PDA

View Full Version : Wii exploit Found Via corrupted Zelda Save data.



shadowprophet
January 27th, 2008, 08:00
It seems the guys over at tehskeen have been busy, They have apparently found a way to run unsigned code on the wii console via a corrupted zelda twilight princess save.

More info Via a helpful post from Mr. Soully below. *nods

News Via tehskeen (http://www.tehskeen.com/index.php)

souLLy
January 27th, 2008, 12:09
The site is down at the minute, but to quote from the site:


Yes, that's right - an exploit for the Nintendo Wii has been discovered and it allows you to run custom code. The method is pretty simple. Copy over a save file for Zelda, load it and the code runs. Don't get too excited yet. They have only been able to run 4 lines of code, but this is in a days work.

Segher was the one to find the exploit and Bushing has been testing it out with the aid of the USB Gecko. The process is far from simple as once you modify a save game it requires it be to signed with 3 keys. Here's some info from Bushing.

"Once the Wii decrypts the save game, it checks its signature. Every Wii has its own private key which is used to sign save games, and when you save a game, the Wii actually saves three bits of data:

* The encrypted save game
* The signature for the save game (using your console's private key)
* A copy of your console's public key, signed by Nintendo."

Of course, the end user wouldn't have to go through this process unless they were wanting to inject their own code into the save game, but that shouldn't be necessary because when I asked Bushing what his goal was he answered:

"Assuming we don't run into a wall, it should be able to lead to a homebrew loader. I hope. No promises. "

Exciting stuff!

Nicko01
January 27th, 2008, 16:35
Thats cool. I wonder if it is actually real. They need to give a little more info though.

Triv1um
January 27th, 2008, 19:25
Good news for the Wii owners... Real good news.

VampDude
January 27th, 2008, 19:36
I reckon Nintendo will block it with the next firmware update if it's real.

Triv1um
January 27th, 2008, 19:39
Didn't they block the SD exploit?

VampDude
January 27th, 2008, 20:46
Didn't they block the SD exploit?

I think they did (because my Wii which is on the latest firmware won't read my Gecko whereas my GameCube will), but I think that whoever has found the exploit is using an older firmware?

souLLy
January 27th, 2008, 21:34
It's almost certainly real by the way, these are the guys that have released the encryption/decryption software recently and I believed the same guys that showed off that homebrew code at that german hacking show a few weeks ago

shadowprophet
January 27th, 2008, 21:44
Sorry to all about not filling out this article a little better, I was indeed awfully busy this morning :o

VampDude
January 27th, 2008, 21:47
It's almost certainly real by the way, these are the guys that have released the encryption/decryption software recently and I believed the same guys that showed off that homebrew code at that german hacking show a few weeks ago

Theres no doubt about it being real, but the only thing that hasn't been mentioned is if it runs on a regular firmware (obviously not the current firmware) well basically what firmware it runs from.

Eviltaco64
January 27th, 2008, 21:53
That's cool. Although I dont think the homebrew isnt going to be much more superior to Xbox 1's selection of homebrew (then again, I could be wrong).

Safari Al
January 27th, 2008, 22:06
lets hope sooner or later we get someway of hacking it so that it isnt as hard as they make it seem :p

Eviltaco64
January 27th, 2008, 22:15
I thought that you could boot SD Media Launcher with a WiiKey even if the firmware you have blocks it. Is this true? If it is, that might make it a bit easier.

dejkirkby
January 28th, 2008, 16:04
I thought that you could boot SD Media Launcher with a WiiKey even if the firmware you have blocks it. Is this true? If it is, that might make it a bit easier.

Definitely true!

quzar
January 28th, 2008, 21:36
Discussion should continue in the actual wii section here: http://www.dcemu.co.uk/vbulletin/showthread.php?goto=newpost&t=87932