r/switch2hacks • • 4d ago

Hacking Discussion Hacking Methods Suggestion

I have been trying a few things and doing some research. Here are my top 3 most likely ideas.

  1. CPU shock at a very specific time and voltage.

  2. The switch 2 uses Webkit 613.0, it has a zero day RCE / Arbitrary code execution. (CVE-2022-32893 and CVE-2022-32863) But then again, why would Nintendo use a bugged Webkit from 2022?

  3. Direct memory access from the SD Express port. This one is kind of a stretch. But I mean, maybe?

18 Upvotes

24 comments sorted by

28

u/Ncolonslashslash 4d ago

"trying a few things"? what have you been trying

6

u/StrangeBaseball5772 4d ago

Mostly with the album. I have no clue if it will work, but I mean you never know. This is a big if. But if you can break the parser for the captures you theoretically could hide arm64 assembly code inside them.

5

u/iLiikePlayingWii 1d ago

it literally won't work since the switch signs the pictures and videos, this is why you can't play custom videos/pics unless you literally do smth like use a hacked switch and take the clips/screenshots using a media player. like... no.

And Nintendo already had album exploits in the DSi, they've patched the fuck out pf album exploits

3

u/StrangeBaseball5772 1d ago

I 100% have gotten custom screenshots on my switch 2. There is a specific portion of the metadata signed. You can copy that portion and location.

1

u/iLiikePlayingWii 1d ago

Ohhh okay... but Videos though? I have heard of custom screenshot but not custom videos

And have you gotten said screenshots to be 1080p ones and not the crappy 720p ones from Switch 1 software ?

2

u/Badzieta 15h ago

No you won't, DEP is something that's been a thing for over 2 years. Unless driver maps files as executables (it doesn't lol) you're not executing data region.

2

u/oirolab 4d ago

Bruh, it's been over a year since release. You REALLY think this all hasn't been tried yet?

-1

u/Healthy_Sail_1802 4d ago

Had you tried to talk with Gezine to understand what he already tried and doesn't work?

He found a userland exploit too but I doubt in that regard he will talk about it

28

u/DrinkWater-2L 4d ago

Voltage trick => dual core lockstep.

DMA is gonna blocked by IOMMU.

Webkit => Sandbox.

2

u/Melsbacksfriend 1d ago

Your comment is very accurate. Number 1 is definitely the most viable although even that would be difficult as you'd need two identical, synchronized glitches. I am actually in the process of saving up for the parts and tools necessary for that. It'll take a long time as I work a part-time minimum wage job.

4

u/Melsbacksfriend 1d ago

2 and 3 definitely not. 1 could work, but you'd need two synchronized, identical glitches to prevent the DCLS from catching it. I've actually been slowly saving up for the parts and tools necessary to attempt option 1.

2

u/spydrthrowaway 3d ago

Witcher 3 remastered has mod support on switch 2. You think that could be a possible vector for exploiting the switch 2 🤔

3

u/HierKommt_Alex 1d ago

Every App on the switch/2 is sandboxed with 0 access to lower level Environments

1

u/spydrthrowaway 1d ago

Good info. Thanks for explaining 💯

1

u/nmkd 23h ago

meh, we already have a userland exploit

1

u/Zestyclose_Track_443 1d ago

literally anything that's jailed when it comes to having webkit exploits

1

u/nmkd 23h ago

CPU shock at a very specific time and voltage.

Gee, how has no one else thought of this? /s

1

u/Anxiety_timmy 21h ago

For 1.

Lmao

  1. Doesn't matter, webkit cant escalate into kernel

  2. No. Same reason as 2.

1

u/KoopsterShell 2d ago

Dude just hack it using a tool

1

u/Clean-Supermarket-80 1d ago

just ask gpt6 to hack it duhhh

2

u/iLiikePlayingWii 1d ago

I actually wonder if that'll work since other models hacked actual companies and some Vibecoders apparently found PS5 Hypervisor exploits with AI

2

u/Clean-Supermarket-80 1d ago edited 1d ago

it was mainly a joke, my coment that is, they put a lot of guardrails. They would have to use opensource jailbroken local AI models to dig in. There are ways to get around it, I went a few days trying to tell the AI that i wanted to watch movies on the switch2 because i was going on a trip , and we spent days debugging the video gallery portion on how to get "me to watch my movies" and then I convinced it to try via a browser and i slowly had it build a local dns server and track every packet and start running scripts to dump all webkit stuff to get to the login screen, which was hard because it asks to update before it presents you the login screen, then I found a way to only alow a test domain it uses to check internet connectivity and get past that update prompt but then it wouldnt show the credentials screen etc. And it did find some stuff but Im not smart enough to waste weeks on this and get somewhere useful so I stopped. I dont have a good enough pc to run local models, i just tried gpt6 and tricked it to try and hack into the switch because " i wanted to watch movies on it."

1

u/Icy_Mode8773 3h ago edited 3h ago

hay if you have given up on that i would be happy to continue the project and see how far i can get