Hacking DIY amiibo cards

fraret

A puffin
Member
Joined
Nov 22, 2015
Messages
100
Trophies
0
Location
Interblag
Website
localhost
XP
151
Country
I am stuck again, I think I am getting closer, but I want to check my keys file (The locked secret one, not the unfixed infos) can someone help me out here, maybe an md5 checksum or something?
I posted the md5 checksum of the keyfile in this thread:
Md5 of my keyfile: 2551afc7c8813008819836e9b619f7ed
 

derthomas

Well-Known Member
Newcomer
Joined
Mar 23, 2015
Messages
99
Trophies
0
XP
1,879
Country
Germany
Sorry, didnt follow the whole thread, but what I understand so far: its not possible to recreate OPs cards so far? Not sure, if I should buy the stickers already.
 

nurofen

Member
Newcomer
Joined
Jan 5, 2016
Messages
19
Trophies
0
Age
51
XP
54
Country
As I say, I am pretty close. I think I understand, but really need a few more clues / help from @Supercool330 as he has got this to work.
Basically I understand using the 'unfixed infos' key and hashing against 0x011:0x034,0x0A0:0x208,0x034:0x054,0x000:0x008 and 0x054:0x080 to produce the Unfixed HASH for the data at 0x80:0xA0

Now what I think we need before we do this is create the 'Locked secret' HASH at 0x034:0x054. This is where I am stuck, I know we use the 'Locked secret' keyset but I can't work out which areas to HASH against , my guess would be the areas that are not updateable, i.e. 0x208:0x21c ,0x000:0x008 and 0x054:0x080.

As the area 0x034:0x054 is not encrypted I should be able to check the generated data against the actual data. However I am not having much luck. It could be that my keyfile is incorrect.
If anyone can give us some more clues that would be great.
 

javiMaD

Active Member
Newcomer
Joined
Jan 31, 2015
Messages
37
Trophies
0
Location
0's and 1's
XP
315
Country
As I say, I am pretty close. I think I understand, but really need a few more clues / help from @Supercool330 as he has got this to work.
Basically I understand using the 'unfixed infos' key and hashing against 0x011:0x034,0x0A0:0x208,0x034:0x054,0x000:0x008 and 0x054:0x080 to produce the Unfixed HASH for the data at 0x80:0xA0

Now what I think we need before we do this is create the 'Locked secret' HASH at 0x034:0x054. This is where I am stuck, I know we use the 'Locked secret' keyset but I can't work out which areas to HASH against , my guess would be the areas that are not updateable, i.e. 0x208:0x21c ,0x000:0x008 and 0x054:0x080.

As the area 0x034:0x054 is not encrypted I should be able to check the generated data against the actual data. However I am not having much luck. It could be that my keyfile is incorrect.
If anyone can give us some more clues that would be great.

Using 'locked secret' keyset.

'tag' format:
Calc hash of (0x000:0x007 + 0x054:0x07F) (52 bytes), put this hash (32 bytes) at 0x034

'internal' format:
Calc hash of (0x1D4:0x207) (52 bytes), put this hash (32 bytes) at 0x1B4

:)
 
  • Like
Reactions: dibas and Pecrow

OctopusRift

GBATemp's Local Octopus, Open 9am-2am. "Not Yet"
Member
Joined
Nov 19, 2014
Messages
1,460
Trophies
0
XP
947
Country
Saint Kitts and Nevis
Using 'locked secret' keyset.

'tag' format:
Calc hash of (0x000:0x007 + 0x054:0x07F) (52 bytes), put this hash (32 bytes) at 0x034

'internal' format:
Calc hash of (0x1D4:0x207) (52 bytes), put this hash (32 bytes) at 0x1B4

:)
SHA1 please
 

HiddenRambler

Well-Known Member
Member
Joined
Nov 20, 2015
Messages
148
Trophies
0
XP
651
Country
MD5 0ad86557c7ba9e75c79a7b43bb466333
SHA1 ad676ac04c6e7861924093654bd67ff4807ebc53

looks like my file is wrong: md5= 33d0dbefcb660732feadea8fc6921a7b

Could you tell me which parts are wrong from this hexdump snippet:

Code:
0C 0D 0E 0F

b6 a3 c2 05
74 00 00 10
f2 cf d2 9b
96 0f ae d4
45 05 47 66
 
Last edited by HiddenRambler,

javiMaD

Active Member
Newcomer
Joined
Jan 31, 2015
Messages
37
Trophies
0
Location
0's and 1's
XP
315
Country
@HiddenRambler how did you do it? (MAke a tutorial) @javiMaD does the amitool make BIN files that can be written correctly? Cold you PM me the key?
This new amiitool generate both hashes correctly, but for write the tag must be careful with password, PACK0/1 and write order, check page 12 from this thread.
 
  • Like
Reactions: Deleted User

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
    K3Nv2 @ K3Nv2: Hawaii played it smart and said we're too hot for this land