Tutorial  Updated

Patching DevMenu v6.0.1 to remove startup notification

This tutorial implies that you found DevMenu v6.0.1 on some other sites. With this forum rules, links to the required copyrighted material are forbidden.

Problem

This version of DevMenu checks the FW version and displays a message on its startup if it's higher than 6.0:

fda7b072-cf7a-430a-b4fc-cc563703f5e5-jpeg.151526


The purpose of this tutorial is to remove this panel.


Step 1 - Uncompress executable "main"

First, you need HacTool (https://github.com/SciresM/hactool/releases/tag/1.2.2) and the DevMenu executable "main". This executable should have the following properties:

Size: 5807948 bytes
SHA256: DD1BA1C488AF2CD6EAC1B1DCAAB143BF4F2003C0DB7B3FEA74113D80D25C274E​

If you got an NSP file (not a LayeredFS version), you must extract the NSP then the biggest NCA file with the following commands:
  • hactool -t pfs0 -k keys.txt DevMenuApp.nsp --pfs0dir=extract
  • hactool -k keys.txt --exefsdir=exefs --romfsdir=romfs BiggestFileInExtractDir.nca
Now, you should have a "main" file in "exefs" directory. You need to uncompress it with the following command:
  • hactool -t nso0 -k keys.txt exefs/main --uncompressed=mainDec
The uncompressed executable file "mainDec" should have the following properties:

Size: 15011376 bytes (14 MiB)
SHA256: E802D200640E0F0E4A86913BBB616C682DA0BE3D3F47A82F976F37FC4B3DF125​


Step 2 - Patch executable "mainDec"

Open "mainDec" with an hexadecimal editor and replace the following bytes:
  • Binary ARM code: E80345391F19007161000054E8074539 => 080080521F0100716100005408008052
  • Hash check: EA43FE633F51336D3169BBFC70E280BAD95C4EF501AFC7E9D6C2310B745C8FBE => C1BEBE80DFE604D933F049090E95F5DFB60287E2CF65E46DFD70262954EB711D
The modified "mainDec" file should have the following properties:

Size: 15011376 bytes (14 MiB)
SHA256: 82F604C51F2B71D14571308DD5B87273BE1448F68432841BFB244986BA71CCBD​

Now, you can replace "exefs/main" by the patched "mainDec" (rename it to "main").

If you were using a LayeredFS version of DevMenu, you don't have anything more to do. If it was an NSP version, you will have to rebuild the NSP using hacPack (https://github.com/The-4n/hacPack/releases/tag/v1.33).


Method used to find the patch

The executable was opened with IDA Pro 7.0 and the loader "nxo64" available here:
https://github.com/reswitched/loaders

There was a tracking on "Found version" string usage and it leads to the following code which gets and checks the firmware version:

1545508227-devmenuasm.png


Parts of this code have been replaced (thanks to http://armconverter.com website which was used to get equivalent binary code):

1545508267-devmenuasmmod.png


Those changes makes that, whatever the retrieved FW version, it's not checked anymore and conditions to avoid the notification panel are met.

Finaly, in order to make the executable accepted when it's launched, the NSO0 header has to be modified where the ".text" part hash is located (see https://switchbrew.org/wiki/NSO for further details).


Happy hacking! :)
 
Last edited by OperationNT,

OperationNT

Well-Known Member
OP
Member
Joined
May 1, 2016
Messages
353
Trophies
0
Age
39
XP
2,201
Country
France
I mean, there is a DevMenu for 6.2 that you could use while on 6.2 and you wouldn't have to patch anything ;)

When there will be a FW 6.3 or 7.0, the DevMenu v6.2 will pop up the panel again. With those modifications, the DevMenu v6.0.1 will never pop up the panel so you won't have to track the next version.
Of course, there can be another incompatibility in future version (like it happens with DevMenu v5.0 on FW 6.0).

In addition, the tutorial part "Method used to find the patch" will allow you to also replicate the process on any future version of DevMenu.
 

OperationNT

Well-Known Member
OP
Member
Joined
May 1, 2016
Messages
353
Trophies
0
Age
39
XP
2,201
Country
France
The hash check is located at in the header of the NSO file, position 0xA0. You just have to find "EA43FE633F51336D3169BBFC70E280BAD95C4EF501AFC7E9D6C2310B745C8FBE" (it should place you at position 0xA0) and replace it by "C1BEBE80DFE604D933F049090E95F5DFB60287E2CF65E46DFD70262954EB711D".
 
  • Like
Reactions: Hmed

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • Julie_Pilgrim @ Julie_Pilgrim:
    oh man, that always goes great!
  • Julie_Pilgrim @ Julie_Pilgrim:
    im sure half the responses won't be literal racial slurs or "drop table" jokes
  • Veho @ Veho:
    Look, it's China. They know what it's like when you give a poll to half a billion trolls.
    +1
  • K3Nv2 @ K3Nv2:
    How much dollar do you think it is?
  • Veho @ Veho:
    ONE MILLION DOLLA
    +1
  • Veho @ Veho:
    I know the pricing of electronics nowadays isn't "how much it actually costs" but "how much we can get away with", but putting up a poll is just cynical.
    +1
  • K3Nv2 @ K3Nv2:
    Probably $150 someone said Anbernic said around the same price as rg556
  • Julie_Pilgrim @ Julie_Pilgrim:
    you know which game i wish they would rerelease
  • Julie_Pilgrim @ Julie_Pilgrim:
    sonic unleashed
  • K3Nv2 @ K3Nv2:
    Make it a happy meal toy
  • Julie_Pilgrim @ Julie_Pilgrim:
    that game's engine is really fucking intensive so it runs like literal shit on xbox 360 and ps3
  • Veho @ Veho:
    Nah I'm getting value creep again. I look at a $50 console "but for just a few more dollars you could get XYZ" and I end up considering the Steam Deck.
    +1
  • Julie_Pilgrim @ Julie_Pilgrim:
    like the lighting in that game was genuinely so good
  • Veho @ Veho:
    Not getting dragged into that again.
  • Julie_Pilgrim @ Julie_Pilgrim:
    i dont get why they didn't port the one game that ran the worst on consoles, to pc
  • Julie_Pilgrim @ Julie_Pilgrim:
    like you port everything to pc except the one game where it would make the most sense. why. what do you gain from this
  • Julie_Pilgrim @ Julie_Pilgrim:
    is sega just personally fucking with me? are they laughing while watching me through my kinect camera as i get up to restart my xbox for the third time because the game froze again
  • K3Nv2 @ K3Nv2:
    Buy handhelds from five below better quality
  • K3Nv2 @ K3Nv2:
    Valve probably going to do another refresh of the deck this fall with rog ally like specs tbh
    +1
  • Veho @ Veho:
    A smaller form factor would be nice too.
    +1
  • K3Nv2 @ K3Nv2:
    A shield portable 2 would be nice aye Nvidia
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    The big leap in all things tech is when carbon based chips start hitting.
  • Psionic Roshambo @ Psionic Roshambo:
    Longer battery life cooler temps and faster! What's not to like lol (probably expensive as hell)
    Psionic Roshambo @ Psionic Roshambo: Longer battery life cooler temps and faster! What's not to like lol (probably expensive as hell)