Homebrew Why can't the ARM9 be hacked when running an Original DS game?

dotqurter_

Well-Known Member
OP
Newcomer
Joined
Oct 21, 2016
Messages
74
Trophies
0
Location
lost in ARM9
Website
www.google.com
XP
112
Country
United States
My question is that if the ARM9 is used for backwards compatibility when loading original DS/DSI games (this is what I understand from the FIRM page on 3dbrew, and a few other websites), why can't a stack/buffer overflow from the original games trigger a stack/buffer overflow in the ARM9, allowing it to be exploited for some homebrew on N3DS/O3DS on >11.1.0?

I'm just throwing that out there as a question, see if anyone else has thought of that. If so, could someone explain why this couldn't work? I mean, if the ARM9 > ARM11, a stack/buffer on the ARM9 should show at least some type of way to abuse it (maybe even to install unsigned .cia or do a downgrade to it).
 

Mikemk

Well-Known Member
Member
Joined
Mar 26, 2015
Messages
2,092
Trophies
1
Age
28
XP
3,150
Country
United States
It was at one point in time, it was called MSET. It's been patched. Now, all you can crash is yourself, and DS mode doesn't have SD access..
If we can find a way to run DSi homebrew from a flashcart, we can get free DSi downgrading though.
 

metroid maniac

An idiot with an opinion
Member
Joined
May 16, 2009
Messages
2,089
Trophies
2
XP
2,688
Country
You can run code on the ARM9, but all the interesting hardware has been turned off and can't be turned on without a reboot.

You don't need to exploit anything if you're using a flashcard. You're just plain running ARM9 code.

We already use that kind of "exploit" for the DSiWare downgrade.
When DSiWare runs it has complete access to the system NAND. All the interesting keys are already gone from memory though so it's the same as if you got a hardmod - encrypted and impossible to read sensible data to it.
However if you know what FIRM version is installed to the FIRM partition, you can deduce the keystream (xorpad) that decrypts/encrypts it, and can put your own older FIRM in there.
Usually the system menu checks if the FIRM matches the version of the rest of the system but for 11.1/11.0 > 10.4 they forgot. So you can then go ahead and downgrade to 9.2 with an ARM11 exploit.
This only works from DSiWare, not a TWL or NTR cartridge. In those cases, all the cool hardware has been disabled.
 
Last edited by metroid maniac,

metroid maniac

An idiot with an opinion
Member
Joined
May 16, 2009
Messages
2,089
Trophies
2
XP
2,688
Country
It was at one point in time, it was called MSET. It's been patched. Now, all you can crash is yourself, and DS mode doesn't have SD access..
If we can find a way to run DSi homebrew from a flashcart, we can get free DSi downgrading though.

The MSET exploit didn't run in DS mode.

Also, it's unlikely. I'm not aware of any TWL cartridge games that have permission to use the internal NAND, so that hardware would be disabled.
 

dotqurter_

Well-Known Member
OP
Newcomer
Joined
Oct 21, 2016
Messages
74
Trophies
0
Location
lost in ARM9
Website
www.google.com
XP
112
Country
United States
So, technically it IS possible to downgrade the firmware to at least 10.x.xx (and then from 10.x downwards) using a method from the current 11.1.0-34U (I am running a 11.1.0-33U, using menuhax and stock homebrew, on O3DS. If you must know, its a USA model) using DSIware?
I would just enjoy someway to downgrade my firmware far enough where bbm (bigbluemenu) or some other custom firmware (and A9LH) without spending 65+$ for a possibly bricked direct downgrade from 11.1.0-33U (or whatever) to 9.5.x-xx.
 
Last edited by dotqurter_,

Shadow#1

Wii, 3DS Softmod & Dumpster Diving Expert
Member
Joined
Nov 21, 2005
Messages
12,354
Trophies
2
XP
8,032
Country
United States
So, technically it IS possible to downgrade the firmware to at least 10.x.xx (and then from 10.x downwards) using a method from the current 11.1.0-34U (I am running a 11.1.0-33U, using menuhax and stock homebrew, on O3DS. If you must know, its a USA model) using DSIware?
I would just enjoy someway to downgrade my firmware far enough where bbm (bigbluemenu) or some other custom firmware (and A9LH) without spending 65+$ for a possibly bricked direct downgrade from 11.1.0-33U (or whatever) to 9.5.x-xx.

bbm (bigbluemenu) isnt a cfw it is a tool from the sdk to install cia's
 

gkoelho

Well-Known Member
Member
Joined
Apr 16, 2015
Messages
558
Trophies
0
Age
31
XP
346
Country
Brazil
It was at one point in time, it was called MSET. It's been patched. Now, all you can crash is yourself, and DS mode doesn't have SD access..
If we can find a way to run DSi homebrew from a flashcart, we can get free DSi downgrading though.

This a misconception, SD-access in DSi mode was already achieved. It has no use quite yet but make it work is a doable task.
 

dotqurter_

Well-Known Member
OP
Newcomer
Joined
Oct 21, 2016
Messages
74
Trophies
0
Location
lost in ARM9
Website
www.google.com
XP
112
Country
United States
Quick question:
If someone were to try to (maybe) find a useful task for DSi mode, where would I look, what would I use (like programming language) to test it, and is there a link I can use to find how the DSi mode SD-access works?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • BigOnYa @ BigOnYa:
    I'd rather spend like $150 more for a surround receiver.
  • K3Nv2 @ K3Nv2:
    I bought the game at launch never fucked with it until recently
  • BigOnYa @ BigOnYa:
    Its fun, I like it, even tho I'm not a big harry potter fan. Like a wizard rpg. Flying around on a broomstick is cool.
  • K3Nv2 @ K3Nv2:
    Flying sucks ass on it
  • BigOnYa @ BigOnYa:
    Nuh just takes a min to get used to. I think you can upgrade or buy new broomstick also that are better.
    +1
  • K3Nv2 @ K3Nv2:
    I weirdly like inverted controls on all flying type games
  • BigOnYa @ BigOnYa:
    Prob can change it, inverted flying controls.
  • K3Nv2 @ K3Nv2:
    Only thing that annoys me is trying to find wtf to do in it
    +1
  • BigOnYa @ BigOnYa:
    Alright off to the store, later gators.
    +1
  • K3Nv2 @ K3Nv2:
    Some places amaze me were not in network with your insurance would you still like an appointment
    +1
  • AncientBoi @ AncientBoi:
    uhhh, I think I'll just stick with my PSP 3001
  • AncientBoi @ AncientBoi:
    lol, Now I gotta go to the store for more Coffee Mate n other stuff.
  • Xdqwerty @ Xdqwerty:
    i downloaded final fantasy vii into my tv stick
  • Xdqwerty @ Xdqwerty:
    i mean, the game was already there but its the japanese version
  • Xdqwerty @ Xdqwerty:
    and i only downloaded disc 1 so far bc of storage stuff
  • Psionic Roshambo @ Psionic Roshambo:
    @BigOnYa, yeah the patty on McDs burger is 1/10th of a pound now and I think that's the pre cooked weight lol
  • Psionic Roshambo @ Psionic Roshambo:
    I use the app for the 20% off coupon and it's still over priced
  • Xdqwerty @ Xdqwerty:
    @Psionic Roshambo, why is mcdonalds overpriced if their food is bad?
  • Xdqwerty @ Xdqwerty:
    i mean why is mcdonalds food overpriced
  • Psionic Roshambo @ Psionic Roshambo:
    Inflation and greed
    +1
  • ZeroT21 @ ZeroT21:
    it's just fries, make 'em at home
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    I make potato wedges at home with spices and stuff lol
    Psionic Roshambo @ Psionic Roshambo: I make potato wedges at home with spices and stuff lol