Homebrew SigHax Updates and Discussion Thread

Roboman

Well-Known Member
Member
Joined
Jan 7, 2016
Messages
313
Trophies
0
Age
28
XP
734
Country
United States
xorpads are still needed if you want to decrypt games and/or eMMC using a PC.

...until Boot9 is dumped, in which case the actual keys can be retrieved from the BootROM, and OTP dumps can be decrypted to obtain the eMMC keys.

(Interestingly, the only reason xorpads work is because of a weakness in AES-CTR. AES-CBC, which was used on Wii, doesn't have the same problem.)
But the wii had the critical problem of ending signature checking as valid whenever it runs into a null byte. So any brute forced signature that starts with a null byte is valid on the wii!
 
D

Deleted User

Guest
To somebody who actually knows:

Is there a reason that hedge is underclocking greg in order to get at boot9? Is it to cause a bootrom error that allows you to dump the data, or some other reason? I couldn't really figure it out from just the one stream I was able to catch.
 

Zaphod77

Well-Known Member
Member
Joined
Aug 25, 2015
Messages
665
Trophies
0
Age
48
XP
604
Country
United States
sighax doesn't actually let you do the flash. you need another way to get write access to the NAND for that. it just let you write your own code that passes the bootrom signature check.
 

jt_1258

Ella
Member
Joined
Aug 21, 2016
Messages
3,053
Trophies
2
Age
24
XP
4,881
Country
United States
To somebody who actually knows:

Is there a reason that hedge is underclocking greg in order to get at boot9? Is it to cause a bootrom error that allows you to dump the data, or some other reason? I couldn't really figure it out from just the one stream I was able to catch.
perhaps since it thinks slower(the cpu) the flow of things is slower giving more time to triger the flaw and essentialy making time slower, think of it like witch time from bayonetta, although tbh I likely don't have a dam clue what I'm talking about but that's what I think there
 

Starzcream

Well-Known Member
Newcomer
Joined
Feb 22, 2017
Messages
84
Trophies
0
Age
37
XP
93
Country
United States
perhaps since it thinks slower(the cpu) the flow of things is slower giving more time to triger the flaw and essentialy making time slower, think of it like witch time from bayonetta, although tbh I likely don't have a dam clue what I'm talking about but that's what I think there

Bullet time effect lmao
 

EmuAGR

Well-Known Member
Member
Joined
Jan 11, 2016
Messages
205
Trophies
0
Age
31
XP
246
Country
perhaps since it thinks slower(the cpu) the flow of things is slower giving more time to triger the flaw and essentialy making time slower, think of it like witch time from bayonetta, although tbh I likely don't have a dam clue what I'm talking about but that's what I think there
I suppose that's the answer. The slower the CPU is, the more time you have to exploit the flaws.
 

jt_1258

Ella
Member
Joined
Aug 21, 2016
Messages
3,053
Trophies
2
Age
24
XP
4,881
Country
United States
How far have they gotten?
just hopped in so not much of an idea what's goin on

--------------------- MERGED ---------------------------

How far have they gotten?
sorry for the double reply but once I can get the chat replay going after the stream I'll get a screenshot of it in chat but seems my theory was correct about witch timing the 2ds ;P
 
  • Like
Reactions: proflayton123
D

Deleted User

Guest
just hopped in so not much of an idea what's goin on

--------------------- MERGED ---------------------------


sorry for the double reply but once I can get the chat replay going after the stream I'll get a screenshot of it in chat but seems my theory was correct about witch timing the 2ds ;P

i learned it yesterday, because i asked it in the stream that day :P

How far have they gotten?

From what I can figure out, timing is down pat, and at this point it's pretty much debugging and the exploit itself. If you go on there and ask politely they can explain it better than I can.

EDIT: emphasized "politely" because hedge has been super stressed lately and the chat doesn't really like gbatemp
 
Last edited by ,

jt_1258

Ella
Member
Joined
Aug 21, 2016
Messages
3,053
Trophies
2
Age
24
XP
4,881
Country
United States
i learned it yesterday, because i asked it in the stream that day :P



From what I can figure out, timing is down pat, and at this point it's pretty much debugging and the exploit itself. If you go on there and ask politely they can explain it better than I can.

EDIT: emphasized "politely" because hedge has been super stressed lately and the chat doesn't really like gbatemp
I can see the dislike of gbatemp, especially with how hedge was angry about certain arguments that have happened here, nice to see senpai quietly watching over us but I feel bad for what they have to see here, so please, here and in the twitch chat and everywhere, be nice for once in your dam life, let's keep hedge happy and cheer them on
 
  • Like
Reactions: TotalInsanity4

Deleted member 350372

Well-Known Member
Member
Joined
Jun 15, 2014
Messages
316
Trophies
0
Age
29
Location
boot.firm, New Jersey
XP
388
Country
United States
Yuppp. Decrypting the bricked emuNAND and moving the NAND headers or whatever from sysNAND to the emuNAND. Do you guys know how fucking scary it is, restoring a emuNAND backup that you hex edited back to life?
Xorpads eh? That's probably the one thing I never really was interested in knowing what they do, like game .cia xorpads or xorpads for nand backups, etc. So I guess I started mid-way when things were getting a bit easier. Damn I would be terrified if I had to do all the decrypting and encrypting also hex editing jeez so much work! :o

--------------------- MERGED ---------------------------

I can see the dislike of gbatemp, especially with how hedge was angry about certain arguments that have happened here, nice to see senpai quietly watching over us but I feel bad for what they have to see here, so please, here and in the twitch chat and everywhere, be nice for once in your dam life, let's keep hedge happy and cheer them on
I agree dude. Agreed... Let's stay positive so we can cheer Hedge on and not jynx whether or not sighax will be released by her. Don't wanna have her get so angry that she says f**k it, people are just greedy bastards and only want the hax. They don't care on how hard it is, etc for me. Then again, if this does happen, a huge wait if I am not mistaken will most likely happen for someone to step in for dumping prot_boot9.bin
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    Xdqwerty @ Xdqwerty: see ya