Hacking Wii U Hacking & Homebrew Discussion

  • Thread starter Thread starter filfat
  • Start date Start date
  • Views Views 5,122,406
  • Replies Replies 21,104
  • Likes Likes 29
I saw TSK's video about the possibility of smash stack Wii U. In the SD's /private/Nintendo Wii U/app/AXFJ/ folder, I've found a file named AXxx_Album.dat

The name of the final folder and .dat file may change, but when I open the .dat file with TextEdit It appears to be somewhat readable. The names of each image followed by the name of the folder they are in under DCIM appears at the top after some mumbo jumbo. I think this may be the key to decrypting the .bin files TSK's previously mentioned.

Also, under /private/lib/photo I found a file named phtcache.bin

This file appears to be encrypted like the other .bin files.
 
anyway, guess i'll explain. those keys decrypt a certain title key of the released wii u games that were published on torrent sites. it's possible to obtain content from them. the origin of those keys, i will not reveal.
think of them as the 3ds keys for decrypting the game and extracting resources, except for wii u
 
anyway, guess i'll explain. those keys decrypt a certain title key of the released wii u games that were published on torrent sites. it's possible to obtain content from them. the origin of those keys, i will not reveal.
think of them as the 3ds keys for decrypting the game and extracting resources, except for wii u

Are you a dev? Is that how you got them?
 
Are you a dev? Is that how you got them?

a person i knew gave me a program and asked me to analyze it and find the common key, if it existed. since i'm NOT a dev, BUT i know how to find keys in IDA, i asked a friend of mine for confirmation. he said that those keys decrypted a title key from NCCH header. unfortunately, since the hash doesn't match, and didn't back then, we stood there and wrapped up the subject.
 
a person i knew gave me a program and asked me to analyze it and find the common key, if it existed. since i'm NOT a dev, BUT i know how to find keys in IDA, i asked a friend of mine for confirmation. he said that those keys decrypted a title key from NCCH header. unfortunately, since the hash doesn't match, and didn't back then, we stood there and wrapped up the subject.

It wouldn't be in any program. It's in the OTP for a reason.
 
Yes he said he was a dev and all ov a sudden they ended up on his lap.....

I wasn't asking you.

a person i knew gave me a program and asked me to analyze it and find the common key, if it existed. since i'm NOT a dev, BUT i know how to find keys in IDA, i asked a friend of mine for confirmation. he said that those keys decrypted a title key from NCCH header. unfortunately, since the hash doesn't match, and didn't back then, we stood there and wrapped up the subject.

Okay, cheers, I just wanted to see if jimmy was full of crap. Shame it didn't have the common key, as unlikely as it was to obtain they key in the first place.
 
  • Like
Reactions: jammybudga777
Haha, you are saying you could code a program to get the keys out of the OTP? My head is still foggy from the NFL playoffs, lmfao.

No, from what I've gathered from the people who /do/ have the common key they've made programs to do stuff with it, like automatically decrypt/extract ISOs or download/decrypt whatever from NUS.
 
No, from what I've gathered from the people who /do/ have the common key they've made programs to do stuff with it, like automatically decrypt/extract ISOs or download/decrypt whatever from NUS.

which is what the program did, or does. the issue i'm having is why the hash doesn't match.
edit: i don't understand anything of wii u, so please clarify this for me:

how many title keys are there? one only or several per game?
 
I mean, the developers who have the common key are greedy jerks and refuse to release the common key or these magical ISO decrypting programs, TSK's work is likely to be the only thing anyone's more than willing to release. Methinks the common key possessors received threats from other hackers and/or kickbacks promising not to release it to the public, because reasons. People don't respect TSK because they think he's "trolling" (which is a flat out lie), without any substantiation to their claims. Anyone who bashes TSK for some half-assed unsubstantiated reason deserves no respect.
Nothing says "screw you pleb users" better than with dev teams refusing to release their work and bragging about what they can do. :rolleyes: They're the real trolls here.

i see from your post count that you are an avid user, i will try my best to put my words in a respectful manner.

THE DEVELOPERS DO NOT OWE YOU OR OWE ANYBODY A THING, the knowledge they acquire to "do/hack" such things is tedious to learn and they have the right to develop exploits and withhold them because of numerous reasons :
a) their livelihood depends on selling bugs for money
b) legal problems
c) they think that piracy is morally wrong so they don't publish exploits that help do so ( white hats )
d) hurts the company they love and ruins possible games
and many numerous "personal" reasons of their own

you have to comprehend that if you want something you either have to do it yourself or wait for someone to do it for you on their pace and by their rules

i really hope that you understand this, i have been an avid follower of this topic and your replies honestly tick me off .
 
Update on the mysterious smash files:
I placed a new photo in the 100NIN04 folder (within DCIM) and put it's name in the .dat file the same way the other file names were. When I reloaded the album menu it said that my album data was corrupted and it would regenerate it. There are just as many duplicates of the same passage their are snapshots with game-generated bin files. I think the game first checks to make sure the image files match the code in the .dat file and then lets you in to the snapshot menu. It then verifies each snapshot with it's corresponding .bin file and gives you the no sign if they don't match. It may do some magic with photocache.bin as well.

Edit: The album data regeneration message appeared on startup.
 
  • Like
Reactions: Gruntzer
it is strange there are so many ways to leak something without an easy detection of who you are and from where you leaked internet cafe is one via anonymous servers etc ,it is quite easy , piracy on the other hand will grow even with or without keys
remember 3ds none released anything and boom gateway came and i respect that cause prior it we had zero shots on homebrew ,it seems nowadays a lose of cause i am starting to move out to pc gaming i had a ps4 and cause of restrictions and cost sold it wii u was a day one choice but now it is collecting dust cause i didnt upgrade it . i HOPE scene will pass over the point of no release or it will be lost, no benefit of bragging just use it and keep it yourself if you dont wish a release.
 
Another Smash Stack Wii U Update:
Here are things I assume from my experimentation of messing with the .dat file:
  • The .dat file is created by a file and possibly the system (I assume phtcache.bin, which is encrypted)
  • If phtcache.bin is not user specific: the game also gets some other info from the system (I saw my name many times in the .dat file)
  • If phtcache.bin is missing, the game will replace it without any alert
  • If the .dat file is missing or not verified, the game will regenerate it.
  • The .dat file contains text that notes each game-generated snapshot, which the game then uses the corresponding .bin files within /DCIM/100NIN04/ to determine if each image is valid
  • If the .bin file and/or it's corresponding .jpg file is missing, but the .jpg file is still listed in the .dat file, the game will replace that image with the "no sign" shown in TSK's video
  • The same will happen if the .jpg file is not verified by the .bin file
What this means:
  • In order to make an exploit using SSB4, we need to crack open phtcache.bin and possibly require user input
  • We would either need the album's .dat file to be verified and point to exploit code, or point to a corrupted image that run's code (This is how many viruses work)
  • I have only ever been on the receiving end of homebrew. I have school and many other things picking up, plus I don't have any experience with developing exploits.
  • I am sharing all this information so that others know where to start if they wan't to use this exploit.
  • I probably won't ever pick up this project again unless if someone else turns it in to a working exploit. That said, feel free to ask me any questions you have if any part of this post was unclear. I won't know the answer to anything else.
  • Finally, thank you TSK for sparking my interest in this mini project.
 
Guys, c'mon. No one likes to see 3 pages of crap about who releases what. So the_randomizer and Kelton2 and whoever else feels they need to discuss the merits of anti-piracy, take it somewhere else. Thanks to IbbyPlays for making a post which is exactly what people would like to see upon entering this thread.
 
Private keys arent being released for legal reasons, plain and simple.

By releasing instructions for how to dump/obtain the keys, you have a loophole ;). Legal responsibility for misuse falls solely on the end user
 
Guys, c'mon. No one likes to see 3 pages of crap about who releases what. So the_randomizer and Kelton2 and whoever else feels they need to discuss the merits of anti-piracy, take it somewhere else. Thanks to IbbyPlays for making a post which is exactly what people would like to see upon entering this thread.
Anything "serious" will be in a private message and likely IRC. 100% on IRC. Nwplayer1234 and marionumber1 stop by, are very patient, and give useful posts and replies. Never too late to hit the "reset" button in a lot of ways. You can hit "ignore" and then remove the "fluff." I like to glance over it all for a laugh. I have more fun messing with sports forums than video game ones. I buy all of my games and have anything I could want on other devices so aside from a Game Genie type of function and/or a backup loader (others will use it for piracy, lmfao) I really have no use for much of this.

99% want piracy and everyone knows it. The odds are if people cannot find a kernel exploit after the browser bug then they won't find an IOSU exploit. Chadderz and Bean thinking "obfusgation" will protect their exploit are kidding themselves. Whatever NWplayer1234 and MN1 have seems to be a different exploit. As it is, you'll have a choice; stay on an exploitable firmware without using the internet for homebrew you can already get elsewhere (or buy a full system for $5 to $15, lmfao) or update when the great game you've been wanting comes out. From what I've read, the kernel exploit won't allow the region free or "firmware spoofing" people say they want. So really endoverend, not sure if you are like me, but aside from a way to revert (like a 360 with a hardware flasher) or with the Wii and "bootmii" or "priiloader" and an IOSU exploit where I can do what I want (a lot more than with a kernel or "userspace" exploit that is not persistent) it is really not worth it. No disrespect to MN1 or NWplayer who seem to be very nice. Some will stay on 5.2.0 or lower and not get Zelda or other games when Nintendo makes those games require 5.4 or higher, lol. I have a big stack, for me, of about 10 Wii U games that have all been played extensively by me and my family.
 

Site & Scene News

Popular threads in this forum