Hacking [FAQ] Smhax - Should I update?

kumikochan

Well-Known Member
Member
Joined
Feb 4, 2015
Messages
3,753
Trophies
0
Age
36
Location
Tongeren
XP
3,311
Country
Belgium
They also say not to expect a public hack for at least 12 months, am i right?
do what you want. it's Always the same, people telling people not to update and what do people do ? They update and then they come nag and whine on this forum that they didn't listen
 

Thirty3Three

Musician Member
OP
Banned
Joined
Mar 22, 2013
Messages
3,956
Trophies
0
Location
Wherever you want me, baby.
XP
2,605
Country
United States
do what you want. it's Always the same, people telling people not to update and what do people do ? They update and then they come nag and whine on this forum that they didn't listen
He's just being salty trying to justify his act of updating. He's taking it out on others saying they should too. It's a psychological coping mechanism.
 

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
If your basis of waiting or not waiting is one actual user-friendly usability this year or, likely, next (and/or fools promises of gateway-like piracy which you may as well consider a scam at this time). Then I'd recommend not waiting around with a glorified lamp.

If your basis of waiting or not waiting is that you want tools with which to work and make stuff in this or next year? Wait. Tools will slowly roll out over time and you will be able to get your hands on them. If you plan on being involved with development or mucking around with kernel and firmware, I would recommend having multiple Switches.

There are a good few traps in this system that can either brick your system or throw into an inoperable panic. The rarity of Switch units under 3.0.0 is going to be a pain in the as in the long term if newer exploits are not found.

Be aware that most tools will remains hidden or obscured for some time due to HackerOne, and scene behind-the-curtain drama. HackerOne will forever stifle the speed at which anything hits 'public' availability because if you know about it, its very likely Nintendo already knows about it. You don't want your vulnerabilities being catalogued carte blanch for Nintendo because someone couldn't keep their mouth shut.
 
Last edited by V-Temp,

magico29

Well-Known Member
Member
Joined
Aug 2, 2017
Messages
1,586
Trophies
0
XP
1,895
Country
United States
[I know this is a little messy right now, not too presentable. But it has solid information. I'm just crunched on time. I'll update it when I can to make it more presentable]


[Requesting Sticky]
update for online access and get a spare switch for future hacks
I've seen this question way too many times, threads started, asking the same question, etc. Well I'm here to (hopefully) help avoid... this...
sBpPy9u.png



So first off, what is Smhax?

smhax is the informal name of a vulnerability discovered by multiple hackers on the Nintendo Switch. The bug, when fully exploited, appears to be a privilege escalation which allows the attacker to register and run arbitrary services on the console. Specifically, according to the switchbrew wiki:

"Prior to 3.0.1, the service manager (sm) built-in system module treats a user as though it has full permissions if the user creates a new “sm:” port session but bypasses initialization. This is due to the other sm commands skipping the service ACL check for Pids <= 7 (i.e. all kernel bundled modules) and that skipping the initialization command leaves the Pid field uninitialized. Successful exploitation results in Acquisition, registering, and unregistering of arbitrary services"

In other words, coupled with a userland entry point (typically a webkit vulnerability), this could probably be used to gain full access to the console.

[Credit for the paragraph above, goes to Wololo, of Wololo.net. I copy and pasted]

The exploit works on ALL firmware PRIOR to 3.01. So as long as you're below 3.01, you're fine, and good to go.




So guys, now you know what it is... should you update to 3.01?

ultimately? It's up to you. But here are the pros and cons:


If you update:
-Online access (games, eshop, etc.)
-Play the most recent games which require the more recent firmware(s)
-No access to the exploit, when it releases for the common user.

If you don't update:
-No online whatsoever
-Access to the exploit, in time.


Ultimately? It's up to you.
Devs say not to update.


THERE IS NO GUARANTEE THAT ANOTHER EXPLOIT WILL BE RELEASED. EVER. YOU WILL BE TAKING A RISK IF YOU UPDATE... DO NOT LISTEN TO ANYONE WHO TELLS YOU AN EXPLOIT WILL COME IN TIME.


I know this is a messy FAQ right now, I'm sort of crunched for time. I'll edit it when I can to make it more... presentable... I will add dev quotes, recommendations, etc.


In the meantime, if you have any questions or comments you'd like me to add to the faq, let me know.
 

magico29

Well-Known Member
Member
Joined
Aug 2, 2017
Messages
1,586
Trophies
0
XP
1,895
Country
United States
[I know this is a little messy right now, not too presentable. But it has solid information. I'm just crunched on time. I'll update it when I can to make it more presentable]


[Requesting Sticky]
update for online access and get a spare switch for future hacks
I've seen this question way too many times, threads started, asking the same question, etc. Well I'm here to (hopefully) help avoid... this...
sBpPy9u.png



So first off, what is Smhax?

smhax is the informal name of a vulnerability discovered by multiple hackers on the Nintendo Switch. The bug, when fully exploited, appears to be a privilege escalation which allows the attacker to register and run arbitrary services on the console. Specifically, according to the switchbrew wiki:

"Prior to 3.0.1, the service manager (sm) built-in system module treats a user as though it has full permissions if the user creates a new “sm:” port session but bypasses initialization. This is due to the other sm commands skipping the service ACL check for Pids <= 7 (i.e. all kernel bundled modules) and that skipping the initialization command leaves the Pid field uninitialized. Successful exploitation results in Acquisition, registering, and unregistering of arbitrary services"

In other words, coupled with a userland entry point (typically a webkit vulnerability), this could probably be used to gain full access to the console.

[Credit for the paragraph above, goes to Wololo, of Wololo.net. I copy and pasted]

The exploit works on ALL firmware PRIOR to 3.01. So as long as you're below 3.01, you're fine, and good to go.




So guys, now you know what it is... should you update to 3.01?

ultimately? It's up to you. But here are the pros and cons:


If you update:
-Online access (games, eshop, etc.)
-Play the most recent games which require the more recent firmware(s)
-No access to the exploit, when it releases for the common user.

If you don't update:
-No online whatsoever
-Access to the exploit, in time.


Ultimately? It's up to you.
Devs say not to update.


THERE IS NO GUARANTEE THAT ANOTHER EXPLOIT WILL BE RELEASED. EVER. YOU WILL BE TAKING A RISK IF YOU UPDATE... DO NOT LISTEN TO ANYONE WHO TELLS YOU AN EXPLOIT WILL COME IN TIME.


I know this is a messy FAQ right now, I'm sort of crunched for time. I'll edit it when I can to make it more... presentable... I will add dev quotes, recommendations, etc.


In the meantime, if you have any questions or comments you'd like me to add to the faq, let me know.
 

Risingdawn

Tempallica
Member
Joined
May 22, 2010
Messages
1,088
Trophies
1
XP
1,700
Country
United Kingdom
Did you buy your Switch to play Switch games, eshop and/or online= Update.

Did you buy your Switch to play homebrew and emulators= Don't update and be prepared for potentially a long wait.

Did you buy your Switch to do both= choose Either update and hope for a future exploit (new games, eshop and online is more important than homebrew)
Or
Don't update and hope for a way to spoof fw version for new games (could never happen but homebrew is more important)
 
  • Like
Reactions: TotalInsanity4

leonmagnus99

Well-Known Member
Member
Joined
Apr 2, 2013
Messages
3,704
Trophies
2
Age
33
Location
Seinegald
XP
2,875
Country
Iraq
okay guys, since i already updated couple weeks ago i'd like to know whether it is worth it to sell my current switch (3.0.1) to buy one on a lower fw.

i am quite interested in homebrew, i love hax.
i would love to have a cfw where i can use custom themes ,overclocking cpu and some video player/a browser etc.

i believe this will get stuck with 3.0.0 like ps3 with 3.55, and thus i am thinking about selling mine these days but i have not come to a conclusion.

should i sell my current switch and get a new one ?
 

mendezagus

Well-Known Member
Member
Joined
Aug 29, 2017
Messages
159
Trophies
0
Age
44
XP
423
Country
Argentina
He's just being salty trying to justify his act of updating. He's taking it out on others saying they should too. It's a psychological coping mechanism.

Why do we have to attack each other? If the "being salty" was directed to me i repeat: i was jus trying to confirm if the hacker SciresM said not to expect a public hack for at least 12 months. I didn´t update, i don´t even own a game yet.
 
  • Like
Reactions: Carlos_DobleC

TheCyberQuake

Certified Geek
Member
Joined
Dec 2, 2014
Messages
5,012
Trophies
1
Age
28
Location
Las Vegas, Nevada
XP
4,432
Country
United States
Why do we have to attack each other? If the "being salty" was directed to me i repeat: i was jus trying to confirm if the hacker SciresM said not to expect a public hack for at least 12 months. I didn´t update, i don´t even own a game yet.
I don't think any of the devs said when to or not to expect homebrew
 

Miles54321

Well-Known Member
Member
Joined
Dec 16, 2010
Messages
905
Trophies
0
Location
Gateway Headquarters with SonyUSA
Website
derbergerac.com
XP
486
Country
You've guess right xD

Wise move, the truth is we have no idea when we are going to get homebrew but it is always soon, I thought of 3ds scenes SOON tm and ti was long however
when you look back it is ALWAYS worth the wait, the switch is one of the fastest hacked systems so....No POINT IN updating now!
 
  • Like
Reactions: Baoulettes

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    I @ idonthave: :)