Hacking Hack SXOS

  • Thread starter Thread starter Reacher17
  • Start date Start date
  • Views Views 481,370
  • Replies Replies 1,578
  • Likes Likes 63
Looks fake, the gane card is pushed in and that why it appears on the main screen and it just a nro that looks like sx that has a license
That's what I'm thinking. I'm not saying it 100% is but it seems like it. The rom menu doesn't actually do anything to verify if the license is valid, it uses IPC with the tx sys-module using command 26. Also if the version he's launching from hb menu is ripped and modded from the boot.dat why doesn't it have an icon? It had one when Pragma ripped it, unless it has since been removed.

Maybe op could give more details about how it works, I could be wrong. @Reacher17

Edit: agpixel claims to have tested it so I'm probably wrong.
 
Last edited by CompSciOrBust,
That's what I'm thinking. I'm not saying it 100% is but it seems like it. The rom menu doesn't actually do anything to verify if the license is valid, it uses IPC with the tx sys-module using command 26. Also if the version he's launching from hb menu is ripped and modded from the boot.dat why doesn't it have an icon? It had one when Pragma ripped it, unless it has since been removed.

Maybe op could give more details about how it works, I could be wrong. @Reacher17

Edit: agpixel claims to have tested it so I'm probably wrong.
no he tested well. no icon needed I put it back in the boot.dat file

--------------------- MERGED ---------------------------

 
Yes it seems to work, but currently it's not the last version, very cool though ! It need some trials to launch but it launch :)
I need to downgrade to test all features
 
Last edited by Joe88, , Reason: Removed off topic quote
pragma the person who believed hacked the sxos just with the rommenu?:rofl2:

I've managed to find the python script to unpack boot.dat now, renamed ROMMENU.bin to nro and opened that in IDApro - patched those sub routines. So now I have payload_80000000.bin still to patch, how are you opening this in IDA (what loader are you using?), also do you have a link for the script to repack all the files once they are patched?
 
  • Like
Reactions: wolf_
get sha256 from payload80000000.bin and paste it into stage2 at address 0x126A0

--------------------- MERGED ---------------------------

then get the sha256 from stage2 and paste it into the boot.dat file at address 0x10

--------------------- MERGED ---------------------------

select in the boot.dat the code from 0x0 to 0xDF size 0xE0 and recover the sha256

--------------------- MERGED ---------------------------

and pasted the sha256 at address 0xE0 in the boot.dat file

--------------------- MERGED ---------------------------

you still need to re-encrypt the payload80000000.bin and stage2 and put them back in the boot.dat file
 

Site & Scene News

Popular threads in this forum