Hacking Question Ok so hear me out...

Status
Not open for further replies.

Deleted member 550701

Well-Known Member
Newcomer
Joined
Feb 4, 2021
Messages
81
Reaction score
57
Trophies
0
Age
24
XP
148
Country
Czech Republic
Ok so hear me out, if there was a firmware exploit found that works on the mariko version, could we somehow unpatch the RCM (like through a homebrew app or smth) and then hack the switch with fusee-gelee? And yes I know that finding a firmware exploit is a very hard first step, but what i'm really asking is if the patch that was applied to later switches could be unpatched through homebrew?
 
Ok so hear me out, if there was a firmware exploit found that works on the mariko version, could we somehow unpatch the RCM (like through a homebrew app or smth) and then hack the switch with fusee-gelee? And yes I know that finding a firmware exploit is a very hard first step, but what i'm really asking is if the patch that was applied to later switches could be unpatched through homebrew?
In order to "unpatch" RCM we would need another RCM exploit that allowed some sort of code execution. The RCM firmware isn't accessible from anything other than RCM mode itself.
 
In order to "unpatch" RCM we would need another RCM exploit that allowed some sort of code execution. The RCM firmware isn't accessible from anything other than RCM mode itself.
First of all RCM is in read-only, non writeable memory. That's why it cannot be patched even by Nintendo.
So whole point of discussion is now lost.
 
First of all RCM is in read-only, non writeable memory. That's why it cannot be patched even by Nintendo.
So whole point of discussion is now lost.
I put "unpatch" in quotes because it would just be a temporary on the fly patch that would require code execution to do in the first place. It might not actually be that useful if we had a RCM code execution exploit, as we might just be able to do what we need using that alone.
 
Oh well, it was an idea

--------------------- MERGED ---------------------------

Actually wait, how does the SX core work then?
 
First of all RCM is in read-only, non writeable memory. That's why it cannot be patched even by Nintendo.
So whole point of discussion is now lost.
From my (probably incorrect) understanding it would be possible to edit the bootrom if you could get code execution before ipatch fuse lock out. I *think* the boot ROM checks if FUSE_ODM_LOCK is burned and then disables writing to the ipatches. If you could make that check fail ipatch writing would be enabled. That might be possible via fault Injection on Erista but on Mariko there's probably random timing to mitigate it. It would require a mod chip making the entire thing pointless anyway though.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum