Nereba Exploit: Reboot to Fusée Gelée payload from stock firmware.

nintendo-switch-homebrew-launcher.jpg

Stuckpixel of the ReSwitched team recently released his exploit "Nereba".


This exploit will enable Nintendo Switch owners with early units that have held off updating, still on the original 1.0.0 firmware to reboot into a Fusée Gelée payload without any dongle, USB connections to a external device or jig directly from stock untouched firmware. In addition support for 2.x and 3.x firmware is also planned in the future, opening up the exploit to significantly more consoles.

The implementation takes advantage of the nspwn exploit, that users of the original 3.0.0 homebrew implementation will be familiar with. Used in conjunction with this, users will be able to boot any Fusee Gelee payload from the micro SD card, placed in the nereba folder on the root of the SD card. After running the script from the Switch web applet, users can reboot into any payload by launching the album applet from the home menu.

Download:


https://github.com/pixel-stuck/nereba/releases
 
Last edited by RattletraPM, , Reason: Center image to follow news formatting

Nerdtendo

Your friendly neighborhood idiot
Member
Joined
Sep 29, 2016
Messages
1,770
Trophies
1
XP
4,629
Country
United States
I got an extra switch I keep updated but now that my sd card reader went beserk on my hacked switch, i regret that.
 

Deathscreton

Well-Known Member
Member
Joined
Oct 1, 2009
Messages
826
Trophies
0
XP
1,092
Country
United States
But what on earth would be the point? If you've got hekate loaded, you can already load CFW.
For those that don't want AutoRCM/A dongle to push RCM payloads. Cuts out a step. Same reason those who were on 1.0.0 upgraded without burning any fuses (Because initially, the step for bypassing fuse checks completely/downgrading wasn't available).
 

deSSy2724

Well-Known Member
Member
Joined
Sep 11, 2015
Messages
453
Trophies
0
Age
33
XP
1,171
Country
Germany
What do they mean exactly by "In addition support for 2.x and 3.x firmware is also planned in the future, opening up the exploit to significantly more consoles."?`Does it means that it wouldnt require any dongle/jig in the future for 2.x - 3.x firmwares as well or did I misunderstood something here because I remember they were saying its possible only on 1.0.

My Switch is still between 2.x - 3.0.......
 

snoofly

Well-Known Member
Member
Joined
Aug 18, 2015
Messages
1,012
Trophies
0
Age
54
XP
2,133
Country
United Kingdom
wait what?
this sounds awesome.
gonna try this a bit later on

but let me be clear.
so i don’t need a pc to run this, i can just boot stock 1.0 with a properly set sd then run album and i could reboot into sx os emunand?
 

sj33

Well-Known Member
Member
Joined
Oct 22, 2013
Messages
4,072
Trophies
2
XP
4,726
Country
Japan
For those that don't want AutoRCM/A dongle to push RCM payloads. Cuts out a step. Same reason those who were on 1.0.0 upgraded without burning any fuses (Because initially, the step for bypassing fuse checks completely/downgrading wasn't available).
But you would still need a dongle or USB connection to send hekate every time in order to skip the fuse check and actually load 1.0. Without that, you'll just get black screen at boot.
 

Xandroz

Well-Known Member
Member
Joined
Mar 19, 2018
Messages
872
Trophies
0
Age
35
XP
1,625
Country
Egypt
so untill i fix my 1.0 as it needs a replacement screen socket, anyway i can install pegaswitch without puyo.
or can i just use a dongol and jig to install it as nsp and install pega from there
 

sj33

Well-Known Member
Member
Joined
Oct 22, 2013
Messages
4,072
Trophies
2
XP
4,726
Country
Japan
wait what?
this sounds awesome.
gonna try this a bit later on

but let me be clear.
so i don’t need a pc to run this, i can just boot stock 1.0 with a properly set sd then run album and i could reboot into sx os emunand?
Yes and no. You won't be able to downgrade unless you prevented burning fuses in the first place.
 

Deathscreton

Well-Known Member
Member
Joined
Oct 1, 2009
Messages
826
Trophies
0
XP
1,092
Country
United States
But you would still need a dongle or USB connection to send hekate every time in order to skip the fuse check and actually load 1.0. Without that, you'll just get black screen at boot.
So push Hekate instead?

EDIT: I see what you mean now. I misunderstood. Can't boot into 1.0.0 with burnt fuses meaning loading into 1.0.0 just to boot CFW doesn't make sense. My bad.

--------------------- MERGED ---------------------------

Yes and no. You won't be able to downgrade unless you prevented burning fuses in the first place.
You can downgrade with burnt fuses so long as you use hekate.

Either you or I have a terrible understanding of how this works.

EDIT: This still stands though. You can move between firmwares using Choi and Hekate, but it doesn't make much sense to move downwards past burnt fuses since you'd have to use Hekate anyways (as you explained to me earlier).
 
Last edited by Deathscreton, , Reason: Conceding.

M7L7NK7

Well-Known Member
Member
Joined
Oct 16, 2017
Messages
3,897
Trophies
1
Website
youtube.com
XP
5,960
Country
Australia
It sounds like it works, downgrade to 1.0.0 and use Nereba but if your fuses don't match you need to push a payload through USB to even load 1.0.0 so you may as well just use the current RCM way
 
D

Deleted User

Guest
OP
I think this is really cool in the sense it finally was released but here is my take.

We were made aware to hold off on updating that there would be new developments. But aside from piracy the draw to modding my switch was homebrew. If i had waited in this case i would have missed out on all the fun i had playing the various homebrew. I would have also had to do a lot of catching up in terms of config and bios files etc. At this point i have a very impressive system and that would not have happened if I had waited for this. Frankly i feel the people who did wait missed out and continue to miss out. This is similar to someone on ps4 scene waiting for cfw. “Gotta learn when to hold them learn when to fold them...”
 
  • Like
Reactions: peteruk and Zaybokk

sj33

Well-Known Member
Member
Joined
Oct 22, 2013
Messages
4,072
Trophies
2
XP
4,726
Country
Japan
Well, this release is clearly aimed at devs or other people who specifically need a 1.0 device but don't possess the exploit themselves. This presumably arrived now because the final part of the exploit chain was patched in 1.0. Presumably those same parts will be in Deja Vu.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    ButterScott101 @ ButterScott101: +1