Team Xecuter reveal info on upcoming Switch modchip

SwitchTX.jpg

Just over a week ago, team Xecuter announced that they are working on a soon-to-be-revealed modchip for the Nintendo Switch. This was big news because modchip devices are usually used to circumvent anti-piracy measures on many digital platforms, but mainly gaming systems, and to see one already in the works for a machine that is only 10 months old is very rare.

Since then the team have been quiet, no one knows what the device will look like, how it will work, or when they can get their hands on one - but GBAtemp can exclusively reveal today that there will be BOTH a solder AND solderless option of team Xecuter's Nintendo Switch modchip.

Here is a direct quote from team Xecuter:

For now, I can tell you there is a solder and solderless version. We have quite a lot in the works, you will have more info soon.


The difference in pricing should be interesting in the two versions of the device, but at least you can now rest safely, knowing that the team will be providing options for whatever the Xecuter Switch modchip turns out to be.

Stay tuned to GBAtemp for more info in the upcoming weeks.
 

Attachments

  • nintendo-switch.jpg
    nintendo-switch.jpg
    8.3 KB · Views: 179

Onibi

Well-Known Member
Member
Joined
Mar 3, 2018
Messages
153
Trophies
0
Age
39
XP
156
Country
Germany
The bootrom vuln is in the USB RCM part of the bootrom. You can trigger it with the right hardware.
For the glitching, you don't really need USB. Glitching exploits a way to skip the RSA sig check so it will run any bootloader you put on eMMC.

You don't need the 'bootrom keys' to communicate with USB. If you put the Switch into USB RCM mode, it will tell you its UID. Is that not USB comms then and there?

Hey, interresting, thank you, where you got the information from? :)

About the glitching - I though so. Probably harder to pull off then the other way. I mean, I would be happy with a clamp-on eMMC programmer and a chip that could glitch in (even better also calculate ^_^) the signature ...

But if there is a neat way to trigger the RCM, coolio, even better :) That should allow you to permanently flash a new bootrom as well thou, no? You think this is what's going on in the video and what TX is gonna do? That would be nice to have solution :O A neat little cable to just plug in :D

--------------------- MERGED ---------------------------

If you don't believe me read what Nvidia themselves say about the matter: https://http.download.nvidia.com/tegra-public-appnotes/tegra-boot-flow.html
  • If no valid bootloader could be found, enters USB recovery mode (RCM).
Just read this - that would be too easy ... ^__^
 
Last edited by Onibi,

brickmii82

Well-Known Member
Member
Joined
Feb 21, 2015
Messages
1,442
Trophies
1
Age
41
XP
2,930
Country
United States
It feels like both the PS3 and Xbox360 prepared these folks to hack this thing. Xbox had the efuses and PS3 had the recovery mode lol
 

Onibi

Well-Known Member
Member
Joined
Mar 3, 2018
Messages
153
Trophies
0
Age
39
XP
156
Country
Germany
You don't need the 'bootrom keys' to communicate with USB. If you put the Switch into USB RCM mode, it will tell you its UID. Is that not USB comms then and there?

https://http.download.nvidia.com/tegra-public-appnotes/tegra-boot-flow.html
  • The Tegra SoC supports various security modes. Some of these modes require the BCT, bootloader, and/or RCM protocol messages to be encrypted and/or signed with a potentially device-specific key.
I assume you need a key, but that it is either flawed or can be leaked? I mean, I don't think they left that open.
 

mariogamer

Well-Known Member
Member
Joined
Aug 12, 2015
Messages
1,256
Trophies
0
Age
28
XP
790
Country
Canada

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Xdqwerty @ Xdqwerty:
    good night
  • Sicklyboy @ Sicklyboy:
    sup nerds
    +1
  • BigOnYa @ BigOnYa:
    Sup dawg, watching old rap vids so feel like I gotta talk...Real
  • BigOnYa @ BigOnYa:
    Not really just funny. I'm definitely a nerd!
  • ShinyLuxio @ ShinyLuxio:
    Hi there, it's any way to recover original LFCS if I don't have a NAND backup?
  • ShinyLuxio @ ShinyLuxio:
    Bought second hand 3DS, it seems it was "unbanned" but that was before I bought it
  • K3Nv2 @ K3Nv2:
    I got these in today for $20 stink buds they aren't that bad https://a.co/d/fOMSn8g
    +1
  • ShinyLuxio @ ShinyLuxio:
    @BigOnYa thanks but my question isn't there
  • BigOnYa @ BigOnYa:
    You ask your questions there, create a new thread if its not already answered, then eventually a 3ds genius will respond.
  • ShinyLuxio @ ShinyLuxio:
    I will, thanks
    +1
  • BigOnYa @ BigOnYa:
    No prob and btw, welcome to gbatemp! :grog:
  • BigOnYa @ BigOnYa:
    @K3Nv2 I got some cheapies at wallys, that are pretty good, already have lost a few expensive ones (one falls out and gone, can't find) while cutting grass so bought some cheap ones, and of course never lose these cheap ones. (Cheap meaning only $35, compared to air buds which I only have 1 of 2 now)
  • BigOnYa @ BigOnYa:
    They need to add air tags to they airbuds..
  • The Real Jdbye @ The Real Jdbye:
    @BigOnYa the airtags are bigger than the airpods, they won't fit
    +1
  • BigOnYa @ BigOnYa:
    Be cool tech tho. Of course they want to lose them anyways. Buy and buy again.
  • K3Nv2 @ K3Nv2:
    Apple could make a find my AirPods thing pretty easily
    +1
  • BigOnYa @ BigOnYa:
    You would think, esp using bluetooth, not GPS, like a "your getting hot-er" meter on your phone.
  • BigOnYa @ BigOnYa:
    I think they should tie up diddy, and let all the victims come and abuse him, we'll make a holiday of it every year. (jk, maybe)
  • BigOnYa @ BigOnYa:
    I'm starting to sound like a Tck Gonna cut myself off.
  • K3Nv2 @ K3Nv2:
    It's not 4th of July yet
  • Veho @ Veho:
    It is in India.
    Veho @ Veho: It is in India.