A really, REALLY old browser exploit (for 5.3.2)?

Jediweirdo

Well-Known Member
OP
Newcomer
Joined
Aug 3, 2021
Messages
90
Trophies
0
XP
476
Country
United States
Someone I'm helping got a fatal NAND corruption error on their Wii U and I'm trying to help them homebrew it so they can get RedNAND before their NAND is too far gone. However, they're stuck on 5.3.2U and can't update (a fatal error code happens). So, is there any remaining old exploits they could possibly use, and would bluubomb work? We've already tried a lot of newer exploits like the wifi exploit and the more modern web exploits.

Edit: stupid mistake with the version numbers. Sorry! The are on 5.3.2, not 5.5.X
 
Last edited by Jediweirdo,

xpermian

Member
Newcomer
Joined
Apr 3, 2024
Messages
24
Trophies
0
Age
32
XP
7
Country
United States
Did you try dnspresso?
I'm the person who has this issue

Yeah, I tried DNSpresso, but it didn't work. The connection test just kept loading forever. Although, all the videos I saw on DNSpresso used Wired Connections, but I used a normal network connection cuz I don't have a LAN adapter. Not sure if that was the reason why it failed.

I followed this old browser exploit guide: gbatemp dot net/threads/homebrew-launcher-for-wiiu.416905/
This was able to work for me, and I was able to launch the Homebrew Launcher.

I'm not sure how to proceed with installing ISFShax, however, because I tried rerunning the exploit with the ISFShax files, but it just reopened the Homebrew Launcher instead of the minute main menu.
 

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,268
Trophies
0
Age
28
XP
1,388
Country
Germany
Try replacing SD:/wiiu/apps/homebrew_launcher/homebrew_launcher.elf with the payload.elf from the fw_img loader.
 

xpermian

Member
Newcomer
Joined
Apr 3, 2024
Messages
24
Trophies
0
Age
32
XP
7
Country
United States
After I launched the exploit, I got a black screen with white text saying:

"Could not load file /wiiu/apps/homebrew_launcher/homebrew_launcher.elf"

BTW, the website I'm using is wiiu dot insanenutter dot com.
 

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,268
Trophies
0
Age
28
XP
1,388
Country
Germany
The problem is we don't have a IOSU exploit for such an old IOSU, and we would need that for a fw_img loader.

The only option I see, without back porting an exploit to an older IOSU (which I don't see happening anytime soon) would be to update IOSU. Since you say the update isn't working, we could try to install the latest OSv10 using the WUP Installer, which we can launch from the Browser exploit.
If that install works, we can use the 5.5.x IOSU exploit to launch a fw.img.
But this has some risk, since I am not sure if the newer OSv10 title works with the older rest of the firmware. We could also try to update all titles, but that would mean more eMMC writes, which also is a risk.
But even if it can't boot anymore completely with the new OS, we should still be able to use UDPIH.

If you want to do that I can look into WUP Installer later to remove the checks.
 
  • Like
Reactions: Blythe93

xpermian

Member
Newcomer
Joined
Apr 3, 2024
Messages
24
Trophies
0
Age
32
XP
7
Country
United States
The problem is we don't have a IOSU exploit for such an old IOSU, and we would need that for a fw_img loader.

The only option I see, without back porting an exploit to an older IOSU (which I don't see happening anytime soon) would be to update IOSU. Since you say the update isn't working, we could try to install the latest OSv10 using the WUP Installer, which we can launch from the Browser exploit.
If that install works, we can use the 5.5.x IOSU exploit to launch a fw.img.
But this has some risk, since I am not sure if the newer OSv10 title works with the older rest of the firmware. We could also try to update all titles, but that would mean more eMMC writes, which also is a risk.
But even if it can't boot anymore completely with the new OS, we should still be able to use UDPIH.

If you want to do that I can look into WUP Installer later to remove the checks.
Sure, I can try using the WUP Installer once you remove the checks. I'm assuming the checks are for checking your Wii U firmware version.
 

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,268
Trophies
0
Age
28
XP
1,388
Country
Germany
First You understand there is a Risk with this, and I didn't test this exact scenario. If it goes mildly wrong, you will need to use UDPIH or if it goes really wrong you need to defuse (solder). But It's not like there are many options to chose from...

Use the MLCRestorerDownloader https://github.com/Xpl0itU/MLCRestorerDownloader/releases to download the SLC titles.
Create an install folder on the SD, copy the 000500101000400a (OSv10) title the install folder. It will ask you for a Common Key.. You will need to find that somwhere...

There is already a patched version of the WUP Installer: https://hb-app.store/wiiu/wup_installer_gx2_mod
The original WUP Installer doesn't allow installing system titles.
You should be able to launch it from the Homebrew Launcher.

From the WUP Installer you can then install the 000500101000400a title.

After that is done reboot and hope that it still boots from the browser.

You should then be able to use the CFW Booter: https://hb-app.store/wiiu/cfwbooter to load minute from the Homebrew Launcher. (Use the fw_encrypted.img renamed to fw.img on the SD)
 
  • Like
Reactions: Blythe93

xpermian

Member
Newcomer
Joined
Apr 3, 2024
Messages
24
Trophies
0
Age
32
XP
7
Country
United States
Before I try the exploit, can you verify that my SD card files are correct?

  • fw.img
  • ios.img
  • superblock.img
  • superblock.img.sha
  • wiiu
    • apps
      • cfwbooter
        • cfwboot.elf
        • icon.png
        • meta.xml
      • homebrew_launcher
        • homebrew_launcher.elf
        • icon.png
        • meta.xml
      • wup_installer_gx2_mod
        • wup_installer_gx2.elf
        • icon.png
        • meta.xml
    • ios_plugins
      • wafel_core.ipx
      • wafel_isfshax_patch.ipx
  • install
    • 000500101000400a
      • all files downloaded from the MLCRestorerDownloader
 

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,268
Trophies
0
Age
28
XP
1,388
Country
Germany
looks good to me.
Inside the 000500101000400a folder, you just have the app and other files and no subfolders, right?
 

xpermian

Member
Newcomer
Joined
Apr 3, 2024
Messages
24
Trophies
0
Age
32
XP
7
Country
United States
Yeah, it's just the app and files.

I tried the Browser exploit with this SD card, but I got an error saying:

"FSGetMountSource failed."

edit: it was FSGetMountSource, not FSGetMountExploit
 

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,268
Trophies
0
Age
28
XP
1,388
Country
Germany
Make sure it is FAT32 formatted. For Now you can also just use the card that worked with the Browser exploit
 

xpermian

Member
Newcomer
Joined
Apr 3, 2024
Messages
24
Trophies
0
Age
32
XP
7
Country
United States
The card I'm using rn is the one that worked with the Browser exploit. I formatted it to FAT32 a couple of days ago with GUIFormat.
 

xpermian

Member
Newcomer
Joined
Apr 3, 2024
Messages
24
Trophies
0
Age
32
XP
7
Country
United States
Yeah, you were right. I replugged the SD card in and the browser exploit worked.

I ran the WUP installer, and installed 000500101000400a to the NAND.

However, after I rebooted and retried the browser exploit, the Browser exploit is now stuck on the wiiu.insanenutter.com/payload532.html website, without going to the Homebrew Launcher.
 

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,268
Trophies
0
Age
28
XP
1,388
Country
Germany
Then now maybe try the u.wiidb.de one.
But it will look for a wiiu/payload.elf. Make sure you place the fw.img loader payload.elf there https://github.com/wiiu-env/fw_img_payload/releases

If we can't get a browser exploit to work, you could try DNSpresso again. And if that doesn't work maybe bluuebomb. And after that we would need to resort to UDPIH. Do you have a modded switch or a raspberry pi pico?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • K3Nv2 @ K3Nv2:
    How do you know if the night will be good when you're asleep
  • BakerMan @ BakerMan:
    because i didn't say i was asleep
  • BakerMan @ BakerMan:
    i said i was sleeping...
  • BakerMan @ BakerMan:
    sleeping with uremum
  • K3Nv2 @ K3Nv2:
    Even my mum slept on that uremum
  • TwoSpikedHands @ TwoSpikedHands:
    yall im torn... ive been hacking away at tales of phantasia GBA (the USA version) and have so many documents of reverse engineering i've done
  • TwoSpikedHands @ TwoSpikedHands:
    I just found out that the EU version is better in literally every way, better sound quality, better lighting, and there's even a patch someone made to make the text look nicer
  • TwoSpikedHands @ TwoSpikedHands:
    Do I restart now using what i've learned on the EU version since it's a better overall experience? or do I continue with the US version since that is what ive been using, and if someone decides to play my hack, it would most likely be that version?
  • Sicklyboy @ Sicklyboy:
    @TwoSpikedHands, I'll preface this with the fact that I know nothing about the game, but, I think it depends on what your goals are. Are you trying to make a definitive version of the game? You may want to refocus your efforts on the EU version then. Or, are you trying to make a better US version? In which case, the only way to make a better US version is to keep on plugging away at that one ;)
  • Sicklyboy @ Sicklyboy:
    I'm not familiar with the technicalities of the differences between the two versions, but I'm wondering if at least some of those differences are things that you could port over to the US version in your patch without having to include copyrighted assets from the EU version
  • TwoSpikedHands @ TwoSpikedHands:
    @Sicklyboy I am wanting to fully change the game and bend it to my will lol. I would like to eventually have the ability to add more characters, enemies, even have a completely different story if i wanted. I already have the ability to change the tilemaps in the US version, so I can basically make my own map and warp to it in game - so I'm pretty far into it!
  • TwoSpikedHands @ TwoSpikedHands:
    I really would like to make a hack that I would enjoy playing, and maybe other people would too. swapping to the EU version would also mean my US friends could not legally play it
  • TwoSpikedHands @ TwoSpikedHands:
    I am definitely considering porting over some of the EU features without using the actual ROM itself, tbh that would probably be the best way to go about it... but i'm sad that the voice acting is so.... not good on the US version. May not be a way around that though
  • TwoSpikedHands @ TwoSpikedHands:
    I appreciate the insight!
  • The Real Jdbye @ The Real Jdbye:
    @TwoSpikedHands just switch, all the knowledge you learned still applies and most of the code and assets should be the same anyway
  • The Real Jdbye @ The Real Jdbye:
    and realistically they wouldn't

    be able to play it legally anyway since they need a ROM and they probably don't have the means to dump it themselves
  • The Real Jdbye @ The Real Jdbye:
    why the shit does the shitbox randomly insert newlines in my messages
  • Veho @ Veho:
    It does that when I edit a post.
  • Veho @ Veho:
    It inserts a newline in a random spot.
  • The Real Jdbye @ The Real Jdbye:
    never had that i don't think
  • Karma177 @ Karma177:
    do y'all think having an sd card that has a write speed of 700kb/s is a bad idea?
    trying to restore emunand rn but it's taking ages... (also when I finished the first time hekate decided to delete all my fucking files :wacko:)
  • The Real Jdbye @ The Real Jdbye:
    @Karma177 that sd card is 100% faulty so yes, its a bad idea
  • The Real Jdbye @ The Real Jdbye:
    even the slowest non-sdhc sd cards are a few MB/s
  • Karma177 @ Karma177:
    @The Real Jdbye it hasn't given me any error trying to write things on it so I don't really think it's faulty (pasted 40/50gb+ folders and no write errors)
    Karma177 @ Karma177: @The Real Jdbye it hasn't given me any error trying to write things on it so I don't really...