Tutorial  Updated

5.5.2 Browser with 5.5.1 vulnerability [CFW required]

WARNING: DO NOT FOLLOW THIS GUIDE IF YOU DON'T HAVE HAXCHI OR CBHC INSTALLED!
You will lose all Homebrew entry points, the browser will not be usable anymore.

This guide has been written when there was no 5.5.2 exploit. CFW DOES NOT INCLUDE MOCHA, IF YOU LAUNCH MOCHA FROM THE BROWSER!
If you are on 5.5.2 you can use one of the new Homebrew entry points, such as https://stupiid.ovh, https://u.drg.li or https://sleepii.ovh.

This guide is NOT a 5.5.2 exploit, and will not get you Homebrew on 5.5.2, this is purely for those with CBHC or Haxchi who want the old browser exploit back for any reason.

Follow this guide only if you want both cfw and a relatively stable browserhax. (This is more stable than the 5.5.2 browser hax, but doesn't matter too much because it requires Haxchi or CBHC)

Downgraded browser's with NO CFW (Haxchi or CBHC) = no more Homebrew for you! (until a new update comes out, or a new exploit that doesn't require the browser comes out.)


Important note: BEFORE doing any permanent changes to your console's internal files, you should always make sure you have a backup (Seeprom and OTP is a my best option for this guide) (AppStore). if you don't make a full NAND backup, at least do a OTP/SEEPROM dump, that will save your console if you brick the browser, as you can install Haxchi with your Seeprom and OTP. Backing up your Seeprom and OTP will NOT fix full CBHC or FTPiiU bricks (Console not booting). Not necessarily only before following this guide, it's common advice for EVERY console's hacking projects. Always read and understand all the guide before starting it.


DISCLAIMER: This guide requires file transfers via FTPiiU Everywhere. If you mess up your Wii U, I am not liable for any damage. If you follow this properly and read everything, nothing harmful should happen.

-Beginning-

Hello, this is a guide on how to downgrade your Internet Browser as to use the old browser vulnerability.
This means you will be able to use https://loadiine.ovh on 5.5.2, but first read the requirements, your Wii U might not be supported depending on what Homebrew you use.

-Requirements and warnings-

This requires CBHC, or Haxchi (you should have either Haxchi or CBHC if you're on 5.5.2, and if not you're out of luck) an FTP client, FTPiiU Everywhere, and an encrypted version of the Wii U Internet Browser, which can be gained through JNUSTool.
(WARNING, IF YOU'RE USING JUST HAXCHI, TO ACCESS THE INTERNET BROWSER IT WILL REQUIRE SIGNATURE PATCHES, MEANING YOU HAVE TO LAUNCH HAXCHI, OR MOCHA OR ANY OTHER CFW / SIGNATURE PATCHING PROGRAM EACH TIME YOU WANT TO USE THE BROWSER!)
Also, if you want this as a backup method in case CBHC fails, don't bother, dump your Seeprom and OTP instead. Doing this will make your Internet Browser unusable if CBHC fails.

-Starting-

First off, you want to go to the directory where JNUSTool.jar is and open a Command Prompt window there by putting your mouse cursor in an open area, and holding shift and right clicking. You should see an option that says "Open command window here" and you want to click it. Then paste in this command to get the Internet Browser code folder.
"java -jar JNUSTool.jar 000500301001210A v241"
It should do a long string of things in the terminal and then a window should appear.
First, select the arrow that looks like this, next to code (make sure that you don't select the checkbox next to code)
upload_2017-8-11_1-32-20.png

Scroll down until you find mvplayer.rpl, and click the arrow next to it, and then hit download.
upload_2017-8-11_1-34-4.png
It should go through it's download process, and eventually finish. Once it's finished, find the output folder which should have the name "Internet Browser [HBAE01]" open the folder, and then open the "code" folder.

-Wii U Side-

Now, head over to your Wii U, and open the Homebrew Launcher with CFW on, otherwise known as signature patches. Load FTPiiU Everywhere, and open Filezilla or whatever FTP client you use.

-FTP and the Wii U-

In the box that says "host" type the IP address displayed on your gamepad screen and select "connect" on your FTP client.
If your console region is USA, go to /storage_mlc/sys/title/00050030/1001210a/code
If your console region is EUR, go to /storage_mlc/sys/title/00050030/1001220a/code
If your console region is JPN, go to /storage_mlc/sys/title/00050030/1001200a/code
Then, copy the mvplayer.rpl file from /Internet Browser [HBAE01]/code which you opened earlier to your FTP client that's open in the directory I told you to go to. It should prompt you to overwrite another file called mvplayer.rpl, and when it does, select yes. Once the file transfer is completed, press the home button on your gamepad, and do all the necessary steps to get to the home menu.

-Final steps!-

Once you're at the home menu, power down your console (TURNING OFF YOUR WII U IS REQUIRED, DO NOT SKIP THIS STEP OR THE DOWNGRADE WILL NOT WORK), then power it on, and navigate to the Internet Browser with CFW on. Go to https://loadiine.ovh on your Internet Browser, and if it redirects you to a page saying you're on 5.5.2, go to the URL that it redirects you to, and change the "l=552" to "l=551" and hit ok. Once you've done that, launch the browser exploit as you normally would and you should be good to go.
Now, to change your Internet Browser back to 5.5.2, for whatever reason, do the same steps, but when doing the JNUSTool section, do "java -jar JNUSTool.jar 000500301001210A v258" instead.

-Thanks-

I hope you enjoyed this tutorial! It's my first one on here, so I do understand it's not very helpful for a beginner, but I'll try my best, thanks.
 

Attachments

  • upload_2017-8-10_22-59-21.png
    upload_2017-8-10_22-59-21.png
    7.5 KB · Views: 684
  • upload_2017-8-10_22-59-42.png
    upload_2017-8-10_22-59-42.png
    7.5 KB · Views: 718
  • upload_2017-8-11_1-32-4.png
    upload_2017-8-11_1-32-4.png
    413 bytes · Views: 527
  • upload_2017-8-11_1-32-6.png
    upload_2017-8-11_1-32-6.png
    413 bytes · Views: 565
Last edited by Creatable,

MousSe

Member
Newcomer
Joined
Aug 18, 2017
Messages
12
Trophies
0
Age
21
XP
134
Country
France
you can't force an update.
you are already on latest firmware version, and your browser is already on latest version too.
only one module is downgraded, not the browser, so the console will not detect that it can be updated.


your only chance to fix it is :
- hope there's a new console update (5.5.3), but it will certainly patch the 5.5.2 browser exploit. not very useful to hack the console, but useful to get browser access back.
- you did a OTP and SEEPROM dump of your console before doing anything dangerous to your NAND. in that case you can install haxchi from your computer.
- you did a full NAND dump, and you can restore it with hardware (though, if you did, you can just use OTP/SEEPROM from it, and use second option)
- wait until there's a new entry point in another app (crunchy roll? if it's not a joke since the beginning). that's probably the best you can do while staying on 5.5.2

that's all. you can't fix it in any other way (for now).


note: Formating the system will not help.
it's deleting installed eShop and savegames.
it's not deleting system app, and reinstalling them from nowhere as source. the console doesn't keep a "firmware re-installer" file.
it's also modifying your SEEPROM console's seed for encryption, you'll lose access to your USB backup savegames !!

format is not an option to fix something, it's an option to DELETE and LOSE everything from current users, for example to sell the console to ANOTHER user.
all data are lost and can't be recovered. (unless, you have SEEPROM dump to access USB on your computer)
Thanks ! :D
 

Cyan

GBATemp's lurking knight
Former Staff
Joined
Oct 27, 2002
Messages
23,749
Trophies
4
Age
45
Location
Engine room, learning
XP
15,648
Country
France
sorry that you can only wait for something new.
there is still a chance a new vulnerability can be exploited, as long as it doesn't involve the browser you will get it back.

maybe I should add to the guide that users should have a OTP/SEEPROM dump before doing any console's modification.
even if it's the basis in device (console/computer/phones/anything) hacking : have a backup to what you access, when possible.

Done.
I also linked to the proper NAND dump tool.
 
Last edited by Cyan,

MousSe

Member
Newcomer
Joined
Aug 18, 2017
Messages
12
Trophies
0
Age
21
XP
134
Country
France
sorry that you can only wait for something new.
there is still a chance a new vulnerability can be exploited, as long as it doesn't involve the browser you will get it back.

maybe I should add to the guide that users should have a OTP/SEEPROM dump before doing any console's modification.
even if it's the basis in device (console/computer/phones/anything) hacking : have a backup to what you access, when possible.

Done.
I also linked to the proper NAND dump tool.
I need a homebrew access to dump my nand ?
 

Cyan

GBATemp's lurking knight
Former Staff
Joined
Oct 27, 2002
Messages
23,749
Trophies
4
Age
45
Location
Engine room, learning
XP
15,648
Country
France
and how would you load that fw.img if you can't access homebrew launcher to launch firmware reloader ? :(
you can't load anything that involve homebrew channel from browser exploit.

as long as there's no new browser version released, or a new exploit not using the browser, you can't do anything. sorry.
 

MousSe

Member
Newcomer
Joined
Aug 18, 2017
Messages
12
Trophies
0
Age
21
XP
134
Country
France
and how would you load that fw.img if you can't access homebrew launcher to launch firmware reloader ? :(
you can't load anything that involve homebrew channel from browser exploit.

as long as there's no new browser version released, or a new exploit not using the browser, you can't do anything. sorry.
I just want to know if O ca get the seeprom with this file and not load it.
 

Creatable

Well-Known Member
OP
Member
Joined
Jul 10, 2017
Messages
585
Trophies
0
Location
(insert wacky and amusing place here)
Website
hentaihaven.net
XP
1,623
Country
United States
I try before this message appear... I ask help NOW !

--------------------- MERGED ---------------------------


I can do that but the save can't be used after the operation. But I don't know if saves are compatible with the save owner. I'm going to try if crunchyhax is not release.
I know this thread might be dead, but I just wanna get in the fact that there was always a warning since the beginning. I guess it wasn't visible enough. I also had the die comparison because I just needed something compelling to get the readers attention. Anyways, French guy, I had the warning from the beginning and it was never removed, so I guess either Google translate wasn't working properly (as per usual) or you just skimmed over the guide. Every single detail in it, pointless seeming or not, is there for a reason. The warning, the fact that you have to turn off the console after you do the file transfer, things like that may seem unimportant, but they are what make this work. Please read guides better next time.
 
Last edited by Creatable,

MousSe

Member
Newcomer
Joined
Aug 18, 2017
Messages
12
Trophies
0
Age
21
XP
134
Country
France
I know this thread might be dead, but I just wanna get in the fact that there was always a warning since the beginning. I guess it wasn't visible enough. I also had the die comparison because I just needed something compelling to get the readers attention. Anyways, French guy, I had the warning from the beginning and it was never removed, so I guess either Google translate wasn't working properly (as per usual) or you just skimmed over the guide. Every single detail in it, pointless seeming or not, is there for a reason. The warning, the fact that you have to turn off the console after you do the file transfer, things like that may seem unimportant, but they are what make this work. Please read guides better next time.
I don't why I Ask to you but there is a way to dump otp/seeprom with the homebrew Channel (vWii) ?
 

Alvyssy

Member
Newcomer
Joined
Aug 17, 2017
Messages
21
Trophies
0
Age
22
XP
173
Country
Italy
I'm so sorry that I caused all of this problems only for my ignorance. It's funny because even in my life every time I make an irreversible mistake only after I see the consequences of not taking the right precautions. In fact I bricked my wii u browser, guess what new tools come out? Now you can inject wii games onto your wii u menu furthermore you can play all of them with your gamepad, and that would have fixed all my vWii problem since I bricked that too. I REALLY hope for another wii u update, like the last one(please make it real) or at least if someone is good enough to make a custom server that can send updates to consoles every time so that can fix brick problems, but I think that Nintendo gave its last shot with 5.5.2.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Veho @ Veho: Le youtube face.