Nereba Exploit: Reboot to Fusée Gelée payload from stock firmware.

nintendo-switch-homebrew-launcher.jpg

Stuckpixel of the ReSwitched team recently released his exploit "Nereba".


This exploit will enable Nintendo Switch owners with early units that have held off updating, still on the original 1.0.0 firmware to reboot into a Fusée Gelée payload without any dongle, USB connections to a external device or jig directly from stock untouched firmware. In addition support for 2.x and 3.x firmware is also planned in the future, opening up the exploit to significantly more consoles.

The implementation takes advantage of the nspwn exploit, that users of the original 3.0.0 homebrew implementation will be familiar with. Used in conjunction with this, users will be able to boot any Fusee Gelee payload from the micro SD card, placed in the nereba folder on the root of the SD card. After running the script from the Switch web applet, users can reboot into any payload by launching the album applet from the home menu.

Download:


https://github.com/pixel-stuck/nereba/releases
 
Last edited by RattletraPM, , Reason: Center image to follow news formatting

Hayato213

Newcomer
Member
Joined
Dec 26, 2015
Messages
20,093
Trophies
1
XP
21,290
Country
United States
And I can guarantee that scalpers are going to be greedy assholes about it on eBay.

People can put anything on eBay for any price, it up to the other person who buying it if they willing to spend the money, I did managed to get few people to pay $200 buck for stuff that I paid like 30 bucks for lol but it was some rare stuff, a kyogre cover plate from the Japanese exclusive N3DS bundle, and the Boo 3DS cover plate, man people are will to pay. Sorry to says that I am a scalper when I can.
 

ZachyCatGames

Well-Known Member
Member
Joined
Jun 19, 2018
Messages
3,398
Trophies
1
Location
Hell
XP
4,209
Country
United States
Exploit through the browser and from there the sd card through the album. Similar to what we had on 3.0 but instead of the homebrew channel loading it will now load cfw thanks to fuse gelee
This doesn’t involve Fusee Gelee in any way :P
what would happen if we launch that on a Patched Switch
I know that only works on 1.0.0
but whats about nxhax and then Reboot To Payload
Does that works?
If you somehow got a 1.0.0 FG patched system, it’d probably work fine
 

the_randomizer

The Temp's official fox whisperer
Member
Joined
Apr 29, 2011
Messages
31,284
Trophies
2
Age
38
Location
Dr. Wahwee's castle
XP
18,969
Country
United States
Eventually a downgrade option will be available and people who paid more for a 1.x Switch will feel like idiots.

Yeah and I bet there'll be a softmod option for 8.x.x users as well, right? I have a lot of cynicism towards Switch homebrew development as a whole.

People can put anything on eBay for any price, it up to the other person who buying it if they willing to spend the money, I did managed to get few people to pay $200 buck for stuff that I paid like 30 bucks for lol but it was some rare stuff, a kyogre cover plate from the Japanese exclusive N3DS bundle, and the Boo 3DS cover plate, man people are will to pay. Sorry to says that I am a scalper when I can.

And as long as people will enable scalpers, that'll never change.
 

jammybudga777

Well-Known Member
Member
Joined
Aug 23, 2013
Messages
2,284
Trophies
1
Age
37
XP
2,193
Country
i asked earlier if downgrading would be an issue from 6.2 to 3.0 (was done official way so burnt fuses) i got told its not possible. but yet im reading in ChoiDujour guide that fuses now dont matter? could someone just tell me whats actually the correct answer please lol
 

thla

Active Member
Newcomer
Joined
Jul 30, 2017
Messages
36
Trophies
0
XP
677
Country
Denmark
i asked earlier if downgrading would be an issue from 6.2 to 3.0 (was done official way so burnt fuses) i got told its not possible. but yet im reading in ChoiDujour guide that fuses now dont matter? could someone just tell me whats actually the correct answer please lol

When you update Nintendo has the option of "burning a fuse", quite literally it's permanently modifying the hardware. You can't un-modify the fuses (practically) and the software won't boot with the incorrect fuses set.

But of course it might be possible to circumvent the hardware side if the device is compromised.
 

jammybudga777

Well-Known Member
Member
Joined
Aug 23, 2013
Messages
2,284
Trophies
1
Age
37
XP
2,193
Country
When you update Nintendo has the option of "burning a fuse", quite literally it's permanently modifying the hardware. You can't un-modify the fuses (practically) and the software won't boot with the incorrect fuses set.

But of course it might be possible to circumvent the hardware side if the device is compromised.
i no how the fuses burn if you update legitly. but im being passed information that contradicts more information im reading. alot of people are saying fuses dont matter anymore? and others are saying i can still return to a lower firmware even after burning fuses?
 

Garrincho

Well-Known Member
Member
Joined
Sep 16, 2015
Messages
175
Trophies
0
Age
35
XP
510
Country
Uruguay
i no how the fuses burn if you update legitly. but im being passed information that contradicts more information im reading. alot of people are saying fuses dont matter anymore? and others are saying i can still return to a lower firmware even after burning fuses?


You can downgrade to any firmware you want, anytime, no matter the fuses.

BUT

To boot it if you burned more fuses than the corresponding ones for that FW, you'd still need to use a custom bootloader (in essence rcm exploit ) since the official one will refuse to do so.

So even if you did that, why would you want to enter rcm, start the switch, use this software exploit and reboot again to cfw? You'd just use the old RCM method and go to cfw.
 

jammybudga777

Well-Known Member
Member
Joined
Aug 23, 2013
Messages
2,284
Trophies
1
Age
37
XP
2,193
Country
You can downgrade to any firmware you want, anytime, no matter the fuses.

BUT

To boot it if you burned more fuses than the corresponding ones for that FW, you'd still need to use a custom bootloader (in essence rcm exploit ) since the official one will refuse to do so.

So even if you did that, why would you want to enter rcm, start the switch, use this software exploit and reboot again to cfw? You'd just use the old RCM method and go to cfw.
thanks for explaining. obviously i wouldnt when you put it like that.
 

kumikochan

Well-Known Member
Member
Joined
Feb 4, 2015
Messages
3,753
Trophies
0
Age
36
Location
Tongeren
XP
3,311
Country
Belgium
thanks for explaining. obviously i wouldnt when you put it like that.
Sorry didn't mean to quote you, was on the wrong tab lol

--------------------- MERGED ---------------------------

This doesn’t involve Fusee Gelee in any way :P

If you somehow got a 1.0.0 FG patched system, it’d probably work fine
It does and it even says so in the first post. '' still on the original 1.0.0 firmware to reboot into a Fusée Gelée payload without any dongle, ''
 

TP998

New Member
Newbie
Joined
Apr 19, 2019
Messages
2
Trophies
0
Age
25
XP
44
Country
Aruba
And I can guarantee that scalpers are going to be greedy assholes about it on eBay.

Not really sure there is a market for 1.0.0 consoles, the exploit still needs Emunand.

When it comes however, you'll be faced with two options:

1) Sysnand on low firmware (offline) > Warmboot > Emunand (offline)
2) Sysnand on latest (online) > RCM > Emunand (offline)

As it's not possible to be safe online using Emunand due to it being easily detected and redirecting everything to an sdcard, I can see the vast majority of the community using option 2, because they are already using RCM and they can use their sysnand for retail/f2p games, not sure warmboot is worth exiling yourself from online.

It's the one thing that TX have going for them.
 

ZachyCatGames

Well-Known Member
Member
Joined
Jun 19, 2018
Messages
3,398
Trophies
1
Location
Hell
XP
4,209
Country
United States
It does and it even says so in the first post. '' still on the original 1.0.0 firmware to reboot into a Fusée Gelée payload without any dongle, ''
The payloads aren’t Fusee Gelee specific, Atmosphere’s reboot to payload feature doesn’t involve FG as well. This uses Dormez Vous combined with some other exploits
 

kumikochan

Well-Known Member
Member
Joined
Feb 4, 2015
Messages
3,753
Trophies
0
Age
36
Location
Tongeren
XP
3,311
Country
Belgium
The payloads aren’t Fusee Gelee specific, Atmosphere’s reboot to payload feature doesn’t involve FG as well. This uses Dormez Vous combined with some other exploits
Doesn't deja vu use the wekbit exploit to give more userland privileges wich eventually leads to fuse gelee rebooting in to cfw ?
 
D

Deleted-442439

Guest
OP
Thanks JJ, very cool!

Danke
Doesn't deja vu use the wekbit exploit to give more userland privileges wich eventually leads to fuse gelee rebooting in to cfw ?

Deja Vu allows you to reboot to payload through arbitrary TrustZone/BootROM code execution. By using either the original Jamais Vu exploit (<6.0.0) and warmboot exploit for higher.

It also uses webkit as a entry-point, but it is not related to nspwn, separate exploits, but same entry point.

The loaded payloads, are indeed the same as used for FG, but the exploit is separate, hence why it works on Ipatched units.
 
Last edited by ,

kumikochan

Well-Known Member
Member
Joined
Feb 4, 2015
Messages
3,753
Trophies
0
Age
36
Location
Tongeren
XP
3,311
Country
Belgium
Danke


Deja Vu allows you to reboot to payload through arbitrary TrustZone/BootROM code execution. By using either the original Jamais Vu exploit (<6.0.0) and warmboot exploit for higher.

It also uses webkit as a entry-point, but it is not related to nspwn, separate exploits, but same entry point.

The loaded payloads, are indeed the same as used for FG, but the exploit is separate, hence why it works on Ipatched units.
Well thanks for letting me know, wasn't sure but this is a good explanation so thanks for that. Know a lot of stuff but i am in a lot of scenes so don't know what's up with everything 100 percent exactly but learned something new thanks to you :D
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • AncientBoi @ AncientBoi:
    Cholesterol is sorta high, according to my doc
    +1
  • K3Nv2 @ K3Nv2:
    I've been taking fiber pills, eating more grapes, switched to wheat bread in hopes to lower it
    +1
  • BigOnYa @ BigOnYa:
    I like wheat bread, I even like the chunky wheat bread with pieces of whole grain in it.
  • K3Nv2 @ K3Nv2:
    Been getting this honey wheat bread from aldis pretty decent not very sweet to out do it
  • K3Nv2 @ K3Nv2:
    Me making any food at home is an improvement to how I use to be
    +1
  • BigOnYa @ BigOnYa:
    I have an bread machine and use it alot, better than breads you buy, but don't last as long, cause no bs preservatives
  • K3Nv2 @ K3Nv2:
    I got compliments about my weight loss and thought well guess I can pig out again now I'm the piggy
  • BigOnYa @ BigOnYa:
    My biggest prob is alcohol, definitely is fattening
  • K3Nv2 @ K3Nv2:
    I know when to stop at least honestly don't get those that go and go with food
  • BigOnYa @ BigOnYa:
    Or those that order 2 big macs , large fry, ice cream sundie, then a diet coke
  • K3Nv2 @ K3Nv2:
    I might get downing two big macs but nah that's it
  • BigOnYa @ BigOnYa:
    Ok that will be $15.99, cash or charge?
  • K3Nv2 @ K3Nv2:
    My go to orders usually a mcdouble and a mcchicken and I'm happy rarely mess with fries
  • K3Nv2 @ K3Nv2:
    Pro tip ask for that clowns jizzmac sauce on your mcdouble
    +1
  • BigOnYa @ BigOnYa:
    Do they charge extra when you add sauce,etc? I know burger king used to not, but don't know nowadays
  • K3Nv2 @ K3Nv2:
    They may squrit it for free if you ask nice
    +1
  • K3Nv2 @ K3Nv2:
    Last time I got bk it was 35c per sauce fuck you king of my nutsack
    +1
  • K3Nv2 @ K3Nv2:
    I'll buy a bottle of baby rays BBQ for $2 and add it from home out of spite
    +1
  • BigOnYa @ BigOnYa:
    I like baby rays, my favorite is KC masterpiece tho. Figured all you could buy is that there.
  • K3Nv2 @ K3Nv2:
    The metro doesn't discriminate good sauce
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Baby Rays isn't that what killed the crocodile hunter?
  • Psionic Roshambo @ Psionic Roshambo:
    If only he had done an endorsement for them....
  • Psionic Roshambo @ Psionic Roshambo:
    Oy mate don't let a bad bbq sauce kill your party! Baby Rays are killing it!! The flavor hits you right in the chest!
    +1
  • Xdqwerty @ Xdqwerty:
    My phone only has 13% battery so i don't have much time left
  • Xdqwerty @ Xdqwerty:
    Now 12%
    Xdqwerty @ Xdqwerty: Now 12%