Hacking What Wiis have vulnerable boot1?

haru3173

Well-Known Member
OP
Newcomer
Joined
Feb 2, 2009
Messages
59
Trophies
0
XP
221
Country
United States
I get a message from Bootmii saying Boot Can be installed in one variant” -The installed boot1 version prevents a boot2 install (-2). So I installed bootmii as IOS. Is it because of hardware or software? Can I make my wii to have vulnerable boot1 so I can install bootmii boot2? My wii is Lu35 if that helps.
 

jan777

motion control..? srsly? so 2008. 3DS is teh bombz
Member
Joined
Jan 4, 2008
Messages
2,835
Trophies
1
Age
29
XP
878
Country
i think its hardware

because if it was software, they would have tried to fix it first before distributing it

maybe just wait where bootmii develops and eventually theyll be able to install it on all wiis
 

_Alex_

Member
Newcomer
Joined
Feb 8, 2009
Messages
24
Trophies
0
XP
200
Country
Gambia, The
boot1 is software too, but its secured with a sha-1 encryption + hash, so if it's changed and doesn't match, your wii is permantly bricked...
 

Slowking

Well-Known Member
Member
Joined
Dec 31, 2006
Messages
1,403
Trophies
0
XP
260
Country
Germany
frostyfrosty said:
btw its boot2 =P
It's boot1...

Boot1 sits on a read only chip, so you can not change it and it verifys boot2. Since boot1s produced after mid 2008 don't have the signing bug in them anymore you can't fakesign boot2. It's that simple.
 

haru3173

Well-Known Member
OP
Newcomer
Joined
Feb 2, 2009
Messages
59
Trophies
0
XP
221
Country
United States
Slowking said:
frostyfrosty said:
btw its boot2 =P
It's boot1...

Boot1 sits on a read only chip, so you can not change it and it verifys boot2. Since boot1s produced after mid 2008 don't have the signing bug in them anymore you can't fakesign boot2. It's that simple.

Does that mean there's no hope for us?
 

Don Killah

Well-Known Member
Member
Joined
Nov 21, 2002
Messages
1,186
Trophies
2
Age
48
Website
Visit site
XP
999
Country
France
yep, there's nothing we can do.
basically there's 2 type of Wii:
- those which can install as boot2 -> ultimate brick proof.
- all the others (mines fall into this categorie
wink2.gif
) and install as ios -> brick proof with preloader...
 

supagusti

Well-Known Member
Member
Joined
Feb 2, 2008
Messages
287
Trophies
0
XP
115
Country
Australia
haru3173 said:
Slowking said:
frostyfrosty said:
btw its boot2 =P
It's boot1...

Boot1 sits on a read only chip, so you can not change it and it verifys boot2. Since boot1s produced after mid 2008 don't have the signing bug in them anymore you can't fakesign boot2. It's that simple.

Does that mean there's no hope for us?

not till the real certificates are leaked...

edit: but maybe we can change the flash where boot1 resides. Is it a discrete chip or only part of something other - haven't found a systemboard layout yet!
 

PNo4

Well-Known Member
Member
Joined
Apr 10, 2009
Messages
259
Trophies
1
Website
Visit site
XP
256
Country
supagusti said:
edit: but maybe we can change the flash where boot1 resides. Is it a discrete chip or only part of something other - haven't found a systemboard layout yet!

boot1 is protected by boot0, and boot0 is inside the Hollywood Starlet.
 

supagusti

Well-Known Member
Member
Joined
Feb 2, 2008
Messages
287
Trophies
0
XP
115
Country
Australia
PNo4 said:
supagusti said:
edit: but maybe we can change the flash where boot1 resides. Is it a discrete chip or only part of something other - haven't found a systemboard layout yet!

boot1 is protected by boot0, and boot0 is inside the Hollywood Starlet.

That's real shit !
Cause according to http://wiire.org/Wii/console/motherboard and the datasheet of U14 (the NAND, see http://pdf1.alldatasheet.com/datasheet-pdf...9F4G08U0A.html) there is no technical reason, why we cannot exchange boot1 to an older versions (if it really resides on the chip)
 

supagusti

Well-Known Member
Member
Joined
Feb 2, 2008
Messages
287
Trophies
0
XP
115
Country
Australia
Ok - i've found it here: http://wiibrew.org/wiki/Boot_process
boot1 is secured through a hash:
QUOTE said:
boot1 Lives in a modifiable area of the NAND but cannot be changed due to its hash being stored in the OTP. Run by the Starlet.
As we know there are many different versions of code that produce the same hash.
So it is indeed possible to modify the boot1 on any console out there (although it cannot be done by me ;-))
 

PNo4

Well-Known Member
Member
Joined
Apr 10, 2009
Messages
259
Trophies
1
Website
Visit site
XP
256
Country
@supagusti

No need to complicate the explanations, with 2-3 pages of linked information.

boot1 is protected from alteration, by the sha-1 stored in OTP area, boot0 checks boot1 sha-1 against that sha-1 stored in the OTP area when you startup the Wii.

Oh and for someone to find a correct boot1 alteration that works and produce the same sha-1 as the one stored in the OTP area, i don't think we'll see that before Wii 50 has come if ever
wink.gif
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • SylverReZ @ SylverReZ:
    @Maximumbeans, I'm doing alright, thanks.
    +1
  • Maximumbeans @ Maximumbeans:
    That must be rough. Productive I'm sure but hard to balance with daily life
    +1
  • SylverReZ @ SylverReZ:
    @Maximumbeans, Indeed. I've been working on getting this Infecutus chip to work on my PS2. But after soldering, I realised that a plastic piece was missing from the power ribbon cable to the power and eject buttons.
  • SylverReZ @ SylverReZ:
    Now I could go with soldering the contacts from the cable to the connector on the mobo, but doesn't sound like a good permanent solution.
  • Maximumbeans @ Maximumbeans:
    Man, that's beyond my brain :rofl: I'm no good with hardware for now. I'd like to get into hardmods in future though
  • SylverReZ @ SylverReZ:
    @Maximumbeans, Maybe start practice soldering. Get a cheap-ass soldering iron and follow some good YouTube tutorials.
    +1
  • SylverReZ @ SylverReZ:
    Least my experience has gotten better than over a decade ago. My iron would constantly bump into components and break them.
  • Maximumbeans @ Maximumbeans:
    Sounds good. I actually did soldering but like 16 years ago for school so uuuuh probably rusty haha
  • SylverReZ @ SylverReZ:
    @Maximumbeans, Same here. I did soldering at school from a teacher who I honestly liked since he had plenty of good electronics experience.
    +1
  • Maximumbeans @ Maximumbeans:
    I wish I could play chess well
    +1
  • Maximumbeans @ Maximumbeans:
    Useless but a true art
    +1
  • SylverReZ @ SylverReZ:
    @Maximumbeans, I had a friend who had a glass chess set for their birthday.
  • SylverReZ @ SylverReZ:
    It was like all clear and fancy. Tbf I'm not too experienced with chess, but would like to learn someday.
  • Maximumbeans @ Maximumbeans:
    That sounds really cool
  • Maximumbeans @ Maximumbeans:
    I know the basics but no strategy at all :rofl:
    +1
  • Veho @ Veho:
    Watch chess streamers on Twitch and you'll pick up a thing or two.
    +1
  • Veho @ Veho:
    Not to mention there's an infinite number of chess games for every possible platform.
    +1
  • DinohScene @ DinohScene:
    just play it, get beaten a few times and start dominating
    +1
  • K3Nv2 @ K3Nv2:
    Nude chess is best
    +1
  • DinohScene @ DinohScene:
    strip checkers > nude chess
    +1
  • K3Nv2 @ K3Nv2:
    Nude checkers get jumped
    +1
  • SylverReZ @ SylverReZ:
    @Veho, I guess you'd pick up something while watching tub streams.
  • SylverReZ @ SylverReZ:
    @K3Nv2, Dick fights. :tpi:
  • Veho @ Veho:
    Turkish olive oil wrestling.
    +1
    Veho @ Veho: Turkish olive oil wrestling. +1