Tutorial  Updated

A definitive way to test if your Switch is patched or not (purchases after 07-2018)

This tutorial uses TegraRCM command line to send payloads to RCM enabled Switch.
Command line is used since it offers a more detailed explanation on what is going on.
So it is a definitive way to confirm if your Switch is patched or not without further questions.
This tutorial does not make any modification to your Switch console.

Requirement:

No Micro SD Card is required.
1. Any way of entering Recovery Mode. Please read here, https://gbatemp.net/threads/the-ultimate-list-of-mods-to-enter-rcm.502145/
2. biskeydump.bin payload(please get the latest version, as of 30th July 2019, the latest version is V9), can be downloaded from https://switchtools.sshnuke.net/
3. TegraRcm GUI, can be downloaded from https://github.com/eliboa/TegraRcmGUI/releases
4. USB C to USB A cable
5. A PC with USB port (Sorry I don't have Mac so I could not cover this area)

Step-by-Step (in total 7 steps):
1. put in your RCM Jig on the right joy con rail. Press and hold Vol+ then press the power button.
You should see a black/blank screen after you press the power button.
If you see a Nintendo logo, you can power off your console and try to adjust your RCM Jig position.

2. To install APX driver
2.1 Launch TegraRcm GUI, go to Settings tab, click on "Install Driver" button.
2-1-1.jpg

Confirm the driver installation.
2-1-2.jpg

2.2 For those having problems installing APX driver :
Install and launch Zadig. Plug your Switch in RCM mode, then select Options > List All Devices.
Select the APX device and check which driver is installed for this specific device. If libusbK is not the current driver, install it.
zadig.png
(This step is copied from https://gbatemp.net/threads/tegrarcmgui-simple-gui-for-tegrarcmsmash.503510/)

3. Plug in USB cable from your PC to Switch(in RCM).
Open TegraRcm GUI and you should see this window with "RCM OK".
3.jpg

Alternatively, you can use Device Manager to confirm if the APX device is recognized.
3-2.jpg

Now you can close the TegraRcm GUI application.

4. Copy biskeydump.bin to the TegraRcm GUI folder.
4-1.jpg

5. Open a command line and go to the TegraRcm GUI folder.
4.jpg

6. Run this on the command line
Code:
TegraRcmSmash.exe -w biskeydump.bin BOOT:0x0

7. Check the result
7.1 Switch accepts and executes payload, which mean your Switch is not patched.
Please refer to 0X7000
working.png

You will also see QR code on your Switch screen.

7.2 Switch accepts but does not executes payload, which means your Switch is patched.
Please refer to 0X0000
not-working.png
 
Last edited by gnilwob, , Reason: update biskeydump version

gnilwob

Well-Known Member
OP
Member
Joined
Mar 16, 2008
Messages
204
Trophies
1
XP
644
Country
Hong Kong
Hi guys. I tried to mod my cousin's switch and it ran hekate, then tried to run atmosphere but after showing the logo it went black screened. If I got that far, does it mean the Switch is not patched and I'm doing sth wrong or is the switch patched?

Try injecting biskeydump payload and see if you can see emoji icon on the screen.
If not, your switch is patched.
 

78_Alpha

Member
Newcomer
Joined
Jan 10, 2019
Messages
18
Trophies
0
Age
24
XP
197
Country
United States
Bought a XAW9 switch, came from Nintendo, arrived in 4.0.1 condition, and it is giving the 0x700 indicator, so no, not all XAW9 switches are patched, with the current data of 3 people, 2 of the 3 have 0x700, but still 50/50 shot. I have a long road ahead of me to get this thing prepped as a Christmas gift.
 
  • Like
Reactions: Don Jon

PoppaDre

Well-Known Member
Member
Joined
Aug 23, 2016
Messages
309
Trophies
0
Age
36
XP
681
Country
Canada
My refurb unit with SN XAW943002 came back with:

RCM Device detected
Invoking TegraRcmSmash.exe with args : "C:\Users\andre\Downloads\biskeydumpv8\biskeydump.bin"
TegraRcmSmash (32bit) 1.2.1-3 by rajkosto
Opened USB device path \\?\usb#vid_0955&pid_7321#6&17649c12&0&1#{aa0dbd45-3117-f331-5c49-76bf65225042}
RCM Device with id C085040100000024C1A2406401101062 initialized successfully!
Uploading payload (mezzo size: 92, user size: 98624, total size: 164840, total padded size: 167936)...
Smashing the stack!
Smashed the stack with a 0x7000 byte SETUP request!
Payload successfully injected

It is however on FW 8.1.0. From my understanding this can still be hacked with fusee-gelee. If I update to the latest firmware can I still run fusee-gelee? Thanks
 

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,006
Trophies
2
Age
29
Location
New York City
XP
13,372
Country
United States
My refurb unit with SN XAW943002 came back with:

RCM Device detected
Invoking TegraRcmSmash.exe with args : "C:\Users\andre\Downloads\biskeydumpv8\biskeydump.bin"
TegraRcmSmash (32bit) 1.2.1-3 by rajkosto
Opened USB device path \\?\usb#vid_0955&pid_7321#6&17649c12&0&1#{aa0dbd45-3117-f331-5c49-76bf65225042}
RCM Device with id C085040100000024C1A2406401101062 initialized successfully!
Uploading payload (mezzo size: 92, user size: 98624, total size: 164840, total padded size: 167936)...
Smashing the stack!
Smashed the stack with a 0x7000 byte SETUP request!
Payload successfully injected

It is however on FW 8.1.0. From my understanding this can still be hacked with fusee-gelee. If I update to the latest firmware can I still run fusee-gelee? Thanks
Firmware is irrelevant with the Fusee Gelee exploit.
 
  • Like
Reactions: 78_Alpha

stehilton94

Well-Known Member
Newcomer
Joined
Aug 29, 2017
Messages
86
Trophies
0
Age
30
XP
312
Country
Ireland
XAW 70022 0x0000 Byte Setup Request :cry:

--------------------- MERGED ---------------------------

XAW70022 0x000 Byte Setup Request :cry:
 

GoldTNT

New Member
Newbie
Joined
Jan 2, 2020
Messages
1
Trophies
0
Age
46
XP
43
Country
Portugal
It says on Opened USB, what's the problem?

RCM Device detected
Invoking TegraRcmSmash.exe with args : "C:\Users\andre\Downloads\biskeydumpv8\biskeydump.bin"
TegraRcmSmash (32bit) 1.2.1-3 by rajkosto
Opened USB device path \\?\usb#vid_0955&pid_7321#6&17649c12&0&1#{aa0dbd45-3117-f331-5c49-76bf65225042}
 

YoshNuri

New Member
Newbie
Joined
Feb 17, 2020
Messages
1
Trophies
0
Age
45
XP
48
Country
United States
Hey Everyone!!! I just got a used Switch and I wanted to see if I could mod it.

i cant seem to get passed the test though. I have tried it several times and cant seem to check. I got into RCM mode but the test doesnt wanna finish. All I get is this on my command prompt::

C:\Program Files (x86)\TegraRcmGUI>TegraRcmSmash.exe -w biskeydump.bin BOOT:0x0
TegraRcmSmash (32bit) 1.2.1-3 by rajkosto
Opened USB device path \\?\usb#vid_0955&pid_7321#6&3991ba35&0&2#{aa0dbd45-3117-f331-5c49-76bf65225042}
RCM Device with id 4082031700000024C3F55C64212101D0 initialized successfully!
Uploading payload (mezzo size: 92, user size: 97048, total size: 163264, total padded size: 163840)...

Nothing after that at all. Im guessing im not moddable. but Im hoping Im just doing something wrong? I have changed 8 different cables. Tried 3 different PCs/Latops. I tried ALLLLLL of the USB ports I have.

Any help would be greatly appreciated TIA
 

pubtemp

New Member
Newbie
Joined
Feb 29, 2020
Messages
1
Trophies
0
Age
44
XP
42
Country
United States
Is my switch hackable?

this is all i get get from RCM mode after using TegraRCMGUI 2.6

TegraRcmSmash (32bit) 1.2.1-3 by rajkosto
Opened USB device path \\?\usb#vid_0955&pid_7321#6&104fed9e&0&18#{aa0dbd45-3117-f331-5c49-76bf65225042}
RCM Device with id 8002050C0000000C04F85064212101D0 initialized successfully!
Uploading payload (mezzo size: 92, user size: 64036, total size: 130252, total padded size: 131072)...
 

Nekikool

New Member
Newbie
Joined
Nov 17, 2018
Messages
4
Trophies
0
Age
34
XP
46
Country
France
Hello, i have this

D:\- Nintendo\Hack Switch\Tools\TegraRcmGUI_v2.6_portable>TegraRcmSmash.exe -w biskeydump.bin BOOT:0x0
TegraRcmSmash (32bit) 1.2.1-3 by rajkosto
Opened USB device path \\?\usb#vid_0955&pid_7321#5&38e97a59&0&8#{aa0dbd45-3117-f331-5c49-76bf65225042}
RCM Device with id 8002051300000000C9F26464212101D0 initialized successfully!
Uploading payload (mezzo size: 92, user size: 97048, total size: 163264, total padded size: 163840)...

Is patched ?

Thank you
 

matias3ds

Well-Known Member
Member
Joined
Oct 25, 2017
Messages
3,670
Trophies
1
Age
38
XP
9,321
Country
Argentina
Hello!
I came here to inform a sad thing
I got one brand new sealed Switch XAW70017612640 and it is Patched!!!
I even did the biskeydump thing and it returned 0x0000
Well good new for you the presale for Switch core has just begun , so be sure to grab one , and probably will receive it , in less thatn 2 month .
 
  • Like
Reactions: dekuleon

dekuleon

Well-Known Member
Member
Joined
Oct 1, 2010
Messages
645
Trophies
1
Age
31
Location
where the wind makes the curve
XP
2,580
Country
Brazil
Well good new for you the presale for Switch core has just begun , so be sure to grab one , and probably will receive it , in less thatn 2 month .
Indeed! This Switch is for a friend, I'm using Fake News since it came with 4.0.
I already pre-ordered some Switch Cores for other friends hehe.
 
  • Like
Reactions: matias3ds

Billjessm

New Member
Newbie
Joined
May 17, 2020
Messages
1
Trophies
0
Age
31
XP
42
Country
Canada
Mine literally doesn't say... it's been stuck on "Opened USB Device Path"

--------------------- MERGED ---------------------------

Don't know what it's supposed to do but mine just says opened usb device path
 

RODIFIRE

Well-Known Member
Member
Joined
Sep 1, 2008
Messages
168
Trophies
0
Age
38
Location
GREECE
XP
263
Country
Greece
Switched to high buffer
Smashing the stack!
Smashed the stack with a 0x0000 byte SETUP request!

so I did everythink right but at this moment theres is not a way to hack it?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Black_Manta_8bit @ Black_Manta_8bit: Oh @RedColoredStars yeah thats sad :sad: i feel it.