Hacking What is stopping us from hacking into the ISOU using the Kernel exploit?

ARVI80

Well-Known Member
Member
Joined
Feb 25, 2016
Messages
197
Trophies
0
Age
43
Location
UK
XP
315
Country
iosu is possible, full cfw is possible, console bricking is very possible and very likely as it stands.

Get a second hobby and be prepared to wait, and wait some more, and wait some more on top of that. :D
 

Wishi

Rareware Gamer
Member
Joined
Nov 24, 2015
Messages
219
Trophies
0
Age
27
XP
297
Country
Mexico
They say they already have it, but they want the Wii U to be dead to Nintendo before they release it. It'd be fucking stupid if they released it now.
The problem here is that The Wii U will be Dead not only for nintendo but for its users as well :(
 

Datalogger

Living the Dream
Member
Joined
Dec 21, 2009
Messages
416
Trophies
1
Location
Maui
XP
706
Country
United States
Smea, actually, released a video of his working implementation of the IOSU exploit.
Watch the vid again.
You see it boot from NAND, run an "IOSU exploit", reboot FW.IMG from an SD card.
What you don't see is it doing anything else because it would panic as soon as it tried to do much else.
H and S both realized that the ARM was more than they could handle, hence they gave up defeated.

It's easy to say "oh, ummm we did it and you will just have to believe us - but we aren't going to release it because...because.... urr, ummm...because we know what's best for you... yeah, that's the ticket, we are thinking of you!"

It's all BS.
They never got it to work.
If they did, their ego's would have forced them to release it - plain and simple.
 
Last edited by Datalogger,

Logan Pockrus

Knawledge is key.
Member
Joined
Jan 1, 2016
Messages
1,338
Trophies
0
XP
1,062
Country
United States
Watch the vid again.
You see it boot from NAND, run an "IOSU exploit", reboot FW.IMG from an SD card.
What you don't see is it doing anything else because it would panic as soon as it tried to do much else.
H and S both realized that the ARM was more than they could handle, hence they gave up defeated.

It's easy to say "oh, ummm we did it and you will just have to believe us - but we aren't going to release it because...because.... urr, ummm...because we know what's best for you... yeah, that's the ticket, we are thinking of you!"

It's all BS.
They never got it to work.
If they did, their ego's would have forced them to release it - plain and simple.
That's pretty cynical (for lack of a better term). But, considering Smea has a master's in Computer Science, you can safely assume he knows what he's doing. But it wasn't just him and Hykem; there were many more people contributing in some way shape or form. Anyway, the keys Hykem leaked? Proven to be legitimate. The video Smea posted? Well, as you made obvious, we can never be truly sure what goes on "behind the scenes" as they say, but Smea had a custom titled installed. Why is this relevant? Well, that would require signature patches, which requires an IOSU exploit. Things check out, to me. I think you've been burned one too many times by developers over-promising.
 

Datalogger

Living the Dream
Member
Joined
Dec 21, 2009
Messages
416
Trophies
1
Location
Maui
XP
706
Country
United States
If all you need as proof is to add a title to the menu, just IDA hack system_config_tool.rpx to run and you're done.
The ARM is never going to allow you to run it, but changing the menu is no big deal.
You need to look closer at what the boots have in store that keep this from ever being possible.
 
  • Like
Reactions: Subtle Demise

Logan Pockrus

Knawledge is key.
Member
Joined
Jan 1, 2016
Messages
1,338
Trophies
0
XP
1,062
Country
United States
If all you need as proof is to add a title to the menu, just IDA hack system_config_tool.rpx to run and you're done.
The ARM is never going to allow you to run it, but changing the menu is no big deal.
You need to look closer at what the boots have in store that keep this from ever being possible.
Did you watch the video? He did run it. It was a port of Yeti3ds.
 

Datalogger

Living the Dream
Member
Joined
Dec 21, 2009
Messages
416
Trophies
1
Location
Maui
XP
706
Country
United States
And you can run any HB from just a kernel x.... no need for IOSU and no proof, as expected.

It's no use to keep this going.

You think they did it and kept it from you because they know what's best for you... - please go ahead and keep believing this if it makes you feel better. I have no problem with that.

I know it was all a scam and they couldn't get it to work reliable so they came up with "FBI raids", "schools too much, no time to finish it" and "you can't handle this type of thing" of excuses - plain and simple.
 

Logan Pockrus

Knawledge is key.
Member
Joined
Jan 1, 2016
Messages
1,338
Trophies
0
XP
1,062
Country
United States
And you can run any HB from just a kernel x.... no need for IOSU and no proof, as expected.

It's no use to keep this going.

You think they did it and kept it from you because they know what's best for you... - please go ahead and keep believing this if it makes you feel better. I have no problem with that.

I know it was all a scam and they couldn't get it to work reliable so they came up with "FBI raids", "schools too much, no time to finish it" and "you can't handle this type of thing" of excuses - plain and simple.
Alright, I agree; let's end this. But as a final thought, Hykem was full of shit when it came to his excuses. I'm not omniscient or anything, but as other reputable devs said he was legitimate, I think he was, as well.

/end of stupid argument.
 

depaul

Well-Known Member
Member
Joined
May 21, 2014
Messages
1,293
Trophies
0
XP
2,950
Country
France
The IOSU is being worked on, and is probably already near completion. Probably DEVs just need a bit of luck in order to fully complete the exploit.
I agree with what's posted above there are some DEVs that were able to discover interesting things but instead of releasing their knowledge they preferred to show off without releasing anything, and then quit.
 

NWPlayer123

Well-Known Member
Member
Joined
Feb 17, 2012
Messages
2,642
Trophies
0
Location
The Everfree Forest
XP
6,693
Country
United States
eYAhTPl.gif
 

punderino

aka Big-PeePee Swinger
Member
Joined
Jan 5, 2016
Messages
1,247
Trophies
0
Age
32
Location
Kansas City, Missouri
Website
www.anus.trade
XP
2,507
Country
United States
Seems like it would be a straight shot from there...
ISOU, please stop. <---- Title is wrong. Let me send this to Ryan to annoying him; the actual question here. I won't work. It just doesn't work like that.

--------------------- MERGED ---------------------------

Well yeah, but couldn't someone just code up an app that you run from the Kernel exploit that turns off/disables the ISOU?
It's IOSU, not ISOU. Please, this is making me suicidal.
 

Goopyjoe

Member
OP
Newcomer
Joined
Jun 17, 2016
Messages
14
Trophies
0
Age
26
XP
69
Country
United States
ISOU, please stop. <---- Title is wrong. Let me send this to Ryan to annoying him; the actual question here. I won't work. It just doesn't work like that.

--------------------- MERGED ---------------------------


It's IOSU, not ISOU. Please, this is making me suicidal.

Does it really matter? You still know what I'm talking about -_-
 

punderino

aka Big-PeePee Swinger
Member
Joined
Jan 5, 2016
Messages
1,247
Trophies
0
Age
32
Location
Kansas City, Missouri
Website
www.anus.trade
XP
2,507
Country
United States
Does it really matter? You still know what I'm talking about -_-
Yes. It does. You created a post for something that you could of found in other threads, and then proceeded to even spell it incorrectly meaning you didn't even look enough to see how it was spelled. :^ )
 

Billy Acuña

Well-Known Member
Member
Joined
Oct 10, 2015
Messages
3,126
Trophies
1
Age
31
XP
3,701
Country
Mexico
The only ones that have IOSU is Smea (which is agaist piracy and he is alreally out from the Wii U Scene) and "the unnamed" (which is dissapear thanks to the shitposting on this forum and no ones know about him).
 

punderino

aka Big-PeePee Swinger
Member
Joined
Jan 5, 2016
Messages
1,247
Trophies
0
Age
32
Location
Kansas City, Missouri
Website
www.anus.trade
XP
2,507
Country
United States
The only ones that have IOSU is Smea (which is agaist piracy and he is alreally out from the Wii U Scene) and "the unnamed" (which is dissapear thanks to the shitposting on this forum and no ones know about him).
Not true. There's a handful of developers with a 5.2.0 Wii U and the IOSU exploit that's widely known for it. Just have to write it yourself. Hykem left because he quit giving a shit. Never was raided, he's still in IRC. xDD
 
Joined
Apr 19, 2015
Messages
1,023
Trophies
1
Location
Stuck in the PowerPC
Website
heyquark.com
XP
3,908
Country
Australia
Just a quick explanation of the whole PPC=/=IOSU thing for the uninformed among us. This is heavily oversimplified.

In essence, the Wii U has two processors (well, technically three but the third one is boring and has to do with emulating a specific, obscure bit of the vWii). Anyway! Two processors - The PowerPC (what we can run code on using browserhax/take full control of with kernel) and the ARM (IOSU). These are completely separate entities, but they can communicate. This isn't like the Wii, however - the IOSU watches the PowerPC like a hawk and halts the system if the code falls out of line. This is done through a permissions system - The IOSU "knows" what app is running (Mii Maker, Internet Browser, retail disc etc.) and changes the conditions appropriately. For example, the Internet Browser has limited memory, so if we try to use memory that the Internet Browser can't use under browserhax the IOSU rather firmly stops that. Loadiine works by loading Mii Maker and quietly replacing it with a game. The IOSU still thinks Mii Maker is running (and applies limits as such - No USB, limited internet etc) while the PowerPC is actually running something completely different.
The point of all this is that while we can fool the IOSU, there's no simple way to modify it. Mii Maker will never need to fiddle with system settings or poke around the system's boot code, so the IOSU doesn't allow it. Since most homebrew runs under Mii Maker now, these restrictions apply to us as well. (And no, there isn't another app we can inject into to get around this. Someone public would have figured it out by now.)
There's another thing worth noting: Yes, the PowerPC can directly communicate with the IOSU (IPCK_ functions for all you aspiring developers). In fact, we even got a nice example of such communication straight from MN1 himself (Link). However, this does not immediately give us full access - Communication is not control. I can communicate with one of Google's servers, but I can't take control of it. The server decides which of my instructions it obeys or denies based on my access rights. The same principle applies to the IOSU - It decides whether it follows my commands based on which app I am (Mii Maker most of the time).

So to answer the OP, the IOSU is stopping us from hacking the IOSU. Even though we have full control of the PowerPC via the kernel, the IOSU still expects it to stay within certain boundaries and any attempts to get out of them (modifying the IOSU for instance) are quickly stopped.

What do we need then? Simply put, we need an exploit which appears normal enough to the IOSU right up until we take control of it. Whether that means covertly doing stuff it doesn't notice or abusing existing, perfectly normal functions, I don't know. It may even involve something unimaginable right now (Say what you will about the more infamous devs, but there's no denying that abusing the graphics card (!) to write to protected memory to replace a syscall with one that allows unrestricted PowerPC code is absolute genius).

If you're up for it, grab yourself a copy of fw.img from the NUS and the files that will literally tell you everything about it (Link). If you show interest, you'll soon find out about the place where the progress is being made (not GBATemp!) and hopefully we can all move towards getting a public exploit out there. There's a few awesome people working on this and they'd be damn happy to have another person on the team (You know who you are, we really appreciate all your work and the time you've sacrificed towards this!)

Wow, this turned out waaay longer than I was hoping... Hope you guys don't mind! I'm open to questions - I don't bite ;3
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: damn wifi