Hacking Contenthax - a Vulnerability in Wii U File System Verification

AboodXD

I hack NSMB games, and other shiz.
Member
Joined
Oct 11, 2014
Messages
2,880
Trophies
1
Location
Not under a rock.
XP
2,921
Country
United Arab Emirates
You started this whole thing with a "LMAO, we had cafiine OMG lolol" post, making fun of everyone else. I just asked if you know what you're talking about.
I was being sarcastic at first... (hence the video :rofl2:)
But then I edited my post to be more serious.
In cafiine, you hook directly into the FSRead (+other) functions. Instead of reading the file from the FS, you directly fill in the buffer with data from the network. (https://github.com/mariogamer2/Cafiine/blob/master/cafiine_v1.0/cafiine/client/main.c#L123).
This way the game can't even detect whats going on. Hash checks would be still passing (as the content on the sysnand would be taken for the hash, and this is not changed while using cafiine).
This is the only part that I needed, thanks man. :)
 
  • Like
Reactions: Peninsula

loler55

Well-Known Member
Member
Joined
Jan 4, 2012
Messages
1,045
Trophies
1
XP
1,911
Country
Gambia, The
I tried and got this: any ideas why?
tried settings back and retry and nothing the same problem

ConnectionResetError: [WinError 10054] Eine vorhandene Verbindung wurde vom Remotehost geschlossen
>>>
^C
C:\Users\loler\Desktop\Neues Verzeichnis (6)>python -i wupclient.py
0x1ca042
0x0
0x0
>>> w.up("rom.zip", "/vol/storage_mlc01/usr/title/00050000/10179C00/content/0010/rom.zip")
up error : could not open /vol/storage_mlc01/usr/title/00050000/10179C00/content/0010/rom.zip
-1
>>> w.up("rom.zip", "/vol/storage_mlc01/usr/title/00050000/10179C00/content/0010/rom.zip")
up error : could not open /vol/storage_mlc01/usr/title/00050000/10179C00/content/0010/rom.zip
-1
>>> w.up("rom.zip", "/vol/storage_mlc01/usr/title/00050000/10179C00/content/0010/rom.zip")
up error : could not open /vol/storage_mlc01/usr/title/00050000/10179C00/content/0010/rom.zip
-1
 
Last edited by loler55,

nolimits59

Well-Known Member
Member
Joined
Apr 25, 2008
Messages
701
Trophies
1
XP
2,064
Country
France
Need help, my problems was flooded 2 times :(, i w.up all the files, rom , meta, images, the name is changed, image also, but the game doesnt boot homebrew channel at all... someone experienced that ?
 

bluke

Well-Known Member
Member
Joined
Feb 2, 2010
Messages
137
Trophies
1
XP
342
Country
Yo, don't try it if you haven't redNAND, and only try it on your redNAND !!!!!

I bricked my Wii u yesterday :/ (sysNAND)

Then if you're ok, then yeah the change on sys_xml is good

--------------------- MERGED ---------------------------



Go in sys_settings and exit then retry
OK ill will try to change brain age image and guild to my kid run it after boot :)
 

loler55

Well-Known Member
Member
Joined
Jan 4, 2012
Messages
1,045
Trophies
1
XP
1,911
Country
Gambia, The
tried settings back and retry and nothing the same problem

ConnectionResetError: [WinError 10054] Eine vorhandene Verbindung wurde vom Remotehost geschlossen
>>>
^C
C:\Users\loler\Desktop\Neues Verzeichnis (6)>python -i wupclient.py
0x1ca042
0x0
0x0
>>> w.up("rom.zip", "/vol/storage_mlc01/usr/title/00050000/10179C00/content/0010/rom.zip")
up error : could not open /vol/storage_mlc01/usr/title/00050000/10179C00/content/0010/rom.zip
-1
>>> w.up("rom.zip", "/vol/storage_mlc01/usr/title/00050000/10179C00/content/0010/rom.zip")
up error : could not open /vol/storage_mlc01/usr/title/00050000/10179C00/content/0010/rom.zip
-1
>>> w.up("rom.zip", "/vol/storage_mlc01/usr/title/00050000/10179C00/content/0010/rom.zip")
up error : could not open /vol/storage_mlc01/usr/title/00050000/10179C00/content/0010/rom.zip
-1
help plz.. connection to wupserver is up brain training pal
lol failed its on my usb drive
 
Last edited by loler55,

Kohmei

Well-Known Member
Member
Joined
Feb 17, 2013
Messages
824
Trophies
0
XP
1,039
Country
United States
Does anyone have a nice set of modified meta data to change the DS game icon/banner etc into HBL? Seen a few in this thread but no links
 

Deleted member 129634

Well-Known Member
Member
Joined
Jun 30, 2008
Messages
151
Trophies
0
XP
722
Country
United States
to everyone doing custom icons, bootdrc and bootTV, which software are you using to keep the sizes to 65 kb, 1201 kb and 2701 kb? I also have the sdk if that helps but I don't know which tool can do this.
 

nolimits59

Well-Known Member
Member
Joined
Apr 25, 2008
Messages
701
Trophies
1
XP
2,064
Country
France
So since no one see my posts, tried to investigate and see whats in the NDS game folders with wupclient and some w.ls and w.cd, there is planty of rom.nds, one on the ID game root and one on the 0010 folder near my rom.zip.

Why there is so many rom.nds ? And why my game is booting normaly and not booting the homebrew launcher ? :/ this is really strange... did everything right so i don't understand...

Please help :(
 

VinsCool

Persona Secretiva Felineus
OP
Global Moderator
Joined
Jan 7, 2014
Messages
14,600
Trophies
4
Location
Another World
Website
www.gbatemp.net
XP
25,217
Country
Canada
So since no one see my posts, tried to investigate and see whats in the NDS game folders with wupclient and some w.ls and w.cd, there is planty of rom.nds, one on the ID game root and one on the 0010 folder near my rom.zip.

Why there is so many rom.nds ? And why my game is booting normaly and not booting the homebrew launcher ? :/ this is really strange... did everything right so i don't understand...

Please help :(
Try to delete the game andredownload from eshop.
 

nolimits59

Well-Known Member
Member
Joined
Apr 25, 2008
Messages
701
Trophies
1
XP
2,064
Country
France
Try to delete the game andredownload from eshop.
Gonna edit when it's finnished, trying at this moment, it's sending the two big TGAs, but DAMN that was funny, when i was on the eShop, the loading screen minigame with the game icons had the homebrew launcher in it x) that was really funny to see the homebrew channel on the eShop :D.
 

subcon959

@!#?@!
Member
Joined
Dec 24, 2008
Messages
5,848
Trophies
4
XP
10,131
Country
United Kingdom
Gonna edit when it's finnished, trying at this moment, it's sending the two big TGAs, but DAMN that was funny, when i was on the eShop, the loading screen minigame with the game icons had the homebrew launcher in it x) that was really funny to see the homebrew channel on the eShop :D.
Might not be so funny if you end up bricking though, be careful it's still possible to do some serious damage with these commands.
 

xXDungeon_CrawlerXx

Well-Known Member
Member
Joined
Jul 29, 2015
Messages
2,092
Trophies
1
Age
28
Location
Liverpool
XP
3,722
Country
Doesn't even loop... :(

That's sad.
No need for loop because it didn't play completely anyways xD

--------------------- MERGED ---------------------------

It's worth noting the meta.xml here is for brain training (eur) so you should probably not replace your meta.xml with it unless that's what your game is
You can edit the meta.xml if you want
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    S @ salazarcosplay: how are you @BigOnYa ??