Hacking PSA: Reports of Fusee gelee patched units in the wild

  • Thread starter Deleted-442439
  • Start date
  • Views 85,764
  • Replies 315
  • Likes 10

tecfreak

Well-Known Member
Member
Joined
Apr 24, 2018
Messages
186
Trophies
0
Location
Berlin
XP
439
Country
Germany
am i the only one slightly confused
Apparently. You can't patch it after it left the factory but you can patch it during the manufacturing process.

--------------------- MERGED ---------------------------

Realistically, Nintendo can patch this exploit on all current Switch units
I dont think that this is possible. Once alle the involved fuses are burnt, no one can make changes to the bootROM, not even Nintendo or Nvidia.
 

CreAtor135

GBATemp's #1 Nothing
Member
Joined
Jan 10, 2015
Messages
814
Trophies
0
Location
Ikeb, Ukuro
XP
1,499
Country
United States
Despite this however, Team Xecuter has released a video showcasing their SX Pro functioning properly on said hardware revision.​



TX has voiced that they would like the community's help in narrowing down what the actual problem is with these hardware units.

Team Xecuter said:
Today, we got sent a video showing that SX PRO is working fine on one of these so-called 'problem consoles', the mainstream media and other sites are working that Nintendo patched the f-g exploit, as such RCM and Jigs don't work anymore on these models 'HAC-S-JXE-C3' that are shipping from factory mainly in asia/hk area with v4.1.0 firwmare with iPatches that block the usage of Jig to get into RCM mode and to send up a payload.

Team-Xecuter has already bought 5 of these problem consoles, and all are working fine, but they need the community out there with SX PRO to report on the issues directly to them via their 'contact us' page, not with 'other ways' of loading payloads, but using SX PRO exclusively itself, with latest SX OS v1.3, and depending on the info you give them they will be in touch asking for more details and are offering to send the person money that owns a 'problem console' or a compatible console plus cost for shipping & handling to us, so they can collect it and properly diagnose and fix all the issues.
:arrow: Source
 

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
RIP. Maybe Nintendo could pull some wizardry and transfer all of your data into a patched Switch unit :D

They'd just replace the entire unit for anything they got if they were that adamant. If you send it in for repair, for example, you may not get the unit back.
 

_Shebang

Well-Known Member
Newcomer
Joined
Dec 14, 2016
Messages
66
Trophies
0
Age
27
XP
207
Country
Canada
Recently, it has been speculated that a factory-level Nintendo Switch hardware revision was the cause of a coldboot exploit, Fusee Gelee, being patched.

Despite this however, Team Xecuter has released a video showcasing their SX Pro functioning properly on said hardware revision.​



TX has voiced that they would like the community's help in narrowing down what the actual problem is with these hardware units.

:arrow: Source


This isn't the correct 'revision', note the serial number. All affected units so far have been of the form XAJ7004XXXXXX. Even then, one user has one starting with XAJ700418 and his boots payloads just fine.
 

CreAtor135

GBATemp's #1 Nothing
Member
Joined
Jan 10, 2015
Messages
814
Trophies
0
Location
Ikeb, Ukuro
XP
1,499
Country
United States
This isn't the correct 'revision', note the serial number. All affected units so far have been of the form XAJ7004XXXXXX. Even then, one user has one starting with XAJ700418 and his boots payloads just fine.
i made that thread like two hours ago, shortly after the information released. It was in "User Submitted News" and was moved here, though admittedly at the time I hadn't known about the margin of error from the reports that had been out at the time. That being said, the current results are not to say that TX's post was made with malice in mind, as there just isn't enough to go off of when determining what a revision unit is and isn't.
 
  • Like
Reactions: comput3rus3r

bitteorca

Member
Newcomer
Joined
Jul 12, 2018
Messages
21
Trophies
0
Age
28
XP
100
Country
United States
I purchased a Switch with the serial number XAW700183***** and I can confirm that payload injection doesn't work.

Steps to recreate:
1. Copied the Switch Starterkit root files to the root of my FAT32 SDcard from my PC
2. Inserted SDcard into Switch, then booted into RCM mode with paperclip jig
3. Plugged Switch into PC, used Zandig to install the libusbK drivers, confirmed APX came up as a device in device manager
4. Tried to run the NX bootkit 64-bit executable, the Switch screen remains black and the cmd prompt window displayed some code then counted down from 5 seconds to close the window

Is it possible that my USB-C cable (came with my phone) is the culprit here or is it likely that I have a patched Switch?
 

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
I purchased a Switch with the serial number XAW700183***** and I can confirm that payload injection doesn't work.

Steps to recreate:
1. Copied the Switch Starterkit root files to the root of my FAT32 SDcard from my PC
2. Inserted SDcard into Switch, then booted into RCM mode with paperclip jig
3. Plugged Switch into PC, used Zandig to install the libusbK drivers, confirmed APX came up as a device in device manager
4. Tried to run the NX bootkit 64-bit executable, the Switch screen remains black and the cmd prompt window displayed some code then counted down from 5 seconds to close the window

Is it possible that my USB-C cable (came with my phone) is the culprit here or is it likely that I have a patched Switch?
seems to be a low serial, whats the date code on the switch?

might be worth trying a different USB port/pc, unfortunately I feel like anyone having troubles with setup at this point are going to be "arrrgh its a patched switch!!!!"
 
Last edited by gamesquest1,
  • Like
Reactions: RAGER and gnilwob

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,021
Trophies
2
Age
29
Location
New York City
XP
13,421
Country
United States
I purchased a Switch with the serial number XAW700183***** and I can confirm that payload injection doesn't work.

Steps to recreate:
1. Copied the Switch Starterkit root files to the root of my FAT32 SDcard from my PC
2. Inserted SDcard into Switch, then booted into RCM mode with paperclip jig
3. Plugged Switch into PC, used Zandig to install the libusbK drivers, confirmed APX came up as a device in device manager
4. Tried to run the NX bootkit 64-bit executable, the Switch screen remains black and the cmd prompt window displayed some code then counted down from 5 seconds to close the window

Is it possible that my USB-C cable (came with my phone) is the culprit here or is it likely that I have a patched Switch?
If you had some video documenting the process, it would be easier to critique whether you are doing everything right or if you messed up on one or more of the steps.

Also, I don't believe the USB cable is the culprit here as your PC was able to detect the Switch as an APX device when it was plugged in.
 

bitteorca

Member
Newcomer
Joined
Jul 12, 2018
Messages
21
Trophies
0
Age
28
XP
100
Country
United States
seems to be a low serial, whats the date code on the switch?

might be worth trying a different USB port/pc, unfortunately I feel like anyone having troubles with setup at this point are going to be "arrrgh its a patched switch!!!!"
Sorry where do I find the date code? I purchased it today

And I just tried again on my other laptop and the same thing happened
 

gnilwob

Well-Known Member
Member
Joined
Mar 16, 2008
Messages
204
Trophies
1
XP
646
Country
Hong Kong
Sorry where do I find the date code? I purchased it today

And I just tried again on my other laptop and the same thing happened
Can you try tegrarcmsmash with biskeydump ?
Go to https://switchtools.sshnuke.net/ to download the files.
And run this command when you connect your RCM switch to your pc.

TegraRcmSmash.exe -w biskeydump.bin BOOT:0x0

Then capture the output on the command line windows and post it here please.

It should look like this:
2018-07-13_4-48-11.png
 
Last edited by gnilwob,

stephrk398

Well-Known Member
Member
Joined
May 29, 2018
Messages
544
Trophies
0
XP
1,421
Country
United States
ive had my extra one since launch

You going open your next extra? That's my dilemma, I want to sell it as New but want to be absolutely sure it can launch payloads. =/
I purchased a Switch with the serial number XAW700183***** and I can confirm that payload injection doesn't work.

Steps to recreate:
1. Copied the Switch Starterkit root files to the root of my FAT32 SDcard from my PC
2. Inserted SDcard into Switch, then booted into RCM mode with paperclip jig
3. Plugged Switch into PC, used Zandig to install the libusbK drivers, confirmed APX came up as a device in device manager
4. Tried to run the NX bootkit 64-bit executable, the Switch screen remains black and the cmd prompt window displayed some code then counted down from 5 seconds to close the window

Is it possible that my USB-C cable (came with my phone) is the culprit here or is it likely that I have a patched Switch?

Went from "confirmed" to "likely" in the same post. Guess I'll add another grain of salt to my pile.
 

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
Since this is an XAW unit, its very possible our XAJ expectations for serial do not match up, so do keep that in mind.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • BigOnYa @ BigOnYa:
    Biomutant looks cool tho, may have to try that
  • Quincy @ Quincy:
    Usually when such a big title leaks the Temp will be the first to report about it (going off of historical reports here, Pokemon SV being the latest one I can recall seeing pop up here)
  • K3Nv2 @ K3Nv2:
    I still like how a freaking mp3 file hacks webos all that security defeated by text yet again
  • BigOnYa @ BigOnYa:
    They have simulators for everything nowdays, cray cray. How about a sim that shows you playing the Switch.
  • K3Nv2 @ K3Nv2:
    That's called yuzu
    +1
  • BigOnYa @ BigOnYa:
    I want a 120hz 4k tv but crazy how more expensive the 120hz over the 60hz are. Or even more crazy is the price of 8k's.
  • K3Nv2 @ K3Nv2:
    No real point since movies are 30fps
  • BigOnYa @ BigOnYa:
    Not a big movie buff, more of a gamer tbh. And Series X is 120hz 8k ready, but yea only 120hz 4k games out right now, but thinking of in the future.
  • K3Nv2 @ K3Nv2:
    Mostly why you never see TV manufacturers going post 60hz
  • BigOnYa @ BigOnYa:
    I only watch tv when i goto bed, it puts me to sleep, and I have a nas drive filled w my fav shows so i can watch them in order, commercial free. I usually watch Married w Children, or South Park
  • K3Nv2 @ K3Nv2:
    Stremio ruined my need for nas
  • BigOnYa @ BigOnYa:
    I stream from Nas to firestick, one on every tv, and use Kodi. I'm happy w it, plays everything. (I pirate/torrent shows/movies on pc, and put on nas)
  • K3Nv2 @ K3Nv2:
    Kodi repost are still pretty popular
  • BigOnYa @ BigOnYa:
    What the hell is Kodi reposts? what do you mean, or "Wut?" -xdqwerty
  • K3Nv2 @ K3Nv2:
    Google them basically web crawlers to movie sites
  • BigOnYa @ BigOnYa:
    oh you mean the 3rd party apps on Kodi, yea i know what you mean, yea there are still a few cool ones, in fact watched the new planet of the apes movie other night w wifey thru one, was good pic surprisingly, not a cam
  • BigOnYa @ BigOnYa:
    Damn, only $2.06 and free shipping. Gotta cost more for them to ship than $2.06
  • BigOnYa @ BigOnYa:
    I got my Dad a firestick for Xmas and showed him those 3rd party sites on Kodi, he loves it, all he watches anymore. He said he has got 3 letters from AT&T already about pirating, but he says f them, let them shut my internet off (He wants out of his AT&T contract anyways)
  • K3Nv2 @ K3Nv2:
    That's where stremio comes to play never got a letter about it
  • BigOnYa @ BigOnYa:
    I just use a VPN, even give him my login and password so can use it also, and he refuses, he's funny.
  • BigOnYa @ BigOnYa:
    I had to find and get him an old style flip phone even without text, cause thats what he wanted. No text, no internet, only phone calls. Old, old school.
    K3Nv2 @ K3Nv2: @BigOnYa...