Hacking Wii U Hacking & Homebrew Discussion

  • Thread starter Thread starter filfat
  • Start date Start date
  • Views Views 5,127,737
  • Replies Replies 21,104
  • Likes Likes 29
As awesome as this is, I don't think you'd be allowed to make/release exploits. You could leak them or something though I guess.


That's kind of what I was thinking ;). I wouldn't release anything through the official means (aka eshop), i would host w/e I develop directly from a web server somewhere ;) :P.

I just want access to the (limited) SDK as it would give me a lot more to work with :P.

The leaked SDK's for one are ILLEGAL to obtain and use. Not to mention are currently useless on a retail wii U.

code written under Unity or the Nintendo Web Framework will run on ANY retail Wii U :D
 
  • Like
Reactions: ChrisX930
I'm glad to see that someone's picked up the slack here :). I abandoned this project, but I'm happy to see others working on it :). As for initiating code execution, I think Marionumber1 is right. Its going to take more than just redirecting to our own custom file to get it to run. The code won't be signed properly so the Wii U will reject it right away. My original idea with this would be to use corrupted image files to trigger an exploit to get the code to run (much like how black hat hackers, use corrupted image files to install and run viruses without the user's consent or knowledge on a pc). Except in our case, we wouldn't be doing anything malicious with it.

If we can trigger an unhandled exception using a corrupted image file, we might be able to tweak it for code execution. In theory, if we can trigger code execution within Smash bros, it "should" give us the same privileges that the game itself has (meaning sd card access :D). We could then use this to launch simple homebrew apps off an sd card. Of course this would only result in a userland exploit so it would be limited, but it would be sufficient enough for basic homebrew apps (nes emulators, MAYBE some simplistic media players etc). If this exploit can be accomplished, someone could write code for a custom homebrew menu, that could be triggered with the exploit, that functions much like hbc on the wii/vWii and list all the homebrew apps on the sd card for the user to select w/e they want to launch. Of course, with a userland exploit NOTHING can be installed to NAND, but the menu could run entirely off the sd card.

I have a feeling if a userland exploit like this is developed, it would be extremely difficult for Nintendo to do anything about it (like with the original smashstack, heck it still runs on the vWii XD).

K. That is the backup plan if the current approach doesn't work. I was hoping that MN1 could help a little with kernel access, given he would know how to obtain it at that point.
 
K. That is the backup plan if the current approach doesn't work. I was hoping that MN1 could help a little with kernel access, given he would know how to obtain it at that point.


In game exploits are not likely to achieve kernel access (at least not easily, by any means). Marionumber1 mentioned a while back that there is some security measure in place called "NX" that make it really difficult to gain kernel access from within a game.
 
Maybe he could just make a game or app that coincidentaly has some security issues (Konami Code activated homebrew anyone?)

Good idea, not like Nintendo wouldn't check for security issues or anything before they distributed it.

...actually, that explains how we got Smash Stack AND Twilight Hack.

That's kind of what I was thinking ;). I wouldn't release anything through the official means (aka eshop), i would host w/e I develop directly from a web server somewhere ;):P.

I just want access to the (limited) SDK as it would give me a lot more to work with :P.

The leaked SDK's for one are ILLEGAL to obtain and use. Not to mention are currently useless on a retail wii U.

code written under Unity or the Nintendo Web Framework will run on ANY retail Wii U :D

This makes more sense, just re read that agreement you sign or whatever and check everything so you can do it without legal problems. Also, try not to announce that you found an exploit before you can show anything, I know someone with terrible typing skills who'll get upset.
 
  • Like
Reactions: TeamScriptKiddies
Good idea, not like Nintendo wouldn't check for security issues or anything before they distributed it.

...actually, that explains how we got Smash Stack AND Twilight Hack.



This makes more sense, just re read that agreement you sign or whatever and check everything so you can do it without legal problems. Also, try not to announce that you found an exploit before you can show anything, I know someone with terrible typing skills who'll get upset.


that was the plan. No early announcements and of course I'll read all the terms of the contract (if selected). You don't even get to see it unless selected apparently XD. We'll see what can be done, legally, if I'm picked :D.

Even if the terms of the contract don't allow it, it will still give me a lot of insight in how things work, which could ultimately lead to something down the road ;) without violating anything ;).

Acquire the necessary knowledge, terminate the contract (and of course remove all officially licensed SDK software from my pc) then download notepad++ and do all my coding in that XD. Its all Unity, HTML5, javascript, CSS etc so it can be done in any text editor really. I just need to learn my way around, that's the biggest thing really. Learn and memorize the libraries blah blah blah....
 
I might go 007, sneak into Nintendo headquarters, hang from a wire and spy on Reggie. Maybe ask my friend who knows people who know (because they say they do) what all of the keys are. Even boot1. I am going to sell my GameCube, Wii, N64, and not update my Wii U to play 10 year old (er) games. It will all work out, you'll see ;-) Oh, don't ask, I won't reveal their names and they won't share (exclusive club). Phase 2 only, lol.
 
no just my soldering iron, sizzling some solder :P
You already soldered your wires for the emmc/nand reading and writing. It is like a manic episode with racing thoughts and delusions of grandeur mixed in. I believe you have good intentions though. I came to realize that the choice is old firmware for crap I don't think is more interesting than newer Wii U games that will require newer firmware. Then get a new kernel and browser exploit? A kernel exploit is said to be inadequate for backup loaders (piracy, lol). It is great work but a choice people need to make on their own.
 
I know this thread got distracted by other tangents recently but really no additional information on this topic by zecoxao:
https://gbatemp.net/goto/post?id=5252719#post-5252719
Or my respond?
https://gbatemp.net/threads/wii-u-hacking-discussion.367489/page-111#post-5254001

Does anyone know if this topic was discussed elsewhere? (like another forum,etc). I have not found anything similar elsewhere.
No. I've been working on it a little bit but nothing has come of it. I'm waiting for someone to reply to me currently.
 
  • Like
Reactions: Bug_Checker_
  • Like
Reactions: Fpsrussia117
I know this thread got distracted by other tangents recently but really no additional information on this topic by zecoxao:
https://gbatemp.net/goto/post?id=5252719#post-5252719
Or my respond?
https://gbatemp.net/threads/wii-u-hacking-discussion.367489/page-111#post-5254001

Does anyone know if this topic was discussed elsewhere? (like another forum,etc). I have not found anything similar elsewhere.

I missed the post before it was censored, but if they were the keys that are in all the scene release nfo's then this is your answer:
https://gbatemp.net/threads/theres-...r-decrypting-games.374735/page-4#post-5182522
 
He is on twitter, tweet him to ask.

That's a little too public. I know once it was posted to a forum it should be assumed that it is public knowledge(even if removed). But I believe that they were removed not because of secrecy but to compile with forum rules (out of "fear" in case they were important private keys).

I missed the post before it was censored, but if they were the keys that are in all the scene release nfo's then this is your answer:
https://gbatemp.net/threads/theres-...r-decrypting-games.374735/page-4#post-5182522

No, they were almost certainly not the released disc's AES keys for the update partition(commonly in released nfos).
But they could have been keys for a specific disc's game partition that would allow access to the formerly encrypted game partition's FST and files. But basically a lot of stuff is signed/encrypted in the WiiU so with seeing the keys(that were posted) it is anyone's guess.
I just thought this may have been discussed elsewhere or posted to pastebin or pastie.
 
No, they were almost certainly not the released disc's AES keys for the update partition(commonly in released nfos).
But they could have been keys for a specific disc's game partition that would allow access to the formerly encrypted game partition's FST and files. But basically a lot of stuff is signed/encrypted in the WiiU so with seeing the keys(that were posted) it is anyone's guess.
I just thought this may have been discussed elsewhere or posted to pastebin or pastie.


The keys that were posted belong to crediar's private WiiU disc utility and are most likely specific to a previously released game disc.
 
Has anyone tried to "reverse engineer" WiiU formatted HD's beyond the "It doesn't mount under Windows/Linux" stage? Had friends WiiU under modding couple of weeks ago, but hadn't time to format removable disk under WiiU and check the contents myself.

I doubt Nintendo has written a new filesystem from scratch, but rather used an existing and proven one with obfuscated FS tag. One FS candidate I'd tested would definitely have been FreeBSD's GELI or gbde encrypted UFS. Of course if someone doesn't mind making an small - and even empty - image of WiiU disk, I'll could try checking what it says if mounting on BSD.
 

Site & Scene News

Popular threads in this forum