Hacking Early Switch model - Black Screen on payload injection (Linux)

Deleted member 669151

New Member
OP
Newbie
Joined
Aug 18, 2023
Messages
2
Trophies
0
XP
27
I have a Nintendo Switch with a serial # of less than XAW1001 (in the XAW10009 range precisely). I wanted to see if it was actually hackable before going out to get a larger microSD card, but after injecting the payload with fusee-launcher (the Tk interface running as root) I get a black screen. I have tried two payloads, TegraExplorer and a fusee-test payload. The firmware of this Switch is currently at 11.0.1. I tried to find an earlier version of TegraExplorer that was made for 11.0.1 but this didn't work either. I get the following output across any payload:

Code:
Important note: on desktop Linux systems, we currently require an XHCI host controller. A good way to ensure you're likely using an XHCI backend is to plug your device into a blue 'USB 3' port. 

Identified a Linux system; setting up the appropriate backend.

Found a Tegra with Device ID: [ Redacted for privacy ]

Setting ourselves up to smash the stack...
Uploading payload...
Smashing the stack...
skipping checks
The USB device stopped responding-- sure smells like we've smashed its stack. :)
Launch complete!

I've ensured I am using USB3 because the cable that I'm using, which is the one for the Switch Pro Controller, is plugged into the blue USB port. lsmod shows me that XHCI is indeed being used, and the Injector GUI recognizes the Switch when it is in RCM mode (otherwise the button to inject payload cannot be pressed).

I suppose it can't be hacked, but with such a low serial # and that the site for checking the serial number shows me that mine is in the green, it begs the question of am I doing something wrong? I am using aluminum foil taped to the two farthest back pins to access RCM. I've tried inserting the only microSD card I have (which is 32 GB) formatted with FAT32 to see if it makes a difference, which it doesn't. Is there a certain step in this process that I'm missing or am I just unlucky and have an early patched Switch?
 

Ryab

Well-Known Member
Member
Joined
Aug 9, 2017
Messages
3,286
Trophies
1
XP
4,562
Country
United States
I have a Nintendo Switch with a serial # of less than XAW1001 (in the XAW10009 range precisely). I wanted to see if it was actually hackable before going out to get a larger microSD card, but after injecting the payload with fusee-launcher (the Tk interface running as root) I get a black screen. I have tried two payloads, TegraExplorer and a fusee-test payload. The firmware of this Switch is currently at 11.0.1. I tried to find an earlier version of TegraExplorer that was made for 11.0.1 but this didn't work either. I get the following output across any payload:

Code:
Important note: on desktop Linux systems, we currently require an XHCI host controller. A good way to ensure you're likely using an XHCI backend is to plug your device into a blue 'USB 3' port.

Identified a Linux system; setting up the appropriate backend.

Found a Tegra with Device ID: [ Redacted for privacy ]

Setting ourselves up to smash the stack...
Uploading payload...
Smashing the stack...
skipping checks
The USB device stopped responding-- sure smells like we've smashed its stack. :)
Launch complete!

I've ensured I am using USB3 because the cable that I'm using, which is the one for the Switch Pro Controller, is plugged into the blue USB port. lsmod shows me that XHCI is indeed being used, and the Injector GUI recognizes the Switch when it is in RCM mode (otherwise the button to inject payload cannot be pressed).

I suppose it can't be hacked, but with such a low serial # and that the site for checking the serial number shows me that mine is in the green, it begs the question of am I doing something wrong? I am using aluminum foil taped to the two farthest back pins to access RCM. I've tried inserting the only microSD card I have (which is 32 GB) formatted with FAT32 to see if it makes a difference, which it doesn't. Is there a certain step in this process that I'm missing or am I just unlucky and have an early patched Switch?
Deleted
 
Last edited by Ryab,

Hayato213

Newcomer
Member
Joined
Dec 26, 2015
Messages
20,104
Trophies
1
XP
21,320
Country
United States
If you use something like TegraRCMhgui it will specify if the system is in RCM mode. If the system says it is in RCM mode then it 100% is a hackable system. Also make sure you have installed the proper driver for it. If you have not I know that TegraRCMGui does have the installer built in.

Patched unit can enter RCM mode too, just that they don't accept payload.
 

masagrator

The patches guy
Developer
Joined
Oct 14, 2018
Messages
6,332
Trophies
3
XP
12,175
Country
Poland
It's easier to confirm that with TegraRCMGui as it returns how many bytes it "smashed".

If it's 0x0000, it's patched. If it's 0x7000, it's not patched. Payload may not work for other reasons than unit being patched, so this is definitive way to check if Switch is patched.
 

Deleted member 669151

New Member
OP
Newbie
Joined
Aug 18, 2023
Messages
2
Trophies
0
XP
27
It's easier to confirm that with TegraRCMGui as it returns how many bytes it "smashed".
Sadly TegraRCMGui doesn't work on Linux. So far the only injectors I know that work would be fusee-launcher and any frontends to it like the Tk one I used since its written in Python.
Post automatically merged:

Holy cow, JTegraNX works! TegraExplorer successfully appears on screen

My suggestion for Linux users, use JTegraNX. :)
 
Last edited by Deleted member 669151,

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • K3Nv2 @ K3Nv2:
    @Veho, where's the poll at?
  • Julie_Pilgrim @ Julie_Pilgrim:
    they're giving the internet an open text box?
  • BigOnYa @ BigOnYa:
    I never played or own any of they devices, but I like small style, but with a somewhat grip
  • Julie_Pilgrim @ Julie_Pilgrim:
    oh man, that always goes great!
  • Julie_Pilgrim @ Julie_Pilgrim:
    im sure half the responses won't be literal racial slurs or "drop table" jokes
  • Veho @ Veho:
    Look, it's China. They know what it's like when you give a poll to half a billion trolls.
  • K3Nv2 @ K3Nv2:
    How much dollar do you think it is?
  • Veho @ Veho:
    ONE MILLION DOLLA
  • Veho @ Veho:
    I know the pricing of electronics nowadays isn't "how much it actually costs" but "how much we can get away with", but putting up a poll is just cynical.
  • K3Nv2 @ K3Nv2:
    Probably $150 someone said Anbernic said around the same price as rg556
  • Julie_Pilgrim @ Julie_Pilgrim:
    you know which game i wish they would rerelease
  • Julie_Pilgrim @ Julie_Pilgrim:
    sonic unleashed
  • K3Nv2 @ K3Nv2:
    Make it a happy meal toy
  • Julie_Pilgrim @ Julie_Pilgrim:
    that game's engine is really fucking intensive so it runs like literal shit on xbox 360 and ps3
  • Veho @ Veho:
    Nah I'm getting value creep again. I look at a $50 console "but for just a few more dollars you could get XYZ" and I end up considering the Steam Deck.
  • Julie_Pilgrim @ Julie_Pilgrim:
    like the lighting in that game was genuinely so good
  • Veho @ Veho:
    Not getting dragged into that again.
  • Julie_Pilgrim @ Julie_Pilgrim:
    i dont get why they didn't port the one game that ran the worst on consoles, to pc
  • Julie_Pilgrim @ Julie_Pilgrim:
    like you port everything to pc except the one game where it would make the most sense. why. what do you gain from this
  • Julie_Pilgrim @ Julie_Pilgrim:
    is sega just personally fucking with me? are they laughing while watching me through my kinect camera as i get up to restart my xbox for the third time because the game froze again
  • K3Nv2 @ K3Nv2:
    Buy handhelds from five below better quality
  • K3Nv2 @ K3Nv2:
    Valve probably going to do another refresh of the deck this fall with rog ally like specs tbh
  • Veho @ Veho:
    A smaller form factor would be nice too.
  • K3Nv2 @ K3Nv2:
    A shield portable 2 would be nice aye Nvidia
    K3Nv2 @ K3Nv2: A shield portable 2 would be nice aye Nvidia