Homebrew TWLbf - a tool to brute force DSi Console ID or EMMC CID

hutiu

Member
Newcomer
Joined
Nov 30, 2005
Messages
5
Trophies
1
XP
292
Country
United States
How would I use this tool ? I've downloaded both the TWLbf and bfCL release. I need to brute my CID. I've copied the web browser and was able to acquire my console id from it. I've also hard modded my dsi and took 3 identical nand dumps.
 

hutiu

Member
Newcomer
Joined
Nov 30, 2005
Messages
5
Trophies
1
XP
292
Country
United States
I have 2 dsi. The first one came with Flipnote so I used that in conjunction with ugpown to dump and downgrade.

Burgundy DSi-XL - USA
Console ID: 08202XXXXXXXX1XX
EMMC CID: 9DXXXXXXXX3257373136354D00011500
No Photo of EMMC Chip since I didn't have to open it.

My second dsi was given to me many moons ago. I only connected it once to the shop to download the browser. I did the hardmod on it. Tried to use your tool to brute the EMMC CID. Couldn't get it to work because I am a noob. Spent the next 30 mins to configure rpi and got EMMC CID. I would have love to see how fast brute forcing could have been on my system.

Black DSi - USA
Console ID: 08A1893015103135
EMMC CID: BBC567869F034D303046504100001500
Photo of EMMC Chip: https://mega.nz/#!5jBSFYhK

I will be using the black dsi as a test system so no harm in posting all of its info.

edit: I was able to use your tool to brute the emmc cid after all.
testing bb??????0?034d303046504100001500
testing bb??????1?034d303046504100001500
testing bb??????2?034d303046504100001500
testing bb??????3?034d303046504100001500
testing bb??????4?034d303046504100001500
testing bb??????5?034d303046504100001500
testing bb??????6?034d303046504100001500
testing bb??????7?034d303046504100001500
testing bb??????8?034d303046504100001500
testing bb??????9?034d303046504100001500
got a hit: bbc567869f034d303046504100001500
609.00 seconds, 4.39 M/s
Press any key to continue . . .
 

Attachments

  • EMMC DSi.jpg
    EMMC DSi.jpg
    1.1 MB · Views: 389
Last edited by hutiu,
  • Like
Reactions: JimmyZ

Abequinn

Member
Newcomer
Joined
Aug 14, 2017
Messages
24
Trophies
0
Age
33
XP
96
Country
United States
Console ID:
08201, DSi XL, U, Burgundy id is 0-9
EMMC CID:
bc ss ss ss ss 03 4D 30 30 46 50 41 00 00 15 00 (SAME SYSTEM)
Transcript of the label:
SAMSUNG 946
KMAPF0000M-S998
N23A3MF6
DSi, U, Black:
Console ID:
08a19 (rest is 0-9)
EMMC CID:
bb ss ss ss ss 03 4d 30 30 46 50 41 00 00 15 00
Transcript of the label:
SAMSUNG 846
KMAPF0000M-S998
N1HW8MC2
 
Last edited by Abequinn,
  • Like
Reactions: JimmyZ

Sahaquiel

Member
Newcomer
Joined
Dec 13, 2017
Messages
23
Trophies
0
XP
208
Country
Germany
I think I understand now how to use the programm, but could someone tell me how the programm looks for the nand dump, or how you got it to work? I looked at github too but didn't found anything.

EDIT: Ok, got it. It's a bit confusing for newbies and I hope that in the future there will be a guide or a thread that explains everything. If I'm succesfull to bruteforce my CID, I will post my data here.
 
Last edited by Sahaquiel,

Sahaquiel

Member
Newcomer
Joined
Dec 13, 2017
Messages
23
Trophies
0
XP
208
Country
Germany
Sorry, but now I'm confused (again). I'm having problems to give a correct template CID, because I don't know where the hell I should take the MY byte. TWLbf crashes if I use "MY ss ss ss ss 03 4D 30 30 46 50 41 00 00 15 00" as template CID an gives me the error message: invalid input "MY". So, could someone help me to bruteforce my CID?
 

JimmyZ

Sarcastic Troll
OP
Member
Joined
Apr 2, 2009
Messages
681
Trophies
0
XP
762
Country
Zimbabwe
Sorry, but now I'm confused (again). I'm having problems to give a correct template CID, because I don't know where the hell I should take the MY byte. TWLbf crashes if I use "MY ss ss ss ss 03 4D 30 30 46 50 41 00 00 15 00" as template CID an gives me the error message: invalid input "MY". So, could someone help me to bruteforce my CID?
There're examples one page back.

A proper "template" would be a valid hex string, like this: AB000000034D303046504100001500

Start with those numbers listed in the OP, and try others if no hit, and no spaces.
 
Last edited by JimmyZ,
  • Like
Reactions: Sahaquiel

Sahaquiel

Member
Newcomer
Joined
Dec 13, 2017
Messages
23
Trophies
0
XP
208
Country
Germany
There're examples one page back.

A proper "template" would be a valid hex string, like this: AB000000034D303046504100001500

Start with those numbers listed in the OP, and try others if no hit, and no spaces.

God damn it, thank you. ^^ I only, accidently, wrote it here with the spaces. "The Biggest Loser" is on the way, but I'll try it later till I got it.

EDIT: Does the "MY" byte still remains every time "ab"?

BTW: Do you still need people with hardmod to test TWLnf? When I'm ready with the console I'll write a message in the thread.
 
Last edited by Sahaquiel,

Koksi__

Well-Known Member
Newcomer
Joined
Jun 27, 2016
Messages
82
Trophies
0
Age
29
XP
1,270
Country
Austria
I have a NDSi XL with Hardmod and the Console ID, but i dont understand how to bruteforce the CID.
Its on 1.4.0, but without Flipnote
My Console ID is:0820154919126126
Today i received my Biggest Loser Game, but its USA Region:hateit:
Yes i read the OP, but i dont understand.

Please help me
 

JimmyZ

Sarcastic Troll
OP
Member
Joined
Apr 2, 2009
Messages
681
Trophies
0
XP
762
Country
Zimbabwe
I have a NDSi XL with Hardmod and the Console ID, but i dont understand how to bruteforce the CID.
Its on 1.4.0, but without Flipnote
My Console ID is:0820154919126126
Today i received my Biggest Loser Game, but its USA Region:hateit:
Yes i read the OP, but i dont understand.

Please help me

OP and the readme on github
 

FFT

Active Member
Newcomer
Joined
Jan 6, 2016
Messages
41
Trophies
0
Age
32
XP
425
Country
Poland
Still looking for ConsoleID and CID of various versions? I would like to provide mine, they are 100% correct.

ConsoleID
08201
DSi XL, E, Dark Brown

08A21
DSi, U, Light Blue

EMMC CID
MY SS SS SS SS 03 4d 30 30 46 50 41 00 00 15 00
DSi XL, E, Dark Brown
DSi, U, Light Blue

I should have also dump from another DSi (E) Red system which had different numbering somewhere... I need to look on my old drive.

@JimmyZ, it seems that I've provided my EMMC CID without datecode. So just in case I'll provide full CID and you can update info in the first post if you want:

ConsoleID
08201
DSi XL, E, Dark Brown
Note: 14th digit is '1', has digits only in 0-9 range

08A21
DSi, U, Light Blue
Note: 14th digit is '2', has digits in 0-F range (13th digit is 'A')

EMMC CID
5d SS SS SS SS 03 4d 30 30 46 50 41 00 00 15 00
DSi XL, E, Dark Brown
5c SS SS SS SS 03 4d 30 30 46 50 41 00 00 15 00
DSi, U, Light Blue

Does providing full ConsoleID and CID helps anyhow? I can provide one if you want. ;)

Best regards,
FFT
 
  • Like
Reactions: JimmyZ

JimmyZ

Sarcastic Troll
OP
Member
Joined
Apr 2, 2009
Messages
681
Trophies
0
XP
762
Country
Zimbabwe
@JimmyZ, it seems that I've provided my EMMC CID without datecode. So just in case I'll provide full CID and you can update info in the first post if you want:

ConsoleID
08201
DSi XL, E, Dark Brown
Note: 14th digit is '1', has digits only in 0-9 range

08A21
DSi, U, Light Blue
Note: 14th digit is '2', has digits in 0-F range (13th digit is 'A')

EMMC CID
5d SS SS SS SS 03 4d 30 30 46 50 41 00 00 15 00
DSi XL, E, Dark Brown
5c SS SS SS SS 03 4d 30 30 46 50 41 00 00 15 00
DSi, U, Light Blue

Does providing full ConsoleID and CID helps anyhow? I can provide one if you want. ;)

Best regards,
FFT
I'd like a NAND dump of that DSi(PM me), makes me really curious...
 

FFT

Active Member
Newcomer
Joined
Jan 6, 2016
Messages
41
Trophies
0
Age
32
XP
425
Country
Poland
I'd like a NAND dump of that DSi(PM me), makes me really curious...

Oh my, my fault! While the information provided (ConsoleID and CID) is correct, that second DSi doesn't have A-F digits in ConsoleID. I've just made a mistake when writing this post (I was writing this when I was at work thinking about other stuff and I've written information about the digits after writing full values and read them from the footer, where the value is reversed). :glare: I'm so sorry about this one. Still, if you are still anyhow interested in NAND dump please let me know, but I assume you were interested due to the A-F digits in ConsoleID but it was just my typo. Just in case I'll provide full ConsoleID and CID if you want.

CID:
5C C3 14 03 09 03 4D 30 30 46 50 41 00 00 15 00

ConsoleID:
08 A2 14 88 13 09 91 17

Sorry again for the mistake.
 
Last edited by FFT,

Sahaquiel

Member
Newcomer
Joined
Dec 13, 2017
Messages
23
Trophies
0
XP
208
Country
Germany
So, I habe read the OP.... but I still don't geht it where I'm supossed to take the month/year data code from the EMMC Chip. I already habe my CID from a TBL copy but I also would like to test this programm.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: yawn