Hay que aclarar que solo se ha filtrado un xploit a medio terminar, no permite ni cargar juegos ni cargar homebrew, es solo técnico.
Estoy revisando los archivos que se han filtrado, dejo aquí lo más interesante de los supuestos dumps hasta ahora inéditos.
Parece que se trata de crear un servidor rcp en un ordenador conectado a la misma red y desde el navegador de la Wii U acceder a una dirección.
Como supongo que no puedo poner el link al archivo .rar dejo aquí los hash para comprobar que es el archivo correcto:
wiiubrowserexploit.rar
MD5 3229d808b96900f0c5f05834723a3059
SHA1 2efc7a36b7a34006b16b03f140ef958873d59406
SHA256 08db7b56bcf24fc013179e9b1669b2dbf129a1413ee0fdea4d75701494c8b4b0
Partes relevantes de los archivos filtrados:
BUILT AS OS_VERSION_MAJOR 000500101000800A MINOR 0x16FB
D óØ €Ð` Kernel Build date - Mar 11 2014 10:03:26
( ò, €Ð` NDEBUG ( ñ €Ð` PPC D ïÚ €Ð` Cafe OS SDK Version 2.10.12 Build 6075
PROD Mode - don't even try to load kdebug.elf
[AppJump] MainApp title is "Wii U Menu".
UserMode OS library build date: Mar 11 2014 10:04:27
` Gôê € MEM2 Arena clear complete, size 368 MB, 195ms
AVM: COMPOSITE, D ?Ôín €š€ DC: Build date - Mar 11 2014 10:06:35
D ?Ô˜¨ €š€ TVE: Build date - Mar 11 2014 10:06:33
D ?ÇŠÎ €š€ AVM: Build date - Mar 11 2014 10:06:40
Going to try with relaunch.
***Launch or Call Outstanding. Cannot do another concurrently.
Pr $ ”™‡( €œ d
**Out of memory during fast relaunch.
***PrepareTitle() for replace and for relaunch errcode %d
PrepareTitle(Relaunch) Succeeded. IOS should have or will be telling us to shut down.
PrepareTitle(Relaunch) Succeeded, but cosxml has DISABLE_FAST_RELAU
[CBL] Saving crashdump to USB storage if available...
AppPanic 0x%08X %s
[+-*APPLICATION EXITED %d*-+]
OSBlockThreadsOnExit default for sdk version 21011
D Fãñ €€ __AppFlags: 0x00000000
` FÜ €€ UserMode OS library build date: Mar 11 2014 10:04:27
` 1y¾ €*€ Core 2 Complete, MSR 0x00005072, Default Thread 0x10040EE0
` 12Z €
€ Core 0 Complete, MSR 0x00005072, Default Thread 0x100401A0
VVVVVVV----- PPC Kernel Waiting -----VVVVVVV
cos COS shell service available.
/dev/iopsh LOST GAIN *** action callback not in foreground.
------------------PROCESS %d %s FOREGROUND--------------------
*** action callback out of process context.
*** KiRPLStartup called in wrong process $ <Âl² €œ out of range
Stopwatch Index is out of range
Disabled , Pending
------------
CORE%d: Process %d Interrupts:%s%s
------------
Enabled
[CBL] Saving crashdump to USB storage if available...
[CBL] Saving crashdump to USB storage if available for p
** System process cannot run in non-system-process s $ <Âdy €œ O SHUT DOWN (m%d,f%d)***
***APD REQUEST***
SHUTINFO: PFID %d is in Foreground
SHUTINFO: PFID %d is also alive.
***PPC FAST CYCLE***
SHUTINFO: no process is in Foreground
***ShutdownCompleted call when system not in shutdown!
***PPC SHUTDOWN COMP $ <ÂcØ €œ ile type %d, name "%s" - err %d
***KiProcLoadShared - file type %d name "%s" is too big for target.
***KiProcLoadShared - file type %d name "%s" is too big to fit.
***KiProcLoadShared - LoadAsync(%d,%d) failed with error %d on file "%s".
***PPC TOLD T $ <Âc7 €œ KiProcReleaseEpilogue
APPEXIT %d %08X *** HBM cannot do fast exit.
*** HBM must be running to do fast exit.
*** KiProcLoadShared times out loading shared data.
!!!KiProcLoadShared - transfer rate is really slow.
***KiProcLoadShared - could not find f $ <Âb“ €œ master title is a Game(0x%08X)
***Logic Error on Fast Restart(2)
--- Master title is Abandon-On-Exit ---
** Logic error
***Process releasing foreground without saved/ready notification.
** ReleaseForeground when no message sent to process to do that. $ <Âaî €œ de size.
*** Process code size is > maximum.
*** Process mapping+gen data size consumes more than whole process data area!
odd usb sdcard ***Logic Error on Fast Restart
---PPC USER-LEVEL FAST RESTART---
New master title is a CafeMenu(0x%08X)
New $ <ÂaJ €œ ocEndAtomicOp when atomic op not in progress
*** A required ram partition was listed more than once.
*** At least one required ram partition could not be found.
*** Process trying to allocate non-present ram partition.
*** Process max size is <= its co $ <Â`ª €œ specified for SendPolicy.
*** Unknown policy kernel identifier - 0x%08X. Ignored.
*** Invalid process id specified for SendPolicy
*** Cant send specified policy to game in foreground.
*
Stack Execution
-----------------------------------------------------------------
1. Load buffer_address into r30 and (buffer_address + 4) into r31, both off the stack (at 0x0E0F55C8)
2. Call OSGetCodegenVirtAddrRange(), but in the middle (at 0x0103249C)
3. Load r3 into r31, then jump back into our ROP chain (at 0x0F0B5EB0)
4. Load the address of our shellcode into r4, off the stack (at 0x0E0F498C)
5. Load the length of our shellcode into r5, like 0x400, off the stack (at 0x0E10606C)
6. Call OSCodegenCopy() indirectly (at 0x0EA12168)
7. Move r3 to CTR and branch there to begin executing our shellcode (at 0x0E0F347C)
Iré actualizando este mensaje