Hacking Switch bootrom warmboot exploit

  • Thread starter Deleted User
  • Start date
  • Views 45,419
  • Replies 161
  • Likes 19
D

Deleted User

Guest
OP
In case anyone wants to go looking for the bootrom exploit that caused this ktempkin drama, it's related to SDRAM warmboot.
Apparently there is a flaw in the bootrom that lets you takeover the bootrom itself when the bootrom is executing code during a warmboot reset.

How it fits together is you set up some special values in memory and trigger a warmboot reset. If you did it correctly it will trigger the vulnerability and will jump to your code, thus taking over the bootrom.
If you have a 4.1 exploit to trigger warm boot reset, you can have a softmod that does this.


Obviously I left out a few details, but someone more skilled knows where to look now...
 

Kioku

猫。子猫です!
Member
Joined
Jun 24, 2007
Messages
12,010
Trophies
3
Location
In the Murderbox!
Website
www.twitch.tv
XP
16,162
Country
United States
I hope this brand is good enough

Y'know? Apparently it's a really good product. Maybe it'll work here. Lord knows we've got some bad leaks in the scene.
 

Kioku

猫。子猫です!
Member
Joined
Jun 24, 2007
Messages
12,010
Trophies
3
Location
In the Murderbox!
Website
www.twitch.tv
XP
16,162
Country
United States
Doesn't mean anything if it doesn't come to fruition or the end result is never released publicly *shrug*. I didn't see that being released in all honest.
It might be. There's a chance they're sitting on it until they know for sure it'll work or not on Mariko units. Time will tell. Even if not current devs, someone might.
 
  • Like
Reactions: weatMod and V-Temp

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
It might be. There's a chance they're sitting on it until they know for sure it'll work or not on Mariko units. Time will tell. Even if not current devs, someone might.

Not sure any one was sitting on it, not any more.

This more or less IS Deja Vu, betweeen the warmboot exploit and coldboot enabling which was what DJ promised. Now everyone knows how its done, so whether or not its released, its already pretty much lost.

Kate was right in what she said on twitter, this was know about already. 5.x fixed this because Nintendo knew about the ability to coldboot on <4.1, which means they knew this exact thing was possible.
 
  • Like
Reactions: Kioku

Kioku

猫。子猫です!
Member
Joined
Jun 24, 2007
Messages
12,010
Trophies
3
Location
In the Murderbox!
Website
www.twitch.tv
XP
16,162
Country
United States
Not sure any one was sitting on it, not any more.

This more or less IS Deja Vu, betweeen the warmboot exploit and coldboot enabling which was what DJ promised. Now everyone knows how its done, so whether or not its released, its already pretty much lost.

Kate was right in what she said on twitter, this was know about already. 5.x fixed this because Nintendo knew about the ability to coldboot on <4.1, which means they knew this exact thing was possible.
Well, I misworded that. I meant waiting to try and make it work on 5.x. :x

Apparently there's some traces of it in tact, just no known way to execute it.
 
  • Like
Reactions: V-Temp

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
Well, I misworded that. I meant waiting to try and make it work on 5.x. :x

Apparently there's some traces of it in tact, just no known way to execute it.

Yup you're right, that's been the status of it.

But now that we know how this works I don't know if this would have worked on Mariko any way, its not a Tegra X1.
 
  • Like
Reactions: Kioku

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    K3Nv2 @ K3Nv2: Oh man don't get the snowflakes worked up