PegaSwitch: Exploit Toolkit for Nintendo Switch
pegaswitch.com
pegaswitch.com
Quickly looking over the code I think you use a slightly different way to achieve the r/w than qwerty - you don't misalign a pointer, correct? Can you give a short description how you do it?
I wondered how to not crash the switch when done, and you seem to simply set everything to 0 `this.bufs[i] = 0;` and that solves that issue. Could you say a few words on why that is the case?
Any information yet you want to share about the execution environment? Is there some kind of sandbox? Anything interesting you can already access, or surprisingly not access?
Edit: One more question. Did you guys get to play any BotW yet? :D
I really love the overengineering of this toolkit <3
EDIT: Found the comment, https://news.ycombinator.com/item?id=13675898
In terms of not crashing, it really comes down to appeasing the garbage collector. If there are non-object-objects on the heap (e.g. raw pointers just sitting there), the GC will explode and the whole thing crashes. So we take great care to ensure that only real JS objects exist at any point, outside of a few critical paths (which only last a few ms at worst). This leads to an insanely stable exploit base.
We're not really talking much about the execution environment yet, but what we can say is that it's really an upgraded (potentially rewritten?) 3DS OS.
I understand that console hackers are notoriously secretive, but what are your plan(s) in the short and long term? Fostering the eventual homebrew community? Improving upon the OS? etc.
In terms of our plans, it's pretty simple: learn more about the system, escalate privileges where we can, and eventually be able to run our own code.
Personally, I really want Linux running. With the things we know now, we'll almost certainly have Linux as soon as the kernel is under our control.
It would most likely be much easier to accomplish once we have full access to the system, and hopefully could be branched out much more than what the 3DS does.
"We'd like to thank the amazing rockstars at Google and Apple for making WebKit what it is today and following through on their mission to provide millions of people access to otherwise restricting environments. Without your lack of hard work and due diligence, WebKit would be a tied down, secure enclave that would not allow for consumers to exercise their constitutional rights."
First and foremost: Of the devs that are following along this thread, who has spent the most time playing BOTW? Real question.
Another one: Why do you think Nintendo failed learn their lesson the first and second times?
In terms of failing to learn their lesson, I think that it actually remains to be seen, to an extent. They failed by including an old WebKit bug, but the bigger failure was outsourcing their browser code in whole; that makes patching things so, so much harder. We'll see how bad the other layers are, but we've barely scratched the surface there.
I noticed on the share applet, there is a JavaScript object: window.nx that exposes some internal functions. However, I have had no luck actually calling those functions. If you want to know more about this, I can show you how I execute JavaScript on it and give you a list of window.nx functions
That said, I know there are a couple JS projects aiming to build a kind of 'debugger' into the web applets; might help them to know what you know!
I'm interested to learn more about this. Not for any practical use (well, maybe hacked Pokémon), but just to understand the choice. I naively figured this would be locked-down Android, but it's neat to see that it's FreeBSD + something.
We're not talking much about details of the lower levels yet (frankly, we just don't know enough to confidently do so, even if we wanted to put it all out there), but it's almost certainly a fork or (partial?) rewrite.
My 6-year-old son accidentally threw away his event Munchlax in Pokemon Sun, which led me down the path of installing a full custom firmware on my 3DS and using PokeHex to restore the event card and get Munchlax back. He went from depressed to ecstatic. Now we can both have saves on our Pokemon games and he loves to show me how to get past gyms and other stuff. Great bonding experience.
A little bit further down this path, it's been amazing to be able to play classics like Super Mario Sunshine with real GameCube controllers and updated 4K textures via Dolphin. It looks like a brand new game, and again, my son loves hearing about how I played through it 15 years ago on the original GameCube. We just went on a short trip and we were able to play Super Smash Brothers Brawl on my laptop during the flight.
These experiences really underscore the power and importance of hacking communities. I'd love to see modifications to the legal structures to keep emulation, hacking, and modding communities out of the legal grey area and allow them to more fully flesh out their products. Their work is a vastly understated boon to our cultural heritage, and it allows it to be enjoyed and improved for generations. These people are heroes. The way we treat them is a shame.
Open source is critical for the success of projects like Dolphin, but what do you think the emulator developers of the future are going to do when they see the cash they can earn by being secretive?
[1]: cemu.info
Having a pile of people running the Wii U version of Breath of the Wild on their gaming PCs will do it too:
https://www.youtube.com/watch?v=Pmf0xA6aVM4
I hadn't been keeping up with CEMU progress, but looking at the 1.7.3 progress preview video, it's damn impressive.
I'm looking forward to a world where systems have workable emulators within several months of release, not several years. That will only bring the legal issues into more stark relief. So few of us realize that our intellectual property regime is holding back a lot of major accessibility and practicality improvements.
We need to fix it. Amazing projects like CEMU should not have to live in fear that someone is going to squash them and cause a lot of real harm just to protect someone else's bottom line.
And looking it up on the net didn't improve things... My second gaming console was an 8-bit nintendo...
I'm one of the primary developers for PKHeX -- hacking Pokémon is a very practical use of time as far as I'm concerned.
2. I understand that "future use" includes shiny, 6IV Arceus clones.
I can't speak for others, but I have no intention of enabling piracy in any way; I just want Linux on it. Others will most likely abuse this for piracy at some point, which I personally find sad, but I don't control others.
Whether the details are published by the developers of the exploit themselves or by a 3rd party, it's frustrating to see the hubris of proving one's ability to explain the exploit winning out over actually helping the users hold onto the ability to root for as long as possible.
EDIT: Clarification, a few others already gave exploit code to use the Pegasus webkit exploit, and it's been going around the "news" sites. We just gave a prettier/easier to use implementation now that it was obvious Nintendo already saw it.
Additionally, this isn't a root, nor is it even close. This is the first stepping stone to be used by researchers to get deeper into the Switch and find new bugs. In no way will this impede the homebrew community; it will only serve to empower it.
It's really Nintendo's fault for shipping an insecure version of Webkit.
Of course it's not about practical reasons, since if you really need it, you can just get a normal Tegra based hardware without locks.