Homebrew Question running memloader on v1 ipatched sx core switch

Rebeca

Member
OP
Newcomer
Joined
Oct 1, 2020
Messages
18
Trophies
0
Age
26
XP
88
Country
Brazil
I ran incognito on a v1 ipatched switch without a nand backup and bricked it. I had given up fixing it for now until I realized that I could run most payloads on it, including Hekate and memloader. Problem is, whenever I try to mount emmc via usb my PC gives a "Unknown USB device (device descriptor request failed)". I have tried uninstalling on the device manager multiple times, but it doesn't work. I know the problem is not my PC or cable since I have an unpatched switch and I'm able to mount it easily. Is there any way to get memloader to run? I can't seem to be able to downgrade/restore my nand without it.
 

DragarX

Well-Known Member
Member
Joined
Apr 26, 2016
Messages
113
Trophies
0
Age
31
XP
345
Country
Australia
Don't quote me on this but I'm pretty sure this won't work due to the tegra usb exploit being patched and therefore not allowing any communication with your switch through rcm over usb.
 

Rebeca

Member
OP
Newcomer
Joined
Oct 1, 2020
Messages
18
Trophies
0
Age
26
XP
88
Country
Brazil
Ipatched unit uses xusb, so memloader may not work. Did you try hekate UMS?
Yes, I get timed out or disconnected every time.

--------------------- MERGED ---------------------------

I'd suggest try this payload with the files placed on your sd. Should allow you to copy the files from sd to nand using only your switch.

https://github.com/suchmememanyskill/TegraExplorer

TegraExplorer does run fine. I'm trying to follow the manual downgrade guide though, but I assume that's not possible for me now, right?
 

Rebeca

Member
OP
Newcomer
Joined
Oct 1, 2020
Messages
18
Trophies
0
Age
26
XP
88
Country
Brazil
https://suchmememanyskill.github.io/guides/unbrick/#mmc-rebuild

I think you should read this guide, and it doesn't require to use memloader/UMS.
Choidujour downgrade guide is outdated.
Will the system restore script activate autorcm? The guide says that following it will activate autorcm?

I'm getting errcode 13, dsc No Fat when dumping firmware on TegraExplorer.

Tried running EmmcHaccGen with my other switch's firmware dump (they were both on 10.2) and got "Unable to create NCA class. Is your keyset file valid?"

On another note, lockpick_rcm only managed to get 81 keys. It showed "unable to derive package2 key" and "missing fs keys. skipping es/ssl keys".
 
Last edited by Rebeca,

HenryMin

Well-Known Member
Member
Joined
Jun 19, 2020
Messages
141
Trophies
0
XP
1,139
Country
Korea, South
Will the system restore script activate autorcm? The guide says that following it will activate autorcm?

I'm getting errcode 13, dsc No Fat when dumping firmware on TegraExplorer.

Tried running EmmcHaccGen with my other switch's firmware dump (they were both on 10.2) and got "Unable to create NCA class. Is your keyset file valid?"

On another note, lockpick_rcm only managed to get 81 keys. It showed "unable to derive package2 key" and "missing fs keys. skipping es/ssl keys".

You don't need to dump firmware, just get it from other source :P
AFAIK you can disable autorcm using NXNandManager, so open BOOT0.bin (generated by emmchaccgen or Choidujour), and disable autorcm, then falsh it using the tegraexplorer script.
 

Rebeca

Member
OP
Newcomer
Joined
Oct 1, 2020
Messages
18
Trophies
0
Age
26
XP
88
Country
Brazil
You don't need to dump firmware, just get it from other source :P
AFAIK you can disable autorcm using NXNandManager, so open BOOT0.bin (generated by emmchaccgen or Choidujour), and disable autorcm, then falsh it using the tegraexplorer script.
Ok. Can't get EmmcHaccGen to work with my prod.keys though. They are fine, I've tested them on NxNandManager, but I get "Error: Unable to decrypt NCA header. The file is not an NCA file or the header key is incorrect." on EmmcHaccGen for some reason.

Update: Managed to get EmmcHaccGen to work by using the latest release of Lockpick RCM, performed system restore via Tegra Explorer, still stuck on the Nintendo Switch Joycon screen.
 
Last edited by Rebeca,

DragarX

Well-Known Member
Member
Joined
Apr 26, 2016
Messages
113
Trophies
0
Age
31
XP
345
Country
Australia
Ok. Can't get EmmcHaccGen to work with my prod.keys though. They are fine, I've tested them on NxNandManager, but I get "Error: Unable to decrypt NCA header. The file is not an NCA file or the header key is incorrect." on EmmcHaccGen for some reason.

Update: Managed to get EmmcHaccGen to work by using the latest release of Lockpick RCM, performed system restore via Tegra Explorer, still stuck on the Nintendo Switch Joycon screen.
Do you not have a working joycon or rail? This guide should help if that's the case.
https://gbatemp.net/threads/how-to-skip-the-connect-joycons-system-init-screen.559745/

also you may not have seen this, but if these caps are damaged it will cause you to be stuck on that screen too
https://ibb.co/qRrrm97
 
Last edited by DragarX,

Rebeca

Member
OP
Newcomer
Joined
Oct 1, 2020
Messages
18
Trophies
0
Age
26
XP
88
Country
Brazil

Rebeca

Member
OP
Newcomer
Joined
Oct 1, 2020
Messages
18
Trophies
0
Age
26
XP
88
Country
Brazil
did you run the system wipe script after injecting your new firmware?
Ah. That might be the problem. When I try to run the system wipe script I get "Mounting SYSMMC... System failed to mount!". I've tried formatting the SD Card in both ExFat and Fat32, tried injecting Tegra Explorer from both the SX OS menu and Hekate. This one script won't run. When I try to acess Emmc on Tegra Explorer I also get an error, "err code: 13 dsc: NO FAT".
 

DragarX

Well-Known Member
Member
Joined
Apr 26, 2016
Messages
113
Trophies
0
Age
31
XP
345
Country
Australia
Ah. That might be the problem. When I try to run the system wipe script I get "Mounting SYSMMC... System failed to mount!". I've tried formatting the SD Card in both ExFat and Fat32, tried injecting Tegra Explorer from both the SX OS menu and Hekate. This one script won't run. When I try to acess Emmc on Tegra Explorer I also get an error, "err code: 13 dsc: NO FAT".
That would seem to indicate that the keys you have are incorrect. Either the dump was incorrect or maybe your keys are corrupt.
 

Rebeca

Member
OP
Newcomer
Joined
Oct 1, 2020
Messages
18
Trophies
0
Age
26
XP
88
Country
Brazil
That would seem to indicate that the keys you have are incorrect. Either the dump was incorrect or maybe your keys are corrupt.
I was running into this error before even performing the system restore. Nonetheless, is there any way to check the integrity of my keys?
Edit: I was looking at my Prodinfo in HxD and I realized that Incognito did work and at offset 0x0250 where my system's serial number should be it shows XAW00000000000. Now, if my switch was unpatched I'm fairly certain this wouldn't stop it from booting, but as it is, could this be the cause of the brick?
 
Last edited by Rebeca,

DragarX

Well-Known Member
Member
Joined
Apr 26, 2016
Messages
113
Trophies
0
Age
31
XP
345
Country
Australia
I was running into this error before even performing the system restore. Nonetheless, is there any way to check the integrity of my keys?
Edit: I was looking at my Prodinfo in HxD and I realized that Incognito did work and at offset 0x0250 where my system's serial number should be it shows XAW00000000000. Now, if my switch was unpatched I'm fairly certain this wouldn't stop it from booting, but as it is, could this be the cause of the brick?
That's what incognito is meant to do so that shouldn't cause a brick. You could manually input your actual serial and see if that helps, but I can't see it fixing anything.

I'm not sure how you can verify your keys. If your keys are incorrect though, you will not be able to restore or repair a backup.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BigOnYa @ BigOnYa:
    What did you learn?
  • BakerMan @ BakerMan:
    since my sister said manga was a good gateway into anime, i decided to get a manga, i was going to get one punch man, but volume 1 wasn't there
  • AncientBoi @ AncientBoi:
    Well, what about Dr. What? Don't leave him out. @BigOnYa
    +2
  • BakerMan @ BakerMan:
    and so i got mashle instead, which is actually quite good
  • O @ OhHiNick:
    GUYS YOU CAN LAUNCH HEALTH AND SAFETY INFO IN AROMA NOW
  • Xdqwerty @ Xdqwerty:
    @BakerMan,i only watched anime
  • BakerMan @ BakerMan:
    for anyone wondering what that is, basically, it's about the one person in the world without magic, instead he's just dummy strong
  • BigOnYa @ BigOnYa:
    Dr. What and Dr. Where got lost together somewhere in time, Dr. When is looking for them
    +1
  • BakerMan @ BakerMan:
    What about Dr. How?
  • BakerMan @ BakerMan:
    OR DR. WHY?
  • O @ OhHiNick:
    @Xdqwerty sorry i get excited when i get to see what type of laser the wii u uses
  • AncientBoi @ AncientBoi:
    They ALL went to Nurse Why's house
  • BakerMan @ BakerMan:
    fun fact: SCPs started from some Dr. Who fanfic or smth on 4chan
  • BigOnYa @ BigOnYa:
    Dr How and Why, will be in the prequel
    +2
  • Xdqwerty @ Xdqwerty:
    @BakerMan, or dr when
  • O @ OhHiNick:
    dr what
    +1
  • AncientBoi @ AncientBoi:
    ooohhh the steamy scene with Nurse Why. omg :blush:
    +1
  • BigOnYa @ BigOnYa:
    @Xdqwerty is Dr. Wut
    +2
  • BigOnYa @ BigOnYa:
    My wifey gets mad and tells me its a bad habit to bite your nails, even though I told her I washed my feet first.
  • Psionic Roshambo @ Psionic Roshambo:
    Dr Strange is a gynecologist for prostitutes.
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    Going where lots of men have gone before
    +2
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, i tear off my nails
  • BigOnYa @ BigOnYa:
    Nuh it was a joke, but I used to bite my nails when I was young, but when I started doing construction work and seen what crap was under my nails, I stopped.
  • Xdqwerty @ Xdqwerty:
    What i said isnt a joke
    Xdqwerty @ Xdqwerty: What i said isnt a joke