Hacking vWii System Menu Hack

asper

Well-Known Member
OP
Member
Joined
May 14, 2010
Messages
942
Trophies
1
XP
2,030
Country
United States
Listening to the very interesting lecture (https://fail0verflow.com/blog/2014/console-hacking-2013-omake.html) of team f0f I noticed that the vWii boot sequence is the following one:
H2PE7cr.png


Looking at that picture we can see that cafe2wii loads straight into System Menu IOS, then System Menu IOS loads bootrom which checks and decrypts the ancast image (vWii System Menu) and if it is correct it executes it.
Now we have bootrom dump, we have IOSes dumps, we have cafe2wii dump (a packet of them can be found in a famous dev-u site, the one with IRC chat :) )

So my questions are:
1 - can we "bypass" the bootrom patching the IOS to directly load an already decrypted System Menu image ?
2 - alternatively can we patch the IOS to load a pre-patched bootrom (ex. from file) ?
3 - as last chance can we boot a vWii homebrew -> warm-reboot vWii -> inject new System Menu using ToC/ToU described in the team f0f talk ? (thank to @QuarkTheAwesome for this suggestion).

This will make, for example, custom System Menu themes and also priiloader a vWii reality. If you do not find this thread useful for whatever reason please avoid answering.

Tank you very much for your attention hoping someone will get deeper into it.


EDIT: just for your info, I managed to patch the IOS80 (System Menu IOS) and the vWii is still working so no checks for IOS80 integrity. I also managed to modify System Menu data content (00000022.app) but i bricked vWii (all test were done in realnand). I resotred it replacing original 00000022.app file via wupserver.
 
Last edited by asper,

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • K3Nv2 @ K3Nv2:
    Did someone loose a leg? You're fired
  • K3Nv2 @ K3Nv2:
    Ffs 55gb patch for hogwarts legacy
  • SylverReZ @ SylverReZ:
    @K3Nv2, Teslas are prob running Windows XP to this day.
  • Sicklyboy @ Sicklyboy:
    sometimes I wonder where I went wrong and why I'm so dissatisfied with my life
  • Sicklyboy @ Sicklyboy:
    Then I find myself arguing with someone on reddit about how blatantly wrong their understanding of the USB Power Delivery specification is.
  • Sicklyboy @ Sicklyboy:
    At 1 AM.
  • Sicklyboy @ Sicklyboy:
    Where did I go wrong, again? 😕
  • SylverReZ @ SylverReZ:
    @Sicklyboy, What do you mean?
  • K3Nv2 @ K3Nv2:
    @Sicklyboy, always blame women
  • Veho @ Veho:
    Blame woke.
  • SylverReZ @ SylverReZ:
    Blame society.
  • K3Nv2 @ K3Nv2:
    Woke isn't part of society they woke up from it
    +1
  • Veho @ Veho:
    *spends years yelling "wake up sheeple"
    *acts shocked when they actually wake up
  • Veho @ Veho:
    Make up your mind.
  • K3Nv2 @ K3Nv2:
    You mean the government doesn't care? :(
  • Veho @ Veho:
    I have no idea what you're talking about.
  • K3Nv2 @ K3Nv2:
    The government
  • K3Nv2 @ K3Nv2:
    Lol jedi fallen order crashed on SteamDeck through ea play guess the deck doesn't have the force
  • Veho @ Veho:
    Well it's called the "fallen" order, not the "stable" order.
  • Veho @ Veho:
    The "smooth running" order.
  • K3Nv2 @ K3Nv2:
    Guess they weren't lying about not being compatible
  • K3Nv2 @ K3Nv2:
    Ea play is such hot garbage for making you register per console
  • SylverReZ @ SylverReZ:
    Site's down again. :/
    SylverReZ @ SylverReZ: Site's down again. :/