Hacking Bought a bricked Nintendo Switch

SanderJ

Member
OP
Newcomer
Joined
Nov 22, 2019
Messages
24
Trophies
0
Age
29
XP
78
Country
United Kingdom
I am guessing something is failing when they try to read the NAND, causing the console to crash. Or it might be some other hardware that it's trying to access. Anyway, you might have a hardware failure on your hands. Guess there's a reason it was so cheap...

Interesting. I'll keep poking at it. If I find a fix, I'll post back on this thread. thanks
 

Awesomeslayerg

Well-Known Member
Member
Joined
Jan 21, 2011
Messages
145
Trophies
0
XP
292
Country
United States
£20 such a steal
I want to know the outcome seems like an interesting problem to fix.

--------------------- MERGED ---------------------------

Interesting. I'll keep poking at it. If I find a fix, I'll post back on this thread. thanks
Are you using tegrarcm to push the the hetake payload?
 
  • Like
Reactions: SanderJ

SanderJ

Member
OP
Newcomer
Joined
Nov 22, 2019
Messages
24
Trophies
0
Age
29
XP
78
Country
United Kingdom
I want to know the outcome seems like an interesting problem to fix.

--------------------- MERGED ---------------------------


Are you using tegrarcm to push the the hetake payload?
Yeah using tegrarcmgui. When I inject, hekate I get a black screen, same with lockpick

but when I inject biskeydump.bin I get this and it dumped my keys to sd card

K2VvYo9.jpg


--------------------- MERGED ---------------------------

I put white blocks over the data
 
Last edited by SanderJ,

Awesomeslayerg

Well-Known Member
Member
Joined
Jan 21, 2011
Messages
145
Trophies
0
XP
292
Country
United States
Yeah using tegrarcmgui. When I inject, hekate I get a black screen, same with lockpick

but when I inject biskeydump.bin I get this and it dumped my keys to sd card

https://i.imgur.com/K2VvYo9.jpg

--------------------- MERGED ---------------------------

I put white blocks over the data


Try an older version see if that boots. Are you using scardsetup page to download stuff??
 

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,246
Trophies
4
Location
Space
XP
13,798
Country
Norway
I want to know the outcome seems like an interesting problem to fix.

--------------------- MERGED ---------------------------


Are you using tegrarcm to push the the hetake payload?
Try not to break it more in your attempt to fix it. I'm pretty sure you'll get way more than that for it on eBay. The joycons, dock and charger alone are worth way more. So even if the Switch is a lost cause you can make some decent money reselling the accessories.
Faulty Switches with accessories easily go for $150++. Depending on what the fault is of course, but I'm sure you could get more than $100.
 

SanderJ

Member
OP
Newcomer
Joined
Nov 22, 2019
Messages
24
Trophies
0
Age
29
XP
78
Country
United Kingdom
Try an older version see if that boots. Are you using scardsetup page to download stuff??

No. I'll try an older one

Try not to break it more in your attempt to fix it. I'm pretty sure you'll get way more than that for it on eBay. The joycons, dock and charger alone are worth way more. So even if the Switch is a lost cause you can make some decent money reselling the accessories.
Faulty Switches with accessories easily go for $150++. Depending on what the fault is of course, but I'm sure you could get more than $100.

I understand. But I would really like to find a fix, not really for the sake of selling. But for this to become a future reference as I find articles on the internet for various things years later which are helpful for many things in life, etc.
 

SanderJ

Member
OP
Newcomer
Joined
Nov 22, 2019
Messages
24
Trophies
0
Age
29
XP
78
Country
United Kingdom
Update:

No luck as of yet, but I'm not going to sell the Switch. I really want to get this fix for any future reference so if anyone has any suggestions, do let me know as crazy as it be may, I don't care :) I'm really sure there's a fix but it's finding the how. I've spent 7 hours so far straight and will continue tomorrow. Really interesting, the Switch I won't sell, making it my mission to find the fix. Thanks for all the help guys today and tomorrow is another day.
 
  • Like
Reactions: antiNT

SanderJ

Member
OP
Newcomer
Joined
Nov 22, 2019
Messages
24
Trophies
0
Age
29
XP
78
Country
United Kingdom
I can't sleep, Is this even possible? I removed the eMMC, now I can hold Vol+ and connect cable with no jig connected and TegraRCM says RCM OK and I can inject only biskeydump.bin still but how is that even possible with no jig?
 

Philliyxx

Well-Known Member
Member
Joined
Sep 21, 2018
Messages
304
Trophies
0
Age
36
XP
943
Country
United States
I can't sleep, Is this even possible? I removed the eMMC, now I can hold Vol+ and connect cable with no jig connected and TegraRCM says RCM OK and I can inject only biskeydump.bin still but how is that even possible with no jig?

Auto rcm
 

SanderJ

Member
OP
Newcomer
Joined
Nov 22, 2019
Messages
24
Trophies
0
Age
29
XP
78
Country
United Kingdom
No. I've just had my friend unscrew his Nintendo Switch. Remove the eMMC nand and then hold vol+ and then connect cable and RCM is detected. I really hope this is a new method. I'm not joking and no not auto rcm too

--------------------- MERGED ---------------------------

NO JIG Too
 

SanderJ

Member
OP
Newcomer
Joined
Nov 22, 2019
Messages
24
Trophies
0
Age
29
XP
78
Country
United Kingdom
My friend can make an XAJ40062 be detected for RCM on Tegra with this method. But injecting payloads haven't worked and this is as far as he believes a patched Switch
 

Kafluke

Well-Known Member
Member
Joined
May 6, 2006
Messages
5,474
Trophies
0
Age
47
XP
4,636
Country
United States
My friend can make an XAJ40062 be detected for RCM on Tegra with this method. But injecting payloads haven't worked and this is as far as he believes a patched Switch
Patched switches have no problem entering RCM. You just cant push a payload
 

ZachyCatGames

Well-Known Member
Member
Joined
Jun 19, 2018
Messages
3,398
Trophies
1
Location
Hell
XP
4,208
Country
United States
A blue screen simply means pkg2/kernel panicked. Could be caused by something as simple as a pkg1/pkg2 mismatch resulting in a validation error, or could be caused by a very deep problem within the ODNX01/ODNX02/ODNX10 chip.

You can try running android or Ubuntu on a spare SD card if you have one to check if its hardware is functional.
 
Last edited by ZachyCatGames,
  • Like
Reactions: loler55

Snomannen_kalle

Well-Known Member
Member
Joined
Sep 2, 2018
Messages
350
Trophies
0
Age
29
XP
2,366
Country
Norway
I can't sleep, Is this even possible? I removed the eMMC, now I can hold Vol+ and connect cable with no jig connected and TegraRCM says RCM OK and I can inject only biskeydump.bin still but how is that even possible with no jig?
I can't find anything to back this up after a quick google search, but I am sure I read somewhere, around the time when the exploit was first revealed, that it is possible to enter RCM by removing the NAND chip
 
  • Like
Reactions: loler55

chippy

Well-Known Member
Member
Joined
Dec 21, 2017
Messages
321
Trophies
0
Age
124
XP
967
Country
Australia
Isn't boot 0/1 in the nand chip and it will go into rcm if they are corrupt (in this case non existant)? That's how auto rcm works by corrupting them
 

SanderJ

Member
OP
Newcomer
Joined
Nov 22, 2019
Messages
24
Trophies
0
Age
29
XP
78
Country
United Kingdom
If PRODINFO isn't intact you won't be able to create a working NAND but that is literally the only thing that needs to be intact to create a new NAND from scratch and even that might change with time (using a donor PRODINFO is in theory possible by changing or removing the console unique info, well it's a bit more complex than that but still possible, even generating a PRODINFO may be possible although it would never work online that way)

@OP It's a long shot but you could also try making an emunand from hekate/oxos and then build your new nand from that. Make sure emunand boots first before you use it as your base though.

Good luck OP, I’m rooting for you to fix this.

:ph34r:

Try an older version see if that boots. Are you using scardsetup page to download stuff??

Patched switches have no problem entering RCM. You just cant push a payload

Hi,

Just want to give you an update. After messing around with everything inside I just decided to press on components after RCM was dected. I pressed my thumb firmly on this component here, I assume something important is under the shield

upload_2019-11-24_18-10-59.png


and it lets me inject any payload I want. I was able to inject hekate and lockpick RCM. It told me I burnt 11/64 fuses. But the only problem is my SD card isn't being detected. It's saying it's not mounted. But this is progress I guess as now I know how to inject any payload with this. But my question is how comes I don't have to press anything firmly to get biskeydump.bin to inject successfully. Like I said, I will continue with this till I hopefully find a fix. Maybe it needs like a reflow or something?
 
  • Like
Reactions: KiiWii

ZachyCatGames

Well-Known Member
Member
Joined
Jun 19, 2018
Messages
3,398
Trophies
1
Location
Hell
XP
4,208
Country
United States
Hi,

Just want to give you an update. After messing around with everything inside I just decided to press on components after RCM was dected. I pressed my thumb firmly on this component here, I assume something important is under the shield

View attachment 187793

and it lets me inject any payload I want. I was able to inject hekate and lockpick RCM. It told me I burnt 11/64 fuses. But the only problem is my SD card isn't being detected. It's saying it's not mounted. But this is progress I guess as now I know how to inject any payload with this. But my question is how comes I don't have to press anything firmly to get biskeydump.bin to inject successfully. Like I said, I will continue with this till I hopefully find a fix. Maybe it needs like a reflow or something?
The two 2gb LPDDR4 DRAM chips, and Tegra X1 are under that shield, the side you circled has the DRAM.
The DRAM could be messed up, would explain pkg2 and hekate not being able to run.
 
Last edited by ZachyCatGames,

SanderJ

Member
OP
Newcomer
Joined
Nov 22, 2019
Messages
24
Trophies
0
Age
29
XP
78
Country
United Kingdom
The two 2gb LPDDR4 DRAM chips, and Tegra X1 are under that shield, the side you circled has the DRAM.

Here's what I also found out, I get into RCM right. Hold my thumb down on the shield. It lets me inject hekate. Now, if I want hekate to display my fuse information, etc, I have to hold my thumb on the shield. If not, it will show nothing. But when I hold it down, all the fuse information is displayed eg this one burnt 11/64
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: Ohkay