xboxscene.org forums

Pages: 1 [2]

Author Topic: Paper: 17 Mistakes Microsoft Made in the Xbox Security System  (Read 185 times)

melongstrike

  • Archived User
  • Sr. Member
  • *
  • Posts: 313
Paper: 17 Mistakes Microsoft Made in the Xbox Security System
« Reply #15 on: December 16, 2005, 09:25:00 AM »

QUOTE(d0pe @ Dec 16 2005, 10:35 AM) View Post

I'm more interested in the 360 mistakes M$ made. wink.gif



Precisely!
Logged

krayzie

  • Archived User
  • Hero Member
  • *
  • Posts: 3350
Paper: 17 Mistakes Microsoft Made in the Xbox Security System
« Reply #16 on: December 16, 2005, 09:36:00 AM »

QUOTE
As the next step, MS blacklisted the old Dashboard in the new kernel. It was impossible to just "dd" an old Dashboard image onto newer Xboxes.
Still no major problem for hackers: The second executable on the hard disk, "xonlinedash", which is used for Xbox Live configuration, had the same bug, so it was possible to copy the old "xonlinedash" and to rename it to "xboxdash" to make it crash because of the faulty fonts.
MS consequently blacklisted the vulnerable version of "xonlinedash".
Again, no major problem for hackers: All Xbox Live games come with the "dashupdate" application, which adds Xbox Live functionality to the Dashboard for the first Xboxes which came without it. This update application has the same font bug, and it can be run from hard disk. So it is possible to copy the file from any Xbox Live game DVD, rename it to "xboxdash" and let it crash.
MS could not blacklist this one. Xbox Live enabled games run the update application every time they start, making sure the Xbox has the Xbox Live functionality. Blacklisting "dashupdate" would break these games.


This part seems rather incomplete and not completely true...

First they forget to mention that the update.xbe exploit was the 2nd exploited dashboard file and the xonlinedash.xbe exploit was way later then that. MS blacklisted any dashboard or related executable in the 5713+ kernel and "all" xbox live games contents are useless for these kernels as they were all patched up. Renaming them to xboxdash.xbe would not cause a crash but an error screen. We had to find a specific version of the dash executable family that passed the new xbox's certificate check and still had the font bug. We found a special dahboard fitting in these criteria and that's what everyone is using now if they use a UXE or Ndure based softmod.
Also blacklisting a dashupdate like mentioned is not performed by MS and is useless as both exploits are well protected against dashupdates (either in retail state or virtual/modded state)
Logged

manguelo

  • Archived User
  • Newbie
  • *
  • Posts: 4
Paper: 17 Mistakes Microsoft Made in the Xbox Security System
« Reply #17 on: December 16, 2005, 10:39:00 AM »

cool.gif  I just want to say this:
THX M$ !!! because of you i have learned skills that i never imagined, and now i have a wonderful machine that is far away from the original concept of yours.

"Great Errors" hope to see them on the 360 ( not the same, but i'm sure others will surface...)

My System:

X2 Pro with 512Kb Bios
V 1.0 on a Crystal Special edition
Crystal Xbox Development Kit TOP
Dual HDD's ( 120GB and 80GB )
Blue LED´s on the ring
LAN LED, DVD LED and HDD LED indicators

PS:

Viva Mexico !!!
Logged

Perplexer

  • Recovered User
  • Hero Member
  • *
  • Posts: 1096
Paper: 17 Mistakes Microsoft Made in the Xbox Security System
« Reply #18 on: December 16, 2005, 11:04:00 AM »

An excellent read.  Thanks for the link!
Logged

OcnewB

  • Archived User
  • Full Member
  • *
  • Posts: 209
Paper: 17 Mistakes Microsoft Made in the Xbox Security System
« Reply #19 on: December 16, 2005, 02:29:00 PM »

QUOTE(ShyGuy91284 @ Dec 16 2005, 04:07 PM) View Post

Biggest mistake they made (not sure if it's listed)?  The LPC/whatever port all mod chips plug into.  Other then d0, that's the only thing that has to be touched on earlier X-Boxes, all in one simple place.  Had it not been so easy to mod, I probably wouldn't have gotten it (They lost money on me because I use it as a media center etc.  and don't buy games).


U better start reading the text becuz your post is pretty much useless.

The 1st modchips were based on 30+ wires and not even one or just one wire touched lpc points. It was way longer before the lpc points were used when new hacks and bugs were found.

They needed the LPC points to program some chip on the mainboard so they couldnt remove it. For that they had to redesign the complete board which was to expensive.
Only make it more difficult to utilize them hence the version 1.6(cool.gif xbox with some of the lpc points cutoff which have to be rebuild. They COULD not remove them.

Please read the complete article and skip the techincal stuff. It should be very interesting to read and not TO hard to follow.
Good luck man!
Logged

manguelo

  • Archived User
  • Newbie
  • *
  • Posts: 4
Paper: 17 Mistakes Microsoft Made in the Xbox Security System
« Reply #20 on: December 16, 2005, 02:35:00 PM »

d0pe:

You are ABSOLUTELY RIGHT, because without them maybe i would not have even an unmodified Xbox ( and that would be a shame...)

Thanks to those wonderful hackers... biggrin.gif
Logged

ksteiner

  • Archived User
  • Full Member
  • *
  • Posts: 188
Paper: 17 Mistakes Microsoft Made in the Xbox Security System
« Reply #21 on: December 16, 2005, 04:03:00 PM »

It will come
 it will come...
Logged

downlowfunk

  • Archived User
  • Jr. Member
  • *
  • Posts: 69
Paper: 17 Mistakes Microsoft Made in the Xbox Security System
« Reply #22 on: December 18, 2005, 06:51:00 PM »

Wow people are damned smart.    I feel stupid after reading that.   All I can say is the TSOP loaded with x2 4983.67 is a hell of a lot of fun.     Its going to be along time before we see this 360 get whacked. And when it does, it will be pointless because its so intensly live based.
Logged
Pages: 1 [2]