Hacking Hardware Picofly - a HWFLY switch modchip

rehius

Well-Known Member
Member
Joined
Feb 6, 2023
Messages
377
Trophies
1
Age
34
XP
1,790
Country
Canada
I have, but I didn't know it would matter if I didn't keep part of pin 26 ( I removed It completely). Got a spare one and will try again.
oh, that is not the pad that matters, I meant you were too close to the oscillator, there are important traces and vias close to the pad 20 that you could cut or short
 
  • Like
Reactions: FreeLander

Dee87

Well-Known Member
Member
Joined
Mar 19, 2023
Messages
1,139
Trophies
1
XP
1,588
Country
Germany
Nice. What AWG/MM Did you use?
Post automatically merged:


Hi Dee. Been a minute

I have, but I didn't know it would matter if I didn't keep part of pin 26 ( I removed It completely). Got a spare one and will try again.

Thanks, my man.
well how far it matters but there are some close traces are still needed so just get as close as its on the diagramm
 
  • Like
Reactions: FreeLander

SorataVP69

Active Member
Newcomer
Joined
Mar 21, 2023
Messages
36
Trophies
0
Age
25
XP
82
Country
United States
Latest firmware here

ChangeLog:

v2.0 + Active MMC communication
v2.1 + Toshiba support
v2.2 + Fix Toshiba boot fail
v2.3 + SanDisk support
v2.4 + Faster Toshiba boot
v2.5 + fix OFW boot
v2.6 + software update, xiao & itsy support
v2.61 + Instinct-NX sdloader, bug fixes
v2.62 + Make 16.0.1 happy (fix OFW boot)
v2.63 + roll back some 2.62 boot speed tricks
v2.64 + enable back the board detection
v2.65 + RP Pico support, double reset removed
v2.66 + Bypass to OFW after update for proper fuse burning

must be RED after USB write. if you see green, set "RGB mode" jumper

WHITE = eMMC write
BLUE = glitch
PURPLE = eMMC boot failure, check CMD / CLK
PINK = NS eMMC init fails, inoperative eMMC ?
YELLOW = eMMC write failure, check D0 / unsupported eMMC
CYAN = no reaction to glitch, check mosfet wire
GREEN = success



Q: What is supported?
A: Erista (v1), Mariko (v2, Lite, OLED)

Q: eMMC types support?
A: Tested on Hynix, Samsung, Toshiba, SanDisk

Q: rp2040 boards support
A: WaveShare 2040-zero/one, xiao-rp2040, adafruit itsybitsy (Pi Pico is not supported for now)

Q: GREEN, but instant reset
A: Clean flux near the RST point

Q: Do I really need 47 Ohm resistors?
A: You can skip them, however in this case you will have to use emuMMC due to the line interference, sysNAND would not boot (sysNAND data can be damaged).

Q: Does the firmware has learning? How to reset statistics
A: Short pin 0 to either 1 or GND during start for chip reset. The statistics is collected each boot. The more you start it - the better it boots.

Q: open source?
A: no

Q: why you made it?
A: to prove it possible!

Q: run Atmosphere?
A: no piracy

v2.5 firmware had a bug with BOOT0 corruption. To recover it:
- boot "Full Stock" using hekate
- update to the latest official firmware over Wi-Fi

- boot "Full Stock" using hekate
- perform a full system reset

- show firmware information
- update firmware from SD card (place update.bin into the root folder)
- rollback to the backup firmware slot
- reset learning statistics
- dump / write sdloader

if you have an rp2040-zero from waveshare/ali then it has a neopixel. It is used for diagnosing proper firmware flashes as well as console glitching. If you plug it in, and flash the uf2 firmware to it and immediately see a red light after flashing (this is not the same as flashing, then unplugging and replugging), then no rgb jumper needs to be made. If on the other hand, you get one quick green flashing light, then you need to bridge the jumper pads indicated to swap the LED colors for proper diagnoses capability.
Hello, is it possible to use the Flex cable from V2 (mariko) in v1 (erista)?
 

FreeLander

Well-Known Member
Member
Joined
Apr 6, 2023
Messages
350
Trophies
0
Age
35
XP
467
Country
United States
Hello. I've tried 3 different MOSFET types, and two different wires (0.1mm and 0.3mm). I just won't get a CPU value on diode mode.

I've tried the close GND ground and tried two MOSFETs at once. Same thing.


Any advice? Thank you.
IMG_B892466071F5-1.jpeg
 

SorataVP69

Active Member
Newcomer
Joined
Mar 21, 2023
Messages
36
Trophies
0
Age
25
XP
82
Country
United States
while it is possible I would just get a v1 flex

I had seen someone do it, its pretty sketchy and even they recommended against it.
Trying to remember who did it and where I saw it.thanks, if you remember where you saw it please let me know, I'm interested to know
Post automatically merged:

I had seen someone do it, its pretty sketchy and even they recommended against it.
Trying to remember who did it and where I saw it.
thanks, if you remember where you saw it please let me know, I'm interested to know
 

calishooter

Member
Newcomer
Joined
Mar 23, 2023
Messages
17
Trophies
0
Age
44
XP
97
Country
United States
Can someone please tell me what voltage the RST point needs to be when checking it to ground? I'm getting around 3.5v...is that normal on a switch lite? Thanks!
 

malgamer

Well-Known Member
Newcomer
Joined
May 8, 2022
Messages
85
Trophies
0
Age
46
Location
malaysia
XP
450
Country
Malaysia
Can someone please tell me what voltage the RST point needs to be when checking it to ground? I'm getting around 3.5v...is that normal on a switch lite? Thanks!
rst line 1.8v
Post automatically merged:

Can someone please tell me what voltage the RST point needs to be when checking it to ground? I'm getting around 3.5v...is that normal on a switch lite? Thanks!
rst line 1.8v
 
  • Like
Reactions: calishooter

POPOLO

Active Member
Newcomer
Joined
Apr 17, 2023
Messages
34
Trophies
0
Age
44
XP
194
Country
Japan
Hello. I've tried 3 different MOSFET types, and two different wires (0.1mm and 0.3mm). I just won't get a CPU value on diode mode.

I've tried the close GND ground and tried two MOSFETs at once. Same thing.


Any advice? Thank you.
View attachment 366932
"Both capacitors should be connected at the point."。
 

Attachments

  • S__35815429.jpg
    S__35815429.jpg
    1.9 MB · Views: 61
  • S__35823618.jpg
    S__35823618.jpg
    1.9 MB · Views: 82
  • S__35823620.jpg
    S__35823620.jpg
    2 MB · Views: 75

leerz

Well-Known Member
Member
Joined
Jan 11, 2015
Messages
754
Trophies
0
Age
36
Location
Makati
Website
leerz25.sitesled.com
XP
2,202
Country
Hello @FreeLander, looks like you found the dangerous incorrect diagram by sthetix where the 3.3v point is actually direct 4.2v right from the battery. Be careful, such overvoltage may fry your RP Pico and the console. Please use the proper 3.3v point here:
View attachment 366724
i'm curious where that 4.2v is? XD i've always used the 3.3v
 

FreeLander

Well-Known Member
Member
Joined
Apr 6, 2023
Messages
350
Trophies
0
Age
35
XP
467
Country
United States
"Both capacitors should be connected at the point."。
Hello, POPO. Thank you.
I did this and I'm still getting zero on diode mode. I can't tell what is it I'm doing wrong.
I even removed the caps entirely and soldered to the pads directly, but still no luck, and even worse, the console wouldn't boot.
Thankfully, @rehius anticipated noobs like me would do this, so I did his trick by salvaging the caps off an rp2040 and re-soldering them to the console. Now it boots fine, but I'm still determined to figure out how to get a successful glitch with MOSFETs.

I followed every step. 0.2mm enameled, two MOSFETs, short wires, close grounds.

IMG_6792.JPG
 

Dee87

Well-Known Member
Member
Joined
Mar 19, 2023
Messages
1,139
Trophies
1
XP
1,588
Country
Germany
Hello, POPO. Thank you.
I did this and I'm still getting zero on diode mode. I can't tell what is it I'm doing wrong.
I even removed the caps entirely and soldered to the pads directly, but still no luck, and even worse, the console wouldn't boot.
Thankfully, @rehius anticipated noobs like me would do this, so I did his trick by salvaging the caps off an rp2040 and re-soldering them to the console. Now it boots fine, but I'm still determined to figure out how to get a successful glitch with MOSFETs.

I followed every step. 0.2mm enameled, two MOSFETs, short wires, close grounds.

View attachment 366978
since its runing fine now with the 2 caps stollen from the rp go ahead and reinstall the pico with the caps on it should work
 

Adran_Marit

Walküre's Hacker
Member
Joined
Oct 3, 2015
Messages
3,781
Trophies
1
Location
42*South
XP
4,566
Country
Australia
Hello, POPO. Thank you.
I did this and I'm still getting zero on diode mode. I can't tell what is it I'm doing wrong.
I even removed the caps entirely and soldered to the pads directly, but still no luck, and even worse, the console wouldn't boot.
Thankfully, @rehius anticipated noobs like me would do this, so I did his trick by salvaging the caps off an rp2040 and re-soldering them to the console. Now it boots fine, but I'm still determined to figure out how to get a successful glitch with MOSFETs.

I followed every step. 0.2mm enameled, two MOSFETs, short wires, close grounds.

View attachment 366978

Do you have a clearer photo of your firsts? Also have you tried the flex?
 

FreeLander

Well-Known Member
Member
Joined
Apr 6, 2023
Messages
350
Trophies
0
Age
35
XP
467
Country
United States
since its runing fine now with the 2 caps stollen from the rp go ahead and reinstall the pico with the caps on it should work
Hello, Dee.
Okay, but shouldn't I be getting a 0.6- 0.9.0v diode reading on the G point?
Post automatically merged:

Do you have a clearer photo of your firsts? Also have you tried the flex?
Wil try to do a better pic. I have not tried the flex on it since it's a v1 experimental console, I'm kind of hesitant about wasting a cable on it. I'm interested in doing MOSFETs moving forward, that's why I'm experimenting with this v1. I guess my question is, shouldn't I be getting a diode reading on G point?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Psionic Roshambo @ Psionic Roshambo:
    Having every channel is fun lol
  • D @ diamondsofmayhem:
    Actually, finally found someone who was looking for the same thing. https://gbatemp.net/threads/lost-hyrule-warriors-legends-v1-6-0-ntr-plugin.628141/ to no avail.
  • D @ diamondsofmayhem:
    well, sorry for bugging yall with this.
  • Xdqwerty @ Xdqwerty:
    good night
  • Sicklyboy @ Sicklyboy:
    sup nerds
    +1
  • BigOnYa @ BigOnYa:
    Sup dawg, watching old rap vids so feel like I gotta talk...Real
  • BigOnYa @ BigOnYa:
    Not really just funny. I'm definitely a nerd!
  • ShinyLuxio @ ShinyLuxio:
    Hi there, it's any way to recover original LFCS if I don't have a NAND backup?
  • ShinyLuxio @ ShinyLuxio:
    Bought second hand 3DS, it seems it was "unbanned" but that was before I bought it
  • K3Nv2 @ K3Nv2:
    I got these in today for $20 stink buds they aren't that bad https://a.co/d/fOMSn8g
    +1
  • ShinyLuxio @ ShinyLuxio:
    @BigOnYa thanks but my question isn't there
  • BigOnYa @ BigOnYa:
    You ask your questions there, create a new thread if its not already answered, then eventually a 3ds genius will respond.
  • ShinyLuxio @ ShinyLuxio:
    I will, thanks
    +1
  • BigOnYa @ BigOnYa:
    No prob and btw, welcome to gbatemp! :grog:
  • BigOnYa @ BigOnYa:
    @K3Nv2 I got some cheapies at wallys, that are pretty good, already have lost a few expensive ones (one falls out and gone, can't find) while cutting grass so bought some cheap ones, and of course never lose these cheap ones. (Cheap meaning only $35, compared to air buds which I only have 1 of 2 now)
  • BigOnYa @ BigOnYa:
    They need to add air tags to they airbuds..
  • The Real Jdbye @ The Real Jdbye:
    @BigOnYa the airtags are bigger than the airpods, they won't fit
    +1
  • BigOnYa @ BigOnYa:
    Be cool tech tho. Of course they want to lose them anyways. Buy and buy again.
  • K3Nv2 @ K3Nv2:
    Apple could make a find my AirPods thing pretty easily
    +1
  • BigOnYa @ BigOnYa:
    You would think, esp using bluetooth, not GPS, like a "your getting hot-er" meter on your phone.
  • BigOnYa @ BigOnYa:
    I think they should tie up diddy, and let all the victims come and abuse him, we'll make a holiday of it every year. (jk, maybe)
  • BigOnYa @ BigOnYa:
    Crazy, the rich get away with this shit, and I can't shit without the poop police checking my asshole every time I shit, or have my toilet seatbelt on.
    BigOnYa @ BigOnYa: Crazy, the rich get away with this shit, and I can't shit without the poop police checking my...