Hacking Hykem's 5.5 iosu Exploit

Status
Not open for further replies.

ajd4096

Well-Known Member
Member
Joined
Feb 17, 2009
Messages
179
Trophies
1
XP
562
Country
There is no verification, online or otherwise, for that kind of thing. A future firmware could -possibly- do this, but since we will have emuNAND, the check could be completely patched out or just send modified responses. So this isn't really something to worry about, no. If they don't do it on N3DS which has better security, they won't do it on WiiU.

If Nintendo do it correctly you wouldn't even know there was a check being done at all, let alone know how to send the correct response.
Fortunately they don't seem to care, and often make mistakes.
 

SonyUSA

We're all mad here
OP
Editorial Team
Joined
May 12, 2006
Messages
1,780
Trophies
2
XP
5,618
Country
United States
If Nintendo do it correctly you wouldn't even know there was a check being done at all, let alone know how to send the correct response.
Fortunately they don't seem to care, and often make mistakes.
Packet scanner
 

SonyUSA

We're all mad here
OP
Editorial Team
Joined
May 12, 2006
Messages
1,780
Trophies
2
XP
5,618
Country
United States
I'm not sure that is a fair assumption to make. We have no idea the specifics of what he plans to release, or how long he has focused on the 5.4+ webkit... if at all.

Yes, he says IF he cannot get the permanent install to work, he will release everything -immediately-, which implies it's ready ;)
 

SonyUSA

We're all mad here
OP
Editorial Team
Joined
May 12, 2006
Messages
1,780
Trophies
2
XP
5,618
Country
United States
Steganography.
We know what data they send, if we see something weird we will know something is concealed, therefore defeating the purpose of the concealment, and since we will have full system access we can just use a debugger to see what the WiiU is sending if nobody wants to packet scan.
 

gudenau

Largely ignored
Member
Joined
Jul 7, 2010
Messages
3,882
Trophies
2
Location
/dev/random
Website
www.gudenau.net
XP
5,379
Country
United States
Something like that already exists.

--------------------- MERGED ---------------------------



Hardware key spoof in emuNAND :P
You can unban without emuNAND, do not ask me how; I do not know.

--------------------- MERGED ---------------------------

Is he working on the project alone?
Mostly.
 

gudenau

Largely ignored
Member
Joined
Jul 7, 2010
Messages
3,882
Trophies
2
Location
/dev/random
Website
www.gudenau.net
XP
5,379
Country
United States
If the first unban methods show up, we're pretty fucked. If they haven't made a new ban system, something like bean did for Wiimmfi would've been a good thing. Although I really don't think they did something like that, so we'll have MKW all over again.
Not like the people who know how at this point will ever share it. All they said is that they know how.
 
  • Like
Reactions: H93

MattKimura

3DS & WiiU Enthusiast
Member
Joined
Jun 30, 2014
Messages
2,137
Trophies
1
XP
2,937
Country
United States
If/when IOSU is here and Loadiine gets ported, I hope that the LoadiineReady format won't get abandoned (Ex: Code Content Meta folders)
I heard you guys talking about .wud and .wux files, I delete my .wud files a while back because they take up way too much space on my computer!

Even for USB loading, I"d hope we don't HAVE to use .wud/.wux files.
 
  • Like
Reactions: Deleted User

ajd4096

Well-Known Member
Member
Joined
Feb 17, 2009
Messages
179
Trophies
1
XP
562
Country
We know what data they send, if we see something weird we will know something is concealed, therefore defeating the purpose of the concealment, and since we will have full system access we can just use a debugger to see what the WiiU is sending if nobody wants to packet scan.

If it is done right, it won't even look weird. That's the whole point of steganography.
It would be absolutely trivial to trickle back the installed firmware one byte (or bit) at a time and piece it together server-side.
Do Nintendo want to do this at scale for a console due to be replaced? Probably not, but it most certainly is possible.
 
S

Simonwayneee

Guest
If/when IOSU is here and Loadiine gets ported, I hope that the LoadiineReady format won't get abandoned (Ex: Code Content Meta folders)
I heard you guys talking about .wud and .wux files, I delete my .wud files a while back because they take up way too much space on my computer!

Even for USB loading, I"d hope we don't HAVE to use .wud/.wux files.
(Please know that this is what I think)
IF there is a new format like *.wbfs for Wii, there should be a converter, that converts the files into the new format.
 

Zap Rowsdower

Well-Known Member
Member
Joined
Jan 17, 2015
Messages
456
Trophies
0
Location
I don't go map findin' behindin'
XP
2,369
Country
Canada
Yes, he says IF he cannot get the permanent install to work, he will release everything -immediately-, which implies it's ready ;)
The latest intentions stated are not what is in question here. I have no doubt that firmwares 5.3.2 and less IOSU will either be supported either initially or ported to soon after. Now what IS left to question is the "everything". Hykem has not explicitly said that he was working on the 5.4+ webkit, just that it was being worked on... which probably just means that he had heard others say that they were working on it.
 

SonyUSA

We're all mad here
OP
Editorial Team
Joined
May 12, 2006
Messages
1,780
Trophies
2
XP
5,618
Country
United States
If it is done right, it won't even look weird. That's the whole point of steganography.
It would be absolutely trivial to trickle back the installed firmware one byte (or bit) at a time and piece it together server-side.
Do Nintendo want to do this at scale for a console due to be replaced? Probably not, but it most certainly is possible.

Look brah, if Blizzard can't even do it properly, a company who had an entire department devoted to coding Warden and its server/client secret checks only to be defeated by ONE GUY, then I think we can handle it on the Wii U. You can't just make checks like that invisible, there has to be processes/threads that run to perform the functions/hashes to send back to nintendo. You can't make something like that invisible, we will see it right away by checking processes.

Plus, the buttholes at Sony and M$ would have implemented this if it was possible.
 
Last edited by SonyUSA,
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    HiradeGirl @ HiradeGirl: Spider Ninja.