First usermode exploit and more: Nintendo Switch 2 had a busy (hacking) week for its launch

wololo

Finger on the pulse of the PlayStation hacking scene since 2006

23 Responses

  1. Golephish says:

    Make it cost less

    • Vertigon100YouTube says:

      I have a link for an ESP32-S2 setup that on top of replacing a popular self hosted exploit for pOOBs4 9.00 also has a Linux internal distro and initramfs and bzImage working for my belize2A0 CUH-7016B and I can launch ps4_linux_4gb_pro.bin from the web browser’s index2.html as ps4.local/index.html hosts the auto exfatHAX process with the latest GoldHEN available.
      If Wololo allows it, I will follow-up with a reply.
      It’s cheaper I guess…
      And more available also…
      I plan to upload video usage guide on my channel. It’s small TBH but it will eventually grow I guess…

    • nub says:

      get a better job

  2. c0de90e7 says:

    ROP only and you are able to map or access the framebuffer and draw a xor pattern ? WOW, not an easy one, that ROP chain must be biggg

    • Sc0rp10 says:

      You have no idea how much understanding how difficult this is means. I’m tired of people assuming ROP chains are simplistic or basic. Sometimes a lot can be done with the right libs.

  3. Noworriescunt says:

    Just wanted to correct the point about the MIG Flash cart – the actual manufacturers of the device (migflash.com) have made no such claims about Switch 2 compatibility. It’s one of their official resellers – MigFlashStore (themigflash.store) – who made the false claims and owns the Twitter handle @MigSwitch.

    • John smith says:

      Yeah this is a big one Wololo. Please correct asap – and add a statement explaining the misunderstanding and correction.

      I usually refer to this site as a very trustful source of factual hacking information – but this article just adds to the confusion by spreading misinformation around migswitch, rather than correcting the already circulating misinformation.

  4. MetaMetal says:

    It’s always great to see these kind of things but I don’t know if I want to hack (when available) my switch 2.

  5. Qwalvis says:

    I think the non-native part is because it’s ROP, not because it’s userland.

  6. Jokerwolf says:

    Can’t wait until the system is cracked open so we can get us some emulation going. The translation layer for Switch 1 games could be the holy grail for native PC ports down the road.

  7. Jason says:

    Hey wololo, according to your experience, how much would you say it would take to run backups on Switch 2? As usual there’s people implying that’s gonna be soon because they achieved this on day 1.

  8. r0y says:

    ROP is not machine code. Usermode ROP is not usermode native code.

  9. Ninty says:

    Migflash never claimed support for the Switch 2. The official Migflash website is Migflash.net, not Migflash.store. The @MigFlash twitter account is ran by the latter, which is a known scammer.

  10. ViRGE says:

    I always thought it interesting that there was relatively little (public) use of user-mode hacks on the Switch. The RCM exploit really blew things open, but even once Nintendo fixed that, the field largely switched over to mod chips and the MIG.

    I’m not sure if that’s indicative of a weak, easily-compromised hardware design, or a strong OS. Horizon OS is pretty locked down in terms of enabled features.

  11. TotallyEthical says:

    If one has a launch Switch 2 and given the initial day 1 patch is apparently very important, should one get this day 1 patch and then leave it be, or just leave in the box as is, without any patches whatsoever, if the intention is to run CFW (if that ever happens)?

  12. John says:

    Nintendo shaking down its customers i hope it gets hacked

  13. lollypop says:

    first usermode linux … does anybody know this library for this lib linking dev ???
    ../shared/image-loader.c: In function ‘load_jpeg_icc’:
    ../shared/image-loader.c:163:14: error: implicit declaration of function ‘jpeg_read_icc_profile’ [-Wimplicit-function-declaration]
    163 | if (!jpeg_read_icc_profile(cinfo, &profdata, &proflen)) {
    | ^~~~~~~~~~~~~~~~~~~~~

  14. V says:

    Since this article hasn’t been updated, the official migswitch website posted that the tweet was demoing an in-house beta firmware. Which I thought was obvious but I guess not. As of yesterday said firmware is released to the general public for use playing switch 1 games on Switch 2. Though I cannot personally confirm if it works or not.

  15. I wish you beat other outlets to a story we saw a million times since it happened

    And now the mig is banning consoles it’s a shame that these articles come out late with a lack of passion and that gba temp is more active

  16. Lollypop says:

    Ish-psvita runs the alpine iso downloader and unpacks alpine iso to run alpine cmd for psvita

  17. dacore says:

    Is there nothing happening in the hacking scene anymore or is this site just dead? :/