fusée gelée -- coldboot proof-of-concept for the Tegra X1

DWOUcCQU8AEMUEb.jpg DWOUZnCVAAAb2jJ.jpg Thank's to @ktemkin and all Reswitched Team[prebreak]1[/prebreak]:wink::wink:

I'm super pleased to tease "fusée gelée", @reswitchedteam's proof-of-concept coldboot execution hack-- with which we join the growing ranks of those with unpatchable Tegra X1 bootrom bugs.
Quick video of it in action on a Switch: https://youtu.be/ik04jn0obag

 

DerProGamer2000

Well-Known Member
Newcomer
Joined
Apr 17, 2017
Messages
56
Trophies
0
Age
23
XP
129
Country
Germany
isn't it kind of funny that nintendo did the protection very good on this console but its somehow the fastest hacked console of nintendo yet even thou the protection is good :D
 
  • Like
Reactions: Owenge

ken28

Well-Known Member
Member
Joined
Oct 21, 2010
Messages
1,181
Trophies
1
XP
1,693
Country
Germany
isn't it kind of funny that nintendo did the protection very good on this console but its somehow the fastest hacked console of nintendo yet even thou the protection is good :D
it isnt, nintendo made the protection strong but that doesnt matter if nvidias protectiong is worthless.
 

ken28

Well-Known Member
Member
Joined
Oct 21, 2010
Messages
1,181
Trophies
1
XP
1,693
Country
Germany
oh so its because of nvidia... what if the chip would be the best protection which exploits would not work?
thats what i get out of most of explaination of the exploit.
Also there is no prefect protection. If its made by a human it can be destroyed/cracked by a human its as easy as that.
 

ken28

Well-Known Member
Member
Joined
Oct 21, 2010
Messages
1,181
Trophies
1
XP
1,693
Country
Germany
Eh its nintendos fault as well to they did not patch the trust zone exploit properly they just patched access to it. Nintendo are lazy with fixing stuff.
fixing the trust zone exploit could be complicated and in the meanwhile they just closed the accsess point. this a common approach in programming, not just nintendo.
 

Jayro

MediCat USB Dev
Developer
Joined
Jul 23, 2012
Messages
12,964
Trophies
4
Location
WA State
Website
ko-fi.com
XP
16,974
Country
United States
I suppose now it's just a race to see who releases their cold boot hax first. Probably Team Xecuter with their "modchip". Which judging by other's cold boot exploits, don't need one... A modchip is just a cashgrab.
 

TheCyberQuake

Certified Geek
Member
Joined
Dec 2, 2014
Messages
5,012
Trophies
1
Age
28
Location
Las Vegas, Nevada
XP
4,432
Country
United States
I suppose now it's just a race to see who releases their cold boot hax first. Probably Team Xecuter with their "modchip". Which judging by other's cold boot exploits, don't need one... A modchip is just a cashgrab.
It could depend on what the "public" coldboot exploits require for installation. My guess is they would at minimum require userland access, and it may require higher privileges. That means it would be free to install on firmwares that support those privileges, but anything higher would be SoL. Supposedly the hardmod would allow coldboot hacks on any firmware regardless of having code execution or not.
 

Kubas_inko

"Something funny goes here."
Member
Joined
Feb 3, 2017
Messages
6,324
Trophies
1
Age
24
Location
I gues on earth.
XP
5,176
Country
Czech Republic
It could depend on what the "public" coldboot exploits require for installation. My guess is they would at minimum require userland access, and it may require higher privileges. That means it would be free to install on firmwares that support those privileges, but anything higher would be SoL. Supposedly the hardmod would allow coldboot hacks on any firmware regardless of having code execution or not.
Well, we (at least SciresM) have tzhax on any firmware. Is that enough privileges? :D
 
Last edited by Kubas_inko,

chrisrlink

Has a PhD in dueling
Member
Joined
Aug 27, 2009
Messages
5,554
Trophies
2
Location
duel acadamia
XP
5,730
Country
United States
sorry to bring this up but some older consoles held up pretty well PS3 4x aka super slim and sega saturn just only got fully cracked last year(sega saturn not pss3 superslim though that maybe exploited soon too) i think but theres a golden rule i learned here if it's a manmade electronic it can be exploited in some form
 
Last edited by chrisrlink,

Jayro

MediCat USB Dev
Developer
Joined
Jul 23, 2012
Messages
12,964
Trophies
4
Location
WA State
Website
ko-fi.com
XP
16,974
Country
United States
It could depend on what the "public" coldboot exploits require for installation. My guess is they would at minimum require userland access, and it may require higher privileges. That means it would be free to install on firmwares that support those privileges, but anything higher would be SoL. Supposedly the hardmod would allow coldboot hacks on any firmware regardless of having code execution or not.
That does make sense... Soft-mod method probably requires 3.0.0, whereas the modchip works on any system firmware.
 

Mrdx

Well-Known Member
Member
Joined
Dec 12, 2013
Messages
107
Trophies
0
XP
1,077
Country
Antigua and Barbuda
I think that every time Team Xecuter make a move, f0f and other teams show the possibilities of their "free" alternatives in order to dissuade TX from trying to make money out of piracy devices. That's the reason why they just show poc but never release anything...
 

TheCyberQuake

Certified Geek
Member
Joined
Dec 2, 2014
Messages
5,012
Trophies
1
Age
28
Location
Las Vegas, Nevada
XP
4,432
Country
United States
I think that every time Team Xecuter make a move, f0f and other teams show the possibilities of their "free" alternatives in order to dissuade TX from trying to make money out of piracy devices. That's the reason why they just show poc but never release anything...
Except if they never release their free alternatives, all it does is push more traffic to the things that actually release, even if they are a paid product
 
  • Like
Reactions: RedHunter

guily6669

GbaTemp is my Drug
Member
Joined
Jun 3, 2013
Messages
2,324
Trophies
1
Age
34
Location
Doomed Island
XP
2,090
Country
United States
sorry to bring this up but some older consoles held up pretty well PS3 4x aka super slim and sega saturn just only got fully cracked last year(sega saturn not pss3 superslim though that maybe exploited soon too) i think but theres a golden rule i learned here if it's a manmade electronic it can be exploited in some form
Best one is Sega Dreamcast, just burn a game CD and run it lol, that was epic.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    Psionic Roshambo @ Psionic Roshambo: @SylverReZ, Indeed lol