Quick Jump Daily Digest

Thank you for your interest in the Quick Jump Daily Digest. Get notified of all new content on QJ in our free Daily Digest. To subscribe, enter your email address below and click the subscribe button.


Email Address:


Email will come from "donotreply@caputomedia.com". Please whitelist this email address.

Cancel and Return to page

Wii homebrew - Xyzzy v1.1

Posted Nov 26, 2008 at 4:36PM EST by Glenn M.

Listed in: Wii Tags: Bushing, nand
Ó

xyzzy - Image 1


Bushing is back, and he brings the very useful Xyzzy v1.1 with him. Wii homebrew devs out there may want to give this thing a shot, 'cause it's very useful in extracting OTP encryption keys. It should automatically save the keys to a text file on your SD, but it also displays them on-screen if ever you need to write them down by hand.

xyzzy extracts the following data:
  • ECC Private Key - used for signatures in various places
  • Console ID - the unique identifier for your Wii
  • NAND AES key - used to encrypt and decrypt the Wii's NAND
  • NAND HMAC - used to generate or verify a hash of the NAND, and therefore judge its integrity
  • Common key (AES) - used to decrypt keys found on items distributed from Nintendo
  • PRNG seed - a random seed
  • SD key (AES) - used to encrypt and decrypt anything being written to/read from the SD card
  • Device cert - you Wii's personal cert

You've probably seen this before, but for information's sake, I'll put it here. This is what xyzzy does automatically.
  • Download IOS11 from the Nintendo Update Server
  • Patch it to remove the MEM2 protection (so the PPC can access all 64MB of it)
  • Patch it to allow it to delete itself later using ES_DeleteTitle()
  • Find an unused IOS slot (counting downward from IOS255)
  • Install the hacked IOS11 there
  • Reboot into the hacked IOS
  • Copy the private key structure from the IOS address space into MEM1
  • Reboot back into a sane IOS
  • Delete the temporary, hacked IOS
  • Display the keys on screen
  • Try to write them to a file on the SD card — keys.txt
  • Pause for 60 seconds to allow you to copy the keys down using pen and paper,if necessary
One last thing.
It ain't pretty, but at least it no longer contains copyrighted code. Bushing reckons you only need to run this once on any given Wii, but it should be safe to run multiple times.

Download: Xyzzy v1.1



More on xyzzy:




This story sucks? This story rocks!
Vote Now!    This story ROCKS! (0) This story SUCKS!! (0)




Become a Member of QJ.Net!

If you want your comments to go live without waiting for moderation, you need to be logged in. Being logged in has its benefits:
  • Logged in members do not wait for their comments to be approved.
  • Logged in members can sign up for nightly updates.
  • Logged in members can create Profiles to be seen by other users.
So why wait? Create an account or login now! It's easy, quick, and free.

To get started, use the LOGIN boxes, or the REGISTER link at the top right!

Comments 


 
# bushing = sell outz32tt3z 2008-11-27 08:19
how can he even still show his face in the homebrew scene after snitching to nintendo??? we dont need this guy anymore we have waninkoko!!!

Reply
 

Add comment

Security code
Refresh


Welcome to QJ.Net!

If you want your comments to go live without waiting for moderation, you need to be logged in. Being logged in has its benefits:
  • Logged in members do not wait for their comments to be approved.
  • Logged in members can create Profiles to be seen by other users.
So why wait? Create an account or login now! It's easy, quick, and free.

To get started, use the LOGIN boxes, or the REGISTER link below!



Want to learn more about the team who brings you the QJ news?

Read about them now!


RSS Feeds Follow us on Twitter Find us on Facebook
Login:

HOT FLASH GAMES

Monster Truck Jumper

Left to Die

The Empire 2

Dark Dimension

Town Drift Competition

Heroes of the Sword