Homebrew Discussion The Nintendo Switch, Malicious Apps, and You

blawar

Developer
Developer
Joined
Nov 21, 2016
Messages
1,708
Trophies
1
Age
40
XP
4,311
Country
United States
I'm not too familiar with the process myself, but you can verify NSP and XCI files by verifying the ACID signature. As far as doing that with NSZ files, worst case would be having to convert it back to an NSP before verifying. Good news though, most title installers do signature verification by default and will throw an error if the signature check fails. @blawar is far more knowledgeable than me about how sig checking works if he'd like to chime in.

the nsz can be verified with nicoboss’ nsz tool and nsc_builder
 
  • Like
Reactions: Relink

Relink

Member
Newcomer
Joined
Dec 10, 2019
Messages
5
Trophies
0
Age
33
XP
34
Country
Switzerland
I'm not too familiar with the process myself, but you can verify NSP and XCI files by verifying the ACID signature. As far as doing that with NSZ files, worst case would be having to convert it back to an NSP before verifying. Good news though, most title installers do signature verification by default and will throw an error if the signature check fails. @blawar is far more knowledgeable than me about how sig checking works if he'd like to chime in.

I have seen that most installers have the option to run unsigned code and that it's often required installing NSZ's and NSP files according to youtube videos where people installed the youtube channel and some backups.
To be sure it might be a good idea to check if it's custom build, corrupt or infected. And if it's custom build, if you have to worry about it or not.

I tried looking at some of my NSZ's and XCI's with XCI Explorer and Tinfoil's website/ID database, all the game ID's matched, some of the SDK's did not match with the NSZ's, the NSZ's file structure could not be shown in XCI Explorer and none of the NCAid's from the XCI's could be found on the Tinfoil website but extracting the full game as a romfs did give me all the expected files I needed to create mods. I'm really trying to find a safe and easy way to verify if I have something to worry about or not at all, mostly in the cases where people run code unsigned.
I know you can never be certain running unsigned homebrew but unsigned backups do scare me.

Maybe @Crusatyr knows how to look at the file structure when it comes to XCI files or what to look for in XCI Explorer if it doesn't match tinfoil but is a real backup.

the nsz can be verified with nicoboss’ nsz tool and nsc_builder

I can't get Nicoboss's tool to work because I already have python 2.7 running which doesn't play nice with python 3.x (requirement) causing pip to fail for some reason.

Is NSC_Builder easy to install and use?
Looking at the topic it looks like it requires some sort of different structure in my key dump? Or am I misunderstanding it because the post is a bit chaotic?
I can't find any dependency requirements either.
 
Last edited by Relink,

The234sharingan

Member
Newcomer
Joined
Dec 31, 2019
Messages
10
Trophies
0
Age
28
XP
277
Country
United States
It really is a wild world out there. I admittedly trust most sources by default I really need to be more critical in that regard I can see.
 

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,471
Trophies
3
XP
29,138
Country
United States
doesn't nx info tell you what is and isn't harmful? I don't have an exploited system. it's exploitable, but I choose not to do that for a while. anyway, it will say safe next to the content. based on what I've read, only games and updates can contain malicious code (not dlc), because I think it enables full privileges to that content.
 

Crusatyr

Well-Known Member
OP
Member
Joined
Jul 31, 2016
Messages
197
Trophies
0
XP
901
Country
United States
Nope, switchFuckerUpper shows that a homebrew app can mess stuff up. Even with Atmo's prodinfo protection stuff, it's trivial to have a homebrew app drop a rcm payload onto the sdcard then reboot into it.
 

ZachyCatGames

Well-Known Member
Member
Joined
Jun 19, 2018
Messages
3,398
Trophies
1
Location
Hell
XP
4,209
Country
United States
> FuseBurner.bin is purely theoretical
“So uh, I may or may not have gotten a little bored awhile back and may or may not have made such a thing”
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    K3Nv2 @ K3Nv2: https://www.ebay.com/itm/386617469929?mkcid=16&mkevt=1&mkrid=711-127632-2357-0&ssspo=2T8UwYf_Qse&...