Hacking Hardware Picofly - a HWFLY switch modchip

jkyoho

Well-Known Member
Member
Joined
Sep 2, 2020
Messages
1,350
Trophies
0
Age
39
Location
TORONTO
Website
form.jotform.com
XP
2,282
Country
Canada
I tried this new AON7524 Vgs=2.5v mosfet on the back of this v2 board, it works with 3x47 ohm rp2040 setup.
Can't say how this mosfet glitch compared to 8342 or normal Vgs=4.5v mosfet yet, I will need some time turning on and off then switch back to 8432 then do the same thing,

Update: using back 8342 with same 0.5mm copper loaded with tin ," ==*" error code/glitch failed. Pretty sure is not soldering issue or lack of D or S solder.
AON7524 gives me averagely glitching around 3.5s (occasionally 5s+), from PSU measured it draws [email protected] when glitching and successes at [email protected] when picofly logo shows(bare board, you get the idea).
 

Attachments

  • PXL_20230714_183942795.mp4
    36.2 MB
  • 1689375396629.png
    1689375396629.png
    2.5 MB · Views: 43
Last edited by jkyoho,

roxzii

Well-Known Member
Newcomer
Joined
Nov 11, 2022
Messages
47
Trophies
0
Age
27
XP
251
Country
Portugal
Yes, rename Lockpick to payload and see if you could run
Post automatically merged:


No, I dont think boot0/1 can be mount on those software,I confirm error is normal.
Post automatically merged:

https://switch.homebrew.guide/usingcfw/manualchoiupgrade.html

this guide here show how etcher can overwire Boot0/1, you just skip the hekate part and do the ums-loader way to mount the partition you want to rebuild
Okay, I forgot to reply to this, sorry. No, Lockipck won't run, just ums-loader, so no prod.keys. I'm going to search for a way to build a boot0/1 and try to flash with etcher, but not sure if there's any way to do that without prod.keys. If anyone knew about this, help would be appreciated.

But I also don't think that will solve the overall problem.
I have cut the lobe from de dat0 adapter and tried to place it as far drom dat1 as possible, but NX Nand Manager still can't read boot 0 and boot 1 (GPP works perfectly). I'm going to assume that's because the partitions have already been corrupted and can't be read even if dat0/1 isn't shorting anymore and try this.

But I also think the result will be the same and this is somehow RAM related, since even with short and boot0/1 corruption hekate should still launch.
 

jkyoho

Well-Known Member
Member
Joined
Sep 2, 2020
Messages
1,350
Trophies
0
Age
39
Location
TORONTO
Website
form.jotform.com
XP
2,282
Country
Canada
Okay, I forgot to reply to this, sorry. No, Lockipck won't run, just ums-loader, so no prod.keys. I'm going to search for a way to build a boot0/1 and try to flash with etcher, but not sure if there's any way to do that without prod.keys. If anyone knew about this, help would be appreciated.

But I also don't think that will solve the overall problem.
I have cut the lobe from de dat0 adapter and tried to place it as far drom dat1 as possible, but NX Nand Manager still can't read boot 0 and boot 1 (GPP works perfectly). I'm going to assume that's because the partitions have already been corrupted and can't be read even if dat0/1 isn't shorting anymore and try this.

But I also think the result will be the same and this is somehow RAM related, since even with short and boot0/1 corruption hekate should still launch.
Very true, myself only seen once Blue screen when booting into OFW after picofly installed back to v2.5x FW I believe. And I was able to go into maintenance mode update OFW through wifi. At that time Hekate definitely running ok.

FYI, I remember Boot0/1 can be shared as long as on same OFW
 
  • Like
Reactions: roxzii

roxzii

Well-Known Member
Newcomer
Joined
Nov 11, 2022
Messages
47
Trophies
0
Age
27
XP
251
Country
Portugal
Very true, myself only seen once Blue screen when booting into OFW after picofly installed back to v2.5x FW I believe. And I was able to go into maintenance mode update OFW through wifi. At that time Hekate definitely running ok.

FYI, I remember Boot0/1 can be shared as long as on same OFW
Even between Erista and Mariko? I have an unpatched switch and I never use it online. Because by luck they are both on 16.0.3. Would flashing that boot0/1 work? (Also, I have AutoRCM in my unpatched switch, I assume I would need to turn it off before the backup of boot0.)
 

abal1000x

Well-Known Member
Member
Joined
Jun 5, 2022
Messages
1,070
Trophies
0
XP
1,417
Country
Gaza Strip
So I say low melt is not good for MOSFET soldering?
i think its good.

i dont meet a problem using low melt on mosfet.
Post automatically merged:

Wooow,
actually soldering the wrong capacitor. But now I switched to the right capacitor and the same error code continued.
Will it never work? I am sad.

Error code ==*

See images bellow.

Thaaaanks!
photo_5012639173223492804_y.jpg
For enameled wire this could lead to problem. That sharp edge easily ripped the enameled off hence make short with pin no 14.
 
Last edited by abal1000x,
  • Like
Reactions: QuiTim and Dee87

Seco_Gobbo2

Member
Newcomer
Joined
Jul 6, 2023
Messages
15
Trophies
0
Age
35
XP
272
Country
Brazil
Hello everybody.

I had a lot of work so it took me a while to give a feedback here.

Thanks for the information, I apologize if my questions were bothersome and silly, I managed to install picofly with just one mosfet (irh8342) on the back of my switch model V1 and it is working perfectly.

I used a very thin double-sided tape to fix the mosfet on the board to help solder and also avoid any future problem of the solder breaking due to impact, I also used UV mask to protect, isolate and better fix the wires and solders. It wasn't as pretty as I had hoped, but it was pretty safe.

I'm going to leave pictures of how my work turned out, I hope it can help others, I'm also going to leave picofly's "flash-nuke", I had trouble finding it, I think it's interesting to share.

Again, thanks to everyone who replied.
 

Attachments

  • IMG_20230710_154058.jpg
    IMG_20230710_154058.jpg
    2 MB · Views: 40
  • IMG_20230710_155238.jpg
    IMG_20230710_155238.jpg
    2.2 MB · Views: 41
  • IMG_20230710_164533.jpg
    IMG_20230710_164533.jpg
    2.6 MB · Views: 49
  • IMG_20230710_201233.jpg
    IMG_20230710_201233.jpg
    3.5 MB · Views: 44
  • IMG_20230710_201310.jpg
    IMG_20230710_201310.jpg
    2.5 MB · Views: 40
  • IMG_20230710_230148.jpg
    IMG_20230710_230148.jpg
    2.8 MB · Views: 36
  • IMG_20230710_233829.jpg
    IMG_20230710_233829.jpg
    3 MB · Views: 37
  • IMG_20230711_000014.jpg
    IMG_20230711_000014.jpg
    2.7 MB · Views: 34
  • IMG_20230711_000203.jpg
    IMG_20230711_000203.jpg
    3 MB · Views: 35
  • IMG_20230711_014123.jpg
    IMG_20230711_014123.jpg
    2.5 MB · Views: 38
  • IMG_20230711_022823.jpg
    IMG_20230711_022823.jpg
    2.9 MB · Views: 38
  • VID_20230714_230902.mp4
    31.6 MB
  • flash_nuke.rar
    8.3 KB · Views: 16

raksmey1231

Active Member
Newcomer
Joined
May 13, 2023
Messages
33
Trophies
0
XP
289
Country
Cambodia
Hello everyone, I broke my switch oled screen connector. is there any hope to repair this? :cry:
 

Attachments

  • 215c00fd-c217-4a4d-adae-7f5084bef650.jpg
    215c00fd-c217-4a4d-adae-7f5084bef650.jpg
    249.9 KB · Views: 35

Seco_Gobbo2

Member
Newcomer
Joined
Jul 6, 2023
Messages
15
Trophies
0
Age
35
XP
272
Country
Brazil
I have lost 5 of the pads on the motherboard
I can't say for sure by the photo, but they look like pads that don't have a connection in the circuit. Maybe just soldering a new connector will do the trick.
But like I said, you can't be sure from the picture.
Post automatically merged:

Ohh I'll try when the connector arrives. Thank you
Using an aluminum tape to protect the connector, a medium air flow and the temperature between 350 to 400°C, you will be able to solder from the top. But it requires some practice with the hot air station to not damage the new connector.
 
Last edited by Seco_Gobbo2,

Danook28

Well-Known Member
Member
Joined
Jul 17, 2018
Messages
506
Trophies
0
Age
34
XP
1,068
Country
Oman
Hello everybody.

I had a lot of work so it took me a while to give a feedback here.

Thanks for the information, I apologize if my questions were bothersome and silly, I managed to install picofly with just one mosfet (irh8342) on the back of my switch model V1 and it is working perfectly.

I used a very thin double-sided tape to fix the mosfet on the board to help solder and also avoid any future problem of the solder breaking due to impact, I also used UV mask to protect, isolate and better fix the wires and solders. It wasn't as pretty as I had hoped, but it was pretty safe.

I'm going to leave pictures of how my work turned out, I hope it can help others, I'm also going to leave picofly's "flash-nuke", I had trouble finding it, I think it's interesting to share.

Again, thanks to everyone who replied.
GND 3v3 wier type?????
 

twins333

Well-Known Member
Newcomer
Joined
May 30, 2023
Messages
86
Trophies
0
XP
335
Country
Afghanistan
Hi

Is this for use with Picofly ?
Hi. From the comments it looks like they work with the picofly. For more info on the mosfet specs you can check @QuiTim's and @abal1000x's posts here:
.
Post automatically merged:


The AON6554 has only one G terminal the other 3 below it are S so as long as you did not bridge the 3 and 4 together you should be OK as far as wiring goes (see picture).
I am assuming that this is the orientation, so 1st pin bottom right (please check since I cannot see the mark on the mosftet from the picture)
Anyway, I think there is something else at play here.
The mosfets that work (tested by me) example IRF8342 has a total gate charge Qg of 4.2; AON7506 Qg 4.3; AON7518 Qg 6.9; IRF8714 Qg 8.1 while the one you are using AON6554 has the Qg of 21.3
@abal1000x what are your thoughts about this?

I think The mosfet already an okay . The rds is around 3-4mohms which already suitable for the glitch.
I agreed, from the picture i can't confirm wether the 1st pin is the right bottom or left top.

Also because the transistor flipped down, we couldn't solder to the center pad. Its important for the D to be soldered as wide as possible.
 
Last edited by twins333,
  • Like
Reactions: chronoss

RiotRetroGaming

Well-Known Member
Newcomer
Joined
Mar 25, 2023
Messages
60
Trophies
0
Age
43
XP
164
Country
United Kingdom
Ohh I'll try when the connector arrives. Thank you

If you can't do it, send it to me.
Done a few oled connectors now.
People have come to me in emergency via this forum to help.
I'm in Surrey.

Ant
Post automatically merged:

@rehius

Do you have a donation link?
I paid my last months rent off selling chipped Switches... this is the least I can do for your efforts.

:bow:
 
Last edited by RiotRetroGaming,

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    I mean the drug not the booty pervs
    +2
  • linuxares @ linuxares:
    @cearp At a plumber convenstion. Loads of cracks!
    +2
  • K3Nv2 @ K3Nv2:
    A plumber is either on crack or in crack or showcasing crack
    +2
  • cearp @ cearp:
    or of course, dealing with cracks (in pipes)
  • K3Nv2 @ K3Nv2:
    Sure he could be on cracked flooring causing the leak
  • K3Nv2 @ K3Nv2:
    How much you bet delta going to be DRMd to hell and back
  • The Real Jdbye @ The Real Jdbye:
    @linuxares the dev just ends up at 0
  • The Real Jdbye @ The Real Jdbye:
    it's no worse than if you pirated
  • The Real Jdbye @ The Real Jdbye:
    it's probably better, because not all keys on key sites are stolen
  • The Real Jdbye @ The Real Jdbye:
    plus piracy is not always an option
  • The Real Jdbye @ The Real Jdbye:
    i heard a related story for a dev actually
  • The Real Jdbye @ The Real Jdbye:
    from a dev*
  • K3Nv2 @ K3Nv2:
    DRMs are getting stronger these days
  • The Real Jdbye @ The Real Jdbye:
    they bought their own game on a key site and checked where they came from and it turned out they were review copies he had given out by email to someone
  • The Real Jdbye @ The Real Jdbye:
    *all* of them
  • NinStar @ NinStar:
    no storefront I'm aware of (at least on pc) requires the devs to pay for the keys they generate
  • NinStar @ NinStar:
    they don't lose money doing this, even if someone decide to chargeback
  • The Real Jdbye @ The Real Jdbye:
    so that seems to be a pretty common thing, i kinda blame the dev for that one though as they were giving out like 5 keys to someone just because they asked for multiple copies for review for whatever reason and there were multiple people doing this. he should've seen the red flags
  • linuxares @ linuxares:
    @The Real Jdbye Yet devs tell US that they get charged possible charge backs? Its no idea we keep this up since I have to trust the devs more than key reseller sites.
  • linuxares @ linuxares:
    (the chargeback is a penalty fee from the Credit card company, apparently around 30$)
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, i decided to watch serial experiments lain subbed bc the audio in the latin spanish dub is in bad quality (probably bc that anime hasnt been oficially rereleased with that dub)
    Xdqwerty @ Xdqwerty: @SylverReZ, i decided to watch serial experiments lain subbed bc the audio in the latin spanish...