Hacking Derrek6 has the Wii U Boot1 Key!

  • Thread starter Thread starter Piluvr
  • Start date Start date
  • Views Views 37,744
  • Replies Replies 154
  • Likes Likes 9
You can't bruteforce a hash because of collisions, especially when you're dealing with completely random strings such as keys to begin with. There are a (virtually) infinite amount of strings that have the same hash

Password guessing works because it's using a dictionary-based attack and calculating what the hash of known words actually is

You don't need to bruteforce, sha1 collision attacks (namely collision detection) has been possible since 2012 and substantially improved in speed since. This is why Google is trying to push everyone away from sha1.
 
For anyone who is wondering what'll this do?

You can use it to decrypt boot1, and then get to boot0.

You may say "And why would we need to do that?".
To find possible bugs, and exploit them, aka haxx on boot, possibly permanent exploits.
 
  • Like
Reactions: ARVI80
It would be quicker to just wait for the key to be leaked either way. As for wanting the key, I have my reasons other than decrypting boot1.
 
  • Like
Reactions: buda81 and KiiWii
It would be quicker to just wait for the key to be leaked either way. As for wanting the key, I have my reasons other than decrypting boot1.
Like what? it's pretty much useless for anyone who doesn't know what he's doing...
I, myself, am not interested in exploiting systems, so I'll just wait and see. :)
 
For anyone who is wondering what'll this do?

You can use it to decrypt boot1, and then get to boot0.

You may say "And why would we need to do that?".
To find possible bugs, and exploit them, aka haxx on boot, possibly permanent exploits.

This makes no sense. Boot0 = arm/Starbucks bootrom(Read Only Memory).
You may be able to break the chain of trust from boot1 (since it is write able) but boot0 is set in stone.
 
This makes no sense. Boot0 = arm/Starbucks bootrom(Read Only Memory).
You may be able to break the chain of trust from boot1 (since it is write able) but boot0 is set in stone.
Some people are interested in looking at boot0, IDK why.
I don't think that it has anything to do with exploiting... :unsure:
 
I am not talking about copyrighting a number. THERE IS NO SUCHTHING,PERIOD END OF DISCUSSION

I was talking about posting a link to copyrighted code. For that, there is no excuse.
 
  • Like
Reactions: KiiWii
If its anything like the Wii, boot0 also checks the hash of boot1. and since boot0 can't be changed cause its read-only. That means all this Key can be used for is decrypting boot1 but cause boot0 checks the hash of boot1 it still can't be modded even with this key. And lastly because boot1 has already been readable before this key was known, its completely useless just for bragging rights I guess. Correct me if I'm wrong.
 
  • Like
Reactions: Bug_Checker_
I doubt anyone except the finder of it does.... ATM.

So you want to know what I have been doing and why the boot1 key is of possible interest to my research, and you go about this by goading.
OK........ Great gameplan
 
  • Like
Reactions: CJB100
In order to copyright a number, said number would have to publicly be mentioned in that copyright, so would defeat the whole purpose ...

It's not copyrighted, and as I said, if it is, the number would be a matter of public record.
 

Site & Scene News

Popular threads in this forum