Hacking Secret Fail0verflow key leak?

Status
Not open for further replies.

lismati

Speedrunner in practice
OP
Member
Joined
Feb 24, 2010
Messages
373
Trophies
1
Age
26
Location
Yes.
Website
www.wiiplanet.info
XP
659
Country
Poland
@fail0verflow, 5 hours ago
As usual, we failed. Correction: 3d331b3165f9638c6cd6221702b2f736f7fcf931 . We forgot to trim a bit of garbage padding.
 

McHaggis

Fackin' Troller
Member
Joined
Oct 24, 2008
Messages
1,749
Trophies
0
XP
1,466
Country
Come on man. You know what I meant. What could hackers do with the key?
Private keys are used to sign things, so it would allow us to sign software to run on a Wii U. It's not the private key, though.

Even if they did find the private key, I sincerely hope they would not release it. fail0verflow made a mistake blowing their load, a so-called, pwn everything hack, too early into the PS3's life which resulted in Sony recovering and many people on newer firmwares unable to run homebrew. To do the same thing less than a month after the Wii U was launched would be a mistake. A discovery or hack like that should only be released much later in a product's life cycle (ie when the successor is announced), though it could be used to find other exploits in the meantime.
 

Ericthegreat

Not New Member
Member
Joined
Nov 8, 2008
Messages
3,455
Trophies
2
Location
Vana'diel
XP
4,281
Country
United States
Private keys are used to sign things, so it would allow us to sign software to run on a Wii U. It's not the private key, though.

Even if they did find the private key, I sincerely hope they would not release it. fail0verflow made a mistake blowing their load, a so-called, pwn everything hack, too early into the PS3's life which resulted in Sony recovering and many people on newer firmwares unable to run homebrew. To do the same thing less than a month after the Wii U was launched would be a mistake. A discovery or hack like that should only be released much later in a product's life cycle (ie when the successor is announced), though it could be used to find other exploits in the meantime.

Why in the world would we want to wait longer for "homebrew", when new fw are released there are always fixes found in the future.
 

SifJar

Not a pirate
Member
Joined
Apr 4, 2009
Messages
6,022
Trophies
0
Website
Visit site
XP
1,175
Country
This is very interesting....

EDIT: Ok i got it, if you inspect the highlighted section(as element) its says sha1sum.
Nope.

HTML:
<div class="sha1sum"><span class="overflow">3d331b3165f9638c6cd6221702b2f736</span>f7fcf931</div>

The entire thing is "sha1sum", not just the highlighted section.
 
  • Like
Reactions: pelago

hergipotter

Well-Known Member
Member
Joined
Aug 28, 2007
Messages
100
Trophies
0
XP
123
Country
Gambia, The
@fail0verflow, 5 hours ago
As usual, we failed. Correction: 3d331b3165f9638c6cd6221702b2f736f7fcf931 . We forgot to trim a bit of garbage padding.
So it was no key. A key has no garbage padding. Maybe first WiiU firmware dump?
 

Cyan

GBATemp's lurking knight
Former Staff
Joined
Oct 27, 2002
Messages
23,749
Trophies
4
Age
45
Location
Engine room, learning
XP
15,649
Country
France
Sha1 of a key?
That way, they show to Nintendo that they found it (they can sha1 whatever they have), but don't provide it to other users.

Are they going to 29c3, or it's too late to register this year? maybe not enough data to show, but the first year they had things to display for the Wii.
Edit: even if we already know few things on WiiU/vWii, they could explain it to less scene-aware people.
 

muskieratboi

Rydian's got some competition!
Member
Joined
Sep 19, 2012
Messages
423
Trophies
1
XP
436
Country
It seems like fail0verflow won't be at 29C3 (according to the speaker's list today, unless that gets updated closer to time), but there is an interesting talk on 1024 Bit RSA attack vectors that seems rather interesting for the WiiU and 3DS (not to mention, like.. every 7th gen console out there!)

http://events.ccc.de/congress/2012/Fahrplan/events/5275.en.html

There's also a talk about low-cost microprobing which could be a possible alternative to the current 3DS decapping fundraiser: http://events.ccc.de/congress/2012/Fahrplan/events/5275.en.html
 

McHaggis

Fackin' Troller
Member
Joined
Oct 24, 2008
Messages
1,749
Trophies
0
XP
1,466
Country
Why in the world would we want to wait longer for "homebrew", when new fw are released there are always fixes found in the future.
Because the private key is the holy grail, no other hack compares. Waiting longer than three months after the previous exploithad been found would have meant more consoles hackable. But, of course, most people only care about themselves, as your post indicates.
 
  • Like
Reactions: [Truth]

SifJar

Not a pirate
Member
Joined
Apr 4, 2009
Messages
6,022
Trophies
0
Website
Visit site
XP
1,175
Country
Sha1 of a key?
A key probably wouldn't have garbage padding (by "garbage padding", they mean extra bytes added to the thing they took the hash of e.g. at the start or end; a key most likely wouldn't have that). Probably some file from the WiiU system menu or whatever.
 
  • Like
Reactions: pelago

Carl Rivest

Member
Newcomer
Joined
Nov 22, 2012
Messages
17
Trophies
0
Age
40
Location
Saint-Hubert, Quebec
XP
85
Country
Canada
Sha1 of a key?
That way, they show to Nintendo that they found it (they can sha1 whatever they have), but don't provide it to other users.

Are they going to 29c3, or it's too late to register this year? maybe not enough data to show, but the first year they had things to display for the Wii.
Edit: even if we already know few things on WiiU/vWii, they could explain it to less scene-aware people.

They are going to 29c3 this year, and they talks about Wiiu on this page!
http://events.ccc.de/congress/2012/wiki/Fail0verflow
 
  • Like
Reactions: lismati and Cyan
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: