Hacking Downgrading for 9.3+ Owners is now a reality!

Zidapi

Well-Known Member
OP
Member
Joined
Dec 1, 2002
Messages
3,112
Trophies
3
Age
42
Website
Visit site
XP
2,681
Country
Just wanted to bring this to everyone's attention.

This all started happening in a topic unrelated to downgrading, so it may have gone unnoticed by many.

The process is working fine for old3DS owners, but is a little less reliable for new3DS users.

Some have reported having to try up to 50 times before finally succeeding in downgrading their new3DS. It mostly seems to hang at step 8, if it does, hard reboot and start over until it finally gets passed step 8.

@TheStoneBanana has put together a tutorial here, and @Ptrk25 a quick tutorial specifically aimed at new3DS users here.


Enjoy your free Gateway-free CFW!
 

Joeli53

Well-Known Member
Newcomer
Joined
Dec 31, 2015
Messages
72
Trophies
0
XP
127
Country
United States
Would anyone be able to explain some of the steps that were linked to for N3DS? I realize I should receive a reply like "if you can't figure it out, then you shouldn't be doing it," but I'm taking a chance someone can provide a step-by-step explanation like this tutorial: https://gbatemp.net/threads/tutoria...including-emunand-coldboot-cia-manager.405589

Download the right n3ds cia files (or extract it from the ttp)
- What are these files and where do we get them?

Install the newest sysupdater homebrew
- Is there a tutorial?

Use menuhax
- Likewise, is there a tutorial?
 

Aroth

Well-Known Member
Member
Joined
Apr 14, 2015
Messages
2,066
Trophies
0
Age
37
XP
891
Country
United States
Does this actually downgrade the NATIVE_FIRM as well?

The homebrews for downgrading have been in a sort of testing phase for several hours, since early this afternoon, but inital attempts found that while the system reported as being on 9.2, no exploits beyond the homebrew entrypoints worked. Apparently process9 was running a version check on installation of NATIVE_FIRM and if the existing FIRM was newer it would skip the install, resulting in a 9.2 3ds with a 10.3 NATIVE_FIRM, and no CFW.
 

Astoria

Well-Known Member
Member
Joined
Aug 26, 2009
Messages
665
Trophies
1
XP
1,280
Country
Costa Rica
Does this actually downgrade the NATIVE_FIRM as well?

The homebrews for downgrading have been in a sort of testing phase for several hours, since early this afternoon, but inital attempts found that while the system reported as being on 9.2, no exploits beyond the homebrew entrypoints worked. Apparently process9 was running a version check on installation of NATIVE_FIRM and if the existing FIRM was newer it would skip the install, resulting in a 9.2 3ds with a 10.3 NATIVE_FIRM, and no CFW.
Yes. The downgrade is completly functional and allows you to run CFW when you return to 9.2.
 

Zidapi

Well-Known Member
OP
Member
Joined
Dec 1, 2002
Messages
3,112
Trophies
3
Age
42
Website
Visit site
XP
2,681
Country
Would anyone be able to explain some of the steps that were linked to for N3DS? I realize I should receive a reply like "if you can't figure it out, then you shouldn't be doing it," but I'm taking a chance someone can provide a step-by-step explanation like this tutorial: https://gbatemp.net/threads/tutoria...including-emunand-coldboot-cia-manager.405589

Download the right n3ds cia files (or extract it from the ttp)
- What are these files and where do we get them?

Install the newest sysupdater homebrew
- Is there a tutorial?

Use menuhax
- Likewise, is there a tutorial?
I haven't needed to do it as I've only had exploitable 3DSes. Best to ask in the "unrelated thread" I linked to in my opening post. You'll get plenty of help there :)
 

Aroth

Well-Known Member
Member
Joined
Apr 14, 2015
Messages
2,066
Trophies
0
Age
37
XP
891
Country
United States
Could I downgrade 2DS? My little sister has a 2DS but there is no one confirm if it could work or not :wacko:

2DS is virtually identical to the O3DS in every way baring the lack of a 3D screen. Simply use O3DS files and avoid downgrading lower than 6.x and you will be fine.
 
  • Like
Reactions: Zidapi

Aroth

Well-Known Member
Member
Joined
Apr 14, 2015
Messages
2,066
Trophies
0
Age
37
XP
891
Country
United States
No idea, I can't read code.

The source is available here if you can (and then explain it for us?)

So it looks like the fix involved replacing a single if/then qualifier with an extended if/else/then.

Basically the initial attempt would check the result of a AM service call for installing FIRM and based on the result would potentially throw an Exception and fail to install NATIVE_FIRM. The updated code now checks if the user is doing a downgrade first, and if not continues as before. If they are doing a downgrade it sends a slightly different set of info into the AM service call, more or less forcing it to install regardless of the result of the version comparison check done by process9.
 

Aroth

Well-Known Member
Member
Joined
Apr 14, 2015
Messages
2,066
Trophies
0
Age
37
XP
891
Country
United States

Tokiopop

Caffeine fiend
Member
Joined
Apr 14, 2009
Messages
1,833
Trophies
0
Age
29
Location
UK
XP
446
Country
Your initial post was sort of right. From what I can see, before they even do the part listed in that change they actually delete the NATIVE_FIRM from the system, which would most definitely solve the problem of process9 getting pissy about the existing FIRM being newer.
Ah, okay. I didn't bother looking up what the system titles were so i wasn't very confident in my assumption. But yeah, for anyone wondering I originally said it deleted a couple of system titles on the nand which I assumed were to do with NATIVE_FIRM, meaning Process9 would have nothing to compare the 'new' NATIVE_FIRM to, allowing it to be downgraded.

I guess they implemented the downgrade earlier but it didn't work until that small change
 

Aroth

Well-Known Member
Member
Joined
Apr 14, 2015
Messages
2,066
Trophies
0
Age
37
XP
891
Country
United States
Ah, okay. I didn't bother looking up what the system titles were so i wasn't very confident in my assumption. But yeah, for anyone wondering I originally said it deleted a couple of system titles on the nand which I assumed were to do with NATIVE_FIRM, meaning Process9 would have nothing to compare the 'new' NATIVE_FIRM to, allowing it to be downgraded.

I guess they implemented the downgrade earlier but it didn't work until that small change

Sounds like it. The titleIDs it tries to delete are 0x0004013800000002LL and 0x0004013820000002LL. 0004013800000002 is the Old 3DS (and 2DS) NATIVE_FIRM, while 0004013820000002 is the New3DS NATIVE_FIRM.
 
  • Like
Reactions: Tokiopop

kiryu1

Well-Known Member
Member
Joined
Apr 4, 2014
Messages
296
Trophies
0
Age
35
XP
231
Country
Does this mean I can now buy N3DSes that are 9.5 - 9.9 and just wait for a stable build?
 

Aroth

Well-Known Member
Member
Joined
Apr 14, 2015
Messages
2,066
Trophies
0
Age
37
XP
891
Country
United States
Does this mean I can now buy N3DSes that are 9.5 - 9.9 and just wait for a stable build?

You can buy ANY New3DS on the market atm and then just wait for a stable build. To my knowledge no new in box system should even have 10.3 yet and this method will work on any system with 10.3 or lower.
 
  • Like
Reactions: kiryu1 and Zidapi

Zidapi

Well-Known Member
OP
Member
Joined
Dec 1, 2002
Messages
3,112
Trophies
3
Age
42
Website
Visit site
XP
2,681
Country
So it looks like the fix involved replacing a single if/then qualifier with an extended if/else/then.

Basically the initial attempt would check the result of a AM service call for installing FIRM and based on the result would potentially throw an Exception and fail to install NATIVE_FIRM. The updated code now checks if the user is doing a downgrade first, and if not continues as before. If they are doing a downgrade it sends a slightly different set of info into the AM service call, more or less forcing it to install regardless of the result of the version comparison check done by process9.
Thank you!
 

Aroth

Well-Known Member
Member
Joined
Apr 14, 2015
Messages
2,066
Trophies
0
Age
37
XP
891
Country
United States
Thank you!

To clarify, it looks like the original code involved grabbing the titleID and version info from the cia to be installed. It would then compare compare the version of the one to be installed to the one on the NAND, and if the NAND version was higher it would delete it, then install the cia in question.

For some reason the if/then statement for throwing an exception when installing NATIVE_FIRM was not working properly and resulted in it never actually installing NATIVE_FIRM. I suspect it was not possible to actually delete NATIVE_FIRM from the NAND, so process9 would then get pissy when you tried to install the new (older) version.

Without a more in-depth understanding of the AM service calls being used, I cannot say for certain what went wrong or why the change from an if statement to an if/else statement fixed it, but it appears to have been the change that solved the problem.
 

tony_2018

Well-Known Member
Member
Joined
Jan 3, 2014
Messages
3,107
Trophies
0
XP
1,022
Country
United States
Good info on how on how the process came to be. Will definitely try to hunt down an n3ds of my choice with some insane high firmware on there.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Xdqwerty @ Xdqwerty:
    Also somebody is remaking it
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, the other game where I found newgrounds is new york shark
    +1
  • SylverReZ @ SylverReZ:
    Spoke to Tom Fulp the other day, if he can find his old Newgrounds site content like the mini Flash animations from the 2000's that played on the portal.
  • SylverReZ @ SylverReZ:
    So far no response, but he did say that he'll find them. Wayback Machine doesn't have em.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, atleast the 1999 versión of pico's school is avaliable (the difference between it, the 2006 versión and the 2016 versión is that the speed of the game depends of the speed of your computer and that it had the og soundtrack)
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Another being Pico VS Bear, the original 1999 version before Jim Henson filed a DMCA takedown.
    +1
  • Xdqwerty @ Xdqwerty:
    The 2006 versión was made when the flash portal was made
  • SylverReZ @ SylverReZ:
    Many people thought it was lost, but was discovered that he hid it on the same page.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, although the "secrets" system where the game was has been removed. Also pico vs uberkids had a netplay versión that was shutdown, although the swf file has been found
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Nope. There are two download buttons on the same page, where you can download the original under a file called "bear.exe". "bear2.exe", however, is the updated game in a Flash projector. P.s. this was on the archived Pico page from 2000.
  • SylverReZ @ SylverReZ:
    @Xdqwerty, That's been there for a long time, too. People who search for lost media don't look hard enough lmao.
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, also the pico 2 demos used to be only for the newgrounds patrons but they are on internet archive too (https://archive.org/download/picos_school_2)
    +1
  • Xdqwerty @ Xdqwerty:
    Iirc the demos were removed from newgrounds in 2022
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, or well only the demo with mindchamber's style was on newgrounds
    +1
  • Xdqwerty @ Xdqwerty:
    Fun fact @SylverReZ: iirc one of the goals on the fnf Kickstarter stated that pico 2 would be finished but the Kickstarter didnt get enough money for that goal to be fullfiled
  • SylverReZ @ SylverReZ:
    @Xdqwerty, FNF sucks, their community is toxic as hell.
  • The Real Jdbye @ The Real Jdbye:
    @SylverReZ its a single player game
  • Xdqwerty @ Xdqwerty:
    @The Real Jdbye, Yea but it has a shitton of mods with their own songs and stuff
  • Xdqwerty @ Xdqwerty:
    @The Real Jdbye, and quite a lot of people involved in those mods get cancelled
  • SylverReZ @ SylverReZ:
    Newgrounds wasn't the birth of FNF; rather, it was games where you beat up celebrities and parodies.
    +2
  • a_username_that_is_cool @ a_username_that_is_cool:
    FNF was born from Game Jams
  • a_username_that_is_cool @ a_username_that_is_cool:
    Specifically Ludum Dare 47
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, and Sonic fights a la dragón ball z
    Xdqwerty @ Xdqwerty: @SylverReZ, and Sonic fights a la dragón ball z