Hacking [RCM Payload] Hekate - CTCaer mod

  • Thread starter CTCaer
  • Start date
  • Views 1,075,012
  • Replies 3,243
  • Likes 128

CTCaer

Developer
OP
Developer
Joined
Mar 22, 2008
Messages
1,154
Trophies
0
XP
3,008
Country
Greece
The filesize is correct.
That's what I'm getting:
[06:14:20:146294] [info] Trying to read partition table from -snip-/raw4-20180627/Backup/Restore/rawnand - Copy.bin
[06:14:20:150584] [info] Loaded primary GPT, checking secondary from offset 31268535808
[06:14:20:150880] [info] Secondary GPT is okay
[06:14:20:151003] [info] Using primary GPT as backup GPT is identical

What have run until now (payloads, modules, kips, homebrew, etc)?


EDIT:
Actually, just open the backup in a hexeditor and go to 31268535808 (decimal), take a screenshot and attach it here.
 
Last edited by CTCaer,

CTCaer

Developer
OP
Developer
Joined
Mar 22, 2008
Messages
1,154
Trophies
0
XP
3,008
Country
Greece
Can you explain more about the battery desync fix found here? How'd you get this to work?
I explained it in another thread, but well..

It forces the battery charger to disconnect the main battery supply pin (BATFET) from the system.
It's not actually virtual or software disconnect as we call it. It's a hardware disconnect caused by software.

This forces the fuel gauge to reset and also the well programmed HOS to wipe its battery fuel gauge cache.
Basically it thinks that a new battery was inserted.
 
Last edited by CTCaer,

1LastRide

Member
Newcomer
Joined
Mar 22, 2018
Messages
22
Trophies
0
Age
44
XP
185
Country
United States
What have run until now (payloads, modules, kips, homebrew, etc)?
EDIT:
Actually, just open the backup in a hexeditor and go to 31268535808 (decimal), take a screenshot and attach it here.

Thanks for posting your HacTool results. That's interesting. It could legitimately be a problem with my switch. I'm not sure what a good partition table should look like.
If it is a problem, this is a fun problem, at least, and it's not effecting my switch horizon OS at all.

As for what I've run, only two payloads: the CTCaer/Hekate 2.3 payload through RCM + tegraRCMSmash.
and the biskeydump payload through RCM + tegraRCMSmash
No kips, hbmenus, or modules.

I'm just playing around getting a good NAND backup and getting familiar with things so I can start to contribute.

hex editor shows all 00 at that decimal offset of rawnand.bin
 

Attachments

  • hex_editor.png
    hex_editor.png
    7.5 KB · Views: 186

CTCaer

Developer
OP
Developer
Joined
Mar 22, 2008
Messages
1,154
Trophies
0
XP
3,008
Country
Greece
Thanks for posting your HacTool results. That's interesting. It could legitimately be a problem with my switch. I'm not sure what a good partition table should look like.
If it is a problem, this is a fun problem, at least, and it's not effecting my switch horizon OS at all.

As for what I've run, only two payloads: the CTCaer/Hekate 2.3 payload through RCM + tegraRCMSmash.
and the biskeydump payload through RCM + tegraRCMSmash
No kips, hbmenus, or modules.

I'm just playing around getting a good NAND backup and getting familiar with things so I can start to contribute.

hex editor shows all 00 at that decimal offset of rawnand.bin
Yeah, you are missing the secondary (backup) partition table. That's strange.
Just to make sure I'll make a payload to test.
 

CTCaer

Developer
OP
Developer
Joined
Mar 22, 2008
Messages
1,154
Trophies
0
XP
3,008
Country
Greece
Thanks for posting your HacTool results. That's interesting. It could legitimately be a problem with my switch. I'm not sure what a good partition table should look like.
If it is a problem, this is a fun problem, at least, and it's not effecting my switch horizon OS at all.

As for what I've run, only two payloads: the CTCaer/Hekate 2.3 payload through RCM + tegraRCMSmash.
and the biskeydump payload through RCM + tegraRCMSmash
No kips, hbmenus, or modules.

I'm just playing around getting a good NAND backup and getting familiar with things so I can start to contribute.

hex editor shows all 00 at that decimal offset of rawnand.bin
Try the attached payload. Run the first option and tell me what you see.

It should be OK.
 

Attachments

  • iplctc_2nd_gpt.zip
    40 KB · Views: 106

1LastRide

Member
Newcomer
Joined
Mar 22, 2018
Messages
22
Trophies
0
Age
44
XP
185
Country
United States
Try the attached payload. Run the first option and tell me what you see.

Thanks for this. I'm seeing the partition from the payload.
I'm starting to think my 256 GB card might not be writing properly.
 

Attachments

  • IMG_8805 2.jpg
    IMG_8805 2.jpg
    1.5 MB · Views: 218

CTCaer

Developer
OP
Developer
Joined
Mar 22, 2008
Messages
1,154
Trophies
0
XP
3,008
Country
Greece
Thanks for this. I'm seeing the partition from the payload.
I'm starting to think my 256 GB card might not be writing properly.
And this is with the latest commits from my repo, correct?

If yes, your card is legit? Have you tried H2testw on it (all available space)?
 

1LastRide

Member
Newcomer
Joined
Mar 22, 2018
Messages
22
Trophies
0
Age
44
XP
185
Country
United States
And this is with the latest commits from my repo, correct?

If yes, your card is legit? Have you tried H2testw on it (all available space)?
At work and will run H2testw on the card when I get home.
I compiled your latest commits last night (had to comment out a ment_options sections to get it to compile) and running it without any ini file / configuration options.
I formatted my SD card last night before I went to bed. I will try a fresh NAND dump and see what happens when I get home.
 
Last edited by 1LastRide,

1LastRide

Member
Newcomer
Joined
Mar 22, 2018
Messages
22
Trophies
0
Age
44
XP
185
Country
United States
I used Horizon 5.1.0 to format the SD card again.
I ran the latest version of IPL that I compiled last night to dump boot and full nand. Took just short of an hour to do the dump.

Validation failed immediately.
IMG_8807.jpg

The file size for Backup/rawnand.bin written is still right.
IMG_8808.JPG

Perhaps it's extended writing to the SD card that's causing an issue, and it's just writing 00's.

I downloaded h2testw 1.4 from heise.de and am currently running a full write/verify of the 256GB SD card. This is going to take about 7 hours.
I'm bottlenecked by an old USB 1.0 miniSD adapter at about 10 MByte/s
With a fresh Windows exFat format of the SD Card at 256kb allocation (same as Horizon formats, I believe), H2testw is still saying it can only write/verify 255934/299936 Mbytes.
So I wonder if there's a 2MByte partition table for exFat.

Anyway, If the SD card comes back good, my next step is to do a Horizon system reset, format the SD card in horizon, and then try to dump the nand again.

*EDIT* the SD Card test did NOT come back good. It's most likely a 32 GB card sold to me as a 256 GB Sandisk SDXC. Frustrating, but I think I can solve that problem outside here and try again later. The SD Card had a nintendo album and some game updates living on it, so most likely could not fit the nand backup in the memory that was good, which I'm guessing is why all the secondary partition was read from the SD card file as all 00's. Oh, the irony of trying to hack my console with a hacked SD card.
 

Attachments

  • IMG_8808.JPG
    IMG_8808.JPG
    2.2 MB · Views: 200
Last edited by 1LastRide,

tottti1914

Active Member
Newcomer
Joined
May 3, 2018
Messages
38
Trophies
0
XP
520
Country
Syria
hi
so if i don't have much space what is the most important backup i should do (Dump eMMC BOOT+Dump eMMC SYS) enough to be able to restore my system if something happen
thanks
 

CTCaer

Developer
OP
Developer
Joined
Mar 22, 2008
Messages
1,154
Trophies
0
XP
3,008
Country
Greece
I used Horizon 5.1.0 to format the SD card again.
I ran the latest version of IPL that I compiled last night to dump boot and full nand. Took just short of an hour to do the dump.

Validation failed immediately.
View attachment 133720

The file size for Backup/rawnand.bin written is still right.
View attachment 133723

Perhaps it's extended writing to the SD card that's causing an issue, and it's just writing 00's.

I downloaded h2testw 1.4 from heise.de and am currently running a full write/verify of the 256GB SD card. This is going to take about 7 hours.
I'm bottlenecked by an old USB 1.0 miniSD adapter at about 10 MByte/s
With a fresh Windows exFat format of the SD Card at 256kb allocation (same as Horizon formats, I believe), H2testw is still saying it can only write/verify 255934/299936 Mbytes.
So I wonder if there's a 2MByte partition table for exFat.

Anyway, If the SD card comes back good, my next step is to do a Horizon system reset, format the SD card in horizon, and then try to dump the nand again.

*EDIT* the SD Card test did NOT come back good. It's most likely a 32 GB card sold to me as a 256 GB Sandisk SDXC. Frustrating, but I think I can solve that problem outside here and try again later. The SD Card had a nintendo album and some game updates living on it, so most likely could not fit the nand backup in the memory that was good, which I'm guessing is why all the secondary partition was read from the SD card file as all 00's. Oh, the irony of trying to hack my console with a hacked SD card.
That's unfortunate :/
I hope that you can return it and get your money back. Send me a screenshot of Print sdcard info and maybe I can tell you if they also faked the vendor details.
And yes, a fake sd card that can reply for addresses out of its real max, it normally replies with 00s or it starts sending the data from the start.

hi
so if i don't have much space what is the most important backup i should do (Dump eMMC BOOT+Dump eMMC SYS) enough to be able to restore my system if something happen
thanks
Do BOOT0/1 and raw first. And then do a SYS one.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • K3Nv2 @ K3Nv2:
    I'll reformat and have a 3tb raid0 m. 2 at least
    +1
  • K3Nv2 @ K3Nv2:
    Lmao that sold out fast
    +1
  • Veho @ Veho:
    Yeet the cat.
    +1
  • K3Nv2 @ K3Nv2:
    Good idea
    +1
  • The Real Jdbye @ The Real Jdbye:
    i thought everybody knew cocktails are like 75% ice
  • Veho @ Veho:
    Yeah but not like this.
  • Veho @ Veho:
    It's not like they're complaining that their Slurpee is 99% ice or something, but if the cocktail calls for "shot of vodka, shot of vermouth, shot of gin, shot of Campari, three shots of juice, squirt of lemon" and ends up being a thimbleful of booze, that's a problem.
  • The Real Jdbye @ The Real Jdbye:
    the funny thing is cocktails in norway are only allowed to have 1 20ml shot of booze
  • The Real Jdbye @ The Real Jdbye:
    so..... yeah
  • The Real Jdbye @ The Real Jdbye:
    we're used to only having a thimbleful of booze
  • Veho @ Veho:
    Booo.
  • The Real Jdbye @ The Real Jdbye:
    same thing if you want whisky on the rocks or something, you can't get a double
  • The Real Jdbye @ The Real Jdbye:
    but you could buy as many shots of whisky (or anything else) as you want and ask for a glass of ice and pour them in
  • The Real Jdbye @ The Real Jdbye:
    it's dumb
  • Veho @ Veho:
    Maybe.
  • Veho @ Veho:
    There was a comparison of the number of Ibuprofen poisonings before and after they limited the maximum dosage per box or per pill (i'll look that up). No limit on the number of boxes you can still buy as many as you want, so people argued it was pointless.
  • Veho @ Veho:
    But the number of (accidental) poisonings dropped because drinking an entire package of ibuprofen pills went from "I need a new liver" to "I need a new box of Ibuprofen".
  • Veho @ Veho:
    Here we have ketoprofen that used to be prescription-only because of the risk of toxic dosages, but then they halved the dose per pill and sell them in bottles of six pills apiece instead of twenty and it doesn't need a prescription any more. Yes you can buy more than one bottle but people simply don't.
  • Psionic Roshambo @ Psionic Roshambo:
    Usually accidentally overdose of ibuprofen here is from people taking like cold medicine then ibuprofen for a headache and the combination is over what they need
    Veho @ Veho: https://imgur.com/gallery/QQkYnQu