/hbg/ - Homebrew & Hacking General:

Alex tri rave med edition

Last thread: -SAFE FIRMWARES-
3DS: 11.3 (11.6 via magnethax or system transfer)
Switch: 3.0.0
Wii U: 5.5.2
Vita: 3.60
PS4: 4.05
PS3: 3.55 (4.82 for 25xx models (minver 3.56) and below)

-GUIDES-
3DS: pastebin.com/TQwDsWh9
Wii U: pastebin.com/DhfG6z7F
Wii: sites.google.com/site/completesg/hacking-guide
Vita: pastebin.com/6DjeR08L
PS3: pastebin.com/6rH9Fc2E

-RECENT NEWS-
>3DS
[Dec 20] Luma3DS 9.0 commits several lingering tweaks, including open source modules into a new stable release. github.com/AuroraWright/Luma3DS/releases
>Switch
[Jan 8] fail0verflow have announced shofEL2, a coldboot exploit for NVidia Tegra. wololo.net/2018/01/08/fail0verflow-announce-coldboot-exploit-nintendo-switch-say-interesting-times-ahead/
[Jan 8] kgsws has released a homebrew launcher UI, which is compatible with Pegaswitch and therefore 3.0.0 only. wololo.net/2018/01/08/nintendo-switch-kgsws-releases-homebrew-launcher-gui/
[Jan 3] qlutoo has posted an image of a Homebrew launcher GUI. More info on February 1st. twitter.com/qlutoo/status/948690228763680768
[Jan 2] New product by Team Xecuter will hack "any Switch" and be "absolutely future-proof". There are no details for now, but it's probably a modchip. It's coming out this spring. team-xecuter.com/team-xecuter-coming-to-your-nintendo-switch-console
[Dec 28] plutoo, derrek and naehrwert held a lecture at 34c3. switchbrew.github.io/34c3-slides/
>Vita
[Dec 28] ReNpDrm and ReStore released. wololo.net/2017/12/28/restore-updated-to-beta-42/
>PS4
[Jan 8] Flatz has published a writeup concerning possible ways of installing and running custom packages regardless of firmware. wololo.net/2018/01/08/flatz-writeup-ps4-package-files-open-console-convenient-native-homebrews-piracy/

Other urls found in this thread:

reddit.com/r/SwitchHacks/comments/7rq0cu/jamais_vu_a_100_trustzone_code_execution_exploit/
youtube.com/watch?v=EJ9euU2u-EU
twitter.com/SFWRedditImages

reddit.com/r/SwitchHacks/comments/7rq0cu/jamais_vu_a_100_trustzone_code_execution_exploit/
New news: SciresM released a TrustZone exploit description on 1.0.0.

Skate 3 DLC rap files when

Reminder that DS ROM loading from SD was not worth waiting for

What shall we do about the MQ?
The moralfag question.
Why is it that all moral fags just join a scene and corrupt from within. They go out of their way to infect a scene with their faggotry and aids.
The constantly push anti-piracy propaganda and subvert efforts by others to open a system up.
They lie about others to get what they want. Is it any wonder they have been removed form every scene they settle in?

I still haven't gotten a Switch.

I broke my 3ds by charging it next to where I was doing the dishes and now I don't know if I should get a new one
I definitely will if AA7 is released on the 3ds

me neither, I have absolutely zero interest in switch exclusives and mp4 isn't out yet.

You should probably get on that, user! Or you might miss out on all the kickass exploit writeups like (no actual releases because piracy is bad hehe :^) )

I'm working on getting a publically usable version of the exploit -- all the pieces are in place, including a publically documented way to pwn am on 1.0.0.

I think you mischaracterize me a touch.

>no actual releases because piracy is bad hehe
No actual releases because the entire pipeline to getting there would burn up unpatched releases.

1.0.0 has a publically documented flaw:

>Unchecked domain ID in common IPC code Prior to 2.0.0, object IDs in domain messages are not bounds checked. This out-of-bounds read could be exploited to brute-force ASLR and get PC control in some services that support domain messages.

That should be sufficient to pwn am, and from there TZ. As I said in I'll be working on getting a publically usable codebase going.

>1.0.0
I didn't think this would need to be said, but when I say "release" I'm talking about things people can actually use
On top of being for 1.0.0, doesn't this also need a japanese copy of puyo puyo tetris?

Little known fact: 1.0.0 has a browser, too.

Yes, it does.

Trustzone stuff for higher firmwares (tentatively "deja vu") will be released/made public when it makes sense to do so -- and given it still affects 4.x (although can't do much without the memory controller)...makes more sense to keep it waiting in the hopes that we can keep using it on even higher firmwares before Ninty patches it.

What are your plans from here on out?

I'm currently working on ncatool. Pic related.

After that, cfw dev/implementing emunand, then getting ready for 2.x/3.x deja vu release?

Heh, forgot to include pic.

No shit? That's what puyo puyo is for.

But why bother working on 1.0.0 at all then? Nobody is going to be able to use anything you release for it because nobody has a 1.0.0 console.

Because I have a 1.0.0 console, the exploits are all fixed which means I can make them public and get everyone who *does* have a 1.0.0 to serve as a public beta for my work, and then release deja vu after some more time has passed (and I get it to work on higher firmwares) letting everyone benefit from the work I've put in in the meantime?

Seems really win-win all-around.

HOLY SHIT

How do you get NCAs?

Dump the client cert from your console, and decrypt it (another thing you can do on PC with TrustZone taken down). Then download them from the CDN. Client certs are console-unique, though, so be careful...

You can also dump your current OS's from the SYSTEM:/ partition of NAND.

I think I'll wait until more tooling is available, but thanks

Yeah. The lack of tooling's a big problem, at the moment -- I'm trying to address it with ncatool, but my time's really better spent working on cfw stuff at the moment, I think.

Would you say this is a good time to buy a Switch, then? I've contacted GAME and I can't return the console, but I believe I can with Amazon, so I should be able to hunt for at least 3.0.2.

Yeah. A switch bought now on

Thank you! Keep on the good work!

Hey man thanks for what you're doing. BTW just so you know (and you probably already know) but Switchhax are not really complete unless we can pirate Dark Souls remaster.
There is not really any other point to owning a Switch for me at least. That and maybe MP4 and then the tiny chance we'll get MHW.

gee, all those:
>SMT
>Layton
>Ace Attorney
>Zelda
>Picross
>Fire Emblem
>ACNL/lifesim
>NES, SNES, GB, GBC, GBA, NDS, etc.
games are *totally* not worth a new 3ds. it's not like I plan on keeping this bad boy as a catch-all portable beast for years down the line.

has fail0verflow ever released any exploit for any console ever? they seem to just want epeen cred.

>it's not like I plan on keeping this bad boy as a catch-all portable beast for years down the line.
My thoughts exactly that's why I recently bought a n3dsxl, the thing is it feels a bit flimsy, like every button feels like a microswitch, I don't know it might be paranoia but we will have to see in the future

No, they haven't. But SciresM is a clever cookie, she can do something when he knows it's possible.

Reminder for brainlets like myself who just hacked their PS3 and had trouble starting folder format PS3 backups through Multiman / other managers:

Go to rebug toolbox and ENABLE Cobra Mode, that's literally all you have to do. I have no idea why it's not enabled by default.

3.61?

never

but I already played most of these. that said I had the small 3ds prior and got hand cramps from using it which discouraged me to play other good games

I never got the hand cramps meme. People that get them probably just have bad genetics.

1. How do I append 2 PS1 isos together to get a single EBOOT?
2. Are ReNpDrm and ReStore and pkgi working okay for everyone? I like to wait a bit until shit stops breaking before I use new stuff.
3. Will we pirates get Dark Souls Remaster on Switch?
4. Will a 128GB USB 3.0 Sandisk work okay on a PSTV?
5. When I install games with NoNpDrm, do I need double the disk space? And do updates still work from the PSN?
6. Is there any way to download updates on PS3 games with Rebug/CFW? Or can't we ever go online again?

Sorry for the massive number of questions, accept this qt wallpaper as payment

do you have the large 3ds?

Yes, but I play on my GBA SP and SNES on the Wii with the wiimote and I'm ok. I've never had wrist, hand or fingers pain either.
I would even like to get a GB Micro, but flashcarts are damn expensive.

Play 2 cups of mario kart 7 while drifting all the time on a n3dsxl and tell me you don't cramp

Did more than 2 on the O3DSXL. No cramps.

>burn up unpatched releases
this is just tranny moralfag propaganda, why don't those people who are 10000x smarter than me get to make the decisions about what to release or not?

>1.0.0
I regret updating my switch to 2.0.0 to go the browser way, now.
But keep up the good work, you're a champ !

>1.0.0 TZ shit is coming out
>2.3 and 3.0.0 "soon" too

Nice. So 1.0 to 3.0.0 will be getting CFW and all that jazz I take it? What about 3.0.1+?

It's 3.x, meaning 3.0.1 and 3.0.2 are affected. 4.x will be in wait mode.

Just wish I didn't have to lose my botw save switching switches.

6. Yes, just press triangle and check for updates if you're connected to the internet
No need to be logged to PSN, I have no account and can update my games just fine

I'm guessing Nintendo is trying hard at the moment to find the trustzone vulnerability and coldboot exploit. They haven't found the TZ vulnerability yet, as it hasn't been released and still in 4.1, right?

Anyone download and play Drakengard 3 with the Japanese dlc?

Doesnt seem to be available anywhere. Googling shows some people having issue with it just reinstalling but simply reinstalling the game and/or dlc doesnt seem to work

>hacks but no piracy
why bother anons
chinks release your tools
Xecuter light this scene on fire by releasing YOUR SHIT

Babby here, having trouble with Ps3 CFW

>CECHK02 Fat
>Following tutorial youtube.com/watch?v=EJ9euU2u-EU
>says 'no applicable update found' when I try to install
>try 4 different USB sticks
>try re-download files
>try re-format sticks

What do?

>by releasing YOUR SHIT
aka an expensive modchip

I'm confident we'll see something from SciresM, but the coodboot shit will never see the light of day.

>pay $50 or so
>get unlimited free games

It instantly pays for itself.

What does your folder structure look like?
Make sure the actual firmware file is named PS3UPDAT.PUP and it's located in PS3/UPDATE

So which one of you chucklefucks vandalised the titledb freeshop entry?

Make sure the USB is FAT32. Inside should be folders: "GAME" and inside that folder "UPDATE" drop rebug cfw in there and rename it PS3UPDAT.PUP

Yea That's all good.

Ok I'mma try changing the PS3 folder to GAME

You /v/itabros are using oclockvita or VSHMenu for the best performance, right?

What are some good PS3 games that aren't available on PSNDL ect?

Wow I'm dumb, that won't do anything, it has to be "PS3" , "UPDATE". I have no idea why I said "GAME", I've been multitasking and installing games over FTP into that folder on internal HDD and had a brainfart when typing.

Nah wait till xecuter releases their exploit then reverse that. Its probly a drmed version of fof exploit. Like the trueblu dongle on the ps3

? Wasn't there some drama going on between one of the freeshop dev or something like that?

>reddit.com/r/SwitchHacks/comments/7rq0cu/jamais_vu_a_100_trustzone_code_execution_exploit/

TrustZone code execution exploit on the switch

>literally the first post in the thread

Hey guys did you hear about that trustzone code execution exploit on switch?

You mean this?


>reddit.com/r/SwitchHacks/comments/7rq0cu/jamais_vu_a_100_trustzone_code_execution_exploit/

Yo guys, any news on some Switch hax yet? It's been a bit quiet on that front for a while.

Heard there was a 1.0.0 exploit, not sure though might need to double check leddit

>want more games to come out for the Switch in 2018 since it's looking pretty barren for now
>new games will probably require a firmware update
>have to sit on old firmware with no games until some nerds decide it's time to release the hax
life is suffering

That was the life of v2.15< PSP owners back in 2005

Buy Jap Puyo Puyo Tetris. Launch title that only requires firmware 1.0, plenty of gameplay and you'll probably need it for hax anyway.

I think you mean 1.5

Life sucked before devhook the OG emunand. , I was upgrading and downgrading between 2.0 and 1.5 to play Liberty City Stories.

/hbg/ I need your help. I wanna stream the gba emulator to my vita using moonlight but boy, I have no idea how to configurate steam big picture to work with the vita controls. Any ideas ?

I bought a PSP Slim when they came out and was happy to learn it could be hacked right away. Cost a pandora battery but m33 was well established by then so I had perfect running free games for years.
Sometimes patience is a virtue.

Thanks slowpoke

Downloading from most excellent duty freeshop. Give me random game titles. I have 48g of free space.

Style Savvy Trendsetters

7th Dragon III: Code VFD
Stella Glow

>telling someone to use Freeshop for Stella Glow when you can't get the undub without installing via CIA

I'll take suggestions on stuff outside of freeshop to download. I'm downloading Heroes of Ruin and Labyrinth No Kanata.

You're right, I'm an idiot. Only Code VFD, get the undub for Stella Glow.

>she

No it hasn't, CFW is coming for 3.x and below.
There aren't even games I want to play on switch for the next couple months besides Bayonetta and Dark souls, which are ports.

>he

SciresM must be a (beautiful

I don't care what ScriseM identifies as. At least he's been putting up for the 3ds and switch.

Yes, it really makes a difference in many places.

tfw my ps3 is cech-3004A, exploits never ever.

5 hours.

RELEASE THE PS4 5.X EXPLOIT NOW!

I was born male, and I identify as male.

would u bang women 3ds hackers

Did you just presume your own gender?

You're not a real homebrew developer if you're mentally stable.

idk where you live, but have you found any stores that still carry 3.0.2 and lower? I was thinking Toys R Us?

Im about to try and hack my 2ds xl and on the main menu on how to install bootstrap it says that the guide is going to assume that you already have it installed.

Please explain to a brainlet like myself on what i actually need to do. I dont want to mess everything up by jumping steps. I have the four swords but im not sure what else i need to do.

What is reading comrpehension

Look, im not a tech savy man.
Oh, so i install cfw first?

T-TWO MORE WEEKS.. I PROMISE.