Hacking Suggestion Setting up a exploit bounty for patched switches

Mouser X

Well-Known Member
Member
Joined
Aug 26, 2009
Messages
101
Trophies
0
XP
546
Country
United States
sounds like a load of bull to me. as far as I know, there is no way to unpatch an ipatched switch, since its a hardware problem.
I've heard/read a few people say that it's possible to "unpatch" an ipatched Switch, by replacing the patched chip with a non-patched chip. I haven't heard anyone say where or how you'd get said non-patched chip. No, I don't remember who said it, but it was a few, different people. Most of it was regarding if someone accidently implemented "autoRCM" on an ipatched unit. This would result in a fully bricked Switch. To which they said the *only* fix would be a hardware fix, to replace the patched chip.
 

Dysproh

Well-Known Member
Newcomer
Joined
Dec 30, 2016
Messages
48
Trophies
0
Age
34
XP
126
Country
United States
I've heard/read a few people say that it's possible to "unpatch" an ipatched Switch, by replacing the patched chip with a non-patched chip. I haven't heard anyone say where or how you'd get said non-patched chip. No, I don't remember who said it, but it was a few, different people. Most of it was regarding if someone accidently implemented "autoRCM" on an ipatched unit. This would result in a fully bricked Switch. To which they said the *only* fix would be a hardware fix, to replace the patched chip.
Replacing the SoC sounds like a very hard and probably not doable for free task.
 

Chocola

GBAtemp Meowgular
Member
Joined
Sep 18, 2018
Messages
379
Trophies
0
Age
32
Location
Neko Paradise
XP
723
Country
Korea, South
This is harder, because the company have bounties for exploit reports so another hackers try to find it and report to N, then N pay for this reports and apply a fix (like the fix on 7.x, they get a report for a important part of DejaVu and they patch it).

You ask for ZeroDay vulnerability, a new and unknown breach to exploit the system, but it's really harder find it and probably if someone found anything gona report it to N for the money (because its generous payed).

Anyway with this, it's only the first step for exploit, you need chain more vulnerabilities on the system to get full access.
 

Off42

Member
Newcomer
Joined
Jun 13, 2019
Messages
12
Trophies
0
Age
44
XP
136
Country
United States
A vulnerability with such a high severity may give you 20k even from Nintendo. You will probably get even more in other bounties targeting devices using the same SoC. Your $50 is joke.

He's not asking to buy it for $50, he's just saying he's going to pitch in and hopes other people will so the money can add up. I agree it won't add up to $20k or anything close, but its better than nothing if a hack dev doesn't want to sell out to Nintendo.
 

ghjfdtg

Well-Known Member
Member
Joined
Jul 13, 2014
Messages
1,360
Trophies
1
XP
3,279
Country
He's not asking to buy it for $50, he's just saying he's going to pitch in and hopes other people will so the money can add up. I agree it won't add up to $20k or anything close, but its better than nothing if a hack dev doesn't want to sell out to Nintendo.
Reasonable. Still not convinced they will take this over a real bug bounty. There is no guarantee whatsoever the money will arrive unlike on official ones.
 

smf

Well-Known Member
Member
Joined
Feb 23, 2009
Messages
6,641
Trophies
2
XP
5,857
Country
United Kingdom
Replacing the SoC sounds like a very hard and probably not doable for free task.

Yes, if you buy blank chips from nvidia then you could replace the one on the motherboard & it can have whatever ipatches you want. I'm not sure they'd sell you one though.
 
D

Deleted User

Guest
Reasonable. Still not convinced they will take this over a real bug bounty. There is no guarantee whatsoever the money will arrive unlike on official ones.
It wont. The OP has no reputation, fails to use correct English (below what is acceptable for non-native speakers), offers a stupidly low sum of money and fails to outline a clear plan of how he will collect money from other users and deliver it. It's like he woke up with an idea yesterday and posted it without thinking it through.
 
Last edited by ,

Off42

Member
Newcomer
Joined
Jun 13, 2019
Messages
12
Trophies
0
Age
44
XP
136
Country
United States
Reasonable. Still not convinced they will take this over a real bug bounty. There is no guarantee whatsoever the money will arrive unlike on official ones.

Probably won't, but you see tons of devs not telling Nintendo about the bugs and coming up with hacks which is a great thing. Some people aren't in it for a bit of money, but its a nice thing to donate since they are on our side and helping us out.
 

Galactiiix

Member
Newcomer
Joined
May 10, 2019
Messages
14
Trophies
0
Age
28
XP
129
Country
France
but to be clear, the flaw is already patched for the switch after 7.1 with deja vu . So there is nothing left for sale
 

Bedel

The key of the blade
Member
Joined
Oct 28, 2015
Messages
1,384
Trophies
0
XP
2,835
Country
United States
It wont. The OP has no reputation, fails to use correct English (below what is acceptable for non-native speakers), offers a stupidly low sum of money and fails to outline a clear plan of how he will collect money from other users and deliver it. It's like he woke up with an idea yesterday and posted it without thinking it through.
In his defense, I'll say I've seen native english speakers using worst english that OP in this same site, so...
 
D

Deleted User

Guest
In his defense, I'll say I've seen native english speakers using worst english that OP in this same site, so...
OP made fundamental mistakes like forgetting full stops at the end of sentences and referring to himself using lower case "i"s. This indicates he didn't even try. He's too sloppy to sucessfully coordinate a crowdfunded exploit bounty.
 

Bedel

The key of the blade
Member
Joined
Oct 28, 2015
Messages
1,384
Trophies
0
XP
2,835
Country
United States
OP made fundamental mistakes like forgetting full stops at the end of sentences and referring to himself using lower case "i"s. This indicates he didn't even try. He's too sloppy to sucessfully coordinate a crowdfunded exploit bounty.
You are right, and still I'm not wrong.
 

TheCyberQuake

Certified Geek
Member
Joined
Dec 2, 2014
Messages
5,012
Trophies
1
Age
28
Location
Las Vegas, Nevada
XP
4,432
Country
United States
Just wanted to throw out the fact that $50 really isn't a whole lot considering the amount of work that goes into this kind of thing. And honestly they are probably already looking into it and likely have been. There just isn't much to find, at least for public knowledge.
 

x124

Active Member
Newcomer
Joined
Mar 22, 2019
Messages
26
Trophies
0
Age
29
XP
213
Country
United States
I don't know why everybody seems upset. It's not like any of you were going to collect any bounty anyway
As far as I can tell from the OP, he is just asking for a public implementation of an exploit that works on patched switches.
Deja vu exploit chain implementation for >=4.1.0 (lowest firmware on patched switches) should qualify.
As nintendo already patched dejavu, it's worthless for them and they won't be willing to pay a dime for it. Furthermore all the exploit details are public and most of it already implemented for earlier firmware versions.

All it should take is for someone to implement nvhax on top of pegaswitch to access deja vu and release it for the hack to be complete. And I think $50 should be a fair prize for this work.
Bounty or not, deja vu for higher firmwares is coming. TX has already been teasing for it for a few months and I think pegascape promised support. I don't see the harm in increasing the incentives to get it out sooner by offering such bounty (as low as it may be)
 

kumikochan

Well-Known Member
Member
Joined
Feb 4, 2015
Messages
3,753
Trophies
0
Age
36
Location
Tongeren
XP
3,311
Country
Belgium
OP made fundamental mistakes like forgetting full stops at the end of sentences and referring to himself using lower case "i"s. This indicates he didn't even try. He's too sloppy to sucessfully coordinate a crowdfunded exploit bounty.
I fail to see what English grammar has to do with it at all, I've seen successful bounties been given out by people who couldn't even spell at all. I do agree with you that this won't lead to anything tho.
 
Last edited by kumikochan,

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: @BakerMan, I have a piano keyboard but I never use it