Hacking RealWnD - Wii Mini Edition

nitr8

Well-Known Member
OP
Member
Joined
Apr 4, 2007
Messages
366
Trophies
1
Website
vermillion57.wixsite.com
XP
1,478
Country
Gambia, The
Here comes the Wii Mini NAND dumper.

R-E-A-D C-A-R-E-F-U-L-L-Y

It's straight forward: Run it from within HBC.

It dumps directly to an attached USB drive with ECC data included.

No inputs required.

In order to accomplish the dumping process, you need these prerequisites:

https://gbatemp.net/threads/simpleiospatcher-wii-mini-edition.553353/

IF you have all the above prerequisites, the app does the following:

1.) Reloads into IOS236
2.) Disables AHBPROT automatically
3.) Disables MEMPROT automatically
4.) Patches IOS for gaining access back to /dev/flash (will be patched until the console is turned off)
5.) (Ab)uses IOS and mounts /dev/flash
6.) (Ab)uses IOS and dumps to usb:/WiiFlash_n_ECC.img (encrypted NAND binary)
7.) (Ab)uses IOS and dumps to usb:/WFD_XXX_YY.img ("Error" data - which is not really neccessary)
8.) Creates LOGFILE usb:/WiiFlash.log

??? - What's missing: The NAND key. You can obtain it using @DarkMatterCore's modified version of @bushing's Xyzzy.

Have phun.

Info for the new release:

- no longer needs YOU to dump and patch the AHBPROT bit within the IOS TMD

The NEW release is right here: http://www.mediafire.com/file/a1dzg9b6ahkdj06/RealWnD_Mini.zip/file
 

Attachments

  • RealWnD_Mini.zip
    121.1 KB · Views: 267
Last edited by nitr8,

asper

Well-Known Member
Member
Joined
May 14, 2010
Messages
942
Trophies
1
XP
2,030
Country
United States
Great ! What is the average dumping time ? In my case it tooks about 30 mins. Is there a tool to automatically add the 1024 footer used in bootmii and in every Wii NAND manager software taking it from Xyzzy keys.txt ?

Anyway I manually hex-edited the dump and decrypted/loaded it with showmiiwads:
eDpB2y0.png


Thank you !
 
Last edited by asper,

DarkKnight_TJ

Member
Newcomer
Joined
Oct 22, 2019
Messages
23
Trophies
0
Age
36
XP
564
Country
Mexico
i used both attached file and mediafire link, in both apps i get AHBPROT is not disabled error and then exits. i have installed "simpleiospatcher" with no errors. any idea?. thanks!
 

DarkKnight_TJ

Member
Newcomer
Joined
Oct 22, 2019
Messages
23
Trophies
0
Age
36
XP
564
Country
Mexico
well, i had to do "simpleiospatcher" manually to patch "AHBPROT", then i was able to dump wii mini nand. Is there any nand writer available for mini?
 

DarkKnight_TJ

Member
Newcomer
Joined
Oct 22, 2019
Messages
23
Trophies
0
Age
36
XP
564
Country
Mexico
is there any way to get a "normal" dump instead of an ".ecc" one? just for testing purposes (trying to make a "full dump" using a "normal" wii dump and encrypting using wii mini keys, would be nice to have full sytem capabilities back in wii mini xD). (i own a hardware programmer)
 

tech_land

Member
Newcomer
Joined
Feb 10, 2018
Messages
18
Trophies
0
Age
44
XP
88
Country
Italy
Great ! What is the average dumping time ? In my case it tooks about 30 mins. Is there a tool to automatically add the 1024 footer used in bootmii and in every Wii NAND manager software taking it from Xyzzy keys.txt ?Anyway I manually hex-edited the dump and decrypted/loaded it with showmiiwads:
Thank you !

is there a tool? is there a guide line to edit the dump with hex editor?
 

felixsrg

Temp's Ghost
Member
Joined
Aug 20, 2008
Messages
282
Trophies
1
Location
Here and there
XP
2,297
Country
Colombia
Hi there, thank you so much for this, it is nice to have the Wii Mini's NAND available and safe.


Great ! What is the average dumping time ? In my case it tooks about 30 mins. Is there a tool to automatically add the 1024 footer used in bootmii and in every Wii NAND manager software taking it from Xyzzy keys.txt ?

Anyway I manually hex-edited the dump and decrypted/loaded it with showmiiwads:
eDpB2y0.png
Thank you !

Hi there, maybe this is a stupid question, but may I ask how you got your console specific 1024-bytes? Thanks in advance.
 

asper

Well-Known Member
Member
Joined
May 14, 2010
Messages
942
Trophies
1
XP
2,030
Country
United States
Hi there, thank you so much for this, it is nice to have the Wii Mini's NAND available and safe.




Hi there, maybe this is a stupid question, but may I ask how you got your console specific 1024-bytes? Thanks in advance.
The 1024 bytes contains the OTP dump. You can obtain it using various tools, I used the latest Xyzzxy-mod (it is able to dump directly to a file and you just can copy-past the 1024 bytes at the end of the nand image). More info here, unfortunately not in english).
 
Last edited by asper,
  • Like
Reactions: felixsrg

felixsrg

Temp's Ghost
Member
Joined
Aug 20, 2008
Messages
282
Trophies
1
Location
Here and there
XP
2,297
Country
Colombia
The 1024 bytes are the OTP dump. You can obtain it using various tools, I used the latest Xyzzxy-mod (it is able to dump directly to a file and you just can copy-past the 1024 bytes at the end of the nand image). More info here, unfortunately not in english).

I was able to create my BootMii NAND with your instructions and the website you linked, thank you very much!
 
  • Like
Reactions: asper

Zane_Julien

Well-Known Member
Newcomer
Joined
Dec 24, 2019
Messages
79
Trophies
0
Age
43
XP
277
Country
Germany
After using the simple Ios Patcher and then starting RealWnD on my Wii mini, it first shows some information about the tool and then just a blackscreen, is that normal?
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, the other game where I found newgrounds is new york shark
    +1
  • SylverReZ @ SylverReZ:
    Spoke to Tom Fulp the other day, if he can find his old Newgrounds site content like the mini Flash animations from the 2000's that played on the portal.
  • SylverReZ @ SylverReZ:
    So far no response, but he did say that he'll find them. Wayback Machine doesn't have em.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, atleast the 1999 versión of pico's school is avaliable (the difference between it, the 2006 versión and the 2016 versión is that the speed of the game depends of the speed of your computer and that it had the og soundtrack)
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Another being Pico VS Bear, the original 1999 version before Jim Henson filed a DMCA takedown.
    +1
  • Xdqwerty @ Xdqwerty:
    The 2006 versión was made when the flash portal was made
  • SylverReZ @ SylverReZ:
    Many people thought it was lost, but was discovered that he hid it on the same page.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, although the "secrets" system where the game was has been removed. Also pico vs uberkids had a netplay versión that was shutdown, although the swf file has been found
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Nope. There are two download buttons on the same page, where you can download the original under a file called "bear.exe". "bear2.exe", however, is the updated game in a Flash projector. P.s. this was on the archived Pico page from 2000.
  • SylverReZ @ SylverReZ:
    @Xdqwerty, That's been there for a long time, too. People who search for lost media don't look hard enough lmao.
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, also the pico 2 demos used to be only for the newgrounds patrons but they are on internet archive too (https://archive.org/download/picos_school_2)
    +1
  • Xdqwerty @ Xdqwerty:
    Iirc the demos were removed from newgrounds in 2022
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, or well only the demo with mindchamber's style was on newgrounds
    +1
  • Xdqwerty @ Xdqwerty:
    Fun fact @SylverReZ: iirc one of the goals on the fnf Kickstarter stated that pico 2 would be finished but the Kickstarter didnt get enough money for that goal to be fullfiled
  • SylverReZ @ SylverReZ:
    @Xdqwerty, FNF sucks, their community is toxic as hell.
  • The Real Jdbye @ The Real Jdbye:
    @SylverReZ its a single player game
  • Xdqwerty @ Xdqwerty:
    @The Real Jdbye, Yea but it has a shitton of mods with their own songs and stuff
  • Xdqwerty @ Xdqwerty:
    @The Real Jdbye, and quite a lot of people involved in those mods get cancelled
  • SylverReZ @ SylverReZ:
    Newgrounds wasn't the birth of FNF; rather, it was games where you beat up celebrities and parodies.
    +2
  • a_username_that_is_cool @ a_username_that_is_cool:
    FNF was born from Game Jams
  • a_username_that_is_cool @ a_username_that_is_cool:
    Specifically Ludum Dare 47
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, and Sonic fights a la dragón ball z
    Xdqwerty @ Xdqwerty: