Switch v2, OLED, and Lite Cracking Group
A group dedicated to cracking the IPATCHED (v2, improved battery), OLED, and Lite Nintendo Switch protection and/or finding exploitable software holes.

Hacking anything takes time. Rather than doubting it or spamming saying it's impossible, help look for holes, secret modes, etc. With a team of people working together, the PATCHED Switch issue may become a thing of the past.

(FOR RESEARCH PURPOSES)
Switch v2, OLED, and Lite Cracking Group
Switch v2, OLED, and Lite Cracking Group

Switch v2 RCM Exploit (Theoretical)

Deleted member 535703

Waluigi's Propaganda Mine
Member
Joined
Aug 13, 2020
Messages
826
Reaction score
1,844
Trophies
2
XP
3,393
Whoops, forgot that I made this a group, but guess what, I have things to actually show for it now.

In reading up on the Fusee Gelee exploit, I did learn quite a bit about how RCM works. And then the code for the Switch bootloader actually leaked. Great. Even more information.

I've been looking through some sources, and it looks like RCM needs to just confirm the signature of a payload before it runs it. So I thought, hey, maybe it's cryptographically possible to sign a binary using these things?

I actually found a key used for signing NVIDIA assets that actually verified with the bootloader public key. Butttt, I haven't been able to test it with the bootloader itself. I don't have a way to send a payload to that since I don't have access to the RCM tools. I think I would need an Nvidia account for that.

Anyways, if anyone can find a way to push a payload to the Switch RCM the way NVIDIA intends for a payload to be sent, let me know. I need to test these signed versions of hekate. Provided they don't actually work, and I don't expect them to, at least this will be a potential entryway into the Switch.

TegraRCMsmash isn't going to work for this as the whole point of it is to smash the stack, not actually deliver the payload normally.
 
  • Like
Reactions: m_babble and Finray
Whoops, forgot that I made this a group, but guess what, I have things to actually show for it now.

In reading up on the Fusee Gelee exploit, I did learn quite a bit about how RCM works. And then the code for the Switch bootloader actually leaked. Great. Even more information.

I've been looking through some sources, and it looks like RCM needs to just confirm the signature of a payload before it runs it. So I thought, hey, maybe it's cryptographically possible to sign a binary using these things?

I actually found a key used for signing NVIDIA assets that actually verified with the bootloader public key. Butttt, I haven't been able to test it with the bootloader itself. I don't have a way to send a payload to that since I don't have access to the RCM tools. I think I would need an Nvidia account for that.

Anyways, if anyone can find a way to push a payload to the Switch RCM the way NVIDIA intends for a payload to be sent, let me know. I need to test these signed versions of hekate. Provided they don't actually work, and I don't expect them to, at least this will be a potential entryway into the Switch.

TegraRCMsmash isn't going to work for this as the whole point of it is to smash the stack, not actually deliver the payload normally.
Mad props an respec to u man. I LOVE when someone gets the brain going for this subject... Dont listen to all the naysayers that all the sudden think N is smarter than the NSA:lol:. I hope u stuck wit it and made progress on this.... it can be done. Where there is a will...there is a way.
 

Group statistics

Group owner:
Deleted member 535703
Members:
101
Threads:
3
Messages:
9

Site & Scene News

New Hot Discussed User Submitted