Developer Hykem has generated some controversy with his upcomingIOSU exploit, but published additional proof that the exploit is real: Wii U Kernel keys. The release date for Hykem’s IOSU exploit has been delayed a few times. Some people have been doubting that the exploit even exists, but knowing Hykem’s history on pretty much all gaming consoles, it’s safe to say naysayers couldn’t be more wrong.
Nevertheless, to shut people off, Hykem published a screenshot showing the Wii U ancast and vWii common keys, or at least a huge part of them. Accompanying the picture was a “happy bruteforcing” message, a way to say that people with the right tools and knowledge will be able to confirm his keys are the real deal, with some level of effort.
Developer Crediar has published the full keys on his twitter account on reply to Hykem, who acknowledged the result with a smiley.
This is also Hykem’s confirmation that his IOSU exploit works on the recently released Wii U firmware 5.5.1.
Hykem has recently
followed up on his release on GBATemp. He had
recently promised a release by end of January, but it seems this might get delayed again, as he is looking for ways to obfuscate his code, in an attempt to delay Nintendo patching the exploit. Hykem also decided to use Yellows8’s recently released
MP4 exploit, which has been confirmed to work up to the latest firmware 5.5.1. This allows Hykem to keep his own userland exploit for future use.
Hykem advises people to not update their Wii U and block future update from Nintendo, as they will most likely implement patches in their next firmware update. Blocking updates is done by blocking some specific IP addresses at your router level, this is easier than it sounds and you can google for it.
Hykem’s full statement:
In case you were afraid to deduce it from the screen I posted, yes, the hack works up to 5.5.1. However, I strongly recommend everyone to start blocking updates. That’s why I announced I was working on IOSU in the first place, to raise awareness.
I reached IOSU in 5.5.1 using a different bug (another lame UAF in WebKit) than yellows8‘s, but the libstagefright one is much more reliable and it’s already public. Which means that the release for 5.5.1 will be using yellows8‘s exploit while I keep the crappy one I used private.
Beware that Nintendo will likely push a big update to the Internet Browser anytime soon (I believe it’s logical to deduce that), which will quite likely patch (properly) both the libstagefright bugs and other previously unpatched WebKit bugs (the one I mentioned included).
Marionumber1 also made a solid point about investigating userland bugs in areas not related to the browser (like Mii data, for example), which is something we will likely investigate soon.
Aside from all that, the exploit just needs obfuscation to be released. Like I stated before, the obfuscation layers will be complex which will take time to implement properly. If any delays follow, they will be strictly related to the obfuscation of the exploit.
Also, I mentioned that my “vacations” are extended to the end of February, but that doesn’t mean the exploit will only be released by then. I’m guessing it will be done quite before that, but right now it’s just a matter of getting it right so Nintendo won’t patch it as soon as it comes out.