Hacking Atmosphere-NX - Custom Firmware in development by SciresM

mariogamer

Well-Known Member
Member
Joined
Aug 12, 2015
Messages
1,256
Trophies
0
Age
28
XP
790
Country
Canada
Well 1.0 was supposed to have coldboot very soon, I guess that's probably why no one even cares talking about a warmboot exploit when we are talking about FW 1.0...

I don't think is that any warmboot above FW1.0 will be released in the day atmosphere is released, but we never know...
Heh, even 1.0 is long term.
 

guily6669

GbaTemp is my Drug
Member
Joined
Jun 3, 2013
Messages
2,348
Trophies
1
Age
34
Location
Doomed Island
XP
2,139
Country
United States
Well SciresM as far as I know always said Coldboot was coming soon for FW1.0... And at first he also stated that FW1.0 would most likely load atmosphere emunand before the others, but that's probably not valid anymore since the RCM exploit works everywhere and was leaked shortly after, but I guess the coldboot for FW1.0 coming soon is still valid, no idea.
 

mariogamer

Well-Known Member
Member
Joined
Aug 12, 2015
Messages
1,256
Trophies
0
Age
28
XP
790
Country
Canada
Well SciresM as far as I know always said Coldboot was coming soon for FW1.0... And at first he also stated that FW1.0 would most likely load atmosphere emunand before the others, but that's probably not valid anymore since the RCM exploit works everywhere and was leaked shortly after, but I guess the coldboot for FW1.0 coming soon is still valid, no idea.
Well this is the last message that explains everything well from sciresm:

Lemme be very clear:
On up to 4.1.0, we have a means of triggering full privileges code execution through softwarehax. This softwarehax requires user interaction. All of our current hax does.

Because the Switch uses ASLR, static exploits (not attacking scripting engines) are extremely unlikely to ever arise once you go down to OS-level exploitation. There's a flaw that allows for a "partial" ASLR defeat on < 3.0.2, but it's extremely difficult to use -- there's currently a $200 bounty from qlutoo and I for anyone being able to trigger a non-scripting engine aslr defeating exploit (e.g. via a savegame), and frankly I don't expect anyone to claim it any time soon. It's extremely difficult. I think in the long term, maybe 1.0.0 could get a solution where you turn it on and it boots into softwarehax. There's a theoretical vector that is almost impossible to use and also has no accompanying savegame exploit on < 3.0.2. Higher than that, your odds of getting what you'd call "coldboothax" are best summarized as followed:
"You're fucked."
I would genuinely maintain approximately zero hope.
 

guily6669

GbaTemp is my Drug
Member
Joined
Jun 3, 2013
Messages
2,348
Trophies
1
Age
34
Location
Doomed Island
XP
2,139
Country
United States
Guys please refer them as coldboot exploit and warmboot exploit to not misunderstand it, I'm noob :'v
Nothing is there to misunderstand... CFW\emunand has nothing to do with coldboot\warmboot exploit, they are separated things. To have a CFW we need a entry point which is the exploit (tethered\untethered, warmboot\coldboot)...

If I remember well Coldboot publicly known can be achieved up to 3.01 if I even remember well and above it up only warmboot is known up to 4.1, however only FW1.0 was said to get coldboot very soon, the others have no ETA, might never be completely leaked or might even never be exploited, but at least we know they exist and above 4.1 nothing is known and might never have anything other than using the crap jig'n payload 4 ever ;).
Well this is the last message that explains everything well from sciresm:
Yep, but there were other messages from him and Kate...

1 of them said the FW1.0 would have coldboot soon (not soon as in releasing with atmosphere though if I understood well, but can't remember ;)).
 
Last edited by guily6669,

guily6669

GbaTemp is my Drug
Member
Joined
Jun 3, 2013
Messages
2,348
Trophies
1
Age
34
Location
Doomed Island
XP
2,139
Country
United States
The exploit for FW1.0 nop, its exclusive for the first ever released console with FW 1.0 only (no idea why it still didnt show up working ;))...

The warmboot exploit for up to 4.1 (including it) is the one being hold down for mariko as they are hopping it will come with FW that still support it and it might be the only way to hack it as RCM tethered exploit is kaput in them.
 
Last edited by guily6669,

mariogamer

Well-Known Member
Member
Joined
Aug 12, 2015
Messages
1,256
Trophies
0
Age
28
XP
790
Country
Canada
The exploit for FW1.0 nop, its exclusive for the first ever released console with FW 1.0 only (no idea why it still didnt show up working ;))...

The warmboot exploit for up to 4.1 (including it) is the one being hold down for mariko as they are hopping it will come with FW4.1 and it might be the only way to hack it as RCM tethered exploit is kaput in them.
No it won't come with 4.x. They know mariko comes with 5.x because of someconfiguration added for it.
5.x didn't patch deja vu completely throught software, part of it is in the bootrom.
 

Bumblecito

Well-Known Member
Member
Joined
May 25, 2017
Messages
110
Trophies
0
Age
38
XP
411
Country
Mexico
The warmboot exploit for up to 4.1 (including it) is the one being hold down for mariko as they are hopping it will come with FW that still support it and it might be the only way to hack it as RCM tethered exploit is kaput in them.
But this is what Kate leaked to Nintendo, right?
 

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,021
Trophies
2
Age
29
Location
New York City
XP
13,422
Country
United States
But this is what Kate leaked to Nintendo, right?
Kate leaked to Nvidia (who then most likely disclosed it to Nintendo) the current RCM exploit, Fusee Gelee sometime in late winter/early spring, maybe February but I can't really remember the exact time. The warmboot exploits have not been disclosed to Nintendo otherwise they would have been released already as that gives Nintendo all the info they need to patch it and exploits are generally released after they have been fixed.
 
  • Like
Reactions: Bumblecito

guily6669

GbaTemp is my Drug
Member
Joined
Jun 3, 2013
Messages
2,348
Trophies
1
Age
34
Location
Doomed Island
XP
2,139
Country
United States
Is that supposed to be a joke? If you check their discord there's something being done almost every day. Those things take a huge work as its not just changing a few lines of code on the Nintendo FW, its like having a full custom OS written almost from scratch (I think SciresM said he actually started doing some work before any hack was known or maybe it was even before the Switch release, can't even remember lol, but he is a 3DS veteran).
 

M7L7NK7

Well-Known Member
Member
Joined
Oct 16, 2017
Messages
3,910
Trophies
1
Website
youtube.com
XP
6,005
Country
Australia

guily6669

GbaTemp is my Drug
Member
Joined
Jun 3, 2013
Messages
2,348
Trophies
1
Age
34
Location
Doomed Island
XP
2,139
Country
United States
10$ for the person that make it work, oh wait, I don't even have a Switch FW1.0, therefore 0$ 4 who release it working :)...

Now if someone would release a full working coldboot exploit for 3.01 then I would pay 10$ right away as I'm on 3.02 and since they share the same e-fuses, in theory I can go back to 3.01.

But I would be 99% happy with a hassle-free warmboot method of launching into emunand, if they made it work like GW emunand, would be 4 me just as good as coldboot with just like 2 or 3 touches on the screen and bam booting to atmosphere, I will keep dreaming and can only stop dreaming in the day something like that comes out :)
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: one of the people that appeared there was a minor when filming the cutscenes where she appears