xboxscene.org forums

Pages: 1 2 3 [4]

Author Topic: Idea For Softmod Exploit?  (Read 446 times)

Ozy

  • Archived User
  • Hero Member
  • *
  • Posts: 1436
Idea For Softmod Exploit?
« Reply #45 on: November 02, 2006, 02:13:00 PM »

QUOTE(Textbook @ Jul 4 2006, 06:33 PM) View Post

Here are my $.02

Can we play Xbox 1 backups on the Xbox 360?  Yes, I wrote one of the first tutorials to do so, you can find it in the backup FAQ.  Can we inject modified data files into the image before burning, and will it work?  Theoretically, yes.  The only thing signed on Xbox 1 discs are XBE files.  Almost all data files are unsigned.  we can modify...say...a Halo 2 map, fix the encryption...then inject it into the image and it will most likely work.  I haven't tried this yet, but everything logically says "you can play modded Halo 2 maps on the Xbox 360 using the firmware hack".  Go on Live and have fun with being permanently banned though.  Anyways... where does this get us?  Nowhere for right now.  The only files that we can load any homebrew from are XBE files.  It just so happens that we cannot modify these files in any way, because they are signed.  It is possible that somebody may find an exploit in a certain Xbox 1 game's unsigned data files.  This, coupled with the firmware hacks, would get homebrew running at least through the backwards compatibility emulator.  The only problem we face is finding this Xbox 1 game data file exploit.  And before you ask, no none of the Xbox 1 exploits using 007, Mechassault, or Splinter Cell will work.  These relied on buffer overflows.  The Xbox 360 is nearly impervious to buffer overflows.  For now, we wait until somebody can find an exploitable data file in an Xbox 1 game (on the backwards compatiblity list).


So just finding them, then. What about one of the 100 OXM demo disc, you you think that one would work?
Should we try every disc?

The key to any softmod exploit here has got to be in the emulator.
We should try some of the xbox release games; Amped, something-something racing etc. that my not have all their XBEs signed (after all it was a long time before the xbox was hacked). Or trying something stupid like the Halo map pack or a second rate game like rayman.

Another thing to try would be splinter cells, maps ond xbes or even unreal tornamanet.

Those are the only ones I can thinks of right now.
Logged

stowelly

  • Archived User
  • Jr. Member
  • *
  • Posts: 75
Idea For Softmod Exploit?
« Reply #46 on: November 09, 2006, 03:30:00 AM »

QUOTE(Gecko Slayer @ Nov 9 2006, 06:06 AM) View Post

Sorry, I havne't read all 4 pages and this probably was explained soemwhere else.

Injecting an executable into a non-executable file will not help!

That's like putting an exe file into a jpg file and running the jpg file in paint!  It simply wont work!  In order for anything to load, it has to be EXECUTED, not READ.

Anyway, there goes me.



the point of a bufferflow is that the program is expecting a "file" or "buffer" of a certain size.... if its larger than that size it overflows onto the return address which can be replaced with your own code

not saying it will work int his situation i feel the hypervisor will cut that shit straight out
Logged

xbox7887

  • Archived User
  • Newbie
  • *
  • Posts: 15
Idea For Softmod Exploit?
« Reply #47 on: November 09, 2006, 09:37:00 AM »

I'm not quite sure of what use this will be, but here are some interesting links below dealing with hypervisor exploitation (Blue Pill) as well as a pretty ingenious way of modifying vista kernel contents by paging them to the hard drive first, definitely worth reading....

blue pill concept - http://invisiblethings.org/index.html (click on the recent blog post at the top)

kernel exploit presentation - http://invisiblethin.....ta kernel.ppt
Logged

roofus

  • Archived User
  • Jr. Member
  • *
  • Posts: 90
Idea For Softmod Exploit?
« Reply #48 on: November 10, 2006, 08:31:00 PM »

Eh, completely useless towards the 360 - the Xbox 360 uses STFS for all file storage, including cache file storage - and there is no paged memory on disk.
Logged

xbox7887

  • Archived User
  • Newbie
  • *
  • Posts: 15
Idea For Softmod Exploit?
« Reply #49 on: November 11, 2006, 10:29:00 AM »

Oh well, I still found it pretty interesting nonetheless tongue.gif
Logged

jameswalter

  • Archived User
  • Hero Member
  • *
  • Posts: 745
Idea For Softmod Exploit?
« Reply #50 on: November 11, 2006, 07:21:00 PM »

QUOTE(Gecko Slayer @ Nov 8 2006, 10:06 PM) View Post

Sorry, I havne't read all 4 pages and this probably was explained soemwhere else.

Injecting an executable into a non-executable file will not help!

That's like putting an exe file into a jpg file and running the jpg file in paint!  It simply wont work!  In order for anything to load, it has to be EXECUTED, not READ.

Anyway, there goes me.


Sure it will....this is how all exploits work....the xbox game save is read not executed, the first PSP exploit was an image file exploit....the code overflows the stack, and points to an executable, not is an executable.
Logged

dutch nelson

  • Archived User
  • Jr. Member
  • *
  • Posts: 64
Idea For Softmod Exploit?
« Reply #51 on: November 27, 2006, 02:06:00 PM »

Glad not everybody on this forum just wants to play back-ups,

I want homebrew apps!  laugh.gif



But the homebrew scene for the 360 is very dead sadly  sad.gif
Logged
Pages: 1 2 3 [4]