Hacking PSA: Reports of Fusee gelee patched units in the wild

  • Thread starter Deleted-442439
  • Start date
  • Views 85,619
  • Replies 315
  • Likes 10

tecfreak

Well-Known Member
Member
Joined
Apr 24, 2018
Messages
186
Trophies
0
Location
Berlin
XP
439
Country
Germany
am i the only one slightly confused
Apparently. You can't patch it after it left the factory but you can patch it during the manufacturing process.

--------------------- MERGED ---------------------------

Realistically, Nintendo can patch this exploit on all current Switch units
I dont think that this is possible. Once alle the involved fuses are burnt, no one can make changes to the bootROM, not even Nintendo or Nvidia.
 

CreAtor135

GBATemp's #1 Nothing
Member
Joined
Jan 10, 2015
Messages
814
Trophies
0
Location
Ikeb, Ukuro
XP
1,499
Country
United States
Despite this however, Team Xecuter has released a video showcasing their SX Pro functioning properly on said hardware revision.​



TX has voiced that they would like the community's help in narrowing down what the actual problem is with these hardware units.

Team Xecuter said:
Today, we got sent a video showing that SX PRO is working fine on one of these so-called 'problem consoles', the mainstream media and other sites are working that Nintendo patched the f-g exploit, as such RCM and Jigs don't work anymore on these models 'HAC-S-JXE-C3' that are shipping from factory mainly in asia/hk area with v4.1.0 firwmare with iPatches that block the usage of Jig to get into RCM mode and to send up a payload.

Team-Xecuter has already bought 5 of these problem consoles, and all are working fine, but they need the community out there with SX PRO to report on the issues directly to them via their 'contact us' page, not with 'other ways' of loading payloads, but using SX PRO exclusively itself, with latest SX OS v1.3, and depending on the info you give them they will be in touch asking for more details and are offering to send the person money that owns a 'problem console' or a compatible console plus cost for shipping & handling to us, so they can collect it and properly diagnose and fix all the issues.
:arrow: Source
 

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
RIP. Maybe Nintendo could pull some wizardry and transfer all of your data into a patched Switch unit :D

They'd just replace the entire unit for anything they got if they were that adamant. If you send it in for repair, for example, you may not get the unit back.
 

_Shebang

Well-Known Member
Newcomer
Joined
Dec 14, 2016
Messages
66
Trophies
0
Age
27
XP
207
Country
Canada
Recently, it has been speculated that a factory-level Nintendo Switch hardware revision was the cause of a coldboot exploit, Fusee Gelee, being patched.

Despite this however, Team Xecuter has released a video showcasing their SX Pro functioning properly on said hardware revision.​



TX has voiced that they would like the community's help in narrowing down what the actual problem is with these hardware units.

:arrow: Source


This isn't the correct 'revision', note the serial number. All affected units so far have been of the form XAJ7004XXXXXX. Even then, one user has one starting with XAJ700418 and his boots payloads just fine.
 

CreAtor135

GBATemp's #1 Nothing
Member
Joined
Jan 10, 2015
Messages
814
Trophies
0
Location
Ikeb, Ukuro
XP
1,499
Country
United States
This isn't the correct 'revision', note the serial number. All affected units so far have been of the form XAJ7004XXXXXX. Even then, one user has one starting with XAJ700418 and his boots payloads just fine.
i made that thread like two hours ago, shortly after the information released. It was in "User Submitted News" and was moved here, though admittedly at the time I hadn't known about the margin of error from the reports that had been out at the time. That being said, the current results are not to say that TX's post was made with malice in mind, as there just isn't enough to go off of when determining what a revision unit is and isn't.
 
  • Like
Reactions: comput3rus3r

bitteorca

Member
Newcomer
Joined
Jul 12, 2018
Messages
21
Trophies
0
Age
28
XP
100
Country
United States
I purchased a Switch with the serial number XAW700183***** and I can confirm that payload injection doesn't work.

Steps to recreate:
1. Copied the Switch Starterkit root files to the root of my FAT32 SDcard from my PC
2. Inserted SDcard into Switch, then booted into RCM mode with paperclip jig
3. Plugged Switch into PC, used Zandig to install the libusbK drivers, confirmed APX came up as a device in device manager
4. Tried to run the NX bootkit 64-bit executable, the Switch screen remains black and the cmd prompt window displayed some code then counted down from 5 seconds to close the window

Is it possible that my USB-C cable (came with my phone) is the culprit here or is it likely that I have a patched Switch?
 

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
I purchased a Switch with the serial number XAW700183***** and I can confirm that payload injection doesn't work.

Steps to recreate:
1. Copied the Switch Starterkit root files to the root of my FAT32 SDcard from my PC
2. Inserted SDcard into Switch, then booted into RCM mode with paperclip jig
3. Plugged Switch into PC, used Zandig to install the libusbK drivers, confirmed APX came up as a device in device manager
4. Tried to run the NX bootkit 64-bit executable, the Switch screen remains black and the cmd prompt window displayed some code then counted down from 5 seconds to close the window

Is it possible that my USB-C cable (came with my phone) is the culprit here or is it likely that I have a patched Switch?
seems to be a low serial, whats the date code on the switch?

might be worth trying a different USB port/pc, unfortunately I feel like anyone having troubles with setup at this point are going to be "arrrgh its a patched switch!!!!"
 
Last edited by gamesquest1,
  • Like
Reactions: RAGER and gnilwob

Draxzelex

Well-Known Member
Member
Joined
Aug 6, 2017
Messages
19,012
Trophies
2
Age
29
Location
New York City
XP
13,395
Country
United States
I purchased a Switch with the serial number XAW700183***** and I can confirm that payload injection doesn't work.

Steps to recreate:
1. Copied the Switch Starterkit root files to the root of my FAT32 SDcard from my PC
2. Inserted SDcard into Switch, then booted into RCM mode with paperclip jig
3. Plugged Switch into PC, used Zandig to install the libusbK drivers, confirmed APX came up as a device in device manager
4. Tried to run the NX bootkit 64-bit executable, the Switch screen remains black and the cmd prompt window displayed some code then counted down from 5 seconds to close the window

Is it possible that my USB-C cable (came with my phone) is the culprit here or is it likely that I have a patched Switch?
If you had some video documenting the process, it would be easier to critique whether you are doing everything right or if you messed up on one or more of the steps.

Also, I don't believe the USB cable is the culprit here as your PC was able to detect the Switch as an APX device when it was plugged in.
 

bitteorca

Member
Newcomer
Joined
Jul 12, 2018
Messages
21
Trophies
0
Age
28
XP
100
Country
United States
seems to be a low serial, whats the date code on the switch?

might be worth trying a different USB port/pc, unfortunately I feel like anyone having troubles with setup at this point are going to be "arrrgh its a patched switch!!!!"
Sorry where do I find the date code? I purchased it today

And I just tried again on my other laptop and the same thing happened
 

gnilwob

Well-Known Member
Member
Joined
Mar 16, 2008
Messages
204
Trophies
1
XP
644
Country
Hong Kong
Sorry where do I find the date code? I purchased it today

And I just tried again on my other laptop and the same thing happened
Can you try tegrarcmsmash with biskeydump ?
Go to https://switchtools.sshnuke.net/ to download the files.
And run this command when you connect your RCM switch to your pc.

TegraRcmSmash.exe -w biskeydump.bin BOOT:0x0

Then capture the output on the command line windows and post it here please.

It should look like this:
2018-07-13_4-48-11.png
 
Last edited by gnilwob,

stephrk398

Well-Known Member
Member
Joined
May 29, 2018
Messages
544
Trophies
0
XP
1,421
Country
United States
ive had my extra one since launch

You going open your next extra? That's my dilemma, I want to sell it as New but want to be absolutely sure it can launch payloads. =/
I purchased a Switch with the serial number XAW700183***** and I can confirm that payload injection doesn't work.

Steps to recreate:
1. Copied the Switch Starterkit root files to the root of my FAT32 SDcard from my PC
2. Inserted SDcard into Switch, then booted into RCM mode with paperclip jig
3. Plugged Switch into PC, used Zandig to install the libusbK drivers, confirmed APX came up as a device in device manager
4. Tried to run the NX bootkit 64-bit executable, the Switch screen remains black and the cmd prompt window displayed some code then counted down from 5 seconds to close the window

Is it possible that my USB-C cable (came with my phone) is the culprit here or is it likely that I have a patched Switch?

Went from "confirmed" to "likely" in the same post. Guess I'll add another grain of salt to my pile.
 

V-Temp

Well-Known Member
Member
Joined
Jul 20, 2017
Messages
1,227
Trophies
0
Age
34
XP
1,342
Country
United States
Since this is an XAW unit, its very possible our XAJ expectations for serial do not match up, so do keep that in mind.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BigOnYa @ BigOnYa:
    I don't trust the free ones, but ipvanish I've used for couple years now, n like
  • Psionic Roshambo @ Psionic Roshambo:
    I wonder if they could get CPUs to run that hot then use the heat to power a steam turbine to power the CPUs....
  • BigOnYa @ BigOnYa:
    Good idea, or at least power the GPU
  • Psionic Roshambo @ Psionic Roshambo:
    It's not the movies or games downloads that I would worry about, like breaking into networks, downloading encrypted things, spying on network traffic. I have seen so many "Top Secret" seals on files when I was a kid
  • Psionic Roshambo @ Psionic Roshambo:
    I was obsessed with finding UFOs, a surprising amount of US files where stashed on computers in other countries, China back in the early 90s omg sooo much
  • BigOnYa @ BigOnYa:
    Yea that crazy, I've never tried hack into anything, I just pirate, and my ISP have send me 3-4 letters, so had to VPN it
  • Psionic Roshambo @ Psionic Roshambo:
    Ship to ship communication software for the Navy although without access to the encrypting chips it was mostly useless
  • Psionic Roshambo @ Psionic Roshambo:
    I bet now a 4090 could probably crack it? Hmmm maybe not even back then I'm pretty sure they where using like 1024 bit encryption
  • Psionic Roshambo @ Psionic Roshambo:
    Yayyy the one set finished 324GBs lol
  • Psionic Roshambo @ Psionic Roshambo:
    Compressed....
  • Psionic Roshambo @ Psionic Roshambo:
    I wonder how many years that would have taken on a 56K modem lol
  • Psionic Roshambo @ Psionic Roshambo:
    18000 hours lol
  • Psionic Roshambo @ Psionic Roshambo:
    750 days lol
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    So Internet is very much faster now lol
  • BigOnYa @ BigOnYa:
    "Time Remaining- 2 years, 9 girlfriends, 6 hairstyles, please standby..."
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    I remember one time I downloaded like a 500MB ISO file on 56K and that literally took like 2 days
  • Psionic Roshambo @ Psionic Roshambo:
    I had some sort of resume thing, I remember the software had chains
  • Psionic Roshambo @ Psionic Roshambo:
    Damned if I can't remember.the name though
  • Psionic Roshambo @ Psionic Roshambo:
    Some sort of download management app
  • BigOnYa @ BigOnYa:
    Ok good chatting, I'm off to the bar, to shoot some pool, nighty night.
    +1
  • BakerMan @ BakerMan:
    hey psi
  • BakerMan @ BakerMan:
    i call your girl lyndon the way she b on my johnson
    BakerMan @ BakerMan: i call your girl lyndon the way she b on my johnson