Hacking Question about trucha bug restorer ?

Cecilmax

Well-Known Member
OP
Member
Joined
Mar 7, 2015
Messages
451
Trophies
0
Age
44
XP
1,196
Country
Canada
Hi guys,

I just found there is a possibility to use trucha bug restorer to be able to install bootmii on boot2..

But I have wii with serial 7xx on 4.2u softmodded, can someone confirm I can use that tool to restore the bug ?

Thanks :)
 

Litle_Bird

Well-Known Member
Member
Joined
Jan 1, 2017
Messages
133
Trophies
0
Age
28
XP
1,404
Country
Sweden
Long answer, it is not possible to modify boot2 and replace it with bootmii on newer Wiis and here's why.

The Wiis boot process consist of boot0, boot1 and boot2. When you press the power button on the Wii, boot0 is initiated, this bootrom is hardcoded inside the GPU. Boot0 does some things, and verifies boot1 through a hash control, one hash value is programmed inside boot0 and one hash in on the go, meaning boot0 calculates it. This means, if you modified boot1 the hash would be different compared to what boot0 expects. If the hashes match boot1 is launched, it does more things before initiating boot2, boot2 is verified by boot1, and is only launched if the it is signed by nintendo. However early wiis had the trucha bug (string comparison bug) which let things be fake signed yet the wii would still believe the signature to be correct.

This is what bootmii exploited, since bootmii, a substitute for boot2 could be fake signed making boot1 think that bootmii was properly signed and execute it. So why can't you restore the trucha bug in boot1 then? As I said earlier, boot0 has a stored hash value of boot1, and at each start the boot1 located nand is hashed, and if the hashes match, boot0 proceds to execute boot1. If you would reintroduce the trucha bug, you would change the hash value of boot1 and thus boot 0 would not execute it, essentially hardbricking your console.
 
  • Like
Reactions: Cecilmax

Cecilmax

Well-Known Member
OP
Member
Joined
Mar 7, 2015
Messages
451
Trophies
0
Age
44
XP
1,196
Country
Canada
Thanks for the informations :) I think my only hope to protect from brick then it is to install priiload :)
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    NinStar @ NinStar: It will actually make it worse