Hacking Wii U Hacking & Homebrew Discussion

  • Thread starter Thread starter filfat
  • Start date Start date
  • Views Views 5,123,755
  • Replies Replies 21,104
  • Likes Likes 29
Ok thanks! So the work with the softmod for the wii was similar to that of the IOSU, in terms of work process?
The Wii had IOS, the Wii U has IOSU. They're essentially modules that contain the code for various functions (Amiibo, USB access, storage on NAND, etc) that games then tap into to use. So an exploit would allow us to call these functions in our own user-made applications and utilize them for whatever we want to do. Once users make said programs, the "workload" for the average user should be similar to something like the Wii Letterbomb Exploit, I assume. Follow certain steps to run the exploit and then it can install an application to the system menu.

EDIT for completeness: ^ Would only be true if we can break signature checking. Otherwise, we will have to run the steps at each boot, like we do right now with the kernel exploit. See below posts for details.
 
Last edited by fiveighteen,
  • Like
Reactions: TotalInsanity4
The Wii had IOS, the Wii U has IOSU. They're essentially modules that contain the code for various functions (Amiibo, USB access, storage on NAND, etc) that games then tap into to use. So an exploit would allow us to call these functions in our own user-made applications and utilize them for whatever we want to do. Once users make said programs, the "workload" for the average user should be similar to something like the Wii Letterbomb Exploit, I assume. Follow certain steps to run the exploit and then it can install an application to the system menu.
well i think the only reason why it was so easy with the wii (iirc) was that channels that were already installed werent checked for authenticity before launching, this means once you have a hack that can be installed to the home screen it will persist....from what i understand about the wii u this will not be the case unless someone figures out an exploit in the homescreen (similar to themehax on the 3DS) basically unless i have missed something the kernel exploit will probably still have to be triggered to then trigger the iosu exploit every restart of the console....unless its some huge IOSU exploit that works off the bat with no prior kernel exploit being required for a total take over
 
  • Like
Reactions: Azel
Alright, then you're confirming that the IOSU exploit being worked on also runs on 5.2.0FW, not just below? From what I've seen, only SSBU V1 has 5.2.0 FW, and is difficult to find. If needed, I'd be willing to contribute in any way I can to back porting the exploit to 5.1.2, as it's reasonably easy to find a B version MarioKart 8, which is what I used to update from my original 2.1.0FW. I'm actually in electronics engineering though, so code might not be my best contribution, but I can set up any debug tools needed on my Wii U to help out, including any hardware debug, like serial terminal output or otherwise. Else, I'll just backup everything on a hardware level and update to 5.3.2FW in hopes of a future release.

I may be wrong about it working on 5.2.0, and it may just be versions before that. But like I said, IOSU work is being done for more recent versions as well. Porting the 5.2.0 exploit will likely require software debugging experience, so hardware knowledge is unlikely to be very useful. If there is a large demand for backporting, our team may take up up.

well i think the only reason why it was so easy with the wii (iirc) was that channels that were already installed werent checked for authenticity before launching, this means once you have a hack that can be installed to the home screen it will persist....from what i understand about the wii u this will not be the case unless someone figures out an exploit in the homescreen (similar to themehax on the 3DS) basically unless i have missed something the kernel exploit will probably still have to be triggered to then trigger the iosu exploit every restart of the console....unless its some huge IOSU exploit that works off the bat with no prior kernel exploit being required for a total take over

This is correct - on the Wii, titles only had their signatures checked on installation, but the Wii U checks them every time they run. This makes it impossible to simply put an unsigned title on the system and run it. So a normal IOSU exploit that just runs from the browser won't be enough for a homebrew channel. However, if we manage to exploit the Wii U in the middle of its boot process (for example, if the title metadata parsing code in IOSU has an exploitable bug), we could break IOSU right at boot and disable signature checks early on.
 
I may be wrong about it working on 5.2.0, and it may just be versions before that. But like I said, IOSU work is being done for more recent versions as well. Porting the 5.2.0 exploit will likely require software debugging experience, so hardware knowledge is unlikely to be very useful. If there is a large demand for backporting, our team may take up up.



This is correct - on the Wii, titles only had their signatures checked on installation, but the Wii U checks them every time they run. This makes it impossible to simply put an unsigned title on the system and run it. So a normal IOSU exploit that just runs from the browser won't be enough for a homebrew channel. However, if we manage to exploit the Wii U in the middle of its boot process (for example, if the title metadata parsing code in IOSU has an exploitable bug), we could break IOSU right at boot and disable signature checks early on.
good to know i remembered that correctly from the fail0verflow presentation :P
 
So could you successfully install a channel that just wouldn't load? With just the browser / kernel ? I guess how that WUP installer works? With a one time installation would it still sit there and not bother with signature checks until you try to launch it?
 
So could you successfully install a channel that just wouldn't load? With just the browser / kernel ? I guess how that WUP installer works? With a one time installation would it still sit there and not bother with signature checks until you try to launch it?
probably the same as the 3DS, sit there installed but be unlaunchable unless you disable signature checks.....but i dont think anyone could say for sure until they try.....well unless they check the code, but i would assume it doesnt get checked until you try to boot it
 
probably the same as the 3DS, sit there installed but be unlaunchable unless you disable signature checks.....but i dont think anyone could say for sure until they try.....well unless they check the code, but i would assume it doesnt get checked until you try to boot it
After thinking about it, the closest thing to installing a channel would be that WUP Installer. But it cannot install something fresh even if it's free. It needs whatever tickets are. Since I don't think there's a method for installing fake tickets already then probably can't install a new channel. Maybe it's possible to mess with updates though if you're able to decompress and compress custom stuff into a game update or app. Then install it on the WiiU via WUP Installer if the tickets match you might have some custom code installed permanently on the WiiU, just not able to launch it.
 
Can anyone help me?. I'm trying to get hold of wj44. We spoke in a personal PM but he has not been active on here for a while he last mentioned to me he had updated his AIO OSDriver + PHP file and he says its really stable now I was asking him for a zip file of the htmls for myself cause I cannot build my own but I cannot find him to get an answer back has anyone made a new version of his aio osdriver that they could share with me to try out please? I'm sure he has hes own reasons in life not to be here I'm sure he is very busy I understand that but I would of liked a complete zip copy of his server files to self host myself as I do think his are really good to work with! He usually always keeps in touch with me from time to time and I respect that and he helps out more than enough for me so I don't think anything other is at an issue here I just think its a case of catching him on here at the right time. There is no way of downloading a complete package from him you have to build your own files but like I say I find that hard to do!
 
Last edited by Reecey,
Can anyone help me?. I'm trying to get hold of wj44. We spoke in a personal PM but he has not been active on here for a while he last mentioned to me he had updated his AIO OSDriver + PHP file and he says its really stable now I was asking him for a zip file of the htmls for myself cause I cannot build my own but I cannot find him to get an answer back has anyone made a new version of his aio osdriver that they could share with me to try out please? I'm sure he has hes own reasons in life not to be here I'm sure he is very busy I understand that but I would of liked a complete zip copy of his server files to self host myself as I do think his are really good to work with! He usually always keeps in touch with me from time to time and I respect that and he helps out more than enough for me so I don't think anything other is at an issue here I just think its a case of catching him on here at the right time. There is no way of downloading a complete package from him you have to build your own files but like I say I find that hard to do!
If he updated his AIO OSDriver, it's likely to be on his site already. Just rip it from there.... It's not rocket science. Lol.

It is computer science though I guess. :think:
 
damn it Nintendo, 5.4 is really starting to suck
Webkit exploits come up all the time, kernel exploits don't. Just relax and enjoy the fact that you're on a firmware with a working kernel exploit. Once interest increases, I'm sure 5.4 will be broken with the current kexploit and a new webkit exploit, shouldn't even need the new private one.
 
Webkit exploits come up all the time, kernel exploits don't. Just relax and enjoy the fact that you're on a firmware with a working kernel exploit. Once interest increases, I'm sure 5.4 will be broken with the current kexploit and a new webkit exploit, shouldn't even need the new private one.
I know, at least it's likely that Xenoblade X will come with 5.3.2 or lower since AFAIK didn't Wooly World come with 5.3.2 even though 5.5.0 was out?
 
About half the Wooly World copies came with 5.3.2, the other half came with 5.4. Unlike Wooly World copies, Xenoblade copies probably aren't just sitting in a warehouse so more amiibo can be manufactured for its release; and are actually probably not even printed yet. I would say that it is very likely they will come with 5.5 on them.
 
About half the Wooly World copies came with 5.3.2, the other half came with 5.4. Unlike Wooly World copies, Xenoblade copies probably aren't just sitting in a warehouse so more amiibo can be manufactured for its release; and are actually probably not even printed yet. I would say that it is very likely they will come with 5.5 on them.
Good thing we have the 5.5 spoof then eh?
 
  • Like
Reactions: I pwned U!
Webkit exploits come up all the time, kernel exploits don't. Just relax and enjoy the fact that you're on a firmware with a working kernel exploit. Once interest increases, I'm sure 5.4 will be broken with the current kexploit and a new webkit exploit, shouldn't even need the new private one.
there's no kernel exploit on 5.5 right? the private one is just a webkit exploit? T__T
 

Site & Scene News

Popular threads in this forum