Fusee Gelee: All the payloads

Discussion in 'Switch - Exploits, Custom Firmwares & Soft Mods' started by jjbredesen, Apr 25, 2018.

  1. dubbz82

    dubbz82 GBAtemp Advanced Maniac

    Member
    7
    Feb 2, 2014
    United States

    They can't be linked here. They're considered copyrighted data, I believe
     
  2. Naked_Snake

    Naked_Snake Constant Miscreant

    Member
    6
    Oct 6, 2013
    Australia
    Hyrule Field
    Is there a tutorial for this
     
  3. jjbredesen
    OP

    jjbredesen WarezNX Owner

    Member
    13
    GBAtemp Patron
    jjbredesen is a Patron of GBAtemp and is helping us stay independent!

    Our Patreon
    Feb 16, 2018
    Norway
    Hyrule
    There are but we can't link to anything, google.
     
  4. Naked_Snake

    Naked_Snake Constant Miscreant

    Member
    6
    Oct 6, 2013
    Australia
    Hyrule Field
    I’m getting nothing in google but I’ll try different word combinations and see
     
  5. Ghost92

    Ghost92 GBAtemp Fan

    Member
    4
    Jun 29, 2017
    Colombia
    Because you add Admosfera if it's not a useful charge yet
     
  6. Indigo Marz

    Indigo Marz Indigo Marz - No HooX

    Member
    4
    Aug 4, 2011
    United States
    Funcoland
    Bruh imma just wait for the guide to drop ive been this patient, im definitely not about to risk my system yet when its not even managed by the teams yet. Take yall time and get it right cuz i knoooow hella folks are about to try this shit and fuck up their switch lol
     
    Last edited by Indigo Marz, Apr 27, 2018
    Maximilious likes this.
  7. asper

    asper GBAtemp Advanced Fan

    Member
    6
    May 14, 2010
    United States
    Is TSEC FW the same for all Switches or does it contain per-console data ?
     
    Last edited by asper, Apr 27, 2018
  8. kombos

    kombos GBAtemp Regular

    Member
    2
    Apr 24, 2018
    Ukraine
    Universe
    It contains console specific SBK key.
     
    asper likes this.
  9. asper

    asper GBAtemp Advanced Fan

    Member
    6
    May 14, 2010
    United States
    Do you know at which offset ?

    EDIT: anyway to transform extracted TSEC fw.bin into an usable array use this command:

    Code:
    hexdump -v -e '", " "0x" 1/1 "%02X"' fw.bin >array.txt
    just remember to remove the 1st 2 chars (", ") from obtained array.txt
     
    Last edited by asper, Apr 27, 2018
  10. ehnoah

    ehnoah GBAtemp Advanced Fan

    Member
    4
    Oct 9, 2012
    Netherlands
    Got my Keys and everything :]
     
    Last edited by ehnoah, Apr 27, 2018
    asper and Stoned like this.
  11. rajkosto

    rajkosto GBAtemp Advanced Fan

    Member
    11
    Apr 6, 2017
    No, the TSEC FW does not contain anything console specific, and it's the same binary regardless of what switch firmware version you have. (It's in boot0, search for the first 4 bytes mentioned in tsecfw.inl to find it)
    Obviously the TSEC KEY you get out of the dumper is console specific, as are all the keys dumped by biskeydump.

    ehnoah, did you type them all out by hand ? Because you no longer have to (QR Code output in v3) :P
     
    Last edited by rajkosto, Apr 27, 2018
    asper likes this.
  12. asper

    asper GBAtemp Advanced Fan

    Member
    6
    May 14, 2010
    United States
    My fw offset was 0x101A00 and not 0x101900
     
  13. rajkosto

    rajkosto GBAtemp Advanced Fan

    Member
    11
    Apr 6, 2017
    yes, the offsets mentioned are for 1.0.0. newer firmwares (like 3.0.0) have a bit more code before the tsec fw starts, thats why its recommended to just search for the 4 bytes instead
     
  14. TheZander

    TheZander King of the Level 7's

    Member
    9
    Feb 1, 2008
    United States
    Level 7
    I found the first bits mentioned, but I don't know how many of these things to copy. I know it's 3840 bytes but I'm not sure how man 2 digit numbers make that up
     
    kombos likes this.
  15. hippy dave

    hippy dave BBMB

    Member
    12
    Apr 30, 2012
    United Kingdom
    If you're talking about in a hex editor, each pair of characters is a byte.
     
  16. kombos

    kombos GBAtemp Regular

    Member
    2
    Apr 24, 2018
    Ukraine
    Universe
    aut0mat3d and Nick1983 like this.
  17. asper

    asper GBAtemp Advanced Fan

    Member
    6
    May 14, 2010
    United States
    Well i finally was able to compile biskeydump.bin with absolutely no errors (my problem was related to a missing/invalid devkitarm path) but obtained keys give error in the HacDiskMount "FAIL! Entropy: 8.989 (tested 16348 out of 16348)"; i tested with 2 kinds of data array, always with the same keys results but they seems not to work... any hint ? Is it possible that tsec fw is different in size between 1.0.0 and 3.0.0 switch fw ?
     
  18. rajkosto

    rajkosto GBAtemp Advanced Fan

    Member
    11
    Apr 6, 2017
    do you get a different tsec key if you run SciresM tsec_key_stub.bin (with properly filled in tsecfw instead of the XXXXXXXs, of course) ? If you do, then there might be some weirdness going on where different payloads read different tsec keys (and there's no consistency which one is the right one, on like 90% switches they both give out the same key)

    and no, tsec fw is identical for all switches, all fw revisions, if the CRC32 says its CORRECT! then that's not the problem
     
  19. asper

    asper GBAtemp Advanced Fan

    Member
    6
    May 14, 2010
    United States
    If you point me to sciresm tool i will test it right now.
     
  20. leon315

    leon315 POWERLIFTER

    Member
    7
    Nov 27, 2013
    Italy
    even a youtube videoguide is forbidden?
     
Loading...