Trucha Signer 0.2.1 released February 27
Ingenieria Inversa has released Trucha Signer 0.2.1. Trucha Signer is a PC program that can resign edited Wii data. While nothing is being done with it yet, the potential is there for some great homebrew to come out in the future.
Thank you to zkello for the tip.
The last year I was quite lucky in attend for the 24th Chaos Communication Congress and meet very interesting people, renowned console hackers like tmbinc and bunnie, the authors of radare, and hackers of different topics.
Even more interesting was to be at the first row at the Why Silicon-Based Security is still that hard: Deconstructing Xbox 360 Security presentation by tmbinc and Michael Steil, and see the bushing’s surprise making a demo of homebrew running on the Wii.
The bug exploited in that demo never was made public, they only talk about the method to access the “common key” that is the one that let us decrypt the discs and updates, so now hack the system is only matter of found a bug… The biggest bug is just in the place where the public key verification stuff is performed. Moreover this bug not only compromise the discs security, it compromise ALL the certificates verifications (the RSA ones), that means discs, WADs, channels, VC Games, and so on.
Being this bug so clearly for everyone (and especially for Nintendo) I can’t see the need to keep it secret forever, thinking that Nintendo never will find it, for instances there was another bug (in former firmwares versions) that could be exploited to break the system in a similar way, even if nobody tried to exploit it, that bug was already fixed.
Also as tmbinc states, the system compromise is total, and for sure new attacks and exploits are coming like the Zelda TP exploit come some days ago.
After spend some time thinking on it, I see there is no problem to release Trucha Signer, a tool that let us extract and replace files withing a disc and after that insert a “trucha signature” to be autenticathed by the Wii.
Trucha Signer 0.2
*edit: I’ve fixed it as I’ve to forget to enable something before release, be sure to use version 0.21
Download: trucha021.rar
Discuss this topic in our forums.
