Toggle menu
Toggle preferences menu
Toggle personal menu
Not logged in
Your IP address will be publicly visible if you make any edits.

3DS:GYTB and Wii U:ISFShax: Difference between pages

From Hacks Guide Wiki
(Difference between pages)
ItsCrocoSwine (talk | contribs)
renamed most of the headers to match other pages + added more badge requirements
 
Adds update blocking information, instructions and exploit method for Haxchi/CBHC, instructions to replace the encrypted fw.img with the non-encrypted one, general troubleshooting information, and a plugin list. Removes disclaimers for legacy environments, as there is a proper method for them now.
 
Line 1: Line 1:
{{Infobox homebrew
'''ISFShax''' exploits boot1 using a specially designed ISFS (SLC filesystem) superblock. Once installed, it offers similar capabilities to defuse. Since it runs before IOSU, it can apply early patches to IOSU and repair most types of bricks. However, it cannot protect against bricks caused by boot1 corruption, seeprom issues, or installing a faulty ISFShax superblock. Additionally, ISFShax cannot help if the Wii U is already bricked.
| title = GYTB
| image = GYTB-Banner.png
| imagealt = GYTB banner as used on the HOME Menu
| for3ds = 1
| developers = MrCheeze
| version = 1.0
| releasedate = 2019-02-02
| github = MechanicalDragon0687/GYTB
| githubtag = 1.0
| universaldb = 3ds/gytb
}}
'''GYTB''' (an acronym for Give You This Budge) is a homebrew app for the 3DS, developed by [https://github.com/MrCheeze/GYTB MrCheeze]. It allows you to install image files as custom badges to display on your HOME Menu. GYTB only works on system firmwares 9.3 and above.


==Installation==
== Features ==
 
*Rebuilding or upgrading the MLC
*Removing the 64GB MLC limit and disabling SCFM
*Brick protection, such as before performing a region change
*Cold booting redNAND, which is helpful when the eMMC is failing
*Providing a minimal CFW that can launch old homebrew using the homebrew launcher (though this might be less useful with Aroma and Tiramisu available)
*Preventing the Wii U from turning on the Tablet during boot using a stroopwafel plugin
 
{{info|text= To protect against Nintendo pushing a boot1 update, which would brick a console with ISFShax, '''system updates get blocked''' by the <code>wafel_isfshax_patch</code> plugin. If you need to perform a system update, use v1.0 of said plugin, which doesn't contain the update block.}}
 
== Exploit Methods ==
 
There are quite a few ways to launch the ISFShax installer.
 
*If you already have Tiramisu or Aroma installed and can launch it, follow the Instructions for Aroma
*If you already have Haxchi or CBHC installed, follow Instructions for Haxchi
*If the Browser still works and you can launch the browser exploit u.wiidb.de, follow the Instructions for Browser
*If you can't access the Browser, but Settings still work follow Instructions for DNSpresso
*If your Wii U crashes in the initial setup on Mii creation, follow Instructions for DNSpresso
*If your Wii U can't launch the browser anymore or can't connect to the internet, follow the Instructions for UDPIH
 
Make sure your SD card is FAT32, although this should already be the case if you have an environment installed.
 
== SD Preparation ==
 
You will need:
*The [https://github.com/isfshax/isfshax_installer/releases ISFShax installer] (<code>ios.img</code>)
*The [https://github.com/isfshax/isfshax/releases ISFShax Superblocks] (<code>superblock.img</code> and <code>superblock.img.sha</code>)
*The [https://github.com/jan-hofmeier/stroopwafel/releases stroopwafel] (<code>wafel_core.ipx</code>)
*The [https://github.com/isfshax/wafel_isfshax_patch/releases IOSU ISFShax tolerance patch] (<code>wafel_isfshax_patch.ipx</code>)
 
*The [https://github.com/jan-hofmeier/minute_minute/releases minute image] (<code>fw_encrypted.img</code>) '''[Aroma/Haxchi/Browser/DNSpresso]'''
*The [https://github.com/wiiu-env/fw_img_payload/releases fw_img_payload] zip '''[Browser/DNSpresso only]'''
*The [https://github.com/wiiu-env/PayloadFromRPX/releases root.rpx] '''[DNSpresso only]'''
*The [https://github.com/jan-hofmeier/minute_minute/releases minute images] (<code>fw.img</code> and <code>boot1.img</code> '''[UDPIH only]'''
*The [https://github.com/jan-hofmeier/recovery_menu/releases recovery_menu] '''[UDPIH only]'''
 
# Copy the <code>ios.img</code> to the root of your SD card.
# Copy the <code>superblock.img</code> and <code>superblock.img.sha</code> to root of your SD card.
# Copy the <code>wafel_core.ipx</code> and <code>wafel_isfshax_patch.ipx</code> to the <code>ios_plugins</code> folder in the <code>wiiu</code> folder.
# Copy the <code>fw_encrypted.img</code> to the root of your SD card and rename it to <code>fw.img</code>. '''(Aroma/Haxchi/Browser/DNSpresso)'''
# Extract the contents of the <code>fw_img_payload</code> zip to the root of your SD card. '''(Browser/DNSpresso)'''
# Copy the <code>root.rpx</code> to the root of your SD card and rename it to <code>launch.rpx</code> '''(DNSpresso)'''
# Copy the <code>fw.img</code> and <code>boot1.img</code> to the root of your SD card. '''(UDPIH)'''
# Copy the <code>recovery_menu</code> to the root of your SD card. '''(UDPIH)'''
 
 
The structure on the SD should look like this:
{{Tree list}}
 
* {{Tree icon|sd}} (root)
** {{Tree icon|f}} boot1.img (UDPIH only)
** {{Tree icon|f}} fw.img
** {{Tree icon|f}} ios.img
** {{Tree icon|f}} recovery_menu (UDPIH only)
** {{Tree icon|f}} launch.rpx (DNSpresso only)
** {{Tree icon|f}} superblock.img
** {{Tree icon|f}} superblock.img.sha
** {{Tree icon|d}} wiiu
*** {{Tree icon|f}} payload.elf (Browser, DNSpresso only)
*** {{Tree icon|d}} ios_plugins
**** {{Tree icon|f}} wafel_core.ipx
**** {{Tree icon|f}} wafel_isfshax_patch.ipx
{{Tree list/end}}
 
==Booting into Minute ==
 
Choose the appropriate method to boot into Minute based off of the setup you have.


<tabber>
<tabber>
|-|Universal-Updater=
 
|-|Aroma=
 
<span>
<span>
# Power on the console
# Hold B on boot or while launching Health and Safety (whether you coldboot or not) to boot into the PayloadLoader.
# Open '''Universal-Updater'''
# You will be asked to choose your payload.
# Tap the magnifying glass on the bottom screen, then search for '''GYTB'''
# Select "fw_img_loader".
# Press {{B|A}} while hovering over '''GYTB''' from the list of homebrew
 
# Choose <code>GYTB.3dsx</code> for the Homebrew Launcher or <code>GYTB.cia</code> for HOME Menu installation
{{info|text= If the fw_img_loader isn't present, grab it from the [https://aroma.foryour.cafe Aroma Website].}}
# Wait until the app installs
# Exit '''Universal-Updater'''
</span>
</span>


|-|FBI=
|-|Haxchi=
{{FBI QR code
| name1 = CIA
| url1 = https://github.com/MechanicalDragon0687/GYTB/releases/download/1.0/GYTB.cia
| name2 = 3dsx
| url2 = https://hacksguidewiki.sfo3.digitaloceanspaces.com/hacksguidewiki/GYTB.3dsx
}}


|-|Manually as CIA=
<span>
<span>
* Download [https://github.com/MechanicalDragon0687/GYTB/releases/download/1.0/GYTB.cia GYTB.cia] (direct download)
# Hold A on the gamepad while launching the Haxchi or DO NOT TOUCH ME app.
* Install it using a CIA installer such as [[3DS:FBI|FBI]]
# Alternatively, if you have CHBC, you can hold A on the gamepad while booting the console.
</span>
</span>


|-|Manually as 3dsx=
|-|Browser=
 
<span>
<span>
* Download [https://github.com/MechanicalDragon0687/GYTB/releases/download/1.0/GYTB_hax.zip GYTB_hax.zip] (direct Download)
# Navigate to the browser and type in "u.wiidb.de" in the address bar.
* Copy the <code>3ds</code> folder from inside the <code>GYTB_hax.zip</code> onto the root of your SD card
# Click on "HAXX".
** If you are using macOS, hold the {{Key press|Option}} key while dragging the folders to the root of your SD card, then click '''Merge'''
</span>
</span>
|-|DNSpresso=
<span>
If you can access the settings, follow the instructions provided here (you already have the correct files on the SD card): [https://gbatemp.net/threads/dnspresso-a-wii-u-dns-exploit.642123/ DNSpresso - A Wii U DNS Exploit.]
If you are stuck on User/Mii creation during the initial setup:
# If your Wii U is already connected to your AP/Router, turn off the AP/Router or disable its WiFi.
# When the setup asks if you already have a NNID, select "Yes" (even if you don't have one).
# The system will attempt to connect to the Internet, fail, and then prompt you to return to the WiFi settings.
# Turn your AP/Router back on and wait for it to start.
# If your WiFi is not already configured, connect to it now, but enter an incorrect password.
# Edit your WiFi connection and set 85.215.57.182 as the Primary DNS. If you entered a wrong password before, correct it now.
# Press (B) to go back and select "Connection Test."
</span>
|-|UDPIH=
<span>
# Boot into recovery_menu as per [https://gbatemp.net/threads/udpih-usb-host-stack-exploit-recovery-menu.613369/ this guide]
# Unplug the pico or Switch.
# Select "Load BOOT1 Payload" from the list and continue on.
{{info|text=(If your tv doesn't display an output, you'll have to navigate blindly: 18x eject, 1x power, 1 eject, 1 power)}}
</span>
</tabber>
</tabber>


==Badge requirements==
You should now see the minute main menu. If not, ensure you have the correct fw.img file on the SD card.
* Custom badges must be <code>.png</code>(s) whose dimensions are divisible by 64 pixels
 
* [https://themeplaza.art/badges Theme Plaza] has a large collection of such badge images
In minute, use the power button to move the cursor and the eject button to select (this is opposite to the recovery menu controls).
** If you get custom badges from Theme Plaza, look for and delete <code>preview.png</code>
 
* The custom badge's name is set to whatever the filename of the badge is
{{info|text=Minute only outputs 1080p through HDMI, with no display on the GamePad or analog outputs. Some users have reported that the screen output doesn't work when minute is loaded from the recovery_menu. If you've verified that the fw.img file is correct and your TV supports 1080p HDMI, you can still proceed by pressing the appropriate buttons blindly. Make sure to wait long enough between presses to allow the system to load. Without display output, skip the first backup and go directly to installing ISFShax.}}
* Images larger than 64x64 will be split into separate badges (eg. 128x128 will be split into four badges)
 
** Badges split in this way will share the same name or app shortcut
 
* The most badges you can install at a time is 1,000. If you attempt to install more than 1,000 badges, GYTB will crash.
==Backup and Installation==
We will now start with a fresh NAND backup.
 
#Navigate to <code>Backup and Restore</code>
#Select <code>Dump OTP and Seeprom</code>
#When that is done, select <code>Dump SLC.RAW</code>
#Once that is done, return to the main menu.
 
===Installing ISFShax ===
#Select <code>Boot ios.img</code> (blind combo is Power 6x, Eject 1x)
# The ISFShax installer will launch after a brief moment.
#Follow the onscreen instructions, the buttons are the same as minute's (3x Eject, 1x Power, 3x Eject).
# The console should now turn off.
# Replace the encrypted <code>fw.img</code> on the SD with the <code>fw.img</code> '''(NOT the encrypted one)'''.  
#If it successfully installed, the Wii U will directly boot into minute once you boot again.
 
===Backing up ISFSHax ===
Go back to Backup and Restore and Dump the SLC.RAW again. This will replace the previous SLC.RAW file you dumped earlier. It's required if you want to restore the SLC for unbricking, without losing ISFShax, in case the superblock protection fails. Keep that backup somewhere safe.
 
==Booting with ISFShax ==
 
From this point on, the Wii U can still boot without the SD card, but will have some patches applied (ISFShax tolerance for IOSU, update blocking).
To boot into the Wii U OS in minute, select <code>Patch (sd) and boot IOS (slc)</code> (2x Power, 1x Eject).
 
{{info|text= If your console bootloops through minute over and over again, you're probably coldbooting Aroma or Tiramisu and replaced the <code>wiiu/payload.elf</code> with the fw_img loader. Just replace it with the proper <code>wiiu/payload.elf</code> for Aroma [https://github.com/wiiu-env/PayloadLoaderPayload/releases here] (This also applies to Tiramisu).}}
 
===Launching Aroma/Tiramisu with ISFShax ===
You can use ISFShax to boot into Aroma or Tiramisu.
To begin, you will need the latest files from the sites.
 
{{info|text=If you are already coldbooting Tiramisu or Aroma via the PayloadLoader Installer, you need to disable the coldboot in the PayloadLoaderInstaller first.}}
 
*Aroma: Download [https://aroma.foryour.cafe here]
*Tiramisu: Download [https://tiramisu.foryour.cafe here]
*The [https://github.com/jan-hofmeier/wafel_payloader wafel_payloader.ipx]
# Put the wafel_payloader.ipx file in the ios_plugins folder.
#Place the root.rpx file from [https://github.com/wiiu-env/PayloadFromRPX/releases PayloadFromRPX] in the wiiu folder on the SD card.
#*Alternatively, if you have Aroma and/or Tiramisu already, you can just grab the root.rpx from your environment of choice's folder from <code>wiiu/environments/[ENVIRONMENT]/</code> and place it  in the wiiu folder of the SD card.
 
===Booting without SD ===
 
This step is optional but highly recommended. Without the SD card, the Wii U will still boot, but will only have minimal patches applied.


===Shortcuts===
To fix this, we need to install minute (fw.img) and the stroopwafel plugins (wafel_core + wafel_isfshax_patch) to the internal memory (SLC). This can be done using FTPiiU-Everywhere, which can be launched from Tiramisu and is part of the Aroma Package (enable in the plugin settings), or you can use the [https://github.com/mackieks/haxcopy haxcopy homebrew].
Custom badges can be made into shortcuts to launch system applications; a list of compatible titles can be found [[3dbrew:Title_list#00040010_-_System_Applications|here]]. To create a badge shortcut, rename the badge so the TIDLow of the system app is between the first and second period of the file name, like so: <code>BadgeName.<TIDLow>.png</code>.  For example, a file named <code>settings.00021000.png</code> would create a badge named settings that launches USA System Settings (mset). Badges made into shortcuts will display the banner of the application they launch, rather than being a pin; applications without a banner will display a default banner instead.


==Instructions==
Haxcopy is recommended for most users, but if you accidentally copy a wrong plugin to the SLC or need to delete one, you'll still need to use FTP.


<tabber>
<tabber>
|-|CIA=
 
|-|Haxcopy=
<span>
<span>
===Section I - Prep work===
# Create a folder named "hax" on the SD card.
# Create a <code>badges</code> folder on the root of your SD card
# Copy the fw.img to the hax folder.
# Copy your badge <code>.png</code> files to the <code>badges</code> folder
# Create a subfolder named "ios_plugins" in the hax folder.
# Reinsert your SD card into your console
# Rename wafel_core.ipx to 0core.ipx and copy it to the hax/ios_plugins folder.
 
# Rename wafel_isfshax_patch.ipx to 6isfshax.ipx and copy it to the hax/ios_plugins folder.
===Section II - Installing Badges===
# If you want to coldboot Aroma or Tiramisu, rename wafel_payloader.ipx to 9payldr.ipx and copy it to the hax/ios_plugins folder.
# Power on your console and Launch '''GYTB''' from the HOME screen
# If you need other plugins like wafel_unlimit.ipx, rename and copy them to the hax/ios_plugins folder.
#* You should see your badges flash on the screen, and be sent back to the HOME Menu afterward
# Download the <code>haxcopy.wuhb</code> from [https://github.com/mackieks/haxcopy/releases here] and copy it to to the wiiu/apps folder (as you would normally install homebrew).
# Insert the SD card into the Wii U and run haxcopy to transfer the hax folder to the SLC.
</span>
</span>


|-|3dsx=
|-|FTP=
<span>
<span>
===Section I - Prep work===
{{info|text=You do not need to do the first two steps if you already have system file access enabled in the FTPiiU configuration.}}
# Create a <code>badges</code> folder in the same location as <code>GYTB.3dsx</code>
#Open the Aroma Plugin Configuration Menu using L + Down + SELECT (-) on the GamePad or Pro Controller (or B + Down + Minus (-) for WiiMotes).
#*{{Tree list}}
#Open the FTPiiU option, then settings, and set ‘Allow access to system files’ to ‘true’ by pressing A.
#** {{Tree icon|sd}} (root)
# Use an FTP client on the PC to browse to /storage_slc/.
#*** {{Tree icon|d}} 3ds
# If you see a scfm.img file and sys folder, go into the sys folder. If you see folders like config, import, logs, proc, rights, security, title, and tmp, move to the next step.
#**** {{Tree icon|d}} GYTB
# Create a subfolder named "hax" and enter it.
#***** {{Tree icon|d}} badges
# Ensure your FTP client is in binary mode (not ASCII mode).
#***** {{Tree icon|f}} GYTB.3dsx
# Upload the minute fw.img to the /storage_slc/sys/hax folder.
# Copy your badge <code>.png</code> files to the <code>badges</code> folder
# Create another subfolder named "ios_plugins" in /storage_slc/sys/hax.
# Reinsert your SD card into your console
# Enter the /storage_slc/sys/hax/ios_plugins folder.
 
# Rename wafel_core.ipx to 0core.ipx and upload it.
===Section II - Installing Badges===
# Rename wafel_isfshax_patch.ipx to 6isfshax.ipx and upload it.
# Power on your console and open the '''Homebrew Launcher'''
# If you want to coldboot Aroma or Tiramisu, rename wafel_payloader.ipx to 9payldr.ipx and upload it.
#* If you already have a '''Homebrew Launcher''' icon on the HOME Menu, use that
# If you need other plugins like wafel_unlimit.ipx, rename and upload them too.
#* If you do not have this icon, do the following set of steps:
#*# Open '''Download Play'''
#*# Open [[3DS:Luma3DS/Rosalina|Rosalina]] (the most common keycombos for the menu are {{Key press|L|Down|SELECT}} and {{Key press|X|Y}}
#*# Go into '''Miscellaneous options''', then select '''Switch the hb. title to the current app'''
#*# Press {{B|B}} until you exit Rosalina, then close '''Download Play''' and reopen it - at this point, the Homebrew Launcher should appear
# Launch '''GYTB''' from the list of homebrew
#* You should see your badges flash on the screen, and be sent back to the HOME Menu afterward
</span>
</span>
</tabber>
</tabber>
Now, the Wii U should autoboot if no SD card is inserted. If an SD card is inserted, the minute menu should show up (even if the SD doesn't contain a fw.img). In that menu, you can select the Patch (SLC) and boot IOS (SLC) to load the plugins from the SLC and boot (no need to have them on the SD anymore).
{{info|text=The Wii U will first try to load the fw.img from the SLC, and if that fails, it will fall back to the SD. If you install a broken fw.img that doesn't load, you can force ISFShax to load the fw.img from the SD by repeatedly pressing the power button until the menu shows up.}}
{{warning|text=A factory reset will delete the hax folder. Without the fw.img on the SD, the Wii U will boot with minimal patches, but some actions (such as leaving the System Settings) may be slower. It's recommended to set up minute and stroopwafel again.}}
===Autobooting with SD (Optional) ===
To enable autoboot on the Wii U with an SD card inserted, create the file <code>sd:/minute/minute.ini</code> with the following content:
<syntaxhighlight>
[boot]
autoboot=1
autoboot_timeout=3
</syntaxhighlight>
You can adjust the timeout (in seconds) to your preference. The <code>autoboot</code> option determines which entry from the minute menu will be loaded. Setting it to <code>1</code> corresponds to <code>Patch (slc) and boot IOS (slc)"</code>, which loads the ios_plugins from the SLC. If you haven't installed them to the SLC or want to load them from the SD for any reason, change the value to <code>3</code>, which corresponds to <code>"Patch (sd) and boot IOS (slc)</code>.
{{info|text=If you combine autobooting minute with the wafel_payloader plugin, you can autoboot Aroma or Tiramisu without having Health and Safety injected at all!}}
As an alternative, check out the Fastboot option below.
===Fastbooting (Optional) ===
To make the Wii U boot as fast as possible, without showing minute, you can now use the fw_fastboot.img. This won't work with redNAND
It is hardcoded to go straight to the first option (booting the SLC, with patches from SLC). It won't display anything and ignore any autoboot configuration in the minute.ini.
#First make sure the system can boot using the first option in minute. (see Booting without SD)
#Replace the the fw.img in the hax folder on the SLC with the fastboot image (fw_fastboot.img renamed to fw.img)
If you get stuck for whatever reason and need to fully load minute from your SD, you can do this:
#Place the minute fw.img on the SD card
#Repeatedly press the power button until the minute menu shows up on the screen.
==Uninstalling ISFShax ==


===Section III - Decorate with Badges===
{{warning|text=Do NOT restore an older SLC backup, as it will break SCFM!}}


# Tap on HOME Menu Settings in the top left of the HOME Menu
Ensure your Wii U doesn't rely on any patches (like wafel_unlimit_mlc.ipx or redNAND). You can verify this by booting with only the wafel_core.ipx and wafel_isfshax_ipx plugins in the ios_plugins directory on the SD card and selecting the "Patch (sd) and boot IOS (slc)" option.
# Tap on the new button titled "'''Decorate with Badges'''"
# Drag your custom badges from the top of the screen onto your HOME Menu
#* To attach badges to folders, tap on the top right wrench icon and select "'''Attach Badge to Folder'''"
# Tap on the <code>X</code> or press the {{B|HOME}},{{B|B}}, or {{B|X}} buttons to exit the badge menu


== Troubleshooting ==
To proceed:


If '''GYTB''' causes an [[3DS:EXCEPTION|exception]] when you open it, it is usually one of two reasons:
#Delete the /storage_slc/sys/hax folder if you have set up SLC booting.
# There is an image whose dimensions can't be divided by 64 in the <code>badges</code> folder
# Run the ISFShax installer again from minute and follow the on-screen instructions to uninstall.
#* <code>preview.png</code> is a common instance of this, especially when downloading from Theme Plaza. Check for this file and delete it.
# There are more than 1000 images inside the <code>badges</code> folder
#* The 3DS can only have 1000 badges installed. This is a hard limit that cannot be bypassed; remove images until you are under the limit again.


If '''GYTB''' gives the error "'''WHAT IS WRONG WITH THE ELF.'''", it is for one of two reasons:
==Recommended Plugins ==
# If the error appears after saying "'''Writing to extdata...'''", your badges folder is either not present, misplaced, or misnamed.
# If the error appears after saying "'''Checking for preexisting Badge Arcade badges to dump...'''", then your pre-existing badges were unable to be dumped.


Here is a list of currently available stroopwafel plugins you can use with ISFShax:


[[Category:Nintendo 3DS guides]]
# [https://github.com/jan-hofmeier/wafel_noinit_tablet wafel_noinit_tablet] - Prevents the gamepad from turning on while booting the console.
[[Category:Nintendo 3DS homebrew]]
# [https://github.com/jan-hofmeier/wafel_sd_usb/releases SDUSB] - Allows you to run games from the SD Card.
# [https://github.com/jan-hofmeier/wafel_usb_partition/releases USB Partition] - Allows you to use partitioned USB devices with the Wii U.
# [https://github.com/jan-hofmeier/wafel_setup_mlc/releases wafel_setup_mlc] - Allows you to rebuild or upgrade the MLC.

Revision as of 23:27, 9 August 2024

ISFShax exploits boot1 using a specially designed ISFS (SLC filesystem) superblock. Once installed, it offers similar capabilities to defuse. Since it runs before IOSU, it can apply early patches to IOSU and repair most types of bricks. However, it cannot protect against bricks caused by boot1 corruption, seeprom issues, or installing a faulty ISFShax superblock. Additionally, ISFShax cannot help if the Wii U is already bricked.

Features

  • Rebuilding or upgrading the MLC
  • Removing the 64GB MLC limit and disabling SCFM
  • Brick protection, such as before performing a region change
  • Cold booting redNAND, which is helpful when the eMMC is failing
  • Providing a minimal CFW that can launch old homebrew using the homebrew launcher (though this might be less useful with Aroma and Tiramisu available)
  • Preventing the Wii U from turning on the Tablet during boot using a stroopwafel plugin
Info icon To protect against Nintendo pushing a boot1 update, which would brick a console with ISFShax, system updates get blocked by the wafel_isfshax_patch plugin. If you need to perform a system update, use v1.0 of said plugin, which doesn't contain the update block.

Exploit Methods

There are quite a few ways to launch the ISFShax installer.

  • If you already have Tiramisu or Aroma installed and can launch it, follow the Instructions for Aroma
  • If you already have Haxchi or CBHC installed, follow Instructions for Haxchi
  • If the Browser still works and you can launch the browser exploit u.wiidb.de, follow the Instructions for Browser
  • If you can't access the Browser, but Settings still work follow Instructions for DNSpresso
  • If your Wii U crashes in the initial setup on Mii creation, follow Instructions for DNSpresso
  • If your Wii U can't launch the browser anymore or can't connect to the internet, follow the Instructions for UDPIH

Make sure your SD card is FAT32, although this should already be the case if you have an environment installed.

SD Preparation

You will need:

  1. Copy the ios.img to the root of your SD card.
  2. Copy the superblock.img and superblock.img.sha to root of your SD card.
  3. Copy the wafel_core.ipx and wafel_isfshax_patch.ipx to the ios_plugins folder in the wiiu folder.
  4. Copy the fw_encrypted.img to the root of your SD card and rename it to fw.img. (Aroma/Haxchi/Browser/DNSpresso)
  5. Extract the contents of the fw_img_payload zip to the root of your SD card. (Browser/DNSpresso)
  6. Copy the root.rpx to the root of your SD card and rename it to launch.rpx (DNSpresso)
  7. Copy the fw.img and boot1.img to the root of your SD card. (UDPIH)
  8. Copy the recovery_menu to the root of your SD card. (UDPIH)


The structure on the SD should look like this:

  • SD card icon (root)
    • File icon boot1.img (UDPIH only)
    • File icon fw.img
    • File icon ios.img
    • File icon recovery_menu (UDPIH only)
    • File icon launch.rpx (DNSpresso only)
    • File icon superblock.img
    • File icon superblock.img.sha
    • Folder icon wiiu
      • File icon payload.elf (Browser, DNSpresso only)
      • Folder icon ios_plugins
        • File icon wafel_core.ipx
        • File icon wafel_isfshax_patch.ipx

Booting into Minute

Choose the appropriate method to boot into Minute based off of the setup you have.

  1. Hold B on boot or while launching Health and Safety (whether you coldboot or not) to boot into the PayloadLoader.
  2. You will be asked to choose your payload.
  3. Select "fw_img_loader".
Info icon If the fw_img_loader isn't present, grab it from the Aroma Website.

  1. Hold A on the gamepad while launching the Haxchi or DO NOT TOUCH ME app.
  2. Alternatively, if you have CHBC, you can hold A on the gamepad while booting the console.

  1. Navigate to the browser and type in "u.wiidb.de" in the address bar.
  2. Click on "HAXX".

If you can access the settings, follow the instructions provided here (you already have the correct files on the SD card): DNSpresso - A Wii U DNS Exploit.

If you are stuck on User/Mii creation during the initial setup:

  1. If your Wii U is already connected to your AP/Router, turn off the AP/Router or disable its WiFi.
  2. When the setup asks if you already have a NNID, select "Yes" (even if you don't have one).
  3. The system will attempt to connect to the Internet, fail, and then prompt you to return to the WiFi settings.
  4. Turn your AP/Router back on and wait for it to start.
  5. If your WiFi is not already configured, connect to it now, but enter an incorrect password.
  6. Edit your WiFi connection and set 85.215.57.182 as the Primary DNS. If you entered a wrong password before, correct it now.
  7. Press (B) to go back and select "Connection Test."

  1. Boot into recovery_menu as per this guide
  2. Unplug the pico or Switch.
  3. Select "Load BOOT1 Payload" from the list and continue on.
Info icon (If your tv doesn't display an output, you'll have to navigate blindly: 18x eject, 1x power, 1 eject, 1 power)

You should now see the minute main menu. If not, ensure you have the correct fw.img file on the SD card.

In minute, use the power button to move the cursor and the eject button to select (this is opposite to the recovery menu controls).

Info icon Minute only outputs 1080p through HDMI, with no display on the GamePad or analog outputs. Some users have reported that the screen output doesn't work when minute is loaded from the recovery_menu. If you've verified that the fw.img file is correct and your TV supports 1080p HDMI, you can still proceed by pressing the appropriate buttons blindly. Make sure to wait long enough between presses to allow the system to load. Without display output, skip the first backup and go directly to installing ISFShax.


Backup and Installation

We will now start with a fresh NAND backup.

  1. Navigate to Backup and Restore
  2. Select Dump OTP and Seeprom
  3. When that is done, select Dump SLC.RAW
  4. Once that is done, return to the main menu.

Installing ISFShax

  1. Select Boot ios.img (blind combo is Power 6x, Eject 1x)
  2. The ISFShax installer will launch after a brief moment.
  3. Follow the onscreen instructions, the buttons are the same as minute's (3x Eject, 1x Power, 3x Eject).
  4. The console should now turn off.
  5. Replace the encrypted fw.img on the SD with the fw.img (NOT the encrypted one).
  6. If it successfully installed, the Wii U will directly boot into minute once you boot again.

Backing up ISFSHax

Go back to Backup and Restore and Dump the SLC.RAW again. This will replace the previous SLC.RAW file you dumped earlier. It's required if you want to restore the SLC for unbricking, without losing ISFShax, in case the superblock protection fails. Keep that backup somewhere safe.

Booting with ISFShax

From this point on, the Wii U can still boot without the SD card, but will have some patches applied (ISFShax tolerance for IOSU, update blocking). To boot into the Wii U OS in minute, select Patch (sd) and boot IOS (slc) (2x Power, 1x Eject).

Info icon If your console bootloops through minute over and over again, you're probably coldbooting Aroma or Tiramisu and replaced the wiiu/payload.elf with the fw_img loader. Just replace it with the proper wiiu/payload.elf for Aroma here (This also applies to Tiramisu).

Launching Aroma/Tiramisu with ISFShax

You can use ISFShax to boot into Aroma or Tiramisu. To begin, you will need the latest files from the sites.

Info icon If you are already coldbooting Tiramisu or Aroma via the PayloadLoader Installer, you need to disable the coldboot in the PayloadLoaderInstaller first.
  1. Put the wafel_payloader.ipx file in the ios_plugins folder.
  2. Place the root.rpx file from PayloadFromRPX in the wiiu folder on the SD card.
    • Alternatively, if you have Aroma and/or Tiramisu already, you can just grab the root.rpx from your environment of choice's folder from wiiu/environments/[ENVIRONMENT]/ and place it in the wiiu folder of the SD card.

Booting without SD

This step is optional but highly recommended. Without the SD card, the Wii U will still boot, but will only have minimal patches applied.

To fix this, we need to install minute (fw.img) and the stroopwafel plugins (wafel_core + wafel_isfshax_patch) to the internal memory (SLC). This can be done using FTPiiU-Everywhere, which can be launched from Tiramisu and is part of the Aroma Package (enable in the plugin settings), or you can use the haxcopy homebrew.

Haxcopy is recommended for most users, but if you accidentally copy a wrong plugin to the SLC or need to delete one, you'll still need to use FTP.

  1. Create a folder named "hax" on the SD card.
  2. Copy the fw.img to the hax folder.
  3. Create a subfolder named "ios_plugins" in the hax folder.
  4. Rename wafel_core.ipx to 0core.ipx and copy it to the hax/ios_plugins folder.
  5. Rename wafel_isfshax_patch.ipx to 6isfshax.ipx and copy it to the hax/ios_plugins folder.
  6. If you want to coldboot Aroma or Tiramisu, rename wafel_payloader.ipx to 9payldr.ipx and copy it to the hax/ios_plugins folder.
  7. If you need other plugins like wafel_unlimit.ipx, rename and copy them to the hax/ios_plugins folder.
  8. Download the haxcopy.wuhb from here and copy it to to the wiiu/apps folder (as you would normally install homebrew).
  9. Insert the SD card into the Wii U and run haxcopy to transfer the hax folder to the SLC.

Info icon You do not need to do the first two steps if you already have system file access enabled in the FTPiiU configuration.
  1. Open the Aroma Plugin Configuration Menu using L + Down + SELECT (-) on the GamePad or Pro Controller (or B + Down + Minus (-) for WiiMotes).
  2. Open the FTPiiU option, then settings, and set ‘Allow access to system files’ to ‘true’ by pressing A.
  3. Use an FTP client on the PC to browse to /storage_slc/.
  4. If you see a scfm.img file and sys folder, go into the sys folder. If you see folders like config, import, logs, proc, rights, security, title, and tmp, move to the next step.
  5. Create a subfolder named "hax" and enter it.
  6. Ensure your FTP client is in binary mode (not ASCII mode).
  7. Upload the minute fw.img to the /storage_slc/sys/hax folder.
  8. Create another subfolder named "ios_plugins" in /storage_slc/sys/hax.
  9. Enter the /storage_slc/sys/hax/ios_plugins folder.
  10. Rename wafel_core.ipx to 0core.ipx and upload it.
  11. Rename wafel_isfshax_patch.ipx to 6isfshax.ipx and upload it.
  12. If you want to coldboot Aroma or Tiramisu, rename wafel_payloader.ipx to 9payldr.ipx and upload it.
  13. If you need other plugins like wafel_unlimit.ipx, rename and upload them too.

Now, the Wii U should autoboot if no SD card is inserted. If an SD card is inserted, the minute menu should show up (even if the SD doesn't contain a fw.img). In that menu, you can select the Patch (SLC) and boot IOS (SLC) to load the plugins from the SLC and boot (no need to have them on the SD anymore).

Info icon The Wii U will first try to load the fw.img from the SLC, and if that fails, it will fall back to the SD. If you install a broken fw.img that doesn't load, you can force ISFShax to load the fw.img from the SD by repeatedly pressing the power button until the menu shows up.
Warning icon A factory reset will delete the hax folder. Without the fw.img on the SD, the Wii U will boot with minimal patches, but some actions (such as leaving the System Settings) may be slower. It's recommended to set up minute and stroopwafel again.

Autobooting with SD (Optional)

To enable autoboot on the Wii U with an SD card inserted, create the file sd:/minute/minute.ini with the following content:

[boot]
autoboot=1
autoboot_timeout=3

You can adjust the timeout (in seconds) to your preference. The autoboot option determines which entry from the minute menu will be loaded. Setting it to 1 corresponds to Patch (slc) and boot IOS (slc)", which loads the ios_plugins from the SLC. If you haven't installed them to the SLC or want to load them from the SD for any reason, change the value to 3, which corresponds to "Patch (sd) and boot IOS (slc).

Info icon If you combine autobooting minute with the wafel_payloader plugin, you can autoboot Aroma or Tiramisu without having Health and Safety injected at all!

As an alternative, check out the Fastboot option below.

Fastbooting (Optional)

To make the Wii U boot as fast as possible, without showing minute, you can now use the fw_fastboot.img. This won't work with redNAND It is hardcoded to go straight to the first option (booting the SLC, with patches from SLC). It won't display anything and ignore any autoboot configuration in the minute.ini.

  1. First make sure the system can boot using the first option in minute. (see Booting without SD)
  2. Replace the the fw.img in the hax folder on the SLC with the fastboot image (fw_fastboot.img renamed to fw.img)

If you get stuck for whatever reason and need to fully load minute from your SD, you can do this:

  1. Place the minute fw.img on the SD card
  2. Repeatedly press the power button until the minute menu shows up on the screen.

Uninstalling ISFShax

Warning icon Do NOT restore an older SLC backup, as it will break SCFM!

Ensure your Wii U doesn't rely on any patches (like wafel_unlimit_mlc.ipx or redNAND). You can verify this by booting with only the wafel_core.ipx and wafel_isfshax_ipx plugins in the ios_plugins directory on the SD card and selecting the "Patch (sd) and boot IOS (slc)" option.

To proceed:

  1. Delete the /storage_slc/sys/hax folder if you have set up SLC booting.
  2. Run the ISFShax installer again from minute and follow the on-screen instructions to uninstall.

Here is a list of currently available stroopwafel plugins you can use with ISFShax:

  1. wafel_noinit_tablet - Prevents the gamepad from turning on while booting the console.
  2. SDUSB - Allows you to run games from the SD Card.
  3. USB Partition - Allows you to use partitioned USB devices with the Wii U.
  4. wafel_setup_mlc - Allows you to rebuild or upgrade the MLC.