Hacking Contenthax - a Vulnerability in Wii U File System Verification

  • Thread starter Thread starter VinsCool
  • Start date Start date
  • Views Views 188,670
  • Replies Replies 1,235
  • Likes Likes 43
Just finished dumping the working meta files from my redNAND mod. This MEGA folder now includes:
- Modified rom.zip files that boot cfwboot.elf from /wiiu/boot, includes all 3 current exploit VC titles
- Modified cfwboot.elf that loads fw.img from /wiiu/boot instead of the SD root
- Meta files to theme VC titles into a custom redNAND app. meta.xml is only for Brain Age US
https://mega.nz/#F!QV8CgJIQ!yB0s5pzMtSXUV96CQ2rrRQ
 
Just finished dumping the working meta files from my redNAND mod. This MEGA folder now includes:
- Modified rom.zip files that boot cfwboot.elf from /wiiu/boot, includes all 3 current exploit VC titles
- Modified cfwboot.elf that loads fw.img from /wiiu/boot instead of the SD root
- Meta files to theme VC titles into a custom redNAND app. meta.xml is only for Brain Age US
https://mega.nz/#F!QV8CgJIQ!yB0s5pzMtSXUV96CQ2rrRQ
.tga's are working great now. Thanks for the reupload + the rest dude!!
 
Here is a video showing the entire custom redNAND title working and booting redNAND, including showing that it boots a different fw.img than what HBL loads (redNAND title loads from /wiiu/boot to load redNAND, HBL will load from SD root to load sysNAND WUPServer)


Now time to figure out github.
 
  • Like
Reactions: KiiWii
No, Meta files go in titleid/meta/. Only the rom goes in content.

Like this for brain age..

w.up("iconTex.tga", "/vol/storage_usb01/usr/title/00050000/10179C00/meta/iconTex.tga")
Thanks I was just trying but I kept getting an question mark so would I just keep changing the first bit and the last bit for each tag file for example:-
w.up("meta.xml", "/vol/storage_usb01/usr/title/00050000/10179C00/meta/meta.xml")
w.up("bootDrcTex.tga", "/vol/storage_usb01/usr/title/00050000/10179C00/meta/bootDrcTex.tga")
w.up("bootSound.tga", "/vol/storage_usb01/usr/title/00050000/10179C00/meta/.bootSoundtga")

and so on..
 
Last edited by Reecey,
  • Like
Reactions: ARVI80
Guys, how you create tga's? I'm using Paint.NET, save picture as 24-bit non-compressed .tga, but when i upload it into /meta folder and reboot my console i got grey "?" icon and system sez me that game is corrupted. When I uploaded original iconTex.tga back - it perfectly works.
 
Thanks I was just trying but I kept getting an question mark so would I just keep changing the first bit and the last bit for each tag file for example:-
w.up("meta.tga", "/vol/storage_usb01/usr/title/00050000/10179C00/meta/meta.tga")
w.up("bootDrcTex.tga", "/vol/storage_usb01/usr/title/00050000/10179C00/meta/bootDrcTex.tga")
w.up("bootSound.tga", "/vol/storage_usb01/usr/title/00050000/10179C00/meta/.bootSoundtga")

and so on..
Yes. BTW, You have meta.tga in your post. There's no such file named like that.
 
There was a cfw meta folder in the files I downloaded for the homebrew icon I thought maybe I had to upload that as well?
Only file's you really need to upload/replace are...

meta.xml
iconTex.tga
bootTvTex.tga
bootSound.btsnd
bootDrcTex.tga

All go in the /meta folder.
 
  • Like
Reactions: Reecey
Guys, how you create tga's? I'm using Paint.NET, save picture as 24-bit non-compressed .tga, but when i upload it into /meta folder and reboot my console i got grey "?" icon and system sez me that game is corrupted. When I uploaded original iconTex.tga back - it perfectly works.
Same for me
 
Guys, how you create tga's? I'm using Paint.NET, save picture as 24-bit non-compressed .tga, but when i upload it into /meta folder and reboot my console i got grey "?" icon and system sez me that game is corrupted. When I uploaded original iconTex.tga back - it perfectly works.
I used photoshop, but I don't know exactly what settings to use to get it to work. Sometimes when I use 24bit color no compression it works, and other times using the same exact settings and image it won't work for some reason.
 
I used photoshop, but I don't know exactly what settings to use to get it to work. Sometimes when I use 24bit color no compression it works, and other times using the same exact settings and image it won't work for some reason.
Do you have a cfwbooter rom.zip so I can run that instead HBL?

Edit: I don't have rednand but I have wii VC games installed with fake Tik and they need iosuhax fw.img to run
 
Last edited by huma_dawii,
Do you have a cfwbooter rom.zip so I can run that instead HBL?

Edit: I don't have rednand but I have wii VC games installed with fake Tik and they need iosuhax fw.img to run
The files he posted last are for cfwbooter. You'll need to put cfwbooter.elf & ioshax fw.img in wiiu/boot to use his version though.
 
Last edited by BIFFTAZ,
So I just found one weird behavior with my current redNAND modifications. It seems doing anything that causes the system to reload fw.bin (entering and exiting settings) from within redNAND will cause it to load back into sysNAND. I have no clue if it still has all the sig patches but is just reading sysNAND, and I am not going to test that. So for now be VERY careful with my currently released redNAND items until I can figure out what is causing this problem

Edit:
The issue is exactly what I was thinking it was. It seems reloading firmware causes it to read from the SD root again instead of /wiiu/boot, leading me to believe it is an issue with the fw.img this time. I'll have a look into the code to see if I can figure out what to change to fix this, but if someone wants to point me in the right direction I would sure appreciate that.
 
Last edited by TheCyberQuake,

Site & Scene News

Popular threads in this forum