De_Fuse: Unable to Dump OTP.bin: Firmware Mismatch

Bman3990wx

Active Member
OP
Newcomer
Joined
May 7, 2023
Messages
33
Trophies
0
Age
23
XP
103
Country
United States
Hello All,
Taking a stab at another Wii U recovery. Boots the the Wii U logo and freezes. Tried UDPIH and nothing happened, so I moved on to De_Fuse. De_Fuse seemed to install correctly, but the output in Putty gets scrambled after the exploit starts (which is why I am not posting outputs from Putty in the initial post. Sorry, I know those are preferred for cases like this). The output on the TV is fine though, so I kept going and installed a nandaid board and new SD card.

Attempting to Dump OTP.bin with PRSHhax results in "Unknown Prod boot1 version: v1610612831 (2068) either your nand is corrupt or you got something exotic" error. I looked around the gbatemp forums and found https://gbatemp.net/threads/how-to-...ii-u-internal-memory-mlc.636309/post-10226220 in here, shinyquagsire posts the hash of a BOOT1_SLC.RAW and a website to verify what the hash is. I looked at mine and I do not get the same hash (MD5: mine: f2fccabb8ecf9f720b9fc6a2de45e84c shiny: c941ed70442744feafcb8578e5625c09).

At this point I'm assuming that my boot1 is somehow corrupt or this is a really interesting Wii U. Is there anything that I can do? I see that it's possible to flash a new boot1 through minute, but not sure if that's tied to the console. (Attached is the Boot1_SLC that I dumped if you want to have a look. I also have dumps of SLC.RAW, SLCCMPT.RAW, and seeprom.bin if that helps).
 

Attachments

  • Boot1_SLC.zip
    57.5 KB · Views: 8

Lazr1026

Well-Known Member
Member
Joined
Oct 30, 2020
Messages
148
Trophies
0
Age
17
XP
756
Country
United States
can you send me the SEEPROM? The SEEPROM key seems to be identical between all retail wiius, so I should be able to decrypt it.
 

Lazr1026

Well-Known Member
Member
Joined
Oct 30, 2020
Messages
148
Trophies
0
Age
17
XP
756
Country
United States
try putting the otp.bin from here onto the sd root, dump the otp and seeprom in minute, and then send the decrypted seeprom

delete this otp after dumping the seeprom. booting iosu with the wrong otp can be dangerous
 

Attachments

  • otp.bin.zip
    1 KB · Views: 5

Bman3990wx

Active Member
OP
Newcomer
Joined
May 7, 2023
Messages
33
Trophies
0
Age
23
XP
103
Country
United States
try putting the otp.bin from here onto the sd root, dump the otp and seeprom in minute, and then send the decrypted seeprom

delete this otp after dumping the seeprom. booting iosu with the wrong otp can be dangerous
Ok. Here's what I got from that
 

Attachments

  • Decrypt_SEEPROM.zip
    380 bytes · Views: 5

Lazr1026

Well-Known Member
Member
Joined
Oct 30, 2020
Messages
148
Trophies
0
Age
17
XP
756
Country
United States
your boot1 version is v8339, which is really old. i bet iosu is also really old, so udpih not working makes sense
Post automatically merged:

i just checked, this wiiu is running somewhere around 3.0.0!
 

Bman3990wx

Active Member
OP
Newcomer
Joined
May 7, 2023
Messages
33
Trophies
0
Age
23
XP
103
Country
United States
oh holy hek! lmao
Post automatically merged:

Thatsssss gotta have been sitting in the closet for a while....
 

Lazr1026

Well-Known Member
Member
Joined
Oct 30, 2020
Messages
148
Trophies
0
Age
17
XP
756
Country
United States
I think the best thing to do here is to flash the latest boot1 to the slc, and then let it fix the seeprom. you would need to have that otp on the sd though. PRSHhax should work after that
Post automatically merged:

this should be the latest version of boot1. you would just copy the BOOT1_SLC.RAW and restore it in minute and let it fix the seeprom.
 

Attachments

  • BOOT1_SLC.zip
    57.4 KB · Views: 8
Last edited by Lazr1026,

Bman3990wx

Active Member
OP
Newcomer
Joined
May 7, 2023
Messages
33
Trophies
0
Age
23
XP
103
Country
United States
Ok. So do I get that through JNUS (found the title ID) and flash it through minute using the Restore BOOT1_SLC.RAW? Or do I need to obtain another BOOT1_SLC.RAW from another Wii U?
 

Lazr1026

Well-Known Member
Member
Joined
Oct 30, 2020
Messages
148
Trophies
0
Age
17
XP
756
Country
United States
i already sent you a boot1 you can flash. the boot1 packages from nus arent in a neat little format you can just flash
 

Bman3990wx

Active Member
OP
Newcomer
Joined
May 7, 2023
Messages
33
Trophies
0
Age
23
XP
103
Country
United States
ope sorry, didn't refresh to see that post. I'll give it a shot!
Post automatically merged:

That got farther, but it blackscreens on the reboot.

1714261045861.png

1714261078937.png
 
Last edited by Bman3990wx,

Bman3990wx

Active Member
OP
Newcomer
Joined
May 7, 2023
Messages
33
Trophies
0
Age
23
XP
103
Country
United States
Oh sorry, I took that out after I flashed the BOOT1_SLC.RAW.

Tried to dump the OTP again with that OTP.bin on the sd card after and get this:

1714261613036.png

1714261637765.png


After these flashes, I get a black screen.
Post automatically merged:

I wondered what would happen if I unpluged and plugged back in De_Fuse when the system showed a black screen and it comes up with the below:
View attachment 1714270333781.jpeg

Potentially an issue SEEPROM?
Post automatically merged:

Ok big news.

I had another idea. I didn't like how the putty terminal was outputting garbage after the console launched the minute menu. So I tried an older version of De_Fuse/minute and my Putty terminal returned to normal.

I then tried dumping the OTP on this setup and it successfully dumped!!!!! Now to put it back on the new version and install some cafe os.
 
Last edited by Bman3990wx,

V10lator

Well-Known Member
Member
Joined
Apr 21, 2019
Messages
2,680
Trophies
1
Age
36
XP
5,663
Country
Germany
Now to put it back on the new version and install some cafe os.
In case the data on the console isn't important for you I would suggest to do a complete firmware update by rebuilding the MLC as described here: https://gbatemp.net/threads/how-to-upgrading-rebuilding-wii-u-internal-memory-mlc.636309/

Just make sure to not only install the MLC titles but the SLC titles, too (as the guide says: If your console has an old firmware it might also be necessary to get the latest SLC titles). Installing both, MLC and SLC titles is equal to a firmware update. ;)

You can even upgrade the SD card in the NAND-AID to 64 GB while doing so (or even higher with permanent ISFSHax or de_fuse).
 

Bman3990wx

Active Member
OP
Newcomer
Joined
May 7, 2023
Messages
33
Trophies
0
Age
23
XP
103
Country
United States
In case the data on the console isn't important for you I would suggest to do a complete firmware update by rebuilding the MLC as described here: https://gbatemp.net/threads/how-to-upgrading-rebuilding-wii-u-internal-memory-mlc.636309/

Just make sure to not only install the MLC titles but the SLC titles, too (as the guide says: If your console has an old firmware it might also be necessary to get the latest SLC titles). Installing both, MLC and SLC titles is equal to a firmware update. ;)

You can even upgrade the SD card in the NAND-AID to 64 GB while doing so (or even higher with permanent ISFSHax or de_fuse).
Yep! I got the SLC files and the MLC ones, threw them on the as card and went off to the races…. 30 mins of troubleshooting bad solder joints on my nandaid later and I’m in Caffe OS!

I wish I had a bigger SD card on hand but 32gb was what I had laying around.

Thank you for your help everyone!!!!
 
  • Like
Reactions: V10lator

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, the other game where I found newgrounds is new york shark
    +1
  • SylverReZ @ SylverReZ:
    Spoke to Tom Fulp the other day, if he can find his old Newgrounds site content like the mini Flash animations from the 2000's that played on the portal.
  • SylverReZ @ SylverReZ:
    So far no response, but he did say that he'll find them. Wayback Machine doesn't have em.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, atleast the 1999 versión of pico's school is avaliable (the difference between it, the 2006 versión and the 2016 versión is that the speed of the game depends of the speed of your computer and that it had the og soundtrack)
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Another being Pico VS Bear, the original 1999 version before Jim Henson filed a DMCA takedown.
    +1
  • Xdqwerty @ Xdqwerty:
    The 2006 versión was made when the flash portal was made
  • SylverReZ @ SylverReZ:
    Many people thought it was lost, but was discovered that he hid it on the same page.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, although the "secrets" system where the game was has been removed. Also pico vs uberkids had a netplay versión that was shutdown, although the swf file has been found
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Nope. There are two download buttons on the same page, where you can download the original under a file called "bear.exe". "bear2.exe", however, is the updated game in a Flash projector. P.s. this was on the archived Pico page from 2000.
  • SylverReZ @ SylverReZ:
    @Xdqwerty, That's been there for a long time, too. People who search for lost media don't look hard enough lmao.
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, also the pico 2 demos used to be only for the newgrounds patrons but they are on internet archive too (https://archive.org/download/picos_school_2)
    +1
  • Xdqwerty @ Xdqwerty:
    Iirc the demos were removed from newgrounds in 2022
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, or well only the demo with mindchamber's style was on newgrounds
    +1
  • Xdqwerty @ Xdqwerty:
    Fun fact @SylverReZ: iirc one of the goals on the fnf Kickstarter stated that pico 2 would be finished but the Kickstarter didnt get enough money for that goal to be fullfiled
  • SylverReZ @ SylverReZ:
    @Xdqwerty, FNF sucks, their community is toxic as hell.
  • The Real Jdbye @ The Real Jdbye:
    @SylverReZ its a single player game
  • Xdqwerty @ Xdqwerty:
    @The Real Jdbye, Yea but it has a shitton of mods with their own songs and stuff
  • Xdqwerty @ Xdqwerty:
    @The Real Jdbye, and quite a lot of people involved in those mods get cancelled
  • SylverReZ @ SylverReZ:
    Newgrounds wasn't the birth of FNF; rather, it was games where you beat up celebrities and parodies.
    +2
  • a_username_that_is_cool @ a_username_that_is_cool:
    FNF was born from Game Jams
  • a_username_that_is_cool @ a_username_that_is_cool:
    Specifically Ludum Dare 47
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, and Sonic fights a la dragón ball z
    Xdqwerty @ Xdqwerty: