Hacking Huge exploit found on firmware 3.0.0: smhax

Status
Not open for further replies.

Ceuse

Well-Known Member
Member
Joined
Jul 23, 2017
Messages
134
Trophies
0
Age
36
XP
769
Country
Germany
I thought it ment you can register an. Service/code. Depending if the service runns with root or not you could use that to create a new root account outside of that service (linux noob with bad english again ^^) with the update i merly ment that you could update and while it would close fhe sm haxx entry point you would still keep the new root account for homebrew down the line (depending what the update does or does not overwrite).
 

Nealio

Active Member
Newcomer
Joined
Mar 9, 2014
Messages
26
Trophies
1
Age
37
XP
1,970
Country
United States
Very excited about this news. I've been on the fence about whether or not to get a Switch for a little while now... but with the possibility of homebrew in sight, I figured I had better try to find one on firmware 3.0.0 or less sooner rather than later.

Here's my quick story about finding a Switch today.

I was looking online to see if anyone had them in stock at the normal $299 price, but I didn't have any luck with that route. I did, however, see that on GameStop's home page they mention that a lot of stores have them in stock. Their online stock checker isn't working, so I called my local store and the guy picked up the phone stating "Thanks for calling GameStop where we have Nintendo Switch's in stock!" Anyhow, I just picked up the grey joy-con system for $299.99 + tax. The first thing I did was boot it straight into recovery mode (by holding the volume buttons while powering on) to verify the firmware version, and bam... 2.2.0! Nice!

So yeah, if you're looking for a Switch, check your local GameStop!
 
Last edited by Nealio,
  • Like
Reactions: digipimp75

geodeath

Well-Known Member
Member
Joined
Oct 26, 2006
Messages
300
Trophies
0
Location
London
XP
752
Country
Stupid question, is leaving the switch on airplane mode enough to avoid updating? On 3.0 atm

Yeah. I forgot mine on flight mode because i travelled not a week after getting it on launch day and left it like that forever, since i did not care for online stuff and digital purchases. Unless there would be a compelling enough reason (such as mario needing an upgrade) i would leave it like this forever.
 
  • Like
Reactions: Garrincho

TobiasAmaranth

Well-Known Member
Member
Joined
Feb 6, 2009
Messages
456
Trophies
1
Age
38
Location
Texas
Website
werewolfdarkarts.com
XP
2,616
Country
United States
  • For your update question (I don't really understand it) it seems like you're attempting to change the update that's placed on switch carts? This is impossible since switch carts are Read Only Memory (ROMs) which by no circumstances are rewriteable. Also, instead of this, if you're below 3.0 you could simply manually update using the install service, same way we spoof on the Wii U, and spoofed on the 3ds, except with a full system update. You may be wondering if this is possible because of efuses, well, it is, since when booting it'll check your firmware, and if you have too few fuses burnt, it'll simply burn those fuses and boot regularly, effectively updating your console without the need of a game card. (Thanks to @TerraPhantm for letting me know about this, since I cant read.)
So yeah, I hope you find my answers to your questions satisfactory, sadly it's not as simple as you make it seem. I wish it was, but it isn't. Have a good day. :)

That does make me wonder something about the e-fuse and CFW...

If you're running 3.0.0, for example, and CFW beyond that, wouldn't the system brick after exiting the updated CFW? Wouldn't the system's CFW updates modify the efuses and then cause the system to lock you out? If it's an on-boot thing, it just feels like it's going to be really difficult this time around. Damn technology, actually getting good. :O
 

xxNathanxx

Well-Known Member
Member
Joined
Oct 28, 2011
Messages
403
Trophies
1
XP
533
Country
New Caledonia
Oh boy, I updated just two days ago to check out a trailer for one of the games in the news overview. Guess I'll have to catch the next train.
 

Yami Anubis ZX

Well-Known Member
Member
Joined
Mar 20, 2016
Messages
208
Trophies
0
Age
37
XP
587
Country
United States
That does make me wonder something about the e-fuse and CFW...

If you're running 3.0.0, for example, and CFW beyond that, wouldn't the system brick after exiting the updated CFW? Wouldn't the system's CFW updates modify the efuses and then cause the system to lock you out? If it's an on-boot thing, it just feels like it's going to be really difficult this time around. Damn technology, actually getting good. :O


Well Xbox 360 and PS3 also had efuses but there was a way to bypass, by using a modchip and flashing them and yes people tell me, if you look inside the Switch, there's not much room and blah blah blah but even then where there is a will, there is a way, so there may eventually be a mod chip for the Switch, where it's inside or outside, there will be something like a mod chip to bypass efuses and also it's selling super well, so hackers who by a recent version, whether it is above 3.00 or not, it will be hacked because of a simple fact, challenge and mod chip makers can make money at it aswell.
 

GerbilSoft

Well-Known Member
Member
Joined
Mar 8, 2012
Messages
2,395
Trophies
2
Age
34
XP
4,250
Country
United States
So yeah, I hope you find my answers to your questions satisfactory, sadly it's not as simple as you make it seem. I wish it was, but it isn't. Have a good day. :)
To add on to this: Assuming it's like 3DS, there's no real concept of "root" in the sense of Unix root or Windows Administrator on 3DS and Switch. Instead, there are privileged processes and permissions lists. On 3DS, processes with a PID lower than the total number of ARM11 FIRM sysmodules are automatically granted all permissions, since it's assumed that those PIDs are all allocated on startup. Other titles have lists that indicate which permissions they get when they're loaded. These permissions are granted by Nintendo when they authorize and sign the title, so the OS assumes that if the signature is valid, then the permissions are also valid.

Injecting a service that has "all permissions" is basically the equivalent of having root access, which means the ability to run custom code. Things like CIA installers (or the equivalent) would require patching out signature checks, and I'm not sure if that's doable with just service-level access.
 
Last edited by GerbilSoft,

3dsgametime

Active Member
Newcomer
Joined
Aug 7, 2015
Messages
27
Trophies
0
Age
50
Location
Toronto
XP
130
Country
Canada
Is there any way to know which Switch systems would still be running 3.0 or lower? They have 5 right now at my local Toys'R'Us and I asked them to put one on hold for me, but I wondered if anyone here had something to identify which systems would not have been updated. The guy on the phone at Toys'r'US said they just got the shipment in, and I know 3.0.1 was released on July 31, so could it be these systems hve been updated already?

I know there were some threads before on how to get a 3DS that was the right firmware to use with the Gateway Card, etc... Just wondered if anyone has found something similar to identify lower FW Switch systems.
 
D

Deleted-355425

Guest
Is there any way to know which Switch systems would still be running 3.0 or lower? They have 5 right now at my local Toys'R'Us and I asked them to put one on hold for me, but I wondered if anyone here had something to identify which systems would not have been updated. The guy on the phone at Toys'r'US said they just got the shipment in, and I know 3.0.1 was released on July 31, so could it be these systems hve been updated already?

I know there were some threads before on how to get a 3DS that was the right firmware to use with the Gateway Card, etc... Just wondered if anyone has found something similar to identify lower FW Switch systems.


it will be 2.2.0 or lower right now.
 

3dsgametime

Active Member
Newcomer
Joined
Aug 7, 2015
Messages
27
Trophies
0
Age
50
Location
Toronto
XP
130
Country
Canada
Ok. Thanks for the reply. That's great news. I will go and pick up the one they're holding for me till end of day today and leave it on 2.2.0 for now.. :)

Thanks again!
 

g4jek8j54

Well-Known Member
Member
Joined
Aug 30, 2007
Messages
532
Trophies
0
Website
Visit site
XP
437
Country
United States
I never bothered to upgrade my switch from the launch day fw (put it on flight mode on a flight few days after launch, never put it back lol), not for conservation or to be able to run hacks easily but just because i hate nagging screens to update. I was never interested in any online modes or buying digital (esp. from nintendo).

With this in mind, and given i prefer to keep it where it is... which games do not need an upgrade from the physically released ones? Was thinking of maybe getting Street Fighter or Arms if i find it cheap and the mario + rabbids game is up my alley too. Do these require/include an upgrade? Which other games would you suggest that do not require an upgrade, from physical (obviously) releases only?

That sounds a lot like me. I didn't get a Switch on launch day, but I did manage to get one near the end of March, and it still has the 1.0.0 firmware on it. It has never been connected to the internet, and thus far, the only game that I have played on it is Breath of the Wild. I am guessing that I will be on 1.0.0 until at least Christmas, since I have no desire to get any new games anytime soon, and no desire to connect the Switch to the internet. I would like to play Snipperclips, but I prefer to buy physical copies of games, so that took it out of the equation. I figured that this "no update" policy of mine would hurt me on potential exploits (I'm not all that interested in Switch homebrew, to be honest), but according to this post, this post, and this page, 1.0.0 has a web browser, which surprised me to find out. Although, I'm not at all sure how it could be accessed.

I am also wondering what games don't require any updates at all (including to 2.x.x). I'm assuming, though I could be wrong, that the physical launch games do not require any update, but I'd be nice to know for sure. It may also be necessary to look for old used copies, since I'm guessing that it's possible that newer versions of those games will require an update (perhaps even to 3.0.1). Shovel Knight looks interesting to me, but it appears that a physical copy of Shovel Knight: Treasure Trove is available for the Wii U, so I suppose I could also get it on that, to satisfy me for awhile.
 

Enryx25

Well-Known Member
Member
Joined
Jan 25, 2016
Messages
703
Trophies
0
XP
1,732
Country
Italy
disclaimer, I'm not certain on what i'm saying, it may be wrong, feel free to correct me.
  • We don't have full access to everything, while having access to all services with arbitrary code execution is a lot, it does not mean the system is fully cracked. For example, you wouldn't be able to install a coldboot system, pirate games, patch out signature checks or ignore game cart updates. We're not at the point where we can just install a cfw

Many people will be angry.
 
Last edited by Enryx25,

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
That does make me wonder something about the e-fuse and CFW...

If you're running 3.0.0, for example, and CFW beyond that, wouldn't the system brick after exiting the updated CFW? Wouldn't the system's CFW updates modify the efuses and then cause the system to lock you out? If it's an on-boot thing, it just feels like it's going to be really difficult this time around. Damn technology, actually getting good. :O

Yes, people will brick their Switches.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    Maximumbeans @ Maximumbeans: butte