Exploits/Zelda
From WiiLi
This exploit takes advantage of a buffer overflow in the game "The Legend of Zelda: Twilight Princess".
Originally discussed on efnet in #wiidev then put teh<pseudeo>sceen, "Bushing along with Segher ... [were] able to modify a saved game from Zelda to crash the [Wii] and run their own code on it".
The process requires than once you modify a save game it is signed with 3 keys!
Some info from Bushing:
"Once the Wii decrypts the save game, it checks its signature. Every Wii has its own private key which is used to sign save games, and when you save a game, the Wii actually saves three bits of data:
- The encrypted save game
- The signature for the save game (using your console's private key)
- A copy of your console's public key, signed by Nintendo."
[edit] Picture Gallery
[edit] External Links
- Our forum topic about this exploit
- Zelda Exploit - Run Unsigned Code w/o Modchip - Original location. Current and temporary(?) location (Disabled the forums and are using the homepage because of high traffic)





