Tmbinc says: "Wii hacked it!"

Status
Not open for further replies.

Railgun

( ' _ ' )
OP
Member
Joined
Feb 20, 2006
Messages
326
Trophies
1
Location
GBAtemp City
XP
347
Country
Gambia, The
QUOTE said:
Tmbinc has detailed his exploits in hacking the Wii to run unsigned code on the Debugmo blog...

http://debugmo.de/?p=59

Summary...
Quote:
QUOTE said:
* First thing which ever executes on the Wii is the “boot0? code, which is probably stored inside the hollywood in a mask rom.
* boot0 loads the first 0×2F pages (”boot1?) from flash, decrypts them with a fixed aes key, calculates a SHA-1 hash (with some obscure bugs specialities, I still couldn’t calculate it by hand), and checks that versus the expected values, read from some internal memory.
* If the hash bytes in the “internal memory” is all-zero, the hash check is skipped. This is probably used for production, and maybe for devkits.
* boot1 then searches a certain header in flash, where it extracts specific information where to find boot2.
* At that position, some certificate chain is checked, and finally the boot2 “tmd” is verified, and the hash extracted.
* The boot2 payload is load from flash, decrypted, and hash-checked (against the hash from the boot2 tmd).
* boot2 will then load the firmware, or whatever. That’s not my region of interest at the moment.

SOURCE

Wow, the homebrew is coming soon i think
smile.gif
 
Status
Not open for further replies.

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • K3Nv3 @ K3Nv3:
    Delete ancientboi.bin and leave it deleted
    +1
  • BakerMan @ BakerMan:
    guys, if the first thing you eat for the day is in the afternoon, is that lunch or breakfast?
  • BakerMan @ BakerMan:
    lunch is food in the afternoon, sure, but breakfast is break fast, breaking your fasting
  • BakerMan @ BakerMan:
    does it even matter?
  • AncientBoi @ AncientBoi:
    :unsure: Brunch I think
  • Skv0ra @ Skv0ra:
    And burger rhymes with breakfast
  • Skv0ra @ Skv0ra:
    as well as brunch
  • Skv0ra @ Skv0ra:
    grill chicken salad is IMO way better to start the day than wylk and all that sugar and carbs
    +1
  • AncientBoi @ AncientBoi:
    I intend to make 🌭 🌭 for this afternoon. :unsure: :unsure: :unsure: mmm an maybe put some hormel chili, cheese and top it off with some pickle relish. :)
    +1
  • Skv0ra @ Skv0ra:
    you gotta go score Heinz pickle ketchup! absolute game-changer. and some smol sub or pretzel buns.
    +1
  • K3Nv3 @ K3Nv3:
    Ancientboi has crouton buns
    +2
  • Skv0ra @ Skv0ra:
    oh lord, but that's how I feel picking up my 3DS
  • K3Nv3 @ K3Nv3:
    Lol $80 for the ten people that will buy it looks cool https://youtu.be/3LPb9GksX10
    +1
  • Skv0ra @ Skv0ra:
    neat not to rely on the CDs or similar tho
  • K3Nv3 @ K3Nv3:
    If they could read games directly from it would've worth it more
  • Skv0ra @ Skv0ra:
    So, it can't/isn't a microSD input device?
  • Veho @ Veho:
    You would need to hack the Dreamcast to run games from the memory card instead of trying to read the disk drive.
  • K3Nv3 @ K3Nv3:
    Don't know if it's that hard dreamcast had no write protection and it's basically a ps1
  • Veho @ Veho:
    I guess you could make a bootloader that would just run off a CD and tell the console to read and run a game off of the memory card?
  • K3Nv3 @ K3Nv3:
    They could potentially get GDEMU (GD-ROM Emulator) to read from vmu like how ps1 has mx4iso
  • Veho @ Veho:
    Thing is, the Dreamcast was so easy to pirate I don't think anyone bothered to hack it.
    K3Nv3 @ K3Nv3: https://www.aliexpress.us/item/3256805585920373.html $60 ain't bad