Hacking fail0verflow releases coldboot exploit proof of concept

  • Thread starter Thread starter Paiuand
  • Start date Start date
  • Views Views 79,714
  • Replies Replies 329
  • Likes Likes 19
Not dissimilar to the AU$50 people were charging to mod a NES and SNES mini? It's a 10 minute job... People still pay!

softmodding the snes mini is actually a cakewalk if you stick to the basics like just adding a few snes games..paying that amount is a waste unless you don't have a working computer. However, hardmodding is different. I have zero skills because i'm rich and haven't touched a soldering iron all my life. I'm being sarcastic. But still, my point is that not everyone is willing to open up their console and tinker with it. It is afterall a very expensive device and you need tiny soldering skills.
 
The chip on the ftdi friend is probably a voltage regulator(1.8v?) it connect to the 5v source, common ground and the chip signal power pin(vccio), rx and tx probably connected to pin 5(rx?) and 8(tx?) on the joycon connector (joycon side).

github-dekuNukem-Nintendo_Switch_Reverse_Engineering(sorry spam filter, google it)
View attachment DS_FT232R.pdf
DVXIvONXUAYfQyh.jpg
ftdifriendsch.png
 
Last edited by Nirim000,
I for one assume from f0f’s latest tweet that they WILL release their exploit, right after TX come out with their modchip solution.
After all, why make the point No Modchip needed?
Surely that’s a direct threat to TX to say we have a free solution up our sleeve, and assuming they dislike people making money out of piracy more than any other factor, would feel obliged to steal their thunder if required.

BTW in case anyone missed it I see qlutoo’s got a boot rom exploit also
https://twitter.com/qlutoo/status/953260267823157248
Not sure if it’s the same method as f0f’s
Bootromhax are getting like 10 a penny these days.

What makes you think he has a bootrom exploit?
 
What makes you think he has a bootrom exploit?

Because if you look at qlutoo's contribution on the wiki, his presentation at the conference... Those are info need more higher privilege to access more info on the Switch, AKA Bootrom level exploit. Then in this tweet, qlutoo confirmed he doesn't rely on any kind of hardware to do so. This means it's softmod approach
 
Last edited by tivu100,
Because if you look at qlutoo's contribution on the wiki, his presentation at the conference... Those are info need more higher privilege to access more info on the Switch, AKA Bootrom level exploit. Then in this tweet, qlutoo confirmed he doesn't rely on any kind of hardware to do so. This means it's softmod approach
This doesn't automatically verify it as a bootrom exploit though. They were able to pwn TZ on firmware 1.0.0 via a side channel attack. They didn't have a bootrom exploit then If I'm not mistaken. Feel free to correct me.
 
This doesn't automatically verify it as a bootrom exploit though. They were able to pwn TZ on firmware 1.0.0 via a side channel attack. They didn't have a bootrom exploit then If I'm not mistaken. Feel free to correct me.
TX teased coldbooting Switch for their product and said work all available firmware. Qlutoo tweet directly mocks that product.
 
TX teased coldbooting Switch for their product and said work all available firmware. Qlutoo tweet directly mocks that product.
My bad, you're right. TX released a tease on the 7th, Plutoo mocked on the 17th. I don't know if he was directly mocking them based on him having a bootrom exploit as well, or if he was making fun of them potentially releasing a solderless option, but not following through though.
 

Site & Scene News

Popular threads in this forum