Hacking Awesome WiiU hacking theories!

Cyan

GBATemp's lurking knight
Former Staff
Joined
Oct 27, 2002
Messages
23,749
Trophies
4
Age
45
Location
Engine room, learning
XP
15,650
Country
France

SifJar

Not a pirate
Member
Joined
Apr 4, 2009
Messages
6,022
Trophies
0
Website
Visit site
XP
1,175
Country
If you want, you can download the titles with NUS Downloader. The encryption key is different though, so you can't unpack them yet or otherwise do anything meaningful. We're probably going to have to wait until either someone dumps them in decrypted form off a vWii, or until we know what the key is.

My guess would be that they are still encrypted with the same key as the Wii (otherwise, the key for the WiiMode would be different, and Wii games wouldn't work), but then re-encrypted with a WiiU key. These things are installed from the WiiU side of things, not directly in WiiMode right? So the WiiU would decrypt it's layer and then pass it on to the WiiMode to install.

But of course, that's just a guess. I'm sure far more knowledgeable individuals will unravel the secrets soon enough.
 

Arras

Well-Known Member
Member
Joined
Sep 14, 2010
Messages
6,318
Trophies
2
XP
5,413
Country
Netherlands
The WiiU has two wlan modules and one is dedicated for the gamepad.
Yeah, I think I read something to that effect in a quick teardown. A separate 802.11n for the pad. What I do not know is how this affects it's ability to be used on a PC. Does that mean it's possible with normal wireless cards as long as they are not currently being used (so no laptops currently using Wifi)? As long as someone actually takes the time to write drivers, of course (which will probably take a pretty long time).
 

mumitroll

Active Member
Newcomer
Joined
Feb 23, 2012
Messages
43
Trophies
0
XP
200
Country
Gambia, The
I was so free to create a wiiubrew logo for the wiki - hope u like it ^^;
 

Attachments

  • wiiubrew.png
    wiiubrew.png
    6.2 KB · Views: 222
  • Like
Reactions: Fear Zoa

techboy

Well-Known Member
Member
Joined
Mar 15, 2009
Messages
1,720
Trophies
0
Age
31
Location
Pennsylvania
Website
Visit site
XP
306
Country
United States
HCVA = Return to WiiU
HCUx = Wii menu Manual

http://wiiubrew.org/wiki/Title_database
That answers that. When I checked that site yesterday, there weren't any pages besides the front page and a bunch of "To be populated".

Where's that "Wii System Transfer" channel come from though, built into the menu? I wonder how it'd behave if that were installed onto a Wii and then used. I suspect it'd either crash or spit out an error, but it'd be interesting to try nonetheless.

A syscheck log of a vWii would be interesting, but IIRC the app needs extra rights.

My guess would be that they are still encrypted with the same key as the Wii (otherwise, the key for the WiiMode would be different, and Wii games wouldn't work), but then re-encrypted with a WiiU key. These things are installed from the WiiU side of things, not directly in WiiMode right? So the WiiU would decrypt it's layer and then pass it on to the WiiMode to install.
If that's the case, we'll be better off extracting them once the vWii is hacked, at least until in-roads are made on the Wii U side.

That brings up another question...will AHBPROT still work on a vWii to get "Direct sandbox access"? I'm thinking not, since there was no legitimate use for it on a Wii outside the factory.
 

flouri

Active Member
Newcomer
Joined
Jan 6, 2009
Messages
31
Trophies
1
XP
173
Country
United States
what if it's possible for a movable (from wii to wii U) channel to be hacked/created from a versatile-proven Wii to take advantage of a loophole on the Wii U when it is copied during the moving process?
 

techboy

Well-Known Member
Member
Joined
Mar 15, 2009
Messages
1,720
Trophies
0
Age
31
Location
Pennsylvania
Website
Visit site
XP
306
Country
United States
what if it's possible for a movable (from wii to wii U) channel to be hacked/created from a versatile-proven Wii to take advantage of a loophole on the Wii U when it is copied during the moving process?
The Wii U transfer app validates titles before moving them. If you modify the channel in an effort to pack something funny inside, the signature becomes invalid. The transfer app won't even try to move it if it's been messed with.
 

RocketRobz

Stylish TWiLight Hero
Developer
Joined
Oct 1, 2010
Messages
16,614
Trophies
3
Age
24
XP
21,032
Country
United States
Anybody try stack smash yet? Also, even if we find an exploit that works, I'm guessing we will need a new version of the HackMii installer just like we have for the last two or three Wii updates. The most interesting thing at this point we be to see if they somehow segregated the NAND, or if the Wii mode could dump the whole thing.
Smash Stack DOES work on Wii U.
 

Supercool330

Well-Known Member
Member
Joined
Sep 28, 2008
Messages
752
Trophies
1
XP
1,129
Country
United States
Has anybody tried to use Smash Stack to launch Casper to launch BootMii to launch the Hackmii Installer (MINI version) to install the HBC? As soon as I find an SD card that works I will give this a shot.
 

Cyan

GBATemp's lurking knight
Former Staff
Joined
Oct 27, 2002
Messages
23,749
Trophies
4
Age
45
Location
Engine room, learning
XP
15,650
Country
France
What about Riivolution ? Someone tested it? It doesn't require ahbprot from HBC (I already used it with HBC1.0.6)
It's using official IOS 37 (though, depending how riivolution is working, it may need a rebuild, to match new ios folder's name, or new IOS version)

Maybe it need to decrypt/resign it, in which case it will not work.
(I don't know enough about Riivolution internals, I'm just wondering which homebrew are working or not).
 

Supercool330

Well-Known Member
Member
Joined
Sep 28, 2008
Messages
752
Trophies
1
XP
1,129
Country
United States
The real roadblock is that the IOS exploit that the Hackmii installer was using is blocked. From what I understand, Riivolution and Casper use a different IOS exploit (the same one apparently). Unfortunately the plan I posted above won't work as the Wii U has no reset button (Marcan's joke wasn't totally wrong). The real question is if Riivolution or Casper will launch at all. If they do, then we will at least know that the IOS exploit they use is still present. Fortunately, I'm a moron sometimes, and I forgot that MINI jus loads the PPC elf by name.

Also, did anybody ever find anything interesting using a fileystem browser? It wasn't able to see any of the Wii U stuff was it?
 

SifJar

Not a pirate
Member
Joined
Apr 4, 2009
Messages
6,022
Trophies
0
Website
Visit site
XP
1,175
Country
You don't need the reset button. Take the boot_mini.elf file and rename it "ppcboot.elf", replace the one in the "BootMii" folder with that one, and as soon as you load Casper it should load HackMii Installer. (By doing this, you replace the BootMii GUI ["Ceiling Cat"] with the HackMii Installer).

I think Riivolution is hardcoded to only use specific revisions of IOS37, so it will probably give some error. I'm not sure about Casper.
 

Supercool330

Well-Known Member
Member
Joined
Sep 28, 2008
Messages
752
Trophies
1
XP
1,129
Country
United States
Oh right, I was thinking you had to use the launch thing inside bootmii, but your right, simply replacing the ppc elf loaded by MINI is a way better plan.

OK, so somebody that has a working SD card should give this a shot.
Download Smash Stack and put the private directory at the root of your SD card (like normal)
Download Hackmii Installer and put bootmini.elf at SD :/bootmii/ppcboot.elf
Download Casper and put casper_X.Y.elf (where X and Y are version numbers) at SD :/boot.elf
Download MINI (armboot.bin) and put it at SD :/bootmii_ios.bin
Then, load up super smash bros and run the exploit like normal.
I will run by my local computer store and grab a couple SD cards later today to give this a shot.
I would be surprised if this works, but not overly so.

Note: SD paths have an extra space in them to prevent smiley substitution.
 

techboy

Well-Known Member
Member
Joined
Mar 15, 2009
Messages
1,720
Trophies
0
Age
31
Location
Pennsylvania
Website
Visit site
XP
306
Country
United States
Anyone tried installing a wad to their vWii with WAD manager?
Unsigned stuff will fail because the signature bug does not exist.

As for official stuff...that's a good question. Anyone tried installing an Internet Channel or Wii Speak Channel wad downloaded from NUS? Those shouldn't need any patched IOS or special permissions since they're signed correctly.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • BakerMan @ BakerMan:
    i said i was sleeping...
  • BakerMan @ BakerMan:
    sleeping with uremum
  • K3Nv2 @ K3Nv2:
    Even my mum slept on that uremum
  • TwoSpikedHands @ TwoSpikedHands:
    yall im torn... ive been hacking away at tales of phantasia GBA (the USA version) and have so many documents of reverse engineering i've done
  • TwoSpikedHands @ TwoSpikedHands:
    I just found out that the EU version is better in literally every way, better sound quality, better lighting, and there's even a patch someone made to make the text look nicer
  • TwoSpikedHands @ TwoSpikedHands:
    Do I restart now using what i've learned on the EU version since it's a better overall experience? or do I continue with the US version since that is what ive been using, and if someone decides to play my hack, it would most likely be that version?
  • Sicklyboy @ Sicklyboy:
    @TwoSpikedHands, I'll preface this with the fact that I know nothing about the game, but, I think it depends on what your goals are. Are you trying to make a definitive version of the game? You may want to refocus your efforts on the EU version then. Or, are you trying to make a better US version? In which case, the only way to make a better US version is to keep on plugging away at that one ;)
  • Sicklyboy @ Sicklyboy:
    I'm not familiar with the technicalities of the differences between the two versions, but I'm wondering if at least some of those differences are things that you could port over to the US version in your patch without having to include copyrighted assets from the EU version
  • TwoSpikedHands @ TwoSpikedHands:
    @Sicklyboy I am wanting to fully change the game and bend it to my will lol. I would like to eventually have the ability to add more characters, enemies, even have a completely different story if i wanted. I already have the ability to change the tilemaps in the US version, so I can basically make my own map and warp to it in game - so I'm pretty far into it!
  • TwoSpikedHands @ TwoSpikedHands:
    I really would like to make a hack that I would enjoy playing, and maybe other people would too. swapping to the EU version would also mean my US friends could not legally play it
  • TwoSpikedHands @ TwoSpikedHands:
    I am definitely considering porting over some of the EU features without using the actual ROM itself, tbh that would probably be the best way to go about it... but i'm sad that the voice acting is so.... not good on the US version. May not be a way around that though
  • TwoSpikedHands @ TwoSpikedHands:
    I appreciate the insight!
  • The Real Jdbye @ The Real Jdbye:
    @TwoSpikedHands just switch, all the knowledge you learned still applies and most of the code and assets should be the same anyway
  • The Real Jdbye @ The Real Jdbye:
    and realistically they wouldn't

    be able to play it legally anyway since they need a ROM and they probably don't have the means to dump it themselves
  • The Real Jdbye @ The Real Jdbye:
    why the shit does the shitbox randomly insert newlines in my messages
  • Veho @ Veho:
    It does that when I edit a post.
  • Veho @ Veho:
    It inserts a newline in a random spot.
  • The Real Jdbye @ The Real Jdbye:
    never had that i don't think
  • Karma177 @ Karma177:
    do y'all think having an sd card that has a write speed of 700kb/s is a bad idea?
    trying to restore emunand rn but it's taking ages... (also when I finished the first time hekate decided to delete all my fucking files :wacko:)
  • The Real Jdbye @ The Real Jdbye:
    @Karma177 that sd card is 100% faulty so yes, its a bad idea
  • The Real Jdbye @ The Real Jdbye:
    even the slowest non-sdhc sd cards are a few MB/s
  • Karma177 @ Karma177:
    @The Real Jdbye it hasn't given me any error trying to write things on it so I don't really think it's faulty (pasted 40/50gb+ folders and no write errors)
  • DinohScene @ DinohScene:
    run h2testw on it
  • DinohScene @ DinohScene:
    when SD cards/microSD write speeds drop below a meg a sec, they're usually on the verge of dying
    DinohScene @ DinohScene: when SD cards/microSD write speeds drop below a meg a sec, they're usually on the verge of dying