Hacking Wii U Hacking & Homebrew Discussion

ldeveraux

Well-Known Member
Member
Joined
Jan 4, 2007
Messages
430
Trophies
1
XP
1,895
Country
United States
So guys, any news about the firmware spoofing already? I'd really want to give Mario Maker a try already but I'm still on 5.3.2 and I have to download it from the eShop, but won't matter anyways because that game sure brings an updater with it...
Check that thread, not this one
 

FR0ZN

Well-Known Member
Member
Joined
Nov 2, 2013
Messages
1,384
Trophies
1
Age
37
XP
3,883
Country
United States
@Marionumber1 I recently saw one of your posts here you mentioned that FW 4.1.0 and 5.0.0 have WebKit exploits which are more stable?
Is there any place I can read up which FW has the most stable userspace exploits? Or can you quickly say what's actually unstable about the 5.3.2 userspace exploit?

I found a list here of what FW has which option for exploitation, but I thinks it's a bit wrong here and there?

http://rhcafe.us.to/

I see a lot FW version in the userspace section which are nowhere mentioned inside the OSDriver src on git? Or do some FWs share the same kernel adresses?
And what about the "unstable" note for the kernel exploit on 5.3.2 ? According to the list the kernel exploit is stable for any other FW below 5.3.2 ???

I'm confused :huh::blink::wacko:
 

FR0ZN

Well-Known Member
Member
Joined
Nov 2, 2013
Messages
1,384
Trophies
1
Age
37
XP
3,883
Country
United States
Just bookmarked it. I'm also seeing something about a 5.4.0 Kernel Exploit that isn't private... Would anyone care to explain?

The kernel exploit for 5.4.0 is the current exploit which also works on 5.3.2.
The Problem here is, that we have no public way to execute it through a userspace wxploit (webkit exploit), so peeps are currently awaiting it.

NWPlayer mentioned the current situation here: https://gbatemp.net/threads/wii-u-hacking-homebrew-discussion.367489/page-552#post-5669495
 

xXDungeon_CrawlerXx

Well-Known Member
Member
Joined
Jul 29, 2015
Messages
2,092
Trophies
1
Age
28
Location
Liverpool
XP
3,722
Country
Just bookmarked it. I'm also seeing something about a 5.4.0 Kernel Exploit that isn't private... Would anyone care to explain?
True, there's a Kernel Exploit for 5.4.0 and 5.5.0 already but you're not able to use them.
Why? Because you need to use the userland-Exploit first, which isn't public yet.
 

oumoumad

Well-Known Member
Member
Joined
Apr 20, 2015
Messages
798
Trophies
0
Age
31
XP
890
Country
France
Just bookmarked it. I'm also seeing something about a 5.4.0 Kernel Exploit that isn't private... Would anyone care to explain?
True, there's a Kernel Exploit for 5.4.0 and 5.5.0 already but you're not able to use them.
Why? Because you need to use the userland-Exploit first, which isn't public yet.

I no think there is a public 5.5.0 kernel exploit. The main reason the last kernel exploit was released is because it was patched on 5.5.0
 

NWPlayer123

Well-Known Member
Member
Joined
Feb 17, 2012
Messages
2,642
Trophies
0
Location
The Everfree Forest
XP
6,693
Country
United States
Guess I'll post some more stuff
The first kernel exploit we made, the OSDriver one, theoretically works on 1.0 to 5.4.0, and was patched in 5.5.0, which was why it was released. There's another one made a while ago that works on 5.3.2-5.5.0, but I'm not sure how far back it can go. There's also several Webkit exploits, one that was made for 4.0.0-5.1.0 or something and I think Hykem backported it to 3.0.0+, a new one that works up to 5.3.2 (the one everyone's using), and then a new one that is confirmed working on 5.4.0 and 5.5.0.
Also, if you want to get TCPGecko and Cafiine working at the same time, you'll need to do several things. Not sure what FIX's changes do since my brain's out of it today, but basically when the kernel exploit maps stuff, it's mirrored into 0xA0000000. What this means, in I think 5.3.2+, coreinit's loaded in at 0x101C400 (it's "base"), and this
https://github.com/wiiudev/pyGecko/...fcb8222cb86b4c420bb598/installer/loader.c#L50
just patches a bctrl right before exiting in its start function, this one
TCPGeckoPatch.png
which, when initialized by a game, it'll run the start function, and then the PowerPC instruction we install will jump to TCPGecko's codehandler we install at 0xA11DD000. Then those other 2 instructions patch nsysnet, don't remember exactly what. Since Cafiine just hooks into the functions, it doesn't need to be run, it'll run when the normal functions are ran, and it's initialized with FSInit. So all you'd need to do is move Cafiine back from 0xA11DCC00 to however far back you're able to move it, and then edit the address the TCP codehandler installs at and the instruction that jumps to it. Leave the 0xA101C55C intact. Also, that screenshot is from 5.5.0, 55C is correct for 5.3.2 and 5.4.0, and it's 56C on 5.5.0.
 

YugamiSekai

Mr. Picross
Member
Joined
Dec 24, 2014
Messages
2,015
Trophies
1
Age
22
XP
2,285
Country
United States
  • Like
Reactions: Margen67

OncleJulien

tool of peers
Member
Joined
Apr 6, 2009
Messages
1,170
Trophies
0
Location
Los Angeles
XP
439
Country
United States
@gamesquest1 I have, I just get tired of the negativity and the impression it might leave on other users.
i think it's totally bollocks there there's no detailed tutorial on how to interact with that guy...but i guess we're all totally screwed forever until such time as someone never makes one ever - thanks holier-than-thou hoarding devs!
 
  • Like
Reactions: frogboy

the_randomizer

The Temp's official fox whisperer
Member
Joined
Apr 29, 2011
Messages
31,284
Trophies
2
Age
38
Location
Dr. Wahwee's castle
XP
18,969
Country
United States
anyway, after digging, vc injection is not as bad as it seemed to be.

Have you tested Snes games by chance? We think the config files are buried within the exe or wrapper that the ROMs use, curious to see what makes them hard-coded to run X games.
i get the impression you haven't came across the randomizer before :creep:

It's nice to know that I'm so loved around here. I should learn how to program and port emulators (Snes9x 1.53, PCSX-R, DeSmuME and so on) over to the Wii U out of spite :creep:
 

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
Have you tested Snes games by chance? We think the config files are buried within the exe or wrapper that the ROMs use, curious to see what makes them hard-coded to run X games.


It's nice to know that I'm so loved around here. I should learn how to program and port emulators (Snes9x 1.53, PCSX-R, DeSmuME and so on) over to the Wii U out of spite :creep:
wouldn't be gbatemp without you to put a dampener on things XD

anyways im just messing about, some people try to focus on the positive, others dont, not like everyone can be in high spirits all of the time :)
 

galneon

Well-Known Member
Member
Joined
Jul 9, 2006
Messages
254
Trophies
1
XP
536
Country
United States
So...no emulators are ever gonna happen? Guess we're stuck with the largely unsuccessful VC injections then :glare: We all know how well that went last week. Damn hard-coded emulators.

"Ever"? That's a bit short-sighted for someone who has been here for a few years. There will likely be additional exploits discovered, and there will certainly be new capabilities realized from exploits we already have.
 

Ericzander

GBAtemp's residential attorney
Editorial Team
Joined
Feb 28, 2014
Messages
2,228
Trophies
3
Location
Grand Line
XP
7,722
Country
Somalia
This is great news! Unfortunately, my console auto updated recently (my fault, I moved the console to a different location). In the other thread @golden45 said that he is only working on 5.3.2 but it shouldn't be hard to port. Does that mean it should be portable to the latest version?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Psionic Roshambo @ Psionic Roshambo: Playing the Judge Dredd arcade game prototype lol I can see why they didn't finish it but at the...