Unable to dump OTP.bin

skawo

Well-Known Member
OP
Member
Joined
Aug 18, 2015
Messages
623
Trophies
0
Age
34
XP
3,072
Got this WiiU with flashing blue light.
Defusing worked and I can get into minute. I dumped Seeprom, SLC.raw and SLCCMPT.raw before I did anything.

Trying to dump OTP with PRSHhax fails with message:

Code:
Unknown dev boot1 version: v1610612831 (2069).
Either your NAND is corrupt of you've got something exotic,
maybe ask ShinyQuagsire to add a bruteforce option.

Can anything be done, or is the SLC toast somehow?
I followed the suggestion here:
https://gbatemp.net/threads/de_fuse-unable-to-dump-otp-bin-firmware-mismatch.654994/

But then I get a message that it can't write the boot1 version to SEEPROM. Trying to dump otp then always results in:

Code:
boot1 never jumped to payload! Offset or SEEPROM version might be incorrect.
(try it again just in case, sometimes the resets can get weird)
 
Last edited by skawo,

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,969
Trophies
2
Age
29
XP
2,289
Country
Germany
Since the seeprom key seems to be the same on all consoles, you could try to use another consoles otp.bin while flashing the latest boot1.raw (dumped from another console) and update the version in the seeprom with that.
After that remove the otp.bin again and try PRSHhax again.

If course make a seeprom and SLC backup before attempting this and copy it somewhere safe
 

skawo

Well-Known Member
OP
Member
Joined
Aug 18, 2015
Messages
623
Trophies
0
Age
34
XP
3,072
I get the following using another console's OTP.bin:
1715796433081.png


Also, somehow otp.bin, seeprom.bin and the BOOT1_SLC.raw image get changed into hex zeroes on the SD card...?
 

skawo

Well-Known Member
OP
Member
Joined
Aug 18, 2015
Messages
623
Trophies
0
Age
34
XP
3,072
Fake 1GB SD card...?
...Well, I mean, I guess I can try another one.
Post automatically merged:

Dang, I guess it was either fake or faulty, because it no longer does that zeroing thing.

Seeprom still fails to validate, though :/

I wonder if I now screwed this up because I didn't notice the SD was fake, and thus don't have a valid seeprom/slc backup :s
 
Last edited by skawo,

skawo

Well-Known Member
OP
Member
Joined
Aug 18, 2015
Messages
623
Trophies
0
Age
34
XP
3,072
Unfortunately, while I only wrote the Boot1_SLC.RAW to SLC, I did try to restore seeprom.bin from the backup I made - and that seems to fail to verify.

I attached it, and it doesn't LOOK wrong, but clearly it is.

So I think I boned myself by not considering that a 1GB SD can be fake :s
 

Attachments

  • seeprom.zip
    394 bytes · Views: 26

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,969
Trophies
2
Age
29
XP
2,289
Country
Germany
There are two copies of the the boot1 on the SD. Did it reject to write the seeprom? Then you should be good.
What is the attached seeprom? A freshly dumped one?
 

skawo

Well-Known Member
OP
Member
Joined
Aug 18, 2015
Messages
623
Trophies
0
Age
34
XP
3,072
That's the SEEPROM I dumped on the fake SD card. If I try dumping SEEPROM now, it is the same :s
Post automatically merged:

Oh well.
Unless there's some way to boot without a valid SEEPROM and the SLC, I guess this is done.

Too bad that out of four 1GB SD cards I have I happened to pick up the only one that's faulty/fake :s
 
Last edited by skawo,

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,969
Trophies
2
Age
29
XP
2,289
Country
Germany
The seeprom looks fine. The only thing notable is that the USB keys seems to be all 0, the rest looks normal
 

skawo

Well-Known Member
OP
Member
Joined
Aug 18, 2015
Messages
623
Trophies
0
Age
34
XP
3,072
Well, attempting to write it back with another console's OTP present results in it failing to verify.
So... :s
 

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,969
Trophies
2
Age
29
XP
2,289
Country
Germany
you should not write the backup back. Just flash the boot1.raw backed up from another console and then it should prompt you to update the bboot1 version in the seeprom. If it fais at that I have to see if I can decrypt the seeprom and looks at how minute veriefies the seeprom. Do you have the exact error message?
 

skawo

Well-Known Member
OP
Member
Joined
Aug 18, 2015
Messages
623
Trophies
0
Age
34
XP
3,072
Doesn't prompt me to fix the SEEPROM, just seems to do it automatically (or tries to verify the seeprom before trying to), at which point It just says pretty much the same thing:
1715805216055.png
 

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,969
Trophies
2
Age
29
XP
2,289
Country
Germany
hm yeah the versions look wrong, so the decryption probably failed. On the other hand the versions look close together, so maybe not? Very strange.
That is a standard retail console? What board revision does it have?
 

skawo

Well-Known Member
OP
Member
Joined
Aug 18, 2015
Messages
623
Trophies
0
Age
34
XP
3,072
No idea, frankly. It LOOKS normal, but it's odd. It has a weird label on the case that seems misprinted, because it's mirrored.
Board is WUP-CPU-X10
 

SDIO

Well-Known Member
Member
Joined
Feb 13, 2023
Messages
2,969
Trophies
2
Age
29
XP
2,289
Country
Germany
That's definitely no retail console, so the boot1 from a retail console probably won't work. Also the SEEPROM key is likely different
 

skawo

Well-Known Member
OP
Member
Joined
Aug 18, 2015
Messages
623
Trophies
0
Age
34
XP
3,072
Huh, well, that's a doozy, then.

I guess it did say
"Unknown dev boot1 version: v1610612831 (2069)."

Naturally I have no idea where one would source this stuff from now, though :s
 

Lazr1026

Well-Known Member
Member
Joined
Oct 30, 2020
Messages
164
Trophies
0
Age
18
XP
873
Country
United States
this is absolutely not a retail console, its probably a test console of some sort. It's probably using the DEBUG keyset, which I do have an otp of which i can send you later
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Xdqwerty @ Xdqwerty: I wish I was allowed to talk to people online