From 64af89cf300252019e3afd973d63102b2998af38 Mon Sep 17 00:00:00 2001 From: halbg0tt Date: Wed, 8 Jul 2026 14:53:37 +0200 Subject: [PATCH] first commit --- blog.txt | 41 ++++++++++++ blog/iridium.txt | 161 +++++++++++++++++++++++++++++++++++++++++++++ blog/switch_hb.txt | 132 +++++++++++++++++++++++++++++++++++++ index.txt | 58 ++++++++++++++++ 4 files changed, 392 insertions(+) create mode 100755 blog.txt create mode 100755 blog/iridium.txt create mode 100755 blog/switch_hb.txt create mode 100755 index.txt diff --git a/blog.txt b/blog.txt new file mode 100755 index 0000000..ee52d97 --- /dev/null +++ b/blog.txt @@ -0,0 +1,41 @@ +ASCII Art +====================================================================== + . . . . . . . + . . . . . ______ + . . . //////// + . . ________ . . ///////// . . + . |.____. /\ .///////// . + . .// \/ |\ ///////// + . . .// \ | \ ///////// . . . + ||. . .| | ///////// . . + . . || | |//`,///// . + . \\ ./ // / \/ . + . \\.___./ //\` ' ,_\ . . + . . \ //////\ , / \ . . + . ///////// \| ' | . + . . ///////// . \ _ / . + ///////// . + . .///////// . . + . -------- . .. . + . . . . . + ________________________ +____________------------ -------------_________ + + +BLOGS +====================================================================== + +I wrote some blogs and how-to's about some stuff which i found +interesting and i post it here e.g. Iridium or Switch Hacking. + + +TOPIC | LOCATION +====================================================================== +Iridium | [ 0x74.org/blog/iridium.txt ] +Switch Hacking | [ 0x74.org/blog/switch_hb.txt ] + + + +FOOTER - [ LESS IS MORE ] +====================================================================== + diff --git a/blog/iridium.txt b/blog/iridium.txt new file mode 100755 index 0000000..5a70f8f --- /dev/null +++ b/blog/iridium.txt @@ -0,0 +1,161 @@ +My BLOG where i explain iridium (How i understand it). +DATE: 30/10/2025 (DD:MM:YYYY) +AUTHOR: halbg0tt +PROCESS: [ W.I.P ] +============================== + +WHAT EVEN IS IRIDIUM? +============================== +Iridium is a constellation of many Satellites(66 Satellites) in a low earth orbit (LEO) +and are primary used for telecommunication such as SMS or Voice Calls. +The Benefit of using Iridium is the fact that: Iridium satellites are in a Low Earth Orbit +and passing over both poles. +It has a higher b/s than for example Inmarsat and the fact that inmarsat doesnt cover the both poles. +There are many iridium satellites in orbit so you have basically at least 1-2 satellites that cover your area. +You dont need a Cell tower near you because you satellite phone communicates directly with the satellite. +So you can establish a connection between you and iridium basically everywhere on the whole earth. + +WHAT CAN TX IRIDIUM? +============================== +Iridium has many of services and not only SMS/VC. +Its transmit other services like for example ACARS or Pagers. +ACARS is basically telecommunication for pilot's and groundstation over satellite. + +DIAGRAM: +[GROUND STATION] <-> [ IRIDIUM ] <-> [ AIR CRAFT ]. + +You can also connect to websites but it takes a longer to load since the connections are ~700 kbps +But it should work to recv e.g. emails. + +SOME TECHNICAL INFOS: +============================== +FREQ: 1616 - 1626 MHz. +MODULATION: GMSK. +ORBIT: Low-Earth Orbit (LEO) not like Inmarsat (GEO). +SATELLITES: 66 currently +SERVICES: SMS, VOICE CALLS, ACARS, PAGER, Short Burst Data (SBD) Ring Alert Channel (RAC) + +[ Sources ] +https://github.com/muccc/iridium-toolkit +https://www.iridium.com/services/iridium-sbd/ + + +WHAT WE CAN DO WITH IRIDIUM? +============================== +We can (legality is another question) decode Data packages from the iridium +by using for example the gr-iridium and iridium-toolkit + +1.[ GR-IRIDUM ] +============================= +gr-iridium includes the iridium-extractor which receives(Actually the SDR) the data from The +Satellite and demodulate it. +There also configs for diff SDRs such as BladeRF, HackRF, LimeSDR or RTL SDR(i dont recommend it). + + +CMD: [ iridium-extractor -D 4 /path/to/conf > ~/output.bits ] +NOTE: the configs for various sdrs are located in ~/gr-iridium/examples/ + +The iridium-extractor write the recv content into the output.bits file +Looks like this: p-1472473197 000001626.1625 1621698688 100% -59.2|-116.2|21.7 179 DL +The Data what you can see here (lemme break it down for you): [Source is btw iridium-toolkit FORMAT.md] + + CONTENT | MEANING +===================================================================================================== +- [ p-1472473197 ] | represent the time in UNIX-Format [ The prefix is always "p-{UNIX TIME}" ] +- [ 000001626.1625 ] | Time in milliseconds inside the recording +- [ 1621698688 ] | This is the Frequency in Hz +- [ 100% ] | Basically the Signal Quality +- [ -59.2|-116.2|21.7 ] | The Signal level in dBFS (decibels relative to full scale) +- [ 179 ] | The length in symbols where 1 symbol represent 2 bits +- [ DL ] | This is basically is this Uplink (UL) or Downlink (DL). So is it sended from satellite to ground(modem or phone) (Downlink) + | or from ground(modem or phone) to satellite (Uplink) + +2. [ IRIDIUM-TOOLKIT ] +============================= +You can now use the iridium-toolkit where you have various tools. +the most important tool is iridium-parser.py. iridium-parser.py is a parser which convert it into useful data +After that you COULD(legality questionable(not allowed like every other decoding)) +decode the data from the iridium satellite which includes ACARS, SMS, VOICE CALLS, PAGERS, BURSTS, RING ALERTs. + +CMD: [ iridium-parser.py -p ~/output.bits] +NOTE: Add the iridium-toolkit path to your $PATH. CMD: [ export PATH:"$PATH:/path/to/iridium-toolkit" ] + It add the tools directly to your path while its needed for VOD/VOC decryption using tnt's AMBE Decoder ( An Audio Codec which is used by e.g. Inmarsat or Iridium). + +2.2 [ VOICE DECODING ] +============================= +As i mentioned before you CAN decode Voice Calls which is going from the iridium satellite. +The iridium satellite is using the AMBE Codec and we can use a AMBE Decoder +to actually decode the voice calls and listen to it. + +[ AMBE Decoder: https://gitea.osmocom.org/satellite/osmo-ir77 ] + +Move it to the root of your iridium-toolkit. The play-iridium-ambe just need this Decoder +to decode the voice transmission. If you use stats-voc.py then you can select captured +voice frames and listen to it. + + +2.3 [ REASSEMBLER.py ] +============================= +REASSEMBLER.py is used for "reconstruct" the data from the parsed output in a "higher level". +it contains for example + +args | meaning +===================================================================================================== +- ida | outputs L3 msgs in hex +- idapp | literally ida but in pretty and a bit of parsing +- lap | LAP is GSM-Compatible L3 messages which you can convert to GSMtap .pcap and it has + | mostly the same like Call Ctrl [0x03], LUR, ID-R, ...[0x05], [0x09] and Non Call Related SS MSG [0x0b]. + | Iridium has also custom codes like call [0x06], SBD [0x76] and is currently unknown service [0x08]. +- sbd | short burst data msgs +- page | ring alert channel +- msg | pager messages (confusing) +- burst | "Global Data Burst" assembled from pager messages +- livemap | create/update a sats.json for interactive satellite display +- satmap | it tries to map the iridium satellites IDs to "NORAD-Approved Names" +- acars | parsed ACARS SBD msgs + + +2.3 [ MODE: IDA ] +============================= +IDA is output the messages in hex from the Um Layer 3. +IDAPP does the same but with parsing and pretty output/printing. +You will see pretty much the same content as in the pcap. + +CMD: [ reassembler.py -m idapp ] + +2.4 [ MODE: LAP ] +============================= +Now we take a look on LAP. +LAP are basically GSM-Compatible L3 Messages and from the behavior the same. +There the same Mobility MGMT MSGs (MM) such as Location Update Request(LUR), Identity Request(ID-R), TMSI Realloc etc... +My favourite and interesting part is the proto Desc 0x09 (as mentioned earlier SMS). +In this Data Packet you will not only see the SMS or so... No, will also see: + +Few interesting items from an imaginary packet: +- Sender TEL Number : [49]162xxxxxxx [ For me in Germany would it be the country code +49 ] +- Receiver TEL Number: [8816]xxxxxxx + NOTE: The Sender or Receiver either 8816(Iridium code) or a natural phone number [as example 49162123456 in germany] +- The Timestamp of the message. For example [04/20/1971, 04:20 P.M.]. +- The actual content of the message. Like text ("Hello, how are you today?") or unicode (such as a emoji). + +CMD: [ reassembler.py -i .parsed -m lap -o .pcap ] + +2.5 [ MODE: SBD ] +============================= +Short Burst Data (SBD) is basically a quick and short data transmission in limited size of 370 Byteand its used for telemetry and +data exchanges between origin and destination e.g. of Oil rigs or pipelines. + + +2.6 [ MODE: ACARS ] +============================= +ACARS is Datalink between ground station/or satellite and the aircraft. +ACARS is transmitting telemetry or status of the aircraft or process of e.g. boarding or refueling. + + +Hardware i use (in an imaginary scenario): +- LimeSDR USB (Type-A) / RSP1a. +- RHCP Antenna from RTL-SDR Blog. +- Just Linux (Debian) + + +DISCLAIMER: Im not responsible for any law breaks. This is education only. Do not decode any data that are not for you. diff --git a/blog/switch_hb.txt b/blog/switch_hb.txt new file mode 100755 index 0000000..57a2bdc --- /dev/null +++ b/blog/switch_hb.txt @@ -0,0 +1,132 @@ +How to homebrew a switch lulz +DATE: 2025-10-30 +Author: halbg0tt +==================================================== + + +1. what the fuck is homebrew? +===================================================== +So homebrew's are basically programs that written by +third-party developers and sideloading it on the switch. +Thats are Homebrew programs. + +Actually the real meaning (my opinion) of Homebrew is: +its basically like a jailbreak. You just get somehow +access to the console itself and youre able to give the +console other instruction how it behave and youre able +to run like .dol(wii, gamecube), .nro (switch) or .nds (nds). + +For example: On the switch rev 1 you had/have a hardware vuln. +It was the Tegra X1 Exploit (secure boot) where is was +possible to intercept the boot process and you were able +to give the BootROM different instruction and load for example +hekate(bootloader). + +Nintendo released a new rev of (HAC-001) and patched the vuln. +And newer switch models like oled or lite are not hackable +with the bootROM exploit cuz it was fixed with the new board +rev. + + +2. what are the options to homebrew a switch? +===================================================== +if you have a switch rev 1. (You need to have a special S/N) +Where the bootROM is existant. +If you have a newer rev, oled or lite and skills in soldering +then you could solder a mod chip into the switch which basically +doing the same thing. Its literally a RP2040. + + +3.1 how to homebrew you switch rev 1. +===================================================== +its basically very easy. +You just need: +- SD Card (FAT32) +- Bootloader +- e.g. TegraRCMLoader and a OTG or directly RCM Loader. +- paperclip or jig (basically the same) to short the + pin 1 and 10 on the right joycon side of the switch +- Laptop. +- firmware (e.g. Atmosphere, ReiNX or SXOS). There many + forks of Atmosphere like DeepSea (packed with HB's) + + +3.2 prepare sd card. +===================================================== +move the downloaded firmware to the +root of you sd coard. +the content should be(/): +[ hbmenu.nro, atmosphere/, bootloader/ ] + +You could also add a payload/ folder for payloads +like fusee.bin + +3.3 prepare injection. +===================================================== +download for windows a TegraRCM Loader for +payload injection. +or just use a RCM Loader(if available). + + +3.4 inject and load the firmware. +===================================================== +Short pin 10 and GND(PIN 1) and keep it in this position. +Press and hold PWR ON and VOL+ on the Switch and if the +screen keeps black then you should be in the RCM or +your battery is empty. + +And at TegraRCM you can choose you +payload (either hekate or directly fusee.bin). + +and inject it. or just put a rcm loader at the USB-C Port. + +depending which Payload you injected you should be in +the bootloader or booting atmosphere with fusee.bin. + + +3.5 press on the album on the home screen. +===================================================== +And it should open the hbmenu.nro from the / +of your sd card. + + +3.6 homebrews programs. +===================================================== +You should see nothing hbmenu if you dont have any +apps installed. + +The homebrews are located on the / of you sd card +in switch/ (if not created, create it). + +You download homebrews or directly the +homebrew store (requires internet) + +Few cool homebrews: +- HBStore +- Tinfoil +- Goldleaf +- FTPD +- choidujournx + + +INFO: +If you connect to the Nintendo Server the chance +is very high that youre receive a ban for going +online with homebrewed switch. + +You have 2 options: +1. You use just Atmosphere + and stay offline and additional + you change you dns to 90DNS. +- Primary DNS: 163.172.141.219 (EU) +- Second DNS : 207.246.121.77 (EU) + +90DNS: [ https://switch.hacks.guide/extras/blocking_nintendo.html ] + +2. You could use emuNAND to have both. +- 1 Partition for Stock FW. +- 1 Partition for Atmosphere. + + +Disclaimer: Im not responsible for any breaks of law. its for education purpuse only. So do it at your own risk + diff --git a/index.txt b/index.txt new file mode 100755 index 0000000..cf314b8 --- /dev/null +++ b/index.txt @@ -0,0 +1,58 @@ +ASCII ART +============================================================= + + ____________ + ___/ ___________\ + / ___/ _____ + / / (____ \ +| | A B O U T \ \ +| | 0x74.org ) ) + \ \__ __/ / __ + \__ \_____________/ __/ ___/ \ + \_______________/ ___/ \_ + ___/ \ + ___/ __/ \ + ___/ __ \__/\ \ + ___/ __/ _\ ___/| + ____/ __ \ / ___/ _ ( + / \ /_ \ ___/ _ \\ | + |\ __ \ / ___/ _ \\ _H_/ + | \/ \ \/ ___/ _ \\ _H_/ Y + |`| _/ ___/ _ \\ _H_/ Y ! 0x74.org. + \|_|\ ___/ _ \\ _H_/ Y ! ! + ! | \_/ _ \\ _H_/ Y ! ! + ! \` | \\ _H_/ Y ! ! + \`| _H_/ Y ! ! + \|_/ Y ! ! + ! ! + ! + + +ABOUT 0x74.org // halbg0tt +============================================================== +Hello, i'm halbg0tt, + + +SOME STUFF I DO +============================================================== +- signal intelligence from ground and sat signals w/ sdr +- researching and modding on consoles +- using bash, go and c +- working with nix +- running a homelab +- i like *bsd too + +CONTACT +============================================================== +Discord: +- Username : halbg0tt +IRC(libera): +- Username : halbg0tt + +Other sites you can visit +============================================================== +[BLOG] https://0x74.org/blog + + +FOOTER - [ LESS IS MORE ] +==============================================================