iQue Player hacking possibility with ique_diag.exe?

KevinLSX

Well-Known Member
Member
Joined
Mar 6, 2016
Messages
526
Trophies
0
XP
1,112
Country
United States
Wow! That's incredible! Are you a hardware engineer or something?


hahaha nah all it took was a little bit of soldering and knowing where the wires had to go.

--------------------- MERGED ---------------------------

I meant the iQue menu where you can select games from
I remember someone trying and they broke there Ique. I dont know if id risk breaking it.
 

KevinLSX

Well-Known Member
Member
Joined
Mar 6, 2016
Messages
526
Trophies
0
XP
1,112
Country
United States
Not sure if it matters or not but when I inserted the depot disc it started download game files and those files were put in a cache folder.
 

Krem Quay

Well-Known Member
Newcomer
Joined
Aug 24, 2014
Messages
89
Trophies
0
Age
26
XP
229
Country
United States
3989pk.png


You know, i'm pretty sure that text before the ROOT CPCA is the encrypted titlekey or something.
 

Krem Quay

Well-Known Member
Newcomer
Joined
Aug 24, 2014
Messages
89
Trophies
0
Age
26
XP
229
Country
United States
Extensive research on title keys (tickets) of Nintendo systems, especially the Wii, which probably has the most similar encryption method.
 

KevinLSX

Well-Known Member
Member
Joined
Mar 6, 2016
Messages
526
Trophies
0
XP
1,112
Country
United States
Couldnt we see if someone on here could help. If it similar to wii or other systems, then someone with the experience could probably do it.
We need to reach out to someone who has the experience on these kind of things.
 
  • Like
Reactions: Krem Quay

asper

Well-Known Member
Member
Joined
May 14, 2010
Messages
942
Trophies
1
XP
2,028
Country
United States
Well, .rec file is the game that, reading the above link, is encrypted with a per-console specific key that probably is inside recrypt.sys. Keys are usually 16bytes and Nintendo encryption formats are (read here and here for more info):

0x010000 RSA_4096 SHA1 (Unused for 3DS) 0x200 0x3C
0x010001 RSA_2048 SHA1 (Unused for 3DS) 0x100 0x3C
0x010002 Elliptic Curve with SHA1 (Unused for 3DS) 0x3C 0x40
0x010003 RSA_4096 SHA256 0x200 0x3C
0x010004 RSA_2048 SHA256 0x100 0x3C
0x010005 ECDSA with SHA256 0x3C 0x40

Also more info about Nintendo ticket system can be read here.

Then the decrypted game must be decrypted again with a "common key" that must stored somewhere in the system dump.

Can someone post a screenshot of the 1st bytes (at least 0x200) .sys files opened with an hex editor ?

EDIT: 0-8192 partial dump taken from one of the above posted-link is surely encrypted.
 
Last edited by asper,
  • Like
Reactions: Krem Quay

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • Sicklyboy @ Sicklyboy:
    maaaaan that's so awesome but I also don't want to fork over a hundo for it
  • Veho @ Veho:
    The fuuuuu---
  • Veho @ Veho:
    I thought it was an actual xBox at that price.
  • Sicklyboy @ Sicklyboy:
    I wanna grab a 360 Slim and a 360 E one of these days. Missed the boat of getting them at their lowest though, once they were discontinued. Could've got them for cheap back when I was a broke 20 something working at Target, but then again, I was a broke 20 something working at Target
  • Veho @ Veho:
    Being broke is no fun.
  • K3Nv2 @ K3Nv2:
    @Sicklyboy, $150 isn't that bad for a jtag slim on ebay
  • Veho @ Veho:
    I only wish it was actually playable.
  • Veho @ Veho:
    There's a guy on the Tube of You that makes playable mechanical arcade games out of Lego. This could work on the same principle.
  • Veho @ Veho:
    Just a couple of guys taking their manatee out for some fresh air, why you have to molest them?
  • Veho @ Veho:
    Stupid Chinese shop switched their shipping company and this one is slooooooow.
  • LeoTCK @ LeoTCK:
    STOP BUYING CHINESE CRAP THEN
  • LeoTCK @ LeoTCK:
    SUPPORT LOCAL PRODUCTS, MAKE REVOLUTION
  • LeoTCK @ LeoTCK:
    THEY KEEP REMOVING LOCAL SHIt AND REPLACING WItH INFERIOR CHINESE CRAP
  • LeoTCK @ LeoTCK:
    THATS WHY MY PARTNER CANT GET A GOOTWEAR HIS SIZE ANYMORE
  • LeoTCK @ LeoTCK:
    HE HAS BIG FOOT AND BIG DUCK
  • LeoTCK @ LeoTCK:
    d*ck i mean*
  • LeoTCK @ LeoTCK:
    lol
  • Veho @ Veho:
    Mkay.
  • Veho @ Veho:
    I just ordered another package from China just to spite you.
  • SylverReZ @ SylverReZ:
    Leo could not withstand communism.
  • SylverReZ @ SylverReZ:
    Its OUR products to begin with lol.
    SylverReZ @ SylverReZ: Its OUR products to begin with lol.