xboxscene.org forums

Pages: 1 2 [3]

Author Topic: Slim Stock Fw 0272?  (Read 289 times)

moh.sakhaii

  • Archived User
  • Jr. Member
  • *
  • Posts: 86
Slim Stock Fw 0272?
« Reply #30 on: April 11, 2011, 03:41:00 AM »

QUOTE(xfxgames @ Apr 11 2011, 06:37 AM) *

could have a way to update the firmware does not have to open the console, why? become routine! all the time will have to open the console to change the firmware, get the original and put the hacked total discomfort. everyone. I think the solution would be to flash the drive by the usb console would become easier and faster. with the information we have everything on the Internet become easier and faster,  sort by flashing stick.

haha, you are high brother (IMG:style_emoticons/default/biggrin.gif) lol  You can not change anything in an update, if you do it will be useless, because updates are signed by Microsoft, if we had the private key for signing the update files we would have simply create a custom firmware like what people did for the PS3, but no 360 remained secure in this regard, so no way.
Logged

KaISeR SoZEi

  • Archived User
  • Newbie
  • *
  • Posts: 20
Slim Stock Fw 0272?
« Reply #31 on: April 11, 2011, 08:52:00 AM »

The BIGGEST problem is the lost of the key for CFW flashed consoles...

The good thing is microsoft included in this update all necessary routines for flashing Liteon/benq easily, we just have to apply it in a PC based program and we will have an easy way to flash our drives (IMG:style_emoticons/default/smile.gif)


So I hope the problem with CFW based console is a bug from the beta and will be changed in the final ( I prefer to have a machine flashed with OFW than bricked.. )

This post has been edited by KaISeR SoZEi: Apr 11 2011, 03:52 PM
Logged

juggahax0r

  • Archived User
  • Hero Member
  • *
  • Posts: 602
Slim Stock Fw 0272?
« Reply #32 on: April 11, 2011, 12:04:00 PM »

Yea their is another thread dedicated to "official" information on the drive flashing that is going on. I already posted 3 different times which files are doing the flash it's oddupd1 oddupd2 and oddupd3. Optical Disc Drive , pretty easy to deduce that.


 You can't upload shit like that here BTW , a mod will just delete your link. I'm also not going to download a random file to see what it is, that's how you get viruses. We can all use Xextool to get the FW files if we want too , it's in the system update.
Logged

moh.sakhaii

  • Archived User
  • Jr. Member
  • *
  • Posts: 86
Slim Stock Fw 0272?
« Reply #33 on: April 11, 2011, 12:10:00 PM »

QUOTE(juggahax0r @ Apr 11 2011, 09:34 PM) *

Yea their is another thread dedicated to "official" information on the drive flashing that is going on. I already posted 3 different times which files are doing the flash it's oddupd1 oddupd2 and oddupd3. Optical Disc Drive , pretty easy to deduce that.
 You can't upload shit like that here BTW , a mod will just delete your link. I'm also not going to download a random file to see what it is, that's how you get viruses. We can all use Xextool to get the FW files if we want too , it's in the system update.

Sorry to ask such a noob question (IMG:style_emoticons/default/biggrin.gif) but are these files that you extract with xextool encrypted or not? I do not know much about xbox360 security, but it makes sense that these files should be  encrypted ?? (IMG:style_emoticons/default/tongue.gif)
Logged

juggahax0r

  • Archived User
  • Hero Member
  • *
  • Posts: 602
Slim Stock Fw 0272?
« Reply #34 on: April 11, 2011, 12:15:00 PM »

QUOTE(moh.sakhaii @ Apr 11 2011, 02:10 PM) *

Sorry to ask such a noob question (IMG:style_emoticons/default/biggrin.gif) but are these files that you extract with xextool encrypted or not? I do not know much about xbox360 security, but it makes sense that these files should be  encrypted ?? (IMG:style_emoticons/default/tongue.gif)



 The FW will disassemble on IDA i know that. The oddupd.xex's are in just the system update folder i believe, the FW file is a normal 256k FW , i would guess that it is blank seeing as how it wouldn't be able to have a DVD key yet , and so no it probably is not encrytped. I know it disassembles on IDA just fine.

xextool -r . oddupd.xex   - this will dump the FIRMWARE to the directory you are in with the oddupd ,and if you put xextool in your path you can just jump around all you want and use xextool in any directory.
Logged

moh.sakhaii

  • Archived User
  • Jr. Member
  • *
  • Posts: 86
Slim Stock Fw 0272?
« Reply #35 on: April 11, 2011, 12:20:00 PM »

QUOTE(juggahax0r @ Apr 11 2011, 09:45 PM) *

The FW will disassemble on IDA i know that. The oddupd.xex's are in just the system update folder i believe, the FW file is a normal 256k FW , i would guess that it is blank seeing as how it wouldn't be able to have a DVD key yet , and so no it probably is not encrytped. I know it disassembles on IDA just fine.

xextool -r . oddupd.xex   - this will dump the FIRMWARE to the directory you are in with the oddupd ,and if you put xextool in your path you can just jump around all you want and use xextool in any directory.

Thanks for the info wink.gif but I do not understand the shi**y security Microsoft has used here biggrin.gif they have given their precious system programs to others without any protection whatsoever laugh.gif
Logged

juggahax0r

  • Archived User
  • Hero Member
  • *
  • Posts: 602
Slim Stock Fw 0272?
« Reply #36 on: April 11, 2011, 12:49:00 PM »

QUOTE(moh.sakhaii @ Apr 11 2011, 02:20 PM) *

Thanks for the info wink.gif but I do not understand the shi**y security Microsoft has used here biggrin.gif they have given their precious system programs to others without any protection whatsoever laugh.gif


 Well the Xex itself is not a normal Xex , you can't do much with it in XeXtool , as it doesn't have a valid PE basefile (so it says) , it also reads as a system file AKA dll. The Firmware file itslef , i would speculate gets encrypted at some point during the update when it adds your DVD key to it etc ... SO I don't think it is necessary for them to try to make it impossible for use to disassemble it , their job is to assume we can and make it work regardless , kinda like the HV.
 
Felix made this point in his C3 talk on the HV bug , without looking at the video the basic quote was about how even if your secrets are known your security should still work. Obviously having the private key would make that statement moot , but that key isn't anywhere on the system to retrieve it , only a hash to compare and check for validity of the xex signatures etc ... And after updating the 2BL even if you know your CPU key , and have a disassembled HV/Kernel you still can't hack it, so even though the 1bl key is known and we will go ahead and pretend you also have the CPU key , you still can't break the security because of the HV , and the updates made in the 2bl.

 Sorry I didn't mean to take it that far off topic ... the point is still valid even when not discussing unsigned code , MS is going to assume their work can be disassembled , instead of assuming their encryption will stop anyone from seeing their code , they in turn make the code harder to exploit instead of making it harder to disassemble. Make Sense? Not saying they don't do both , Just saying they will have to assume at some point someone from the -scene- will reverse it , they need to make sure even when that happens they are still safe.
Logged

k0mpresd

  • Archived User
  • Sr. Member
  • *
  • Posts: 289
Slim Stock Fw 0272?
« Reply #37 on: April 11, 2011, 03:14:00 PM »

i tried to update my slim with the disc and it did not update. so i flashed it back to stock and it updated ok.
then i dumped the key again using slim key and slim unlock then reflashed with 9504 lt+.
console boots ok and drive plays backups.

0000: 05 80 00 32 5B 00 00 00 - 50 4C 44 53 20 20 20 20 ...2[...PLDS  
0010: 44 47 2D 31 36 44 34 53 - 20 20 20 20 20 20 20 20 DG-16D4S      
0020: 30 32 37 32 00 00 00 00 - 00 00 00 00 00 00 00 00 0272............
0030: 00 00 00 00 41 30 41 30 - 00 00 00 00 00 00 00 00 ....A0A0........
0040: 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0050: 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

it seems my drive was updated to 0272 but i was still able to use slim key to get the key and to unlock the drive. and i reflashed the drive no problem with lt+.

This post has been edited by k0mpresd: Apr 11 2011, 10:22 PM
Logged

john2185

  • Archived User
  • Jr. Member
  • *
  • Posts: 70
Slim Stock Fw 0272?
« Reply #38 on: April 11, 2011, 03:18:00 PM »

this has been been confirmed by xecuter and c4eva



It's confirmed by C4E himself BTW:

[2011-04-09 06:53AM UTC] <VGCrepair> that not possible unless the console is writting to the DVD drive
[2011-04-09 06:53AM UTC] <mib_2ikxl> yup i meant drive
[2011-04-09 06:53AM UTC] <c4eva> beta dash flashes drive!

So far it's confirmed for the slim drive 9504! The Phat ones are still in question and being tested...(04421C is the new fw for BenQ, 02510C for Phat LiteOn)
Oh and yeah you HAVE to keep your drive key saved before updating the dashboard or you'll lose access to your key! (Any Non-stock fw will have its key zeroed).
Another move from M$ I guess..
Edit: Not a security move though, apparently fw update is just to conform to the new XGD3 format... A new XGD3 CFW by C4E will probably follow.





heres the info source


http://team-xecuter.com/forums/showthread.php?t=63569
Logged

Ranger72

  • Archived User
  • Hero Member
  • *
  • Posts: 3746
Slim Stock Fw 0272?
« Reply #39 on: April 11, 2011, 04:05:00 PM »

QUOTE(k0mpresd @ Apr 11 2011, 05:14 PM) *

i tried to update my slim with the disc and it did not update. so i flashed it back to stock and it updated ok.
then i dumped the key again using slim key and slim unlock then reflashed with 9504 lt+.
console boots ok and drive plays backups.

0000: 05 80 00 32 5B 00 00 00 - 50 4C 44 53 20 20 20 20 ...2[...PLDS  
0010: 44 47 2D 31 36 44 34 53 - 20 20 20 20 20 20 20 20 DG-16D4S      
0020: 30 32 37 32 00 00 00 00 - 00 00 00 00 00 00 00 00 0272............
0030: 00 00 00 00 41 30 41 30 - 00 00 00 00 00 00 00 00 ....A0A0........
0040: 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0050: 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

it seems my drive was updated to 0272 but i was still able to use slim key to get the key and to unlock the drive. and i reflashed the drive no problem with lt+.



Yes I figured as such. Only issue will be that when the new disk style comes out you wont be able to play them without ether going back to the stock 272 firmware or wait until something new comes out from C4eva.
Logged

Yamthief

  • Archived User
  • Newbie
  • *
  • Posts: 23
Slim Stock Fw 0272?
« Reply #40 on: May 29, 2011, 09:44:00 AM »

QUOTE(k0mpresd @ Apr 11 2011, 09:14 PM) *

i tried to update my slim with the disc and it did not update. so i flashed it back to stock and it updated ok.
then i dumped the key again using slim key and slim unlock then reflashed with 9504 lt+.
console boots ok and drive plays backups.

0000: 05 80 00 32 5B 00 00 00 - 50 4C 44 53 20 20 20 20 ...2[...PLDS  
0010: 44 47 2D 31 36 44 34 53 - 20 20 20 20 20 20 20 20 DG-16D4S      
0020: 30 32 37 32 00 00 00 00 - 00 00 00 00 00 00 00 00 0272............
0030: 00 00 00 00 41 30 41 30 - 00 00 00 00 00 00 00 00 ....A0A0........
0040: 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................
0050: 00 00 00 00 00 00 00 00 - 00 00 00 00 00 00 00 00 ................

it seems my drive was updated to 0272 but i was still able to use slim key to get the key and to unlock the drive. and i reflashed the drive no problem with lt+.


So let me get this straight; did you spoof the 9504 LT+ 1.1 FW as "0272", with your usual drive key too, using hex editor?
And it boots all but upcoming disc waves? Boots AP2.5 Also?
Logged
Pages: 1 2 [3]