Hacking Suggestion Downloading Switch updates on PC for hacking purposes

punderino

aka Big-PeePee Swinger
Member
Joined
Jan 5, 2016
Messages
1,247
Trophies
0
Age
32
Location
Kansas City, Missouri
Website
www.anus.trade
XP
2,506
Country
United States
Yes, but hopefully at some point in the future (possibly years, but likely more) we will be able to decrypt them. If we could modify them and then proxy the updater to download and install the modded FW...
Uhmm.... You do realize they sign everything? You can't just patch or change something and put it on the console. It will never work. Never ever ever without the bootrom being leaked or hacked.
 
  • Like
Reactions: chaoskagami

SocraticBliss

Well-Known Member
Member
Joined
Jun 3, 2017
Messages
130
Trophies
0
Age
36
XP
273
Country
United States
Ok.. I setup an android with tethering, rooted it and used tcpdump.. (no access to router right now) I have two packet captures of the data.. I know people have access to them on the forum, etc but I didn't, and nobody has shared them.. Feel free to let me know if you need them... Anyways, the SSL hierarchy has some certificates using SHA-1, and possibly other older, co algorithms algorithms... its a last option if all else fails..

I'll give SSLStrip a shot soon to see if the switch will allow communications through non-nintendo SSL certs and maybe trying to force HTTP instead of HTTPS, etc.. ill see if I can use a HTTP proxy, or anything like that

If anyone knows or has tried any of these things let me know...

Hey Mike,

I don't have the ability to send PM's yet, but I need a bit of help finding the specific URL (or maybe the post request?) for the firmware.

I scoured the web yesterday and found the following SSL certs you can use to help, the password for the keys is alpine, I downloaded and added the CTR Common Prod 1 and Nintendo Class 2 CA - G3 to my personal cert store, I hope this helps...

I managed to get a switch UA from reddit... not sure if its the right one for firmware downloads though...

"Mozilla/5.0 (Nintendo Switch; ShareApplet) AppleWebKit/601.6 (KHTML, like Gecko) NF/4.0.0.5.9 NintendoBrowser/5.1.0.13341"

Then the URL I tried using was the one everyone is blocking...

http://sun.hac.lp1.d4c.nintendo.net:443/



In the end my final wget command looks something like this so far, but I am still unable to download any firmware files, can you let me know if you have any luck with this or the next steps I should be trying? Thanks!

wget --user-agent="Mozilla/5.0 (Nintendo Switch; ShareApplet) AppleWebKit/601.6 (KHTML, like Gecko) NF/4.0.0.5.9 NintendoBrowser/5.1.0.13341" http://sun.hac.lp1.d4c.nintendo.net:443/
 

mosb3rg

Member
Newcomer
Joined
Mar 17, 2017
Messages
9
Trophies
0
Age
40
XP
56
Country
United States
that isn't going to work. because your user agent isn't the only factor here. Likely, theres also some CORS happening, so custom headers are probably being used to give access to these domains from the device. so despite that url your mentioning not being https its not going to work that way.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    SylverReZ @ SylverReZ: @NinStar, Who's whipping who?