Hacking Question Custom Screenshots on Switch?

  • Thread starter Deleted User
  • Start date
  • Views 6,125
  • Replies 8
D

Deleted User

Guest
OP
https://twitter.com/SciresM/status/885694921696354305
I might be a bit late, but this guy on Twitter was able transfer saves from one console to another, get custom screenshots etc. (I heard some hackers say that once you get access to your Switch saves, the security is a joke.) But for now, how would I get custom screenshots on my Switch? I have edited a screenshot and it just tells me that it is corrupted or damaged or something. I just wanna test something. I use paint.net and it retains the image info, but it doesn't work on switch. (It works on PC and every device I try.)
 
D

Deleted User

Guest
OP
I know that you cannot make an exploit out of this, I wasn't asking, I just wanna try out custom screenshots.
 

jakerman999

Well-Known Member
Newcomer
Joined
May 15, 2013
Messages
52
Trophies
0
Age
31
XP
338
Country
Canada
TL;DR: It's not a simple hex edit :(

The Switch won't look at an image unless it has the same timestamp as one that's already in memory. This means you either need to use an editor that doesn't alter the timestamp, or change the timestamp back after editing. This is fairly trivial.

But meeting that requirement doesn't mean the Switch will display the image yet. It now makes a copy of the image, makes the timestamp 0, hashes that copy and compares the hash to another that was saved with the timestamp that the image matches. The hash that is being compared against was generated from the screenshot taken at the timestamp. So how do we get our image to have the same hash as the one in memory(the original)?

Option A) hash collision. The new image has extra data added or some parts altered slightly to make the hash the same as the stored one. This is hard, as the nature of a hash means we can't use a formula to figure out what we need to change/add, it's a guess and check which means brute force. This borders on impossible as to figure out the hash we need to know what number the Switch uses to make the hash. Solving this takes breaking the Switch's crypto once and then a bruteforce for every picture you want to import.

Option B) change the hash in memory. Run the new image through the Switch's hash function, and overwrite the old hash with the new one. I believe this is what @SciresM has done, although I can only speculate how. PegaSwitch might be able to do it, or it might be a product of smhax, or some other unannounced [noun].

Option C) patch the hash check to always return true, or the image display to not care about a wrong hash (signature patching iirc). This probably requires TrustZone or at least kernel level code execution. Not likely.

Option D) ???
 
D

Deleted User

Guest
OP
So making the edited photo's properties the same as the Switch, as in the same date the screenshot was taken on the switch and making sure it is the same file size?
 

DarkIrata

Well-Known Member
Member
Joined
Jun 12, 2015
Messages
493
Trophies
0
Age
29
Website
ipmix.de
XP
1,591
Country
Germany
Well, first of all. You can Edit posts and don't need to make multiple posts.
How its currently work only SciresM can say more to it.
 

Dann_

Well-Known Member
Newcomer
Joined
May 3, 2016
Messages
66
Trophies
0
Age
32
XP
204
Country
Afghanistan
TL;DR: It's not a simple hex edit :(

The Switch won't look at an image unless it has the same timestamp as one that's already in memory. This means you either need to use an editor that doesn't alter the timestamp, or change the timestamp back after editing. This is fairly trivial.

But meeting that requirement doesn't mean the Switch will display the image yet. It now makes a copy of the image, makes the timestamp 0, hashes that copy and compares the hash to another that was saved with the timestamp that the image matches. The hash that is being compared against was generated from the screenshot taken at the timestamp. So how do we get our image to have the same hash as the one in memory(the original)?

Option A) hash collision. The new image has extra data added or some parts altered slightly to make the hash the same as the stored one. This is hard, as the nature of a hash means we can't use a formula to figure out what we need to change/add, it's a guess and check which means brute force. This borders on impossible as to figure out the hash we need to know what number the Switch uses to make the hash. Solving this takes breaking the Switch's crypto once and then a bruteforce for every picture you want to import.

Option B) change the hash in memory. Run the new image through the Switch's hash function, and overwrite the old hash with the new one. I believe this is what @SciresM has done, although I can only speculate how. PegaSwitch might be able to do it, or it might be a product of smhax, or some other unannounced [noun].

Option C) patch the hash check to always return true, or the image display to not care about a wrong hash (signature patching iirc). This probably requires TrustZone or at least kernel level code execution. Not likely.

Option D) ???
Hmm, doesn't it actually hash it on the fly instead of obtaining the hash from memory? Pretty sure it says so on switchbrew and hashing it is as easy as zeroing out the makernote and hashing it with a private key that has already been leaked by sciresm
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BakerMan @ BakerMan:
    or that german ninja turtle commercial
    +1
  • K3Nv2 @ K3Nv2:
    Forgot to buy BBQ sauce at the store so made my own ffs
  • RedColoredStars @ RedColoredStars:
    Blues Hog BBQ sauces are pretty good.
  • K3Nv2 @ K3Nv2:
    My insurance has a thing where if I do a virtual visit they'll just send me a $100 gift card to Walmart I'm about to sell a company my medical history for $100 lol
  • BigOnYa @ BigOnYa:
    My insurance has a thing called, " Nope, we aren't paying for that." that they like to use on us all the time. Then we play the "Ok we will go to some other insurance company." then they miraculously say ok we will pay for that.
  • The_Dizzy_Vizzy @ The_Dizzy_Vizzy:
    Well look at what the cat dragged in!!!
  • BigOnYa @ BigOnYa:
    Hey, do you feel any older?
  • K3Nv2 @ K3Nv2:
    No I don't
    +1
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, not right now
    +1
  • BigOnYa @ BigOnYa:
    @K3Nv2 That's my phrase, stop it
    +1
  • K3Nv2 @ K3Nv2:
    Your phrase is I'm not drunk
    +1
  • Xdqwerty @ Xdqwerty:
    I feel a discomfort in my throat
  • SylverReZ @ SylverReZ:
    BigOnYa after a long day.
  • AlbertJulian @ AlbertJulian:
    I got scammed last year by some internet fraudsters who made away with my crypto worth $210,000.I almost lost my life because i was so frustrated and was depressed..5 months ago a friend introduced me to {Assets lab} a crypto recovery company.At first i was very scared because then i was afraid because of the bad experience i had ..Three months ago i decided to contact {Assets lab} and I made my complain to them and they took some information and assured me that they will assist me recover my crypto .. They helped me throughout the process and so far so good they have recovered 95 % of the money that was stolen from me..Today am a happy woman and i will continue to spread the good news.. Contact {Assets lab} for any of your funds lost to scams.. They are the best..Below is their contact informaation Name : ASSETS LAB RECOVERYEmail: [email protected] / Whatsapp: +17126004729Telegram: @Assets_labWebsite: https://lab-assets.tech/
  • Xdqwerty @ Xdqwerty:
    Reported
  • K3Nv2 @ K3Nv2:
    Mario kart 8s been out ten years now due for a 9 any time soon
    +1
  • DTApple @ DTApple:
    Maybe in the upcoming Direct?
  • K3Nv2 @ K3Nv2:
    Probably saving it for a switch 2 announcement
    +2
  • DTApple @ DTApple:
    Ay!
    +1
  • Xdqwerty @ Xdqwerty:
    @DTApple, gonna download the gdevelop app cuz sometimes i don't have the chance to use my pc
  • Xdqwerty @ Xdqwerty:
    And I also got an idea for another game
    Xdqwerty @ Xdqwerty: And I also got an idea for another game