well. actually sooner or later this thing would have happened.
the wii online store biggest point of failure was, since the beginning, that the whole application and security check is done localy on the wii.
nintendo did a BIG mistake to create a simple passive download server, couse you can actually access the content, encrypted or not, and once you have access to the content, the encryption is only a metter of time.
btw i think that if nintendo is smart enaugh, they will rework the wii shop channel in a more secure way soon.
and i think they will deal with this exploit in two different phases
1) they will prepare a quick workaround wich will temporarely prevent or will make it extremely difficult to use this tool.
2) in the meanwhile they will rework the wii shop with an active server-side web application wich will check directly on the server if a console is authorized to access a particular content or not.
and the second part, despite the backend is pretty easy to implement since all the necessary parts for identifying a wii in an unique way are already in place.
it's enaugh for nintendo to create a database to store the wii console codes that purchased a content, associated to that content.
when you try to download such content, the remote server application will check in the DB for the autorization and will then grant or deny the access to the files.
btw nice exploit, i'm really interested, more then in the software itself, in some documentation explaining the ticket forging process.
i'm not a big fan of piracy, but i like to know how stuff work, so in the hope that you will disclose this vulnerability to the public, i hope, for the sake of nintendo and all the indie software house out there that relay on wiiware to provide low cost quality software, that this bug will be fixed as soon as possible.
@cwstjdenobs: I'm really looking forward to a message from you related to the ticket forging process and the vuln you exploited to accomplish this. even without the software, since as i explained below, i don't really care on pirating wiiware/vc games, can you send me a PM with some infos? or tell me how can i contact you to talk about this topic?
thnx in advice