Hacking I can install IOS in vWii! But...

Skeet1983

Well-Known Member
Member
Joined
Apr 22, 2012
Messages
3,595
Trophies
1
Age
41
Location
Somewhere, out there...
XP
3,184
Country
United States
Just a heads up: MMM doesn't support WM+ Wiimotes. you need to navigate using an oldskool wiimote. :P

I was unable to boot fstoolbox from MMM, but I was able to move pointer up/down and select with a and I was using WM+ remote... I dunno really, are you using most recent MMM version? Like you, I am also unable to do a successful NAND dump... Still getting errors -1017 and -101...
 

CobraStr1ke

Well-Known Member
Member
Joined
Nov 24, 2012
Messages
109
Trophies
0
XP
128
Country
United States
I was unable to boot fstoolbox from MMM, but I was able to move pointer up/down and select with a and I was using WM+ remote... I dunno really, are you using most recent MMM version? Like you, I am also unable to do a successful NAND dump... Still getting errors -1017 and -101...


I have noticed a thread on gamefaqs with someone claiming the new retro SNES style controller for the Wii U also works in Wii mode as well as NSMB U instead of having to use the gamepad to play....Has anyone else seen this and if thats the case then wouldnt this be ok to use if say, Dios Mios etc, was developed for the vWii ? They claim it basically has the components of a Wiimote inside it... A link to the thread is here -----> http://www.gamefaqs.com/boards/631516-wii-u/64902401
 

CobraStr1ke

Well-Known Member
Member
Joined
Nov 24, 2012
Messages
109
Trophies
0
XP
128
Country
United States

damysteryman

I am too busy IRL these days...
OP
Member
Joined
Oct 4, 2007
Messages
1,223
Trophies
1
XP
1,026
Country
Antarctica
Ok back again :lol:

@Krestent:
DARKCORP was a lot simpler than d2x :lol:
What DARKCORP was, was the already compiled DIP module from IOS249 being copied over to all other IOS more or less. But now that the Wii base IOS are not compatible, d2x has to be ported to use the vWii IOS as bases to have any chance of functioning on vWii.

@Skeet1984:
Does FS Toolbox have AHBPROT privileges when being run?
If running via HBC, make sure the meta.xml for FS Toolbox has the <ahb_access/> (or <no_ios_reload/>, either one works) tag in it. That way it should be able to apply the patches and be able to dump the files form NAND.

@DeadlyFoez:
Yeah, that is true, well, you got a full NAND dump, I only got a FS dump :lol:
You can at least recover your vWii if something goes wrong, I cannot.
But, got a question... if I say, uhhh, had gotten my vWii keys from xyzzy, would that be enough for you fix it should I ever screw it up? For example if I messed something up like IOS80 or System Menu, would those keys be enough to dump, decrypt, install fixed IOS80 or System Menu, reencrypt, and reflash? Just want to know for sure if this would work as a safety net before I try modifying either of these.

@driverdis:
http://wiibrew.org/wiki/Ticket
Hmm, I am not sure, but I think it might be because those are titles that actually cost money, and therefore AFAIK make use of the 60-byte section starting at offset 0x180 in the ticket... maybe try zeroing out those bytes too and see if the wad works afterwards?

As for the fakesigned wads not playing or copying from the SD Menu, that would be because the System Menu IOS, which is IOS80, has not been patched to allow fakesigned titles, like IOS236 has been. Now it is possible to patch IOS80 with the fakesign patch again and install it, however, since IOS80 is one of the first things that runs when you start WiiMode (needed by System Menu), if the patching process screws up, you will not have any way to fix it, due to BootMii being unavailable.
Now, in saying that, it IS just a simple patch, like IOS236, but just unable to be fixed in the case that something DOES go wrong. If you want to test patching IOS80 with fakesign patch for me (I can provide the required stuff or just patch it for you), you can, but if it screws up then I will not be able to fix it is all.
Personally, I doubt it would screw up, should go fine, but it is still risky without BootMii.

@Excelsiior:
Thanks for posting those man. Just had a look at them, YAWMM works fine, installs IOS fine :)
Also, I do not know why, but this bluedump actually works! I wish to add this to my first post along with IOS236 installer as a little guide to get it installed, but would you be willing to translate it to English by any chance? Also noticed that whoever made the bluedump mod (whoever "BohserOnkel/LukWiiDSi" is) failed to credit nicksasa, the original author of the app (source code has his name commented in it, but app does not give credit to him when run).

Also, saw that you updated IOS236 Installer with the updated iospatch.c, however, when actually patching and installing IOS236, that portion of the app still uses the older version of my patches. This is still OK for IOS36 though, but I updated it anyway: here
 

Excelsiior

Well-Known Member
Member
Joined
Sep 13, 2009
Messages
274
Trophies
0
Website
www.nanolx.org
XP
328
Country
Germany
@Excelsiior:
Thanks for posting those man. Just had a look at them, YAWMM works fine, installs IOS fine :)
Also, I do not know why, but this bluedump actually works! I wish to add this to my first post along with IOS236 installer as a little guide to get it installed, but would you be willing to translate it to English by any chance? Also noticed that whoever made the bluedump mod (whoever "BohserOnkel/LukWiiDSi" is) failed to credit nicksasa, the original author of the app (source code has his name commented in it, but app does not give credit to him when run).

This version of bluedump was linked against an older version of -liospatch, only applies three patches, I will test if doing the same will work. I already have a re-translated version, but not (yet) working.
 

Skeet1983

Well-Known Member
Member
Joined
Apr 22, 2012
Messages
3,595
Trophies
1
Age
41
Location
Somewhere, out there...
XP
3,184
Country
United States
Ok back again :lol:

@Krestent:
DARKCORP was a lot simpler than d2x :lol:
What DARKCORP was, was the already compiled DIP module from IOS249 being copied over to all other IOS more or less. But now that the Wii base IOS are not compatible, d2x has to be ported to use the vWii IOS as bases to have any chance of functioning on vWii.

@Skeet1984:
Does FS Toolbox have AHBPROT privileges when being run?
If running via HBC, make sure the meta.xml for FS Toolbox has the <ahb_access/> (or <no_ios_reload/>, either one works) tag in it. That way it should be able to apply the patches and be able to dump the files form NAND.

@DeadlyFoez:
Yeah, that is true, well, you got a full NAND dump, I only got a FS dump :lol:
You can at least recover your vWii if something goes wrong, I cannot.
But, got a question... if I say, uhhh, had gotten my vWii keys from xyzzy, would that be enough for you fix it should I ever screw it up? For example if I messed something up like IOS80 or System Menu, would those keys be enough to dump, decrypt, install fixed IOS80 or System Menu, reencrypt, and reflash? Just want to know for sure if this would work as a safety net before I try modifying either of these.

@driverdis:
http://wiibrew.org/wiki/Ticket
Hmm, I am not sure, but I think it might be because those are titles that actually cost money, and therefore AFAIK make use of the 60-byte section starting at offset 0x180 in the ticket... maybe try zeroing out those bytes too and see if the wad works afterwards?

As for the fakesigned wads not playing or copying from the SD Menu, that would be because the System Menu IOS, which is IOS80, has not been patched to allow fakesigned titles, like IOS236 has been. Now it is possible to patch IOS80 with the fakesign patch again and install it, however, since IOS80 is one of the first things that runs when you start WiiMode (needed by System Menu), if the patching process screws up, you will not have any way to fix it, due to BootMii being unavailable.
Now, in saying that, it IS just a simple patch, like IOS236, but just unable to be fixed in the case that something DOES go wrong. If you want to test patching IOS80 with fakesign patch for me (I can provide the required stuff or just patch it for you), you can, but if it screws up then I will not be able to fix it is all.
Personally, I doubt it would screw up, should go fine, but it is still risky without BootMii.

@Excelsiior:
Thanks for posting those man. Just had a look at them, YAWMM works fine, installs IOS fine :)
Also, I do not know why, but this bluedump actually works! I wish to add this to my first post along with IOS236 installer as a little guide to get it installed, but would you be willing to translate it to English by any chance? Also noticed that whoever made the bluedump mod (whoever "BohserOnkel/LukWiiDSi" is) failed to credit nicksasa, the original author of the app (source code has his name commented in it, but app does not give credit to him when run).

Also, saw that you updated IOS236 Installer with the updated iospatch.c, however, when actually patching and installing IOS236, that portion of the app still uses the older version of my patches. This is still OK for IOS36 though, but I updated it anyway: here

I don't know if FS Toolbox has AHBPROT privileges... any way to change that? Also, how do I edit the meta.xml file like you suggested?
 

SifJar

Not a pirate
Member
Joined
Apr 4, 2009
Messages
6,022
Trophies
0
Website
Visit site
XP
1,175
Country
Hey, just a thought, with patches like this would it be possible to make Casper and Riivolution work again?
No. Casper and Riivolution both rely on the same IOS exploit (in IOS37), which was blocked in vIOS. That exploit had nothing to do with installing system titles, and is therefore completely unrelated to this. megazig has already built a version of Riivolution that works on vWii (although it is not released publicly), and it's probably also worth noting that tueidj (who contributed the IOS exploit used in the most recent HackMii Installer) is also part of the Riivolution team. Not sure if megazig used that same exploit as is in HackMii Installer or a different one, but either way, they have options when/if they decide to release a new version.

On the other hand, if you meant installing a version of IOS37 WITH the exploit, that also wouldn't work as regular IOS don't work on vWii (although I'm sure you know that, and I'm guessing you didn't mean this, but I'm including it as well, just in case).
 

Maxternal

Peanut Gallery Spokesman
Member
Joined
Nov 15, 2011
Messages
5,210
Trophies
0
Age
40
Location
Deep in GBAtemp addiction
Website
gbadev.googlecode.com
XP
1,709
Country
No. Casper and Riivolution both rely on the same IOS exploit (in IOS37), which was blocked in vIOS. That exploit had nothing to do with installing system titles, and is therefore completely unrelated to this. megazig has already built a version of Riivolution that works on vWii (although it is not released publicly), and it's probably also worth noting that tueidj (who contributed the IOS exploit used in the most recent HackMii Installer) is also part of the Riivolution team. Not sure if megazig used that same exploit as is in HackMii Installer or a different one, but either way, they have options when/if they decide to release a new version.

On the other hand, if you meant installing a version of IOS37 WITH the exploit, that also wouldn't work as regular IOS don't work on vWii (although I'm sure you know that, and I'm guessing you didn't mean this, but I'm including it as well, just in case).
Okay, that's fine.
Actually, I was just talking about undoing the fix that Nintendo did to the vIOS's, kinda like there's a PriiLoader hack to add BannerBomb support back to the System Menu, but it's cool to know that a new version with a different exploit is being made. (I understand, too, that if the IOS fix was a rewrite instead of a simple code adjustment it may not be as simple as just patching out the security check or something.)
 

Skeet1983

Well-Known Member
Member
Joined
Apr 22, 2012
Messages
3,595
Trophies
1
Age
41
Location
Somewhere, out there...
XP
3,184
Country
United States
within multi mod manager there is an item that says app manager that allows you to launch apps.


also got it working properly from homebrew channel now the trick is to have a meta.xml file in the sd:\apps\fstoolbox folder

<?xml version="1.0" encoding="UTF-8" standalone="yes"?>
<appversion="1.0">
<name>FSToolBox AHBPROT MOD</name>
<coder>nicksasa, Lupo96</coder>
<version>1.0</version>
<release_date>01-13-2012</release_date>
<short_description>A WII FS Swiss Army Knife</short_description>
<long_description>This is little yet really usefull utility originally coded by nicksasa and then modified by Lupo96 to use AHBPROT with IOS58.
Based on FSToolBox v4beta, may be unstable.
You need HBC 1.0.8 or higher to run this!!!
Find me (Lupo96) on wiitaly.altervista.org</long_description>
<no_ios_reload/>
</app>

Also got WiiXplorer working by adding <no_ios_reload/> right before the </app> tag this appears to enable / disable AHBROOT access for the application you're launching

Where/how do I get the meta.xml file and how do I make/edit the file with those suggested tags?
 

Gizmo1k

Well-Known Member
Newcomer
Joined
Jun 21, 2006
Messages
59
Trophies
0
XP
317
Country
United States
Where/how do I get the meta.xml file and how do I make/edit the file with those suggested tags?
put that into a file named meta.xml if its not there create it. This meta.xml is intended for fstoolbox itself and makes it able to be launched directly from homebrew channel.

you basically create your own text file that can be created with notepad or wordpad or some other text editor. the key is that you have everything thats in the <?xmlversion> </app> tags in my post copied into your meta.xml and that its in the same folder as the fstoolbox dol you want to execute which should be named boot.dol.
 

Skeet1983

Well-Known Member
Member
Joined
Apr 22, 2012
Messages
3,595
Trophies
1
Age
41
Location
Somewhere, out there...
XP
3,184
Country
United States
put that into a file named meta.xml if its not there create it. This meta.xml is intended for fstoolbox itself and makes it able to be launched directly from homebrew channel.

you basically create your own text file that can be created with notepad or wordpad or some other text editor. the key is that you have everything thats in the <?xmlversion> </app> tags in my post copied into your meta.xml and that its in the same folder as the fstoolbox dol you want to execute which should be named boot.dol.

I created the meta file, but fstoolbox is not showing up in HBC. When I tried booting from Wiixplorer, I still get the same -1017 and -101 errors... How can I go about dumping my NAND?
 

Skeet1983

Well-Known Member
Member
Joined
Apr 22, 2012
Messages
3,595
Trophies
1
Age
41
Location
Somewhere, out there...
XP
3,184
Country
United States
is it named boot.dol and located in "SD:/apps/SOMEFOLDER/boot.dol"?

I can edit the meta file by right-clicking it and selecting "edit", but when I open it normally, it does not display anything. Although, it says file type is xml and there is the coding in edit mode. File size is 602 bytes...
 

Maxternal

Peanut Gallery Spokesman
Member
Joined
Nov 15, 2011
Messages
5,210
Trophies
0
Age
40
Location
Deep in GBAtemp addiction
Website
gbadev.googlecode.com
XP
1,709
Country
I tried booting fstoolbox... Unable to see it in HBC and also doesn't boot the program from MMM either... I am using the .dol file
Where EXACTLY is that DOL file located and what is it named?
Do you have HBC set to look for apps in the SD card or in USB?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BakerMan
    The snack that smiles back, Ballsack!
    BakerMan @ BakerMan: yeah, i'm Anyone, that's just not my alias here