Hacking Switch bootrom warmboot exploit

  • Thread starter Deleted User
  • Start date
  • Views 45,437
  • Replies 161
  • Likes 19

IPLbug

Well-Known Member
Member
Joined
Jun 6, 2018
Messages
127
Trophies
0
Age
35
Location
Under Your bed stealing your data
XP
360
Country
United States
Might be possible once basic interpreters like fuze and smilebasic show up.

There no escalation of privileges off save files.it well know with the current state of openness of the console that save files would be the mostly used area for attempts to escalate with and have yet to yield any result that's not a panic in the kernel. there a reason there a bounty by the devs for anyone that can manage it and no one has claimed it.
 

adrifcastr

Well-Known Member
Member
Joined
Sep 12, 2016
Messages
2,038
Trophies
0
XP
1,947
Country
Germany
wow ,2.x.x switch and finally get my SX pro dongle in the mail yesterday and this happens literally the next day
still have not activated it yet tho ,waiting on 256gb msd
maybe i should dump it for a profit and get the OS instead?
the existence of jamais vu and deja vu is known since half a year.
 

BlastedGuy9905

where's the updated autopsy report
Member
Joined
Apr 13, 2017
Messages
2,334
Trophies
1
Age
34
Location
under your desk
XP
4,053
Country
United States
Only if you have 5 or less fuses burnt. Otherwise, you would have to use the current bootrom exploit anyways to load your 4.1 NAND dump.
Hey, can you not downgrade with the rajkosto method? (even though that would defeat the purpose of a warmboot cause... you need rcm to get into your downgraded firm, right?)
 

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
IS THIS the famous trump card which hackers are holding all this time to counter New Fusée Gelée patched Switches??

Only if they were <4.1 and as a possible ace-in-the-hole on Mariko but that's screwed now.

But its sort of obvious that Nintendo's know about this flaw for half a year or more now.
 

leon315

POWERLIFTER
Member
Joined
Nov 27, 2013
Messages
4,100
Trophies
2
Age
124
XP
4,087
Country
Italy
Only if they were <4.1 and as a possible ace-in-the-hole on Mariko but that's screwed now.

But its sort of obvious that Nintendo's know about this flaw for half a year or more now.
SO if Nintendo already known this exploit, then ''K'' must leaked this exploit many months earlier? then things got heated up only recent because K was caught playing double agent all this time?
 
  • Like
Reactions: TAUSENN

Phoenixrite

Well-Known Member
Newcomer
Joined
Jul 7, 2018
Messages
59
Trophies
0
Age
34
XP
262
Country
South Africa
Only if they were <4.1 and as a possible ace-in-the-hole on Mariko but that's screwed now.

But its sort of obvious that Nintendo's know about this flaw for half a year or more now.

So why watch people struggling to make dongles to launch the payload when you can have tetherless booting and there's no need to keep the exploit secret coz big N ran the numbers
 

N0n@me

Well-Known Member
Member
Joined
Jun 1, 2015
Messages
167
Trophies
0
Age
27
XP
264
Country
United States
So why watch people struggling to make dongles to launch the payload when you can have tetherless booting and there's no need to keep the exploit secret coz big N ran the numbers
It seems like nintendo hasn't fully patched it yet on the latest update so theythey are probably waiting for nintendo to fully patch it since releasing it now will put it at a higher priority to fix. Any ways making a dongles is simple enough.
 
Last edited by N0n@me,

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
SO if Nintendo already known this exploit, then ''K'' must leaked this exploit many months earlier? then things got heated up only recent because K was caught playing double agent all this time?

Nintendo probably found it themselves, its a common flaw in TX1. ktemkin mentioned that it an open source flaw.

So why watch people struggling to make dongles to launch the payload when you can have tetherless booting and there's no need to keep the exploit secret coz big N ran the numbers

It seems like nintendo hasn't patched it yet on the latest update so theythey are probably waiting for nintendo to fully patch it since releasing it now will put it at a higher priority to fix. And making a dongles is simple enough.

They know about the flaw, not necessarily all of the execution paths to it. They've mitigated it hard in 5.0, but maybe not entirely. But as you draw attention to it and talk about how possible it is, you make Nintendo look into it more.

Mariko may have carried the flaw.

We don't know if its possible on 5.0 or higher we just know it exists. It will always exist because its hardware but exploiting may be fully theory and not practical.
 
Last edited by V-Temp,
  • Like
Reactions: N0n@me

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,019
Trophies
2
Age
29
Location
New York City
XP
13,413
Country
United States
Hey, can you not downgrade with the rajkosto method? (even though that would defeat the purpose of a warmboot cause... you need rcm to get into your downgraded firm, right?)
Hmm, that's a good question. I don't believe the patched units come with the fuses already burnt so if you could hijack the first bootup of the console with RCM, load either Hekate or SX OS V1.3, check how many fuses are burnt with briccmii V2, you should load a firmware that matches however there are burnt or not. I could be wrong though but it definitely is worth testing out.
 
  • Like
Reactions: RichKK

adrifcastr

Well-Known Member
Member
Joined
Sep 12, 2016
Messages
2,038
Trophies
0
XP
1,947
Country
Germany
Hmm, that's a good question. I don't believe the patched units come with the fuses already burnt so if you could hijack the first bootup of the console with RCM, load either Hekate or SX OS V1.3, check how many fuses are burnt with briccmii V2, you should load a firmware that matches however there are burnt or not. I could be wrong though but it definitely is worth testing out.
Well I'm certainly pretty sure that the initial firmware flash burns the needed fuses, as the bootloader would otherwise panic upon boot.
 
  • Like
Reactions: Zulnoth

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
Hmm, that's a good question. I don't believe the patched units come with the fuses already burnt so if you could hijack the first bootup of the console with RCM, load either Hekate or SX OS V1.3, check how many fuses are burnt with briccmii V2, you should load a firmware that matches however there are burnt or not. I could be wrong though but it definitely is worth testing out.

Its burned on flash at factory.
 

tecfreak

Well-Known Member
Member
Joined
Apr 24, 2018
Messages
186
Trophies
0
Location
Berlin
XP
439
Country
Germany
well the people that were constantly asking to update and did so because they wanted to use SXOS are basicly fucked now
Why? FG is all you need. Only those who buy the new patched units and update their FW are fucked. And it won't be long and they all will be shipped with FW >4.1.
 
  • Like
Reactions: tbb043

kumikochan

Well-Known Member
Member
Joined
Feb 4, 2015
Messages
3,753
Trophies
0
Age
36
Location
Tongeren
XP
3,311
Country
Belgium
Such hate for SX lel.
No hate at all, just funny that people were constantly saying to not update and then they do. Don't twist what I said, it just has to do with updating and nothing to do with SXOS what I said. No need for xecuter drama

--------------------- MERGED ---------------------------

No, not really...
it does, only up to 4.1.0
 
Last edited by kumikochan,

Kioku

猫。子猫です!
Member
Joined
Jun 24, 2007
Messages
12,012
Trophies
3
Location
In the Murderbox!
Website
www.twitch.tv
XP
16,165
Country
United States
No hate at all, just funny that people were constantly saying to not update and then they do. Don't twist what I said, it just has to do with updating and nothing to do with SXOS

--------------------- MERGED ---------------------------


it does, only up to 4.1.0
Still have homebrew access and the ability to play backups (should I choose to). So, I'll live.
 
  • Like
Reactions: tbb043

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Psionic Roshambo @ Psionic Roshambo: https://www.youtube.com/watch?v=1Gt2ToRSjQA