Hacking PSA: Reports of Fusee gelee patched units in the wild

  • Thread starter Deleted-442439
  • Start date
  • Views 85,043
  • Replies 315
  • Likes 10

bitteorca

Member
Newcomer
Joined
Jul 12, 2018
Messages
21
Trophies
0
Age
28
XP
100
Country
United States
Can you try tegrarcmsmash with biskeydump ?

And run this command when you connect your RCM switch to your pc.

TegraRcmSmash.exe -w biskeydump.bin BOOT:0x0

Then capture the output on the command line windows and post it here please.
My bad it wasn't letting me reply to your post but I figured it out I had to remove your hyperlink

Here's the output:
tegrasmash.png
 

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,005
Trophies
2
Age
29
Location
New York City
XP
13,371
Country
United States
I purchased a Switch with the serial number XAW700183***** and I can confirm that payload injection doesn't work.

Steps to recreate:
1. Copied the Switch Starterkit root files to the root of my FAT32 SDcard from my PC
2. Inserted SDcard into Switch, then booted into RCM mode with paperclip jig
3. Plugged Switch into PC, used Zandig to install the libusbK drivers, confirmed APX came up as a device in device manager
4. Tried to run the NX bootkit 64-bit executable, the Switch screen remains black and the cmd prompt window displayed some code then counted down from 5 seconds to close the window

Is it possible that my USB-C cable (came with my phone) is the culprit here or is it likely that I have a patched Switch?

My bad it wasn't letting me reply to your post but I figured it out I had to remove your hyperlink

Here's the output:
View attachment 135507
So it appears these units have been smuggled into the US but we have another problem: we don't know the serial number cut-off for un-patched units...I think. Need to double check that spreadsheet...
 

gnilwob

Well-Known Member
Member
Joined
Mar 16, 2008
Messages
204
Trophies
1
XP
644
Country
Hong Kong
Lucky me.
Just to explain.

This is from a working console.
2018-07-13_5-20-39.png

I asked you to run the biskeydump because you were not sure about your cable.
But from the command line output, it can send data using your cable.

Next, see the different 0x0000(not working) and 0x7000(working) output?
 

bitteorca

Member
Newcomer
Joined
Jul 12, 2018
Messages
21
Trophies
0
Age
28
XP
100
Country
United States
Just to explain.

This is from a working console.
View attachment 135511

I asked you to run the biskeydump because you were not sure about your cable.
But from the command line output, it can send data using your cable.

Next, see the different 0x0000(not working) and 0x7000(working) output?
That's right, it also looked identical to the screen that came up when I ran Hekate. I know for a fact it said "Smashed with 0x0000 stack" as well

The girl at the counter even offered me a used unit, damn. Does anyone have any news on the webkit exploit Deja vu?
 

Scoob0

New Member
Newbie
Joined
Jul 12, 2018
Messages
4
Trophies
0
Age
40
XP
141
Country
United States
First time posting, but wanted to include info on my switch I bought on June 29 through Newegg. Its very close to the serial bitteorca posted, but mine does work im running SX Pro and been playing backups and even updated to 5.1. Hope this helps in figuring out where the line is between patched and unpatched.

Serial: XAW700119XXX
Serial on device matches serial on box: Yes
Region: US
Firmware: 4.1.0
Color option: Blue / Red
Store: Newegg
Was a bundle (if yes, which): No
Purchase date: June 29 2018
Fusée Gelée works: Yes
 
Last edited by Scoob0,

gnilwob

Well-Known Member
Member
Joined
Mar 16, 2008
Messages
204
Trophies
1
XP
644
Country
Hong Kong
First time posting, but wanted to include info on my switch I bought on June 29 through Newegg. Its very close to the serial bitteorca posted, but mine does work im running SX Pro and been playing backups and even updated to 5.1. Hope this helps in figuring out where the line is between patched and unpatched.

Serial: XAW700119XXX
Serial on device matches serial on box: Yes
Region: US
Firmware: 4.1.0
Color option: Blue / Red
Store: Newegg
Was a bundle (if yes, which): No
Purchase date: June 29 2018
Fusée Gelée works: Yes

If it is ok, can you also post it here please, https://gbatemp.net/threads/switch-firmware-by-serial-number.481215/page-59
So people who checks on serial number can use yours as an indicator.
Thanks.


That's right, it also looked identical to the screen that came up when I ran Hekate. I know for a fact it said "Smashed with 0x0000 stack" as well

The girl at the counter even offered me a used unit, damn. Does anyone have any news on the webkit exploit Deja vu?
Please also post your serial and model information here, https://gbatemp.net/threads/switch-firmware-by-serial-number.481215/page-59
Thanks.
 
Last edited by gnilwob,
  • Like
Reactions: Draxzelex

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,005
Trophies
2
Age
29
Location
New York City
XP
13,371
Country
United States
XAW700119XXX = not patched
XAW700183XXXXX = patched
So 11 is still safe, but 18 isn't. That leaves like 7 more possible Switch serial numbers, at least. And while there is no word yet on when Deja Vu will be released, this is what it looks like in action:
 

Essometer

Needs data
Member
Joined
Oct 22, 2010
Messages
732
Trophies
1
Age
32
Location
Bielefeld
Website
none.de
XP
3,573
Country
Germany
seems to be a low serial, whats the date code on the switch?

might be worth trying a different USB port/pc, unfortunately I feel like anyone having troubles with setup at this point are going to be "arrrgh its a patched switch!!!!"
XAW700183 is actually a really high serial number. It is just that assembly line XAW7 is pretty slow in producing switches. According to my
serial list, it is very possible that this serial is another cutoff point for patched switches.
 
Last edited by Essometer,

SuppaMario

Member
Newcomer
Joined
Jul 11, 2018
Messages
9
Trophies
0
Age
34
XP
76
Country
United States

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,005
Trophies
2
Age
29
Location
New York City
XP
13,371
Country
United States
XAW700183 is actually a really high serial number. It is just that assembly line XAW7 is pretty slow in producing switches. According to
serial list, it is very possible that this serial is another cutoff point for patched switches.
An XAW700119XX doesn't have it patched so its a little more specific. Similar to the Japanese ones, the cutoff point is not XAJX004, butXAJX0043 since there were people who could still do the exploit on the former serial number.
 

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
XAW700183 is actually a really high serial number. It is just that assembly line XAW7 is pretty slow in producing switches. According to
serial list, it is very possible that this serial is another cutoff point for patched switches.
oh, no I know that, I meant the previous patched systems were 7004, but his was 7001 with others with 7003 being ok, but with it being a US console the "patched/no-patched" serials are going to be different
 

Essometer

Needs data
Member
Joined
Oct 22, 2010
Messages
732
Trophies
1
Age
32
Location
Bielefeld
Website
none.de
XP
3,573
Country
Germany
An XAW700119XX doesn't have it patched so its a little more specific. Similar to the Japanese ones, the cutoff point is not XAJX004, butXAJX0043 since there were people who could still do the exploit on the former serial number.
Yes, this is what I think as well that the cutoff point for the XAJ7 line is more specific as for XAW7. We definitely need more serials to get a cutoff point for all assembly lines.
Also, we have a confirmed unpatched switch @ XAW700164.

oh, no I know that, I meant the previous patched systems were 7004, but his was 7001 with others with 7003 being ok, but with it being a US console the "patched/no-patched" serials are going to be different
When we talk about serials, it doesn't make sense to compare a XAW7 serial to a XAJ7 serial, since they are completely different form each other.
The same is true for XAJ7 and XAJ4 or XAJ1. The produce at different places in different rates, some slower, some faster.
 
Last edited by Essometer,
  • Like
Reactions: Draxzelex

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Psionic Roshambo @ Psionic Roshambo:
    Tandem even
  • The Real Jdbye @ The Real Jdbye:
    i think i heard of that, it's a good idea, shouldn't need a dedicated GPU just to run a LLM or video upscaling
  • The Real Jdbye @ The Real Jdbye:
    even the nvidia shield tv has AI video upscaling
  • The Real Jdbye @ The Real Jdbye:
    LLMs can be run on cpu anyway but it's quite slow
  • BakerMan @ BakerMan:
    Have you ever been beaten by a wet spaghetti noodle by your girlfriend because she has a twin sister, and you got confused and fucked her dad?
  • Psionic Roshambo @ Psionic Roshambo:
    I had a girlfriend who had a twin sister and they would mess with me constantly.... Until one chipped a tooth then finally I could tell them apart.... Lol
  • Psionic Roshambo @ Psionic Roshambo:
    They would have the same hair style the same clothes everything... Really messed with my head lol
  • Psionic Roshambo @ Psionic Roshambo:
    @The Real Jdbye, I could see AMD trying to pull off the CPU GPU tandem thing, would be a way to maybe close the gap a bit with Nvidia. Plus it would kinda put Nvidia at a future disadvantage since Nvidia can't make X86/64 CPUs? Intel and AMD licensing issues... I wonder how much that has held back innovation.
  • The Real Jdbye @ The Real Jdbye:
    i don't think nvidia wants to get in the x64 cpu market anyways
  • The Real Jdbye @ The Real Jdbye:
    you've seen how much intel is struggling getting into the gpu market
  • The Real Jdbye @ The Real Jdbye:
    and nvidia is already doing ARM
  • The Real Jdbye @ The Real Jdbye:
    i don't think they want to take more focus away from their gpus
  • Psionic Roshambo @ Psionic Roshambo:
    Yeah I think Nvidia s future lays in AI GPU acceleration stuff if they can get that going it's going to be super interesting in the long term
  • Psionic Roshambo @ Psionic Roshambo:
    AI assisted game creation might become a thing
  • Psionic Roshambo @ Psionic Roshambo:
    At least that's something I think would be pretty cool.
  • Psionic Roshambo @ Psionic Roshambo:
    Don some VR glasses and gloves and talk to the computer and paint entire worlds
  • Psionic Roshambo @ Psionic Roshambo:
    "OK Cortana I want that mountain a little taller and more snow on top, and I would like some random ancient pine forest around the bottom"
  • Psionic Roshambo @ Psionic Roshambo:
    "Now we need a spring fed river flowing down the north side and add some wild life appropriate for the biome"
  • Psionic Roshambo @ Psionic Roshambo:
    Many TBs of assets and the programming of something like that is going to be tough but I think it's something we might see in 20 years maybe sooner
  • The Real Jdbye @ The Real Jdbye:
    @Psionic Roshambo AI assisted game creation is kinda already here, there was recently that AI that can turn any 2D image into a fully modeled 3D object, it's not perfect, but it's a starting point, beats starting from zero
  • The Real Jdbye @ The Real Jdbye:
    before that there was one to generate a fully modeled scene from a 2D image
  • The Real Jdbye @ The Real Jdbye:
    but most recently, there was one that actually generates a working unity scene with terrain and textures already set up that you can import right into unity, that's a huge time saver right there
  • The Real Jdbye @ The Real Jdbye:
    and using LLMs to generate NPC dialogue and even dynamically generated quests is something i'm sure is already happening
  • The Real Jdbye @ The Real Jdbye:
    will just take some time for games made using those things to be completed and released
    The Real Jdbye @ The Real Jdbye: will just take some time for games made using those things to be completed and released