/hbg/ - Homebrew & Hacking General

hbg.exe edition

Previous thread /hbg/ Wiki: homebrew-general.wikia.com

-SAFE FIRMWARES-
3DS: 11.3 (11.5 via system transfer or magnethax)
Switch: 3.0.0
Wii U: 5.5.1
Vita: 3.60
PS4: 4.05 (Userland)
PS3: 3.55

-GUIDES-
3DS: pastebin.com/TQwDsWh9
b9s + CFW: 3ds-guide.b4k.co/
Wii U: pastebin.com/8u0WAyJC
Wii: sites.google.com/site/completesg/hacking-guide
Vita: pastebin.com/6DjeR08L

-RECENT NEWS-
>3DS
[Aug 13] Magnethax released. Requires a DS flashcard. R4i Gold 3DS RTS and Acekard 2i require no additional hardware.
[Sep 1] Anemone3DS is a new theme manager and recommended after what happened to the last two. gbatemp.net/threads/482804

>Switch
[Aug 1] Nintendo patched a major exploit with the release of 3.0.1. Set the primary and secondary DNS as 205.166.76.187 to block this update.

>Wii U
[Aug 15] New browser hack method for Wii U on firmware 5.5.2 gbatemp.net/threads/480966
[Jul 24] Hint at a Crunchyroll entrypoint. twitter.com/WiiUbru/status/889303560655175684

>Vita
[Aug 14] MLTActivator: activate your PS Vita offline wololo.net/2017/08/14/mltactivator-activate-ps-vita-offline/
[Jul 29] Vita online activation no longer works on 3.60, if you haven't activated it Adrenaline will NOT work. gist.github.com/yifanlu/c4cc12d3f1ccaebbf1846b84a69a4bfb
[Jul 29] HENkaku Enso got released. enso.henkaku.xyz/

>PS4
[Aug 3] 4.73 released, blocks MTX Key, ban reports on shared piracy accounts. wololo.net/2017/08/03/ps4-firmware-4-73-released-blocks-mtx-key-ban-reports-shared-piracy-accounts/

Other urls found in this thread:

youtu.be/R5wxs8vSQps
youtube.com/watch?v=aW2LvQUcwqc
github.com/TheOfficialFloW/Adrenaline/releases
twitter.com/SFWRedditGifs

Reposting because the last thread hit bump limit.
If any of the PKHeX creators are here, I've got a question. Are there any plans to update/improve Pokemon Battle Revolution support?

Right now, I can only see Pokemon I uploaded from Pearl that are in boxes, and can't edit anything else. It'd be nice to edit (or even see) the stats of Pokemon on rental passes, as I've gotten a lot of mons I like from the Trade Battle system, and would like to be able to replicate them on a cart-based game. Also, in the editors for every cart-based game, you were able to edit Pokemon in your party, but in PBR's editor you can't do that.
Also, would it be possible to change trainer customization through PKHeX later on? I want to change my black rental pass trainer to make him white, and vice versa for another trainer, but you can't change skin tones in the in-game customizer.

Safe to update 3ds with Luma 7.0.5? (or whatever the last pre b9s version was?)

FOURTH FOR METROID SR FUCKING WHEN

What are you expecting to happen

Black screen like every other time the luma version wasnt compatible with new fw

>mfw user says the game is leaked
WHERES THE FUCKING CIA LINK

the game no one cares about MH:Stories leaked. check the last thread for a mega link

Metroid SR PLS

I forgot to type in Metroid Samus returns

How do I update my emunand from cakes to luma? got back from deployment and it's been a long time messing with this shit. It's on old firmware.

And it would be that difficult for you to swap out a single file on your root if that happened?

Follow the guide at the top from start to finish. Welcome back user.

Welcome back user

Welcome back. Goodluck.

NTRBoot possible with regular 3DS game cartridges, to be dubbed CTRBoot.

youtu.be/R5wxs8vSQps

what the fuckshit-

how??

>Set the primary and secondary DNS as 205.166.76.187

I get the error, "Could not perform DNS name resolution". I've tried this on two different routers.

Hopefully with this the price of flashcards will return to normal.

Just like DSi Mode flashcarts, CTR carts have a flashable NAND. The encryption on these was much more advanced and modifying the firmware to respond to NTR cart commands took a lot longer than it did for the flashcarts, but it is possible as shown in the POC here.

nobody said they planned to release ;)

Are all games the same in this regard or could it be like flashcards and it is only compatible with some games developers find a way to flash?

nobody said they didn't either, fuckwit.

>NAND
Only some games though. I think Animal Crossing was the first; Pokemon X, Y, and a number of others now do this.

in the "Card2" CTR cards, the game ROM data and save data are stored side-by-side on the cartridge's NAND, and it's fed through a new controller which simulates the classic burned-in ROM data.
Normally to flash/rewrite the entire NAND memory in a cartridge, beyond the savedata "partition", required factory-level access to the NAND/CARD controller, which includes a crypto engine, and even a tiny ARM core!

After the game is burned in, a fuse is blown, making the controller disallow access to the rest of the card data.

This is an exploit involving said controller, a vulnerability in its processing of certain commands related to high-speed reverse entabulation of the cryptographical values in flux.

now now, play nice

How does Nintendo do it?

fake

Not real, since the bootrom tries to read from an NTR card (i.e. Nintendo DS card), not a CTR card (i.e. Nintendo 3DS card).

The bootrom can't read from CTR cards. So it's FAKE NEWS

My PS3 shut down earlier with a red flashing light while I was deleting some stuff in multiman. Supposedly that's caused by overheating, but I haven't had any issues yet with overheating while playing games. The only other time it's ever happened was when I was watching something on it using Showtime. Are there a separate set of fan settings for CFW stuff that I should mess with, or is my PS3 just starting to die?

The firmware of the CTR card was rewritten to respond to the same cart commands as an NTR card.

>reverse entabulation
How does this exploit work? It's pretty simple, in theory.
The original algorithm had a base state of prefabricated memory allocated in ROM, surrounded by a mutable deterministic header in such a way that the two main seed values were in a direct line with the parametric scrambler.
The latter consisted simply of six high-entropic Markov chains, so fitted to the analytic columnar table shifter, that side-channel fumbling was effectively prevented.
The main Feistel network was of the normal Tripling-oriented Doche–Icart–Kohel curve type, placed in projective homomorphic isolation to the pseudo-random number generator, every seventh iteration being conducted within a nonreversible time-domain multiplexed pipe to the differential cache delimiter, on the "top" end of the memory.

Umm no, you can't write to CTR cards like that. They are read-only for a reason. Or did you suddenly find out how to write to read-only memory? And how would you even make it respond to different commands?

I hope Samus Returns doesn't leak until at least the 10th.

I dont want to get distracted from MH stories plus I might give Zero Mission a run on my 3DS right before it comes out.

Not exactly. The CTR card has a small microcontroller, called a Flash Transition Layer. Look it up.
Most flash memories have a similar type of controller between the raw SLC/MLC NAND flash and the host device.
This exploit involves the firmware of the FTL in the CTR card. It's similar to, say, Samdunk on Samsung eMMC chips.

This stinks of jargon and bullshit but it makes me smile for some reason.

stories is shit, SR might be decent, what's the problem here

>buy a 32 GB SD
>put games in
>it's full
>buy a 64 GB SD
>put even more games in
>now only have 5GB left
>still missing a ton of good games
>need to get a 128GB SD

The pirate life ain't an easy life, I tell ya.

Thread OP should include something about Adrenaline for Vita no longer needing activation to be installed. That pretty much deprecates MLTActivator, since pretty much the only thing you need activation for now is using PSN. And going on to PSN with a Vita activated with MLTActivator will get you banned.

Is disliking MH stories a meme?

What's wrong with it? Seems like a high quality title.

Sounds like you don't know what you're talking about...

it's a flash translation layer and no, it does not.
The CTR card, even the oh-so-special "Card 2" kinds, are just dumb cards which handle raw data out to the 3DS.

The reason your whole thing with this is totally incompatible, is because of the voltages. The two card types run at different voltages, and even an expertly-reniggered 3DS game won't work for the magnethax.
Sorry, but you've been caught in bullshit.

tfw youtube.com/watch?v=aW2LvQUcwqc

goes against everything the franchise once stood for MONSTER HUNTING, has a fucking fleshed out story despite no other monhun game having one, just a very bare bones "hey this monster fucked my shit/the village up so go kill it", graphics and artstyle more fitting for an animal's crossing than this

disliking it is not a meme, it's unpopular even on japan and they eat up cute shit like this on a daily basis

Wii injects into Wii U VC and no one has anything made yet?

>The reason your whole thing with this is totally incompatible, is because of the voltages. The two card types run at different voltages, and even an expertly-reniggered 3DS game won't work for the magnethax.

This shows you have no idea what you're talking about. Maybe you're thinking of GBA carts.

The voltage is supplied by the console, not the cart. If the carts ran at different voltages, they wouldn't work at all, and could very well be friend by the console.

Your attempts to call others "bullshit" just made you seem uneducated and completely discredited you.

> and could very well be friend by the console.

3DS x Cart. Adorable.

got in touch with the creator and he said they probably wont release it any time soon but more details will be coming soon

I'm following the gbatemp thread, it's a fucking mess. People are still trying to figure out how to get Nintendon't to work. The compatibility with gamepad controls is also fucking horrible.

I hope people will actually making and sharing the injects once all this shit is done. I'm happy with not needing a second HDD to play Wii games already, and I don't really mind the wiimote.

when hl3 releases

How's this?

[Sep 4] Adrenaline no longer requires any basegame or activation, just PSN. In fact, going on PSN with a system using MLTActivator will get you banned.

>l'eh old mememe!! xxddd

So, if this thing is real. Does it delete your ROM data? What about your saves? Is it permanent?

So you're upset that a side game has a story to it and isn't solely about hunting monsters (even though you do indeed do that in the game among other things).

>it's unpopular even on japan and they eat up cute shit like this on a daily basis
[Citation needed]
Isn't this the same game has also has a 50 episode anime?
I ave a hard time believing at a pokemon esque game for a huge franchise like monster hunter isn't popular.

Seems like you're one of those purists that cant handle side things in a series.

>So, if this thing is real. Does it delete your ROM data? What about your saves? Is it permanent?
I mean, assuming it's even real. Of course it would overwrite the rom and basically destroy it. Again, assuming it's real.

Aight guys I've been sitting on my Vita since they came out. It's currently on 3.6.0, should I follow the standard Vita guide or is there any wonky shit I need to do?

>a whole week and no Risky Boots DLC for my WiiU

Henkaku is pretty foolproof, probably the easiest hack here.

You may want to look into getting an SD2Vita adapter

It modifies a small amount of firmware data, on the cartridge NAND, outside of reach of the actual game data and gamesaves, and places the ntrboot payload in empty space reserved for the card firmware, for wear-leveling the writeable savedata areas.

There's no guarantee that it won't delete everything, but while the exploit is installed, the cartridge is absolutely unusable for playing games. You can restore it by flashing back a backup of that data, though.

However, it is very possible to brick your cartridge, making it unusable - it enters a "programming mode", used in the factory for writing the original ROM and card-specific data like online information. Since the write-protect fuse is already burned, this mode doesn't allow you to recover the card, and the exploit we use for it in the normal CTRCARD mode, does not work in this mode.

Fun fact: 3DS cartridges are programmed while in NTRCARD mode. We take advantage of this, to allow ntrboot to work.

it'd be more useful if you could inject Gamecube games.
call me when thats possible.

I meant Vita TV but it should work just the same though right? Also def will check out the SD2Vita

Risky never gets me harder than with her hair down.

[Sep 4] Adrenaline no longer requires a base game or activation. You still cannot activate new Vitas to use PSN. Do not use MTLActivator and go on PSN, you will be banned.

Gotcha. Hopefully this is the best of both.

[Sep 4] New Adrenaline release. github.com/TheOfficialFloW/Adrenaline/releases
-Adrenaline no longer requires a base game or activation. You still cannot activate new Vitas to use PSN. Do not use MTLActivator and go on PSN, you will be banned.

It works the same. Although Playstation TVs don't even need an SD2Vita because you can use normal USB mass storage with them, but they are still compatible with SD2Vita if you really want to use one for some reason.

Oh cool then thanks helpful user

I bought a 2DS from them back when the latest was 10.something and it came with 8.0. They really aren't as strict about updating refurbs as you fags think.

of course you got a low one when hacking it wasnt as big dumbass

CHECK 3DSISO SOMEONE HAS A COPY AND THEY NEED HELP UPLOADING

10.X was peak hacking, retard. Nintendo cares way less now than they did then.

Incase you didn't see it last thread:Can't you just download the flash/kernal from somewhere and rewrite it?Or does only a backup work?

you're lying.

>seek out Shantae DLC titlekey
>nothing, as usual for DLC
>desperately try to get the titlekey or tik
>can't get anything
>use Uwizard to download all the game files and decrypt them
>that doesn't give me anything remotely useful
WHERE THE FUCK IS THE TITLEKEY

Is there a hardware/software reason why you can only have 10 themes on shuffle for homebrew theme programs? Or is it just an arbitrary number?

nintendo just made it that way

Official theme shuffle only lets you cycle through 10 too

don't give up, user. you might be our only hope!

there's only ten slots in the shuffle data, as far as I know. Nintendo did a lot of things like this, hardcoding numbers like this.

By the way, would it be more helpful to dump my PBR save and upload it here?

What do you expect me to do from here? All I have is decrypted game files, I don't even know if that's SUPPOSED to have the ticket anywhere. I see a bunch of .pak files.

Ah, I see. So it's an arbitrary number on Nintendo's end. Fair enough.

That which you seek is available for you to achieve through underhanded means. Time is of the essence, for you must seize this opportunity before what you desire is removed.

>Anemone3DS is a new theme manager and recommended after what happened to the last two.
What happened?

Only oldfags will remember.

The guy who waged the war on official Adblock devs made Themely, then at the same time he said it was a really funny idea to steal friend seeds using his software made it closed source. At least someone forked that beforehand, but now we have a reliable dev making a soon to be better tool.

P.S. Rinne was always a cunt. Who remembers people defending their honor itt?

I think the words he said was that the software that stole the seeds was 'clever', which isn't quite an endorsement, but considering he closed his source just afterward, it's not much better.

On top of that he shut his tempkiddie thread, unable to keep himself out of drama. No real explanation for his actions either way.

Really? I didn't hear about that one.
What is it about homebrew stuff that creates so much drama, I wonder?

>At least someone forked that beforehand
He didn't delete the repository so everything that was there is still on there. You can still fork the original project if you really wanted to. It is funny though that the commit message when he deleted everything was "Remove source to prevent confusion" which only added confusion if anything.

>Unofficial Bootstrap
4787-Pokemon Heart Gold NTR IPKE USA Latest unofficial red/cannot boot white screen

4788-Soul Silver NTR IPKE USA latest unofficial green/works fine

4998-Pokemon Platinum NTR CPUE USA latest unofficial green/works fine

Is ds rom loading worth waiting for?I mostly use cash for all things and don't trust just any site with my credit card.

That's funny. Even the guy who forked it is endorsing Anemone, so Themely honestly feels depreciated in my book.

What's the recommended Vita screenshot plugin? I was using Screenie for a while, but is there anything better?

You mean 3DS ThemeManager?That caused alot of butthurt from Erman's fans,some mods and Erman himself.

Am I retarded?My themes that work with other managers won't install with Anemone3DS and just my home menu looks all white even though it said it installed the theme.Splash installing works fine.

Doesn't the Vita have screenshot functionality built-in? Just press the PS button and Start at the same time.

thanks man

Yes, but it does so as .jpg, adds a few things to the image like the logo of the game, and is also blocked in certain games/parts of games.

Is there an easy way to convert .cia to .3ds? All of the tools I have found are old as fuck and do not work properly.

Why would you even want to do that?

No because as the full game data, .3ds files contain some unique 0's and header info.

I have and still use my Gateway. Storage is full on my SD card within the system and the titles I want to install are shit like MH Stories that will be deleted after beating.

Do Luma screenshots still take triple the amount of time NTR does?

I'm trying to install the BotW update 1.1.3 + DLC via WUPinstaller. I installed the update, but the title screen says 1.1.0. What did I do wrong?