Hacking Hardware Picofly - a HWFLY switch modchip

Mansi

Well-Known Member
Newcomer
Joined
Jan 14, 2023
Messages
70
Trophies
0
Age
30
XP
331
Country
Belarus
Sorry, what do you mean with the system version check?
This means that if you have an older firmware version, the glitch may not work. Because it uses a different hacking method.

Why could old set-top boxes of a certain version be flashed, but not with a new firmware version? Because!
 
  • Like
Reactions: FruithatMods

Tafty

Well-Known Member
Member
Joined
Sep 23, 2016
Messages
116
Trophies
0
Age
36
XP
923
Country
Can you show a picture of how you wired things up? Especially the CPU flex cable to the Pico
Its wired up the same way a hwfly/sx is wired up except I've ran manual wires instead of the flex... I've attached a photo for reference but this is purely setup for testing at the minute
 

Attachments

  • 20230206_180741.jpg
    20230206_180741.jpg
    848.6 KB · Views: 101

Piorjade

Well-Known Member
Member
Joined
Nov 8, 2015
Messages
142
Trophies
0
XP
407
Country
Gambia, The
Its wired up the same way a hwfly/sx is wired up except I've ran manual wires instead of the flex... I've attached a photo for reference but this is purely setup for testing at the minute
Isn't that the CPU flex cable on the bottom right of the chip?
 

Tafty

Well-Known Member
Member
Joined
Sep 23, 2016
Messages
116
Trophies
0
Age
36
XP
923
Country
Yes that is the cpu flex and then I have manually soldered a cable to sp1 and then to the Pico...
 

vittorio

Well-Known Member
Member
Joined
May 12, 2014
Messages
243
Trophies
0
Age
26
XP
960
Country
Italy
cpu flex have 1 cable?
Post automatically merged:

did you see the hekate config well?
Post automatically merged:

can try with this @Tafty
 

Attachments

  • SXOS_to_atmosphere.rar
    3.9 MB · Views: 45
Last edited by vittorio,
  • Like
Reactions: szubiennica

Adran_Marit

Walküre's Hacker
Member
Joined
Oct 3, 2015
Messages
3,781
Trophies
1
Location
42*South
XP
4,551
Country
Australia
It boots hekate now.

And this is what happens when you try to launch hos
not sure it'll work but try running lockpick_rcm
Post automatically merged:

@Adran_Marit any ideas? you seem to be pretty knowledgeable about this stuff :ha:
Boot encryption key missing 🤔

So we are getting rcm, hekate boots, but it is failing to boot HOS. The bek is either missing or the wrong key for FW.

Possibly try lockpick RCM first via hekate, if not then the bek might be hard coded in the picofly code? (this is just speculation)

Yeah I'm tech minded but not smart enough to do this XD, but once someone gets it going I can translate down for end users
Post automatically merged:

Yes that is the cpu flex and then I have manually soldered a cable to sp1 and then to the Pico...

What pin on the flex is it wired to? I might have to break out my lite after work and do some testing 🤔
 
  • Like
Reactions: saladus

Tafty

Well-Known Member
Member
Joined
Sep 23, 2016
Messages
116
Trophies
0
Age
36
XP
923
Country
Boot encryption key missing 🤔

So we are getting rcm, hekate boots, but it is failing to boot HOS. The bek is either missing or the wrong key for FW.

Possibly try lockpick RCM first via hekate, if not then the bek might be hard coded in the picofly code? (this is just speculation)

Yeah I'm tech minded but not smart enough to do this XD, but once someone gets it going I can translate down for end users
Post automatically merged:



What pin on the flex is it wired to? I might have to break out my lite after work and do some testing 🤔
lockpick rcm doesnt load at all.

and its wired to both sp1 and sp2, its bridged on the flex.

the original photo on page 1 is setup the same way hence why i did it this way aswell.
 

Tafty

Well-Known Member
Member
Joined
Sep 23, 2016
Messages
116
Trophies
0
Age
36
XP
923
Country
you can try the payload i sent you
let me see what happens give me a minute
Post automatically merged:

you can try the payload i sent you
doesn't load HOS either bud, same problem

yours does load lockpick....which then black screens and doesnt do anything
Post automatically merged:

dont know if this is useful for anyone here, but i managed to dump the sdloader using hwfly toolbox....it wouldnt let me dump the firmware obvs.
 

Attachments

  • dumped_sdloader.zip
    22.2 KB · Views: 25
Last edited by Tafty,

Tafty

Well-Known Member
Member
Joined
Sep 23, 2016
Messages
116
Trophies
0
Age
36
XP
923
Country
Try this pack
if it wont load stock hekate and stock atmosphere then it isnt going to load any of these.
i tested it anyway and same thing missing BEK. we wont magically get it working with a payload at this point.
 

Piorjade

Well-Known Member
Member
Joined
Nov 8, 2015
Messages
142
Trophies
0
XP
407
Country
Gambia, The
if it wont load stock hekate and stock atmosphere then it isnt going to load any of these.
i tested it anyway and same thing missing BEK. we wont magically get it working with a payload at this point.
Then how do we usually get the BEK? Is it something HWFLY / SX Core do too before booting the payload?
Or is it that this firmware somehow writes an old payload to BOOT0?
 

Tafty

Well-Known Member
Member
Joined
Sep 23, 2016
Messages
116
Trophies
0
Age
36
XP
923
Country
What happened if you restore a boot0 image from a Hwfly and try too boot Atmosphere?
wont let you fails, and trying to overwrite the sdloader loader with the hwfly one DOES work, but after reboot the switch fails to to glitch.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    Maximumbeans @ Maximumbeans: butte