Nereba Exploit: Reboot to Fusée Gelée payload from stock firmware.

nintendo-switch-homebrew-launcher.jpg

Stuckpixel of the ReSwitched team recently released his exploit "Nereba".


This exploit will enable Nintendo Switch owners with early units that have held off updating, still on the original 1.0.0 firmware to reboot into a Fusée Gelée payload without any dongle, USB connections to a external device or jig directly from stock untouched firmware. In addition support for 2.x and 3.x firmware is also planned in the future, opening up the exploit to significantly more consoles.

The implementation takes advantage of the nspwn exploit, that users of the original 3.0.0 homebrew implementation will be familiar with. Used in conjunction with this, users will be able to boot any Fusee Gelee payload from the micro SD card, placed in the nereba folder on the root of the SD card. After running the script from the Switch web applet, users can reboot into any payload by launching the album applet from the home menu.

Download:


https://github.com/pixel-stuck/nereba/releases
 
Last edited by RattletraPM, , Reason: Center image to follow news formatting

tjok3000

Well-Known Member
Newcomer
Joined
Oct 3, 2016
Messages
57
Trophies
0
Age
55
XP
215
Country
Belgium
Is for a switch with firmware 1.0.0, the Nereba exploit with help from pc on wifi, and with atmosphere with emu for higher firmware as for now the best option?
Or i'm curious are there also other developments going on for 1.0.0?
 

snoofly

Well-Known Member
Member
Joined
Aug 18, 2015
Messages
1,012
Trophies
0
Age
54
XP
2,133
Country
United Kingdom
Is for a switch with firmware 1.0.0, the Nereba exploit with help from pc on wifi, and with atmosphere with emu for higher firmware as for now the best option?
Or i'm curious are there also other developments going on for 1.0.0?
On my 1.0.0 I boot into stock 1.0 OFW then run fake news to access Pegascape DNS in order to run nereba to load SX OS payload (or Atmosphere whatever) into emunand on 8.1.
It sounds long winded but really only takes a few seconds.
So as long as the Pegascape DNS is up you've basically got a method to boot to 8.1 emunand direct from OFW.
I host Pegascape locally as well and use my PC as second DNS entry in case Pega is down but it never has been.
Outside of a modchip/trinket, I think this is the only way to enable CFW from Stock OFW without need of a PC or other cables/dongles etc.
 
  • Like
Reactions: tjok3000

tjok3000

Well-Known Member
Newcomer
Joined
Oct 3, 2016
Messages
57
Trophies
0
Age
55
XP
215
Country
Belgium
That sounds like a very nice solution. So the only thing is a wifi to internet or a pc as a backuphost to Pegascape is needed I understand.

Do you know if Pegascape is also hostable on for example an android phone?
For my ps4 i got some sort of a Pegascape, but I can trigger it with an old android phone.
 

snoofly

Well-Known Member
Member
Joined
Aug 18, 2015
Messages
1,012
Trophies
0
Age
54
XP
2,133
Country
United Kingdom
Sorry, I'm not sure, I expect so but I've never tried it.
I use a ESP8266 for my PS4 and I think you can go that route also with Pegascape so I expect you can also use an Android phone as well
but https://gbatemp.net/threads/pegaswi...witch-4-1-using-esp8266-chip-possible.542740/ maybe a place to enquire?
I guess 99.99% of time the Pega DNS is available and you can hotspot to it thru your phone if you have no wifi so it's not something I looked into.
 
  • Like
Reactions: tjok3000

tjok3000

Well-Known Member
Newcomer
Joined
Oct 3, 2016
Messages
57
Trophies
0
Age
55
XP
215
Country
Belgium
I don't have that chip, maybe I get one. It looks like a cool thing to try with that ESp8266 chip!
A hotspot with the phone is also a nice solution if I want to enable when away from home.
 

snoofly

Well-Known Member
Member
Joined
Aug 18, 2015
Messages
1,012
Trophies
0
Age
54
XP
2,133
Country
United Kingdom
I don't have that chip, maybe I get one. It looks like a cool thing to try with that ESp8266 chip!
A hotspot with the phone is also a nice solution if I want to enable when away from home.
Yeah, I tried the hotspot and connected the switch to that and it worked fine, that was my only concern - if I had no wifi.
And sure, get a couple of ESP8266s - they're handy little things. I have one hanging off my 5.05 ps4 with Leeful exploit flashed to it
https://gbatemp.net/threads/release...st-and-esp-devices.534441/page-5#post-8743282
 

modern

Member
Newcomer
Joined
Jul 4, 2018
Messages
7
Trophies
0
Age
34
XP
109
Country
Brazil
I read thru the thread and am a bit confused.... is this a semi cold boot exploit?

I have a switch without any burnt fuses so I can go back to 1.0.0 I used puyo to hack my switch so redo that with this exploit. Then I reupgrade with Choidoujour to 8.1.0? Without auto rcm wouldn’t switch burn fuses? Do I use that emu thing to have 1.0.0 stock and Cfw 81.0?

Edit so I read back 5 posts and seems I need to run pegaswitch each time so seems for now using a pc to drop payload is easier for now
 
Last edited by modern,

snoofly

Well-Known Member
Member
Joined
Aug 18, 2015
Messages
1,012
Trophies
0
Age
54
XP
2,133
Country
United Kingdom
I read thru the thread and am a bit confused.... is this a semi cold boot exploit?

I have a switch without any burnt fuses so I can go back to 1.0.0 I used puyo to hack my switch so redo that with this exploit. Then I reupgrade with Choidoujour to 8.1.0? Without auto rcm wouldn’t switch burn fuses? Do I use that emu thing to have 1.0.0 stock and Cfw 81.0?

Edit so I read back 5 posts and seems I need to run pegaswitch each time so seems for now using a pc to drop payload is easier for now
you do mostly what you said but create an emunand and upgrade that via choi to 8.1.
You don’t touch your sys firm at all, that stays at 1.0 for the purpose of launching nereba via pegascape
and you don’t need rcm as you’ll always only boot to 1.0 so you won’t burn anything
You don’t need pc cables or dongles, just wifi or hotspot

of course all this assumes you are sure you haven’t burnt any fuses at all else you won’t be able to boot to stock 1.0 so double check that
 
Last edited by snoofly,

renegade2k82

Well-Known Member
Member
Joined
Oct 1, 2016
Messages
102
Trophies
0
XP
256
Country
United States
When i click the nebra icon from pegascape i always get a error and tells me to shut down.so how do i fix this?i have the pegafolder and the files from the pegascape site.
 

renegade2k82

Well-Known Member
Member
Joined
Oct 1, 2016
Messages
102
Trophies
0
XP
256
Country
United States
Also i got past the error screen by renaming the latest hekate payload nereba.bin and put it in the nereba folder but i was able to boot to hekate from pegascape once now everytime i try to do that when my switch reboots the screen just flickers black.
 

BaamAlex

UDE GA NARU ZE!
Member
Joined
Jul 23, 2018
Messages
6,061
Trophies
1
Age
29
Location
Lampukistan
Website
hmpg.net
XP
6,174
Country
Germany
Also i got past the error screen by renaming the latest hekate payload nereba.bin and put it in the nereba folder but i was able to boot to hekate from pegascape once now everytime i try to do that when my switch reboots the screen just flickers black.
Why don't you use fusee gelee? Much more convenient :)
 

snoofly

Well-Known Member
Member
Joined
Aug 18, 2015
Messages
1,012
Trophies
0
Age
54
XP
2,133
Country
United Kingdom
Why don't you use fusee gelee? Much more convenient :)
For 1.0 users, nereba provides an untethered payload injection.
Unless things have changed and I’m out of the loop I thought best you could do for untethered with FG is a trinket, failing that you’re lugging a dongle or cable around for a reboot
 

renegade2k82

Well-Known Member
Member
Joined
Oct 1, 2016
Messages
102
Trophies
0
XP
256
Country
United States
yeah i got it working now i just used a older version of hekate and have 2 separate sd cards 1 fat32 to load into pegascape and inject the payload and the other exfat one to swap out to in hekate to load my emummc with latest firmware.i defiantly rather swap sd cards then have to be tethered or have to use a jig and carry that stuff around.like snoofly said its much more convenient with 1.0 compared to fusee gelee.
 

snoofly

Well-Known Member
Member
Joined
Aug 18, 2015
Messages
1,012
Trophies
0
Age
54
XP
2,133
Country
United Kingdom
yeah i got it working now i just used a older version of hekate and have 2 separate sd cards 1 fat32 to load into pegascape and inject the payload and the other exfat one to swap out to in hekate to load my emummc with latest firmware.i defiantly rather swap sd cards then have to be tethered or have to use a jig and carry that stuff around.like snoofly said its much more convenient with 1.0 compared to fusee gelee.
Glad you got it working but not sure why you need to swap sd cards.
I’m running the pega/nereba/emummc setup on my 1.0 switch with just the one fat32 sd card.
I’d be very wary swapping in and out sd cards, that microsd socket is very flimsy and broke on one of mine.
 

petspeed

Well-Known Member
Member
Joined
Nov 13, 2009
Messages
1,134
Trophies
1
Age
49
XP
1,744
Country
Denmark
yeah i got it working now i just used a older version of hekate and have 2 separate sd cards 1 fat32 to load into pegascape and inject the payload and the other exfat one to swap out to in hekate to load my emummc with latest firmware.i defiantly rather swap sd cards then have to be tethered or have to use a jig and carry that stuff around.like snoofly said its much more convenient with 1.0 compared to fusee gelee.
Firmware 1.0.0 doesn't support exfat. If you reformat your exfat SD card to FAT32 I bet it will work fine with just one SD card.
 

gbadl

Well-Known Member
Member
Joined
Sep 13, 2009
Messages
199
Trophies
1
XP
554
Country
Hopefully researched can use this to figure out if something can be modified in patches OFW up to current versions.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • SylverReZ @ SylverReZ:
    Ninty can still make money filing false DMCAs.
    +1
  • realtimesave @ realtimesave:
    they need to have a strong line up on the launch titles too. I think they should move metroid prime 4 to the next console because by now it has been quite a while and there's no release date scheduled yet
  • realtimesave @ realtimesave:
    lol there's a guy selling mig switch in usa on ebay for $200/ea he's definitely going to get nailed with dmca by tomorrow
  • ZeroT21 @ ZeroT21:
    Wasn't Metroid Prime 4 teased all the way back in 2017? For the switch no less?
    :rofl2:
  • ZeroT21 @ ZeroT21:
    Pretty sure anyone buying the switch just for that got duped
  • realtimesave @ realtimesave:
    for $200? rofl.
  • realtimesave @ realtimesave:
    well as far as metroid prime 4 is concerned, the next system probably is similar enough to the current gen they can probably easily just slap it onto a next gen cart and call it good :P
  • K3Nv2 @ K3Nv2:
    The switch was about 350 in 2017
  • Metoroid0 @ Metoroid0:
    mabe where you live
  • K3Nv2 @ K3Nv2:
    Nintendo president Tatsumi Kimishima took the stage at the outset to reveal that Switch will launch globally on March 3, 2017 for $299.99—earlier than some had expected at the price many suspected. https://time.com/4632820/nintendo-switch-nx/
  • Psionic Roshambo @ Psionic Roshambo:
    The NES launched at like 250 and the rob and light gun kit was like 350 or something
  • Psionic Roshambo @ Psionic Roshambo:
    I was near the test market for the NES and man did it make my 2600 look like ass lol
  • K3Nv2 @ K3Nv2:
    There has to be some mutual agreement with them all anything over $600 is just pc territory
  • realtimesave @ realtimesave:
    next system rumored to launch at $400
  • realtimesave @ realtimesave:
    but I don't really believe any rumors yet
  • realtimesave @ realtimesave:
    need to have official info from N
  • Psionic Roshambo @ Psionic Roshambo:
    The 3DO and Neo Geo where like 700 bucks hmm the PS3 was stupid expensive at launch lol
  • Psionic Roshambo @ Psionic Roshambo:
    But at least the PS3 was only 500 for the cheapest one at launch
  • Psionic Roshambo @ Psionic Roshambo:
    My opinion is that 199.99 is the sweet spot but that spot is long gone lol
  • Psionic Roshambo @ Psionic Roshambo:
    Just played some Micheal Jackson Moonwalker.... Those poor parents trying desperately to protect their children
  • K3Nv2 @ K3Nv2:
    400 is a decent sweet spot if we get enough out of it
  • K3Nv2 @ K3Nv2:
    It's not like how it was when we were locked down to a few options and that's it
  • Psionic Roshambo @ Psionic Roshambo:
    For me just buying a Pi and some accessories fills that not a PC void new consoles have just put them close to PC prices and all the patching and updates makes me feel like I might as well just get a PC
    Psionic Roshambo @ Psionic Roshambo: For me just buying a Pi and some accessories fills that not a PC void new consoles have just put...