Homebrew Discussion SX OS Crack Thread

Status
Not open for further replies.

someofthemwork

New Member
Newbie
Joined
Jun 23, 2018
Messages
1
Trophies
0
Age
34
XP
69
Country
United States
Not encrypted (as far as I can tell)
Seems to just be some kind of Console Fingerprint with 32 bytes of 00 padding at the end.

Is it still just zero padded for licenses generated by the Pro? They appear to have some way of differentiating between license-request.dat files from the Lite and the Pro. If I had to guess, the ones from the Pro aren't zero padded but instead have something to identify the license associated with the key. Has anyone opened a license-request.dat file generated from a Pro?

Also, does that mean the payload is different for the Pro dongle vs. the one posted on the website? Where does the license come from?

EDIT: Yes, the Pro license files have something besides the 0 padding. But what is it? Just a license key? I don't have one to look at.
 
Last edited by someofthemwork,

HRudyPlayZ

Developer, Gamer and Power User.
Member
Joined
Dec 29, 2016
Messages
371
Trophies
0
XP
2,066
Country
France
Very well written! It's nice to see how the crack is going ;)

Did someone tried downloading the website's sources? Maybe we could see more about what is going on the server-side... and maybe crack it more easily.
(For reference HTTrack can be useful)

@PRAGMA Don't listen to people who are trying to discourage you. Try, if it works, nice, we'll have a permanent hack for free, else, you will and already had learnt a lot about how SXOS is made & how the switch FM works too...
 
Last edited by HRudyPlayZ,
  • Like
Reactions: jmmc and xenofly

Gabri9292

Member
Newcomer
Joined
Jun 22, 2018
Messages
9
Trophies
0
Age
25
XP
74
Country
Italy
In stage2.bin, it does a hash check of data.bin, we need to patch this out. Was pretty easy, search for the original sha256 hash of data before editing and replace it with edited versions SHA256.
Somebody can Explain me this?
 

y4my4m

Member
Newcomer
Joined
Jun 19, 2018
Messages
15
Trophies
0
Age
33
XP
70
Country
Japan
I've messaged a few devs on twitter but just gonna post this here.

I discovered there was a "hidden" gameboy rom file in data_8000000.bin (a file you get after uncompacting boot.dat).

The game is "hOT GB/iCEbiRD", some german hack-demo from 98. You can get the file by doing a hexdump from 0x169038 offset, its a gb file.
 

Attachments

  • Screen Shot 2018-06-24 at 5.58.35.png
    Screen Shot 2018-06-24 at 5.58.35.png
    13.9 KB · Views: 556

scottgl

Well-Known Member
Newcomer
Joined
Jan 4, 2016
Messages
52
Trophies
0
Age
39
XP
151
Country
United States
I've messaged a few devs on twitter but just gonna post this here.

I discovered there was a "hidden" gameboy rom file in data_8000000.bin (a file you get after uncompacting boot.dat).

The game is "hOT GB/iCEbiRD", some german hack-demo from 98. You can get the file by doing a hexdump from 0x169038 offset, its a gb file.

I noticed that as well with binwalk, sometimes binwalk misidentifies files, surprised it's an actual gameboy rom.
 
  • Like
Reactions: y4my4m

jakkal

Well-Known Member
Member
Joined
Apr 27, 2018
Messages
2,303
Trophies
1
Age
44
XP
3,982
Country
United States
I've messaged a few devs on twitter but just gonna post this here.

I discovered there was a "hidden" gameboy rom file in data_8000000.bin (a file you get after uncompacting boot.dat).

The game is "hOT GB/iCEbiRD", some german hack-demo from 98. You can get the file by doing a hexdump from 0x169038 offset, its a gb file.
This is old news
 
  • Like
Reactions: Centergaming

Dabiolos

Well-Known Member
Newcomer
Joined
Jan 17, 2018
Messages
47
Trophies
0
Age
41
XP
364
Country
Germany
Somebody can Explain me this?

It means (easy explained) that the code inside stage2.bin checks if the data.bin file has been modified (the modified file will have a different hash checksum. Comparable to the crc, md5 check you can do on downloaded files but more secure).

They created a new hash for the modified file and replaced the value inside stage2.bin to look for the modified hash so it won't see that data.bin has been tampered.

I think that's a smart move but tx could have used the original hash value to calculate jump points inside the code (at least that's what I would have minimally done to protect my code). If you change the value now it would point to the wrong locations and could cause the freeze when launching.
 

Kupie

Well-Known Member
Member
Joined
Jun 9, 2013
Messages
320
Trophies
1
Age
31
XP
906
Country
United States
I recommend not listening to PRAGMA on anything, he's just some stupid script kiddie

quote-1.png
 

noahc3

Well-Known Member
Member
Joined
Oct 17, 2015
Messages
123
Trophies
0
XP
1,288
Country
Canada
Quite sad that you have to spell that out... Even then, I'd assume people would be smart enough to know he's joking.

People were freaking out on discord, quite frankly I think people think PRAGMA is smarter than he actually is.
 

Kupie

Well-Known Member
Member
Joined
Jun 9, 2013
Messages
320
Trophies
1
Age
31
XP
906
Country
United States
Quite sad that you have to spell that out... Even then, I'd assume people would be smart enough to know he's joking.

If you want to trust someone that's stating they put trojans in the shit they've made, then go ahead and be retarded all you want.
 
  • Like
Reactions: TAUSENN

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,374
Trophies
4
Location
Space
XP
13,978
Country
Norway
To be fair, him claiming many times that he was close to cracking it screamed of amateurism. He has no experience whatsoever in software cracking.
It became quite obvious when he only installed IDA to check into the boot hangs.
Maybe he recently reinstalled Windows or got a new PC and hasn't installed IDA yet. Also, there are other alternatives to IDA that work fine. IDA just tends to be a bit easier to use and has more features. But not having IDA installed means nothing.
 
  • Like
Reactions: sigboe

y4my4m

Member
Newcomer
Joined
Jun 19, 2018
Messages
15
Trophies
0
Age
33
XP
70
Country
Japan
please redirecty me to where it was ever mentioned

if you mean the person who mentioned it on the 19th, i dont think he decrypted it (not that it was hard, just maybe didnt bother), you can see the name "hot gameboy / icebird" if you look at the text value of the binary.
Still different than extracting it and running it on an emu :P
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • Quincy @ Quincy:
    Usually when such a big title leaks the Temp will be the first to report about it (going off of historical reports here, Pokemon SV being the latest one I can recall seeing pop up here)
  • K3Nv2 @ K3Nv2:
    I still like how a freaking mp3 file hacks webos all that security defeated by text yet again
  • BigOnYa @ BigOnYa:
    They have simulators for everything nowdays, cray cray. How about a sim that shows you playing the Switch.
  • K3Nv2 @ K3Nv2:
    That's called yuzu
    +1
  • BigOnYa @ BigOnYa:
    I want a 120hz 4k tv but crazy how more expensive the 120hz over the 60hz are. Or even more crazy is the price of 8k's.
  • K3Nv2 @ K3Nv2:
    No real point since movies are 30fps
  • BigOnYa @ BigOnYa:
    Not a big movie buff, more of a gamer tbh. And Series X is 120hz 8k ready, but yea only 120hz 4k games out right now, but thinking of in the future.
  • K3Nv2 @ K3Nv2:
    Mostly why you never see TV manufacturers going post 60hz
  • BigOnYa @ BigOnYa:
    I only watch tv when i goto bed, it puts me to sleep, and I have a nas drive filled w my fav shows so i can watch them in order, commercial free. I usually watch Married w Children, or South Park
  • K3Nv2 @ K3Nv2:
    Stremio ruined my need for nas
  • BigOnYa @ BigOnYa:
    I stream from Nas to firestick, one on every tv, and use Kodi. I'm happy w it, plays everything. (I pirate/torrent shows/movies on pc, and put on nas)
  • K3Nv2 @ K3Nv2:
    Kodi repost are still pretty popular
  • BigOnYa @ BigOnYa:
    What the hell is Kodi reposts? what do you mean, or "Wut?" -xdqwerty
  • K3Nv2 @ K3Nv2:
    Google them basically web crawlers to movie sites
  • BigOnYa @ BigOnYa:
    oh you mean the 3rd party apps on Kodi, yea i know what you mean, yea there are still a few cool ones, in fact watched the new planet of the apes movie other night w wifey thru one, was good pic surprisingly, not a cam
  • BigOnYa @ BigOnYa:
    Damn, only $2.06 and free shipping. Gotta cost more for them to ship than $2.06
    +1
  • BigOnYa @ BigOnYa:
    I got my Dad a firestick for Xmas and showed him those 3rd party sites on Kodi, he loves it, all he watches anymore. He said he has got 3 letters from AT&T already about pirating, but he says f them, let them shut my internet off (He wants out of his AT&T contract anyways)
  • K3Nv2 @ K3Nv2:
    That's where stremio comes to play never got a letter about it
  • BigOnYa @ BigOnYa:
    I just use a VPN, even give him my login and password so can use it also, and he refuses, he's funny.
  • BigOnYa @ BigOnYa:
    I had to find and get him an old style flip phone even without text, cause thats what he wanted. No text, no internet, only phone calls. Old, old school.
  • Psionic Roshambo @ Psionic Roshambo:
    @BigOnYa, Lol I bought a new USB card reader thing on AliExpress last month for I think like 87 cents. Free shipping from China... It arrived it works and honestly I don't understand how it was so cheap.
    +1
    Psionic Roshambo @ Psionic Roshambo: @BigOnYa, Lol I bought a new USB card reader thing on AliExpress last month for I think like 87... +1