Homebrew TWLbf - a tool to brute force DSi Console ID or EMMC CID

D

Deleted User

Guest
Burgundy DSi XL, USA
-----
Console ID: 08201XXXXXXXX1XX
All the other digits are in the 0-9 range.
EMMC CID: CC XX XX XX XX 03 4D 30 30 46 50 41 00 00 15 00
Photo of the EMMC chip.

I'll PM the whole ideal as well, as soon as I get all the data sorted out.
 
  • Like
Reactions: JimmyZ

Valery0p

Well-Known Member
Member
Joined
Jan 16, 2017
Messages
560
Trophies
0
XP
1,646
Country
Italy
Hi @JimmyZ , thanks for your program, using this+rPi hardmod, you can hack essentially ANY dsi :D even the ones without a dsiware installed.

Ot: did you knew that the perfect signature, for the 3ds public release of sighax (boot9strap), was bruteforced ?without a bootrom dump?
Here there are some math and algorithms that, who knows, may be inspirational for your tool ;)
https://sciresm.github.io/33-and-a-half-c3/math.html
https://github.com/Myriachan/sighax/commits/master
About b9s: https://sciresm.github.io/33-and-a-half-c3
 
  • Like
Reactions: JimmyZ

JimmyZ

Sarcastic Troll
OP
Member
Joined
Apr 2, 2009
Messages
681
Trophies
0
XP
762
Country
Zimbabwe
Burgundy DSi XL, USA
-----
Console ID: 08201XXXXXXXX1XX
All the other digits are in the 0-9 range.
EMMC CID: CC XX XX XX XX 03 4D 30 30 46 50 41 00 00 15 00
Photo of the EMMC chip.

I'll PM the whole ideal as well, as soon as I get all the data sorted out.
Thank you so much! our first EMMC chip photo! and special thanks for the PM.
BTW how do you get the photo so good?

Hi @JimmyZ , thanks for your program, using this+rPi hardmod, you can hack essentially ANY dsi :D even the ones without a dsiware installed.

Ot: did you knew that the perfect signature, for the 3ds public release of sighax (boot9strap), was bruteforced ?without a bootrom dump?
Here there are some math and algorithms that, who knows, may be inspirational for your tool ;)
https://sciresm.github.io/33-and-a-half-c3/math.html
https://github.com/Myriachan/sighax/commits/master
About b9s: https://sciresm.github.io/33-and-a-half-c3
Thank you, although I've read that when it came out, this kind of document recommendation is very welcomed:D
BTW they use CUDA to brute RSA, I use OpenCL(I don't have a NVIDIA GPU card) to brute SHA1+AES, I'm not able to copy anything from them...
They need to brute 2^43 possibilities, let alone the big math involved with RSA, that's really impressive work.
My work is simpler by like twenty magnitudes, because of the discoveries by nocash we don't have to brute that many bits, and the hardest part is finding out how it's encrypted, which is also done by nocash already.
 
  • Like
Reactions: Valery0p

leratrad

New Member
Newbie
Joined
Aug 28, 2017
Messages
3
Trophies
0
Age
45
XP
55
Country
United States
Black DSi, USA
-----
Console ID: 08A18XXXXXXXX1XX
All the other digits are in the 0-9 range.
EMMC CID: BB XX XX XX XX 03 4D 30 30 46 50 41 00 00 15 00
 
  • Like
Reactions: JimmyZ

JimmyZ

Sarcastic Troll
OP
Member
Joined
Apr 2, 2009
Messages
681
Trophies
0
XP
762
Country
Zimbabwe
Just made OpenCL Console ID brute working, as my test on HD7970, it's about 25x faster(12.4 seconds for 32bit) than Xeon E3-1230v2(single thread, 304 seconds).

But I know absolutely nothing about OpenCL optimize, so this is pretty much it.

BTW, if you run this version, your system will become very sluggish, I don't know how to limit this yet.

And if your GPU's fan doesn't hold well, you may face system crash, like that crappy R7-200 on my code machine, I have to black list it in the code.
 
Last edited by JimmyZ,
D

Deleted User

Guest
Thank you so much! our first EMMC chip photo! and special thanks for the PM.
BTW how do you get the photo so good?
I guess the Nexus 5 has a better camera than I expected :P
I can try to get info from another DSi or two; one doesn't have any DSiWare, and thus requires a hardmod, and another I seem to have bricked while dropping it. (The bottom covering was off, and it fell right on the motherboard...)
At the very least, I can get some more pictures. I think I still have the Console ID from the bricked one somewhere... :)
 
  • Like
Reactions: JimmyZ

JimmyZ

Sarcastic Troll
OP
Member
Joined
Apr 2, 2009
Messages
681
Trophies
0
XP
762
Country
Zimbabwe
I guess the Nexus 5 has a better camera than I expected :P
I can try to get info from another DSi or two; one doesn't have any DSiWare, and thus requires a hardmod, and another I seem to have bricked while dropping it. (The bottom covering was off, and it fell right on the motherboard...)
At the very least, I can get some more pictures. I think I still have the Console ID from the bricked one somewhere... :)
Wow, the first one seems to be a nice test candidate for this tool;)
 
D

Deleted User

Guest
Wow, the first one seems to be a nice test candidate for this tool;)
Speaking of the first one...

Black DSi, USA
-----
Console ID: No DSiWare
EMMC CID: 3C XX XX XX XX 03 4D 30 30 46 50 41 00 00 15 00
Photo of the EMMC chip.

I definitely would try it out with this tool, but I'm terrible at soldering. There are a few people I know who can solder; perhaps I could contact them.
 
Last edited by ,
  • Like
Reactions: JimmyZ

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    ZeroT21 @ ZeroT21: only ps5 updated to latest firmware can go on psn, jailbroken ones just don't use psn or they...