Hacking Secret Fail0verflow key leak?

  • Thread starter Thread starter lismati
  • Start date Start date
  • Views Views 42,084
  • Replies Replies 123
Status
Not open for further replies.
@fail0verflow, 5 hours ago
As usual, we failed. Correction: 3d331b3165f9638c6cd6221702b2f736f7fcf931 . We forgot to trim a bit of garbage padding.
 
Come on man. You know what I meant. What could hackers do with the key?
Private keys are used to sign things, so it would allow us to sign software to run on a Wii U. It's not the private key, though.

Even if they did find the private key, I sincerely hope they would not release it. fail0verflow made a mistake blowing their load, a so-called, pwn everything hack, too early into the PS3's life which resulted in Sony recovering and many people on newer firmwares unable to run homebrew. To do the same thing less than a month after the Wii U was launched would be a mistake. A discovery or hack like that should only be released much later in a product's life cycle (ie when the successor is announced), though it could be used to find other exploits in the meantime.
 
Private keys are used to sign things, so it would allow us to sign software to run on a Wii U. It's not the private key, though.

Even if they did find the private key, I sincerely hope they would not release it. fail0verflow made a mistake blowing their load, a so-called, pwn everything hack, too early into the PS3's life which resulted in Sony recovering and many people on newer firmwares unable to run homebrew. To do the same thing less than a month after the Wii U was launched would be a mistake. A discovery or hack like that should only be released much later in a product's life cycle (ie when the successor is announced), though it could be used to find other exploits in the meantime.

Why in the world would we want to wait longer for "homebrew", when new fw are released there are always fixes found in the future.
 
This is very interesting....

EDIT: Ok i got it, if you inspect the highlighted section(as element) its says sha1sum.
Nope.

This user does not have permission to use the HTML BB code.

The entire thing is "sha1sum", not just the highlighted section.
 
  • Like
Reactions: pelago
@fail0verflow, 5 hours ago
As usual, we failed. Correction: 3d331b3165f9638c6cd6221702b2f736f7fcf931 . We forgot to trim a bit of garbage padding.
So it was no key. A key has no garbage padding. Maybe first WiiU firmware dump?
 
Sha1 of a key?
That way, they show to Nintendo that they found it (they can sha1 whatever they have), but don't provide it to other users.

Are they going to 29c3, or it's too late to register this year? maybe not enough data to show, but the first year they had things to display for the Wii.
Edit: even if we already know few things on WiiU/vWii, they could explain it to less scene-aware people.
 
Oh, I love the Wii Hacking talk (25-I-Think-C3, marcan and bushing only on-stage) and PS3 hacking talk as Fail0verflow on 27c3
 
It seems like fail0verflow won't be at 29C3 (according to the speaker's list today, unless that gets updated closer to time), but there is an interesting talk on 1024 Bit RSA attack vectors that seems rather interesting for the WiiU and 3DS (not to mention, like.. every 7th gen console out there!)

http://events.ccc.de/congress/2012/Fahrplan/events/5275.en.html

There's also a talk about low-cost microprobing which could be a possible alternative to the current 3DS decapping fundraiser: http://events.ccc.de/congress/2012/Fahrplan/events/5275.en.html
 
Why in the world would we want to wait longer for "homebrew", when new fw are released there are always fixes found in the future.
Because the private key is the holy grail, no other hack compares. Waiting longer than three months after the previous exploithad been found would have meant more consoles hackable. But, of course, most people only care about themselves, as your post indicates.
 
  • Like
Reactions: [Truth]
So it was no key. A key has no garbage padding. Maybe first WiiU firmware dump?
... or maybe there was garbage padding of the thing they hashed?
'Cause that'll change the hash since thew input is changing (and SHA-1's a decent hash).
 
Sha1 of a key?
A key probably wouldn't have garbage padding (by "garbage padding", they mean extra bytes added to the thing they took the hash of e.g. at the start or end; a key most likely wouldn't have that). Probably some file from the WiiU system menu or whatever.
 
  • Like
Reactions: pelago
Sha1 of a key?
That way, they show to Nintendo that they found it (they can sha1 whatever they have), but don't provide it to other users.

Are they going to 29c3, or it's too late to register this year? maybe not enough data to show, but the first year they had things to display for the Wii.
Edit: even if we already know few things on WiiU/vWii, they could explain it to less scene-aware people.

They are going to 29c3 this year, and they talks about Wiiu on this page!
http://events.ccc.de/congress/2012/wiki/Fail0verflow
 
  • Like
Reactions: lismati and Cyan
So when is their talk? The page doesn't give a time or even a date.
That's because they aren't making a talk. They're going to be present at the conference, but they aren't giving a talk. They'll just have a few tables in the hack centre.
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum