xboxscene.org forums

Pages: 1 ... 7 8 [9] 10 11 ... 17

Author Topic: BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45  (Read 1754 times)

Mike Bowler

  • Archived User
  • Newbie
  • *
  • Posts: 33
BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45
« Reply #120 on: February 28, 2007, 08:00:00 AM »

Perhaps i should extend upon what i was saying: secret between homebrew developers so that someone couldn't let slip what exactly was being exploited because i'm sure the people making the homebrew wouldn't want to spoil the fun now would they?

You know unless they stopped caring about homebrew and more about money or getting a job with M$ which i'm not sure if they'd get either but who knows eh?

Logged

UB6_IB9

  • Archived User
  • Newbie
  • *
  • Posts: 31
BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45
« Reply #121 on: February 28, 2007, 08:09:00 AM »

QUOTE(PillHarris @ Feb 28 2007, 03:52 PM) *

If it's secret then Microsoft don't care about, because nobody will be using it. They don't care about super secret exploits used by a few people, as soon as you put one out in the public that we all know about, Microsoft have this little thing called eFuse to answer that.

Yeh but by the time they would have figured out where vulnerability is and how the hack works there would have been alot more 360's modded and 360's that are able to be modded. It seems atm there are will be very few that can be hacked unless there becomes a way to downgrade the kernel. The anonymous hacker probly got screwed in the ass by M$ which is why he decided to tell the scene about it, after all they have no use for him once he tells them where the vulnerabilty is. This hack is better then nothing tho.
Logged

Hack_Bird

  • Archived User
  • Jr. Member
  • *
  • Posts: 71
BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45
« Reply #122 on: February 28, 2007, 08:05:00 AM »


 biggrin.gif  A lott of talk here about "nothing"
 and a few Smart guys ...

 smile.gif  Anyway, im staying 4552 and try some hacking myself ...
maybe remove that resistor?  tongue.gif

 ph34r.gif << This guy MUST release How2 soon .... laugh.gif if he wants to
Logged

Chan163

  • Archived User
  • Jr. Member
  • *
  • Posts: 76
BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45
« Reply #123 on: February 28, 2007, 08:39:00 AM »

I don't think we will get that much from this kind of exploit anymore (at least the ones already on 4552), because M$ now knows what to look for. The next exploit has to be something else. I hope the 'final solution' will be more like a 'crack' instead of an exploit running only on certain systems...


Now about that resistor: Will the 360 run normally when this resistor is removed permanently? Will a new kernel be able to check if that efuse is blown?
I have a 4532 sitting right next to me and I'm thinking of removing the resistor before going online again. Does anyone have a picture where to find that thing (I don't want to search the whole board for it)?
Logged

Knasen

  • Archived User
  • Sr. Member
  • *
  • Posts: 329
BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45
« Reply #124 on: February 28, 2007, 08:52:00 AM »

This was a most interesting read although I didn't understand 100% of it.. Hopefully something good comes out of it, like new ways to hack the console  smile.gif
Logged

handles25

  • Archived User
  • Full Member
  • *
  • Posts: 146
BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45
« Reply #125 on: February 28, 2007, 09:02:00 AM »

QUOTE(Chan163 @ Feb 28 2007, 04:39 PM) *

I don't think we will get that much from this kind of exploit anymore (at least the ones already on 4552), because M$ now knows what to look for. The next exploit has to be something else. I hope the 'final solution' will be more like a 'crack' instead of an exploit running only on certain systems...
Now about that resistor: Will the 360 run normally when this resistor is removed permanently? Will a new kernel be able to check if that efuse is blown?
I have a 4532 sitting right next to me and I'm thinking of removing the resistor before going online again. Does anyone have a picture where to find that thing (I don't want to search the whole board for it)?



Hear, hear.  What about this resistor?  If the information posted earlier was correct, and something goes wrong with the CPU, and we have removed the ability to blow the efuses, does this in turn break the "self healing" nature?

Do we risk more by removing it?

This is an interesting development.

This post has been edited by handles25: Feb 28 2007, 05:15 PM
Logged

Havok

  • Archived User
  • Hero Member
  • *
  • Posts: 1105
BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45
« Reply #126 on: February 28, 2007, 09:23:00 AM »

QUOTE(Hack_Bird @ Feb 28 2007, 03:12 PM) View Post

biggrin.gif  A lott of talk here about "nothing"
 and a few Smart guys ...

 smile.gif  Anyway, im staying 4552 and try some hacking myself ...
maybe remove that resistor?  tongue.gif

 ph34r.gif << This guy MUST release How2 soon .... laugh.gif if he wants to



If you are at 4552 then removing the resistor does nothing.  (Except prevent future efuses from being blown)..


BTW Guys: We knew about the blown efuse and resistor as soon as the kernel downgrade hacks were known.  So you could have easily removed the resistor before you upgrade the kernel if you cared... guess hindsight is 20/20.
Logged

asdfzxcv

  • Archived User
  • Newbie
  • *
  • Posts: 2
BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45
« Reply #127 on: February 28, 2007, 09:39:00 AM »


Am I correct to assume that if I my box has 4532 and if I can keep it that way (not connecting to live and not playing new retail games) then I'd be able to run future homebrews even without a modchip?  Kinda like the way dreamcast were?   If that's true, that's a great news!  There are ppl out there with 4532 and 4548 360 boxes.
Logged

basherbacon

  • Archived User
  • Newbie
  • *
  • Posts: 5
BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45
« Reply #128 on: February 28, 2007, 09:50:00 AM »

Does this mean that Homebrew software is possible? and could this also mean that there is a way of playing imported games that are region locked if a hack was sucessfully made for the hypervisor?
Logged

EvanVanVan

  • Archived User
  • Newbie
  • *
  • Posts: 42
BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45
« Reply #129 on: February 28, 2007, 09:44:00 AM »

i didnt read all 9 pages but you people saying this guy just wants an m$ job are stupid...any vulnerability ever found for a program or OS (http://packetstormsecurity.org/) they always tell the developer that they found it and how to fix it before fully releasing it..
Logged

bucko

  • Recovered User
  • Hero Member
  • *
  • Posts: 4255
BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45
« Reply #130 on: February 28, 2007, 10:00:00 AM »

Nice work! Looking forward to Linux3entoox cool.gif
Logged

webMASTER P

  • Archived User
  • Full Member
  • *
  • Posts: 186
BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45
« Reply #131 on: February 28, 2007, 10:21:00 AM »

there's only one homebrew app that i want to run, and that's XBMC
TVersity is doing an OK job for now but i want my XBMC on 360.

Also, with the power of the 360, PS2 emulation might be possible, and that would be sweet.
Logged

SteveNZ

  • Archived User
  • Newbie
  • *
  • Posts: 23
BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45
« Reply #132 on: February 28, 2007, 10:22:00 AM »

So, let me get this right. There _was_ a bug in the dashboard which allowed an exploit. Some time ago MS fixed this bug and anyone with an internet-connected 360 should have this bug fixed via a dash update. Now, AFTER the bug has been fixed (several weeks after), the information has been released, when it's of no use to ANYONE?

How is this possibly useful? And why the hell would they tell MS about it? They're lucky MS didn't sue them, guess they managed to stay anonymous the whole time.

Sounds pointless.
Logged

calderra

  • Archived User
  • Full Member
  • *
  • Posts: 113
BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45
« Reply #133 on: February 28, 2007, 10:29:00 AM »

Not only that, but this explot apprently uses XNA studio- a client that allows you to developer software from scratch and run it on 360, so that one could perhaps run software on the 360 after the crack.

It's like using a can opener to open a "Can-Opener-In-A-Can".

This post has been edited by calderra: Feb 28 2007, 06:30 PM
Logged

Shepdog

  • Archived User
  • Newbie
  • *
  • Posts: 49
BugTraq: Xbox360 Hypervisor Vulnerability - Unsigned Code on Kernel 45
« Reply #134 on: February 28, 2007, 10:31:00 AM »

QUOTE(SteveNZ @ Feb 28 2007, 06:22 PM) View Post

So, let me get this right. There _was_ a bug in the dashboard which allowed an exploit. Some time ago MS fixed this bug and anyone with an internet-connected 360 should have this bug fixed via a dash update. Now, AFTER the bug has been fixed (several weeks after), the information has been released, when it's of no use to ANYONE?

How is this possibly useful? And why the hell would they tell MS about it? They're lucky MS didn't sue them, guess they managed to stay anonymous the whole time.

Sounds pointless.

Some people who still have the old kernel can use this exploit to find other vulnerabillities which are still present in current kernel versions. sleeping.gif
Logged
Pages: 1 ... 7 8 [9] 10 11 ... 17