Homebrew Switch Hacking & Homebrew Discussion

mikeg504

Member
Newcomer
Joined
May 27, 2017
Messages
12
Trophies
0
Age
39
XP
64
Country
United States
Exceptions are possible to get controlled regardless of the OS handling it.. There are massive amounts of ways to do global exception handlers even on windows. Lots of applications have it calling MS (for dumping, and presenting information) yet its still exploitable... It looks more like a kernel error handling like Windows has whenever you fuzz font drivers...

I wouldn't say its 'handled...'

--------------------- MERGED ---------------------------

mskernal2.png

get my point? all kernel exploits in windows show blue screens when addressing, and preparation fails... or it overwrites bug check protected memory..

--------------------- MERGED ---------------------------

I will say that I didn't fuzz this specifically.. I came across it by accident, and it is something that I would expect nintendo to have reports of already...so it may not work anyways in the newer versions but im not sure as of now.. ill get some captures and information soon.. I went to sleep shortly after

--------------------- MERGED ---------------------------

Exception pointers are a little after stack.. it looks kernel now that I think about it, but this is why even things that have exception handlers may also be exploited. It is just a little further down in memory (or higher, but you get my point I hope)
igor1_seh3_stack_layout.gif
 

BlastedGuy9905

where's the updated autopsy report
Member
Joined
Apr 13, 2017
Messages
2,334
Trophies
1
Age
33
Location
under your desk
XP
4,043
Country
United States
Exceptions are possible to get controlled regardless of the OS handling it.. There are massive amounts of ways to do global exception handlers even on windows. Lots of applications have it calling MS (for dumping, and presenting information) yet its still exploitable... It looks more like a kernel error handling like Windows has whenever you fuzz font drivers...

I wouldn't say its 'handled...'

--------------------- MERGED ---------------------------

mskernal2.png

get my point? all kernel exploits in windows show blue screens when addressing, and preparation fails... or it overwrites bug check protected memory..

--------------------- MERGED ---------------------------

I will say that I didn't fuzz this specifically.. I came across it by accident, and it is something that I would expect nintendo to have reports of already...so it may not work anyways in the newer versions but im not sure as of now.. ill get some captures and information soon.. I went to sleep shortly after

--------------------- MERGED ---------------------------

Exception pointers are a little after stack.. it looks kernel now that I think about it, but this is why even things that have exception handlers may also be exploited. It is just a little further down in memory (or higher, but you get my point I hope)
igor1_seh3_stack_layout.gif
GG dude, nice job. Keep up the good work, and don't give up.
 
  • Like
Reactions: Tumoche and peteruk
D

Deleted User

Guest
Unless you can prove me wrong I am going to stop this "exploit" hype train right now.

The only ways I know of to run unsigned code on the Switch currently are:
  1. The internet browser. Pegaswitch is quite literally the best thing we have right now (and that's not saying much). It is actually a working crash that allows the user to poke around in RAM. Using the internet browser allows us to send data to the switch. Even if it is just by running a simple video, we could overflow the Switch or something along those lines.
  2. Figure out what the hell is up with the Album. I don't have a lot of time to work around with the Album right now, but the images go through a process that confirms they haven't been tampered with before displaying them. Unless you can bypass this, loading code isn't even feasible.
  3. Have the system load a file from the microSD card. This requires one of the above to work unless you magically find a special file that the Switch reads all the time, and figure out how to replace it.
Guys, I don't want anybody to get hyped for this "exploit" until screenshots are shown or the "developer" cares to show what he is doing publicly. Hell, it was a mistake to even post that screenshot in the thread, because now people like me are going to "discourage" him and tell him to either show us proof or gtfo.

And @mikeg504 I really don't care if you know everything there is to know about hacking or programming. The Switch has its own firmware which you can't grab from it yet.

Please, show us proof or tell everybody to stop hyping about it until you can. Thanks!
 
  • Like
Reactions: peteruk

BlastedGuy9905

where's the updated autopsy report
Member
Joined
Apr 13, 2017
Messages
2,334
Trophies
1
Age
33
Location
under your desk
XP
4,043
Country
United States
Unless you can prove me wrong I am going to stop this "exploit" hype train right now.

The only ways I know of to run unsigned code on the Switch currently are:
  1. The internet browser. Pegaswitch is quite literally the best thing we have right now (and that's not saying much). It is actually a working crash that allows the user to poke around in RAM. Using the internet browser allows us to send data to the switch. Even if it is just by running a simple video, we could overflow the Switch or something along those lines.
  2. Figure out what the hell is up with the Album. I don't have a lot of time to work around with the Album right now, but the images go through a process that confirms they haven't been tampered with before displaying them. Unless you can bypass this, loading code isn't even feasible.
  3. Have the system load a file from the microSD card. This requires one of the above to work unless you magically find a special file that the Switch reads all the time, and figure out how to replace it.
Guys, I don't want anybody to get hyped for this "exploit" until screenshots are shown or the "developer" cares to show what he is doing publicly. Hell, it was a mistake to even post that screenshot in the thread, because now people like me are going to "discourage" him and tell him to either show us proof or gtfo.

And @mikeg504 I really don't care if you know everything there is to know about hacking or programming. The Switch has its own firmware which you can't grab from it yet.

Please, show us proof or tell everybody to stop hyping about it until you can. Thanks!
Hehehe. Since this is a system crash, I'm thinking run PegaSwitch, then somehow make the system crash with this "exploit". Maybe then we could run code.
 
D

Deleted User

Guest
Hehehe. Since this is a system crash, I'm thinking run PegaSwitch, then somehow make the system crash with this "exploit". Maybe then we could run code.
He already stated once that it is something the user might not want to do constantly in order to load the HBL. Also, @mikeg504 chances are just fucking around and getting the system to crash won't get you an exploit. You will actually need it to freeze and black screen because then it is something that can't be handled by the OS. If there is an error code, look it up on support.nintendo.com, because chances are they already know what happens.
 
  • Like
Reactions: TotalInsanity4

BlastedGuy9905

where's the updated autopsy report
Member
Joined
Apr 13, 2017
Messages
2,334
Trophies
1
Age
33
Location
under your desk
XP
4,043
Country
United States
He already stated once that it is something the user might not want to do constantly in order to load the HBL. Also, @mikeg504 chances are just fucking around and getting the system to crash won't get you an exploit. You will actually need it to freeze and black screen because then it is something that can't be handled by the OS. If there is an error code, look it up on support.nintendo.com, because chances are they already know what happens.
Yes. That may be true, but if it is the only way, I imagine people would do it anyway.
 
D

Deleted User

Guest
Yes. That may be true, but if it is the only way, I imagine people would do it anyway.
I just have a hard time believing he is going to make an exploit out of a system crash with no knowledge on exploiting the system. It seem like a big load of bullshit.

Again, he has yet to prove me wrong, and until them I will consider myself right because what I stated is true.

Especially if what he is trying to go after is an error code. And not playing a video game for 15 years just to buy a console and exploit it seems fishy...
 

BlastedGuy9905

where's the updated autopsy report
Member
Joined
Apr 13, 2017
Messages
2,334
Trophies
1
Age
33
Location
under your desk
XP
4,043
Country
United States
I just have a hard time believing he is going to make an exploit out of a system crash with no knowledge on exploiting the system. It seem like a big load of bullshit.

Again, he has yet to prove me wrong, and until them I will consider myself right because what I stated is true.

Especially if what he is trying to go after is an error code. And not playing a video game for 15 years just to buy a console and exploit it seems fishy...
We just have to wait and see.
 
  • Like
Reactions: Deleted User

ShadowOne333

QVID PRO QVO
Editorial Team
Joined
Jan 17, 2013
Messages
12,184
Trophies
2
XP
33,686
Country
Mexico
Can someone explain to me what the 173.255.238.217 DNS does and what sites does it block exactly?
Is it exclusive to the Switch or does it help Wii U/3DS as well?

I ask because I might Switch ™ to it instead of using my router's parental controls to block traffic to the 10+ sites I have registered from Nintendo.
And also I don't want to block any specific sites, like Youtube or so, since I visit them often in my Wii U.
 

linuxares

The inadequate, autocratic beast!
Global Moderator
Joined
Aug 5, 2007
Messages
13,302
Trophies
2
XP
18,141
Country
Sweden
I bet the Fuze studio games runs in a sandbox mode. So they won't be able to get out in to the rest of the system.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    I @ I-need-help-with-wup-wiiu: does WiiVC injector script work on aroma wiiu?