xboxscene.org forums

Author Topic: Idea For Possible Method Of Attack  (Read 99 times)

Textbook

  • Archived User
  • Hero Member
  • *
  • Posts: 1203
Idea For Possible Method Of Attack
« on: July 05, 2006, 11:23:00 AM »

Ok, I was doing some thinking last night when I came up with this possible method of attack on the Xbox 360 in hopes of running homebrew on it.  Please don't make flame posts, I would like an intelligent discussion, as I belive this may get somewhere if some smart people look into it.

Right now with the Xbox 360 we have a couple things working for us.  The firmware hacks allow us to boot raw dumps of Xbox 360 games as well as Xbox 1 games (raw dumps).  Almost all the files on an Xbox 360 disc are encrypted/signed, meaning we cannot change these.  But, with Xbox 1 games, the only files that seem to be encrypted/signed are XBE files.  Many of the data files can be modified or replaced and the game still boots and will in fact use this modified content.  (Modified maps for example)

The only problem with Xbox 1 games is we are limited to what is on the backwards compatiblity list.  Well, it just so happens that there is a game called Halo 2, which works on the Xbox 360 just fine.  Bungie came out with a "maptacular disc" which updated the game with more balanced weapons and 9 new multiplayer maps.  Fortunately for us, this also works on the Xbox 360.

What is interesting about this update is what can be observed on the Xbox 1.  Halo 2 can actually load the update and use it perfectly fine, even if the update (default.xbe) isn't signed.

For example, take a brand new Xbox, play Halo 2 (1.0) on it and then mod your Xbox.  Use a certain "leaked" Halo 2 Maptacular application which is basically just a ripped version of the official Bungie Maptacular update disc.  Since it is ripped, all signatures were broken.  But, if you run this ripped/leaked maptacular application, it will install the update and new maps.  Now, disable/uninstall your Xbox mod so that it is completely retail.  Boot up Halo 2 and you will notice that is running 1.1.  In other words, Halo 2 has loaded an unsigned XBE that was copied to the hard drive.

I would like to know personally if this is really what is happening or what is actually going on.

Now, how can this be useful?  Well, it leaves the possibility that we can make a rip of the official Bungie Maptacular disc, replace the update "default.xbe" with an unsigned xbe that will load when we insert Halo 2.

It's not really easy and I haven't found anything yet.  I really don't know anything about where to begin with something like this, or maybe something has been tried and I just missed it.  I have already tried replacing the update "default.xbe" with Avalaunch's "default.xbe" and Halo 2 just says "Content that you have downloaded and will not work, please redownload it."

I would imagine there is something special about the xbe but I don't know where to begin with decompiling or anything like that.  I just thought I would throw out this idea and let pedrospad or angerwound have a go at it.

I'm just trying to throw ideas out there in hopes of getting homebrew on the Xbox 360.
Logged

No_Name

  • Archived User
  • Hero Member
  • *
  • Posts: 562
Idea For Possible Method Of Attack
« Reply #1 on: July 05, 2006, 11:32:00 AM »

The Xbe is still signed or it would not run.

It just was not media signed.
Logged

Textbook

  • Archived User
  • Hero Member
  • *
  • Posts: 1203
Idea For Possible Method Of Attack
« Reply #2 on: July 05, 2006, 11:42:00 AM »

Oh, poop.  That really throws a monkey wrench into the whole thing, doesn't it?  So really that doesn't get us anywhere.  I wondered how it was still working.  I knew it had been thought of before, but I couldn't find it with the lousy search.  Thanks for telling me why it was working, that never even crossed my mind.
Logged

lordvader129

  • Archived User
  • Hero Member
  • *
  • Posts: 5860
Idea For Possible Method Of Attack
« Reply #3 on: July 05, 2006, 11:43:00 AM »

right, the xbe is still signed, the media check is still set for HD, the only thing the ripped pack does is sign your eeprom to it, which is essentially what the official disc did too, so its not really that much of a "hack"

xbox-saves.com has had gamesave re-signers for a long time, this is more of a "hack" but still nothign all that useful

Logged

jtom617

  • Archived User
  • Sr. Member
  • *
  • Posts: 322
Idea For Possible Method Of Attack
« Reply #4 on: July 05, 2006, 01:46:00 PM »

QUOTE(Textbook @ Jul 5 2006, 06:13 PM) *

Oh, poop.  That really throws a monkey wrench into the whole thing, doesn't it?  So really that doesn't get us anywhere.  I wondered how it was still working.  I knew it had been thought of before, but I couldn't find it with the lousy search.  Thanks for telling me why it was working, that never even crossed my mind.

dang, i was drewling in the first post of this topic  (IMG:style_emoticons/default/biggrin.gif) Until the 2nd one (IMG:style_emoticons/default/sad.gif) Good idea though, i would of thought the same thing.  (IMG:style_emoticons/default/pop.gif)
Logged

Fraudster

  • Archived User
  • Newbie
  • *
  • Posts: 23
Idea For Possible Method Of Attack
« Reply #5 on: July 12, 2006, 11:43:00 AM »

Can't knock a man for trying.

Nice Thought Though. - Its things like this which drive the whole scene forward.

Regards

Fraudster
Logged