Bought used switch, advice needed

Discussion in 'Switch - Exploits, Custom Firmwares & Soft Mods' started by Madridi, May 14, 2019.

  1. Kafluke

    Kafluke GBAtemp Guru

    Member
    13
    May 6, 2006
    United States
    Just search for "foil RCM switch" on YouTube. I understand your reluctance but if you do it right there is very little risk. It's a clean and easy way to get into RCM. I wouldnt recommend it as a permanent solution but it's enough for you to enable autoRCM.
     
    stitchxd likes this.
  2. stitchxd

    stitchxd GBAtemp Regular

    Member
    3
    Apr 27, 2017
    United States
    nope
    woah that's crazy! The only real risk I see is making the fold too "big" or using cheap foil that breaks very easy. Otherwise it looks viable for sure, even if only to enable AutoRCM.
     
    Kafluke likes this.
  3. Madridi
    OP

    Madridi Card Collector

    Member
    9
    May 9, 2008
    Qatar
    Doha
    @stitchxd

    Used the tinfoil method and tegrarcmgui.

    No RCM device detected
    RCM Device detected
    Preset "PAYLOAD_FILE" set to : E:\hekate_ctcaer_4.10.1.bin
    Invoking TegraRcmSmash.exe with args : "E:\hekate_ctcaer_4.10.1.bin"
    TegraRcmSmash (32bit) 1.2.1-3 by rajkosto
    Opened USB device path \\?\usb#vid_0955&pid_7321#6&fd8bc8d&0&3#{aa0dbd45-3117-f331-5c49-76bf65225042}
    RCM Device with id 000602030000000C4257446401101062 initialized successfully!
    Uploading payload (mezzo size: 92, user size: 121599, total size: 187815, total padded size: 188416)...
    Switched to high buffer
    Smashing the stack!
    Smashed the stack with a 0x0000 byte SETUP request!
    Payload successfully injected

    Does this mean this switch is patched (and therefore, no cfw possible atm)?
     
  4. stitchxd

    stitchxd GBAtemp Regular

    Member
    3
    Apr 27, 2017
    United States
    nope
    No, in fact it pushed the payload, so the switch is unpatched and ready for CFW!

    RE: RCM Device with id 000602030000000C4257446401101062 initialized successfully!
    RE: Payload successfully injected

    Good luck!
     
  5. Draxzelex

    Draxzelex GBAtemp Guru

    Member
    18
    Aug 6, 2017
    United States
    New York City
    No it is patched because it was smashed with 0x0000 byte stack meaning the payload did nothing.
     
  6. Madridi
    OP

    Madridi Card Collector

    Member
    9
    May 9, 2008
    Qatar
    Doha
    I'm confused..

    Please check point 7.1 and 7.2 in this thread:
    https://gbatemp.net/threads/a-defin...atched-or-not-purchases-after-07-2018.512018/

    While this is a different method, isnt it essentially the same result? This lead me to believe that the switch is patched?

    Oh and, after injecting payload, the screen stayed black. Is that what is supposed to happen?

    — Posts automatically merged - Please don't double post! —

    Ah damn, so my suspicions were correct. So this is confirmed to be patched right? I can use it normally?

    How do I exit back to normal now? Just hold Power button for 10s, remove the joycon, remove tinfoil, then use it as normal?
     
  7. Draxzelex

    Draxzelex GBAtemp Guru

    Member
    18
    Aug 6, 2017
    United States
    New York City
    Yeah do exactly as you said. If you really want to hack the Switch, buy an unpatched one after checking the serial number. If you cannot buy another console, keep your firmware as low as possible unless its on 8.X in which case you may really need to invest in another console.
     
    Madridi likes this.
  8. Madridi
    OP

    Madridi Card Collector

    Member
    9
    May 9, 2008
    Qatar
    Doha
    Thanks but I already have several other switches, including a 1.0. I just havent gotten into the cfw scene yet :)
    https://gbatemp.net/threads/bought-used-switch-advice-needed.538465/#post-8635588

    So now, I have 2 patched switches. One on 7.0.1, and one on 8.0.1
    The 7.0.1 have 2 users on it (Me, and my sister). I am going to give this 8.0.1 to my sister.

    Is it possible to transfer 1 user only from the older switch to the newer switch, keeping in mind that one of them is NOT on the latest fw?
     
  9. stitchxd

    stitchxd GBAtemp Regular

    Member
    3
    Apr 27, 2017
    United States
    nope
    My apologies! I read the comment wrong.
     
    Madridi likes this.
  10. Draxzelex

    Draxzelex GBAtemp Guru

    Member
    18
    Aug 6, 2017
    United States
    New York City
    Uh...not quite sure actually. I guess there is no harm in trying; if it works, it works and if it doesn't...well hopefully there isn't any hidden system update messages.
     
    Madridi likes this.
  11. stitchxd

    stitchxd GBAtemp Regular

    Member
    3
    Apr 27, 2017
    United States
    nope
    Yea, I read the comment wrong, definitely patched.
     
    Draxzelex likes this.
  12. ch4chi

    ch4chi Member

    Newcomer
    1
    May 14, 2019
    United Kingdom
    Hi, apologies I dont mean to highjack your thread, but I'm on a very similar path as you and any help from those that have already commented would be much appreciated.

    I have a switch on 7.0.1 and have ran the check in rcm and it is not patched so can be jailbroken. I'm planning on buying the SX OS and injecting it via an android phone app. What do I need to do in the first instance? it's got a clean nand so would like to back it up but unsure how I do it and what I do after that. I just want to make sure I have a clean backup and be able to play downloaded games, have no real desire to play online in the future but want the option of doing so in case it's ever needed with the least chance of getting banned in the process. Thanks in advance
     
    Last edited by ch4chi, May 15, 2019
  13. Kafluke

    Kafluke GBAtemp Guru

    Member
    13
    May 6, 2006
    United States
    Next steps:


    Boot into Hekate
    Backup raw nand
    Backup boot 0 and boot 1
    enable autoRCM
    Decide on a CFW to use (I am a day 1 user of SX OS and couldn't be happier with it)
    You can use either SX OS, Reinx, or Atmosphere
     
  14. ch4chi

    ch4chi Member

    Newcomer
    1
    May 14, 2019
    United Kingdom
    Hi thanks for the reply, I've ordered and been sent the SX OS license so have that ready to go and know how to get into rcm mode.

    So would the above steps enable me to start using the os and have a clean copy of the original nand in case I ever needed to restore everything back to the original point of a clean ofw 7.0.1 (which is my existing ofw)?
     
  15. Kafluke

    Kafluke GBAtemp Guru

    Member
    13
    May 6, 2006
    United States
    Yes. As long as you backup the nand first thing. Dont even launch SX os yet
     
Loading...