Hacking [HOW-TO] Dumping tickets for Brazilian exploit

shutterbug2000

Cubic NINJHAX!
OP
Member
Joined
Oct 11, 2014
Messages
1,088
Trophies
0
Age
29
XP
4,878
Country
United States
First off, you need to follow this: https://gbatemp.net/threads/how-to-load-a-fw-img-for-any-file-dumping-wiiubru-status-update.445840/ to set up cfw hax.

Then, run python and get into a python console(just run the python executable)

Then, type "execfile('path\\to\\the\\.py\\file')"

Then, for eshop:

Run "w.dldir("/vol/system_slc/rights/ticket/apps/")"

OR

For disc games:

Type "mount_odd_tickets()", "w.dldir("/vol/storage_odd_tickets")", and unmount_odd_tickets().

You can then swap the disc and repeat.



For eshop games, to determine the title id, open in a hex editor

Then, find 0005. Make sure it comes Root-CA.

The next 8 hex digits will be your title id, which can be compared with a title id database to find the game the ticket belongs to.
 

veggav

Well-Known Member
Member
Joined
Nov 21, 2009
Messages
208
Trophies
1
XP
1,016
Country
Brazil
I don't think this will work because DLC/Eshop/VC all have console ID bytes.

So it's hooked to your console only.
 

Cyan

GBATemp's lurking knight
Former Staff
Joined
Oct 27, 2002
Messages
23,749
Trophies
4
Age
45
Location
Engine room, learning
XP
15,648
Country
France
I think cyan already tested and get different tickets than the public/pirate .wud
naah, it's not me.
I didn't even build the fw.bin (blocked at armips step), or tried any CFW booter.
I also don't share tickets.


you can get and share the Disc ticket, but the eShop tickets are linked to the console.
until there's a CFW patch with signature check removed, users won't be able to use them.
(unless I'm wrong?)
 
  • Like
Reactions: paulloeduardo

veggav

Well-Known Member
Member
Joined
Nov 21, 2009
Messages
208
Trophies
1
XP
1,016
Country
Brazil
naah, it's not me.
I didn't even build the fw.bin (blocked at armips step), or tried any CFW booter.
I also don't share tickets.


you can get and share the Disc ticket, but the eShop tickets are linked to the console.
until there's a CFW patch with signature check removed, users won't be able to use them.
(unless I'm wrong?)

What if the exact location of the bytes for the console ID are found and we swap it for our own console ID?
Would this kill the hash check?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: good night