xboxscene.org forums

Pages: [1] 2 3 ... 5

Author Topic: Font Exploit Analysis  (Read 487 times)

sega27

  • Archived User
  • Jr. Member
  • *
  • Posts: 73
Font Exploit Analysis
« on: January 29, 2004, 10:27:00 AM »

With all the data you have gathered from the diffrent fonts, which one would u say is the best.. small size and least problems.
Logged

Grospolina

  • Archived User
  • Full Member
  • *
  • Posts: 182
Font Exploit Analysis
« Reply #1 on: January 29, 2004, 11:55:00 AM »

Size isn't really an issue.  I only mentioned that as a difference between the fonts.

For now, I'd go with the hacked MechInstaller fonts (which are not mentioned above, because it hasn't ben updated).  However, I've been using them and I still get the clock loop.

The ones I'm using are the hacked MI ones posted by catfish.  Are there any other versions?  Those were the only ones I've seen, but I have a feeling there might be others.

One interesting thing I found was that when I was looping with catfish's fonts (I couldn't get out after several tries), I plugged in my old hard drive, which still had the "official" MechInstaller fonts, and it got out almost right away (2-3 reboots).  That's why I think there may be other versions.

I'd say the next best are Reloaded.

Right now, I'm trying a blended version of Reloaded and BigFonts that I've hacked up.  I'll try unplugging my Xbox every night for a week and see how they fare.
Logged

sega27

  • Archived User
  • Jr. Member
  • *
  • Posts: 73
Font Exploit Analysis
« Reply #2 on: January 29, 2004, 07:45:00 PM »

can you clarify on how to get out off the clock loop? Im using the reloaded fonts.
Logged

PedrosPad

  • Archived User
  • Hero Member
  • *
  • Posts: 1277
Font Exploit Analysis
« Reply #3 on: January 30, 2004, 05:16:00 AM »

For those that are interested, the presentations the Xbox-Linux Team did at 20C3 on 28 December 2003 are now available online (in .PDF format) and the software presentation carries a reasonable amount of technical details on all the software exploits, inc. the font one.

Xbox Hardware Hacking (14MB) (105 slides)
Xbox Software Hacking (6MB) (92 slides)
Logged

Nailed

  • Archived User
  • Sr. Member
  • *
  • Posts: 251
Font Exploit Analysis
« Reply #4 on: January 31, 2004, 05:25:00 AM »

Very informative post... this one should definitely be pinned.   Thanks for the detailed analysis, Grospolina... looking forward to seeing more on the MechInstaller fonts.
Logged

feilox

  • Archived User
  • Newbie
  • *
  • Posts: 1
Font Exploit Analysis
« Reply #5 on: January 31, 2004, 05:42:00 PM »

ok, i'm a n00b, but wat's all this font exploit supposed to do?...i know it's a buffer overun code, but what does it do? does is fool the xbox into thinking that it has a cd? bios?....i need some info
Logged

motox333

  • Archived User
  • Newbie
  • *
  • Posts: 43
Font Exploit Analysis
« Reply #6 on: January 31, 2004, 06:32:00 PM »

The font exploit loads Phoenix Bios Loader, which puts a different BIOS on the XBOX, and then it lets you run unsigned code. Once you turn it off, the new BIOS goes away and needs to be loaded again the next time you turn it on. That is what PBL does for you.
Logged

BluhDeBluh

  • Archived User
  • Full Member
  • *
  • Posts: 135
Font Exploit Analysis
« Reply #7 on: February 01, 2004, 07:33:00 AM »

smile.gif Very educational. Keep trying and I wish that you have success smile.gif
Logged

Chicken Scratch Boy

  • Archived User
  • Hero Member
  • *
  • Posts: 1054
Font Exploit Analysis
« Reply #8 on: February 01, 2004, 08:34:00 AM »

QUOTE (feilox @ Jan 31 2004, 07:42 PM)
ok, i'm a n00b, but wat's all this font exploit supposed to do?...i know it's a buffer overun code, but what does it do? does is fool the xbox into thinking that it has a cd? bios?....i need some info

it does a buffer overrun thatover writes the memory block that stores the ms public key with one of our own, so wel can sign freely
Logged

Mad_Gouki

  • Archived User
  • Sr. Member
  • *
  • Posts: 310
Font Exploit Analysis
« Reply #9 on: February 01, 2004, 09:51:00 AM »

QUOTE (Grospolina @ Jan 30 2004, 05:06 PM)
sega27:

You can try any or all of these:

1. Plug in a network cable.  Have the other end connected to your PC or a router.
2. Put in an audio CD.
3. Put in a scratched CD.
4. Play with the eject button.  Open it or close it when the MS logo appears under the big X.
5. Turn it off and on a few times.
6. Just wait.  It may take minutes or hours.

After you get out, be sure to set your clock (EvoX can automatically do it from a time server if you're connected to the net).

also i heard from someone taht if you turn it on by holding the eject button an dkeep holding it it will boot to evox like every time... well when i had a clock loop yesterday from bringing my xbox to my moms, i did that and it worked great...

btw, thats awesome that you are learning about the fonts biggrin.gif
i knew vageuly how they worked but you have clarified a lot of stuff
Logged

oblox

  • Archived User
  • Sr. Member
  • *
  • Posts: 414
Font Exploit Analysis
« Reply #10 on: February 11, 2004, 07:39:00 AM »

I just wanted to say my xbox kept on acting really screwy like black scrren red light rebbot ask for time... alot until I gor rid of xodash (the 2.0 version)

Notes I had a mixture of live 2.0 and the exploit dash and was using the audio hack at the time...
Logged

oblox

  • Archived User
  • Sr. Member
  • *
  • Posts: 414
Font Exploit Analysis
« Reply #11 on: February 28, 2004, 09:00:00 AM »

rotfl.gif
Logged

oblox

  • Archived User
  • Sr. Member
  • *
  • Posts: 414
Font Exploit Analysis
« Reply #12 on: February 29, 2004, 08:47:00 AM »

QUOTE
For all thise who would like to know
I tested the 5530 kernal on debug PBL
It goes through all the keys from the boot.cfg
Goes
Calculating 2bl entry point
Calling 2bl
And hangs


From this thread
http://forums.xbox-s...ic=175051&st=45

So yeah looks like some sort of call is going wrong
Logged

Chicken Scratch Boy

  • Archived User
  • Hero Member
  • *
  • Posts: 1054
Font Exploit Analysis
« Reply #13 on: February 29, 2004, 08:51:00 AM »

we are SUCH dummies! it probly stores the bios in a differnt set of memory blocks.. wait then what about modifying the mpublic key....
Logged

oblox

  • Archived User
  • Sr. Member
  • *
  • Posts: 414
Font Exploit Analysis
« Reply #14 on: February 29, 2004, 11:40:00 AM »

QUOTE (Chicken Scratch Boy @ Feb 29 2004, 06:51 PM)
we are SUCH dummies! it probly stores the bios in a differnt set of memory blocks.. wait then what about modifying the mpublic key....

what about if it's only initaly storing the bios in another set of blocks and its messing up then it goes to call it so it can inject it/replace the original one in memory?
Logged
Pages: [1] 2 3 ... 5