Misc Switch 2 nand explorer

Status
Not open for further replies.

TheStonedModder

Well-Known Member
Member
Joined
Dec 25, 2022
Messages
2,617
Reaction score
3,724
Trophies
2
Age
29
XP
8,046
Country
United States


(Screenshots for those who can’t load or view Twitter)
IMG_0110.jpeg
IMG_0111.png
IMG_0112.png
 
Very likely fake but I would LOVE to be proven wrong

Actually, yeah, definitely fake. Allegedly they're writing the tool with VSCode and the binary gets written into the x64-release directory. So this is most likely a dummy x64 Windows application renamed from exe to bin. My best guess: this dummy application prints the text seen on the Switch 2 screen which they then made a screenshot and moved onto the Switch SD card to make it look like the program is running on the console

ALSO :D See how the bin was modified a few minutes after all the other files in that directory ? That's probably from the renaming

ALSO ALSO: (I'm having way too much fun) the two devices which are apparently connecting to each other are on different IPv4 subnets. Nice one. (except if their IP config is 192.168.0.0/16 which would be pretty insane)
 
Last edited by MopSec,
I joined this guys discord and he had a channel called switch 2 exploit, which had this, tbh i dont know what the screenshots are supposed to prove
Screenshot 2026-02-12 165136.png
Screenshot 2026-02-12 165144.png
 
  • Haha
Reactions: ChibiMofo
idk honestly it could be real, in the discord theyre saying how u can supposedly replicate this, idk if it works tho
 
  • Haha
Reactions: ChibiMofo
Yeah I'm calling bullshit and is just another kid farming for attention like the emulator guys a few months ago.

Heck in the discord they even mention RCM mode and as far as I know RCM mode was straight up removed as a thing on the newer tegras because of the X1. Though someone feel free to correct me if I'm wrong.

Would imply while making a farm script they also managed to find a way to decrypt the nand and make homebrew libraries.
 
  • Like
Reactions: MopSec
Heck in the discord they even mention RCM mode and as far as I know RCM mode was straight up removed as a thing on the newer tegras because of the X1. Though someone feel free to correct me if I'm wrong.
RCM mode still exists because this is a valid way to get access by Nintendo service technicians. There is no reason to remove it once they made sure that no unsigned payload can be passed.
 
Care to elaborate or are you just here for the snarky comment :p
Okay let me actually elaborate a little further (trying to beat the snarky comment allegations right here):
Without even going into any technical discussion, let's just apply Occam's razor for a second.
How likely is it that this person. who nobody really knows and who has no prior history in the scene managed to
- find a vulnerability
- exploit to to gain code execution with enough privilleges to dump the UFS
- develop an FTP client without any public SDK being available

apparently all on their own? All of this while actual security experts who have been very active in the scene for years have continued to state how secure the system is. I don't think this is very likely at all.


From a technical standpoint there's the clues I've already given in my first post in this thread.
The person also seems to imply that putting "it into RCM mode" in and of itself is already an exploit.
It isn't and people need to realize that just entering RCM isn't some sort of holy grail*. I work in the security field and I deal with a lot of embedded systems, the overall majority of which have some sort of recovery mode for field return analysis and for debugging during the development lifecycle. I guarantee that the Switch 2 has one too and it will likely work very similiarly to the one in the original Switch, albeit without the same vulnerabiliies. I don't think it is likely that this person has found a way to enter RCM just by messing with the USB ports, but I'm not ruling it out completely.

*Exploits in these recovery modes are of course extremely valuable for attackers because they give you very low-level access to the system often bypassing any and all security measures. These interfaces are usually also deeply embedded into the processors meaning any vulnerabilities are likely not patchable by the vendor (Nintendo in this case) and require a patch from the manufacturer of the chip (Nvidia). But again, exploits in these interfaces are the holy grail, not the interface themselves.
 
@MopSec also two more things:
- they put effort into making wi-fi connection in that payload even though on low level it's much easier to setup usb connection than wi-fi (with how much HOS abstracted that process and made it much easier to use homebrew utilize Wi-fi more often than USB)
- payloads are very small yet theirs have ttf rendering, which means that after using payload they would need to put additional effort into loading additional binary and font from external device such as sdcard and execute it (look how all payloads on Switch 1 utilize 1-bit fixed width font rendering to make that rendering part as small as possible).

They really put effort into worthless shit from programmers perspective. 🤣
 
Last edited by masagrator,
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum