Hacking Trucha Bug Restorer release

WiiPower

Well-Known Member
OP
Member
Joined
Oct 17, 2008
Messages
8,165
Trophies
0
XP
345
Country
Gambia, The
For everybody who wants to try to get Trucha Bug Restorer compatible with the 4.3 update:
ES_AddTitleFinish does check the signature of titles before moving them from /tmp to the correct IOS folder. The error code -1017 should indicate that it's failing because of a signature check and not a version check. If i try to start the installation as regular and then replace all files in /tmp from IOS15v1031 with the ones from IOS15v257*, i still get -1017 on ES_AddTitleFinish. My theory is that after calling ES_AddTitleStart the signatures are saved in memory and ES_AddTitleFinish checks against them. If that's true(which i doubt somehow), then it might be possible to search the signatures in memory and change them to the ones of the title we really want to install.

SifJar said:
TT have said before they have dozens of IOS exploits, so I'm pretty sure they'll be releasing a new HackMii Installer soon. Even if they don't have IOS exploits working on 4.3, others do, like the guys behind Riivolution (installing its channel works on a "virgin" 4.3 Wii).

Any more info about this channel installation? I heard that TT has a few exploits lying around, but currently no exploit to get the privileges that allow to install stuff.

*I do that because IOS15v257 IS correctly signed
 

SifJar

Not a pirate
Member
Joined
Apr 4, 2009
Messages
6,022
Trophies
0
Website
Visit site
XP
1,175
Country
WiiPower said:
SifJar said:
TT have said before they have dozens of IOS exploits, so I'm pretty sure they'll be releasing a new HackMii Installer soon. Even if they don't have IOS exploits working on 4.3, others do, like the guys behind Riivolution (installing its channel works on a "virgin" 4.3 Wii).

Any more info about this channel installation? I heard that TT has a few exploit lying around, but currently no exploit to get the privileges that allow to install stuff.
No. All I know is AerialX said in the Riivolution thread here: http://gbatemp.net/t215807-riivolution?vie...t&p=2934518 that they updated for 4.3, and to use it you can load it via Indiana Pwns or Smash Stack and install the channel.

Also, apparently there's an IOS exploit that's been in the dop-Mii source for a while unnoticed that may work for this...
 

WiiPower

Well-Known Member
OP
Member
Joined
Oct 17, 2008
Messages
8,165
Trophies
0
XP
345
Country
Gambia, The
SifJar said:
WiiPower said:
SifJar said:
TT have said before they have dozens of IOS exploits, so I'm pretty sure they'll be releasing a new HackMii Installer soon. Even if they don't have IOS exploits working on 4.3, others do, like the guys behind Riivolution (installing its channel works on a "virgin" 4.3 Wii).

Any more info about this channel installation? I heard that TT has a few exploit lying around, but currently no exploit to get the privileges that allow to install stuff.
No. All I know is AerialX said in the Riivolution thread here: http://gbatemp.net/t215807-riivolution?vie...t&p=2934518 that they updated for 4.3, and to use it you can load it via Indiana Pwns or Smash Stack and install the channel.

Also, apparently there's an IOS exploit that's been in the dop-Mii source for a while unnoticed that may work for this...

Interesting, did anybody test this exploit by installing one of the new IOS and running dop-Mii with it?
 

SifJar

Not a pirate
Member
Joined
Apr 4, 2009
Messages
6,022
Trophies
0
Website
Visit site
XP
1,175
Country
Arikado was going to do that last night when I was talking to him on IRC, but I left before he gave his results as it was late and I was tired.
sleep.gif
 

SifJar

Not a pirate
Member
Joined
Apr 4, 2009
Messages
6,022
Trophies
0
Website
Visit site
XP
1,175
Country
BTW, once HackMii Installer is working on 4.3, there's apparently a reasonably simple way you can install fake signed content (e.g. patched IOS) on any Wii, regardless of the installed IOS. The Wii just needs DVDx, which when HackMii Installer gets updated to work (as I'm sure it will soon), all Wiis can have.

You run DVDx, which gives you access to ahbprot, allowing you to disable MEM2 protection and patch the sig checking function of ES, which then lets you install fakesigned content e.g. a patched IOS. sven_p mentioned this on #wiidev last night, WiiPower, perhaps you could implement this in a new version of TBR (I'm sure you'll be able to work out how to do all that stuff, I haven't a clue, but apparently its not too hard, and you seem pretty good with that sort of thing
wink.gif
)
 

BBking83

Well-Known Member
Member
Joined
Oct 23, 2008
Messages
676
Trophies
1
Location
Australia
XP
227
Country
Hang on. I know I'm no coder, but you're trying to get TBR to work on "virgin 4.3" Wiis, yeah? They won't have DVDx (IOS254 is stubbed).

So I guess you are relying on a new HackMii installer in which a new TBR can be run? Or just looking at ideas?
smile.gif
 

tj_cool

Site dev
Supervisor
Joined
Jan 7, 2009
Messages
10,064
Trophies
2
Location
This planet
XP
3,107
Country
Belgium
BBking83 said:
Hang on. I know I'm no coder, but you're trying to get TBR to work on "virgin 4.3" Wiis, yeah? They won't have DVDx (IOS254 is stubbed).

So I guess you are relying on a new HackMii installer in which a new TBR can be run? Or just looking at ideas?
smile.gif
DVDx isn't installed as IOS254
huh.gif


Anyway, yeah I think he means after a new HackMii installer is out.
It'd be great if that method works though
smile.gif
 

BBking83

Well-Known Member
Member
Joined
Oct 23, 2008
Messages
676
Trophies
1
Location
Australia
XP
227
Country
Sorry, I swear I remember reading that it was. It must have been BootMii...
unsure.gif


SifJar said:
Yeah I mean once a new HackMii Installer is released. Hence I said at the start of my post "BTW, once HackMii Installer is working on 4.3"
tongue.gif
fazeparm...

Sorry. Again.
 

WiiPower

Well-Known Member
OP
Member
Joined
Oct 17, 2008
Messages
8,165
Trophies
0
XP
345
Country
Gambia, The
SifJar said:
BTW, once HackMii Installer is working on 4.3, there's apparently a reasonably simple way you can install fake signed content (e.g. patched IOS) on any Wii, regardless of the installed IOS. The Wii just needs DVDx, which when HackMii Installer gets updated to work (as I'm sure it will soon), all Wiis can have.

You run DVDx, which gives you access to ahbprot, allowing you to disable MEM2 protection and patch the sig checking function of ES, which then lets you install fakesigned content e.g. a patched IOS. sven_p mentioned this on #wiidev last night, WiiPower, perhaps you could implement this in a new version of TBR (I'm sure you'll be able to work out how to do all that stuff, I haven't a clue, but apparently its not too hard, and you seem pretty good with that sort of thing
wink.gif
)

I can't do any of that, and the exploit used in TBR is really simple compared to this. And if we get a new hackmii installer, i will take a closer look at mini. That way i could write something that always works as long as there's a way to get BootMii IOS.
 

SifJar

Not a pirate
Member
Joined
Apr 4, 2009
Messages
6,022
Trophies
0
Website
Visit site
XP
1,175
Country
WiiPower said:
SifJar said:
BTW, once HackMii Installer is working on 4.3, there's apparently a reasonably simple way you can install fake signed content (e.g. patched IOS) on any Wii, regardless of the installed IOS. The Wii just needs DVDx, which when HackMii Installer gets updated to work (as I'm sure it will soon), all Wiis can have.

You run DVDx, which gives you access to ahbprot, allowing you to disable MEM2 protection and patch the sig checking function of ES, which then lets you install fakesigned content e.g. a patched IOS. sven_p mentioned this on #wiidev last night, WiiPower, perhaps you could implement this in a new version of TBR (I'm sure you'll be able to work out how to do all that stuff, I haven't a clue, but apparently its not too hard, and you seem pretty good with that sort of thing
wink.gif
)

I can't do any of that, and the exploit used in TBR is really simple compared to this. And if we get a new hackmii installer, i will take a closer look at mini. That way i could write something that always works as long as there's a way to get BootMii IOS.

That may be a better option, but why can't you do what I said? Something specifically stopping you? (Not trying to be rude, just curious)
 

WiiPower

Well-Known Member
OP
Member
Joined
Oct 17, 2008
Messages
8,165
Trophies
0
XP
345
Country
Gambia, The
I don't know how to run DVDX, ok that's something i should be able to figure out. Then i do not know what ahbprot is, but maybe it allows me to set the register for mem2 protection, which i don't know how to do it. Well once that's figured out, i may be able to read mem2, look for the code i patch in IOS to ignore signatures and then patch it. But i don't really know where to start on that one. Using mini code on the other hand, i could just write revision 0 into the IOS15 tmd, and done. Or i could read the ES module of IOS36 and patch it directly on nand. Also it should be possible to install patched IOS to nand with a mod of sneek that does NOT emulate the nand, but does everything else sneek does.
 

Aurora Wright

Well-Known Member
Member
Joined
Aug 13, 2006
Messages
1,550
Trophies
3
XP
4,505
Country
Italy
SifJar said:
BTW, once HackMii Installer is working on 4.3, there's apparently a reasonably simple way you can install fake signed content (e.g. patched IOS) on any Wii, regardless of the installed IOS. The Wii just needs DVDx, which when HackMii Installer gets updated to work (as I'm sure it will soon), all Wiis can have.

You run DVDx, which gives you access to ahbprot, allowing you to disable MEM2 protection and patch the sig checking function of ES, which then lets you install fakesigned content e.g. a patched IOS. sven_p mentioned this on #wiidev last night, WiiPower, perhaps you could implement this in a new version of TBR (I'm sure you'll be able to work out how to do all that stuff, I haven't a clue, but apparently its not too hard, and you seem pretty good with that sort of thing
wink.gif
)
Once it's working, you can just install BootMii as IOS and install a cIOS using cBoot2
smile.gif
 

Kikoshi

Well-Known Member
Member
Joined
Dec 21, 2006
Messages
157
Trophies
1
Location
Cuba
XP
262
Country
Davi92 said:
SifJar said:
BTW, once HackMii Installer is working on 4.3, there's apparently a reasonably simple way you can install fake signed content (e.g. patched IOS) on any Wii, regardless of the installed IOS. The Wii just needs DVDx, which when HackMii Installer gets updated to work (as I'm sure it will soon), all Wiis can have.

You run DVDx, which gives you access to ahbprot, allowing you to disable MEM2 protection and patch the sig checking function of ES, which then lets you install fakesigned content e.g. a patched IOS. sven_p mentioned this on #wiidev last night, WiiPower, perhaps you could implement this in a new version of TBR (I'm sure you'll be able to work out how to do all that stuff, I haven't a clue, but apparently its not too hard, and you seem pretty good with that sort of thing
wink.gif
)
Once it's working, you can just install BootMii as IOS and install a cIOS using cBoot2
smile.gif
So this way im able to Access the Boot2 with BootMii when i wasn't able to before? O_ O
 

SifJar

Not a pirate
Member
Joined
Apr 4, 2009
Messages
6,022
Trophies
0
Website
Visit site
XP
1,175
Country
Davi92 said:
SifJar said:
BTW, once HackMii Installer is working on 4.3, there's apparently a reasonably simple way you can install fake signed content (e.g. patched IOS) on any Wii, regardless of the installed IOS. The Wii just needs DVDx, which when HackMii Installer gets updated to work (as I'm sure it will soon), all Wiis can have.

You run DVDx, which gives you access to ahbprot, allowing you to disable MEM2 protection and patch the sig checking function of ES, which then lets you install fakesigned content e.g. a patched IOS. sven_p mentioned this on #wiidev last night, WiiPower, perhaps you could implement this in a new version of TBR (I'm sure you'll be able to work out how to do all that stuff, I haven't a clue, but apparently its not too hard, and you seem pretty good with that sort of thing
wink.gif
)
Once it's working, you can just install BootMii as IOS and install a cIOS using cBoot2
smile.gif

Hard to setup legally (and yes I do care about the legally part).
 

WiiPower

Well-Known Member
OP
Member
Joined
Oct 17, 2008
Messages
8,165
Trophies
0
XP
345
Country
Gambia, The
It's hard to setup legally, that's right, but it's possible. But i would also prefer a solution that's easy to setup and is legal, which is why i mentioned mini.
 

FenrirWolf

Well-Known Member
Member
Joined
Nov 19, 2008
Messages
4,347
Trophies
1
Location
Sandy, UT
XP
615
Country
United States
Kikoshi said:
Davi92 said:
SifJar said:
BTW, once HackMii Installer is working on 4.3, there's apparently a reasonably simple way you can install fake signed content (e.g. patched IOS) on any Wii, regardless of the installed IOS. The Wii just needs DVDx, which when HackMii Installer gets updated to work (as I'm sure it will soon), all Wiis can have.

You run DVDx, which gives you access to ahbprot, allowing you to disable MEM2 protection and patch the sig checking function of ES, which then lets you install fakesigned content e.g. a patched IOS. sven_p mentioned this on #wiidev last night, WiiPower, perhaps you could implement this in a new version of TBR (I'm sure you'll be able to work out how to do all that stuff, I haven't a clue, but apparently its not too hard, and you seem pretty good with that sort of thing
wink.gif
)
Once it's working, you can just install BootMii as IOS and install a cIOS using cBoot2
smile.gif
So this way im able to Access the Boot2 with BootMii when i wasn't able to before? O_ O
No, that won't let you install BootMii/boot2 if you haven't been able to before. cboot2 is a program executed by BootMii, not something that's written to your NAND.
 

calthephenom

Well-Known Member
Member
Joined
Sep 28, 2009
Messages
123
Trophies
0
XP
42
Country
United States
FenrirWolf said:
Kikoshi said:
Davi92 said:
SifJar said:
BTW, once HackMii Installer is working on 4.3, there's apparently a reasonably simple way you can install fake signed content (e.g. patched IOS) on any Wii, regardless of the installed IOS. The Wii just needs DVDx, which when HackMii Installer gets updated to work (as I'm sure it will soon), all Wiis can have.

You run DVDx, which gives you access to ahbprot, allowing you to disable MEM2 protection and patch the sig checking function of ES, which then lets you install fakesigned content e.g. a patched IOS. sven_p mentioned this on #wiidev last night, WiiPower, perhaps you could implement this in a new version of TBR (I'm sure you'll be able to work out how to do all that stuff, I haven't a clue, but apparently its not too hard, and you seem pretty good with that sort of thing
wink.gif
)
Once it's working, you can just install BootMii as IOS and install a cIOS using cBoot2
smile.gif
So this way im able to Access the Boot2 with BootMii when i wasn't able to before? O_ O
No, that won't let you install BootMii/boot2 if you haven't been able to before. cboot2 is a program executed by BootMii, not something that's written to your NAND.
*cough Bootmii/IOS cough*
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Psionic Roshambo @ Psionic Roshambo:
    Jared and his blood covered foot long
  • meowie13 @ meowie13:
    hellooo everyone
  • K3Nv2 @ K3Nv2:
    https://a.co/d/7FN990Y lol flip my switch
  • Veho @ Veho:
    How to automate the un-automatable.
  • K3Nv2 @ K3Nv2:
    Kind of useless now considering my cat probably has a wifi chip inside it
  • Veho @ Veho:
    I guess it's useful if your landlord doesn't let you rewire the apartment or change the switches.
  • K3Nv2 @ K3Nv2:
    Smart plugs and bulbs are already around the same price
  • K3Nv2 @ K3Nv2:
    Wifi power strips even becoming common
  • Veho @ Veho:
    Having a remote servo that can push/pull something for you is still useful.
  • Veho @ Veho:
    It could operate a latch.
  • Veho @ Veho:
    On the other hand there are those chandeliers with like 50 lightbulbs and that would be a bit expensive to replace with smart bulbs.
    +1
  • K3Nv2 @ K3Nv2:
    Maybe if your hands are decapitated
  • Veho @ Veho:
    Maybe if I'm lazy.
    +1
  • Veho @ Veho:
    I have a number of geriatric relatives.
    +1
  • Veho @ Veho:
    Anbernic's SP clone will be $60 and I think I'll buy it. Looks decent enough and it will stop me from drooling over every single new handheld that comes out.
    +2
  • Psionic Roshambo @ Psionic Roshambo:
    It does look fun lol
    +1
  • Veho @ Veho:
    I love the GBA SP and this is the GBA SP on steroids. WiFi, Bluetooth, HDMI out, two microSD card slots, sleep mode on screen close, it has everything :D
    +1
  • SylverReZ @ SylverReZ:
    Hey guys. What's new about the Anbernic SP clone?
  • Veho @ Veho:
    They announced the price.
  • Veho @ Veho:
    Here's an overview:
  • Veho @ Veho:
    SHUT UP AND TAKE MY MONEY
  • AncientBoi @ AncientBoi:
    yea. Shut Up And Take HIS Money :)
    AncientBoi @ AncientBoi: yea. Shut Up And Take HIS Money :)