Hacking Downgrade 9.0.3 Ipatched switch

linuxares

The inadequate, autocratic beast!
Global Moderator
Joined
Aug 5, 2007
Messages
13,329
Trophies
2
XP
18,209
Country
Sweden
But with which tool we can downgrade ? If it's possible.
I thought maybe Mattytrog might know how to raw write it. Classic write every 0101 directly to the nand. I let him answer and we shall see. It might not be possible at all.
 

mattytrog

You don`t want to listen to anything I say.
Member
Joined
Apr 27, 2018
Messages
3,708
Trophies
0
Age
48
XP
4,328
Country
United Kingdom
@mattytrog and/or @MatinatorX
Wouldn't it be possible to do a raw dump of the nand? I guess you need the keys to do a "raw" downgrade as well?
The only way of getting a raw NAND dump for this gentleman, is to unplug his eMMC from his Switch, fit into another fusee vuln Switch and dump rawnand via Hekate, remembering associated boot0/1.

But a downgrade won`t boot because 9.0.1 fusecount is active.

So, yes. You can fully downgrade.

But if your fuses are cooked, forget about actually booting it on an ipatched unit.

I don`t have any ipatched units here sadly.

But I am more convinced we can glitch it into booting. The Tegra oscillator circuit (38.4Mhz) is right there. I`m thinking of a Trinket yet again, use a spare pin, connect a strap to the oscillator testpoint and pulse it (pull it high / low - see if it can dizzy the Tegra into running unsigned code).

I cannot actually try this and I`m sure more knowledgeable people than me have already tried this.
 
Last edited by mattytrog,
  • Like
Reactions: Tumoche

emris93

Active Member
OP
Newcomer
Joined
Nov 21, 2016
Messages
39
Trophies
0
Age
30
XP
221
Country
France
Maybe I have a backup of the rawnand (same with nand?) I will confirm you tonight.
You are a lovely Guy @mattytrog;)

Have a ipatched switch but I'm very noob on "DIY" so too risky for me.
 
Last edited by emris93,

LoggerMan

Well-Known Member
Member
Joined
Jun 10, 2011
Messages
567
Trophies
1
XP
845
Country
Yes it's 9.0.1 a mistake of my part sorry.

omg you nearly gave me a heart attack with this 9.0.3 stuff. I updated my sysnand to that too recently, burning fuses, because it’s compatible with os sx anyway. I’m so lazy. I think I used the safe update method to update emunand though.
 

emris93

Active Member
OP
Newcomer
Joined
Nov 21, 2016
Messages
39
Trophies
0
Age
30
XP
221
Country
France
omg you nearly gave me a heart attack with this 9.0.3 stuff. I updated my sysnand to that too recently, burning fuses, because it’s compatible with os sx anyway. I’m so lazy. I think I used the safe update method to update emunand though.
I'm very sorry for that :(
 

ZachyCatGames

Well-Known Member
Member
Joined
Jun 19, 2018
Messages
3,398
Trophies
1
Location
Hell
XP
4,209
Country
United States
I think yes in choixdujourNX you have the choice to update sysnand or emunand. The mistake that I had is leaving tick sysnand by default.
Just simple search in Google can confirme that.
No, it doesn’t. I’ve been using Choi a shit ton recently, there’s definitely no option like that.
 

emris93

Active Member
OP
Newcomer
Joined
Nov 21, 2016
Messages
39
Trophies
0
Age
30
XP
221
Country
France
No, it doesn’t. I’ve been using Choi a shit ton recently, there’s definitely no option like that.

I don't have a game cartridge and I blocked the nintendo updates with the DNS so I don't see how my switch could be updated and the only update that I made it's with choixdujourNX.
 

ZachyCatGames

Well-Known Member
Member
Joined
Jun 19, 2018
Messages
3,398
Trophies
1
Location
Hell
XP
4,209
Country
United States
I don't have a game cartridge and I blocked the nintendo updates with the DNS so I don't see how my switch could be updated and the only update that I made it's with choixdujourNX.
You probably accidentally booted into your sysmmc instead of emummc when you went to update. Writing to sysmmc from emummc isn’t really something that can be easily done, also the last Choi update released before emummc did :P
 

emris93

Active Member
OP
Newcomer
Joined
Nov 21, 2016
Messages
39
Trophies
0
Age
30
XP
221
Country
France
You probably accidentally booted into your sysmmc instead of emummc when you went to update. Writing to sysmmc from emummc isn’t really something that can be easily done, also the last Choi update released before emummc did :P

I think I found : unintentionally I installed atm in sysnand and when i updated atm it update also the sysnand.
 
Last edited by emris93,

emris93

Active Member
OP
Newcomer
Joined
Nov 21, 2016
Messages
39
Trophies
0
Age
30
XP
221
Country
France
That's not really how it works, you must have had a boot entry for sysNAND in Hekate and booted into it like I said.
That's what I said I installed atm in the sysnand and when booting I booted directly to the sysnand via hekate without creating the emunand and I made the update with choidujourNX everything being in the sysnand believing I was in emunand.
 

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,316
Trophies
4
Location
Space
XP
13,894
Country
Norway
That's what I said I installed atm in the sysnand and when booting I booted directly to the sysnand via hekate without creating the emunand and I made the update with choidujourNX everything being in the sysnand believing I was in emunand.
Oh.
For future reference you can check by looking at the firmware version in System Settings, there should be an E after the version if you're in emuNAND.
Also a good idea to change the theme and user icons so they're different between the two.
 
  • Like
Reactions: Kafluke

emris93

Active Member
OP
Newcomer
Joined
Nov 21, 2016
Messages
39
Trophies
0
Age
30
XP
221
Country
France
Oh.
For future reference you can check by looking at the firmware version in System Settings, there should be an E after the version if you're in emuNAND.
Also a good idea to change the theme and user icons so they're different between the two.
Yeah I know but to late now. Then I have two solutions :
- a miracle occurs to be able to downgrade before January.
- waiting for the solution tx in January.
 
Last edited by emris93,

tivu100

Well-Known Member
Member
Joined
Jun 6, 2015
Messages
2,260
Trophies
0
Age
34
XP
1,136
Country
United States
You can update with choidujournx, but it won't help as you can't avoid burning the fuses with an ipatched switch.

How that works is you force into RCM on every boot and then use a payload, but that can't possibly work for you. Either choidujournx will refuse to enable autorcm, or your switch will be bricked and require you to remove autorcm using a hard mod. Either way as soon as you boot then fuses will be burned.

If you want the latest version on an ipatched switch then you need to setup emunand, but of course you need to be on a quite low firmware to be able to trigger that right now.
Echo this point here but short Andy simple:

Don’t use AutoRCM on ipatched Switch
 

tivu100

Well-Known Member
Member
Joined
Jun 6, 2015
Messages
2,260
Trophies
0
Age
34
XP
1,136
Country
United States
Oh.
For future reference you can check by looking at the firmware version in System Settings, there should be an E after the version if you're in emuNAND.
Also a good idea to change the theme and user icons so they're different between the two.
The more OP said, the more I feel like it’s just lying to cover for his mistake:

Clearly said OP didn’t make an EMUNAND, yet somehow wishful thinking booting via Hetake would magically create EMUNAND!

“...in choixdujourNX you have the choice to update sysnand or emunand...”

Nothing can be further from truth, just as Hekate point.

People, please stop suggesting with downgrading using raw NAND dump. It’s an ipatched Switch and it’s running on latest firmware (fuses burned)! Clearly no fuses protection enabled.

Edit:

Not trying to burn anyone. The point is everyone make mistake. Own it up, and learn from it, or you make the same mistake again (doesn’t understand what you’re doing and don’t ask for help when you should).
 
Last edited by tivu100,
  • Like
Reactions: The Real Jdbye

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • TwoSpikedHands @ TwoSpikedHands:
    Do I restart now using what i've learned on the EU version since it's a better overall experience? or do I continue with the US version since that is what ive been using, and if someone decides to play my hack, it would most likely be that version?
  • Sicklyboy @ Sicklyboy:
    @TwoSpikedHands, I'll preface this with the fact that I know nothing about the game, but, I think it depends on what your goals are. Are you trying to make a definitive version of the game? You may want to refocus your efforts on the EU version then. Or, are you trying to make a better US version? In which case, the only way to make a better US version is to keep on plugging away at that one ;)
  • Sicklyboy @ Sicklyboy:
    I'm not familiar with the technicalities of the differences between the two versions, but I'm wondering if at least some of those differences are things that you could port over to the US version in your patch without having to include copyrighted assets from the EU version
  • TwoSpikedHands @ TwoSpikedHands:
    @Sicklyboy I am wanting to fully change the game and bend it to my will lol. I would like to eventually have the ability to add more characters, enemies, even have a completely different story if i wanted. I already have the ability to change the tilemaps in the US version, so I can basically make my own map and warp to it in game - so I'm pretty far into it!
  • TwoSpikedHands @ TwoSpikedHands:
    I really would like to make a hack that I would enjoy playing, and maybe other people would too. swapping to the EU version would also mean my US friends could not legally play it
  • TwoSpikedHands @ TwoSpikedHands:
    I am definitely considering porting over some of the EU features without using the actual ROM itself, tbh that would probably be the best way to go about it... but i'm sad that the voice acting is so.... not good on the US version. May not be a way around that though
  • TwoSpikedHands @ TwoSpikedHands:
    I appreciate the insight!
  • The Real Jdbye @ The Real Jdbye:
    @TwoSpikedHands just switch, all the knowledge you learned still applies and most of the code and assets should be the same anyway
  • The Real Jdbye @ The Real Jdbye:
    and realistically they wouldn't

    be able to play it legally anyway since they need a ROM and they probably don't have the means to dump it themselves
  • The Real Jdbye @ The Real Jdbye:
    why the shit does the shitbox randomly insert newlines in my messages
  • Veho @ Veho:
    It does that when I edit a post.
  • Veho @ Veho:
    It inserts a newline in a random spot.
  • The Real Jdbye @ The Real Jdbye:
    never had that i don't think
  • Karma177 @ Karma177:
    do y'all think having an sd card that has a write speed of 700kb/s is a bad idea?
    trying to restore emunand rn but it's taking ages... (also when I finished the first time hekate decided to delete all my fucking files :wacko:)
  • The Real Jdbye @ The Real Jdbye:
    @Karma177 that sd card is 100% faulty so yes, its a bad idea
  • The Real Jdbye @ The Real Jdbye:
    even the slowest non-sdhc sd cards are a few MB/s
  • Karma177 @ Karma177:
    @The Real Jdbye it hasn't given me any error trying to write things on it so I don't really think it's faulty (pasted 40/50gb+ folders and no write errors)
  • DinohScene @ DinohScene:
    run h2testw on it
    +1
  • DinohScene @ DinohScene:
    when SD cards/microSD write speeds drop below a meg a sec, they're usually on the verge of dying
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Samsung SD format can sometimes fix them too
  • Purple_Heart @ Purple_Heart:
    yes looks like an faulty sd
  • Purple_Heart @ Purple_Heart:
    @Psionic Roshambo i may try that with my dead sd cards
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    It's always worth a shot
  • TwoSpikedHands @ TwoSpikedHands:
    @The Real Jdbye, I considered that, but i'll have to wait until i can get the eu version in the mail lol
    TwoSpikedHands @ TwoSpikedHands: @The Real Jdbye, I considered that, but i'll have to wait until i can get the eu version in the...