Hacking PSA: Reports of Fusee gelee patched units in the wild

  • Thread starter Deleted-442439
  • Start date
  • Views 85,526
  • Replies 315
  • Likes 10

bitteorca

Member
Newcomer
Joined
Jul 12, 2018
Messages
21
Trophies
0
Age
28
XP
100
Country
United States
Can you try tegrarcmsmash with biskeydump ?

And run this command when you connect your RCM switch to your pc.

TegraRcmSmash.exe -w biskeydump.bin BOOT:0x0

Then capture the output on the command line windows and post it here please.
My bad it wasn't letting me reply to your post but I figured it out I had to remove your hyperlink

Here's the output:
tegrasmash.png
 

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,012
Trophies
2
Age
29
Location
New York City
XP
13,391
Country
United States
I purchased a Switch with the serial number XAW700183***** and I can confirm that payload injection doesn't work.

Steps to recreate:
1. Copied the Switch Starterkit root files to the root of my FAT32 SDcard from my PC
2. Inserted SDcard into Switch, then booted into RCM mode with paperclip jig
3. Plugged Switch into PC, used Zandig to install the libusbK drivers, confirmed APX came up as a device in device manager
4. Tried to run the NX bootkit 64-bit executable, the Switch screen remains black and the cmd prompt window displayed some code then counted down from 5 seconds to close the window

Is it possible that my USB-C cable (came with my phone) is the culprit here or is it likely that I have a patched Switch?

My bad it wasn't letting me reply to your post but I figured it out I had to remove your hyperlink

Here's the output:
View attachment 135507
So it appears these units have been smuggled into the US but we have another problem: we don't know the serial number cut-off for un-patched units...I think. Need to double check that spreadsheet...
 

gnilwob

Well-Known Member
Member
Joined
Mar 16, 2008
Messages
204
Trophies
1
XP
644
Country
Hong Kong
Lucky me.
Just to explain.

This is from a working console.
2018-07-13_5-20-39.png

I asked you to run the biskeydump because you were not sure about your cable.
But from the command line output, it can send data using your cable.

Next, see the different 0x0000(not working) and 0x7000(working) output?
 

bitteorca

Member
Newcomer
Joined
Jul 12, 2018
Messages
21
Trophies
0
Age
28
XP
100
Country
United States
Just to explain.

This is from a working console.
View attachment 135511

I asked you to run the biskeydump because you were not sure about your cable.
But from the command line output, it can send data using your cable.

Next, see the different 0x0000(not working) and 0x7000(working) output?
That's right, it also looked identical to the screen that came up when I ran Hekate. I know for a fact it said "Smashed with 0x0000 stack" as well

The girl at the counter even offered me a used unit, damn. Does anyone have any news on the webkit exploit Deja vu?
 

Scoob0

New Member
Newbie
Joined
Jul 12, 2018
Messages
4
Trophies
0
Age
40
XP
141
Country
United States
First time posting, but wanted to include info on my switch I bought on June 29 through Newegg. Its very close to the serial bitteorca posted, but mine does work im running SX Pro and been playing backups and even updated to 5.1. Hope this helps in figuring out where the line is between patched and unpatched.

Serial: XAW700119XXX
Serial on device matches serial on box: Yes
Region: US
Firmware: 4.1.0
Color option: Blue / Red
Store: Newegg
Was a bundle (if yes, which): No
Purchase date: June 29 2018
Fusée Gelée works: Yes
 
Last edited by Scoob0,

gnilwob

Well-Known Member
Member
Joined
Mar 16, 2008
Messages
204
Trophies
1
XP
644
Country
Hong Kong
First time posting, but wanted to include info on my switch I bought on June 29 through Newegg. Its very close to the serial bitteorca posted, but mine does work im running SX Pro and been playing backups and even updated to 5.1. Hope this helps in figuring out where the line is between patched and unpatched.

Serial: XAW700119XXX
Serial on device matches serial on box: Yes
Region: US
Firmware: 4.1.0
Color option: Blue / Red
Store: Newegg
Was a bundle (if yes, which): No
Purchase date: June 29 2018
Fusée Gelée works: Yes

If it is ok, can you also post it here please, https://gbatemp.net/threads/switch-firmware-by-serial-number.481215/page-59
So people who checks on serial number can use yours as an indicator.
Thanks.


That's right, it also looked identical to the screen that came up when I ran Hekate. I know for a fact it said "Smashed with 0x0000 stack" as well

The girl at the counter even offered me a used unit, damn. Does anyone have any news on the webkit exploit Deja vu?
Please also post your serial and model information here, https://gbatemp.net/threads/switch-firmware-by-serial-number.481215/page-59
Thanks.
 
Last edited by gnilwob,
  • Like
Reactions: Draxzelex

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,012
Trophies
2
Age
29
Location
New York City
XP
13,391
Country
United States
XAW700119XXX = not patched
XAW700183XXXXX = patched
So 11 is still safe, but 18 isn't. That leaves like 7 more possible Switch serial numbers, at least. And while there is no word yet on when Deja Vu will be released, this is what it looks like in action:
 

Essometer

Needs data
Member
Joined
Oct 22, 2010
Messages
732
Trophies
1
Age
33
Location
Bielefeld
Website
none.de
XP
3,594
Country
Germany
seems to be a low serial, whats the date code on the switch?

might be worth trying a different USB port/pc, unfortunately I feel like anyone having troubles with setup at this point are going to be "arrrgh its a patched switch!!!!"
XAW700183 is actually a really high serial number. It is just that assembly line XAW7 is pretty slow in producing switches. According to my
serial list, it is very possible that this serial is another cutoff point for patched switches.
 
Last edited by Essometer,

SuppaMario

Member
Newcomer
Joined
Jul 11, 2018
Messages
9
Trophies
0
Age
34
XP
76
Country
United States

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,012
Trophies
2
Age
29
Location
New York City
XP
13,391
Country
United States
XAW700183 is actually a really high serial number. It is just that assembly line XAW7 is pretty slow in producing switches. According to
serial list, it is very possible that this serial is another cutoff point for patched switches.
An XAW700119XX doesn't have it patched so its a little more specific. Similar to the Japanese ones, the cutoff point is not XAJX004, butXAJX0043 since there were people who could still do the exploit on the former serial number.
 

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
XAW700183 is actually a really high serial number. It is just that assembly line XAW7 is pretty slow in producing switches. According to
serial list, it is very possible that this serial is another cutoff point for patched switches.
oh, no I know that, I meant the previous patched systems were 7004, but his was 7001 with others with 7003 being ok, but with it being a US console the "patched/no-patched" serials are going to be different
 

Essometer

Needs data
Member
Joined
Oct 22, 2010
Messages
732
Trophies
1
Age
33
Location
Bielefeld
Website
none.de
XP
3,594
Country
Germany
An XAW700119XX doesn't have it patched so its a little more specific. Similar to the Japanese ones, the cutoff point is not XAJX004, butXAJX0043 since there were people who could still do the exploit on the former serial number.
Yes, this is what I think as well that the cutoff point for the XAJ7 line is more specific as for XAW7. We definitely need more serials to get a cutoff point for all assembly lines.
Also, we have a confirmed unpatched switch @ XAW700164.

oh, no I know that, I meant the previous patched systems were 7004, but his was 7001 with others with 7003 being ok, but with it being a US console the "patched/no-patched" serials are going to be different
When we talk about serials, it doesn't make sense to compare a XAW7 serial to a XAJ7 serial, since they are completely different form each other.
The same is true for XAJ7 and XAJ4 or XAJ1. The produce at different places in different rates, some slower, some faster.
 
Last edited by Essometer,
  • Like
Reactions: Draxzelex

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Sicklyboy @ Sicklyboy:
    I'm not familiar with the technicalities of the differences between the two versions, but I'm wondering if at least some of those differences are things that you could port over to the US version in your patch without having to include copyrighted assets from the EU version
  • TwoSpikedHands @ TwoSpikedHands:
    @Sicklyboy I am wanting to fully change the game and bend it to my will lol. I would like to eventually have the ability to add more characters, enemies, even have a completely different story if i wanted. I already have the ability to change the tilemaps in the US version, so I can basically make my own map and warp to it in game - so I'm pretty far into it!
  • TwoSpikedHands @ TwoSpikedHands:
    I really would like to make a hack that I would enjoy playing, and maybe other people would too. swapping to the EU version would also mean my US friends could not legally play it
  • TwoSpikedHands @ TwoSpikedHands:
    I am definitely considering porting over some of the EU features without using the actual ROM itself, tbh that would probably be the best way to go about it... but i'm sad that the voice acting is so.... not good on the US version. May not be a way around that though
  • TwoSpikedHands @ TwoSpikedHands:
    I appreciate the insight!
  • The Real Jdbye @ The Real Jdbye:
    @TwoSpikedHands just switch, all the knowledge you learned still applies and most of the code and assets should be the same anyway
  • The Real Jdbye @ The Real Jdbye:
    and realistically they wouldn't

    be able to play it legally anyway since they need a ROM and they probably don't have the means to dump it themselves
  • The Real Jdbye @ The Real Jdbye:
    why the shit does the shitbox randomly insert newlines in my messages
  • Veho @ Veho:
    It does that when I edit a post.
  • Veho @ Veho:
    It inserts a newline in a random spot.
  • The Real Jdbye @ The Real Jdbye:
    never had that i don't think
  • Karma177 @ Karma177:
    do y'all think having an sd card that has a write speed of 700kb/s is a bad idea?
    trying to restore emunand rn but it's taking ages... (also when I finished the first time hekate decided to delete all my fucking files :wacko:)
  • The Real Jdbye @ The Real Jdbye:
    @Karma177 that sd card is 100% faulty so yes, its a bad idea
  • The Real Jdbye @ The Real Jdbye:
    even the slowest non-sdhc sd cards are a few MB/s
  • Karma177 @ Karma177:
    @The Real Jdbye it hasn't given me any error trying to write things on it so I don't really think it's faulty (pasted 40/50gb+ folders and no write errors)
  • DinohScene @ DinohScene:
    run h2testw on it
    +1
  • DinohScene @ DinohScene:
    when SD cards/microSD write speeds drop below a meg a sec, they're usually on the verge of dying
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Samsung SD format can sometimes fix them too
  • Purple_Heart @ Purple_Heart:
    yes looks like an faulty sd
  • Purple_Heart @ Purple_Heart:
    @Psionic Roshambo i may try that with my dead sd cards
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    It's always worth a shot
  • TwoSpikedHands @ TwoSpikedHands:
    @The Real Jdbye, I considered that, but i'll have to wait until i can get the eu version in the mail lol
  • I @ I-need-help-with-wup-wiiu:
    i need help with nusspli failed downloads, can someone respond to my thread? pretty please:wub: