Nereba Exploit: Reboot to Fusée Gelée payload from stock firmware.

nintendo-switch-homebrew-launcher.jpg

Stuckpixel of the ReSwitched team recently released his exploit "Nereba".


This exploit will enable Nintendo Switch owners with early units that have held off updating, still on the original 1.0.0 firmware to reboot into a Fusée Gelée payload without any dongle, USB connections to a external device or jig directly from stock untouched firmware. In addition support for 2.x and 3.x firmware is also planned in the future, opening up the exploit to significantly more consoles.

The implementation takes advantage of the nspwn exploit, that users of the original 3.0.0 homebrew implementation will be familiar with. Used in conjunction with this, users will be able to boot any Fusee Gelee payload from the micro SD card, placed in the nereba folder on the root of the SD card. After running the script from the Switch web applet, users can reboot into any payload by launching the album applet from the home menu.

Download:


https://github.com/pixel-stuck/nereba/releases
 
Last edited by RattletraPM, , Reason: Center image to follow news formatting

WD_GASTER2

Hated by life itself.
Developer
Joined
Jun 17, 2018
Messages
779
Trophies
1
XP
1,853
Country
United States
i have a launch switch that i bought on midnight and only played botw without connecting online. hopefully that means its 1.0.(have to unbox it and charge it)
hopefully there will be a tutorial for this with emunand is out as i am sorely behind the switch stuff
 

TP998

New Member
Newbie
Joined
Apr 19, 2019
Messages
2
Trophies
0
Age
25
XP
44
Country
Aruba
i wonder if it would be possible to have 2 emunands

low sysnand for warm boot
emunand one , latest FW , clean no NSP's installed , for booting legit carts and playing online
emunand two , latest FW , NSP's installed , offline only

if we could boot between sysnand and 2 different emunands it would be best

It's not possible sadly that Emunand will ever be safe online, it would always fail integrity checks making it impossible to be 'clean'.

I cannot wait for Emunand though, looking forward to playing that Tetris game and Mario Maker 2 online! Not too fussed about warm/coldboot as we can already do that with hardware modification.
 
  • Like
Reactions: weatMod

titan_tim

(Can't shut up)
Member
Joined
Mar 10, 2009
Messages
461
Trophies
1
Location
Tokyo
XP
2,475
Country
Japan
How do you find out which version you can downgrade back to based on burnt fuses?

]For all the people <=3.0, that's damn impressive that you have that much self control.
 

MSearles

Well-Known Member
Member
Joined
Jan 4, 2016
Messages
596
Trophies
0
Age
36
XP
2,653
Country
United States
I updated my switch from 3.0.x to 6.0.x. I burned fuses along the way. Does this matter at all with using Fusée Gelée? Will I still be able to use this exploit when it's available for higher firmwares?
 

pcwizard7

Well-Known Member
Member
Joined
Aug 2, 2013
Messages
1,409
Trophies
0
XP
1,688
Country
Australia
with the Deja Vu it let more switch have a warm boot but like with everything stay on lowest fw as possible until its release make sure u can be on fw 7.x or lower
 

annson24

The Patient One
Member
Joined
May 5, 2016
Messages
1,191
Trophies
0
Age
32
XP
1,843
Country
Philippines
Be specific man. Does it work for Switch from different region?

No idea, the switch is region free so maybe? You can just make a back up of news that you're replacing so if it doesn't work you can put it back

Transplant savedata as raw files (including system savedata) which means you can get fakenews installed on your 1.0.0 console without PPT JPN, simply by replacing your SYSTEM:/save/8000000000000090 file with a friend's who already has it (make sure to back yours up first) using HacDiskMount after mounting SYSTEM partition, then launching 1.0.0 using Hekate and this FS.kip1 patch applied, using the fake news entry to launch the browser and install fake news AGAIN via pegaswitch, which should fix the CMAC so you don't have to boot using Hekate anymore.
 

M7L7NK7

Well-Known Member
Member
Joined
Oct 16, 2017
Messages
3,900
Trophies
1
Website
youtube.com
XP
5,967
Country
Australia
  • Like
Reactions: charlieb

Waze0613

Member
Newcomer
Joined
Feb 5, 2018
Messages
16
Trophies
0
Age
34
XP
811
Country
France
So it means we need a computer running Pegaswitch in order to use this exploit ? What's the added value here ? Usning an RCM bootloader seems more convenient then ...
 

snoofly

Well-Known Member
Member
Joined
Aug 18, 2015
Messages
1,012
Trophies
0
Age
54
XP
2,133
Country
United Kingdom
So it means we need a computer running Pegaswitch in order to use this exploit ? What's the added value here ? Usning an RCM bootloader seems more convenient then ...
Yeah, that’s what I’m trying to work out.
Having to run Pega on my PC is much more inconvenient than using a dongle.
i gotta be missing something here
 

deSSy2724

Well-Known Member
Member
Joined
Sep 11, 2015
Messages
453
Trophies
0
Age
33
XP
1,173
Country
Germany
Can someone clear up all this mess finally? I mean, there are too many different opinions, statements and opened questions......

For me personally, if I cant keep my switch on 1.0 (2 - 3 too?) OFW and have two different emunands updated to the latest firmware (one for offline/homebrews/dumps, other one for online/legit carts/eshop) and all that without using any dongle/jig then whats the real point here?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    K3Nv2 @ K3Nv2: Gonna love it when the next update blocks them