Hacking 4.0 Tweezer Attack

  • Thread starter Thread starter pspmte
  • Start date Start date
  • Views Views 5,579
  • Replies Replies 7

pspmte

Well-Known Member
Member
Joined
Oct 23, 2008
Messages
244
Reaction score
0
Trophies
1
XP
239
Country
Does anybody know where i can get the circuit diagram and software for the tweezer attack

As i said a few days ago the wii will boots in the game cube made on a mod chip, so i have an idea of dumping my keys from wii 4.0 in game cube mode, which really was the first hack team tweezers did

So if anybody can help me with the release diagrams ect


Cheers Mat


Mods can we have a Wiidev forum ?
 
Wii you can boot into game cube mode on Yasom mod chip config 1.3 with a mod chip

So i guess not
 
Tweezer attack:
Got the common key for all wii (an AES key), this was changed for the Korean wii but other than that all wiis use it and still use it to this day. It relied on the upper areas of the memory not being wiped/scrambled upon launch of the GC hypervisor (we could run gamecube code quite happily at this point), Nintendo had assumed the memory would not be viewable and the tweezer attack allowed people to shift this memory which led to people finding the common key (although it is a rookie mistake to leave your keys in the memory). They did however fix this bug with a new mIOS (mIOS = the GC hypervisor), not that there was any point and at the same time blocked the datel GC discs and GCOS by way of the header values (which could be easily changed in the case of GCOS but as datel had burned discs...).

Getting this key ultimately allowed decryption of the various parts of the wii including the IOS modules where it was discovered that Nintendo has messed up the signing of games in a big way (the trucha bug). Signing is asymmetric based on RSA with a large key (it was over 1000 bits which is way outside any capability for brute force).
More
http://hackmii.com/2008/04/keys-keys-keys/
http://debugmo.de/?p=61
Ignore the wikipedia links and do a real search.
 
pspmte said:
Does anybody know where i can get the circuit diagram and software for the tweezer attack

As i said a few days ago the wii will boots in the game cube made on a mod chip, so i have an idea of dumping my keys from wii 4.0 in game cube mode, which really was the first hack team tweezers did

So if anybody can help me with the release diagrams ect


Cheers Mat


Mods can we have a Wiidev forum ?

http://www.wiire.org/Wii/console/motherboard

Short various lines under U3 to shift the area of memory used in GameCube mode.

However as FAST6191 mentioned, Nintendo patched MIOS to prevent the attack anyway:

http://hackmii.com/2008/06/genie-into-bottle-mios/

Even so I believe the Tweezer attack only revealed the common key, which we all know already anyway.
 
fogbank said:
pspmte said:
Does anybody know where i can get the circuit diagram and software for the tweezer attack

As i said a few days ago the wii will boots in the game cube made on a mod chip, so i have an idea of dumping my keys from wii 4.0 in game cube mode, which really was the first hack team tweezers did

So if anybody can help me with the release diagrams ect


Cheers Mat


Mods can we have a Wiidev forum ?

http://www.wiire.org/Wii/console/motherboard

Short various lines under U3 to shift the area of memory used in GameCube mode.

However as FAST6191 mentioned, Nintendo patched MIOS to prevent the attack anyway:

http://hackmii.com/2008/06/genie-into-bottle-mios/

Even so I believe the Tweezer attack only revealed the common key, which we all know already anyway.
With xuzzy, which relies on the Tweezer attack, you can see your NAND-key as well.
 
joda said:
With xuzzy, which relies on the Tweezer attack, you can see your NAND-key as well.

Xyzzy is a homebrew app that has very little to do with the Tweezer attack.
 

Site & Scene News

New Hot Discussed User Submitted