/hbg/ - Homebrew & Hacking General

Previous thread Missing link /hbg/ Wiki: homebrew-general.wikia.com

-SAFE FIRMWARES-
3DS: 9.2 (Downgrade: 10.7, 11.1 via b& DSiWare - Entrypoints: smealum.github.io/3ds/)
Wii U: 5.5.1
Vita: 3.60
PS4: 4.05
PS3: 3.55

-GUIDES-
3DS: pastebin.com/TQwDsWh9
Downgrade + a9lh: 3ds.guide/
Wii U: pastebin.com/8u0WAyJC
IOSU+Kernel Exploit: github.com/FlimFlam69/WiiUTutorial/wiki
Vita: pastebin.com/v3caHHnp

-RECENT NEWS-
>3DS
-sighax has been announced, allowing for signing of custom firmwares.
-Bootrom has been dumped, soundhax and fasthax announced at 33c3.
-DS games via SD card released gbatemp.net/threads/454323/
-11.0/11.1 downgrading released. Requires 4 specific DSi games that are no longer available. More info here: 3ds.guide/nfirm-downgrade
-If you're on 11.0-11.2 and don't have any of the 4 games above you'll need a second CFW 3DS along with any DSiWare game.

>Wii U
-Boot0 code execution displayed at 33c3, along with boot1 dumping.
-A new method to get regionfree has been released. gbatemp.net/threads/448468
-New DNS that block updates have been released. gbatemp.net/threads/451486 & gbatemp.net/threads/436346
-New tool for dumping images from a Wii U disc has been released gbatemp.net/threads/wudump-dump-raw-images-from-a-wiiu-game-disc.451736/

>Vita
-PSN spoofing is broken on the Vita for both Henkaku and TaiHenkaku currently.
-Adrenaline released. gist.githubusercontent.com/TheOfficialFloW/0ed4e09e2d447e631416cb84d7c43107/raw/readme.txt
-taiHENkaku released along with source. tai.henkaku.xyz/
-Some .vpk files can brick your Vita. Be careful. wololo.net/2016/10/04/warning-ps-vita-brickers-in-the-wild/
-Update 3.61 patches HENkaku.

>PS4
-4.06 patches the 4.01 jailbreak, DO NOT UPDATE

>PS3
-4.81 Rebug CFW released
-It's possible to run games on OFW 4.70 without ODE and IDPS. gbatemp.net/threads/447577

Other urls found in this thread:

github.com/Cruel/freeShop/
github.com/github/dmca/blob/e4ed44931e5cf8693701461488b597f38e4620d7/2016-12-27-Nintendo.md
3ds.guide/troubleshooting
github.com/nedwill/soundhax
github.com/FlimFlam69/WiiUTutorial/
mega.nz/#!CdcQBaST!thDggOgLzKnFCbpizg_hHKhpQcVgVV0GjlEwK7t5rhM
pastebin.com/ELu6YaaR
Veeky
smealum.github.io/ninjhax2/starter.zip
cdn.discordapp.com/attachments/196635745551646720/263700084611350529/soundhax.m4a
twitter.com/SFWRedditGifs

wew, Previous thread

Reminder that DS rom loading from SD was not worth waiting for

J-just you wait!

and remind me why it isn't.

So, what's the chance of bricking while getting cfw on the Wii U? Is it worth doing yet?

BACK UP THOSE TITLEKEYS

freeShop got DMCA'd
T O P
K
E
K
github.com/Cruel/freeShop/
github.com/github/dmca/blob/e4ed44931e5cf8693701461488b597f38e4620d7/2016-12-27-Nintendo.md

little help? I've downloaded a few gba games to play on my cfw(luma) but whenever I try to launch them, the 3ds just shuts itself.
The same happens when I try to load my r4 with any of the slot-1 launcher, so I guess it's something related to switching to dsi mode(or whatever it's called).
How can I fix this?

They only got DMCA'd because of the logo.

link ps4 cfw pls

They got DMCA'd for more than that, but the logo's probably the only one that will stick.

did you at any point manually patch TWL_FIRM?
if so do this:
3ds.guide/troubleshooting

you won't if you only use normal haxchi, it's worth it

coldbooting/rednand can brick if you make mistakes

What is the latest release of it?

3.63 keys NEVER EVER

logo and loading animation.
both are patented and trademarked.

guys, need help.

doing A9LH update. Following everything to the letter until:
Section IV - CTRNAND Luma3DS
9. Power off your 3DS and remove the SD card
10. Boot with the SD card removed while holding (Select)

Does not boot. What is the problem / how to fix? arm9loaderhax.bin is in CTR NAND root.

Also, at Section II - Payload update, step 2. Press (Select) to update arm9loaderhax. There was no visual response. Is that ok? I am on Luma3DS 6.6

PS4 piracy never
only shitty linux that nobody wants

15 second loading times between scenes
no saves
black screens
white screens
no saves
limited compatibility with games (each rom needs to be repacked)
no cheats
no saves

oh, and did i mention no saves?

Remember when people said WiiU would dominate the market and sony would go bankrupt?

I honestly don't.

...

I suggest you download all the tickets via shameless while the site is still up.
You know, for archival reasons.

Alright. Maybe I'll look into it. Is there a clear cut "best" cfw like luma for the 3ds? And any chance you could point me in the direction of a guide for installing it?

JUST

I fucked up, my vita somehow got 3.61 on it. Literally destroyed my asshole with a thousand trannydicks.

Can I wipe the memory card and put it in another vita?

how do I install soundhax?I just downloaded it.
github.com/nedwill/soundhax

What were you doing?

Only underage nintendrones actually believed that
Same shit with the Switch

if you run from ctrnand root you have to put the safe installer payload in ctrnand/rw/luma/payloads
not on the sd card.

github.com/FlimFlam69/WiiUTutorial/

you sure it's not just spoofing the firmware?

Nintendo took down Freeshop

github.com/github/dmca/blob/e4ed44931e5cf8693701461488b597f38e4620d7/2016-12-27-Nintendo.md

Is there any other way to download/install it?

Of course i Do

Why would you? Tikshop is way better, unless you care about games from other regions.

mega.nz/#!CdcQBaST!thDggOgLzKnFCbpizg_hHKhpQcVgVV0GjlEwK7t5rhM

somebody hold onto this it's a new updated OP in case I'm not able to post it later you lazy faggots

>pastebin.com/ELu6YaaR

Hello, I represent Nintendo and my client believes to have found discussion and enabling behavior of infringing on their copyright and trademarks.

URLs to find this happening are as follows:
>>
Veeky Forums.org

Nintendo's copyrighted work or trademarks are not on the Approved Non-affiliated sites of critical Analysis List (hereinafter referred to as ANAL).

Please immediately remove access to all URLs listed above in compliance.
We lack any uniquely identifiable information about any poster there barring the community-coined "tripfags", "avatarfags" or "namefags".
These exemplary users should be of the highest priority that you give us contact details of so we can seek legal damages compensation.

I swear, under penalty of perjury, that the information in this notification is accurate and that I am the copyright owner, or am authorized to act on behalf of the owner, of an exclusive right that is allegedly infringed.

...

>put the safe installer payload in ctrnand/rw/luma/payloads
there is nothing about this step on 3ds.guide also, don't have /luma/payloads under rw. means I have to create them? Also, down_safea9lhinstaller.bin from update steps?

It should still be up on FBI's TitleDB indefinitely

...

don't mind me, just infringing on some copyrights

where is the root of my SD card?on the SD card first folder or the 3ds folder inside the SD card?

so it's shit then

MARIO IS A NIGGER
A NIGGER

classic

Thank you sir

There should be a folder named "root" on it

PAJEET PATEL

>I overflow my data onto the next heap chunk, which lets me fully control the malloc header of that chunk, which happens to be allocated at the time of the overflow. When that chunk is freed, a heap unlink is performed, which allows me to do an arbitrary write. This means I can write a dword to the stack and control PC. Unfortunately, there aren't any usable gadgets (trust me, I looked), so I had to use a more advanced technique to exploit the bug. I used the arbitrary write to overwrite the free list header with a stack address, while setting the start and end fields of the chunk being freed to cause the block to appear undersized, thus causing it to not be added to the free list and so the stack address I just wrote is used on the next malloc. Because malloc jumps through the free list looking for a suitable block, I had to find a stack address at which there appears to be a valid heap chunk header with a large enough size for the requested allocation and null pointers for the next and prev entries in the list, so that my stack chunk is chosen as the 'best' one. Once all of these conditions are met, the next malloc returns the stack address as the 'heap' location to write my next tag data, which lets me turn the arbitrary write primitive into ROP. From there I use the gspwn GPU exploit to write my stage2 shellcode over the text section of the sound process, before finally jumping to it.

holy shit

this and if not creat a folder named root with a folder inside of it named root

Don't forget you need to make it in the root directory

ciangel wins again

What? SD cards don't have roots, they're not plants silly

fembrewer here, im fucking wet from reading this
take note, this is what we want from guys

Nothing, I haven't touched the thing since the scene exploded and I wanted to install trails of cold steel until after a few errors I looked at the system settings and it said 3.61


I'm an illiterate, what do you mean by spoofing? Do you mean that it's still not properly installed?

Anyone here with nintendont on their wiiu? can i use a usb flash drive for gamecube games? i dont want to have to shell out for a usb hd because theres only 3 or so multiplayer games i want to download for it.

thats fine it means you are just running a9lh from nand rather than both it and luma.
read the guide carefully. it tells you to copy the safearm9installer.bin to luma/payloads and rename it to down_*.bin. but if you managed to get to the installer screen that means you probably already did it right.
the only other thing i can think of that you did wrong is the files in the a9lh folder.
also if you already have the latest version of arm9loaderhax installed, which you have to have in order to run from ctrnand in the first place. safearm9 installer does nothing.
generally speaking you dont even need to update a9lh just luma.

Surely you had a the PIN unlock enabled on it.

I don't know why people think they need to update a9lh so much. Either way, are you sure you're using the Luma arm9haxloader.bin in your root?
If so, are you definitely sure you placed it there? You should have like 9 folders, then one file. That file being the .bin

it doesn't sound that complicated I just wanna know what he did to access it which shouldn't be too hard to guess

use your sd

I'd like you to malloc your stack in my heap chunk, if you know what I mean ;^)

HOW THE FUCK DOES SOUNDHAX EVEN WORKS?DO I JUST PLAY THE FILE ON THE SD CARD AND WAIT FOR MAGIC OR WHAT?

yeah you can use a flashdrive

PIN unlock? what is that?

turn off the vita and turn back on and look at the version

The repo tells you what to do. It only works if you're on US 3DS though.

Someone please give me a run down of all the announced "hax"

Also do I really have to fucking uninstall a9lh for sighax? Fucking hell man.

you play a sound from your sdcard in the music app. it overflows some buffers and starts the boot.3ds file on your sd root.

YES I have an US 3ds on 11.1 but what do I download with it and how is the process?

dmcahax

sighax doesn't present any improvements over a9lh when it's installed.

It's easier to install though.

>use freeshop they said
>Nintendo can't do anything about it they said
>it's safe

Nintendo has all your info.
Enjoy your band and lawsuits.

CIA MASTERRACE

don't worry about sighax for now, I'm sure we'll get more solid info on if it's worth switching to later

it actually is safe still

NOT MY BAND! NOOOOOOOOOOOOOO

a9lh should let you install sighax. You need nand access with a9lh already has.

>If all three boxes are checked (only USA atm), then put otherapp.bin on your SD card along with soundhax.m4a and launch the song from the sound player.
You get otherapp from smea's homebrew site, the m4a is on the repo.

As far as I know, yes, that's literally it.

It exploits a flaw in the MPEG parser (song name buffer overflow) to run the homebrew launcher.

What are some good GBA/DS/PSP games that are easily emulatable on a phone? Since I don't have physical buttons, stuff like RPGs, Visual Novels and stuff are easier to play.

I never owned a PSP so I'm especially looking at those. Finished all the Ace Attorney and Layton games, currently working my way through Ghost Trick and 999. Have Digimon World: Dawn on the backburner. Not especially interested in pokemon titles or Earthbound so I've beaten them so long ago. I have Yggdrasil Union and FF:Tactics on the GBA side.

Phone is an HTC 10 running Nougat, using Drastic/MyBoy/PPSSPP if it matters for any reason

We can still install freeShop if we have the cia, right? It can still pull enctitlekeys, I assume?

The fuck you on about moron. It doesn't take any identifying info.

Yes, yes.

Nintendo solved nothing, as usual.

you can use those for it to? i think i only have a 4gig sdcard left. i havent actually setup nintendont or even vwii im just preparing for it. later today i think i will.

thanks thats great news

yes, I did the rename part. put the sd card back, booted with d-pad down and chose select to install. however, nothing happaned (as in no visual feedback). could this be the problem?

the problem I have (or rather guide does not state) is that I have to copy more then 1 file to ctr nand. so what do?
luma is (arm9loaderhax.bin) both on root of sd and root of ctr nand.
should I create /luma/payloads under rw and copy what into it? Hourglass9 (start_Hourglass9.bin)?

If space is an issue try your luck trimming the rom down, they aren't particuarly big anyway what with the discs being of the mini variety.
dmtoolbox might help, if you can't find a copy try filetrip it never lets me down for random shit like that.
But yes it offers sd and usb loading.

so I got the starter kit,put it on the root of my SD card(I also downloaded the otherapp) and then played the soundhax-usa.m4a and then the screen freezes for some seconds so it comes back to the home menu saying the app has frozen and my 3ds restarts.
did I do anything wrong?

What region is your 3ds?

So what exactly is the benefit of sighax if you already have a9lh?

I get that it lets you sign your own firmwares and stuff, but what is the benefit of that when you have a9lh already?

USA,its on 11.1.0-34U

You can dump your OTP without going to 2.1.

That's literally it.

Did you download the correct otherapp?
Also something I forgot, you'll probably need to move the contents of smealum.github.io/ninjhax2/starter.zip onto your SD card. I don't have a US 3DS so I can't see it's normal to crash.

download the robpin for you FW and region instead of otherapp, place it in root, rename it "browserhax_hblauncher_ropbin_payload.bin"

i swear you idiots cant troubleshoot for shit

If you're on o3DS, use cdn.discordapp.com/attachments/196635745551646720/263700084611350529/soundhax.m4a instead
The one on the repo doesn't work on o3DS

It's still there ;_____;

If there's no solution to this, can I still format my memory card and put it in another vita below 3.61?

and don't forget the starter kit

>3DS gets BTFO at 33c3
>Nintendo only just decides to take down FreeShop
Typical Nintendo being 2 years behind.

You wouldn't even need the OTP. You'd have even more complete access over the system.

A9LH works by gaining control quickly AFTER boot, but with this we have control literally from the start.
The line is blurred because we're running CFW (Luma) immediately to fix the shortcomings.

>a9lh should let you install sighax
any info on this? want to do
>You can dump your OTP
very interested in doing that without jumping through the hoops due to n3DS XL.

Well there's no info yet, because no one's implemented it. You might be waiting a while yet.