iQue Player hacking possibility with ique_diag.exe?

KevinLSX

Well-Known Member
Member
Joined
Mar 6, 2016
Messages
526
Trophies
0
XP
1,113
Country
United States
Wow! That's incredible! Are you a hardware engineer or something?


hahaha nah all it took was a little bit of soldering and knowing where the wires had to go.

--------------------- MERGED ---------------------------

I meant the iQue menu where you can select games from
I remember someone trying and they broke there Ique. I dont know if id risk breaking it.
 

KevinLSX

Well-Known Member
Member
Joined
Mar 6, 2016
Messages
526
Trophies
0
XP
1,113
Country
United States
Not sure if it matters or not but when I inserted the depot disc it started download game files and those files were put in a cache folder.
 

Krem Quay

Well-Known Member
Newcomer
Joined
Aug 24, 2014
Messages
89
Trophies
0
Age
26
XP
231
Country
United States
3989pk.png


You know, i'm pretty sure that text before the ROOT CPCA is the encrypted titlekey or something.
 

Krem Quay

Well-Known Member
Newcomer
Joined
Aug 24, 2014
Messages
89
Trophies
0
Age
26
XP
231
Country
United States
Extensive research on title keys (tickets) of Nintendo systems, especially the Wii, which probably has the most similar encryption method.
 

KevinLSX

Well-Known Member
Member
Joined
Mar 6, 2016
Messages
526
Trophies
0
XP
1,113
Country
United States
Couldnt we see if someone on here could help. If it similar to wii or other systems, then someone with the experience could probably do it.
We need to reach out to someone who has the experience on these kind of things.
 
  • Like
Reactions: Krem Quay

asper

Well-Known Member
Member
Joined
May 14, 2010
Messages
942
Trophies
1
XP
2,030
Country
United States
Well, .rec file is the game that, reading the above link, is encrypted with a per-console specific key that probably is inside recrypt.sys. Keys are usually 16bytes and Nintendo encryption formats are (read here and here for more info):

0x010000 RSA_4096 SHA1 (Unused for 3DS) 0x200 0x3C
0x010001 RSA_2048 SHA1 (Unused for 3DS) 0x100 0x3C
0x010002 Elliptic Curve with SHA1 (Unused for 3DS) 0x3C 0x40
0x010003 RSA_4096 SHA256 0x200 0x3C
0x010004 RSA_2048 SHA256 0x100 0x3C
0x010005 ECDSA with SHA256 0x3C 0x40

Also more info about Nintendo ticket system can be read here.

Then the decrypted game must be decrypted again with a "common key" that must stored somewhere in the system dump.

Can someone post a screenshot of the 1st bytes (at least 0x200) .sys files opened with an hex editor ?

EDIT: 0-8192 partial dump taken from one of the above posted-link is surely encrypted.
 
Last edited by asper,
  • Like
Reactions: Krem Quay

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Psionic Roshambo @ Psionic Roshambo:
    At least I'm not playing single player :P
  • Psionic Roshambo @ Psionic Roshambo:
    Ken so your saying there is a chance? Lol
  • K3Nv2 @ K3Nv2:
    Leeches can't afford a $60 handheld:angry:
  • BigOnYa @ BigOnYa:
    You hater.
  • K3Nv2 @ K3Nv2:
    No I just hate you
  • B @ BigArnold:
    Hey! I need help with getting payloads onto my Switch. Is this the place???
  • K3Nv2 @ K3Nv2:
    Why not HeyArnold
  • B @ BigArnold:
    Can you guys help with my problem concerning my Switch?
  • K3Nv2 @ K3Nv2:
    Did you switch it up
  • B @ BigArnold:
    Switch what up?
  • K3Nv2 @ K3Nv2:
    Switch the switch to resolve your issue
  • Xdqwerty @ Xdqwerty:
    @BigArnold, sorry but i cant, i dont have a switch. also what k3nv2 says is a joke
  • B @ BigArnold:
    That's what I figured. I put a post up in a forum but no one seems to replying to posts there. I also don't what this chat is attached to.
  • K3Nv2 @ K3Nv2:
    General chat as it implies
  • Xdqwerty @ Xdqwerty:
    @BigArnold, try posting in the "switch noob paradise" thread
  • B @ BigArnold:
    That's where I put it. But like I said other people's posts from a day or two ago have no responses. I'm not sure if the chat is part of the Nintendo forum that I'm on or a part of the website as a whole.
  • Xdqwerty @ Xdqwerty:
    @BigArnold, part of the website as a whole
  • Xdqwerty @ Xdqwerty:
    then try making a thread
  • Xdqwerty @ Xdqwerty:
    wait you are too new to be able to do that
  • B @ BigArnold:
    That's fine. I'll find my way.
    +1
  • BigOnYa @ BigOnYa:
    @BigArnold you put the fusee or hekate.bin in the hekate/ payloads folder, or use app to push the payload to switch while its in rcm mode
    +1
  • B @ BigArnold:
    The problem is is that TegraGUI isn't detecting my Switch despite it being plugged in and in RCM or maintenance mode.
    +1
    B @ BigArnold: The problem is is that TegraGUI isn't detecting my Switch despite it being plugged in and in RCM... +1