Hacking Wii U Hacking & Homebrew Discussion

  • Thread starter Thread starter filfat
  • Start date Start date
  • Views Views 5,123,840
  • Replies Replies 21,104
  • Likes Likes 29
Hasn't it already been confirmed that the WiiU doesn't have eMMC NAND? Therefor this won't work.

Edit: I'd be glad to be proven wrong. :) I already tried this before though on my WiiU.
What happened? how did you go about it?
 
Is it possible that the FW is encrypted AES-256 +Salt...? That is what my extremely uninformed about decryption self has come up with...


****I think I have some reading to do, anything anyone can suggest?
 
Last edited by mixelpixx,
Is it possible that the FW is encrypted AES-256 +Salt...? That is what my extremely uninformed about decryption self has come up with...


****I think I have some reading to do, anything anyone can suggest?
Yes, but that would mean that if we manage to get all the keys actually present in the console, we could legitimately sign our own CFW, which would be weird as even the old 3DS had a protection against that (using asymmetric cryptography).

If you really don't know anyting about cryptography, here is some interesting reading : http://www.thegeekstuff.com/2012/07/cryptography-basics/
 
***I found this, but I know squat about Python. It is supposed to be able to identify how something is encrypted -- if I understand correctly. What is the best Python Environment to run on Win 7 64bit so I can run this script?

http://www.mediafire.com/view/i3iob9aoa37j5t6/Hash_ID_v1.1.py
This is a Linux script. It works right away then.

Type the following command on the terminal:
Code:
./Hash_ID_v1.1.py
Also you can install Python 2.7.7. on Windows and run the script by double-clicking it.

Result:
562p49dc.png
 
  • Like
Reactions: Margen67
What happened? how did you go about it?
Solder wires to the clk,cmd,data points.
Connect wires to SD card reader, bridge points/add 50k resistor on SD card reader.

And nothing.
But it is all on the WiiUBrew wiki...
 
I did this before with another card reader, I just wasn't sure of the validity of what came out. I will say I think some card reader chipsets don't work, or don't work well. WHat do I have -- umm don't know, I buy them then remove the case and even replace some thin wires with slightly heavier gauge. The controller on the NAND (unconfirmed though) is probably the usual 8051 micro controller from the 80's -- with all the cmds still present per the spec. So you should be able to bit bang it out, two wire it out, JTAG (if we , or I knew where those points were), or a pure disk image (win32imager). The image is useless so far to anyone but the original console from whence it came, it's encrypted, data, and not in any form usuable by anyone except to flash an exact image to the chip.

Thats it. exciting I know.


And thank you for the crypto basics, I appreciate that. I have worked a tiny bit with it, if you look at the wiiu app me an mysterio made you will see will encrypt all the naughty parts and hide em. I understand just a little more than a beginner. Tiny bit.




Its the "What the F#CK is this !?!?!?" analysis I am not good at...
 
So I wish I knew how far people were along for real. I wouldn't expect to see it in public, but as soon as i started investigating firmware, also going through the Kit, and knowing what keys are available -- seems like everything is already in place. and in my research I came across this from a Unknown (no names, just anonymous posts, so take with large grain of salt):


Webkit exploit is one of the access (Crashing the Wii U, again PPC Reset, patch execute code).
Wii mode is one of the access (Patch just before going into the Wii mode, PPC reset)
Gamepad Wii U is opening every door for the keys that you need (Important information exchange between the Wii U and the Gamepad in 5Ghz (Monitor mode), listen carefully when you press power button on Wii U). You need a Wifi module that support the 5Ghz frequency (Debian recommended to deal with few stuff)
Also open your eyes/mind, check the settings on Wii U and developer tools.


Think I am getting snow blind from looking too hard, sounds legit, from what I know, but would suggest things are further along then publicly stated, again IF true..

Also came with warnings about the upcoming NX system for Nintendo products, explaining that it will effectively close all exploits that are present up to this point. Again, this is the internet, so we know everything posted is absolutely true. :)
 
This is a Linux script. It works right away then.

Type the following command on the terminal:
Code:
./Hash_ID_v1.1.py
Also you can install Python 2.7.7. on Windows and run the script by double-clicking it.

Result:
562p49dc.png


I installed 2.7 64 bit first, it wouldn't see the install. Then I used the 32bit and it would run, but doesn't function. I am on Win 7 64bit, and I guess I need a linux boot somewhere, maybe on my laptop..
 
Just release the kernel exploit god damn! These things are known to hold up the scene from unfolding! Damn! The same shit happened to the ps3 scene! Release your findings so others can contribue and learn. People think too much about credit !

BTW this comment is not intended to hurt anyone, just wanted to let some stuff out LOL :p !
 
  • Like
Reactions: fatsquirrel
Just release the kernel exploit god damn! These things are known to hold up the scene from unfolding! Damn! The same shit happened to the ps3 scene! Release your findings so others can contribue and learn. People think too much about credit !

BTW this comment is not intended to hurt anyone, just wanted to let some stuff out LOL :p !
that triggerfend me.
Please be patient godammit.
 
Just release the kernel exploit god damn! These things are known to hold up the scene from unfolding! Damn! The same shit happened to the ps3 scene! Release your findings so others can contribue and learn. People think too much about credit !

BTW this comment is not intended to hurt anyone, just wanted to let some stuff out LOL :p !

What do you want to do with it? There wouldnt be much for the end user until people start developing on it,calm yourself.
 
Awesome! Except for the fact that I'm on 5.3.2
Hey Marionumber1, You recently said you had ROP capabilities for 5.3.2 and were working on getting execution of C code. Any updates on the progress of 5.3.2 C code execution?
Debugging/fixing
 
Where can we find the "payload500.html" for example?
It's not in the project?

Really kinda interested what the ROP does and how it works.
(And checking out what I can do on my 2.1.0E myself)

Thanks in advance guys!

Edit 2:
Ok, so the payload html file is created via some python code.
Just... how did you guys dump the Memory? (And at what time?)

---

Edit 1:
So essentially the 3DS method? Do you have a compatible SD adapter?
Yes, it is.

But while the same SD adapter worked for my 3DS, @mixellpixx seems to have taken a more in-depth look into this. I hope he can soon provide us with more information, if tries to do it. :)
 
Last edited by Adr990,

Site & Scene News

Popular threads in this forum