Hacking Ninty's workload

WiiCrazy

Be water my friend!
OP
Member
Joined
May 8, 2008
Messages
2,395
Trophies
0
Location
Istanbul
Website
www.tepetaklak.com
XP
387
Country
Ninty have a fair list of bugs at the moment to fix, this is an attempt to summarize them ...

#. Hole - Nature - Region - Status
1. Korean IOS workaround - IOS - PAL/NTSCU/NTSCJ (Reported as being fixed for NTSC-J both by wii shop update and through Metroid Other-M game update)
2. Unknown exploit used by hackmii installer - IOS - All regions - Not fixed
3. Indiana Pwnz exploit - PPC - PAL/NTSCU - Not fixed
4. SmashStack exploit - PPC - NTSCU - Not fixed
5. Yu-gi-oh exploit - PPC - PAL/NTSCU/NTSCJ - Not fixed
6. Bootmii@boot2 - PPC+IOS - PAL/NTSCU/NTSCJ - Not fixed (Latest fix was through 4.2 update by boot2v4)
 

WiiPower

Well-Known Member
Member
Joined
Oct 17, 2008
Messages
8,165
Trophies
0
XP
345
Country
Gambia, The
WiiCrazy said:
Ninty have a fair list of bugs at the moment to fix, this is an attempt to summarize them ...

#. Hole - Nature - Region - Status
1. Korean IOS workaround - IOS - PAL/NTSCU/NTSCJ (Reported as being fixed for NTSC-J both by wii shop update and through Metroid Other-M game update)
2. Unknown exploit used by hackmii installer - IOS - All regions - Not fixed
3. Indiana Pwnz PPC exploit - PPC - PAL/NTSCU - Not fixed
4. SmashStack PPC exploit - PPC - NTSCU - Not fixed
5. Yu-gi-oh PPC exploit - PPC - PAL/NTSCU/NTSCJ - Not fixed
6. Bootmii@boot2 - PPC+IOS - PAL/NTSCU/NTSCJ - Not fixed (Latest fix was through 4.2 update by boot2v4)

1. is already fixed on new 4.3 JAP Wiis and Metroid Other M disc update. So we can expect them for 4.4 or 5.0.
2. That might take actually some time to reverse it and then block it. But i think someone from TT said it's just the 1st of a new kind of wii exploits.
3+5. Savegame exploit, should be easy to fix
4. Maybe never fixed, i think they could even fix it with a main.dol patch. (which is something nintendo does on gamecube games...)
6. Do you expect them to install a new boot2 version on every update? There's a chance of i don't know 0.1 / 1000 Wiis to brick a Wii by this. What advantage would this actually have for nintendo if they did it?

I'm curious if they will do at least the minimal stuff with the next update, and if the next update will take again ages, and if it will add no functionality again.
 

WiiCrazy

Be water my friend!
OP
Member
Joined
May 8, 2008
Messages
2,395
Trophies
0
Location
Istanbul
Website
www.tepetaklak.com
XP
387
Country
dn_angel000 said:
u 4got MarioKart PWNS!! lol

Well it's for chipped wiis and rely on an already existing exploited game listed above. So once the game that it depends fixed then you can use it with that game. To put it another way Ninty will not do anything to fix it directly.
 

SifJar

Not a pirate
Member
Joined
Apr 4, 2009
Messages
6,022
Trophies
0
Website
Visit site
XP
1,175
Country
Ninty need to start adding functionality to updates, as it is, people who want homebrew simply won't update officially, and will just use an unofficial Shop Channel and IOS updater tool. And "legit" users will also start to complain I reckon if Ninty keep pushing updates with no feature updates.
 

WiiCrazy

Be water my friend!
OP
Member
Joined
May 8, 2008
Messages
2,395
Trophies
0
Location
Istanbul
Website
www.tepetaklak.com
XP
387
Country
Ninty somewhat works asynchronously so I don't expect they cover all the holes above in the next update in one go...

Definitely the first holes to fix are #1 & #2 as they are the widest... And it seems they already fixed #1 without issuing a new system menu update.
 

WiiPower

Well-Known Member
Member
Joined
Oct 17, 2008
Messages
8,165
Trophies
0
XP
345
Country
Gambia, The
Blocking the korean IOS doesn't get nintendo anything, there's cBoot2 for ever a year now, and as long as you can get BootMii IOS, cBoot2 will work. Other methods are just easier to perform or are more legal in an easy to use package + instructions. Not to mention new versions of Dop-Mii or TBR with AHBPROT.

As far as i can see they need(in my eyes from top to low priority):
- To block to run code at all to prevent new Wiis being hacked, this would require to fix all game exploits including the "unpatchable" SSBB. And then they still would be screwed when a new game exploit arrives. -> So i guess that's next to impossible for nintendo.
- With an update to remove everything that allows to run any code, and to remove any patched IOS. So that one would need to "rehack" his Wii after an update. This would require to delete or overwrite EVERYTHING that is not nintendo signed. Should be easy, it's just a big step, and they would need to warn you about this. In some countries they can't legally delete stuff from your wii. -> To me it looks doable, they might just be too afraid to do it because of legal reasons or to screw it up
- To prevent that you can install anything you want when you have your foot in the door. I mean 1. prevent that all released hackmii installers are able to install anything. and 2. check signatures of IOS and channels when loading them. With (2) the hackmii installer would be teethless, what good does a HBC to you when you can only start it from the SSBB exploit? -> This has to be doable too, it will just slowdown IOS loading and channel loading by max 1 second.
 

giantpune

Well-Known Member
Member
Joined
Apr 10, 2009
Messages
2,860
Trophies
0
XP
213
Country
United States
WiiPower said:
4. Maybe never fixed, i think they could even fix it with a main.dol patch. (which is something nintendo does on gamecube games...)

they would have to build that main.dol patch into IOS. because they can patch the game all they want when it is loaded in the system menu. but you can play one of the VC trials and it causes the main.dol to be reloaded again from the disc. they would need some 1337 magic to fix it otherwise.
 

WiiPower

Well-Known Member
Member
Joined
Oct 17, 2008
Messages
8,165
Trophies
0
XP
345
Country
Gambia, The
giantpune said:
WiiPower said:
4. Maybe never fixed, i think they could even fix it with a main.dol patch. (which is something nintendo does on gamecube games...)

they would have to build that main.dol patch into IOS. because they can patch the game all they want when it is loaded in the system menu. but you can play one of the VC trials and it causes the main.dol to be reloaded again from the disc. they would need some 1337 magic to fix it otherwise.

Did i mention that they put patch code at 0x1800 on gamecube mode for such stuff? There are some professionals working for nintendo, they could do it if they really wanted to. What was the number of confirmed unique HBC installs? 200.000? Even if you assume a very low pirate rate and that only a low rate of pirates would buy 1 title for 30 bucks per year if he couldn't pirate, you still get quite a sum of money in such a calculation. Which they could use to hire somebody who writes that code.
 

mike333

Well-Known Member
Member
Joined
Aug 30, 2010
Messages
718
Trophies
0
XP
258
Country
Poland
WiiPower said:
[...] all game exploits including the "unpatchable" SSBB.
I don't know, so please tell me.
What is current status about SSBB exploit for PAL consoles?
Game was fixed or exploit waits for its day?
 

WiiCrazy

Be water my friend!
OP
Member
Joined
May 8, 2008
Messages
2,395
Trophies
0
Location
Istanbul
Website
www.tepetaklak.com
XP
387
Country
WiiPower said:
Blocking the korean IOS doesn't get nintendo anything, there's cBoot2 for ever a year now, and as long as you can get BootMii IOS, cBoot2 will work. Other methods are just easier to perform or are more legal in an easy to use package + instructions. Not to mention new versions of Dop-Mii or TBR with AHBPROT.

Again cboot2 is a dependent hole.. you need bootmii for that... Note that hackmii installer released 3 weeks after 4.3 update (or was it 2, dunno)

WiiPower said:
As far as i can see they need(in my eyes from top to low priority):
- To block to run code at all to prevent new Wiis being hacked, this would require to fix all game exploits including the "unpatchable" SSBB. And then they still would be screwed when a new game exploit arrives. -> So i guess that's next to impossible for nintendo.

Yeah pretty tricky, even some companies might deliberately leave holes to boost sales.

WiiPower said:
- With an update to remove everything that allows to run any code, and to remove any patched IOS. So that one would need to "rehack" his Wii after an update. This would require to delete or overwrite EVERYTHING that is not nintendo signed. Should be easy, it's just a big step, and they would need to warn you about this. In some countries they can't legally delete stuff from your wii. -> To me it looks doable, they might just be too afraid to do it because of legal reasons or to screw it up

Well actually this is what they are trying to accomplish (stub stuff) but they are always a minute late for it..

QUOTE(WiiPower @ Sep 3 2010, 12:37 AM)
- To prevent that you can install anything you want when you have your foot in the door. I mean 1. prevent that all released hackmii installers are able to install anything. and 2. check signatures of IOS and channels when loading them. With (2) the hackmii installer would be teethless, what good does a HBC to you when you can only start it from the SSBB exploit? -> This has to be doable too, it will just slowdown IOS loading and channel loading by max 1 second.

Well once you exploit IOS and then PPC then you have full control. Just that everyone will resort to pesky business of patching / downgrading.. Good to break havoc among the users though, people bricking and stuff... There is one way though by putting more serious checks at boot2 level with a new boot2 update. Like the thing they did to region changed korean wiis... Messy...
 

drhacknslash

Well-Known Member
Newcomer
Joined
Sep 29, 2008
Messages
67
Trophies
0
XP
262
Country
United States
giantpune said:
they would have to build that main.dol patch into IOS. because they can patch the game all they want when it is loaded in the system menu. but you can play one of the VC trials and it causes the main.dol to be reloaded again from the disc. they would need some 1337 magic to fix it otherwise.

Totally talking off the cuff here.... I wonder if they could somehow make SSBB require an updated version of its IOS that had a built in fix for Smash Stack. Or for that matter have a system menu come bundled with a patched or fixed version of the SSBB IOS.
 

mauifrog

DA KINE WiiHacker
Member
Joined
Jan 21, 2010
Messages
1,587
Trophies
0
Website
Visit site
XP
392
Country
United States
Yes, it runs on ios36. Just those 3 games AFAIK. They could just stub it on ntsc-u systems.

Edit, perhaps they could just remove sd card support from ios36, then add a SSBB custom stage channel to the wii to manage the custom stages, removing the ability of the disk from loading the exploit.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • K3Nv2 @ K3Nv2:
    I mean for 1st party routers iirc linksys use to support it
  • Sicklyboy @ Sicklyboy:
    ahhhh that I have no idea
  • Sicklyboy @ Sicklyboy:
    pretty cool though if so
  • K3Nv2 @ K3Nv2:
    Or from what ive heard ways to set custom imgs for 1st party routers so locked down now days
  • Sicklyboy @ Sicklyboy:
    OPNsense VM and specs and specs of system it's running on. https://imgur.com/a/S9wgGUD
  • Sicklyboy @ Sicklyboy:
    I've turned more features on in OPNsense lately and it's getting kind of high on RAM usage, I see. Probably bump that up to 4GB soon
  • K3Nv2 @ K3Nv2:
    I wanna make a 8core router with support for 20gbps doesn't even sound that silly lol
  • Sicklyboy @ Sicklyboy:
    I only have 1 gig internet but internally I have 10 gig connectivity for everything on my lan lol
  • Sicklyboy @ Sicklyboy:
    fiber connection from my desktop PC back to my core network switch
  • Sicklyboy @ Sicklyboy:
    2 port HPE SFP+ PCIE NIC in my desktop and all of my servers
  • Sicklyboy @ Sicklyboy:
    silly shit
  • Sicklyboy @ Sicklyboy:
    eventually this desktop is going to act as a server too, just for the hell of it. Because this PC is WAY fucking overkill for how little I use it.
  • Sicklyboy @ Sicklyboy:
    And once I do that, my desktop OS that I interact with is just going to be a virtual machine and use GPU passthrough to connect everything
  • K3Nv2 @ K3Nv2:
    Send it to me ffs
  • Sicklyboy @ Sicklyboy:
    No because it's my desktop lol
  • Sicklyboy @ Sicklyboy:
    The most use this PC is getting right now is 979 Chrome tabs open right now
  • K3Nv2 @ K3Nv2:
    This is my desktop there are many like it but it is mine alone
  • K3Nv2 @ K3Nv2:
    Enabled PPPoE on router now no wifi connection lul
  • HiradeGirl @ HiradeGirl:
    Anyone knows
    where is Juan?
  • K3Nv2 @ K3Nv2:
    Taken by the feet police
  • HiradeGirl @ HiradeGirl:
    Horny jail?
  • K3Nv2 @ K3Nv2:
    It was a nationwide vote
  • BigOnYa @ BigOnYa:
    That does look good
    BigOnYa @ BigOnYa: That does look good