Jump to content

Nintendo Attempts to Drown Hacked 3DSs with Banwave


theSLAYER

Recommended Posts

1 hour ago, theSLAYER said:

The bans should be permanent, as per last time.

When will they decide to stop attacking in waves? No idea, we don't work for Nintendo :/

lets just say i have a banned console and tempted to try the second or third method  https://techdrake.com/2016/11/here-are-some-legit-ways-to-get-unbanned-from-pokemon-sun-moon/     ( mainly because i dont have a spare 3ds right now lol )


 i'm just wondering is there any chance of my system getting banned again ? :/

if the answer is no then i have another inquiry

in reality my system hasn't been banned yet because i luckily  got the news of the banwaves beforehand and didn't turn on my ds  ever since

now can i still use the methods mentioned above as a precautionary step to avoid getting banned for real ?

Link to comment
Share on other sites

I don't know how many times I have to say this,
but there is no point in attempting the unbanning procedures at this point,
simply because after you unban yourself,
They could ban you again

The methods listed doesn't create "an unlimited amount of Seed (localfriendcode)",
which means eventually you'll be run out of seeds to unban yourself.
(which frankly if you're lucky, you only get 1 extra seed from the same 3DS, before having to buy other 3DSs to grab their seeds to unban yourself)


What's important is for devs to identify how the 3DSs got identified/detected for the ban.
and until that can be prevented/circumvented, Nintendo can just up and ban you again and again.

 

So guys, time patiently to wait.

If I'm not mistaken, AuroraWright's standing theory is the titlelist is being sent to the server.
No more fancy FBI and JKSM from your home page; time to run HBL through Health & Safety.
(as well as disabling Spotpass information sending and Friends information sharing)

  • Like 2
Link to comment
Share on other sites

Hey guys! I got banned in my two consoles (Somebody is a bad guy here). But the thing is... in one I've received an Spotpass Notification which says that Friend List, StreetPass and Spotpass won't work on my 3DS games. The other one didn't receive anything.

Did this happen to anyone who is banned?

Link to comment
Share on other sites

2 hours ago, theSLAYER said:

I don't know how many times I have to say this,
but there is no point in attempting the unbanning procedures at this point,
simply because after you unban yourself,
They could ban you again

The methods listed doesn't create "an unlimited amount of Seed (localfriendcode)",
which means eventually you'll be run out of seeds to unban yourself.
(which frankly if you're lucky, you only get 1 extra seed from the same 3DS, before having to buy other 3DSs to grab their seeds to unban yourself)


What's important is for devs to identify how the 3DSs got identified/detected for the ban.
and until that can be prevented/circumvented, Nintendo can just up and ban you again and again.

 

So guys, time patiently to wait.

If I'm not mistaken, AuroraWright's standing theory is the titlelist is being sent to the server.
No more fancy FBI and JKSM from your home page; time to run HBL through Health & Safety.
(as well as disabling Spotpass information sending and Friends information sharing)

oh darn it that means i have to uninstall cfw for the time being

Link to comment
Share on other sites

25 minutes ago, TheObserverYouAlwaysWanted said:

oh darn it that means i have to uninstall cfw for the time being

not necessarily, just don't go online.

(plus if you uninstall CFW, and update to 11.4, there's no other way to get back to CFW right now, I think)

Link to comment
Share on other sites

So far it looks like the following is getting people banned (not exclusively, and this is my opinion):
- boot9strap (hacked/faked signature)
- pirated games (hacked/faked signature)

Some people I know have not been banned and they use Luma (arm9loader or older), and homebrew cias.  No pirated games though.z
It also looks like dumping a legit game from a cart (decrypt9) also didn't trigger it.  I am not familiar with signatures for that method though.

I would venture to guess they are detecting apps/firmware with bogus signatures.

Link to comment
Share on other sites

One of my friends got B9S and has "Send data to Nintendo" on. He uses apps like CIAngel, JKSV, HBL and FBI but hasn't been banned. So I don't think tickets are the cause, or maybe it's just luck he dodged the hammer.

 I would suggest not to put a Homebrew app as your favorite title in Friend's List or maybe turn off wireless when accessing those kinds of apps.

I also heard some people that got it saying the ban lifted for them, but I dunno if they're lying or not considering it's supposed to be permanent.

Link to comment
Share on other sites

2 hours ago, Sabresite said:

It looks like the biggest correlation is Freeshop.  People who have used FBI and other methods to install apps/games, do not seem to be widely affected.

But there is ppl that never used freeshop and got banned

Link to comment
Share on other sites

1 hour ago, JISN064 said:

But there is ppl that never used freeshop and got banned

Did those people install a pirated game somehow? It looks like by and large, those were the people targeted.  And it is true, there are outliers (if you believe internet accounts) where people had a stock N3DS, or didn't pirate a game but had CFW/HB.

Link to comment
Share on other sites

Well ... I started using freeshop like 2 weeks ago ... maybe less ... and got the ban

there is ppl that did have freeshop months before me ... and didn't get the ban ...

 

 

I hope the Dev Gods find what is the thing that tells nintendo who are using CFW T-T

Link to comment
Share on other sites

So far I'm not banned. I only used Freeshop to get Trip World (since it never got put on North America eShop) and GB Tetris (since it got delisted thanks to Ubisoft). This was last year and all three have since been deleted. The rest of my game installs have been from carts I dumped myself. I tend to use FBI, JKSM and Luma Updater. Just to be safe, I did withdraw all of my Pokemon from Bank that I don't already have backups of and cashed in my Battle Points on Moon.

Edited by Invader TAK
Link to comment
Share on other sites

"It's telemetry sent to Nintendo. No it's not just the play activity that's sent, there's a shit load of other stuff too. Everything the 3DS sends by network you can figure it out by using packet sniffers. Nintendo segregates everything, a flaw for sure, so you can block everything that would send unsolicited data and still be able to play online/download games." - Anonymous 

I saw this info and thought I would share maybe its true maybe it isn't but I figured there's no harm in letting you guys know anyway. The person who said this, said there is 6 more links. I don't know anything about all this technical stuff though lol. Anyway do with this info as you will it was shared on 4chan so it could all be bogus.


>https://pls.c.shop.nintendowifi.net/pl/upload This URL is used for uploading data from the home menu NAND shared extdata, it's unknown what this is used for. This data is uploaded every 24 hours.
>https://npul.c.app.nintendowifi.net/p01/recv/<regionID>/<filename> This is used for uploading unknown data from extdata.

Edited by seijiro
Link to comment
Share on other sites

My console was banned Monday night, before it really became a banwave. My situation...

1.) Spotpass was disabled, for a long time, at least since a NAND restore in February, at most since I first got it in October last year.

2.) The Friends List App setting about showing titles being played to friends, was unwittingly left enabled. In contrast all my 6 other consoles had both Spotpass and this setting disabled and have not been banned (at least not yet).

3.) I never used Freeshop, I browsed it once a year ago to see if ORAS updates can be downloaded. They couldn't, this was the banned console. Remembering more, another console, I searched on Freeshop for SM updates, still nothing, and that is currently unbanned.

4.) The banned console really had the least unsighned CIA. NTR CFW, FTPD, InputRedirectionNTR, I ran those the most. When I called Nintendo CS on Tuesday, the rep said that they picked up something on Monday. The thing is all I did was run NTR CFW, the Friends List app to add people, and boot up Pokemon Moon. It does make me lean towards the Friends List app setting.

5.) It may not be a coincidence that I've done the most genning on that particular console, with that particular Moon game. Seeing as it never game synced too, perhaps that kind of activity was detected and I got snuffed out.

6.) Not so significant given the varied userbase, I have 11.4 B9S CFW, on all consoles.

7.) I never went online with the leaked SM copies. I did play a tiny bit (5 minutes worth, technically about 45 minutes but that's the damn cutscenes), but on a console that is currently not banned.

I think I explained enough. The bottom line is they were able to detect the use of "unauthorized software" better than usual, and acted hastily, perhaps in response to B9S and SigHax, and/or an accumulation of building up a list of people to ban, with this week being execution time. Unfortunately the banned console also had the most NNID purchases, so if I can't move that to a safe console, I'm looking at $30-40 of repurchases (if I want the Smash 4 DLC, I'll likely opt out, it still is crap if I had to buy this stuff again).

Link to comment
Share on other sites

27 minutes ago, seijiro said:

I saw this info and thought I would share maybe its true maybe it isn't but I figured there's no harm in letting you guys know anyway. The person who said this, said there is 6 more links. I don't know anything about all this technical stuff though lol. Anyway do with this info as you will it was shared on 4chan so it could all be bogus.

Do you have the other 6 hostnames (links)?

If you have a good router / firewall you can block devices on your network from connecting to:

pls.c.shop.nintendowifi.net
npul.c.app.nintendowifi.net

In theory if you block all the hostnames the 3DS uses to call home you can be connected to WiFi knowing the 3DS can't send data back to Nintendo.

I block updates for the Wii U this way, my router looks for any traffic coming from my Wii U's local IP address, then if it's going to any of the hostname's ive added to the WiiUServers hostname alias, it will block the connection. The end result is I can play Mario Kart online, knowing Nintendo can't update the Wii U in the background, patching the exploits used for homebrew.

6s9E9Yp.jpg

Even if that did work we don't truly know all the hosts Nintendo might use to gather data, even if we we're confident we did blocking them could well break online functionality anyway.

Link to comment
Share on other sites

30 minutes ago, InsaneNutter said:

Do you have the other 6 hostnames (links)?

 

No sorry unfortunately the anon who shared the info said and i quote, ">tfw everyone in the 3ds scene is so incompetent and haven't figured out the bans yet
>you and a buddy that majored in networking figured it out with 99.9% certainty and already protected against it" 
He wasn't too keen on sharing the rest of the info. Someone will have to use packet sniffers like Charles or something to figure out the rest. I don't even know what all this stuff means lmao. I'm just the messenger.

Edited by seijiro
Link to comment
Share on other sites

d0k3 over at GBATemp published a list of hostnames the 3DS uses, the two hostnames your 4chan guy posted are on that list, along with a lot more.

Check and hosts updates:

nus.c.shop.nintendowifi.net
nus.cdn.c.shop.nintendowifi.net

Connection test:

conntest.nintendowifi.net

eShop specific:

ecs.c.shop.nintendowifi.net
cp3s-auth.c.shop.nintendowifi.net

Additional:

cas.c.shop.nintendowifi.net
ccs.c.shop.nintendowifi.net
ccs.cdn.c.shop.nintendowifi.net
ias.c.shop.nintendowifi.net
pls.c.shop.nintendowifi.net
npul.c.app.nintendowifi.net
cp3s.cdn.nintendowifi.net
eou.cdn.nintendowifi.net
npdl.cdn.nintendowifi.net

Apparently if you block all the above the following won't work:

  • Updating the 3DS FW
  • eShop, as that won't start unless it could check for an update first
  • System Data Transfer, for the same reasons
  • Anything that requires access to the update servers.

What works:

  • Browsing the internet
  • Playing online
  • Basically, everything that is not in the 'doesn't work' list will work

Theirs certainly no proof either way blocking any of the above will stop the 3DS sending data that will get you banned back to Nintendo, however for people that are going online you could certainly let the 3DS talk to a lot less servers and still have online play functionality by the looks of it.

  • Like 3
Link to comment
Share on other sites

7 hours ago, InsaneNutter said:

npdl.cdn.nintendowifi.net

Thanks for the list!

Btw, blocking the above one may prevent mystery gift connections.
(not sure about the rest)

edit:
blocking conntest.nintendowifi.net prevents game sync and pgl usage.
(couldn't use battle spot until I removed that entry)

Link to comment
Share on other sites

I i'm still banned, but I tried blocking all the domains and still got the 003-2001; I unlocked and got the ban error

 

I don't understand xD Maybe I did something wrong with my router setting ... gonna look for it tomorrow

gtg to work T-T

Edited by JISN064
Link to comment
Share on other sites

10 minutes ago, JISN064 said:

I i'm still banned, but I tried blocking all the domains and still got the 003-2001; I unlocked and got the ban error

 

I don't understand xD Maybe I did something wrong with my router setting ... gonna look for it tomorrow

gtg to work T-T

Wait, this won't "unban" you.

It's just that if you weren't banned (002-0102), this may help reduce the 3DS' communication with servers.

Odd, my router blocks everything except for npdl.cdn.nintendowifi.net and conntest.nintendowifi.net ,
and I was able to do a few battles and wonder trades just now.

003-2001 isn't a ban message, it's just that the 3ds isn't able to communicate with the necessary servers,
to validate and allow the online gameplay. (not the same as a ban)

Link to comment
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...