Hacking [Semi-working] NFS2ISO2NFS - convert nfs to iso and back

victormr21

Well-Known Member
Member
Joined
Dec 29, 2015
Messages
565
Trophies
0
XP
498
Country

Mario Kart Wii successfully injected :hrth:

I use the "New Super Mario Bros. Wii" to do the template, the beginning is a black screen
Then I copied Xenoblade Chronicles' "fw.img" and "fw.tmd" to cover the code folder and worked well

Share The Meta Image

Did you use original MKWii's tik and tmd files?
 

cucholix

00000780 00000438
Member
Joined
Jan 17, 2017
Messages
3,246
Trophies
1
Age
44
XP
6,297
Country
Chile
Still getting black screen after the Wii white logo, my copy of the game is 1:1 riped directly from the disc itself with CleanRip.
I followed all the steps:
  • Get clean ISO from No More Heroes 2 Desperate Struggle
  • Delete the update partition with Wiiscrubber
  • Extracted the files with Wiiscrubber, renamed rvlt.tik/rvlt.tmd (made sure it wasn't rvlt.tik.bin/rvlt.tmd.bin)
  • Got the code/content/meta/ from Xenoblade Chronicles
  • nfs2iso2nfs the ISO, output 17 nfs files, copied them over content folder
  • Packed with nuspacker from the OP (iHaveamac ver)
  • Installed with WUP Installer Y mod
  • Not a single warning during the whole process

The only things I modified was the meta.xml (to it to show the actual title name) and app.xml to change the title ID :unsure:
 

Ponyboy

Well-Known Member
Newcomer
Joined
Dec 17, 2016
Messages
67
Trophies
0
Age
24
XP
93
Country
United States
Haven't tried this yet, but does multiplayer work with the injected Wii VC's? Can I connect extra Wii remotes for a game like Mario Kart Wii?
 
Last edited by Ponyboy,

sabykos

Well-Known Member
OP
Member
Joined
Jun 10, 2013
Messages
283
Trophies
1
Age
36
XP
729
Country
Gambia, The
Shouldn't it be possible to reduce the total size of the nfs files to something about as big as an wbfs without fucking up the signature? I mean the legit Wii VCs do this aswell, the header specifies how the game is compressed. As long as the WiiU gets a clean iso after decompressing according to the header and decrypting it should. Of course you would still need a clean iso as base, but you would save a lot of space.

--------------------- MERGED ---------------------------

And concerning the tmd file corresponding to the fw.img: Isn't the signature of fw.img checked by the WiiU and not by the vWii? I guess we could just fakesign a patched fw.img, but I might be wrong there.
 

piratesephiroth

I wish I could read
Member
Joined
Sep 5, 2013
Messages
3,453
Trophies
2
Age
103
XP
3,234
Country
Brazil
Shouldn't it be possible to reduce the total size of the nfs files to something about as big as an wbfs without fucking up the signature? I mean the legit Wii VCs do this aswell, the header specifies how the game is compressed. As long as the WiiU gets a clean iso after decompressing according to the header and decrypting it should. Of course you would still need a clean iso as base, but you would save a lot of space
It that was possible, Nintendo wouldn't have repacked (and re-signed) their isos.

And concerning the tmd file corresponding to the fw.img: Isn't the signature of fw.img checked by the WiiU and not by the vWii? I guess we could just fakesign a patched fw.img, but I might be wrong there.
fw.img is a wii IOS (with some weird header) and it has a Wii tmd. The Wii U system doesn't verify it, only vWii does.
 
Last edited by piratesephiroth,

sabykos

Well-Known Member
OP
Member
Joined
Jun 10, 2013
Messages
283
Trophies
1
Age
36
XP
729
Country
Gambia, The
It that was possible, Nintendo wouldn't have repacked (and re-signed) their isos.


fw.img is a wii IOS (with some weird header) and it has a Wii tmd. The Wii U system doesn't verify it, only vWii does.
@JaGoTu10 liked your tutorial btw. So he recognized your work. Maybe he's interested in patching the fw.img
 
  • Like
Reactions: piratesephiroth

pedro702

Well-Known Member
Member
Joined
Mar 3, 2014
Messages
12,732
Trophies
2
Age
34
XP
8,741
Country
Portugal
from what i know every game exploit is just userland and without being able to isntall well the actual hack that gives kernel acess no homebrew like nintendont or emulators will work afaik. its probably easier to debug the gamepad cios and make one for the real vwii than injecting homebrew on vwii stuff.
 

VinsCool

Persona Secretiva Felineus
Global Moderator
Joined
Jan 7, 2014
Messages
14,600
Trophies
4
Location
Another World
Website
www.gbatemp.net
XP
25,228
Country
Canada
I was wondering.

Sorry if that was asked or tested already, just in case I get yelled at haha.

Has there been tests regarding shrunken ISO conversions? I was curious to compare, for example, a whole nfs converted to ISO (using piratesephiroths version), to a 1:1 ISO, and finally a .wbfs of the same game. There has to be a pattern somewhere, if Nintendo managed to do it themselves, right? :P
 

Billy Acuña

Well-Known Member
Member
Joined
Oct 10, 2015
Messages
3,126
Trophies
1
Age
31
XP
3,701
Country
Mexico
I was wondering.

Sorry if that was asked or tested already, just in case I get yelled at haha.

Has there been tests regarding shrunken ISO conversions? I was curious to compare, for example, a whole nfs converted to ISO (using piratesephiroths version), to a 1:1 ISO, and finally a .wbfs of the same game. There has to be a pattern somewhere, if Nintendo managed to do it themselves, right? :P
They should sign their isos after patching it to 1:1
 

piratesephiroth

I wish I could read
Member
Joined
Sep 5, 2013
Messages
3,453
Trophies
2
Age
103
XP
3,234
Country
Brazil
I was wondering.

Sorry if that was asked or tested already, just in case I get yelled at haha.

Has there been tests regarding shrunken ISO conversions? I was curious to compare, for example, a whole nfs converted to ISO (using piratesephiroths version), to a 1:1 ISO, and finally a .wbfs of the same game. There has to be a pattern somewhere, if Nintendo managed to do it themselves, right? :P
"YELLING"
Trimming the iso would reorganize the files and change their positions, moving them to the beginning of the file. This would force the generation of a new tmd that we can't sign because only Nintendo has the private keys for that.

Nintendo just repacked and re-signed, as usual.
 

VinsCool

Persona Secretiva Felineus
Global Moderator
Joined
Jan 7, 2014
Messages
14,600
Trophies
4
Location
Another World
Website
www.gbatemp.net
XP
25,228
Country
Canada
"YELLING"
Trimming the iso would reorganize the files and change their positions, moving them to the beginning of the file. This would force the generation of a new tmd that we can't sign because only Nintendo has the private keys for that.

Nintendo just repacked and re-signed, as usual.
Oh I see then. So our only bet for this would be to bypass the signature check, is that correct?
 

sabykos

Well-Known Member
OP
Member
Joined
Jun 10, 2013
Messages
283
Trophies
1
Age
36
XP
729
Country
Gambia, The
"YELLING"
Trimming the iso would reorganize the files and change their positions, moving them to the beginning of the file. This would force the generation of a new tmd that we can't sign because only Nintendo has the private keys for that.

Nintendo just repacked and re-signed, as usual.
I'm still a bit confused. Isn't the signature of game checked AFTER unpacking and decrypting the nfs files?
 

piratesephiroth

I wish I could read
Member
Joined
Sep 5, 2013
Messages
3,453
Trophies
2
Age
103
XP
3,234
Country
Brazil
I'm still a bit confused. Isn't the signature of game checked AFTER unpacking and decrypting the nfs files?
yeah, the nfs files are joined and decrypted in Wii U mode so this isn't verified at all. But the as soon as the decrypted nfs is read in vWii, the signature and integrity of the disc image is verified.
 
  • Like
Reactions: VinsCool

sabykos

Well-Known Member
OP
Member
Joined
Jun 10, 2013
Messages
283
Trophies
1
Age
36
XP
729
Country
Gambia, The
yeah, the nfs files are joined and decrypted in Wii U mode so this isn't verified at all. But the as soon as the decrypted nfs is read in vWii, the signature and integrity of the disc image is verified.
Well, imo that means we can reduce the size of the nfs files via the header:

https://gbatemp.net/threads/help-eggs-sgge-header-of-wii-vc-eshop-games.454489/page-2#post-6953527

After unpacking and decrypting the nfs files the result should be a clean iso again as long as the input iso was clean.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Shubshub @ Shubshub: oshit its the real jdbye