Hacking Suggestion [IMPORTANT] Possible Nintendo server changes to block web applets from working

  • Thread starter Deleted-442439
  • Start date
  • Views 58,924
  • Replies 183
  • Likes 21
D

Deleted-442439

Guest
OP
So... If I understand all of this correctly.

There is no way to tell if a 3.01 - 5.01 Switch has been affected or not at this time.

You COULD tell if a 3.0.0 Switch has been affected by setting up a fully offline web server hosting the exploit and trying to run it that way. If you can still run it.... Successful exploit = Not affected

Am I missing anything?

Basically yes, if u try to run the webapplet on a patched console on outdated FW it will ask ask for a update, a localhost payload should be safe on non patched systems.
 

Deathscreton

Well-Known Member
Member
Joined
Oct 1, 2009
Messages
826
Trophies
0
XP
1,092
Country
United States
So why is this a big problem? If it's patchable in the future, that means all users who are affected will have to use a Hardmod/Jig at least ONCE, then patch the console/run CFW and they'll be able to patch the OFW so they can use the applets again. It doesn't change anything and Ninty is just wasting manpower at this point.
 
  • Like
Reactions: PCityPaul

notimp

Well-Known Member
Member
Joined
Sep 18, 2007
Messages
5,779
Trophies
1
XP
4,420
Country
Laos
Just to underline the idiocy of that corporate approach.

You'll get most people to update through an inability to handle delayed gratification anyhow.

You'll get most of the rest through online lockouts and nags.

What Nintendo is achieving by locking people out from using the web browser on their platforms, via a silent bit switch is the following:

I HEREBY SOLEMNY SWEAR, that if I was effected by Nintendos outreach into the hardware I baught - while never having accepted their terms and conditions, or creating an online account with them - I WILL INVEST EVERY LIVING HOUR this community is active - to serve as a conduit to get AS MANY PEOPLE AS POSSIBLE to buy and use modchips for whatever reason.

I'll support them in all their efforts, I'll answer all their worries, so for every ME Nintendo just fucked over, there at least will be 200 new modchip users as a result.

Fair?

Talking about diminishing returns.

This my friends, is a corporation making freaking insane decisions.

Also - under which legal premise is Nintendo changing the eprom content of my Switch? If I've made sure not to agree to their terms and services as a "legal" person, and having the knowledge, that shrinkwrap contracts are illegal where I am living. Any lawyers in here?

--------------------- MERGED ---------------------------

So why is this a big problem? If it's patchable in the future, that means all users who are affected will have to use a Hardmod/Jig at least ONCE, then patch the console/run CFW and they'll be able to patch the OFW so they can use the applets again. It doesn't change anything and Ninty is just wasting manpower at this point.
Oh, the problem really is this: Piss off a group of maybe 200-500 people, by bricking their use cases for whatever time it takes to find their modus operandi. And changing your image as Nintendo from "acquiring informed consent" to sneaking into a 12+ year olds bedroom, and changing the function of the product he bought, without him or her getting to know it.

F*ck - sure sounds illegal to me, ... N.
 
Last edited by notimp,

notimp

Well-Known Member
Member
Joined
Sep 18, 2007
Messages
5,779
Trophies
1
XP
4,420
Country
Laos
Lets do a little advocacy here.

Flip your bit back at Nintendo - become a modding guide for someone who has difficulties getting there.


If Nintendo just made sure, that you cant use the Switch in the way you used it in the past - with really nothing you could do about it - make sure, that at least ONE other person will get a modchip installed in their Switch, because of you.

Return the favor. :)



Help your friends with their questions, provide them with guidelines for easy product acquisition. Help them with soldering, do what you can. It doesn't take much, it helps everyone out, and it makes sure, Nintendo doesn't remotely change code and functionality on our systems in the future, without users being informed.

FYI this is a new thing they are pulling, and you where there, when they started. :)


If everyone affected by their current approach gets a modchip, and convinces at least ONE friend to get one as well - their tactic backfires.


Tell a friend, be friendly - and flip your bit back at Nintendo.


Dear Mr. Kimishima - we hope this message will reach you. :)

220px-Tatsumi-Kimishima.jpg



Declaration: We see Nintendos action of finding a way into our systems and changing their functionality remotely, without our knowledge or consent, as an aggressive act and a qualitatively new breach of a preexisting red line, trying to keep your customers in a walled garden ecosystem. Your acts were unprovoked, your actions are unjustified and the legality of your approach is questionable.

The Switch is an unsubsidized hardware platform and we have the expectation to own what we bought, after we have paid for the device in full. If you want to retroactively change core functionality (remove access to a web browser - for everyone that doesn't want to update to your latest firmware) - and do so in a covert approach designed not to grab media attention - expect us to look at you with different eyes, than those of a five year old Labo customer.

Sincerely,

A voice from the scene
 
Last edited by notimp,

Zris96

Well-Known Member
Newcomer
Joined
Jan 10, 2018
Messages
46
Trophies
0
Age
27
XP
447
Country
Dominican Republic
I don't know about programming and stuffs like that... but what if someone emulate a DNS with a fake 5.0.2 firmware authentication to confuse Nintendo's servers? So that way we could get our switch's NeedUpdateVulnerability value set to 0 again... I don't know if something like that is possible ...
 
  • Like
Reactions: deanspeed

Maximilious

Whistles a familiar tune
Member
Joined
Nov 21, 2014
Messages
2,571
Trophies
1
XP
1,855
Country
United States
I don't know about programming and stuffs like that... but what if someone emulate a DNS with a fake 5.0.2 firmware authentication to confuse Nintendo's servers? So that way we could get our switch's NeedUpdateVulnerability value set to 0 again... I don't know if something like that is possible ...

That is likely protected Nintendo IP (intellectual property) and would be very difficult to reverse engineer to flip the switch back to 0 through a publicly hosted webserver. Not to mention, you would have to redirect your DNS entry from the Switch to somehow point to said webserver like a host file in Windows. It would probably be easier for someone to create an applet in CFW that will allow the switch to be flipped back to 0 instead.
 

Zris96

Well-Known Member
Newcomer
Joined
Jan 10, 2018
Messages
46
Trophies
0
Age
27
XP
447
Country
Dominican Republic
That is likely protected Nintendo IP (intellectual property) and would be very difficult to reverse engineer to flip the switch back to 0 through a publicly hosted webserver. Not to mention, you would have to redirect your DNS entry from the Switch to somehow point to said webserver like a host file in Windows. It would probably be easier for someone to create an applet in CFW that will allow the switch to be flipped back to 0 instead.

But then... can we still use fusee gelee/shofEL2 with this value set to 1? (Sorry for being such a noob on the scene :s)
 

TerminatR

Well-Known Member
Newcomer
Joined
Nov 21, 2006
Messages
96
Trophies
0
XP
978
Country
Canada
It would be nice if someone could release some code to quickly check if Switch has been affected or not.

All we would need is some web code to throw into an offline server app that would see if redirection works when the switch connects.
 

Maximilious

Whistles a familiar tune
Member
Joined
Nov 21, 2014
Messages
2,571
Trophies
1
XP
1,855
Country
United States
  • Like
Reactions: Zris96

BL4Z3D247

GBAtemp Stoner
Member
Joined
Oct 22, 2008
Messages
1,942
Trophies
0
Age
39
Location
I'm so high, I don't even know!
XP
1,229
Country
United States
Can someone kindly explain what this would mean to someone with a 1.0.0 console that never ran any hax on it, basically what is affected in terms of exploits and such not working?

I saw HBL and SwitchBruDNS but what about PegaSwitch, Fake News, etc?

(Sorry if I sound like a noob, not sure what is or isn't a web applet and literally just found time to get my Switch all up and running for homebrew.)
 
Last edited by BL4Z3D247,
  • Like
Reactions: dernettemann1983

notimp

Well-Known Member
Member
Joined
Sep 18, 2007
Messages
5,779
Trophies
1
XP
4,420
Country
Laos
Can someone kindly explain what this would mean to someone with a 1.0.0 console that never ran any hax on it, basically what is affected in terms of exploits and such not working?

I saw HBL and SwitchBruDNS but what about PegaSwitch, Fake News, etc?
You know where all those hacks (and all software entry points currently being worked on) open a browser window?
Nintendo, doesn't allow you to get access to the browser anymore, if you are not on the most current firmware. Instead you get a popup that tells you to update.
-

By all intents and purposes Nintendos behavior should be illegal, if they are pulling it off in Europe as well. US customers, as always are out of luck, because their rights can be sold away on a virtual piece of napkin, that no one has to read.

First: Here are the different "license agreements" for both regions:

r2KsZuv.png


The european one does not even have to be read, you can skip it in the setup progress without acknowledging that you have read it. Nintendo simply asks you to, but you don't have to - so you are not entering into an interpersonal contract with them at that point.

Also - the european text doesnt remove their responsibility to inform you of the update or to ask for your consent. Nintendo should also have a hard time arguing, how what they are doing is covered by any of the reasons they list for being allowed to update software automatically -

and as they are putting up another usage restriction, and are not "removing content" (they are flipping a bit, adding a 1), no potential action of theirs is covered in the last paragraph. Also "may render the Software unplayable" is stated passively and should not cover them "hacking into your console" and adding a usage restriction.

So by any of the quasi legal texts they include with the platform in Europe, they shouldn't be allowed to do what they are currently doing.

US users on the other hand are effed, because they dont have consumer protection laws, that wouldnt allow any EULA to sign away their rights. EULAs to them are literally laws, as in that they cant negotiate them, and that to them they are legally binding even if they dont really read them, and whats inside conflicts with their state law.

Other interpretations are welcome.

Would be interesting to know if some of the known bit switches happened for european customers as well.
 
Last edited by notimp,
  • Like
Reactions: Flying Scotsman

ut0pia

Member
Newcomer
Joined
Apr 30, 2018
Messages
17
Trophies
0
Age
42
XP
216
Country
France
I'm not even mad about not going online, fair enought but the problem is some game won't start unless i update.
Is it safe to say a solution will show up later or is better to update now and stick with current live fw (loosing potential sw exploit, i'm on 4.1) ?
 

BL4Z3D247

GBAtemp Stoner
Member
Joined
Oct 22, 2008
Messages
1,942
Trophies
0
Age
39
Location
I'm so high, I don't even know!
XP
1,229
Country
United States
You know where all those hacks (and all software entry points currently being worked on) open a browser window?
Nintendo, doesn't allow you to get access to the browser anymore, if you are not on the most current firmware. Instead you get a popup that tells you to update.
-

By all intents and purposes Nintendos behavior should be illegal, if they are pulling it off in Europe as well. US customers, as always are out of luck, because their rights can be sold away on a virtual piece of napkin, that no one has to read.

First: Here are the different "license agreements" for both regions:

r2KsZuv.png


The european one does not even have to be read, you can skip it in the setup progress without acknowledging that you have read it. Nintendo simply asks you to, but you don't have to - so you are not entering into an interpersonal contract with them at that point.

Also - the european text doesnt remove their responsibility to inform you of the update or to ask for your consent. Nintendo should also have a hard time arguing, how what they are doing is covered by any of the reasons they list for being allowed to update software automatically -

and as they are putting up another usage restriction, and are not "removing content" (they are flipping a bit, adding a 1), no potential action of theirs is covered in the last paragraph. Also "may render the Software unplayable" is stated passively and should not cover them "hacking into your console" and adding a usage restriction.

So by any of the quasi legal texts they include with the platform in Europe, they shouldn't be allowed to do what they are currently doing.

US users on the other hand are effed, because they dont have consumer protection laws, that wouldnt allow any EULA to sign away their rights. EULAs to them are literally laws, as in that they cant negotiate them, and that to them they are legally binding even if they dont really read them, and whats inside conflicts with their state law.

Other interpretations are welcome.

Would be interesting to know if some of the known bit switches happened for european customers as well.
So basically what you're telling me is I'm fucked for now as far as getting homebrew up and running on my Switch tonight.

Damn.
 

notimp

Well-Known Member
Member
Joined
Sep 18, 2007
Messages
5,779
Trophies
1
XP
4,420
Country
Laos
For moral support - so am I. :)

People presumably are now sniffing the network traffic of their consoles to see how Nintendo could connect to them (and ALL of them) without going through the usual update servers - could be a domain that lay dormant and never popped up in logs of the Switch talking to Nintendo before, could be a baked in return channel, that directly communicates to an IP, and circumvents DNS resolving, ...

Once they've found it, we can block it. Presumably once they've found it, they also will analyze the part of their software where the "command and control" pipe comes in to hopefully have a better chance of preventing them to do this in the future.

If they have flipped he bit on your console, "we" can reverse what they have done - but not without considerable effort on the part of everyone who wants to do so. Making syspartition backups and writing to them via linux on the switch primarily. And in the end, they wont be able to prevent the hardware assisted exploits.

So depending on how long folks take to find out what exactly N is doing, this might be an entirely useless storm in the waterglass, that does nothing for N apart from pissing off the most technically savvy users.

If this turns out to take longer than expected - everyone on 3.0.0 should look for the esp8266 method of launching HBL from a local "mini server" that costs about 7USD.

Less convenient, but not really slower, or more complicated.

Of course - using the locally hosted exploit, still blocking the Switches Internet access entirely - is only possible - if the bit hasn't already been switched (the access restriction for the browser enabled). At least until the method to flip the bit back is released. (Which shouldnt take long, but let devs reside on the side of caution there).

Nintendo just made sure TX and others sell a few more modchips today. Not sure if that was in their interest...
 
Last edited by notimp,

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • TwoSpikedHands @ TwoSpikedHands:
    Do I restart now using what i've learned on the EU version since it's a better overall experience? or do I continue with the US version since that is what ive been using, and if someone decides to play my hack, it would most likely be that version?
  • Sicklyboy @ Sicklyboy:
    @TwoSpikedHands, I'll preface this with the fact that I know nothing about the game, but, I think it depends on what your goals are. Are you trying to make a definitive version of the game? You may want to refocus your efforts on the EU version then. Or, are you trying to make a better US version? In which case, the only way to make a better US version is to keep on plugging away at that one ;)
  • Sicklyboy @ Sicklyboy:
    I'm not familiar with the technicalities of the differences between the two versions, but I'm wondering if at least some of those differences are things that you could port over to the US version in your patch without having to include copyrighted assets from the EU version
  • TwoSpikedHands @ TwoSpikedHands:
    @Sicklyboy I am wanting to fully change the game and bend it to my will lol. I would like to eventually have the ability to add more characters, enemies, even have a completely different story if i wanted. I already have the ability to change the tilemaps in the US version, so I can basically make my own map and warp to it in game - so I'm pretty far into it!
  • TwoSpikedHands @ TwoSpikedHands:
    I really would like to make a hack that I would enjoy playing, and maybe other people would too. swapping to the EU version would also mean my US friends could not legally play it
  • TwoSpikedHands @ TwoSpikedHands:
    I am definitely considering porting over some of the EU features without using the actual ROM itself, tbh that would probably be the best way to go about it... but i'm sad that the voice acting is so.... not good on the US version. May not be a way around that though
  • TwoSpikedHands @ TwoSpikedHands:
    I appreciate the insight!
  • The Real Jdbye @ The Real Jdbye:
    @TwoSpikedHands just switch, all the knowledge you learned still applies and most of the code and assets should be the same anyway
  • The Real Jdbye @ The Real Jdbye:
    and realistically they wouldn't

    be able to play it legally anyway since they need a ROM and they probably don't have the means to dump it themselves
  • The Real Jdbye @ The Real Jdbye:
    why the shit does the shitbox randomly insert newlines in my messages
  • Veho @ Veho:
    It does that when I edit a post.
  • Veho @ Veho:
    It inserts a newline in a random spot.
  • The Real Jdbye @ The Real Jdbye:
    never had that i don't think
  • Karma177 @ Karma177:
    do y'all think having an sd card that has a write speed of 700kb/s is a bad idea?
    trying to restore emunand rn but it's taking ages... (also when I finished the first time hekate decided to delete all my fucking files :wacko:)
  • The Real Jdbye @ The Real Jdbye:
    @Karma177 that sd card is 100% faulty so yes, its a bad idea
  • The Real Jdbye @ The Real Jdbye:
    even the slowest non-sdhc sd cards are a few MB/s
  • Karma177 @ Karma177:
    @The Real Jdbye it hasn't given me any error trying to write things on it so I don't really think it's faulty (pasted 40/50gb+ folders and no write errors)
  • DinohScene @ DinohScene:
    run h2testw on it
    +1
  • DinohScene @ DinohScene:
    when SD cards/microSD write speeds drop below a meg a sec, they're usually on the verge of dying
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Samsung SD format can sometimes fix them too
  • Purple_Heart @ Purple_Heart:
    yes looks like an faulty sd
  • Purple_Heart @ Purple_Heart:
    @Psionic Roshambo i may try that with my dead sd cards
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    It's always worth a shot
  • TwoSpikedHands @ TwoSpikedHands:
    @The Real Jdbye, I considered that, but i'll have to wait until i can get the eu version in the mail lol
    TwoSpikedHands @ TwoSpikedHands: @The Real Jdbye, I considered that, but i'll have to wait until i can get the eu version in the...