what Nintendo bans. The CTCert signs this ID, which used to not be necessary to bypass the ban, but hundreds of people thought using "1234" as their ID was a good idea. Because of this Nintendo now requires a legitimate, signed ID.
 
Last edited by Joom,
  • Like
Reactions: GilgameshArcher

TiM127

Active Member
OP
Newcomer
Joined
Sep 26, 2016
Messages
32
Trophies
0
Age
21
XP
126
Country
United States
Just for the record, I didn't write the code or anything. It was pieced together from information available on 3dbrew. I just helped test and debug. The coder doesn't want to be known, so I guess I'm just the publicist or whatever. Also, it's no mystery payload. It's just a modified version of Luma, but any B9S payload used as the boot payload can work. Anyway, your device ID is used to verify your console and model with the Nintendo Network services. This is what Nintendo bans. The CTCert signs this ID, which used to not be necessary to bypass the ban, but hundreds of people thought using "1234" as their ID was a good idea. Because of this Nintendo now requires a legitimate, signed ID.
I haven't been able to find anything about itcm.mem on 3dbrew.
 

TiM127

Active Member
OP
Newcomer
Joined
Sep 26, 2016
Messages
32
Trophies
0
Age
21
XP
126
Country
United States
Ok, so I've done a lot of research and I've found that the CTCert from the Eshop Debugger doesn't contain the "CTCert ECDSA privk".

I guess that means I'm screwed then, right?
 

TiM127

Active Member
OP
Newcomer
Joined
Sep 26, 2016
Messages
32
Trophies
0
Age
21
XP
126
Country
United States
All the information necessary to do this is publicly available. It's all on 3dbrew. I have a sneaking suspicion that they know.

Also, does this really mean that all the information on how to create a payload to replace CTCerts can be found exclusively on 3dbrew?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    Gray zone warfare looks kinda cool
  • Psionic Roshambo @ Psionic Roshambo:
    Ohhh on one episode they could use rings to summon Captain Criminal who is just Obama like a spoof of Captain Planet lol
    +1
  • BigOnYa @ BigOnYa:
    Does look good
  • Psionic Roshambo @ Psionic Roshambo:
    By your powers combined, hmmm where is Epstein?
  • K3Nv2 @ K3Nv2:
    Just another shit fps clone
  • K3Nv2 @ K3Nv2:
    Thought it was some warzone dlc bs
  • Psionic Roshambo @ Psionic Roshambo:
    Looks like an enhanced Far cry 1
  • K3Nv2 @ K3Nv2:
    That's a far cry from it
  • BigOnYa @ BigOnYa:
    Is it a free to play bs, pay to get any good weapon/gear
  • K3Nv2 @ K3Nv2:
    Not free to play but $35
  • K3Nv2 @ K3Nv2:
    Inb4 kiiwii gives it a 0/10
  • BigOnYa @ BigOnYa:
    6/10 rating on steam
  • Psionic Roshambo @ Psionic Roshambo:
    I would like a Predator game "Kill Team" it takes place in the Jungle of the first movie, your team is sent to hunt the predator, using current tech drones and a trained team. Set traps use strategy to hunt and trap or kill the predator.
  • BigOnYa @ BigOnYa:
    Ill stick with my Battlefield. Yea a predator hunting game like that would be cool. Esp if you can be Arnold and say "Get to da choppa"
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Maybe Arnold could do a cameo voice acting, he is the one briefing you on the mission
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Honestly surprised they didn't make a tie in game for Predators that movie was awesome
  • Psionic Roshambo @ Psionic Roshambo:
    I was kinda sad the Yakuza guy died sword fighting a predator lol
  • Psionic Roshambo @ Psionic Roshambo:
    The Russian guy went out like a boss
  • Psionic Roshambo @ Psionic Roshambo:
    Double claymores to the face definitely kill a predator lol
  • BigOnYa @ BigOnYa:
    I went today and looked at a motorcycle someone was selling. I get there and the battery on it was dead, so the guy grabbed a battery charger and hooked it up. He plugged it into the wall, and the motorcycle sparked and started smoking. Come to find out the bike uses a 6 volt battery and the guy had the charger set to 12v. I said sorry to the dude and walked away. I felt bad for him tho.
  • Psionic Roshambo @ Psionic Roshambo:
    Sounds like it would be an exciting ride....
  • Psionic Roshambo @ Psionic Roshambo:
    Not sure I would want something on fire between my legs
  • BigOnYa @ BigOnYa:
    He ruined it basically. Sad cause it was a decent old bike. It would take more money to rewire the bike than it was worth tho.
    BigOnYa @ BigOnYa: He ruined it basically. Sad cause it was a decent old bike. It would take more money to rewire...