Hacking ColdbootHax, if you want it do this.

  • Thread starter Thread starter iAqua
  • Start date Start date
  • Views Views 19,431
  • Replies Replies 108
  • Likes Likes 6
I know, you can install un-legit games in sysNAND with a tutorial i rote somewhere in the comment section of this website :P

You have to boot a WUPServer fw.img (that doesn't need a NAND dump)
And open wupclient.py (python -i wupclient.py)
And type "install_title("pathOnSDCard", 0 or 1)" 0 for NAND, 1 for USB
yeah but for a non legit game to boot you would need signature patches.....in which case you would have to use another method first to load up sig patches to be abe to boot the non legit title to load.........sig patches......but you already done that

people need to just accept that there is no free lunch just yet (except the guys who got brain training free :wink:)

so to clarify, if you set the wiiu to autoboot into a non-legit game you could potentially just end up bricked on your first reboot.
 
Last edited by gamesquest1,
  • Like
Reactions: Ryccardo
yeah but for a non legit game to boot you would need signature patches.....in which case you would have to use another method first to load up sig patches to be abe to boot the non legit title to load.........sig patches......but you already done that

It worked for me ... (haven't redNAND or something , just a 14MB .img)

--------------------- MERGED ---------------------------

This will not allow to boot it FYI, so this method is useless.

It worked for me ....
 
so you can turn on your wii u and boot unsigned content without first having to load up the signature patched fw.img file?......if so then screw it you already have cooldboot hax :rolleyes:

the point of cold boot hax is allowing people to turn on the console and with zero interaction be able to boot into rednand or run unsigned content, having to run a exploit to run the exploit defeats the purpose of it
 
Last edited by gamesquest1,
It worked for me ... (haven't redNAND or something , just a 14MB .img)

--------------------- MERGED ---------------------------



It worked for me ....

You have to launch a web exploit/hbl to activate signature patches, that's why there is 14MB .img (aka fw.img). coldboothax here is another story.
 
seeing as there is the possibility of any wiiu game having an exploitable function via this technique I would imagine that it will probably eventually be possible using a normal wiiu game I.e something that can be installed via disk tickets for those who cannot/refuse to buy anything :rolleyes:

PS does the wiiu have any sort of recovery mode like the 3ds where it will boot to the update screen (to potentially fix bricks if someone screws up)
But it is the features of DS VC that allows it to work.
 
I know, you can install un-legit games in sysNAND with a tutorial i rote somewhere in the comment section of this website :P

You have to boot a WUPServer fw.img (that doesn't need a NAND dump)
And open wupclient.py (python -i wupclient.py)
And type "install_title("pathOnSDCard", 0 or 1)" 0 for NAND, 1 for USB

Wow... Any links to that please?

Video, tutorial, proof?
 
i'll make an video proof later, btw just installed MK8 with udpates and DLC ;)
Hmm.. Have you tried VC? (including Wii VC)

That could possibly open the doors for custom Wii VC games pretty much negating the need for a USB loader on vWii...

If that's the case I'd imagine you'd be able to package custom Wii loaders too for things like GameCube games on the Wii U home menu
 
Are the signatures only checked during installation? If so it makes sense that a non-legit title would continue to work so long as it is installed when sig checks are patched out
 
Are the signatures only checked during installation? If so it makes sense that a non-legit title would continue to work so long as it is installed when sig checks are patched out
Or maybe the system modifies the ticket to include the console ID like if it were downloaded from the eShop...
 
from what I gather the code section is verified but the content directory is not which is why this method works as you can swap content in the content directory to trigger new exploits, Comined with the title auto launch you can auto boot into a game that will auto crash and load up homebrew

it's just that the nds vc games offer a seamless exploit, but from what I gather it may be technically possible to find other exploits in other games using the same content swap technique
 
Last edited by gamesquest1,
i'll make an video proof later, btw just installed MK8 with udpates and DLC ;)
Are you talking about installing with wupserver? MK8 has a legitimate ticket so it will boot afterwards. But try it with something that has no legitimate ticket, like Shantae. It will install but you cannot boot the game afterwards. It will complain about the NNID being deleted
 
Anyone know when this would be out? ETA*, and is the final game going to be Brain Age? (USA Region)
 
I'm assuming this is your friendly way of offering to share a better alternative.
better alternative is using temp's smartness to get the boot1 key and find a flaw in it so execution is much further than waiting all the way for iosu to initialize itself, userspace, boot into a custom title and have the loader do its thing, have that title exploit, load in a new iosu image, and let redNAND do its thing, you're looking at like 40 seconds per boot lmao
 
Last edited by NWPlayer123,
better alternative is using temp's smartness to get the boot1 key and find a flaw in it so execution is much further than waiting all the way for iosu to initialize itself, userspace, boot into a custom title and have the loader do its thing, have that title exploit, load in a new iosu image, and let redNAND do its thing, you're looking at like 40 seconds per boot lmao
Doing this will allow things like A9LH, right?
 

Site & Scene News

Popular threads in this forum