Hacking Switch: Extract keys.txt/prod.keys from a NAND dump

iCRON

Well-Known Member
OP
Newcomer
Joined
Mar 6, 2018
Messages
95
Trophies
0
XP
1,173
Country
Germany
Can i extract the keys.txt/prod.keys fom a NAND dump? I unable to dump the keys with LockpickRCM and so i can't use the manual ChoiDujour Downgrade. I have a clean dump in 14 parts. I have biskeys backup too in the "automatic_backup" folder. Or is there a other method i can try it to get keys.txt/prod.keys? Can i unbrick my console anymore in this situation now? Or it was too late?
 

issayloki

Well-Known Member
Member
Joined
Mar 4, 2018
Messages
146
Trophies
0
Age
43
XP
1,386
Country
Thailand
Can i extract the keys.txt/prod.keys fom a NAND dump? I unable to dump the keys with LockpickRCM and so i can't use the manual ChoiDujour Downgrade. I have a clean dump in 14 parts. I have biskeys backup too in the "automatic_backup" folder. Or is there a other method i can try it to get keys.txt/prod.keys? Can i unbrick my console anymore in this situation now? Or it was too late?
Op why do you need to downgrade?. LockpickRCM is the easy way of getting all the keys. You did meantion that lockpickRCM is not working, mind to tell us why it not working for you?. :)
 

iCRON

Well-Known Member
OP
Newcomer
Joined
Mar 6, 2018
Messages
95
Trophies
0
XP
1,173
Country
Germany
Op why do you need to downgrade?. LockpickRCM is the easy way of getting all the keys. You did meantion that lockpickRCM is not working, mind to tell us why it not working for you?. :)
My console bricked after my NAND restore and i haven't dump the keys before the brick. If i use LockpickRCM i don't getting the full keys because some says "corrupted". If i use there on ChoiDujour(no NX) it says "FAIL! Invalid NCA Header. Are keys correct?" = corrupted prod.keys from LockpickRCM. And my Backup wasn't working. So i have only the PC Downgrade method but without the keys i can't rebulit my NAND :(
 

F4mouZSt4r

Well-Known Member
Newcomer
Joined
Apr 29, 2018
Messages
76
Trophies
0
Age
29
XP
957
Country
Germany
you only need specific keys, when u have keys inside the keys.txt file which ChiDujour dont want he will say that

you only need these keys, ofc replace the X with the real numbers/letters

master_key_00 = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
master_key_01 = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
master_key_02 = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
master_key_03 = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
master_key_04 = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
master_key_05 = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX

header_key = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
aes_kek_generation_source = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
aes_key_generation_source = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
key_area_key_application_source = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
key_area_key_ocean_source = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
key_area_key_system_source = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
package2_key_source = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
 

iCRON

Well-Known Member
OP
Newcomer
Joined
Mar 6, 2018
Messages
95
Trophies
0
XP
1,173
Country
Germany
you only need specific keys, when u have keys inside the keys.txt file which ChiDujour dont want he will say that

you only need these keys, ofc replace the X with the real numbers/letters

master_key_00 = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
master_key_01 = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
master_key_02 = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
master_key_03 = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
master_key_04 = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
master_key_05 = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX

header_key = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
aes_kek_generation_source = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
aes_key_generation_source = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
key_area_key_application_source = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
key_area_key_ocean_source = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
key_area_key_system_source = XXXXXXXXXXXXXXXXXXXXXXXXXXXXX
I opened my keys.txt and there are all these keys already inserted but the situation won't change. Same error before you reply[/QUOTE]
 
Last edited by iCRON,

Boydy86

Well-Known Member
Member
Joined
Jun 3, 2019
Messages
107
Trophies
0
Age
38
XP
304
Country
United Kingdom
If I remember right, this fails if your key file has keys that are unneeded. I think the error should tell you which keys it doesn't recognise. (remove that line from key.txt)
 

Canna

Bad Ass Poisonous Mushroom
Member
Joined
Jul 14, 2018
Messages
1,396
Trophies
0
Age
36
Location
AZ
XP
1,539
Country
United States
@F4mouZSt4r

as The OP Said

My console bricked after my NAND restore and i haven't dump the keys before the brick. If i use LockpickRCM i don't getting the full keys because some says "corrupted"

The console is bricked.. Master keys etc are f***king useless he needs his biskeys to restore not master keys etc..


@MK7Hax1811
You need to restore a nand backup that was good and working. with hekate, hekate does not need emmc to boot..
Restore your old nand image and the matching boot0/1 and aslong as you launch again with hekate to OFW you should get back in , hekate bypasses fuse check so will load old version of system.

And if you want keys, after you have a bootable nand.. Use LockpickRCM and load in rcm mode. This will give you soft decrypt keys and biskeys
 
Last edited by Canna,

Tafich

Member
Newcomer
Joined
Jun 25, 2020
Messages
9
Trophies
0
Age
31
XP
65
Country
Mexico
Did you manage to fix this? I'm in a similar situation. I restored to a corrupted nand (only pkg2 is corrupted) and I get pkg2 decryption error every time I try to boot on CFW, OFW or dump my prod.keys with lockpick.

I was instructed by Ctcaer to rebuild my mmc but my prod.key file is corrupted as it shows the same error (Invalid NCA header). Do a downloaded prod.keys would serve me at all?

What can I do guys?? Is there another way to solve this? I guess I'm in need of someone talented.
 
Last edited by Tafich,

Olmectron

Well-Known Member
Member
Joined
Dec 31, 2012
Messages
2,657
Trophies
2
Age
31
Location
A game
XP
3,855
Country
Mexico
Did you manage to fix this? I'm in a similar situation. I restored to a corrupted nand (only pkg2 is corrupted) and I get pkg2 decryption error every time I try to boot on CFW, OFW or dump my prod.keys with lockpick.

I was instructed by Ctcaer to rebuild my mmc but my prod.key file is corrupted as it shows the same error (Invalid NCA header). Do a downloaded prod.keys would serve me at all?

What can I do guys?? Is there another way to solve this? I guess I'm in need of someone talented.
I think I could try helping you.
 
  • Like
Reactions: Tafich

Canna

Bad Ass Poisonous Mushroom
Member
Joined
Jul 14, 2018
Messages
1,396
Trophies
0
Age
36
Location
AZ
XP
1,539
Country
United States
Did you manage to fix this? I'm in a similar situation. I restored to a corrupted nand (only pkg2 is corrupted) and I get pkg2 decryption error every time I try to boot on CFW, OFW or dump my prod.keys with lockpick.

I was instructed by Ctcaer to rebuild my mmc but my prod.key file is corrupted as it shows the same error (Invalid NCA header). Do a downloaded prod.keys would serve me at all?

What can I do guys?? Is there another way to solve this? I guess I'm in need of someone talented.

Do as Ctcaer says.

Choidujour.exe will say invalid keys or show warnings. Delete the keys that are warned about from your prod.key /key file etc.
And choidujour will move and process ya fw package.

When you use hacdiskmount to push the files to the switch make sure you test and save entorpy, (Enter the biskeys in the correct boxes
 

ragnahawk

New Member
Newbie
Joined
Jan 17, 2021
Messages
2
Trophies
0
Age
40
XP
43
Country
United States
I’m trying to recover data from a decimated switch. And this feels like a start, but I need to understand more. Is there a primer for how the keys are stored and what they are used for? I’ve figured you can’t just yank the chip board out of one switch and plop it into another because it’s encrypted with keys that may be situated elsewhere on the machine, but where they are and if they’re even accessible given the damage to my device is what I’m trying to figure out.
 
Last edited by ragnahawk,

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    ButterScott101 @ ButterScott101: +1