Wii Exploit found in Zelda.

Edgedancer

Director of Moon based operations
OP
Member
Joined
Oct 2, 2006
Messages
2,633
Trophies
0
Age
32
Location
Canberra
Website
Visit site
XP
514
Country
Quoted from TheSkeen.com

"Yes, that's right - an exploit for the Nintendo Wii has been discovered and it allows you to run custom code. The method is pretty simple. Copy over a save file for Zelda, load it and the code runs. Don't get too excited yet. They have only been able to run 4 lines of code, but this is in a days work.

Segher was the one to find the exploit and Bushing has been testing it out with the aid of the USB Gecko. The process is far from simple as once you modify a save game it requires it be to signed with 3 keys. Here's some info from Bushing.

"Once the Wii decrypts the save game, it checks its signature. Every Wii has its own private key which is used to sign save games, and when you save a game, the Wii actually saves three bits of data:

* The encrypted save game
* The signature for the save game (using your console's private key)
* A copy of your console's public key, signed by Nintendo."

Of course, the end user wouldn't have to go through this process unless they were wanting to inject their own code into the save game, but that shouldn't be necessary because when I asked Bushing what his goal was he answered:

"Assuming we don't run into a wall, it should be able to lead to a homebrew loader. I hope. No promises. "
 

Attachments

  • zeldacrash0.jpg
    zeldacrash0.jpg
    50.1 KB · Views: 1,115

Dylaan

Well-Known Member
Member
Joined
Jul 5, 2007
Messages
384
Trophies
0
XP
307
Country
Oh yeah!
biggrin.gif
Hopefully it doesn't get patched before something good can be done. I'd love to see something tangible to play with, it's so frustrating just waiting.
tongue.gif
 

Dirtie

:'D
Former Staff
Joined
Sep 9, 2003
Messages
3,705
Trophies
1
Location
Zealer
XP
405
Country
New Zealand
If only the coders ever actually went into details about their findings, then I could have a play around - it wouldn't result in anything, but at least I could gain a better understanding of how these things work
frown.gif
 

TaMs

Randomizer
Member
Joined
Nov 15, 2006
Messages
1,129
Trophies
0
Age
34
XP
360
Country
Finland
hmh it's weird how long it takes to make homebrew for wii, even though it's "hacked" already. This is exploit a good add, but it really seems that no one is interested in wii.
biggrin.gif
 
D

Deleted User

Guest
If only the coders ever actually went into details about their findings, then I could have a play around - it wouldn't result in anything, but at least I could gain a better understanding of how these things work
frown.gif
looking at the first post, the only possible way they could inject some code would have been by extracting the private key of their console, and use it to sign code. Once you have a proper save that can act as a loader, you can give it to other people like one can share a save file. The dev giving info would either require you to have dumped you wii private key, which will not be that useful considering how hard it could be to dump it, or have them give theirs, which will expose them quite directly by the fact that the private key is directly linked to a console serial number. The way the exploit work should be fairly simple, something like a uber long char name where the game store it in a finite sized buffer.
 

Scorpei

Well-Known Member
Member
Joined
Aug 21, 2006
Messages
1,295
Trophies
0
Website
scorpei.com
XP
263
Country
Netherlands
hmh it's weird how long it takes to make homebrew for wii, even though it's "hacked" already. This is exploit a good add, but it really seems that no one is interested in wii.
biggrin.gif
Hardly, the original hack was fairly easy to patch for the big N (afaik) thus they didn't want to release anything specific as that would plug the hole for them to search for more exploits. Patching the save (though possible, it is signed with a specific key from the console that made the save) is slightly less important as once HB runs everyone could make a similar save (could be run through your own Wii to get it encrypted and signed) so then every Wii would have to be covered/blocked. Everyone COULD make their own save once HB runs and thus this is harder to block.

Don't quote me on this btw
tongue.gif
. Only written with my limited knowlidge of encryption, signing and etc. (so I could be really wrong ;p).
 

[Truth]

Well-Known Member
Member
Joined
Mar 21, 2006
Messages
1,062
Trophies
1
Location
Mushroom Kingdom
XP
2,457
Country
Germany
hmh it's weird how long it takes to make homebrew for wii, even though it's "hacked" already. This is exploit a good add, but it really seems that no one is interested in wii.
biggrin.gif
of course many are interested in it and they are working hard on it, but most of the hb developers don´t make their proceedings public until they are working stable, like bushing and segher now do.
2222046163_e76513996e_o_d.jpg
 

Jax

Pip Pip Cheerioink!
Member
Joined
Jul 31, 2006
Messages
4,132
Trophies
0
Age
36
Location
L.A.V.
XP
1,123
Country
Portugal
QUOTE([Truth said:
@ Jan 27 2008, 12:30 PM)]
hmh it's weird how long it takes to make homebrew for wii, even though it's "hacked" already. This is exploit a good add, but it really seems that no one is interested in wii.
biggrin.gif


of course many are interested in it and they are working hard on it, but most of the hb developers don´t make their proceedings public until they are working stable, like bushing and segher now do.
2222046163_e76513996e_o_d.jpg

FAIL!

That's the GC version!
rofl2.gif
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • NinStar @ NinStar:
    on tiramisu you can access it by opening mii maker
  • crafthp434 @ crafthp434:
    okay
  • NinStar @ NinStar:
    I don't have a wii u anymore to test it myself, but if homebrews are not visible on the wii u menu I think you can press L + R + minus to open the plugin menu, there should be an option called "homebrews on wii u menu" or something similar
  • crafthp434 @ crafthp434:
    nope
  • crafthp434 @ crafthp434:
    it is L+dpad down+ select
  • crafthp434 @ crafthp434:
    but homebrew is appearing in the home menu btw
  • NinStar @ NinStar:
    yes, now I remember it
  • NinStar @ NinStar:
    then it is working, I also don't like that they did this but it is the only option you have if you are using aroma
  • crafthp434 @ crafthp434:
    i just didint know the homebrew launcher didint exist in aroma
  • crafthp434 @ crafthp434:
    thanks btw
  • Xdqwerty @ Xdqwerty:
    Im downloading fallout 3 goty edition
    +1
  • BigOnYa @ BigOnYa:
    I'm downloading more ram for my hamster pc
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    New hamster PC, with anal operation and BT connectivity!
    +1
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, How do I make enemies respawn on gdevelop after
    the player dies?
  • Psionic Roshambo @ Psionic Roshambo:
    Carrying a PC or phone is so old school!
  • Psionic Roshambo @ Psionic Roshambo:
    Squeeze your cheeks twice to answer calls!
  • BigOnYa @ BigOnYa:
    @Xdqwerty you can use a "spawner" function on any object.
    +1
  • BigOnYa @ BigOnYa:
    Or when your player dies, you can say in code, if enemy exists, do nothing, but if enemy does not exist, then create enemy at certain spot. (This would be a pain tho for lots of emeies)
    +1
  • BigOnYa @ BigOnYa:
    Easiest, simple way would be just restart scene, but player would restart from beginning.
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, thx in advance
    +1
  • Spider2190 @ Spider2190:
    Heya
  • Spider2190 @ Spider2190:
    How are you doing, @Xdqwerty
    ?
  • Psionic Roshambo @ Psionic Roshambo:
    Dolphin porn??? This man has my vote!!! Lol
    Psionic Roshambo @ Psionic Roshambo: Dolphin porn??? This man has my vote!!! Lol