first commit

This commit is contained in:
2026-07-08 14:53:37 +02:00
commit 64af89cf30
4 changed files with 392 additions and 0 deletions
Executable
+41
View File
@@ -0,0 +1,41 @@
ASCII Art
======================================================================
. . . . . . .
. . . . . ______
. . . ////////
. . ________ . . ///////// . .
. |.____. /\ .///////// .
. .// \/ |\ /////////
. . .// \ | \ ///////// . . .
||. . .| | ///////// . .
. . || | |//`,///// .
. \\ ./ // / \/ .
. \\.___./ //\` ' ,_\ . .
. . \ //////\ , / \ . .
. ///////// \| ' | .
. . ///////// . \ _ / .
///////// .
. .///////// . .
. -------- . .. .
. . . . .
________________________
____________------------ -------------_________
BLOGS
======================================================================
I wrote some blogs and how-to's about some stuff which i found
interesting and i post it here e.g. Iridium or Switch Hacking.
TOPIC | LOCATION
======================================================================
Iridium | [ 0x74.org/blog/iridium.txt ]
Switch Hacking | [ 0x74.org/blog/switch_hb.txt ]
FOOTER - [ LESS IS MORE ]
======================================================================
+161
View File
@@ -0,0 +1,161 @@
My BLOG where i explain iridium (How i understand it).
DATE: 30/10/2025 (DD:MM:YYYY)
AUTHOR: halbg0tt
PROCESS: [ W.I.P ]
==============================
WHAT EVEN IS IRIDIUM?
==============================
Iridium is a constellation of many Satellites(66 Satellites) in a low earth orbit (LEO)
and are primary used for telecommunication such as SMS or Voice Calls.
The Benefit of using Iridium is the fact that: Iridium satellites are in a Low Earth Orbit
and passing over both poles.
It has a higher b/s than for example Inmarsat and the fact that inmarsat doesnt cover the both poles.
There are many iridium satellites in orbit so you have basically at least 1-2 satellites that cover your area.
You dont need a Cell tower near you because you satellite phone communicates directly with the satellite.
So you can establish a connection between you and iridium basically everywhere on the whole earth.
WHAT CAN TX IRIDIUM?
==============================
Iridium has many of services and not only SMS/VC.
Its transmit other services like for example ACARS or Pagers.
ACARS is basically telecommunication for pilot's and groundstation over satellite.
DIAGRAM:
[GROUND STATION] <-> [ IRIDIUM ] <-> [ AIR CRAFT ].
You can also connect to websites but it takes a longer to load since the connections are ~700 kbps
But it should work to recv e.g. emails.
SOME TECHNICAL INFOS:
==============================
FREQ: 1616 - 1626 MHz.
MODULATION: GMSK.
ORBIT: Low-Earth Orbit (LEO) not like Inmarsat (GEO).
SATELLITES: 66 currently
SERVICES: SMS, VOICE CALLS, ACARS, PAGER, Short Burst Data (SBD) Ring Alert Channel (RAC)
[ Sources ]
https://github.com/muccc/iridium-toolkit
https://www.iridium.com/services/iridium-sbd/
WHAT WE CAN DO WITH IRIDIUM?
==============================
We can (legality is another question) decode Data packages from the iridium
by using for example the gr-iridium and iridium-toolkit
1.[ GR-IRIDUM ]
=============================
gr-iridium includes the iridium-extractor which receives(Actually the SDR) the data from The
Satellite and demodulate it.
There also configs for diff SDRs such as BladeRF, HackRF, LimeSDR or RTL SDR(i dont recommend it).
CMD: [ iridium-extractor -D 4 /path/to/conf > ~/output.bits ]
NOTE: the configs for various sdrs are located in ~/gr-iridium/examples/
The iridium-extractor write the recv content into the output.bits file
Looks like this: p-1472473197 000001626.1625 1621698688 100% -59.2|-116.2|21.7 179 DL
The Data what you can see here (lemme break it down for you): [Source is btw iridium-toolkit FORMAT.md]
CONTENT | MEANING
=====================================================================================================
- [ p-1472473197 ] | represent the time in UNIX-Format [ The prefix is always "p-{UNIX TIME}" ]
- [ 000001626.1625 ] | Time in milliseconds inside the recording
- [ 1621698688 ] | This is the Frequency in Hz
- [ 100% ] | Basically the Signal Quality
- [ -59.2|-116.2|21.7 ] | The Signal level in dBFS (decibels relative to full scale)
- [ 179 ] | The length in symbols where 1 symbol represent 2 bits
- [ DL ] | This is basically is this Uplink (UL) or Downlink (DL). So is it sended from satellite to ground(modem or phone) (Downlink)
| or from ground(modem or phone) to satellite (Uplink)
2. [ IRIDIUM-TOOLKIT ]
=============================
You can now use the iridium-toolkit where you have various tools.
the most important tool is iridium-parser.py. iridium-parser.py is a parser which convert it into useful data
After that you COULD(legality questionable(not allowed like every other decoding))
decode the data from the iridium satellite which includes ACARS, SMS, VOICE CALLS, PAGERS, BURSTS, RING ALERTs.
CMD: [ iridium-parser.py -p ~/output.bits]
NOTE: Add the iridium-toolkit path to your $PATH. CMD: [ export PATH:"$PATH:/path/to/iridium-toolkit" ]
It add the tools directly to your path while its needed for VOD/VOC decryption using tnt's AMBE Decoder ( An Audio Codec which is used by e.g. Inmarsat or Iridium).
2.2 [ VOICE DECODING ]
=============================
As i mentioned before you CAN decode Voice Calls which is going from the iridium satellite.
The iridium satellite is using the AMBE Codec and we can use a AMBE Decoder
to actually decode the voice calls and listen to it.
[ AMBE Decoder: https://gitea.osmocom.org/satellite/osmo-ir77 ]
Move it to the root of your iridium-toolkit. The play-iridium-ambe just need this Decoder
to decode the voice transmission. If you use stats-voc.py then you can select captured
voice frames and listen to it.
2.3 [ REASSEMBLER.py ]
=============================
REASSEMBLER.py is used for "reconstruct" the data from the parsed output in a "higher level".
it contains for example
args | meaning
=====================================================================================================
- ida | outputs L3 msgs in hex
- idapp | literally ida but in pretty and a bit of parsing
- lap | LAP is GSM-Compatible L3 messages which you can convert to GSMtap .pcap and it has
| mostly the same like Call Ctrl [0x03], LUR, ID-R, ...[0x05], [0x09] and Non Call Related SS MSG [0x0b].
| Iridium has also custom codes like call [0x06], SBD [0x76] and is currently unknown service [0x08].
- sbd | short burst data msgs
- page | ring alert channel
- msg | pager messages (confusing)
- burst | "Global Data Burst" assembled from pager messages
- livemap | create/update a sats.json for interactive satellite display
- satmap | it tries to map the iridium satellites IDs to "NORAD-Approved Names"
- acars | parsed ACARS SBD msgs
2.3 [ MODE: IDA ]
=============================
IDA is output the messages in hex from the Um Layer 3.
IDAPP does the same but with parsing and pretty output/printing.
You will see pretty much the same content as in the pcap.
CMD: [ reassembler.py -m idapp <your parsed file> ]
2.4 [ MODE: LAP ]
=============================
Now we take a look on LAP.
LAP are basically GSM-Compatible L3 Messages and from the behavior the same.
There the same Mobility MGMT MSGs (MM) such as Location Update Request(LUR), Identity Request(ID-R), TMSI Realloc etc...
My favourite and interesting part is the proto Desc 0x09 (as mentioned earlier SMS).
In this Data Packet you will not only see the SMS or so... No, will also see:
Few interesting items from an imaginary packet:
- Sender TEL Number : [49]162xxxxxxx [ For me in Germany would it be the country code +49 ]
- Receiver TEL Number: [8816]xxxxxxx
NOTE: The Sender or Receiver either 8816(Iridium code) or a natural phone number [as example 49162123456 in germany]
- The Timestamp of the message. For example [04/20/1971, 04:20 P.M.].
- The actual content of the message. Like text ("Hello, how are you today?") or unicode (such as a emoji).
CMD: [ reassembler.py -i <output>.parsed -m lap -o <output>.pcap ]
2.5 [ MODE: SBD ]
=============================
Short Burst Data (SBD) is basically a quick and short data transmission in limited size of 370 Byteand its used for telemetry and
data exchanges between origin and destination e.g. of Oil rigs or pipelines.
2.6 [ MODE: ACARS ]
=============================
ACARS is Datalink between ground station/or satellite and the aircraft.
ACARS is transmitting telemetry or status of the aircraft or process of e.g. boarding or refueling.
Hardware i use (in an imaginary scenario):
- LimeSDR USB (Type-A) / RSP1a.
- RHCP Antenna from RTL-SDR Blog.
- Just Linux (Debian)
DISCLAIMER: Im not responsible for any law breaks. This is education only. Do not decode any data that are not for you.
+132
View File
@@ -0,0 +1,132 @@
How to homebrew a switch lulz
DATE: 2025-10-30
Author: halbg0tt
====================================================
1. what the fuck is homebrew?
=====================================================
So homebrew's are basically programs that written by
third-party developers and sideloading it on the switch.
Thats are Homebrew programs.
Actually the real meaning (my opinion) of Homebrew is:
its basically like a jailbreak. You just get somehow
access to the console itself and youre able to give the
console other instruction how it behave and youre able
to run like .dol(wii, gamecube), .nro (switch) or .nds (nds).
For example: On the switch rev 1 you had/have a hardware vuln.
It was the Tegra X1 Exploit (secure boot) where is was
possible to intercept the boot process and you were able
to give the BootROM different instruction and load for example
hekate(bootloader).
Nintendo released a new rev of (HAC-001) and patched the vuln.
And newer switch models like oled or lite are not hackable
with the bootROM exploit cuz it was fixed with the new board
rev.
2. what are the options to homebrew a switch?
=====================================================
if you have a switch rev 1. (You need to have a special S/N)
Where the bootROM is existant.
If you have a newer rev, oled or lite and skills in soldering
then you could solder a mod chip into the switch which basically
doing the same thing. Its literally a RP2040.
3.1 how to homebrew you switch rev 1.
=====================================================
its basically very easy.
You just need:
- SD Card (FAT32)
- Bootloader
- e.g. TegraRCMLoader and a OTG or directly RCM Loader.
- paperclip or jig (basically the same) to short the
pin 1 and 10 on the right joycon side of the switch
- Laptop.
- firmware (e.g. Atmosphere, ReiNX or SXOS). There many
forks of Atmosphere like DeepSea (packed with HB's)
3.2 prepare sd card.
=====================================================
move the downloaded firmware to the
root of you sd coard.
the content should be(/):
[ hbmenu.nro, atmosphere/, bootloader/ ]
You could also add a payload/ folder for payloads
like fusee.bin
3.3 prepare injection.
=====================================================
download for windows a TegraRCM Loader for
payload injection.
or just use a RCM Loader(if available).
3.4 inject and load the firmware.
=====================================================
Short pin 10 and GND(PIN 1) and keep it in this position.
Press and hold PWR ON and VOL+ on the Switch and if the
screen keeps black then you should be in the RCM or
your battery is empty.
And at TegraRCM you can choose you
payload (either hekate or directly fusee.bin).
and inject it. or just put a rcm loader at the USB-C Port.
depending which Payload you injected you should be in
the bootloader or booting atmosphere with fusee.bin.
3.5 press on the album on the home screen.
=====================================================
And it should open the hbmenu.nro from the /
of your sd card.
3.6 homebrews programs.
=====================================================
You should see nothing hbmenu if you dont have any
apps installed.
The homebrews are located on the / of you sd card
in switch/ (if not created, create it).
You download homebrews or directly the
homebrew store (requires internet)
Few cool homebrews:
- HBStore
- Tinfoil
- Goldleaf
- FTPD
- choidujournx
INFO:
If you connect to the Nintendo Server the chance
is very high that youre receive a ban for going
online with homebrewed switch.
You have 2 options:
1. You use just Atmosphere
and stay offline and additional
you change you dns to 90DNS.
- Primary DNS: 163.172.141.219 (EU)
- Second DNS : 207.246.121.77 (EU)
90DNS: [ https://switch.hacks.guide/extras/blocking_nintendo.html ]
2. You could use emuNAND to have both.
- 1 Partition for Stock FW.
- 1 Partition for Atmosphere.
Disclaimer: Im not responsible for any breaks of law. its for education purpuse only. So do it at your own risk
Executable
+58
View File
@@ -0,0 +1,58 @@
ASCII ART
=============================================================
____________
___/ ___________\
/ ___/ _____
/ / (____ \
| | A B O U T \ \
| | 0x74.org ) )
\ \__ __/ / __
\__ \_____________/ __/ ___/ \
\_______________/ ___/ \_
___/ \
___/ __/ \
___/ __ \__/\ \
___/ __/ _\ ___/|
____/ __ \ / ___/ _ (
/ \ /_ \ ___/ _ \\ |
|\ __ \ / ___/ _ \\ _H_/
| \/ \ \/ ___/ _ \\ _H_/ Y
|`| _/ ___/ _ \\ _H_/ Y ! 0x74.org.
\|_|\ ___/ _ \\ _H_/ Y ! !
! | \_/ _ \\ _H_/ Y ! !
! \` | \\ _H_/ Y ! !
\`| _H_/ Y ! !
\|_/ Y ! !
! !
!
ABOUT 0x74.org // halbg0tt
==============================================================
Hello, i'm halbg0tt,
SOME STUFF I DO
==============================================================
- signal intelligence from ground and sat signals w/ sdr
- researching and modding on consoles
- using bash, go and c
- working with nix
- running a homelab
- i like *bsd too
CONTACT
==============================================================
Discord:
- Username : halbg0tt
IRC(libera):
- Username : halbg0tt
Other sites you can visit
==============================================================
[BLOG] https://0x74.org/blog
FOOTER - [ LESS IS MORE ]
==============================================================