Hacking Firmware status

SoCALCat

Well-Known Member
Newcomer
Joined
Jun 24, 2018
Messages
92
Trophies
0
Age
37
XP
249
Country
United States
So I think the patches ones don't have a problem getting to recovery mode (rcm) but they are patched so you can't send payloads. So the way to test is to try and push a payload to see if it goes through. I tested mine by checking my bis keys
I injected biskey and TagraRcmGUI Status said "Payload Injected" with a check mark in the green square of the black Switch picture of TagraRcmGUI. The only problem is that I don't see any text on the Switch Screen. The screen is completely off...

PS
I wonder if the black screen when I'm in RCM Mode has anything to do with me not setting up the Switch for the first time. It's still in factory mode...

Update.
I set the Switch for the first time to go to the home menu, but the screen still remains off while on RCM Mode.

TagraRcmGUI detects the Switch with no issues and it's able to send payloads to the Swtch. But no display on the Switch screen.

I wonder if this has to do with me not having an SD card installed in the Switch? I'll have to look for one and test it out to see if that works...
 
Last edited by SoCALCat,

gnilwob

Well-Known Member
Member
Joined
Mar 16, 2008
Messages
204
Trophies
1
XP
646
Country
Hong Kong
I injected biskey and TagraRcmGUI Status said "Payload Injected" with a check mark in the green square of the black Switch picture of TagraRcmGUI. The only problem is that I don't see any text on the Switch Screen. The screen is completely off...

PS
I wonder if the black screen when I'm in RCM Mode has anything to do with me not setting up the Switch for the first time. It's still in factory mode...

Can you try the command line in this post https://gbatemp.net/threads/black-s...-hardware-released.510858/page-7#post-8140618

No SD card is required for biskeydump payload.
 
Last edited by gnilwob,

Cdoan34

Member
Newcomer
Joined
Mar 15, 2009
Messages
11
Trophies
0
XP
115
Country
United States
I injected biskey and TagraRcmGUI Status said "Payload Injected" with a check mark in the green square of the black Switch picture of TagraRcmGUI. The only problem is that I don't see any text on the Switch Screen. The screen is completely off...

PS
I wonder if the black screen when I'm in RCM Mode has anything to do with me not setting up the Switch for the first time. It's still in factory mode...

So rcm mode is supposed to be a completely black screen on the switch. I'm not sure if you are not sending the payload correctly or if it's actually blocked. Gonna have someone with more knowledge than me to help you from here.
 

SoCALCat

Well-Known Member
Newcomer
Joined
Jun 24, 2018
Messages
92
Trophies
0
Age
37
XP
249
Country
United States
So rcm mode is supposed to be a completely black screen on the switch. I'm not sure if you are not sending the payload correctly or if it's actually blocked. Gonna have someone with more knowledge than me to help you from here.
Roger that. I'll try a few more things when I wake up in the morning.
Thx

--------------------- MERGED ---------------------------

Can you try the command line in this post https://gbatemp.net/threads/black-s...-hardware-released.510858/page-7#post-8140618

No SD card is required for biskeydump payload.
Cool! No SD Card required. I'll give it a shoot when I get up in the morning! I'll keep you posted on how it goes. Thank's for the link
 
Last edited by SoCALCat,

SoCALCat

Well-Known Member
Newcomer
Joined
Jun 24, 2018
Messages
92
Trophies
0
Age
37
XP
249
Country
United States
Can you try the command line in this post https://gbatemp.net/threads/black-s...-hardware-released.510858/page-7#post-8140618

No SD card is required for biskeydump payload.
Good Morning here in the US from So.CAL CA. That being said.

I tried the command line with TegraRcmSmash1213 and biskeydump payload! The results were not good.

This are the results I got. I added x for security purposes.

C:\Users\P.C. Killer\Desktop\New folder (4)\x64>TegraRcmSmash.exe -w biskeydump.bin BOOT:0x0
TegraRcmSmash (64bit) 1.2.1-3 by rajkosto
Wanted device not connected yet, waiting...
Looking for devices matching the pattern *VID_0955&PID_7321*
Opened USB device path \\?\usb#vxx_09xx&pxx_7xxx#5&2xxxxxxx&0&3#{aa0dxxxx-3xxx-f3xx-5xx9-7xbf6xxxxxxx}
RCM Device with id C0xxxxxxxxxxxx0Cxxx64xxxxxxxxxx2 initialized successfully!
Uploading payload (mezzo size: 92, user size: 76328, total size: 142544, total padded size: 143360)...
Smashing the stack!
Smashed the stack with a 0x0000 byte SETUP request!

It's confirmed that any Switch that starts with S/N. XAW100857XXXXX is a patched Switch...

PS
I guess that explains the reason for a blank screen on the Switch...
 
Last edited by SoCALCat,

gnilwob

Well-Known Member
Member
Joined
Mar 16, 2008
Messages
204
Trophies
1
XP
646
Country
Hong Kong
Good Morning here in the US from So.CAL CA. That being said.

I tried the command line with TegraRcmSmash1213 and biskeydump payload! The results were not good.

This are the results I got. I added x for security purposes.

C:\Users\P.C. Killer\Desktop\New folder (4)\x64>TegraRcmSmash.exe -w biskeydump.bin BOOT:0x0
TegraRcmSmash (64bit) 1.2.1-3 by rajkosto
Wanted device not connected yet, waiting...
Looking for devices matching the pattern *VID_0955&PID_7321*
Opened USB device path \\?\usb#vxx_09xx&pxx_7xxx#5&2xxxxxxx&0&3#{aa0dxxxx-3xxx-f3xx-5xx9-7xbf6xxxxxxx}
RCM Device with id C0xxxxxxxxxxxx0Cxxx64xxxxxxxxxx2 initialized successfully!
Uploading payload (mezzo size: 92, user size: 76328, total size: 142544, total padded size: 143360)...
Smashing the stack!
Smashed the stack with a 0x0000 byte SETUP request!

It's confirmed that any Switch that starts with S/N. XAW100857XXXXX is a patched Switch...

PS
I guess that explains the reason for a blank screen on the Switch...
Welcome to the club :cry:

If it is ok, please also help to report your finding here, https://gbatemp.net/threads/switch-informations-by-serial-number.481215/
So peoples can avoid the patched unit.
Thanks.
 

SoCALCat

Well-Known Member
Newcomer
Joined
Jun 24, 2018
Messages
92
Trophies
0
Age
37
XP
249
Country
United States
Last edited by SoCALCat,

SoCALCat

Well-Known Member
Newcomer
Joined
Jun 24, 2018
Messages
92
Trophies
0
Age
37
XP
249
Country
United States
Last edited by SoCALCat,
  • Like
Reactions: gnilwob

SoCALCat

Well-Known Member
Newcomer
Joined
Jun 24, 2018
Messages
92
Trophies
0
Age
37
XP
249
Country
United States
Welcome to the club :cry:

If it is ok, please also help to report your finding here, https://gbatemp.net/threads/switch-informations-by-serial-number.481215/
So peoples can avoid the patched unit.
Thanks.
Well! After my girlfriend going to 4 different stores and having the sales people and store manager check every S/N of at least 15 to 20 Switches in stock per store because they have them locked up! :D She finally was able to find one that was on the good S/N list. The crazy part is that it was the last one in stock that had a good S/N.:yayswitch:

The minute I ran TegraRcmSmash1213 and biskeydump payload! The screen on the Switch came on right away displaying the keys, where the first one I had didn't...
20180714_154126.jpg

This things are getting harder and harder to find. I got lucky that my girlfriend was able to find one for me...

Serial: XAW100801xxxxx
Serial on device matches serial on box: yes
Region: US
Firmware: 4.1.0
Color option: Gray/Black
Store: Target
Was a bundle (if yes, which): No
Purchase date: 7-14-2018
Fusée Gelée works: Didn't try it with Fusée Gelée! But Yes! It worked with (TegraRcmSmash1213 and biskeydump payload)

I'll be posting this info to the other link... ;)
 
Last edited by SoCALCat,
  • Like
Reactions: gnilwob

gnilwob

Well-Known Member
Member
Joined
Mar 16, 2008
Messages
204
Trophies
1
XP
646
Country
Hong Kong
Well! After my girlfriend going to 4 different stores and having the sales people and store manager check every S/N of at least 15 to 20 Switches in stock per store because they have them locked up! :D She finally was able to find one that was on the good S/N list. The crazy part is that it was the last one in stock that had a good S/N.:yayswitch:

The minute I ran TegraRcmSmash1213 and biskeydump payload! The screen on the Switch came on right away displaying the keys, where the first one I had didn't...
View attachment 135825

This things are getting harder and harder to find. I got lucky that my girlfriend was able to find one for me...

Serial: XAW100801xxxxx
Serial on device matches serial on box: yes
Region: US
Firmware: 4.1.0
Color option: Gray/Black
Store: Target
Was a bundle (if yes, which): No
Purchase date: 7-14-2018
Fusée Gelée works: Didn't try it with Fusée Gelée! But it Yes! It worked with (TegraRcmSmash1213 and biskeydump payload)

I'll be posting this info to the other link... ;)
It is good that you can return it.
I do not have an option to return my patched unit in Hong Kong :cry:

Are you saying that in your home town, majority of switch consoles are patched ??
WOW, it hits US very fast then.
Which state it is ?
 

SoCALCat

Well-Known Member
Newcomer
Joined
Jun 24, 2018
Messages
92
Trophies
0
Age
37
XP
249
Country
United States
It is good that you can return it.
I do not have an option to return my patched unit in Hong Kong :cry:

Are you saying that in your home town, majority of switch consoles are patched ??
WOW, it hits US very fast then.
Which state it is ?
That sucks that you can not return your patched Switch for another console. If you don't mind me asking! Why can't you return your console from where you bought it?

Here in the US all of the major stores have a 30 day return policy. No questions asked...

Yes! As far as I know. Most of the units are patched in my state of California. I'm saying this because of what my girlfriend had to go thru to find a none patched Switch...
 
Last edited by SoCALCat,

gnilwob

Well-Known Member
Member
Joined
Mar 16, 2008
Messages
204
Trophies
1
XP
646
Country
Hong Kong
That sucks that you can not return your patched Switch for another console. If you don't mind me asking! Why can't you return your console from where you bought it?

Here in the US all of the major stores have a 30 day return policy. No questions asked...

Yes! As far as I know. Most of the units are patched in my state of California. I'm saying this because of what my girlfriend had to go thru to find a none patched Switch...

The culture / marketing / policy in Asia is not as good as US :(
 

SoCALCat

Well-Known Member
Newcomer
Joined
Jun 24, 2018
Messages
92
Trophies
0
Age
37
XP
249
Country
United States
The culture / marketing / policy in Asia is not as good as US :(
That's awful. Maybe you should try to sell your patched switch and buy yourself another one that's not patched. Just make sure you write down a list of none patched S/N that are posted here on this cool site so you could compare them before you buy the Switch...
 

gnilwob

Well-Known Member
Member
Joined
Mar 16, 2008
Messages
204
Trophies
1
XP
646
Country
Hong Kong
That's awful. Maybe you should try to sell your patched switch and buy yourself another one that's not patched. Just make sure you write down a list of none patched S/N that are posted here on this cool site so you could compare them before you buy the Switch...
I got my spare one already. I will also exchange this patched unit with my friend who does not need f-g enabled.
If I am lucky, I would exchange this unit with the custom firmware provider, still waiting for their response :)
 

SoCALCat

Well-Known Member
Newcomer
Joined
Jun 24, 2018
Messages
92
Trophies
0
Age
37
XP
249
Country
United States
I got my spare one already. I will also exchange this patched unit with my friend who does not need f-g enabled.
If I am lucky, I would exchange this unit with the custom firmware provider, still waiting for their response :)
Right on! Well good luck to you and keep me posted on how it goes for you...
 
  • Like
Reactions: gnilwob

SoCALCat

Well-Known Member
Newcomer
Joined
Jun 24, 2018
Messages
92
Trophies
0
Age
37
XP
249
Country
United States
Damn my 3.0.2 switch sitting in the shelves for months waiting for Homebrew. Should I update and use SX pro instead ?
Depends on what you want to do with it! Like play XCI backups or even HB like myself. Unless your willing to wait for Atmosphere to be release and see what it's going to be able to handle.

If you can afford it. Buy yourself a second Switch so you could have the best of both worlds...
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BigOnYa @ BigOnYa:
    They have they own kids now that will pay them back for all the things they did to me, that's how it works, Karma.
    +2
  • K3Nv2 @ K3Nv2:
    Tell their kids about pawn shops
    +2
  • K3Nv2 @ K3Nv2:
    Lol I still got mw2 open beta on this ps4
  • BigOnYa @ BigOnYa:
    I just recently picked up a n64 from a garage sell, and looking to mod it and add a HDMI port to it. https://www.ebay.com/itm/3548173115...044&customid=4f3038da73b61afddf7e5e90f4153856
  • BigOnYa @ BigOnYa:
    I'd like to find a power strip and HDMI selector built in 1 unit, so I can select which game system I want, and will switch to that hdmi, and power on that plug/power supply only, so don't have all game systems powered all the time, but can't find anything like. May just have to make something myself.
  • BigOnYa @ BigOnYa:
    Maybe start a kick starter page and sell them, yea right. Big N would prob C&D me, not anything Big N related, but just because that's what they do nowdays. Then come out with they own in a year or so.
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Nice. Which operating system are you installing?
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, windows 10 and some linux distro like linux mint
  • Xdqwerty @ Xdqwerty:
    dualbooth
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Yeah, I'd recommend having another OS just in-case you want to play games.
  • SylverReZ @ SylverReZ:
    At least Linux doesn't contain spyware than what Windows has.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, cuz of lag?
  • SylverReZ @ SylverReZ:
    @Xdqwerty, No. Whenever you use the internet on Windows, Microsoft collects personal data and installs bloatware that isn't necessarily needed, such as Edge.
  • SylverReZ @ SylverReZ:
    Speaking of which
  • Xdqwerty @ Xdqwerty:
    @SylverReZ,
    I recall @impeeza mentioned some trick about not having bloatware when installing windows where you set up your country to "world" or smh like that
    +1
  • SylverReZ @ SylverReZ:
    Yes, you can debloat the operating system, but in some cases for me it just reinstalls them.
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ,
    I also recall my brother downloded a "non bloated" version of windows 11 on his pc
    +1
  • BigOnYa @ BigOnYa:
    "Why debloat? Why not embrace and enjoy my bloat?" - Gates
    +3
  • impeeza @ impeeza:
    @Xdqwerty yes, when you are installing Windows on the first steps you are asked for your current location, you MUST to select «international» so no bloatware is installed, because the bloatware is location based. if this night I have some time I will setup a VM and take screenshots.
    +2
  • BigOnYa @ BigOnYa:
    User Gates "Disliked" your answer.
    +2
    SylverReZ @ SylverReZ: :rofl2: :rofl2: +1