[HOW-TO] Dumping tickets for Brazilian exploit

Discussion in 'Wii U - Hacking & Backup Loaders' started by shutterbug2000, Oct 22, 2016.

  1. shutterbug2000
    OP

    shutterbug2000 Cubic NINJHAX!

    Member
    1,078
    2,085
    Oct 11, 2014
    United States
    First off, you need to follow this: https://gbatemp.net/threads/how-to-load-a-fw-img-for-any-file-dumping-wiiubru-status-update.445840/ to set up cfw hax.

    Then, run python and get into a python console(just run the python executable)

    Then, type "execfile('path\\to\\the\\.py\\file')"

    Then, for eshop:

    Run "w.dldir("/vol/system_slc/rights/ticket/apps/")"

    OR

    For disc games:

    Type "mount_odd_tickets()", "w.dldir("/vol/storage_odd_tickets")", and unmount_odd_tickets().

    You can then swap the disc and repeat.



    For eshop games, to determine the title id, open in a hex editor

    Then, find 0005. Make sure it comes Root-CA.

    The next 8 hex digits will be your title id, which can be compared with a title id database to find the game the ticket belongs to.
     


  2. KiiWii

    KiiWii GBAtemp Psycho!

    Member
    3,668
    1,219
    Nov 17, 2008
    United Kingdom
    Very cool, do you think will be there possibility to dump directly to SD without a PC present?
     
  3. shutterbug2000
    OP

    shutterbug2000 Cubic NINJHAX!

    Member
    1,078
    2,085
    Oct 11, 2014
    United States
    Possibly, but it depends on how IOSU/cfw progresses.
     
    KiiWii likes this.
  4. zongalito

    zongalito GBAtemp Regular

    Member
    131
    44
    Dec 9, 2013
    Cote d'Ivoire
    Rancagua, Chile
    So now eshop game tickets can be extracted? And dlc?
     
  5. SoulEater98

    SoulEater98 Advanced Member

    Newcomer
    52
    15
    Nov 6, 2010
    United States
    So with this we can get tickets for VC games, eShop titles or DLC?
     
  6. shutterbug2000
    OP

    shutterbug2000 Cubic NINJHAX!

    Member
    1,078
    2,085
    Oct 11, 2014
    United States
    Yep. EShop games for sure, and DLC should work.
     
    canariobr, SoulEater98 and iVcU like this.
  7. veggav

    veggav GBAtemp Regular

    Member
    127
    34
    Nov 21, 2009
    Brazil
    I don't think this will work because DLC/Eshop/VC all have console ID bytes.

    So it's hooked to your console only.
     
  8. Wishi

    Wishi Rareware Gamer

    Member
    185
    147
    Nov 24, 2015
    Mexico
    Great hopefully someone could get us Pokken USA ticket thats the only game I need :c
     
  9. shutterbug2000
    OP

    shutterbug2000 Cubic NINJHAX!

    Member
    1,078
    2,085
    Oct 11, 2014
    United States
    Good point. I'm willing to try, but I'd need someone else's tickets :P

    (either way, still useful for disc games)
     
    iVcU likes this.
  10. brkun

    brkun GBAtemp Fan

    Member
    415
    69
    Mar 9, 2015
    United States
    This, sir, is amazing.

    THanks!
     
    KiiWii likes this.
  11. Kohmei

    Kohmei GBAtemp Advanced Fan

    Member
    758
    457
    Feb 17, 2013
    United States
    I heard the fw.img you need might be available on that one site if you check a PSA thread
     
    veggav likes this.
  12. Exavold

    Exavold GBAtemp Advanced Fan

    Member
    995
    1,043
    Nov 9, 2015
    France
    Wow , I would have dumped a lot of stuff.

    (if I wasn't stuck searching for the ancast iv key :[)
     
  13. veggav

    veggav GBAtemp Regular

    Member
    127
    34
    Nov 21, 2009
    Brazil
    Awesome work! Things move at light speed when the community works together!
     
  14. joacosur15

    joacosur15 GBAtemp Regular

    Member
    114
    49
    Jan 2, 2016
    Argentina
    Buenos Aires
    I think cyan already tested and get different tickets than the public/pirate .wud
     
  15. Pokezuculento

    Pokezuculento GBAtemp Regular

    Member
    103
    23
    Jul 4, 2016
    You can make a video?
     
  16. kongsnutz

    kongsnutz QuickTimeEvent

    Member
    1,457
    272
    Jul 19, 2008
    They work
     
  17. Cyan

    Cyan GBATemp's lurking knight

    Global Moderator
    17,651
    8,240
    Oct 27, 2002
    France
    Engine room, learning
    naah, it's not me.
    I didn't even build the fw.bin (blocked at armips step), or tried any CFW booter.
    I also don't share tickets.


    you can get and share the Disc ticket, but the eShop tickets are linked to the console.
    until there's a CFW patch with signature check removed, users won't be able to use them.
    (unless I'm wrong?)
     
    paulloeduardo likes this.
  18. veggav

    veggav GBAtemp Regular

    Member
    127
    34
    Nov 21, 2009
    Brazil
    What if the exact location of the bytes for the console ID are found and we swap it for our own console ID?
    Would this kill the hash check?
     
  19. SoulEater98

    SoulEater98 Advanced Member

    Newcomer
    52
    15
    Nov 6, 2010
    United States
    You're not able to find them through google?
     
  20. Exavold

    Exavold GBAtemp Advanced Fan

    Member
    995
    1,043
    Nov 9, 2015
    France
    I did , after all.