xboxscene.org forums

Xbox360 Forums => Xbox 360 Hacking Forums => Technical DVD-ROM and Modified DVD Firmware Forum => Topic started by: Xbox-Scene on March 15, 2011, 06:28:00 PM

Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: Xbox-Scene on March 15, 2011, 06:28:00 PM
C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 12625
Posted by XanTium | March 15 20:28 EST | News Category: Xbox360
 
Updates from C4Eva on #FW@EFnet (via c4evaspeaks.com):
Quote

[c4eva] final portion of slim lt code a success!fw stealth implemented via rootkit technology! 12625 dash booting fine!

[c4eva] slim console will do realtime checks of fw!
[c4eva] hence rootkit used on slim lt !




Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: alan_poh on March 15, 2011, 07:31:00 PM
soooo...the wait is finally at the end  biggrin.gif

thank you c4eva  smile.gif
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: Ranger72 on March 15, 2011, 07:43:00 PM
This must mean the USB Pro will be shipping soon...... O wait lol


Great news and awesome work as aways.  pop.gif  pop.gif
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: syntaxerror329 on March 15, 2011, 08:14:00 PM
Wow, very exciting news.

For those of you that don't understand what the significance of Rootkit is there is a decent wiki on it.

http://en.wikipedia.org/wiki/Rootkit

Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: jacker300 on March 15, 2011, 08:41:00 PM
So will this let us flash/hack our slim consoles. Sorry I don't know much about the Xbox scene. Also would I need a USB pro thing or no? Someone please reply and help me with this. Thanks!  smile.gif
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: Kisszoke on March 15, 2011, 08:44:00 PM
Hi!


I'm not a brilliant computer hacker so forgive my stupid? question: If we can make hacking on the level of xbox kernel, are we able may hack the dashboard? so delete or use a older dashboard? Or this post means other thing? sorry for my un - trained post
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: K3thunder on March 15, 2011, 08:47:00 PM
Finally! C4, you have proven the best way to utilize root privileges on the Xbox 360 DVD drive.


You're becoming my favorite out of the #'s


Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: Hoescout on March 15, 2011, 09:05:00 PM
So does this mean that by using a rootkit we would need to install sort of a chip in the dvd drive or something like that?

Thats what I understood after checking the Wiki.

Correct me if Im wrong guys.
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: syntaxerror329 on March 15, 2011, 09:47:00 PM
QUOTE(jacker300 @ Mar 15 2011, 09:41 PM) *

So will this let us flash/hack our slim consoles. Sorry I don't know much about the Xbox scene. Also would I need a USB pro thing or no? Someone please reply and help me with this. Thanks!  smile.gif


Yes this is for 360 Slim with Lite-on. It is very probable that the tools we already have to hack old 360 drives is all we will need. Just wait and see i guess.

QUOTE(Kisszoke @ Mar 15 2011, 09:44 PM) *

Hi!
I'm not a brilliant computer hacker so forgive my stupid? question: If we can make hacking on the level of xbox kernel, are we able may hack the dashboard? so delete or use a older dashboard? Or this post means other thing? sorry for my un - trained post


This hack is for the DVD drive so your post does not belong in this topic. But sure if we had a dashboard hack for the new dash we could do something like the jtag hack i guess.

QUOTE(Hoescout @ Mar 15 2011, 10:05 PM) *

So does this mean that by using a rootkit we would need to install sort of a chip in the dvd drive or something like that?

Thats what I understood after checking the Wiki.

Correct me if Im wrong guys.


From the wiki "A rootkit is software" so my understanding is he does this all from the drive firmware he made.
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: Wompa164 on March 15, 2011, 10:17:00 PM
Wow, sounds like pretty big news. Seems like kind of a risky announcement unless he's confident in this being a sustainable exploitable for future dashboards to come.
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: xmstree on March 15, 2011, 11:00:00 PM
Writing an undetectable rootkit for a piece of firmware that is actively trying to detect modifications and has been in development for many years is a pretty difficult task. I doubt the people complaining "why is it taking so long" fully appreciate just how difficult it is, but full credit to c4eva for accomplishing this.

It remains to be seen however if it is truly undetectable, I'd be willing to bet a system update is able to detect it at some point in the future.

Regardless, I think AP2.5 will pretty much bring an end to playing backups. Everytime there is a system update people will need to re-burn all their discs with new challenges. For me it's not an issue, as I only play one game a month for a couple days - but for people with large libraries, be prepared to do a lot of re-burning. Perhaps rewritable DVDs are the way of the future.
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: majinsoftware on March 15, 2011, 11:52:00 PM
QUOTE(xmstree @ Mar 16 2011, 07:00 AM) *

Regardless, I think AP2.5 will pretty much bring an end to playing backups. Everytime there is a system update people will need to re-burn all their discs with new challenges. For me it's not an issue, as I only play one game a month for a couple days - but for people with large libraries, be prepared to do a lot of re-burning. Perhaps rewritable DVDs are the way of the future.



Theres only some games they can add it to, And there will also be a limit of how many games it can be enabled on at a time since its taking up nand space.

AP2.5 is a failed attempt to stop backups unless they find the way that the challenges are getting ripped from the disk and block it that way but then you still have the old drives that dont support it or a firmware can be made but it wont be live safe.
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: flames_88 on March 16, 2011, 12:39:00 AM
Awesome news, can't wait to flash my slim. Dont really care about live.

I know this might be off topic but its related to hardware somehow. If i have a hacked 250 gig hard drive in my 4gb slim, can i get banned for using "non xbox certified" hardware?
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: majinsoftware on March 16, 2011, 12:43:00 AM
QUOTE(flames_88 @ Mar 16 2011, 08:39 AM) *

Awesome news, can't wait to flash my slim. Dont really care about live.

I know this might be off topic but its related to hardware somehow. If i have a hacked 250 gig hard drive in my 4gb slim, can i get banned for using "non xbox certified" hardware?



You can get banned for using it on a phat xbox so I guess slim would be the same. Its just a risk you take.
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: tomgreen99200 on March 16, 2011, 01:26:00 AM
C4Eva is such a bad ass.  cool.gif
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: Darkflame on March 16, 2011, 02:47:00 AM
I wish I was able to see the thought process he has when he tackles a problem cause he's on it and produces nothing but quality results. Thanks C for what you do. Im grateful to be alive in an era with so much ingenuity.
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: alanewake on March 16, 2011, 03:00:00 AM
Thank you so much C4eva...you're the best...
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: fragger on March 16, 2011, 03:40:00 AM
[2011-03-15 09:23PM UTC] #360news <FiB3R> no doubt this will fall on deaf ears, butÂ… c4eva, you got any views on the build quality/performance of the different slim drives?
[2011-03-15 09:24PM UTC] #360news <c4eva> cheap



lol
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: xmstree on March 16, 2011, 04:38:00 AM
QUOTE(majinsoftware @ Mar 16 2011, 06:52 AM) *

Theres only some games they can add it to, And there will also be a limit of how many games it can be enabled on at a time since its taking up nand space.

AP2.5 is a failed attempt to stop backups unless they find the way that the challenges are getting ripped from the disk and block it that way but then you still have the old drives that dont support it or a firmware can be made but it wont be live safe.


It takes up negligible space, and they can always rotate the games through every few months, even if it's just the popular games. I don't see why they can't simply include an encrypted challenge table on each disc anyway, without taking up nand space. I predict they will increase the challenges used at least every 6 months. This will require reburning/re-buying your games every few months. That will get old pretty quick.

They have enough challenge slots to do this for 20 years+, and they can always increase it.

You cannot use old drives/firmware as the latest dash knows which drive you should have and will block anything else.

I don't think they will be able to block the AP2.5 extraction, as they are simply intercepting the challenge/response. However, they can make the challenges occur at 1hr, 2hr, 3hr, .... 6hr etc so that they become impractical to extract. It is already very time consuming to extract, it will become even more difficult to extract as more challenges are added.

AP2.5 may seem defeated at the moment, but believe me it is a difficult protection, and this will become apparent over the next year or two.

This post has been edited by xmstree: Mar 16 2011, 12:14 PM
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: Exobex on March 16, 2011, 05:06:00 AM
QUOTE(majinsoftware @ Mar 16 2011, 06:43 AM) *

You can get banned for using it on a phat xbox so I guess slim would be the same. Its just a risk you take.

[citation needed]
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: Takashi on March 16, 2011, 05:38:00 AM
Haven't heard of even one instance of that.
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: itoktoeatfish on March 16, 2011, 10:20:00 AM
QUOTE(Takashi @ Mar 16 2011, 01:38 PM) *

Haven't heard of even one instance of that.


People keep saying that you can get banned but I have never heard of it really happening. Im 90% sure those cheap hdds they sell on ebay from china are "spoofed".
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: robo989 on March 16, 2011, 01:00:00 PM
QUOTE(majinsoftware @ Mar 16 2011, 07:43 AM) *

You can get banned for using it on a phat xbox so I guess slim would be the same. Its just a risk you take.



Bull.....Shit. (IMG:style_emoticons/default/smile.gif)

Not one report of a ban in the 3-4 years people have been doing this.
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: danthaman673 on March 16, 2011, 01:40:00 PM
QUOTE(xmstree @ Mar 16 2011, 08:08 PM) *

It takes up negligible space, and they can always rotate the games through every few months, even if it's just the popular games. I don't see why they can't simply include an encrypted challenge table on each disc anyway, without taking up nand space. I predict they will increase the challenges used at least every 6 months. This will require reburning/re-buying your games every few months. That will get old pretty quick.

They have enough challenge slots to do this for 20 years+, and they can always increase it.

You cannot use old drives/firmware as the latest dash knows which drive you should have and will block anything else.

I don't think they will be able to block the AP2.5 extraction, as they are simply intercepting the challenge/response. However, they can make the challenges occur at 1hr, 2hr, 3hr, .... 6hr etc so that they become impractical to extract. It is already very time consuming to extract, it will become even more difficult to extract as more challenges are added.

AP2.5 may seem defeated at the moment, but believe me it is a difficult protection, and this will become apparent over the next year or two.

Yes, that's the bad news as suspected some time ago.... To extract/intercept the challenge under such hostile conditions would need something like a 'rootkit' style exploit, I bet it's a SW solution that accomplishes what I had previously predicted we would need. And it all becomes clear now ;-) Good 4 u going for the (free) SW/FW  approach. I'm guessing this will also mean that we will either be able to extract our own AP2.5 or wont need to anymore ...

OIf course I will look super-silly now if it turns-out to be a HW solution coming to a store near you :-)


At any rate: Bravo sir, Bravo!

This post has been edited by danthaman673: Mar 16 2011, 08:41 PM
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: Martinchris23 on March 16, 2011, 02:05:00 PM
QUOTE(robo989 @ Mar 16 2011, 07:00 PM) *

Bull.....Shit. (IMG:style_emoticons/default/smile.gif)

Not one report of a ban in the 3-4 years people have been doing this.


MS can ban your console if they detect it using non-approved accessories. Read the ToS. It doesn't have to happen to be true. Don't get 'can' and 'will' confused.

Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: alwaysonjohn on March 16, 2011, 04:55:00 PM
BACK ON TOPIC:
This is amazing news that c4e has used a rootkit to let his hack run undetected...  wow!
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: Harbinger076 on March 16, 2011, 08:31:00 PM
QUOTE(alwaysonjohn @ Mar 16 2011, 05:55 PM) *

BACK ON TOPIC:
This is amazing news that c4e has used a rootkit to let his hack run undetected...  wow!



i personally dont give a crap about being banned if c4eva wants a tester send it to me al i want is to be able to boot backups on my worthless SLIM i play on my jtag offline more then the slim which has never been used other then a damn dvd player..  i appericate all the work he and anyone helping him has done but honestly i could do without any teasing updates until its released..  im about to dump my key and put a phat drive hooked up to it at this point regardless of consequences..
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: ravendrow on March 16, 2011, 09:20:00 PM
awesome work cant wait to see it finished. my only concern would be if m$ somehow found a way to detect it could they therefore brick the drive and say it was an attempt to remove malware from the console ?
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: DaShiZNiT on March 16, 2011, 11:06:00 PM
QUOTE(Harbinger076 @ Mar 16 2011, 09:31 PM) *

i personally dont give a crap about being banned if c4eva wants a tester send it to me al i want is to be able to boot backups on my worthless SLIM i play on my jtag offline more then the slim which has never been used other then a damn dvd player..  i appericate all the work he and anyone helping him has done but honestly i could do without any teasing updates until its released..  im about to dump my key and put a phat drive hooked up to it at this point regardless of consequences..


Your "slim" is "worthless" because it will not play backups? LOL try playing the originals?
Title: C4Eva: LiteOn Slim 9504 W.I.P. - 'RootKit' Implemented to boot on 1262
Post by: robo989 on March 17, 2011, 10:26:00 AM
QUOTE(DaShiZNiT @ Mar 17 2011, 06:06 AM) *

Your "slim" is "worthless" because it will not play backups? LOL try playing the originals?


...Originals? What are they  jester.gif  ^  sleep.gif