Hacking Discussion Is it possible to flash SX PRO to a different payload?

SonyUSA

We're all mad here
Editorial Team
Joined
May 12, 2006
Messages
1,780
Trophies
2
XP
5,636
Country
United States
The TX bootloader can load a payload off SD. The dongle is connectable via USB but you would need the driver then figure out the software to re-flash it... so technically yes but feasibly no.
 

SonyUSA

We're all mad here
Editorial Team
Joined
May 12, 2006
Messages
1,780
Trophies
2
XP
5,636
Country
United States
@James310
I know, but Ive been hearing recently of it locking up the emmc cause of the payload? Is that correct?

I think it can get stuck on black screen maybe? Just hold power for 30 seconds then press power again and it's fine. It happens if you shut down the Switch then remove the dongle too fast I think.
 

SeekNDstroy

Active Member
OP
Newcomer
Joined
Apr 19, 2016
Messages
28
Trophies
0
Age
30
XP
84
Country
United States
I think it can get stuck on black screen maybe? Just hold power for 30 seconds then press power again and it's fine. It happens if you shut down the Switch then remove the dongle too fast I think.

No, its not that, Ive heard over from twitter a security researcher "hexkyz" claiming there is brick code with TX's software and it locks up the emmc with a random password. (Similar method to what Gateway did in the past) If my emmc gets locked, then I won't be able to restore my nand dump right?
 

The Real Jdbye

*is birb*
Member
Joined
Mar 17, 2010
Messages
23,347
Trophies
4
Location
Space
XP
13,934
Country
Norway
@James310
I know, but Ive been hearing recently of it locking up the emmc cause of the payload? Is that correct?
They do have brick code that could potentially affect legitimate SX users. If you're worried about that then I would just not use SX at all.
No, its not that, Ive heard over from twitter a security researcher "hexkyz" claiming there is brick code with TX's software and it locks up the emmc with a random password. (Similar method to what Gateway did in the past) If my emmc gets locked, then I won't be able to restore my nand dump right?
It can be unlocked, requires erasing the NAND but as long as you have a NAND backup that's not a huge problem.
 
  • Like
Reactions: Centergaming

Centergaming

Well-Known Member
Member
Joined
Apr 17, 2016
Messages
695
Trophies
0
XP
923
Country
United States
They do have brick code that could potentially affect legitimate SX users. If you're worried about that then I would just not use SX at all.

It can be unlocked, requires erasing the NAND but as long as you have a NAND backup that's not a huge problem.

CTCaer is currently adding an option to permanently disable password emmc locking with hekate. Here is the link: https://github.com/CTCaer/hekate/issues/18
 
  • Like
Reactions: The Real Jdbye

aos10

Yuuki chan
Member
Joined
Apr 10, 2012
Messages
4,756
Trophies
2
Age
38
XP
4,030
Country
Saudi Arabia
i know i can run othe payloads using SX, but is there a way to flash the SX pro usb dongle to launch custom payload instantly?
 

linuxares

The inadequate, autocratic beast!
Global Moderator
Joined
Aug 5, 2007
Messages
13,368
Trophies
2
XP
18,275
Country
Sweden
You can boot any payload via the dongle. It just inject a payload that boots a boot.dat
If you so wish, you can rename ReiNX to boot.dat and it will boot it as well.
Actually, SX allow you to boot other payloads from their menu even.
 
  • Like
Reactions: aos10

smf

Well-Known Member
Member
Joined
Feb 23, 2009
Messages
6,647
Trophies
2
XP
5,894
Country
United Kingdom
Last edited by smf,

rsn8887

Well-Known Member
Member
Joined
Oct 8, 2015
Messages
956
Trophies
1
Age
46
Website
www.patreon.com
XP
3,628
Country
United States
You can boot any payload via the dongle. It just inject a payload that boots a boot.dat
If you so wish, you can rename ReiNX to boot.dat and it will boot it as well.
Actually, SX allow you to boot other payloads from their menu even.

Also, you can leave the boot.dat from SX OS on your SD Card and use it to boot any cfw you want. Just put your ".bin" file in the root of the SD Card and boot with the dongle. In the SX menu, choose options, then choose to boot a custom payload. It will give you a requester to choose your .bin file. I booted the latest hekake using that method without any problems. It really is very user-friendly.
 
Last edited by rsn8887,

linuxares

The inadequate, autocratic beast!
Global Moderator
Joined
Aug 5, 2007
Messages
13,368
Trophies
2
XP
18,275
Country
Sweden
Also, you can leave the boot.dat from SX OS on your SD Card and use it to boot any cfw you want. Just put your ".bin" file in the root of the SD Card and boot with the dongle. In the SX menu, choose options, then choose to boot a custom payload. It will give you a requester to choose your .bin file. I booted the latest hekake using that method without any problems.
Yepp, as I said SX Allows you to boot other payloads from their menu even.
 
  • Like
Reactions: rsn8887

smf

Well-Known Member
Member
Joined
Feb 23, 2009
Messages
6,647
Trophies
2
XP
5,894
Country
United Kingdom
Is this even needed if you can just rename the payload to boot.dat?

Does that actually work though?

Yepp, as I said SX Allows you to boot other payloads from their menu even.

Sure, but if someone wants to boot into hekate every time then it's more steps each time you boot
 
Last edited by smf,

electronrancher

Well-Known Member
Member
Joined
Aug 4, 2018
Messages
208
Trophies
0
XP
371
Country
United States
If you keep holding + while the sxos screen is on, sx loader drops into a menu that lets you choose any payload, such as hekate, that is on your SD card.

There is really no need to flash the dongle directly to hekate, the sx loader is all you need. And the protection was in sx operating system, not the USB payload. The USB payload in the sx dongle is just sx loader. That bin file has already been dumped and put into nxloader and trinket formats. It's pretty good.
 
Last edited by electronrancher,

smf

Well-Known Member
Member
Joined
Feb 23, 2009
Messages
6,647
Trophies
2
XP
5,894
Country
United Kingdom
If you keep holding + while the sxos screen is on, sx loader drops into a menu that lets you choose any payload, such as hekate, that is on your SD card.

There is really no need to flash the dongle directly to hekate, the sx loader is all you need.

Unless you always want to use hekate and want to save the hassle of holding volume and selecting from a menu.

Or are you saying that because you don't feel that is important, that nobody else should too?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • DinohScene @ DinohScene:
    that's what you get for going with sony
  • DinohScene @ DinohScene:
    worse than the mafia
  • K3Nv2 @ K3Nv2:
    Like gnome didn't even detect it correctly
  • DinohScene @ DinohScene:
    fatfingered a contact?
  • K3Nv2 @ K3Nv2:
    Possible it shorted during removal
  • DinohScene @ DinohScene:
    Sony rubbish
  • SylverReZ @ SylverReZ:
    Worst would be getting a DRM rootkit from using audio CDs and then Sony getting sued.
  • K3Nv2 @ K3Nv2:
    Least I can throw the nvme at neighbors now
  • DinohScene @ DinohScene:
    get a 2 TB NVMe from amazon, return the fucked one, get replacement and send that one to me
  • K3Nv2 @ K3Nv2:
    Easier way buy one with a preadded heatsync pop the heat sync open
  • K3Nv2 @ K3Nv2:
    Some nerd at Amazon warehouse may tell the end of the colors off
  • DinohScene @ DinohScene:
    I'd like a 990 pro tyvm <З
  • K3Nv2 @ K3Nv2:
    Gen 5s going to be crazy expensive at like 10k transfer
  • K3Nv2 @ K3Nv2:
    $300for 2tb
  • DinohScene @ DinohScene:
    don't have anything that can take PCIe5
  • K3Nv2 @ K3Nv2:
    It's still m.2 form just the next gen
  • DinohScene @ DinohScene:
    ew crucial
  • K3Nv2 @ K3Nv2:
    13,600 MB/s though
  • DinohScene @ DinohScene:
    I got a 980 pro iirc
  • K3Nv2 @ K3Nv2:
    Soldigms been pretty solid
  • DinohScene @ DinohScene:
    yeh 980 pro
  • DinohScene @ DinohScene:
    good enough tbf
  • K3Nv2 @ K3Nv2:
    https://a.co/d/gMNhZNI never heard about them but reviews are good
    K3Nv2 @ K3Nv2: https://a.co/d/gMNhZNI never heard about them but reviews are good