Hacking [HOW-TO] Dumping tickets for Brazilian exploit

  • Thread starter Thread starter shutterbug2000
  • Start date Start date
  • Views Views 14,087
  • Replies Replies 77
  • Likes Likes 19

shutterbug2000

Cubic NINJHAX!
Member
Joined
Oct 11, 2014
Messages
1,088
Reaction score
2,562
Trophies
0
Age
31
XP
4,903
Country
United States
First off, you need to follow this: https://gbatemp.net/threads/how-to-load-a-fw-img-for-any-file-dumping-wiiubru-status-update.445840/ to set up cfw hax.

Then, run python and get into a python console(just run the python executable)

Then, type "execfile('path\\to\\the\\.py\\file')"

Then, for eshop:

Run "w.dldir("/vol/system_slc/rights/ticket/apps/")"

OR

For disc games:

Type "mount_odd_tickets()", "w.dldir("/vol/storage_odd_tickets")", and unmount_odd_tickets().

You can then swap the disc and repeat.



For eshop games, to determine the title id, open in a hex editor

Then, find 0005. Make sure it comes Root-CA.

The next 8 hex digits will be your title id, which can be compared with a title id database to find the game the ticket belongs to.
 
I don't think this will work because DLC/Eshop/VC all have console ID bytes.

So it's hooked to your console only.
 
Great hopefully someone could get us Pokken USA ticket thats the only game I need :c
 
I think cyan already tested and get different tickets than the public/pirate .wud
naah, it's not me.
I didn't even build the fw.bin (blocked at armips step), or tried any CFW booter.
I also don't share tickets.


you can get and share the Disc ticket, but the eShop tickets are linked to the console.
until there's a CFW patch with signature check removed, users won't be able to use them.
(unless I'm wrong?)
 
  • Like
Reactions: paulloeduardo
naah, it's not me.
I didn't even build the fw.bin (blocked at armips step), or tried any CFW booter.
I also don't share tickets.


you can get and share the Disc ticket, but the eShop tickets are linked to the console.
until there's a CFW patch with signature check removed, users won't be able to use them.
(unless I'm wrong?)

What if the exact location of the bytes for the console ID are found and we swap it for our own console ID?
Would this kill the hash check?
 

Site & Scene News

Popular threads in this forum