Hacking Question Current status of Switch homebrew/CFW?

A

a9lh-1user

Guest
There has to be one:

"Recently, it has come to our attention there's a new revision of the Nintendo Switch in the wild which is incompatible with our SX Pro product. This isn't simply an incompatibility with SX Pro but rather appeared to be a fix of the infamous "USB RCM" exploit.

Naturally, we had to locate one of these new Switch units to get to the bottom of this. Our new Switch unit arrived to us at firmware version 5.1.0 and what we found out is the following (sorry, time to get a bit technical):

One of the IPATCH entries in the fuse set (entry #3) has been replaced with a new patch. The old patch patches the bootrom location 0x10fb3c with the value "00 20" (mov r0, #0 in thumb), and the new patch patches the bootrom location 0x10769a with the value "00 21" (mov r1, #0 in thumb). This new patch effectively zeroes out the upper-byte of the wLength field in the USB RCM endpoint 0 handling code.

Those who are paying attention probably wonder how we know the exact details of this IPATCH entry change, since we can't read out the fuses without our precious USB RCM exploit, right? It is a classic chicken and egg problem.

The answer is obvious: There is more than one coldboot bootrom exploit, and it is not just the warmboot one.

So don't fear: we will deliver a solution for these new "unhackable" switches in due time!

Thank you for attention."


Source: https://team-xecuter.com/team-xecuter-versus-the-unhackable-switch/


But they wont share it ..... me think :blink:
 

Th3C0d3br34k3r

Member
Newcomer
Joined
May 15, 2018
Messages
19
Trophies
0
Age
33
XP
285
Country
Venezuela
as we know long time ago 3.0.0 is the maximun,some people said 4.1.0. lower is better be patient.
I have nothing to wait, I've already (Rather, my sister) updated to 5.1, and it's somewhat awkward putting the jig and connecting. It's just a little bit dissapointing.
 

MushGuy

Well-Known Member
Member
Joined
Feb 11, 2010
Messages
1,280
Trophies
1
XP
2,598
Country
United States
as we know long time ago 3.0.0 is the maximun,some people said 4.1.0. lower is better be patient.
Currently I'm still waiting on 3.0.0, too. One for a coldboot method, second to see if there will be some kind of stealth mode to avoid bans, and third to see how it will turn out with the upcoming paid online service.
 

mariogamer

Well-Known Member
Member
Joined
Aug 12, 2015
Messages
1,256
Trophies
0
Age
28
XP
790
Country
Canada
There has to be one:

"Recently, it has come to our attention there's a new revision of the Nintendo Switch in the wild which is incompatible with our SX Pro product. This isn't simply an incompatibility with SX Pro but rather appeared to be a fix of the infamous "USB RCM" exploit.

Naturally, we had to locate one of these new Switch units to get to the bottom of this. Our new Switch unit arrived to us at firmware version 5.1.0 and what we found out is the following (sorry, time to get a bit technical):

One of the IPATCH entries in the fuse set (entry #3) has been replaced with a new patch. The old patch patches the bootrom location 0x10fb3c with the value "00 20" (mov r0, #0 in thumb), and the new patch patches the bootrom location 0x10769a with the value "00 21" (mov r1, #0 in thumb). This new patch effectively zeroes out the upper-byte of the wLength field in the USB RCM endpoint 0 handling code.

Those who are paying attention probably wonder how we know the exact details of this IPATCH entry change, since we can't read out the fuses without our precious USB RCM exploit, right? It is a classic chicken and egg problem.

The answer is obvious: There is more than one coldboot bootrom exploit, and it is not just the warmboot one.

So don't fear: we will deliver a solution for these new "unhackable" switches in due time!
Thank you for attention."


Source: https://team-xecuter.com/team-xecuter-versus-the-unhackable-switch/


But they wont share it ..... me think :blink:
Just to say that SciresM/hexkyz denied that you need a trustzone warmboot/coldboot exploit to access the fuse (you can access them on userspace by taking over certain parts of the systems). So the message of this is not true and they might not necessary have it.
 

sblast3

Well-Known Member
Member
Joined
Dec 27, 2014
Messages
166
Trophies
0
XP
307
Country
United States
It would be nice if there was a script that periodically scans the /v/ catalog for a new /hbg/ thread and inserts the OP into an RSS feed.
 

tinysolderingguy

Banned!
Banned
Joined
Jul 4, 2018
Messages
69
Trophies
0
Age
23
XP
67
Country
United States
For future reference, the /hbg/ thread on 4chan keeps a little update log in each OP. Good for recent events and advancements. People there aren't very nice so I would recommend limiting interaction with /hbg/ to just lurking.

SX OS patch 1.4. Can find information here.
https://team-xecuter.com/sx-os-v1-4-announcement

Team TX says they found new exploit for the new patched Switch models released in July. Can find information here.
https://team-xecuter.com/team-xecuter-versus-the-unhackable-switch

Switch March SDK was released. Nothing of value for non-developers. Not ok to distribute on GBATemp.

Atmosphere 0.7, first release, coming out at the end of this month. Can find information here.
https://github.com/Atmosphere-NX/Atmosphere/wiki/release-plans

ReiNX CFW is now legal to distribute. Auto patching. Prevents gamecard reader from updating too. Can find here.
https://gbatemp.net/threads/official-reinx-thread.512203/

Tinfoil can install game, game updates, and game DLC via .NSP files. Can find here.
https://buildserv.stayathomeserver.club/tinfoil/

With the .XCI to .NSP converter, there isn't really a need for SX OS anymore unless you really just need to have .XCIs. Reminiscent of 3DS and the .3DS and .CIA conflict. Can find here.
https://gbatemp.net/threads/4nxci-open-source-xci-to-nsp-converter.513758/

RajNX CFW is a thing. Not sure why you would want to use this instead of Atmosphere or ReiNX. Can find here.
https://gbatemp.net/threads/rajnx-c...free-starter-pack-for-nintendo-switch.513785/

ChuoDujourNX allows for automated updating without burning Switch fuses. Still forces AutoRCM to prevent fuse burning. Can find here.
https://gbatemp.net/threads/choiduj...ller-homebrew-for-the-nintendo-switch.513416/
wym? /hbg/ is VERY nice. 100% would love to talk with them again. had a nice discussion with them
 

M7L7NK7

Well-Known Member
Member
Joined
Oct 16, 2017
Messages
3,905
Trophies
1
Website
youtube.com
XP
5,983
Country
Australia
Just to say that SciresM/hexkyz denied that you need a trustzone warmboot/coldboot exploit to access the fuse (you can access them on userspace by taking over certain parts of the systems). So the message of this is not true and they might not necessary have it.

Why would they lie though? They've managed to do things that no one else can do still so I wouldn't doubt them
 
  • Like
Reactions: Pluupy

mariogamer

Well-Known Member
Member
Joined
Aug 12, 2015
Messages
1,256
Trophies
0
Age
28
XP
790
Country
Canada
Why would they lie though? They've managed to do things that no one else can do still so I wouldn't doubt them
The message that you need the rcm exploit for that is still not true.

They got no reasons of lying.
Things they have done by themself on switch? Xci backup loading.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • TwoSpikedHands @ TwoSpikedHands:
    Do I restart now using what i've learned on the EU version since it's a better overall experience? or do I continue with the US version since that is what ive been using, and if someone decides to play my hack, it would most likely be that version?
  • Sicklyboy @ Sicklyboy:
    @TwoSpikedHands, I'll preface this with the fact that I know nothing about the game, but, I think it depends on what your goals are. Are you trying to make a definitive version of the game? You may want to refocus your efforts on the EU version then. Or, are you trying to make a better US version? In which case, the only way to make a better US version is to keep on plugging away at that one ;)
  • Sicklyboy @ Sicklyboy:
    I'm not familiar with the technicalities of the differences between the two versions, but I'm wondering if at least some of those differences are things that you could port over to the US version in your patch without having to include copyrighted assets from the EU version
  • TwoSpikedHands @ TwoSpikedHands:
    @Sicklyboy I am wanting to fully change the game and bend it to my will lol. I would like to eventually have the ability to add more characters, enemies, even have a completely different story if i wanted. I already have the ability to change the tilemaps in the US version, so I can basically make my own map and warp to it in game - so I'm pretty far into it!
  • TwoSpikedHands @ TwoSpikedHands:
    I really would like to make a hack that I would enjoy playing, and maybe other people would too. swapping to the EU version would also mean my US friends could not legally play it
  • TwoSpikedHands @ TwoSpikedHands:
    I am definitely considering porting over some of the EU features without using the actual ROM itself, tbh that would probably be the best way to go about it... but i'm sad that the voice acting is so.... not good on the US version. May not be a way around that though
  • TwoSpikedHands @ TwoSpikedHands:
    I appreciate the insight!
  • The Real Jdbye @ The Real Jdbye:
    @TwoSpikedHands just switch, all the knowledge you learned still applies and most of the code and assets should be the same anyway
  • The Real Jdbye @ The Real Jdbye:
    and realistically they wouldn't

    be able to play it legally anyway since they need a ROM and they probably don't have the means to dump it themselves
  • The Real Jdbye @ The Real Jdbye:
    why the shit does the shitbox randomly insert newlines in my messages
  • Veho @ Veho:
    It does that when I edit a post.
  • Veho @ Veho:
    It inserts a newline in a random spot.
  • The Real Jdbye @ The Real Jdbye:
    never had that i don't think
  • Karma177 @ Karma177:
    do y'all think having an sd card that has a write speed of 700kb/s is a bad idea?
    trying to restore emunand rn but it's taking ages... (also when I finished the first time hekate decided to delete all my fucking files :wacko:)
  • The Real Jdbye @ The Real Jdbye:
    @Karma177 that sd card is 100% faulty so yes, its a bad idea
  • The Real Jdbye @ The Real Jdbye:
    even the slowest non-sdhc sd cards are a few MB/s
  • Karma177 @ Karma177:
    @The Real Jdbye it hasn't given me any error trying to write things on it so I don't really think it's faulty (pasted 40/50gb+ folders and no write errors)
  • DinohScene @ DinohScene:
    run h2testw on it
    +1
  • DinohScene @ DinohScene:
    when SD cards/microSD write speeds drop below a meg a sec, they're usually on the verge of dying
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Samsung SD format can sometimes fix them too
  • Purple_Heart @ Purple_Heart:
    yes looks like an faulty sd
  • Purple_Heart @ Purple_Heart:
    @Psionic Roshambo i may try that with my dead sd cards
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    It's always worth a shot
  • TwoSpikedHands @ TwoSpikedHands:
    @The Real Jdbye, I considered that, but i'll have to wait until i can get the eu version in the mail lol
    TwoSpikedHands @ TwoSpikedHands: @The Real Jdbye, I considered that, but i'll have to wait until i can get the eu version in the...