branfont Posted April 24, 2018 Share Posted April 24, 2018 A newly published "exploit chain" for Nvidia Tegra X1-based systems seems to describe an apparently unpatchable method for running arbitrary code on all currently available Nintendo Switch consoles. Hardware hacker Katherine Temkin and the hacking team at ReSwitched released an extensive outline of what they're calling the Fusée Gelée coldboot vulnerability earlier today, alongside a proof-of-concept payload that can be used on the Switch. "Fusée Gelée isn't a perfect, 'holy grail' exploit—though in some cases it can be pretty damned close," Temkin writes in an accompanying FAQ. The exploit, as outlined, makes use of a vulnerability inherent in the Tegra X1's USB recovery mode, circumventing the lock-out operations that would usually protect the chip's crucial bootROM. By sending a bad "length" argument to an improperly coded USB control procedure at the right point, the user can force the system to "request up to 65,535 bytes per control request." That data easily overflows a crucial direct memory access (DMA) buffer in the bootROM, in turn allowing data to be copied into the protected application stack and giving the attacker the ability to run arbitrary code. On the Switch, the hardest part of the exploit seems to be forcing the system into USB recovery mode. To do this without opening the system requires shorting out a certain pin on the right Joy-Con connector (the bit on the side of the system where the Joy-Con clicks into place). The hacking team at Fail0verflow tweeted a picture of a small plug-in device that can apparently provide this short-out easily, and the team joked that a simple piece of wire from the hardware store can do so today. Temkin also tweeted a picture suggesting that simply exposing and bending the pin in question would also work. Full article@ Ars Technica Link to comment https://www.neowin.net/forum/topic/1362154-the-unpatchable-exploit-that-makes-every-current-nintendo-switch-hackable/ Share on other sites More sharing options...
DrunknMunky Veteran Posted April 24, 2018 Veteran Share Posted April 24, 2018 Hopefully this doesn't kill software releases and sales à la NDS / PSP Nintendo has been working on a new SoC for a few months now though; presumably because they were notified of the exploit, so if you want one of these exploit capable Switches buy one soon. Link to comment https://www.neowin.net/forum/topic/1362154-the-unpatchable-exploit-that-makes-every-current-nintendo-switch-hackable/#findComment-598249210 Share on other sites More sharing options...
Vandalsquad Posted May 9, 2018 Share Posted May 9, 2018 I assume this has been blown wide open now? I'm seeing entire switch rom library dumps happening on private torrent sites. Not that I've looked into what's happening as this progresses much at the moment. Link to comment https://www.neowin.net/forum/topic/1362154-the-unpatchable-exploit-that-makes-every-current-nintendo-switch-hackable/#findComment-598261514 Share on other sites More sharing options...
+Warwagon MVC Posted May 9, 2018 MVC Share Posted May 9, 2018 So you are saying now would be a great time to buy a switch. DConnell 1 Share Link to comment https://www.neowin.net/forum/topic/1362154-the-unpatchable-exploit-that-makes-every-current-nintendo-switch-hackable/#findComment-598261532 Share on other sites More sharing options...
DKAngel Posted May 9, 2018 Share Posted May 9, 2018 cant do much with it until home brew is actually written for it, but all current models are exploitable until they do a hardware revision Link to comment https://www.neowin.net/forum/topic/1362154-the-unpatchable-exploit-that-makes-every-current-nintendo-switch-hackable/#findComment-598261548 Share on other sites More sharing options...
DrunknMunky Veteran Posted May 23, 2018 Veteran Share Posted May 23, 2018 Nintendo Bans Online Services For Prominent Hacker's Switch Console Unlike previous consoles, Nintendo is also banning modders from accessing the eShop on the Switch. Link to comment https://www.neowin.net/forum/topic/1362154-the-unpatchable-exploit-that-makes-every-current-nintendo-switch-hackable/#findComment-598271146 Share on other sites More sharing options...
Recommended Posts