Hacking Huge exploit found on firmware 3.0.0: smhax

Status
Not open for further replies.

ARVI80

Well-Known Member
Member
Joined
Feb 25, 2016
Messages
197
Trophies
0
Age
43
Location
UK
XP
315
Country
What's to tell, I don't have a clue what other people are looking at and why but certificates are always a good way to lock a system down, sometimes replacing something pinned down in the right place is just what you need, especially when it's been taken for granted.
 

ARVI80

Well-Known Member
Member
Joined
Feb 25, 2016
Messages
197
Trophies
0
Age
43
Location
UK
XP
315
Country
It would be better attained via serial com to pcb if a documented pinout for a switch exists that is, can't see putty getting anywhere otherwise.
 
  • Like
Reactions: Deleted User

Kilim

ReiNX Official Dad™
Member
Joined
May 14, 2017
Messages
220
Trophies
0
Age
31
XP
1,630
Country
United States
Makes no difference. The exploit works on 3.0.0 and below.
while i understand this, i also understand that 1.0 has many features "disabled", what im worried about is installing CFW or even getting to HB entry points down the line will require some of these 'features' perse
 

ARVI80

Well-Known Member
Member
Joined
Feb 25, 2016
Messages
197
Trophies
0
Age
43
Location
UK
XP
315
Country
You would need to google or ask around. To putty into the system would not be an easy task by any means. Even if access is available at some point, timing would be bitch and you would be running blind then encryption would be even worse.
 

DocAmes1980

Well-Known Member
Member
Joined
Oct 31, 2016
Messages
873
Trophies
0
Age
43
XP
975
Country
United States
while i understand this, i also understand that 1.0 has many features "disabled", what im worried about is installing CFW or even getting to HB entry points down the line will require some of these 'features' perse

Why worry? If that happens then you could use a cart to update to something equal to or less than 3.0.0. Not like you'll be hosed if it turns out that the entry point requires a browser.
 
D

Deleted User

Guest
You would need to google or ask around. To putty into the system would not be an easy task by any means. Even if access is available at some point, timing would be bitch and you would be running blind then encryption would be even worse.

yeah you have a point mate will be a pain in the ass with putty , would be good to know if you could use the USB C to Serial Adapter ? if its not only for Charging
 

Kilim

ReiNX Official Dad™
Member
Joined
May 14, 2017
Messages
220
Trophies
0
Age
31
XP
1,630
Country
United States
Why worry? If that happens then you could use a cart to update to something equal to or less than 3.0.0. Not like you'll be hosed if it turns out that the entry point requires a browser.
yeah i understand, but for some reason i feel like Nintendo would learn a lesson (lol) and keep updating carts with a newer system version the longer i wait (assuming they manufacture newer carts) so im a bit worried
 

DocAmes1980

Well-Known Member
Member
Joined
Oct 31, 2016
Messages
873
Trophies
0
Age
43
XP
975
Country
United States
yeah i understand, but for some reason i feel like Nintendo would learn a lesson (lol) and keep updating carts with a newer system version the longer i wait (assuming they manufacture newer carts) so im a bit worried

You know I didn't think about that. Even if Nintendo decides to start bundling higher firmware updates with Arms of Splatoon 2 it's not like finding a used copy with the old update would be hard.
 
D

Deleted User

Guest
yeah i understand, but for some reason i feel like Nintendo would learn a lesson (lol) and keep updating carts with a newer system version the longer i wait (assuming they manufacture newer carts) so im a bit worried

can you not make your own thread with those questions they have 0 todo with the exploit, if you dont want any updates turn off your wifi
 

Tilde88

Well-Known Member
Member
Joined
Feb 16, 2015
Messages
295
Trophies
0
Age
36
XP
1,068
Country
United States
well good question idk if its so easy to remove the initailize because why they would try to get the trust zone key ?

--------------------- MERGED ---------------------------

but wait if the switch is running on an free bsd kernel is there any chance to run ssh?

Well sure, if you can add it as a service.
And then start the service.
And then make it listen to a port.
And then get credentials to login.
And then elevate as superuser.
And then bypass trust zone.
And then make an entrypoint that loads alongside trust zone.
And then make a payload that works and loads in the entrypoint.
And then get an exploit compiled.
Then at that point SSH will be not only working, but useful.
GO DO IT!
 
  • Like
Reactions: Deleted User
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    The Real Jdbye @ The Real Jdbye: loved nes remix, but hated having to play Baseball, Tennis and Golf in order to progress