xboxscene.org forums

Author Topic: Possible Save Creation Exploit....  (Read 150 times)

Cookiesrus

  • Archived User
  • Full Member
  • *
  • Posts: 106
Possible Save Creation Exploit....
« on: June 01, 2006, 04:52:00 PM »

i posted this over at xboxhacker.net as wans.

Hi,

   First off i would like to let you know i know the pirs containers are signed and so far uneditable due to the signature.
While browsing the GRAW disc i came accross a png file which i got a friend to edit in photoshop, im total noob when it comes to ps.

I was hoping that this file represented the game you were currently playing but i later found out it was to represent your save file.

I found the offset for the image in the iso (0E0C27000) and replaced it with the edited one, and zero'd out the remaining data until the old picture was totally removed. Ithen burnt the disc and started a campaign to create a save.



he rest with pics is here - XBH thread
Logged

jtom617

  • Archived User
  • Sr. Member
  • *
  • Posts: 322
Possible Save Creation Exploit....
« Reply #1 on: June 01, 2006, 04:59:00 PM »

cool job man, i like those pics, thats really sweet! love.gif
Logged

lordvader129

  • Archived User
  • Hero Member
  • *
  • Posts: 5860
Possible Save Creation Exploit....
« Reply #2 on: June 01, 2006, 05:18:00 PM »

injecting a texture is a far cry from a softmod, and with the buffer overflow protection the 360 has i doubt it will lead to a softmod, but its a neat trick nonetheless
Logged

Cookiesrus

  • Archived User
  • Full Member
  • *
  • Posts: 106
Possible Save Creation Exploit....
« Reply #3 on: June 01, 2006, 05:36:00 PM »

QUOTE(lordvader129 @ Jun 2 2006, 12:25 AM) View Post

injecting a texture is a far cry from a softmod, and with the buffer overflow protection the 360 has i doubt it will lead to a softmod, but its a neat trick nonetheless


Yeah i thought of this too, but maybes using the right disc, custom gamerpics or themes maybe possible.

Its a simple thing to do, cost a DL to try it.  And maybe with more experimentation, and further research into what content is carried on discs, possibly more fun.
The NEAT part of this is that it inserts your modified file into a container then SIGNS it, maybe some thing there?

Unfortunatly my hacking skills are limited so i thought the info be best out than not tested!

Have fun!
Logged

PedrosPad

  • Archived User
  • Hero Member
  • *
  • Posts: 1277
Possible Save Creation Exploit....
« Reply #4 on: June 02, 2006, 01:45:00 AM »

QUOTE(Cookiesrus @ Jun 2 2006, 12:43 AM) View Post

The NEAT part of this is that it inserts your modified file into a container then SIGNS it, maybe some thing there?

That is interesting. smile.gif
Logged

Cookiesrus

  • Archived User
  • Full Member
  • *
  • Posts: 106
Possible Save Creation Exploit....
« Reply #5 on: June 02, 2006, 06:26:00 AM »

QUOTE(PedrosPad @ Jun 2 2006, 08:52 AM) View Post

That is interesting. smile.gif


Not as interesting as Major Nelsons shoes apparently, or a clown advertising 360.  I honestly thought this was front page material.
Oh well i guess your the only one that realises teh significance of a modified Pirs container that still works.
Logged

Flame2k

  • Archived User
  • Full Member
  • *
  • Posts: 152
Possible Save Creation Exploit....
« Reply #6 on: June 03, 2006, 01:00:00 AM »

QUOTE(Cookiesrus @ Jun 2 2006, 12:43 AM) View Post


The NEAT part of this is that it inserts your modified file into a container then SIGNS it, maybe some thing there?



this could be very significant... has anyone else tried injecting anything other than a different png image? ..

 dont really know much about it, but would it be possible to inject something else in there,

i dont really inderstand how pirs containers work and stuff but in this case arnt you basically managing to inject data into a signed object without breaking the signature??
Logged

Cookiesrus

  • Archived User
  • Full Member
  • *
  • Posts: 106
Possible Save Creation Exploit....
« Reply #7 on: June 03, 2006, 08:01:00 AM »

QUOTE(Flame2k @ Jun 3 2006, 08:07 AM) View Post

this could be very significant... has anyone else tried injecting anything other than a different png image? ..

 dont really know much about it, but would it be possible to inject something else in there,

i dont really inderstand how pirs containers work and stuff but in this case arnt you basically managing to inject data into a signed object without breaking the signature??


So far i have not tried injecting anything else, my goal at the minute is customization (sp?), im trying to target gamerpics at the min...

Save file pictures seem easy to modify, i havent looked at a lot of games yet, but i have already done it with Ghost Recon, and know its also possible with King Kong.
Im not exactley sure on the specifications of the pirs conatainer myself, i know there are variations of it, some signed and some unsigned.  The save files are signed and can not be modified once created.  
Its also important to understand that I have not broken the signature of the pirs container, i have simply modified the data the 360 puts into the container then signs...  The created container that contains the modofied .png file is still signed by the 360 and therefor fully usable on the 360.

Obviously progress is running quite slow at the minute, lack of games to test with and length of time it takes to write a disc being the main factor.

If anyone is interested in running tests of there own, please do so and give any info on success of failures here, the more people working on it, the quicker something, if anything will be achieved.
Logged

Flame2k

  • Archived User
  • Full Member
  • *
  • Posts: 152
Possible Save Creation Exploit....
« Reply #8 on: June 03, 2006, 09:55:00 AM »

Ah i see,

well this is very interesting as (in theory) you have stumbled upon a way to get data signed...(well, so far a png file within a pirs container)

I dont have a 360 myself so unfortunatley I cant contribute much to this effort.
Logged

lordvader129

  • Archived User
  • Hero Member
  • *
  • Posts: 5860
Possible Save Creation Exploit....
« Reply #9 on: June 03, 2006, 12:57:00 PM »

not to burst anyones bubble, but it shoudl be noted the signature used for saves is not the same as the signature used for xbes/xexs, so any progress here is limited to gamesaves, and not homebrew

second, gamesave signing isnt that big of a deal IMO, sure this may be the first instace of it on 360, but look at xbox-saves.com, theres lots of re-signers for xbox1 saves, so its clear this sort of thing has been done before

personally i would like to see if you can make a hacked profile to get loaded (like the h2 ones people use for no-releoad and such)
Logged

Cookiesrus

  • Archived User
  • Full Member
  • *
  • Posts: 106
Possible Save Creation Exploit....
« Reply #10 on: June 03, 2006, 01:36:00 PM »

QUOTE(lordvader129 @ Jun 3 2006, 08:04 PM) View Post

not to burst anyones bubble, but it shoudl be noted the signature used for saves is not the same as the signature used for xbes/xexs, so any progress here is limited to gamesaves, and not homebrew

second, gamesave signing isnt that big of a deal IMO, sure this may be the first instace of it on 360, but look at xbox-saves.com, theres lots of re-signers for xbox1 saves, so its clear this sort of thing has been done before

personally i would like to see if you can make a hacked profile to get loaded (like the h2 ones people use for no-releoad and such)



I made a few simple mods to graw, such as removing the recoil for weapons and such, but not really looked into making a hacked profile.  If there is a game with a generic file included both on the disc AND in teh save file, and of course was editable in a way that was usefull, then getting it into the save file wouldnt be a problem.

I realise that this isnt going to get us homebrew... I am sorry if it some how sounded that way, it didnt sound that way to me or i would have worded it different.  I asumed everyone would realise this would only be save game and maybe at a push a way of editing your gamerpic.
Logged

pHeelixx

  • Archived User
  • Newbie
  • *
  • Posts: 27
Possible Save Creation Exploit....
« Reply #11 on: June 12, 2006, 09:49:00 PM »

maybe this is just a neat trick or a way into some nice gamesave mods but it's always good to see some real original thinking for the betterment of the scene keep playing with it and who knows what we can get I wish I could help but no 360 untill we get a hack or I turn down the ps3 till then I'll be messing with psp kudos beerchug.gif
Logged