Hacking So where are the gamesave exploits?

RHOPKINS13

Geek
OP
Member
Joined
Jan 31, 2009
Messages
1,355
Trophies
2
XP
2,631
Country
United States
So needless to say the Switch hacking community has exploded since Fusée was first released. We have linux, emulators, save managers, backup loading, emunand, mods, cheats, and more. Aside from the ipatched units, we're able to do just about everything you can think of involving a glorified tablet with wireless controllers.

AutoRCM can make things slightly more convenient, but damn, it sure would be nice if we didn't need to use a dongle, pc, or phone every time we wanted to use CFW.

Every console I can think of that could be softmodded had gamesave exploits. With the original Xbox Splintercell and MechAssault were the popular choices, on the Wii it started off with Twilight Princess, and then a bunch of other exploits were found, including several other gamesave exploits including Smash Brothers. I don't know that I'd call it a "softmod" but the PS2 had games like "007: Agent Under Fire" that you could use the swap trick with to load homebrew. Perhaps that doesn't count, as it's not really relying on a save file, but once Free MCBoot is installed you really can't get much simpler than that. PSP had multiple exploits, starting with GTA - Liberty City Stories, and DSi had Sudokuhax. The 3DS started with Cubic Ninja and later ended up with exploits for a ton of different games. Of course now it's easiest to just install Boot9Strap and your choice of CFW, but nonetheless there still were a bunch of different gamesave exploits to choose from.

Surprisingly though, no gamesave exploits have been released for Switch, even though we have access to debuggers and other tools that would make finding an exploit easier.

If we found a gamesave exploit, we'd be able to use RCM to boot into CFW once, run Checkpoint and install the exploit, and afterwards we'd be able to boot into OFW and use the game exploit to run homebrew. No more dongles or RCM jigs would be needed!

Heck, I'd bet we could even use Nintendo's Cloud Save service to hack a few ipatched Switches before getting blocked.

It just seems strange to me that these exploits existed for so many other consoles, but none yet for Switch. Why? With all the indie games available in the eShop, I can't imagine that all these game developers suddenly got that much better at protecting their code from vulnerabilities...

Sorry if it feels like I'm whining or begging, I'm really grateful for what we already have, and I lack the time and quite frankly the skills to try and come up with an exploit myself. But I feel like game exploits have been forgotten about now that we have RCM.
 
  • Like
Reactions: Quantumcat

link42586

Well-Known Member
Member
Joined
May 9, 2018
Messages
321
Trophies
0
Age
38
XP
1,184
Country
United States
I think sciresm said something about ASLR or something like that. All I can remember. He had A saying like it was basically impossible. Someone can find it i'm sure.
 

ghjfdtg

Well-Known Member
Member
Joined
Jul 13, 2014
Messages
1,366
Trophies
1
XP
3,299
Country
Because ASLR makes it very very hard to exploit them. You need vulnerable saves and an infoleak at the same time to figure the memory layout out. On top of that there is no easy way to import modified saves.
 

RHOPKINS13

Geek
OP
Member
Joined
Jan 31, 2009
Messages
1,355
Trophies
2
XP
2,631
Country
United States
You cannot export/import saves from/to the Switch
Yes you can, Checkpoint does this beautifully. There are even sites around here where you can download saves that other people have published. As long as you have a way of loading homebrew, you can inject a save.

I think you may even be able to use HacDiskMount to inject the save without launching a full-blown CFW.

--------------------- MERGED ---------------------------

Because ASLR makes it very very hard to exploit them. You need vulnerable saves and an infoleak at the same time to figure the memory layout out. On top of that there is no easy way to import modified saves.

That's a very good point, but I would have expected ASLR to make cheats very difficult if not impossible to implement.
 

masagrator

The patches guy
Developer
Joined
Oct 14, 2018
Messages
6,297
Trophies
3
XP
12,074
Country
Poland
Switch RCM is Independent of operating system. You cannot use game exploit to run unsigned payload on patched Switch.

Edit: maybe I misread something. Nvm.
 
Last edited by masagrator,

smf

Well-Known Member
Member
Joined
Feb 23, 2009
Messages
6,647
Trophies
2
XP
5,885
Country
United Kingdom
If we found a gamesave exploit, we'd be able to use RCM to boot into CFW once, run Checkpoint and install the exploit, and afterwards we'd be able to boot into OFW and use the game exploit to run homebrew. No more dongles or RCM jigs would be needed!

They obviously have better things to do with their time than make dongles redundant. You don't need a jig anyway, just install autorcm.

You'll end up having to use emunand and booting your switch, loading a game and then booting your switch again is way too inconvenient. Just use a dongle, it's easier.
 
Last edited by smf,

ghjfdtg

Well-Known Member
Member
Joined
Jul 13, 2014
Messages
1,366
Trophies
1
XP
3,299
Country
That'sa very good point, but I would have expected ASLR to make cheats very difficult if not impossible to implement.
Cheat engines run on top of already exploited/modified systems allowing them to request the process memory layout. The cheats are offset based since absolute adresses don't work here anymore.
 
  • Like
Reactions: RHOPKINS13

SonyUSA

We're all mad here
Editorial Team
Joined
May 12, 2006
Messages
1,780
Trophies
2
XP
5,630
Country
United States
You would be sandboxed into the game limitations on system resources even if you could save exploit a game, designing an escape exploit would be very troublesome and frankly not worth the effort since the system is wide open with RCM/Payload solutions. You know you can do an internal payload injector for very cheap? You could try looking into one of the Trinket mods.
 

link42586

Well-Known Member
Member
Joined
May 9, 2018
Messages
321
Trophies
0
Age
38
XP
1,184
Country
United States
Long story short. Gamesaves haven't been forgotten about when it comes to the switch. But i'm almost 100% sure sciresm has A saying floating around about how it's nearly impossible to exploit game saves on the switch. And this is what I was takling about ...

https://i.imgur.com/WOYaYhZ.png
 
Last edited by link42586,

link42586

Well-Known Member
Member
Joined
May 9, 2018
Messages
321
Trophies
0
Age
38
XP
1,184
Country
United States
Having read what sciresm posted then..And with what we have now. And my knowledge of other hacking scenes. I wil say that what we have now. Will probably not be what we have in the end. It rarely ever happens that way. I would be surprised if what we have now is the only things that are ever found when the switch is long gone. Something else is already in the pipeline and we might not know about it. May never know about it. But something is always being looked into while the scene is hot.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Veho @ Veho:
    Before a hit they're like zombies, persistent but slow.
    +1
  • Veho @ Veho:
    It's a tradeoff.
    +1
  • The Real Jdbye @ The Real Jdbye:
    no i mean, before a hit is after the previous hit
    +1
  • The Real Jdbye @ The Real Jdbye:
    if you keep them well enough fed, it's the same thing
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    By the power of Florida Man, I have the power!!! *Lifts up meth pipe* Meth Man!!! lol
  • BakerMan @ BakerMan:
    Guys, I just learned my little brother is in the hospital because he had a seizure last night.
  • cearp @ cearp:
    Sorry to hear that BakerMan
    +2
  • BakerMan @ BakerMan:
    Just found out he's doing alright, doing a lot of complaining too, rightfully so. Who wouldn't complain after having a seizure and being hospitalized?
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Glad he is OK and complaining is cool :)
    +1
  • K3Nv2 @ K3Nv2:
    Yeah been there had that no fun
    +1
  • K3Nv2 @ K3Nv2:
    They'll give him sleep studies eegs and possibly one week hospital stay
    +1
  • BakerMan @ BakerMan:
    I hope it's not a week.
  • K3Nv2 @ K3Nv2:
    It's standard so doctors can get a idea about what's going on
  • BakerMan @ BakerMan:
    understood
  • BakerMan @ BakerMan:
    well, i'm glad he seems to be doing fine, and ig i'm going to start spewing goofy shit again
  • BakerMan @ BakerMan:
    Update: Turns out he's epileptic
  • K3Nv2 @ K3Nv2:
    Get a 2nd opinion run mris etc they told me that also
  • Psionic Roshambo @ Psionic Roshambo:
    Also a food allergy study would be a good idea
  • K3Nv2 @ K3Nv2:
    Turns out you can't sprinkle methamphetamine on McDonald's French fries
    +1
  • ZeroT21 @ ZeroT21:
    they wouldn't be called french fries at that point
    +1
  • ZeroT21 @ ZeroT21:
    Probably just meth fries
    +1
  • K3Nv2 @ K3Nv2:
    White fries hold up
    +1
  • The Real Jdbye @ The Real Jdbye:
    @K3Nv2 sure you can
    The Real Jdbye @ The Real Jdbye: @K3Nv2 sure you can