Hacking freakin magnethax; how does it work???

Joined
Nov 24, 2017
Messages
641
Trophies
0
Age
82
XP
832
Country
United States
I'm curious about NTRBoothax, specifically in how the hell it even works. I've got a couple questions regarding it and was wondering if anyone could help me find answers for them.

How did anyone find out how this works?
Are there any examples of service carts that Nintendo uses? I'm curious what they look like and if they've leaked online anywhere.
Lastly, why is it this works for DS mode flash carts specifically?
 

zoogie

playing around in the end of life
Developer
Joined
Nov 30, 2014
Messages
8,560
Trophies
2
XP
15,000
Country
Micronesia, Federated States of
I'm curious about NTRBoothax, specifically in how the hell it even works. I've got a couple questions regarding it and was wondering if anyone could help me find answers for them.

How did anyone find out how this works?
Are there any examples of service carts that Nintendo uses? I'm curious what they look like and if they've leaked online anywhere.
Lastly, why is it this works for DS mode flash carts specifically?
Read this
https://sciresm.github.io/33-and-a-half-c3/
That's your best chance at understanding it.
 

Hucz

Well-Known Member
Newcomer
Joined
Feb 28, 2012
Messages
52
Trophies
0
Location
Vancouver Island
XP
218
Country
Canada
"Upon disassembling boot9, we notice another huge flaw in the bootrom that wasn't mentioned at 33c3. Before trying to boot from NAND, the bootrom checks to see if a key combination (Start + Select + X) is being held, and whether the shell is closed. If so, it tries to boot from an inserted NTR (Nintendo DS) cartridge.

Combined with sighax/boot9strap, this allows one to make a malicious fake DS cartridge, so that holding down a button combination on boot gives you bootrom code execution. Nintendo tried to make it not possible to abuse by requiring the shell to be closed... But you can just use a magnet. This, like sighax, is also not fixable. The NTR cartridge was likely meant to be used for either the factory setup or as a means of recovering bricked NANDs. However, we'll never know for sure."

:)
 
  • Like
Reactions: x65943 and Lemon_

nl255

Well-Known Member
Member
Joined
Apr 9, 2004
Messages
3,004
Trophies
2
XP
2,810
Country
"Upon disassembling boot9, we notice another huge flaw in the bootrom that wasn't mentioned at 33c3. Before trying to boot from NAND, the bootrom checks to see if a key combination (Start + Select + X) is being held, and whether the shell is closed. If so, it tries to boot from an inserted NTR (Nintendo DS) cartridge.

Combined with sighax/boot9strap, this allows one to make a malicious fake DS cartridge, so that holding down a button combination on boot gives you bootrom code execution. Nintendo tried to make it not possible to abuse by requiring the shell to be closed... But you can just use a magnet. This, like sighax, is also not fixable. The NTR cartridge was likely meant to be used for either the factory setup or as a means of recovering bricked NANDs. However, we'll never know for sure."

:)

Wasn't there a report quite a while ago about someone who when they got their 3DS back from Nintendo's repair facility found it came with a weird DS style cart that Nintendo was very eager to get back but most people at the time thought it was fake news?
 

Hucz

Well-Known Member
Newcomer
Joined
Feb 28, 2012
Messages
52
Trophies
0
Location
Vancouver Island
XP
218
Country
Canada
Wasn't there a report quite a while ago about someone who when they got their 3DS back from Nintendo's repair facility found it came with a weird DS style cart that Nintendo was very eager to get back but most people at the time thought it was fake news?
Haha that's hilarious if true! If you can find more information on this report, I'd be interested in reading it :P
 

Zaphod77

Well-Known Member
Member
Joined
Aug 25, 2015
Messages
665
Trophies
0
Age
49
XP
616
Country
United States
tl:dr;

nintendo put a backdoor in the bootrom to let them unbrick consoles.

they attempted to secure it, by having it do a signature check.

But because the bootrom has a flawed signature check, we can fakesign, running our own code off of a pirate flashcart, instead of nintendo's own signed code that's on their unbricker carts.

PWNed. :)
 
  • Like
Reactions: zfreeman

KHANV1CT

Well-Known Member
Member
Joined
May 22, 2013
Messages
130
Trophies
1
Age
37
XP
454
Country
United States
  • Upon disassembling boot9, we notice another huge flaw in the bootrom that wasn't mentioned at 33c3.
  • Before trying to boot from NAND, the bootrom checks to see if a key combination (Start + Select + X) is being held, and whether the shell is closed.
  • If so, it tries to boot from an inserted NTR (Nintendo DS) cartridge.
  • Combined with sighax/boot9strap, this allows one to make a malicious fake DS cartridge, so that holding down a button combination on boot gives you bootrom code execution.
  • Nintendo tried to make it not possible to abuse by requiring the shell to be closed...
  • But you can just use a magnet.

That's so cool, I wish I had the time to learn stuff like that.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Psionic Roshambo @ Psionic Roshambo:
    Meth addicts don't move out of a house they are trying to sell and the boyfriend says she moved and does not know where lol
  • K3Nv2 @ K3Nv2:
    I was about to be like can't wait for gta6 so @Psionic Roshambo can tell me places to go then you drop that
    +3
  • BigOnYa @ BigOnYa:
    But gta6 will be in Psi hometown, and all cars will have a women on the roof, booty shaking.
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    That was a thing here in Florida for a minute
  • Psionic Roshambo @ Psionic Roshambo:
    Like cars with the booty shaking lol I seen it once in person was like smiling lol
    +1
  • K3Nv2 @ K3Nv2:
    Nah I'm talking about visiting areas he hides his bodies at
  • Psionic Roshambo @ Psionic Roshambo:
    Vice City kind of feels like Miami lol
  • Xdqwerty @ Xdqwerty:
    @Psionic Roshambo, it's a parody iirc
  • BigOnYa @ BigOnYa:
    Yea think that's where it was supposed to be, Miami
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Having been to Miami hmmm probably a hundred times lol
  • Psionic Roshambo @ Psionic Roshambo:
    Back in my days as a delivery driver for a cartel well driver slash guy they would send if a payment was forgotten lol
  • Psionic Roshambo @ Psionic Roshambo:
    you know to help them find their checkbook lol
  • BigOnYa @ BigOnYa:
    Gta4 was NewYork or Chicago, gta5 is California
  • K3Nv2 @ K3Nv2:
    Damn camera phones catching crimes
  • Psionic Roshambo @ Psionic Roshambo:
    Always some women screaming... You break a few thousand dollars worth of crap in someone's living room and they scream lol
  • Psionic Roshambo @ Psionic Roshambo:
    lol Ken yeah the things I did as a kid I am soooo glad those didn't exist
  • K3Nv2 @ K3Nv2:
    If someone breaks my $20 TV stand their nose is getting broke
  • Psionic Roshambo @ Psionic Roshambo:
    Psi would be doing like 300-3,000 years in prison lol
  • K3Nv2 @ K3Nv2:
    Have some in closet allegations?
  • Psionic Roshambo @ Psionic Roshambo:
    Someone tried to pull a gun on me once, they reached into the couch thinking I wouldn't notice, quick kick to the arm snapping it between the wrist and elbow broke like a swing lol I reached into the couch to see what was in there, cool a free .380 lol had to hit him with it a few times to remind him not to do it again lol
  • Psionic Roshambo @ Psionic Roshambo:
    He had the 20K he owed the very next day it was a miracle lol
  • Psionic Roshambo @ Psionic Roshambo:
    Psi was a bad bad man at one point lol
  • BigOnYa @ BigOnYa:
    We need a GTA based on your life, or at least put you in 6 as a character.
  • Psionic Roshambo @ Psionic Roshambo:
    I don't think people would believe 10% of the things I have done lol thank god...
    Psionic Roshambo @ Psionic Roshambo: I don't think people would believe 10% of the things I have done lol thank god...