iQue Player hacking possibility with ique_diag.exe?

Zhongtiao1

Well-Known Member
Member
Joined
Feb 24, 2015
Messages
831
Trophies
0
Age
26
XP
2,765
Country
United States
ique_diag.exe is a diagnosis software for the iQue Player, bundled with the latest iQue@Home update V1.4.2 2005101909. (The latest version has a "diagnosis" feature, which probably uses ique_diag.exe
The latest version is neither downloadable here:http://ique.com/products/M_athome.htm, nor is it included on any disk. It can only be aquired after running the update utility.
(The update server went defunct even before the iQue Player shop shutdown, so there's no way to obtain the update officially now. My iQue@Home was updated to the latest version in mid-2013)
The executable is located at iQue@Home/pkgs/diag.
The software requires hooking an iQue Player to it(not possible if your computer/virtual machine is 64-bit as iQue Player only has a 32-bit driver)but can actually be run without running the entire iQue@Home software, though.
Here are all the commands for ique_diag.exe:
4BiQcRb.png

This exe might be helpful for iQue Player hacking because it extracts tickets and other stuff from the iQue Player, and I've not yet seen any attempts to hack the iQue Player tried using this tool.


Download:http://www.mediafire.com/file/g1xaf6q9k84y5ah/ique_diag.exe

What happens if you try to store a game downloaded from the servers using the BBCStoreContent?
 

KevinLSX

Well-Known Member
Member
Joined
Mar 6, 2016
Messages
526
Trophies
0
XP
1,113
Country
United States
What happens if you try to store a game downloaded from the servers using the BBCStoreContent?
I havent tried that. I dont know where the game files are or where I can download them.

--------------------- MERGED ---------------------------

What happens if you try to store a game downloaded from the servers using the BBCStoreContent?
OP afaik doesnt have the files either.
 

KevinLSX

Well-Known Member
Member
Joined
Mar 6, 2016
Messages
526
Trophies
0
XP
1,113
Country
United States
Found this video a while back and it looks like the guy modded the card with a 4 way dip switch and it allows for every dip switch combo to act like a different memory card. I remeber at some point he offered this as a service and installed games.
Cant understand chinese. Can anyone find out what hes saying

Video:

http://m.youku.com/video/id_XNjg4OTg0MzUy.html?from=s1.8-1-1.2
 

Sliter

Well-Known Member
Member
Joined
Dec 7, 2013
Messages
3,264
Trophies
0
Location
ᕕ( ᐛ )ᕗ
XP
1,771
Country
Brazil
Found this video a while back and it looks like the guy modded the card with a 4 way dip switch and it allows for every dip switch combo to act like a different memory card. I remeber at some point he offered this as a service and installed games.
Cant understand chinese. Can anyone find out what hes saying

Video:

http://m.youku.com/video/id_XNjg4OTg0MzUy.html?from=s1.8-1-1.2
it want me do download an apk õ3o I cant just watch idk


Ive seen that too. Im going to try and open my ique swim box and see if I can solder some n64 controller extension cords to it.
Also I found this wierd port at the back of it


interesting XD maybe an "HD" port to be able to put more game sor something? I don't think it would get something like 64DD , right? hahaha
 

HNKii

Well-Known Member
OP
Member
Joined
Jan 28, 2014
Messages
477
Trophies
0
Location
Mario Kart Wii-DS Link Play Stadium
XP
603
Country
Switzerland
What happens if you try to store a game downloaded from the servers using the BBCStoreContent?
I have tried that, and I think it works just as if you write the game onto card on client.
However, if you're trying to store a game into a slot other than the one it was intended for, the game won't show up on iQue(Say, writing paper Mario (2102104) into empty slot 2103104
 

Sliter

Well-Known Member
Member
Joined
Dec 7, 2013
Messages
3,264
Trophies
0
Location
ᕕ( ᐛ )ᕗ
XP
1,771
Country
Brazil
I have tried that, and I think it works just as if you write the game onto card on client.
However, if you're trying to store a game into a slot other than the one it was intended for, the game won't show up on iQue(Say, writing paper Mario (2102104) into empty slot 2103104
you can't edit the file to place another game instead ?
 

HNKii

Well-Known Member
OP
Member
Joined
Jan 28, 2014
Messages
477
Trophies
0
Location
Mario Kart Wii-DS Link Play Stadium
XP
603
Country
Switzerland
Found this video a while back and it looks like the guy modded the card with a 4 way dip switch and it allows for every dip switch combo to act like a different memory card. I remeber at some point he offered this as a service and installed games.
Cant understand chinese. Can anyone find out what hes saying

Video:

http://m.youku.com/video/id_XNjg4OTg0MzUy.html?from=s1.8-1-1.2
I don't think there's anything technical in there. It's just a demonstration on how it would work.
If anyone can't view the video w/o downloading APK, here it is:
http://v.youku.com/v_show/id_XNjg4OTg0MzUy.html?from=s1.8-1-1.2&spm=a2h0k.8191407.0.0

Edit: Modding iQue card into a combo-4 version probably probably doesn't mean hacking the iQue Player is successful. Otherwise, why didn't he make a single 256-MB card instead?
 
Last edited by HNKii,
  • Like
Reactions: Sliter

Sliter

Well-Known Member
Member
Joined
Dec 7, 2013
Messages
3,264
Trophies
0
Location
ᕕ( ᐛ )ᕗ
XP
1,771
Country
Brazil
I don't think there's anything technical in there. It's just a demonstration on how it would work.
If anyone can't view the video w/o downloading APK, here it is:
http://v.youku.com/v_show/id_XNjg4OTg0MzUy.html?from=s1.8-1-1.2&spm=a2h0k.8191407.0.0

Edit: Modding iQue card into a combo-4 version probably probably doesn't mean hacking the iQue Player is successful. Otherwise, why didn't he make a single 256-MB card instead?
so it's possible to get games that you haven't bought there ?but to edit games to make them work there nothing yet, right ? his card had some mod? what was that red thing ?
 

HNKii

Well-Known Member
OP
Member
Joined
Jan 28, 2014
Messages
477
Trophies
0
Location
Mario Kart Wii-DS Link Play Stadium
XP
603
Country
Switzerland
so it's possible to get games that you haven't bought there ?but to edit games to make them work there nothing yet, right ? his card had some mod? what was that red thing ?
I'm not sure if writing unpurchased games would work( I already owned all 14 games when I tried out this tool.
He hacked the card to work like 4 individual cards. The red stuff is a switch that switches between the 4 individual cards in the iQue Player.
 
  • Like
Reactions: Sliter

Sliter

Well-Known Member
Member
Joined
Dec 7, 2013
Messages
3,264
Trophies
0
Location
ᕕ( ᐛ )ᕗ
XP
1,771
Country
Brazil
I'm not sure if writing unpurchased games would work( I already owned all 14 games when I tried out this tool.
He hacked the card to work like 4 individual cards. The red stuff is a switch that switches between the 4 individual cards in the iQue Player.
hmm well you coult try to dump them and then send to Kevin so he can try doing it? xD also me if I get one ...
 

KevinLSX

Well-Known Member
Member
Joined
Mar 6, 2016
Messages
526
Trophies
0
XP
1,113
Country
United States
I'm not sure if writing unpurchased games would work( I already owned all 14 games when I tried out this tool.
He hacked the card to work like 4 individual cards. The red stuff is a switch that switches between the 4 individual cards in the iQue Player.
Do you know why the program isnt letting me do anything with the ique? It detects it when typing (B) into the command line

The guy flashed the cart to work as 4 different carts. The ique is linked to one cart and its locked. You cant share an ique memory card with another ique system. The one that included with the system cant be used on ther systems.
 

HNKii

Well-Known Member
OP
Member
Joined
Jan 28, 2014
Messages
477
Trophies
0
Location
Mario Kart Wii-DS Link Play Stadium
XP
603
Country
Switzerland
hmm well you coult try to dump them and then send to Kevin so he can try doing it? xD also me if I get one ...
Dump the games? Like I mentioned in my earlier posts, the games dumped from iQue card with iQue_diag are all encrypted files identical to download from http://cds.idc.ique.com:16963/cds/download?content_id=x
(x=content id in Dec)
I do have identity, cert, privatedata,crls, tickets and userdata dumped, if you're interested.

--------------------- MERGED ---------------------------

Do you know why the program isnt letting me do anything with the ique? It detects it when typing (B) into the command line

The guy flashed the cart to work as 4 different carts. The ique is linked to one cart and its locked. You cant share an ique memory card with another ique system. The one that included with the system cant be used on ther systems.
Are you using a 32-bit Windows operating system? If you can't get ique_diag to work, try if the iQue@Home software itself detects your iQue Player.
 
  • Like
Reactions: Sliter

KevinLSX

Well-Known Member
Member
Joined
Mar 6, 2016
Messages
526
Trophies
0
XP
1,113
Country
United States
It is a 32 bit system. The ique is recognized in my drivers as (Ique player) in the unidentified tab

--------------------- MERGED ---------------------------

Actually I just remembered that its 64 bit, but I do have an old 32 bit one. Im going to check. Also i thought the operating system had to be windows xp for it to be read? I guess not since it works with 7 and 8.
 

Krem Quay

Well-Known Member
Newcomer
Joined
Aug 24, 2014
Messages
89
Trophies
0
Age
26
XP
231
Country
United States
Hello, I'm a contact of HNK's. It's been almost 3 years since my last post, and I'm about to do another. While I'm not good at hex editing, I am able to look for human-readable strings.

HNK shared the dumped info, including the encrypted titlekeys, for the games on his iQue system. Download here: https://files.catbox.moe/3n5np9.zip

The tickets file has all the good stuff--most of the text is not readable but I have a few interesting things to note:

After each key, the ISBN for the game is listed. Every iQue product has an ISBN, and if you can identify them, figuring out which title key is which will be easy.

After the ISBN is listed, it's followed by a lot of zeroes (until you get to the next title key): https://files.catbox.moe/do4ca2.png
do4ca2.png


After all the zeroes, another title key will come up. It seems to start with the encrypted title keys (at least I figure). It is then followed by the Root-CPCA00000108-CP0000011 text (whatever that is). For example:

8jb6ue.png


That's all the hex editing of the tickets file I've done thus far, but i've left the files above for you guys to dig through.

--------------------- MERGED ---------------------------

https://archive.org/details/iQuePlayerEncryptedGames

Additionally, the encrypted titles for every title can be downloaded from here. I uploaded this to IA last month.

--------------------- MERGED ---------------------------

Ok, sorry for a triple post but on that page, I recommend downloading the Gamecache.zip since the titles are easily identifiable. HnKii also provided this to me--we've been doing a lot of iQue archiving together.

Download link: https://archive.org/download/iQuePlayerEncryptedGames/GAMECACHE.zip
 
  • Like
Reactions: Sliter and KevinLSX

KevinLSX

Well-Known Member
Member
Joined
Mar 6, 2016
Messages
526
Trophies
0
XP
1,113
Country
United States
Hello, I'm a contact of HNK's. It's been almost 3 years since my last post, and I'm about to do another. While I'm not good at hex editing, I am able to look for human-readable strings.

HNK shared the dumped info, including the encrypted titlekeys, for the games on his iQue system. Download here: https://files.catbox.moe/3n5np9.zip

The tickets file has all the good stuff--most of the text is not readable but I have a few interesting things to note:

After each key, the ISBN for the game is listed. Every iQue product has an ISBN, and if you can identify them, figuring out which title key is which will be easy.

After the ISBN is listed, it's followed by a lot of zeroes (until you get to the next title key): https://files.catbox.moe/do4ca2.png
do4ca2.png


After all the zeroes, another title key will come up. It seems to start with the encrypted title keys (at least I figure). It is then followed by the Root-CPCA00000108-CP0000011 text (whatever that is). For example:

8jb6ue.png


That's all the hex editing of the tickets file I've done thus far, but i've left the files above for you guys to dig through.

--------------------- MERGED ---------------------------

https://archive.org/details/iQuePlayerEncryptedGames

Additionally, the encrypted titles for every title can be downloaded from here. I uploaded this to IA last month.

--------------------- MERGED ---------------------------

Ok, sorry for a triple post but on that page, I recommend downloading the Gamecache.zip since the titles are easily identifiable. HnKii also provided this to me--we've been doing a lot of iQue archiving together.

Download link: https://archive.org/download/iQuePlayerEncryptedGames/GAMECACHE.zip
Thankyou to both of you
 
  • Like
Reactions: Krem Quay

Krem Quay

Well-Known Member
Newcomer
Joined
Aug 24, 2014
Messages
89
Trophies
0
Age
26
XP
231
Country
United States
You're most welcome. It surprises me how the iQue Player games have not been cracked, and since support for the system has ended, I think now is the perfect time to crack the system.
 
  • Like
Reactions: KevinLSX

KevinLSX

Well-Known Member
Member
Joined
Mar 6, 2016
Messages
526
Trophies
0
XP
1,113
Country
United States
You're most welcome. It surprises me how the iQue Player games have not been cracked, and since support for the system has ended, I think now is the perfect time to crack the system.
I think if more people owned the ique, then it someone would have cracked it long ago. I guess there just isnt enough interest in the system.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Sonic Angel Knight @ Sonic Angel Knight: Or, I also heard that if you use flash memory, it can act as more "RAM" at least windows tell me...