Hacking Apparently the X1 bootrom was leaked

Geezerdorf

Well-Known Member
Newcomer
Joined
Apr 11, 2016
Messages
96
Trophies
0
Age
40
Location
ヴェラクルス、メキシコ, AKA Hell.
XP
581
Country
Mexico
As it seems the Tegra X1 bootrom was leaked a couple of hours ago on pastebin.

Now everybody can find the exploit without the hassle of dumping the bootrom themselves.

Let the games begin...

This will make those with the bootrom exploits move, but maybe not that much. The fact that now it's in the public and someone outside of the hacking scene can also contribute with it though, makes this interesting...and dangerous. There'll be a storm brewing on the horizon.

Isn't this massively illegal making the whole bootrom public?
Well, you're using an exploit for unautorized code execution. Depending on your final use for it....it is
 

Lacius

Well-Known Member
Member
Joined
May 11, 2008
Messages
18,099
Trophies
3
XP
18,338
Country
United States
Right now sure, but SciresM has said every switch with this tegra has the same vuln and it can only be fixed with a hardware revision. Your switch will eventually be hackable too.
The hardmod he's referring to is for Fusée Gelée. When Fusée Gelée is released this summer, systems on 3.0.1 and higher will require an "easy" hardmod. Systems on 3.0.1-4.1.0 might get access to the private software exploits sometime in the future.
 

Dominator211

JFK's Jelly Donut
Member
Joined
Oct 15, 2016
Messages
1,818
Trophies
0
Location
The LaCrosse Field
XP
3,377
Country
United States
As it seems the Tegra X1 bootrom was leaked a couple of hours ago on pastebin.

Now everybody can find the exploit without the hassle of dumping the bootrom themselves.

Let the games begin...
hallelujah!! hallelujah!! This is Exciting i cannot wait for homebrew to unlock the switches full potential
 
  • Like
Reactions: operador7

the_randomizer

The Temp's official fox whisperer
Member
Joined
Apr 29, 2011
Messages
31,284
Trophies
2
Age
38
Location
Dr. Wahwee's castle
XP
18,969
Country
United States
He also didn't release anything and was pretty much driven off the scene so in Sony's eyes. Job done. Sent the message loud and clear.

So then don't reveal your name and keep things under lock and key and then release it anonymously.
 

Ryccardo

Penguin accelerator
Member
Joined
Feb 13, 2015
Messages
7,696
Trophies
1
Age
28
Location
Imola
XP
6,923
Country
Italy
Literally typed "Tegra X1 Boot ROM (Nintendo Switch) pastebin" and got a file. So what can we even do with this without some instructions?
You can explore it in a disassembler (which may or may not exist for that specific SOC/subarchitecture) and try finding something interesting,
or you can use it in a low-level emulator (which may or may not exist yet, but the MAME team will certainly like the news),
or you can fully reverse engineer it to understand what it does so that a future emulator may have a freely licensed replacement instead of requiring this rom...

("You" for obvious reasons refers to a generic person, in fact it probably doesn't include "you" :P)

Isn't this massively illegal making the whole bootrom public?
It's just "regularly illegal", not differently than uploading the newest 80 GB PC game or the install disks of MS-DOS 6.22

Alternative interpretation: nothing is illegal until you are caught AND proven guilty (see kongsnutz)
 
Last edited by Ryccardo,

Sephirosu

Well-Known Member
Member
Joined
Jan 28, 2015
Messages
266
Trophies
0
Age
34
Location
Boca Raton, Florida
XP
436
Country
You can explore it in a disassembler (which may or may not exist for that specific SOC/subarchitecture) and try finding something interesting,
or you can use it in a low-level emulator (which may or may not exist yet, but the MAME team will certainly like the news),
or you can fully reverse engineer it to understand what it does so that a future emulator may have a freely licensed replacement instead of requiring this rom...

("You" for obvious reasons refers to a generic person, in fact it probably doesn't include "you" :P)


It's just "regularly illegal", not differently than uploading the newest 80 GB PC game or the install disks of MS-DOS 6.22

Alternative interpretation: nothing is illegal until you are caught AND proven guilty (see kongsnutz)


Ohh interesting. So basically this in the hands of someone that's knowledgeable can actually get the ball rolling. Cooooool. Time to wait then. At least something is out in the wild now without the need to wait for summer.
 

aerios169

Well-Known Member
Member
Joined
Dec 30, 2012
Messages
707
Trophies
1
Age
31
XP
2,234
Country
Mexico
its nothing with soldering, you have to open the switch, you have to make a short circuit for a small amount of time on 2 pins everytime you restart the switch tho
well it sounds nice, i will wait for tutorals and everything :P, i hope that this dosent affect nintendo =S
 

subcon959

@!#?@!
Member
Joined
Dec 24, 2008
Messages
5,856
Trophies
4
XP
10,160
Country
United Kingdom
Ohh interesting. So basically this in the hands of someone that's knowledgeable can actually get the ball rolling. Cooooool. Time to wait then. At least something is out in the wild now without the need to wait for summer.
This was probably already in the hands of people who could do anything with it. But of course GBAtemp will hype the hell out of it regardless.
 

andijames

Well-Known Member
Member
Joined
Jan 28, 2016
Messages
428
Trophies
0
Age
43
Location
Manchester
XP
759
Country
United Kingdom
You'll still need CFW though so whilst this may accelerate the x1 exploits visibility there's literally nothing that can be done without having something to run on it right?
 

Lacius

Well-Known Member
Member
Joined
May 11, 2008
Messages
18,099
Trophies
3
XP
18,338
Country
United States
its nothing with soldering, you have to open the switch, you have to make a short circuit for a small amount of time on 2 pins everytime you restart the switch tho
We don't know everything about Fusée Gelée and its variants, but Kate has said that users should only have to open up their Switch systems one time.

You'll still need CFW though so whilst this may accelerate the x1 exploits visibility there's literally nothing that can be done without having something to run on it right?
That's correct. We still need Atmosphère to be completed.
 

Ryccardo

Penguin accelerator
Member
Joined
Feb 13, 2015
Messages
7,696
Trophies
1
Age
28
Location
Imola
XP
6,923
Country
Italy
Ohh interesting. So basically this in the hands of someone that's knowledgeable can actually get the ball rolling. Cooooool. Time to wait then. At least something is out in the wild now without the need to wait for summer.
By the way, "something interesting" is not necessarily an exploitable vulnerability: if you think about the 3DS, while we got lucky and its bootrom ALSO contained the basis for sighax, we also got a truckload of keys out of it - resulting in the ability to encrypt/decrypt the OS and games directly on a PC (which is likely appreciated by high level emulator users), to decrypt the nand with only adding the OTP instead of xorpads to be generated on an already hacked console, ...
 
  • Like
Reactions: awtgrduzwt5r9

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Veho @ Veho:
    Double dickhead chinballs is still better than double dickhead eyeballs.
    +1
  • Veho @ Veho:
    As in, the balls will grow in your eye sockets.
  • K3Nv2 @ K3Nv2:
    I paid 5 grand to get them moved to my chin
    +1
  • Veho @ Veho:
    This you?
  • K3Nv2 @ K3Nv2:
    My hair can't be that cool
    +1
  • Veho @ Veho:
    Ah, yes, portrait mode, surely the best way to film a row of people. If only there were some way to fit a wider shot, at the expense of height... if only...
    +1
  • K3Nv2 @ K3Nv2:
    4k portrait mode?
    +1
  • BigOnYa @ BigOnYa:
    Diddy - "I never touched her, that bitch is crazy." Video is released. Diddy - " Ok I did it, i am remorseful for my actions during my darkest times." Lol
  • SylverReZ @ SylverReZ:
    @BigOnYa, Glad that the Diddler got caught once again.
    +1
  • K3Nv2 @ K3Nv2:
    Iran ran out of options
  • K3Nv2 @ K3Nv2:
    Thought I saw my ex on that new kingdom of the Apes poster
  • BigOnYa @ BigOnYa:
    I thought I saw a puttie snatch...
  • BigOnYa @ BigOnYa:
    I'm so pumped, NCAA football video game is back after a 10 year hiatus, coming to SeriesS/X, PS5 in July.
  • BigOnYa @ BigOnYa:
    Wish they would let us play the NCAA football 14 on newer xbox, its one of the only games I love and own on disc still, that is not back compatible, bs.
  • AdenTheThird @ AdenTheThird:
    @BigOnYa My dad recently bought a spare Series X off of me, got game pass, and saw Madden '24 on Game Pass, decided to try it out.

    ...He was a bit taken aback by the 60GB download size. Poor guy's still living in the 90s!
    +1
  • SylverReZ @ SylverReZ:
    @AdenTheThird, Bro's still in the PS2 age.
  • K3Nv2 @ K3Nv2:
    Lol charging your dad's classic unless he's the type that doesn't like taking things like that
  • AdenTheThird @ AdenTheThird:
    @K3Nv2 He was looking into consoles for his house anyway (for my younger siblings and himself) and I had a spare XSX and Switch I ended up selling him at pretty steep cuts. I would just give them to him, but I did buy them with the intent to sell them... and college is super expensive.
    AdenTheThird @ AdenTheThird: @K3Nv2 He was looking into consoles for his house anyway (for my younger siblings and himself)...