Hacking RELEASE biskeydump and HacDiskMount - Switch eMMC decryption/real-time mounting tools

SocraticBliss

Well-Known Member
Member
Joined
Jun 3, 2017
Messages
130
Trophies
0
Age
36
XP
273
Country
United States
it doesn't ask for a bis key. Notice that the BIS KEY group box doesn't have a number next to it. These partitions arent encrypted (leave the 2 key boxes blank), see: http://switchbrew.org/index.php?title=Flash_Filesystem

Do you think it would be better to hide those 2 boxes if they select those partitions? Might prevent people from making a mistake, as it's true that it isn't very clear.

Also, would be nice to save the previous keys used, that way we don't have to re-enter them each time we re-open a partition.
 

aut0mat3d

Well-Known Member
Member
Joined
Mar 15, 2017
Messages
212
Trophies
0
XP
568
Country
Australia
Do you think it would be better to hide those 2 boxes if they select those partitions? Might prevent people from making a mistake, as it's true that it isn't very clear.

Also, would be nice to save the previous keys used, that way we don't have to re-enter them each time we re-open a partition.

Hiding those boxes would be fine to avoid misunderstandings ;)

A Save Option is already included - the button "check keys" (or so) changes to save if the check was OK
 

riyyi

Well-Known Member
Member
Joined
Sep 13, 2009
Messages
100
Trophies
0
XP
621
Country
Netherlands
Using Hekate ipl (this commit https://github.com/nwert/hekate/commit/e7373548fa3dd51508b34ae9c673885f849f653e)
I get the 3 errors when dumping the eMMC, but it should be fine, according to this:
No. if they were unreadable the dump would have failed. They were able to be read on the 2nd try which is why you only see their address once. The eMMC probably just gets tired and fails sometimes :shrug:

However, my dump is 27.9 GB (29,979,344,896 bytes), which is to small I think.
HacDiskMount says: [08:53:35:222535]
Not enough bytes reading secondary GPT header from offset 31268535808
What could I to fix this? I'm on 3.0.1

BcJb0gP.png

Edit: Dump is correct using the newest commit (https://github.com/nwert/hekate/commit/5ca3bbcaf18daabed20a168cb6ee63d9d51a1161)
 
Last edited by riyyi,

SocraticBliss

Well-Known Member
Member
Joined
Jun 3, 2017
Messages
130
Trophies
0
Age
36
XP
273
Country
United States
Hiding those boxes would be fine to avoid misunderstandings ;)

A Save Option is already included - the button "check keys" (or so) changes to save if the check was OK

Either hiding it, or ignoring the inputs would probably work...

Thanks for the save clarification :) my bad!
 

d4mation

Well-Known Member
Member
Joined
Aug 3, 2013
Messages
189
Trophies
0
XP
1,711
Country
United States
HacDiskMount - use your BIS keys and your RawNand.bin (or the physical eMMC attached via microSD reader or using a mass storage gadget mode in u-boot/linux) to dump, restore or REAL-TIME MOUNT AND EXPLORE/MODIFY partitions from the dump file or attached physical device !

Could this be used to remove the "Super Nag" flag? This could be great for people who are on lower system firmwares who were effected by this.

https://gbatemp.net/threads/importa...ges-to-block-web-applets-from-working.502431/
 

rajkosto

Well-Known Member
OP
Member
Joined
Apr 6, 2017
Messages
819
Trophies
1
XP
2,775
Country
It doesn't go there. HacDiskMount does not do anything with regards to boot0/boot1. If you want to readout keyblobs from your boot0 check out hactool with --infile=keygen
 

Imancol

Otak Productions
Member
Joined
Jun 29, 2017
Messages
1,376
Trophies
0
XP
2,774
Country
Colombia
It doesn't go there. HacDiskMount does not do anything with regards to boot0/boot1. If you want to readout keyblobs from your boot0 check out hactool with --infile=keygen
Try your latest version of BiskeyDump and I could not not know if it should be executed first with TegraRMCSmash 1101 and then in CMD write the argument or just write the argument in CMD. Could you please guide me?
 

Imancol

Otak Productions
Member
Joined
Jun 29, 2017
Messages
1,376
Trophies
0
XP
2,774
Country
Colombia
Use this command with the version biskeydumpV6 and TegraCMSSmash 1.1.0.1

Code:
TegraRcmSmash.exe -w biskeydump.bin BOOT:0x0
 

Addconsult

Well-Known Member
Newcomer
Joined
Apr 29, 2018
Messages
61
Trophies
0
Age
40
XP
197
Country
Sweden
Tried to get the biskeys with tegrarcm and biskeydump.bin as payload. Nothing happens after "uploading payload". Fusee payload works and hekate payload too. I tried the newest version of tegrarcm and the version before that. Same issue. Launched it with
TegraRcmSmash.exe -w biskeydump.bin BOOT:0x0
AND
Without the "boot" flag. Running Switch FW 4.0.1

Anyone know a solution ? I have reinstalled APX drivers several times and rebooted. Also tried different usb ports (Same computer).
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv2 @ K3Nv2:
    Or a win4 things still sexy
  • ZeroT21 @ ZeroT21:
    having money does not mean everyone will just fork it over
  • ZeroT21 @ ZeroT21:
    everyone perceives value diffrently
  • K3Nv2 @ K3Nv2:
    I buy cheap and whats useable
  • K3Nv2 @ K3Nv2:
    Twice out of the year I may get something that's $600
  • ZeroT21 @ ZeroT21:
    we all like nice things, sure, but I also want to keep money on the side
  • K3Nv2 @ K3Nv2:
    I'd have the same mentality if money wasn't an object
  • ZeroT21 @ ZeroT21:
    having a warped sense can happen
  • ZeroT21 @ ZeroT21:
    reason i question myself, but not constantly
  • K3Nv2 @ K3Nv2:
    If I had Elon money sure I'd have a 20 bedroom home
  • ZeroT21 @ ZeroT21:
    if only that alone could make me happy, but nope
    :D
  • ZeroT21 @ ZeroT21:
    you'll only feel more empty after most of your urges go away like that
  • K3Nv2 @ K3Nv2:
    Spam account tried getting $10 off me I'm like you didn't have it last week you'll be fine
    +1
  • ZeroT21 @ ZeroT21:
    i get spam links all the time, even through steam
  • ZeroT21 @ ZeroT21:
    get same links from scammers posing as my steam friends
  • BakerMan @ BakerMan:
    i know how to combat scammers
  • BakerMan @ BakerMan:
    traumatize them, send them a screamer vid first as a warning shot, then if that doesn't work, send them gore
  • K3Nv2 @ K3Nv2:
    I just opened Amazon thinking it was my bank app may as well be
  • ZeroT21 @ ZeroT21:
    i get those fake google , or fake steam mostly phishing for logins
  • K3Nv2 @ K3Nv2:
    I'll buy your account for $10
  • ZeroT21 @ ZeroT21:
    i sent one scam link i got to the other one
  • ZeroT21 @ ZeroT21:
    let them fight it out
    ZeroT21 @ ZeroT21: let them fight it out