Hacking Have the wii u debug ancast keys been released?

zecoxao

Well-Known Member
OP
Member
Joined
Dec 25, 2013
Messages
379
Trophies
1
Age
33
XP
1,703
Country
So far, all i've seen on the web are the retail ancast keys. And in the retail kernel there are no symbols whatsoever. So i was wondering if there have been released the debug ancast keys (and ivs) so that it's possible to decrypt the debug kernels in the sdks :)
 
  • Like
Reactions: Simonwayneee

Hykem

Well-Known Member
Member
Joined
May 22, 2014
Messages
109
Trophies
0
Age
123
XP
2,017
Country
No need to open up a new thread just for asking this. :P

The keys haven't been released yet, probably due to lack of interest? I doubt we would find any relevant additional symbols in the debug versions, but, from a documentation perspective, I do think we should try to grab them as well.
All that's necessary is for someone with a devkit to attempt the already public method to dump the Espresso's OTP.
 
  • Like
Reactions: zecoxao and moops44

palantine

Well-Known Member
Member
Joined
Oct 5, 2014
Messages
174
Trophies
0
Age
38
XP
593
Country
Italy
No need to open up a new thread just for asking this. :P

The keys haven't been released yet, probably due to lack of interest? I doubt we would find any relevant additional symbols in the debug versions, but, from a documentation perspective, I do think we should try to grab them as well.
All that's necessary is for someone with a devkit to attempt the already public method to dump the Espresso's OTP.

If anyone on here has a devkit, I'd be interested in buying it. Also if anyone has a shop unit, those are also very interesting as well.

-palantine
 
  • Like
Reactions: zecoxao

Hykem

Well-Known Member
Member
Joined
May 22, 2014
Messages
109
Trophies
0
Age
123
XP
2,017
Country
I don't think devkits can actually run vWii mode, which is the only way to reset the PPC until we have IOSU kernel code execution.

Hm, didn't know that. Well, that explains why no one has done it then.
In fact, it doesn't seem logical for a devkit to support vWii mode since the goal is to develop Wii U applications (and not backwards compatibility, which sole responsible is Nintendo itself).
 

palantine

Well-Known Member
Member
Joined
Oct 5, 2014
Messages
174
Trophies
0
Age
38
XP
593
Country
Italy
Hm, didn't know that. Well, that explains why no one has done it then.
In fact, it doesn't seem logical for a devkit to support vWii mode since the goal is to develop Wii U applications (and not backwards compatibility, which sole responsible is Nintendo itself).

If we have kernel PPC access via the browser exploit, what's preventing us from leveraging that to dump the key? Sure it would require some actual thought rather than reusing the retail exploit exactly but I don't see what else is in the way.

-palantine
 

Marionumber1

Well-Known Member
Member
Joined
Nov 7, 2010
Messages
1,234
Trophies
3
XP
4,045
Country
United States
If we have kernel PPC access via the browser exploit, what's preventing us from leveraging that to dump the key? Sure it would require some actual thought rather than reusing the retail exploit exactly but I don't see what else is in the way.

-palantine

The boot ROM, which runs on PPC reset, disables the keys once it's done using them, and they can only be reenabled through a PPC reset. We don't have the ability to do that - only the ARM does - and even if we could do that, we'd lose code execution.
 

palantine

Well-Known Member
Member
Joined
Oct 5, 2014
Messages
174
Trophies
0
Age
38
XP
593
Country
Italy
The boot ROM, which runs on PPC reset, disables the keys once it's done using them, and they can only be reenabled through a PPC reset. We don't have the ability to do that - only the ARM does - and even if we could do that, we'd lose code execution.

Hypothetical way to do it:

1. Perform browser kexploit to own the PPC in wiiu mode
2. execute the retail rpl that launches vWii mode, patch as necessary
3. perform vWii exploit

I seem to remember f0f mentioning there is a certain code sequence used to change between vWii and wiiu modes and vice versa. On vWii its the new title that lets you switch back to WiiU mode.

Basically, if we have full PPC control on a devkit, I'm pretty sure we should be able to boot into vWii. Perhaps Nintendo actually did go the extra mile and disable it in IOSU but its at least worth trying.

-palantine
 

Marionumber1

Well-Known Member
Member
Joined
Nov 7, 2010
Messages
1,234
Trophies
3
XP
4,045
Country
United States
Hypothetical way to do it:

1. Perform browser kexploit to own the PPC in wiiu mode
2. execute the retail rpl that launches vWii mode, patch as necessary
3. perform vWii exploit

I seem to remember f0f mentioning there is a certain code sequence used to change between vWii and wiiu modes and vice versa. On vWii its the new title that lets you switch back to WiiU mode.

Basically, if we have full PPC control on a devkit, I'm pretty sure we should be able to boot into vWii. Perhaps Nintendo actually did go the extra mile and disable it in IOSU but its at least worth trying.

-palantine

The code to switch into vWii mode is ARM code (cafe2wii). That being said, devkits have the ability to install titles, so cafe2wii and the vWii titles might be possible to install. I'm not sure how strictly signatures are checked.
 

gamesquest1

Nabnut
Former Staff
Joined
Sep 23, 2013
Messages
15,153
Trophies
2
XP
12,247
I think you can downgrade devkits to any version. Are there any details about this IOSU exploit?

-palantine
nope, afaik the iosu stuff is all very closely guarded by a small handful of dev's, (only one of which has any interest in eventually sharing his results afaik).....tbh idk how useful it would be in this regard as there is very little info about what is done or not regarding iosu...looking into installing cafe2wii might be a more immediate plan as i doubt any iosu stuff will be getting shared for a while
 

I pwned U!

I am pleased to beat you!
Member
Joined
Jun 14, 2013
Messages
927
Trophies
3
Age
28
Website
gbatemp.net
XP
680
Country
United States
I hope that something becomes of this. It would be interesting to decrypt dev titles and projects compiled with the SDK, extract their files, and see if they can boot on 5.3.2 retail units with Loadiine.

This could then lead to a way for licensed developers to test their projects on retail Wii U consoles instead of feeling so pressured to spend lots of money on dev units.
 

palantine

Well-Known Member
Member
Joined
Oct 5, 2014
Messages
174
Trophies
0
Age
38
XP
593
Country
Italy
I hope that something becomes of this. It would be interesting to decrypt dev titles and projects compiled with the SDK, extract their files, and see if they can boot on 5.3.2 retail units with Loadiine.

This could then lead to a way for licensed developers to test their projects on retail Wii U consoles instead of feeling so pressured to spend lots of money on dev units.

Pretty sure you can do this now as Loadiine will boot any rpl/rpx, not just signed ones. Of course you wouldn't be able to use the debugging tools with it, but its a solid start.

-palantine
 
  • Like
Reactions: I pwned U!

I pwned U!

I am pleased to beat you!
Member
Joined
Jun 14, 2013
Messages
927
Trophies
3
Age
28
Website
gbatemp.net
XP
680
Country
United States

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    K3Nv2 @ K3Nv2: Crowbar?