How on earth was Super Mario Odyssey decrypted and dumped? by simonmkwii at 10:49 AM EST on January 19, 2018
This has been baffling me for the past week!

I managed to get the xci cartridge dump for Super Mario Odyssey, and I have been asking around on ways to decrypt and extract the files and have come out empty handed!

All I know is that I need a way to extract the RomFS from the XCI, and then I need a body key to decrypt the contents.

How would I decrypt it and where would I get this key?
by Mr.Sanic at 11:23 AM EST on January 19, 2018
try to search for "Nintendo Switch Decryption Key"

it's almost the same with the Wii U,both uses that key encryption
by simonmkwii at 11:30 AM EST on January 19, 2018
I can't find the key anywhere whatsoever.

Even if I did find the key, what program would I use to decrypt and dump the files?
by mariofan12ify at 11:34 AM EST on January 19, 2018
I would recommend using RomFS Explorer:
http://gbatemp.net/threads/tools-romfs-explorer.478249/
by simonmkwii at 11:54 AM EST on January 19, 2018
That's for .istorage files.

I need something to decrypt and extract .xci files.
by bxaimc at 2:11 PM EST on January 19, 2018
It’s a secret ;)

But. The main part is the dump has to be decrypted by the console itself. Not on a PC. So all of the scene releases that are encrypted are useless right now. Same story when we first started ripping 3DS games. Everything had to be hardware decrypted first.

edited 2:13 PM EST January 19, 2018
by simonmkwii at 6:29 PM EST on January 19, 2018
Hi, bxaimc!

Would you be willing to share the dumped files?

Words couldn't express how much that would mean to me!

I would die for those files!
by bxaimc at 7:18 PM EST on January 19, 2018
I’m sorry, I only had the audio since that’s all I really cared about. Everything else didn’t seem useful to me =/

edited 7:21 PM EST January 19, 2018
by RebeccaSugar at 10:53 PM EST on January 19, 2018
Damn it!! Now how ELSE are we supposed to make SFM cappy porn!?
by Excalibur624 at 9:09 AM EST on January 20, 2018
Get someone to make an accurate Cappy model of course!
by Infomaniac95 at 2:55 PM EST on January 20, 2018
I would kill for those audio files! Any chance you could upload them?
by bxaimc at 3:07 PM EST on January 20, 2018
Music is already uploaded on joshw, everything else has been purged.
by Franpa at 11:00 AM EST on January 21, 2018
It is? I don't see a hyperlink to Switch music dumps...

edited 12:21 PM EST January 21, 2018
by TheUltimateKoopa at 12:03 PM EST on January 21, 2018
Am I the only one who's aware of vgm.hcs64.com?
by Franpa at 12:22 PM EST on January 21, 2018
He specifically mentioned JoshW so I assume he meant this topic: https://hcs64.com/mboard/forum.php?showthread=26929
by bxaimc at 1:01 PM EST on January 21, 2018
@everyone vgm.hcs64.com is a frontend for xxx.joshw.info
by Franpa at 8:57 AM EST on January 22, 2018
Oh, okay.
by simonmkwii at 10:28 PM EST on January 24, 2018
I'm bumping this thread due to the release of ncatool!
Second bump. by simonmkwii at 9:32 PM EST on February 4, 2018
Some assets from the game have been added to The VG resource, which proves the game is dumpable and decryptable.

Now all I need is someone to admit what method and software was used to do it.

SALT ALERT: I will not be accepting "it's a secret" or "it's a private method" as a response.
by bxaimc at 10:08 PM EST on February 4, 2018
It’s not a secret. You just need right the knowledge and tools. The documentation is available and the resources are there. ALL FIRMWARES ARE EXPLOITABLE if you know how to do it. Dump the game on 1.0.0, get the keys from a 3.0.whatever console or whatever firmware is needed, decrypt on PC. Rinse and repeat. Just like SciresM said, it’s called patience dude. That’s why you got banned from ReSwitched’s discord server after probing way too much and admitting to piracy in front of them despite being warned multiple times and eventually kick banned. I don’t appreciate you rolling up in here demanding things from people like you’re hot stuff. You don’t make the rules around here.

edited 10:24 PM EST February 4, 2018
by Segtendo at 10:35 PM EST on February 4, 2018
Simon. You don't deserve anything, judging from that tone. You want the dumps? Do what bxaimc said. Learn the documentation. Grab the tools. Dump the files.

Right now, you sound super entitled to everything.
by soneek at 11:08 PM EST on February 4, 2018
@Simon it's easy. Hang your Switch like a piñata with the game you wanna dump files from loaded. Then you whack it with a USB-C charging cable until it dumps every file.

It could take a while and is life threatening due to exhaustion and overwork, so that's why it's been secret for a while.
by simonmkwii at 12:21 AM EST on February 5, 2018
Apologies to everyone:

Sorry about my passive-aggressive tone, it was a poor decision and a poor choice of words.

It wasn't my intention to offend anyone.

-----

I managed to use SciresM's hactool to dump the encrypted nca's.

I read through the documentation on switchbrew.org, but i'm still not completely clear.

My main question is what method do I use to retrieve the decryption keys from my Switch?

Would it be easier via a software or hardware method?

If software, what firmware, and what exploit and utility should I use to access it?

If hardware, what would be necessary?
by boop snoot at 2:42 PM EST on February 5, 2018
@simonmkwii

Super Mario Odyssey is a 3.0.1 title. There are currently no public ways to get at the keys for 3.0.1 crypto. Effectively, you would need a bootrom exploit to dump your Secure Boot Key and tsec key to get the package1 and master keys.

For the 1.0.0-2.3.0 keys, you could use Team Xecutor's key to decrypt package1.1 and package2/TrustZone and then use the leaked 1.0 master key to get the actual NCA keys.

See also http://switchbrew.org/index.php?title=Cryptosystem
by 54634564 at 5:56 PM EST on February 5, 2018
simon don't bother, you're not going to get anywhere currently. SciresM dumped Odyssey and provided the files to various people so they could have the audio/models/whatever. Just be happy we have anything from it, tbh.

edited 5:57 PM EST February 5, 2018
by RebeccaSugar at 10:35 PM EST on February 5, 2018
"Hang your Switch like a piñata with the game you wanna dump files from loaded. Then you whack it with a USB-C charging cable until it dumps every file."

THIS WORKS!!!! HOLY SHIT, I'M MAKING A YOUTUBE VIDEO, BUT I AM NOT GIVING YOU CREDIT. MY IDEA, MINE!
by NintenComet at 11:44 PM EST on February 7, 2018
@Simon If you want the decrypted files, use the tools. If you want to understand how the tools work, look at the source code. In order to create these tools, one must have an in-depth understanding of computer technology and hardware security. Exploiting firmware isn't something you can learn from a single forum post.
by simonmkwii at 11:36 PM EST on February 8, 2018
All I need now is a method to extract the keys from my Switch!

I have read through all the SwitchBrew documentation thoroughly.

There's not exactly a written method on how to to get the keys per se, but I think I figured out a way to extract them on 3.0.2.

Unfortunately, my Switch is on 4.1.0.

Is there any known way to pwn TrustZone and extract the keys on 4.1.0?

If not, could someone on 3.0.1 or 3.0.2 attempt to extract the keys? I will be eternally grateful!

At this rate, I'm hoping BigBlueBox leaks them!
by Hater at 7:53 AM EST on February 10, 2018
I don't understand why you're all hatin' so much on SIMON
by TheUltimateKoopa at 11:01 AM EST on February 10, 2018
Exactly. It's not his fault. He probably didn't hang his Switch high enough, or maybe he didn't whack it with the USB-C charging cable hard enough.
by NintenComet at 3:03 PM EST on February 10, 2018
The known TrustZone security flaws were fixed in 2.0.0. So unfortunately, you can't exploit TrustZone unless a new flaw gets discovered.
by simonmkwii at 10:23 PM EST on February 18, 2018
Update:

I know exactly how to do it!

I will have to wait for the 4.1.0 TZ exploit's release though...
by Hiccup at 6:21 AM EST on February 19, 2018
Please explain.


Go to Page 0

Search this thread

Show all threads

Reply to this thread:

User Name Tags:

bold: [b]bold[/b]
italics: [i]italics[/i]
emphasis: [em]emphasis[/em]
underline: [u]underline[/u]
small: [small]small[/small]
Link: [url=http://www.google.com]Link[/url]

[img=https://www.hcs64.com/images/mm1.png]
Password
Subject
Message

HCS Forum Index
Halley's Comet Software
forum source