Hacking Firmware Reverse Engineering (Info Dump)

steelseth

Well-Known Member
Member
Joined
Jan 25, 2016
Messages
180
Trophies
0
Age
42
XP
773
Country
Cyprus
I've never seen NWPlayer go off about piracy. Some other ones though... Your post is both off topic, and trash.

Side note: Nice to see devs looking for a more crowd sourced approach in the general public, hopefully smarter people than I can help get this documented out faster. I'll continue to poke around, and as discussion grows, I'll probably get a better idea of where to poke around.
My post wasnt directed to NW but to all devs. But anything against our beloved devs is trash.
It would be nice to see all those opposing piracy to let us know of their views.
The only non hypocritical thing to do is either buy the software for the developers or demand everything to shut down.

EDIT: They should also stop using all homebrew that was a result of piracy.
 
Last edited by steelseth,
  • Like
Reactions: Subtle Demise

Antonio Ricardo

Well-Known Member
Member
Joined
Apr 29, 2013
Messages
359
Trophies
0
Age
38
Location
Rio de Janeiro
XP
502
Country
Brazil
Last edited by Antonio Ricardo,

pwsincd

Garage Flower
Developer
Joined
Dec 4, 2011
Messages
3,686
Trophies
2
Location
Manchester UK
XP
4,482
Yes, @Datalogger was working on IDA for a long time but we dont know the work progress. Ryan was working too.
Create your own firmware AKA CFW/Emunand. Is a risk people knowing how to do but we need more progress.

no i know DL's progress , as i know where its documented , as does nwplayer .. question was specific.
 
  • Like
Reactions: brienj

ARVI80

Well-Known Member
Member
Joined
Feb 25, 2016
Messages
197
Trophies
0
Age
43
Location
UK
XP
315
Country
Please correct me if I'm wrong but looking at the wii u boot chain for launching titles there are 4 steps, 2 of the 4 steps are images that can contain data with audio wich is allowed according to the devkit. The nand can be instructed by the title launch parameters, including from the meta tags, to not disable anything on boot and also disable any checks. A master ROM can be created and called via the title launcher as long as it matches the console info.

On another note I think it's slightly insulting to developers when people talk about boot loaders for piracy simply because it's probably the easiest task to accomplish. The hard work needed to build a platform for homebrew is where the challenge lies and what keeps devs going. To simply hack and console for piracy is a bore and many devs would rather move on. If only people could understand that concept.
 

ryuutseku85

Well-Known Member
Member
Joined
Dec 14, 2015
Messages
110
Trophies
0
Age
39
XP
416
Country
France
As I look inside the kernel , I can tell that we need to expand rom adress at the end to 0xFFFFFFF ( at 1 F near ) there is some "Dword " at the end .

Mw , just a little question , I know how to get the magic happening in arm with the f5 magic touch , but it's not working on the ppc . Any advice ?

Get my head on fw kernel and myqteriU ... do I have a life ? That the best question .

Pswincd : don't talk to loud you gonna wake up the kids lol .
 
Last edited by ryuutseku85,

pwsincd

Garage Flower
Developer
Joined
Dec 4, 2011
Messages
3,686
Trophies
2
Location
Manchester UK
XP
4,482
As I look inside the kernel , I can tell that we need to expand rom adress at the end to 0xFFFFFFF ( at 1 F near ) there is some "Dword " at the end .

Mw , just a little question , I know how to get the magic happening in arm with the f5 magic touch , but it's not working on the ppc . Any advice ?

Get my head on fw kernel and myqteriU ... do I have a life ? That the best question .

Pswincd : don't talk to loud you gonna wake up the kids lol .
Well it might wake others lol
 
  • Like
Reactions: ryuutseku85

NWPlayer123

Well-Known Member
OP
Member
Joined
Feb 17, 2012
Messages
2,642
Trophies
0
Location
The Everfree Forest
XP
6,693
Country
United States
Mw , just a little question , I know how to get the magic happening in arm with the f5 magic touch , but it's not working on the ppc . Any advice ?
That's just it, the Hex Rays Decompiler doesn't support PPC :< if it did my life would be at least 4 times easier
@NWPlayer123 I was trying to decompile the Espresso kernel image but in IDA in processor options it asks for TOC adress, SDA (r13) Adress and MNIO base. I have no idea on what's wrong
Just put in 0xFFFFFFFF, mine fills it in automatically
 

z0mb3

Member
Newcomer
Joined
Jan 3, 2016
Messages
18
Trophies
0
XP
137
Country
Australia
Let me estimate you got a decrypted binary file with readable text and call it decryptedbin.out.
And you want to create an elf file (decryptedbin.elf). Then use DevkitPPC executable ...

powerpc-eabi-objcopy -I binary -O elf32-powerpc -B powerpc --change-addresses=0xffe00000 --set-section-flags .data=code decryptedbin.out decryptedbin.elf

IDA likes those elf files. ;)
 
Last edited by z0mb3,
  • Like
Reactions: NWPlayer123

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    Psionic Roshambo @ Psionic Roshambo: @BigOnYa, FarCry 5 is an awesome game with multiple endings!