OK - make some changes to the xbe scanner.
 It's linux based so it includes a linux kernel. I could probably strip it down, but dont see the point in spending time on that for this purpose.
| QUOTE (ldots @ Jul 14 2004, 01:42 PM) | I could, and it wouldn't be risky. It's just that the package is too big to be posted here |
It's a 2MB RAR - Can anyone host this for ldots?
| QUOTE (ldots @ Jul 14 2004, 01:42 PM) | I could, and it wouldn't be risky. It's just that the package is too big to be posted here  It's linux based so it includes a linux kernel. I could probably strip it down, but dont see the point in spending time on that for this purpose. |
Assuming there is nothing made with the Xbox SDK (so it's legal), couldn't you just start a new Sourceforge project?
Another thing I've got to mention is the hard-disk drive limits that people have mentioned - does it matter what size each partition is? Couldn't you rebuild another HDD with different sized partitions (resulting in a larger C drive that you could fit more game data on)?
| QUOTE | | Edit: Hey! what da you know - deleting the MA demos "LiveDemo.mgf" get's you the load game options back |
I have another question based on this - would LiveDemo.mgf from MechAssault be exploitable?
| QUOTE (BluhDeBluh @ Jul 14 2004, 02:36 PM) | Assuming there is nothing made with the Xbox SDK (so it's legal), couldn't you just start a new Sourceforge project?
Another thing I've got to mention is the hard-disk drive limits that people have mentioned - does it matter what size each partition is? Couldn't you rebuild another HDD with different sized partitions (resulting in a larger C drive that you could fit more game data on)?
I have another question based on this - would LiveDemo.mgf from MechAssault be exploitable? |
The xbedump used is already on xbox-linux cvs, ldots may have written some shell scripts for that which doesn't honour a sourceforge project. Having the xbox-linux cvs to host it is an option but there may be more admin job than needed. may be better to just put them on the usual place.
For the HD limit, not everyone would buy a new larger HD so not practical.
| QUOTE (ldots @ Jul 14 2004, 01:42 PM) | I could, and it wouldn't be risky. It's just that the package is too big to be posted here  It's linux based so it includes a linux kernel. I could probably strip it down, but dont see the point in spending time on that for this purpose. |
since most people is going to use your package to install UDE, why not just add them to it ? All one need is telnet into it and run it.
| QUOTE (BluhDeBluh @ Jul 14 2004, 02:36 PM) | | Another thing I've got to mention is the hard-disk drive limits that people have mentioned - does it matter what size each partition is? |
The HDD partition table is hardcoded into the BIOS, unlike PCs.
| QUOTE (PedrosPad @ Jul 14 2004, 09:50 AM) | []V[]nm6687, may have this cracked with SC1.
But if not, your information will help me when I come to look at the MA content. cheers. |
This earlier version might then be of interest too:
| CODE | Size of certificate : 0x000001EC Certificate timestamp : 0x3EDD3F96 Tue Jun 03 18:38:46 2003 Title ID : 0x4D530017 Title name : "MechAssault" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000005 : XBE_REGION_US_CANADA : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000003 Disk number : 0x00000000 Version : 0x00000401
|
| QUOTE (eh. @ Jul 14 2004, 03:42 PM) | This earlier version might then be of interest too:
| CODE | Size of certificate : 0x000001EC Certificate timestamp : 0x3EDD3F96 Tue Jun 03 18:38:46 2003 Title ID : 0x4D530017 Title name : "MechAssault" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000005 : XBE_REGION_US_CANADA : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000003 Disk number : 0x00000000 Version : 0x00000401
|
|
Very! - it may predate the GameSav fix - and since me HDD is still currently set up to test it
| QUOTE (Vnm6687 @ Jul 14 2004, 03:55 PM) | | hey PedrosPad, this method using SC1 boots me to the MS dash, then i select Xbox LIVE and it boots me to SC1, then i load up the LINUX save and Evox loads right up! it works flawlessly! This MUST be the answer for newer kernel users. i dont see why it wouldn't be? except ROE is on so you have to open it b4 u launch SC1. but yes it works on my kernel perfectly. |
Now that's the feedback we've been waiting for  . Now you need to get ya 200MB package to someone with a K:5713, Dash <5960 and who is confident they can recover (but since you leave the boot dashboard process alone, this is actually fairly safe to test.  ) I've no doubt brave some volunteers will present themselves
| QUOTE (PedrosPad @ Jul 14 2004, 04:05 PM) | Now that's the feedback we've been waiting for .
Now you need to get ya 200MB package to someone with a K:5713, Dash <5960 and who is confident that can recover (but since you leave the boot dashboard process alone, this is actually fairly safe to test. ) |
I see this as an enhanced game save exploit but see a number of issues :
1. ROE - better than starting from DVD as we can have one more chance to use a different DVD/CD whatever.
2. copyright - this still means a legal copy of SC1(?)
| QUOTE (chimpanzee @ Jul 14 2004, 03:12 PM) | | The xbedump used is already on xbox-linux cvs, ldots may have written some shell scripts for that which doesn't honour a sourceforge project. Having the xbox-linux cvs to host it is an option but there may be more admin job than needed. may be better to just put them on the usual place. |
That is just what it is. A script that finds, and checks for executables and Media flags and dumps the certificate with xbedump to a log file. No point in making a sourceforge project or even to setup a new host. If someone can host a 2MB file that would be great - otherwise the usual places could probably host it. But if it's just a few persons who want to scan their HDD's even that is kind of pointless. Edit : I dont want to update 4 UDE installer packages just to add this scanner
| QUOTE (ldots @ Jul 14 2004, 04:12 PM) | Nice! Will be exiting to see how a 5713 kernel will react to the timestamp. |
I'm sure it'll work fine - it's just legacy Dashboards that won't run on K:5713+, not all old XBEs - otherwise legacy games wouldn't work.
ldots - Send me the file @ [email protected] and I will host it for ya.
Keep up the great work guys, I wouldn't mind testing it out, I have a box sitting at home just waiting to be used and abused. Won't be able to test it for 10 hrs as I am still at work.
Pmsg me the instructions or whatever I need.
CP
| QUOTE (PedrosPad @ Jul 14 2004, 04:22 PM) | I'm sure it'll work fine - it's just legacy Dashboards that won't run on K:5713+, not all old XBEs - otherwise legacy games wouldn't work. |
MS is plugging this hole too as it was mentioned that newer dash check for xondash So it is 5713+ kernel and some not so new dash would work.
| QUOTE (chimpanzee @ Jul 14 2004, 04:29 PM) | MS is plugging this hole too as it was mentioned that newer dash check for xondash
So it is 5713+ kernel and some not so new dash would work. |
Correct - the C:\xodash\xonlinedash.xbe check only came in with Dash 5960!.
all that is needed now is a tester...
you think it can be stripped down further (200mb doesnt seem to appealing)
aight
i bet it'll be like 6mb or osomthing like that
i hope, rather
make sure you can still load the save!
Excellant job.
yeah about 12 o'clock i felt a bit sick, went to bed early... wake up.... bam 4 pages.
If you find a 5713 tester, have them test it booting to PBLMe2, loading a bios, and then in turn launching evox or another dash.
| QUOTE (mikeinnj @ Jul 14 2004, 01:03 PM) | I've got an extra, brand new 5713 box laying around with dash 5659. If any of you guys want me to test this with PBLME2 or w/e just reply or PM me. I CAN run a MA gamesave exploit on it, too. I have used UDE on 14 different boxes so far, and upgraded 3 hard drives, so I'm not a total newb. Just tell me what I have to do. |
sounds great, contact []V[]nm6687.
whats the point in adding all these layers of complication, angerwood? why not just do the straight exploit to evox? less chance of error, thats for sure
This is very exciting, man. I cannot wait to test it out, for one, to run Splinter Cell (SC1) on the hard drive. The kernel of MY xbox is 5713. But MY dash board got updated by the snikey m\s to 5960. So how can I get a slightly lower version dash back and try it out?
Secondly what is in the SC1 package to run on the hard drive? Can I get all the content from MY original SC1 DVD? What is the location on C: I put the pcakage?
Thanks for the superb work. Enjoy, every one.
all content is from sc1 disc except the .xbe any maybe a few files. MNM can give you the full rundown
| QUOTE (devz3ro @ Jul 14 2004, 07:15 PM) | | I guess this is where I come into play. |
I'd had you in mind since the off  . (Wondered where you'd been.)
.
-devz3ro
http://sh0x.tk/
Imagine distubiting this package. Half of the n00b 5713 users wouldnt know where to get it...
| QUOTE (afon @ Jul 14 2004, 07:43 PM) | | Imagine distubiting this package. Half of the n00b 5713 users wouldnt know where to get it... |
Been thinking about this too. Got a few ideas brewing (as always  ).
| QUOTE (Angerwound @ Jul 14 2004, 08:05 PM) | | I could see a n00b tutorial as the best way of going about it on X-S. |
That was one of them - accompanied by a DOS batch file to delete unwanted files, rename and move others.  Surly that'd pass inspection?
| QUOTE (PedrosPad @ Jul 14 2004, 03:19 PM) | That was one of them - accompanied by a DOS batch file to delete unwanted files, rename and move others. Surly that'd pass inspection? |
Sounds good here.
BTW, changed the pinned folders around a bit. Better Look? or should we stick with the one pinned 'Pinned Topics' thread.
EDIT: LOL, dumbass free hosting company decided to not let me link to my sig anymore. Off to either make new sig or sign up for new web hosting.
Nope that would break the RSA Signature. If it were that easy, there would be no need for UDE.
| QUOTE (Angerwound @ Jul 14 2004, 09:11 PM) | | Nope that would break the RSA Signature. If it were that easy, there would be no need for UDE. |
Not if the ppf patch also patched the signature back to what was required - after all it's only bytes as well.  MA DVD ->PPFGen<- MA HDD = ppf file. Everyone has MA DVD, applies PPF, gets MA HDD. (However I suspect the ppf file would turn out to be almost as big as MA HDD though )
| QUOTE (ldots @ Jul 14 2004, 12:14 PM) | OK - make some changes to the xbe scanner.
Will scan C,E,X,Y,Z for xbe and xip files. Will check if they are xbe executables (relevant for xip's) Will check for the XBE_MEDIA_HDD flag but filter those with the XBE_MEDIA_USB or XBE_MEDIA_ALLOW_UNLOCKED_HDD flag (or both).
Will dump the certificate for those hits to E:\XBE_SCAN.LOG
Procedure for running this would be upload the scan dir. to your modded xbox and run the scan\default.xbe from your dash or filemanager. When it's done reboot and ftp out the E:\XBE_SCAN.LOG files.
PM me if you want to run this scan. It's linux based (open-source) so there shouldn't be any copyright issues.
Did the scan myself but nothing interresting turned up. I havent been on Live though! |
ldots XBE candidate scanner can now be downloaded from here (all Linux, all legal) (Many thanks to cyberplague for the hosting )
I have SC and Mechassault, a friend of mine is willing to lend me his xbox for a week, and guess what !!!its a 5713!!!
I would just need the HD signed xbes and info on what files can be deleted from the complete game to reap it. PM me to test this.
) we'll see how it goes. this is still a WIP! ;
| QUOTE ([]V[]nm6687 @ Jul 16 2004, 11:25 AM) | newer kernels first look at the Title ID to see if it is a dashboard file (FFFE0000), then if it is, they look at the timestamp, and if it is prior to Aug 5, 2003, then it will fail to launch.
the thing with this update.xbe file is that it is a very old file (from 2002), but it does not have a dashboard Title ID. this means that the timestamp will not matter. And if this thing works, then we will be able to BOOT UP to it, then exploit with the fonts, then boot our dash, and ROE will not be enabled. this would be the perfect UDE/5713+ bootstrap for NTSC users.
get it? |
the question left is, is this an updater that only share the same name or it is the same updater appears in the dashboard. I believe if there is some reference to the "Xbox Book" fonts in the file, there is a 90% probability that it is exploitable.
Alright, I understand now. However, anyone have any idea of the source of this file, as of yet?
| QUOTE (SargeZT @ Jul 16 2004, 11:36 AM) | | Alright, I understand now. However, anyone have any idea of the source of this file, as of yet? |
A WAG:
The XDK has some sample codes for the updater(as they have live in mind and need to help the developer on how to do it) which every live game vendor would use(and modify) to suite its need. So there could be more than one game having this probably exploitable xbe. just dreaming.
| QUOTE ([) | V[]nm6687,Jul 16 2004, 11:32 AM] yeah i wish i could get this file somehow to experiment with it. if anyone has this file... eh. *ahem* then please contact me.
AIM handle: mnm6687 Email: [email protected]
or PM me |
May be we can ask ldots to do us one more favour and add a bit more functionality to the scanner to scan for the reference of "Xbox Book" or whatever fonts in the file as that is still the most prabable exploitable route.
EDIT: I just tried ldots' patcher on the update.xbe found in my MA retail DVD(that is not exploitable as it is a 'run from DVD' one) but it did find the font reference. So whoever found this updater, you can do a easy test to see if it does refer to the fonts by running the patcher against it.
| QUOTE ([]V[]nm6687 @ Jul 16 2004, 11:27 AM) | ok guys, i finally finished my SC1 package and am trying to get it hosted at the usual places. IT'S ONLY 1 MB. here is the readme:
| CODE | ============================ SC1_5713 NTSC Dashboard Hack ============================
Info: ----- We know that kernels 5713 or higher won't allow dash downgrades.
There's a new check in 5713's XBE loader. It checks the XBE certificate structure. If the title ID is 0xFFFE0000 (dash's ID), the kernel then checks the time and date field and anything prior to about Aug 5 2003 causes it to bail out. So dash 4920 and prior versions are out of the question.
Recently, it has been found that games that download content from Xbox LIVE also download an HDD-MS-signed default.xbe that is the actual game. These files are located in the /E/TDATA/%TITLEID%/$u/ folder of your xbox.
Installation: ------------- 1. Downgrade your dashboard to the lowest possible version your kernel will allow (for k:5713 this is d:5659) 2. Gain FTP access to your Xbox via the Splinter Cell gamesave exploit. 3. From the Splinter Cell DVD currently inserted, FTP the necessary files below to your PC so that you can place them in your C:\xodash in a few steps.
**NOTE: The necessary files are not included in this package because they are illegal to distribute due to copyrights and whatnot. About 95% of the files that come with this package are legal to distribute because they are 0 bytes!
/LMaps/000_menu/common.lin /LMaps/000_menu/menu.lin /dynamicxbox.umd /splintercellxboxretail.umd /ThirdEchelonSettings.ini /ThirdEchelonUser.ini /UW.ini /default.xbe
4. Once you have transfered all the above files from your SC1 dvd to your PC, you must use the default.xbe.ppf patch included in this package to convert your dvd-signed default.xbe to an hdd-signed default.xbe. 5. Rename default.xbe to xonlinedash.xbe 6. Place all the the files that you just transfered to your PC back to the Xbox HDD in the directory /C/xodash. Overwrite if needed. 7. FTP all the contents of the C folder in this package to your C:\ drive on the Xbox 8. FTP all the contents of the E folder in this package to your E:\ drive on the Xbox 9. Turn your Xbox console off.
Usage: ------ 1. Your Xbox will boot the the normal M$ Dashboard and the XBOX LIVE tab will be visible. 2. Click on the XBOX LIVE tab and wait for Splinter Cell to boot up to a black screen with a loading bar. You will now be at the Splinter Cell main menu screen. 3. Select Start Game, select Linux, select Check Points 4. nkpatcher will now boot up and will load C:\evoxdash.xbe 5. enjoy and stay tuned for more on the search for a perfect UDE/5713+ bootstrap from xbox-scene.com
Issues: ------- -currently, the only issue is that ROE (Reset On Eject) is enabled because this is a "double-dash" type of hack.
Shoutouts/Thanks: ----------------- -PedrosPad -devz3ro -rmenhal -angerwound -Ldots -Tomilius -all who helped and contributed to this thread http://forums.xbox-scene.com/index.php?showtopic=241936&st=0
----------- // mnm6687 // -----------
|
|
great work , your awesome,
When you click xbox live tab, does xbox need to be connected to net for exploit to work?
regards
i dont think u need 2 be connected 2 the net, all the live tab does is launch xonlinedash.xbe (which is what trys to connect to live), but thats not really xonlinedash.xbe anymore, its really default.xbe and this default.xbe wont connect to the net.
you can also hex the xboxdash.xbe and get the xbox live tab to say something other than xbox live. You can modify it to say something else. i think its around offset 00143474 or just below that... you could change it to say evo x or whatever.
Does MechAssault works with this too?
| QUOTE (Infamous_One @ Jul 17 2004, 12:10 AM) | | Does MechAssault works with this too? |
Nope, the updated MA xbe is patched so it doesn't work with the GameSave
| QUOTE ([) | V[]nm6687,Jul 16 2004, 11:32 AM]yeah i wish i could get this file somehow to experiment with it. if anyone has this file... eh. *ahem* then please contact me.
|
Hope you're not offended but I wanted Pedro to have it first; UDE's his baby eh. (BTW: It ref's the fonts etc.  )
| QUOTE (eh. @ Jul 16 2004, 04:59 PM) | Hope you're not offended but I wanted Pedro to have it first; UDE's his baby eh.
(BTW: It ref's the fonts etc. ) |
rmenhal is the man to have it then. If it really looks for Xbox fonts, I believe the solution has been found.
(It certainly seems to be a strong candidate for XBE_REGION_US_CANADA boxes eh.)
I'm looking into it now. eh. where did you find it? Any idea how it got on your XBOX? What path on your XBOX did you find it in?
| QUOTE | Any idea how it got on your XBOX? What path on your XBOX did you find it in?
|
yeah please share. Us lonely PAL users want candy too.
| QUOTE (PedrosPad @ Jul 16 2004, 05:47 PM) | | I'm looking into it now. eh. where did you find it? Any idea how it got on your XBOX? What path on your XBOX did you find it in? |
I guess my box has an unusual past and thanks to ldots scan it's (hopefully) presently contributing to the future too eh. | CODE | *************************************************************************** Correct Media flag found in : /mnt/E/TDATA/4d530028/$u/update.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3DC83440 Tue Nov 5 21:12:32 2002 Title ID : 0x4D530028 Title name : "Online Updater Application" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000001 : XBE_REGION_US_CANADA Allowed game rating : 0x00000004 Disk number : 0x00000000 Version : 0x00010004
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/4d530028/$u/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3DC83422 Tue Nov 5 21:12:02 2002 Title ID : 0x4D530028 Title name : "NFL Fever 2003" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000001 : XBE_REGION_US_CANADA Allowed game rating : 0x00000004 Disk number : 0x00000000 Version : 0x00010004
|
"NFL Fever 2003", this is the game. Can you recall if you do something for this game(going live) or something ?
EDIT: And why the update.xbe is there ? Because it is yet another MS game, too bad MechAssault doesn't have this HDD runnable update.xbe :-)
http://www.xbox.com/...003/default.htm
check who wrote it. So may be we can focus our search on those MS titles that is live enabled to look for pontential update.xbe
| QUOTE | Correct Media flag found in : /mnt/E/TDATA/4d530028/$u/update.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3DC83440 Tue Nov 5 21:12:32 2002 Title ID : 0x4D530028 Title name : "Online Updater Application" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000001 : XBE_REGION_US_CANADA Allowed game rating : 0x00000004 Disk number : 0x00000000 Version : 0x00010004 |
this is a breaktrhough,
any chance there will be a 007AUF version? or a way to put those files on the "usual places" Because I definatly dont have SC...
It's not like we can pick any game we want. Since auf isn't live compatible it doesn't create xbe files with downloadable content so i don't think auf would ever be an option. Anyway maybe with any luck we don't even need a game and let the UDE do it's work.
well do you think there is a possibility the files that are all needed would be uploaded? or Do I need to go rent SC or see if one of my friends has it?
I did read it a few times, I just wanted to know if you were gonna upload those files that were all needed and I dont need to get the original disk. But that question is answered and I will start looking for a friend with a copy of SC.
I would put my hope on the update.xbe found as it could be the UDE for 5713+ instead of just a HDD run game save hack (SC1)
| QUOTE ([) | | V[]nm6687,Jul 16 2004, 08:27 PM]I'm not sure if it is, but I don't see why you coldn't download some PAL levels from XboxLIVE. If you have a any access to XboxLIVE please download some levels and see if any xbe's are in /E/TDATA/5553000c/$u/. You can't have a modded box when you connect to XBL so a way to get into FTP is through a gamesave exploit. That would really help us out, minus! |
I don't have any acces to XboxLive. Than i can't download PAL level. I can see 2 files "/E/TDATA/5553000c/" directory on my Xbox : -> /E/TDATA/5553000c/audiovideo.par -> /E/TDATA/5553000c/contentimage.xbx
I can give you more details if you need informations.
Ok everybody, until the new update.xbe exploit is further investigated, you can try my super stripped down version of the SC1_5713+_NTSC package for all NTSC 5713 kernel users. It comes with thurough instructions, but you will need to supply your own dashboard to be placed at /C/evoxdash.xbe and your own copyrighted NTSC Splinter Cell files. The only file in the E folder of this package is install.xbe which is Nkpatcher. Use This at your own risk! This will overwrite the current install.xbe in your gamesave hack for Splinter Cell. If you want to use something besides Nkpatcher (such as the PBLME2 edition of phoenix) than be my guest, but don't blame me for anything. Read the readme.txt and post back here with feedback.
| CODE | UEsDBBQAAAAIAHYC8TCpx4FYhyQAANM0AAAZAAAAU0MxXzU3MTNwbHVzX05UU0NfeC1zLnJhcu2Z dVSUXff3hxLpDglp6W6ku7t76JGhhw4paSQkpUMBaSSkU5SQlm4EKQHplHfU+zZ+j/fz3j/W++d7 1pqZa63Z38/eZ+9znXOuc6kDnSmIEAGDsS4AABrgexv2gizG3gP83WC/fvXa7LHhssEAMKHXEoAK ygaLJBaoFfPvVh3frG5/tzL0cLAAutgA9kwHdOVdIdmxwr8bl+HtsZGy3QGQ/2JsaO5gD7G0h4Ds gNaWLB5mHoA9dOIQIV+oK84/uUL/zZWhohLQ0eWbQ08IVCL4JwnBHySGbGxsJnaW9q7ftAFi/9Kd naUFCPhNsqEM7Z/o75Iymx1o/4h/7983iaGYMwgI1rIHsWhCrAB71a+CKCP+U1/6z3oLsLmrC8TB jsXD0RlQAW5B7CeA6oX+pCf8k17DwdXegsXDxeyb2JEcKv4fufouJviTWAfoBi2N+3etSgQ0V3y/ a8tgPkNzhfN7rlzMnS0t7V1sHCCAvTEZrI5nUJ9Kf/JJ97vPnzpDcUsbkL2FiaaNpYmGuaW9JQvE GvgtiFIzKEzxTzDaf4R9HWjODmCwpbOJGdDc9ger7zGUpfAn1r1/ZEl5QJyBJtKWQIirs6XLD1RZ BRQl9ycU9T+ipIHmEBcTdaC9BbS6f4O8Q6EglT+BGP4RpOgAtADZW5tIOrjbg6HXls4/cJqb33Lv BOVgt2EDYK+HmtraoDUj5fzn3IP/wjk6O1hD+/hXJxvYDDADMFtiayafaD6IUuvMLmFiKMhVEF7d qePcA/z/9v/b/+vWduZm+r+/q/4evRBLF8iP26A5BApS/hOI/h9BWmYgFwcriImmMxD0de74ebPT NkNpEn+i3f1Hmqu9I9jV+gcCRAKdS7l+R3xfdzB+n0u/Td/Qda6tkIN08z8X1u9u/8fC+l1jyG7C acLJoqHB8c0jnt+/XHb+Ulu4uEAsrDxYzED23/Tqlf87vZS5jSXYwZ5FQ/W7f6fGf7lK/61XllGU 05AF7PHoScyhQ31L/sk32Z99f9caspmwsSj+1f+WAChD+k8Miv8bw4TjB8V/8+YUzh+UKPqb9Yfd hP0H4+nlzSKBMn7JSn7yzSk/YylgujnlZ241pW5K4fglFp0vN6f8jIWv6qYUzl8ot6ZuTvk5Wnwu bjZafs2K2A0j4fhttDy8YVY4fhstPkg3p/zMbYzpTSm/5iVq5uaUn7FUVdyc8rPOPWc3o3D9lt1e 8ZtTfvYoa/VmY47rFwY/400j+bVCArE3p/yMJefxTfvzsz42qDeNhPOXe0jb+uaUn1nRmr055WdW DrBvlhXuXyJpJbxZJNy/jdqmvJtTfvbn6useRep3SvE3Cvl/pSiJqWqwKCpxAPZSHrgqACD/7gns f0JcXUDmJuIgZzugPcjyR0yU//bp9484CQc7O+gm6m8Y4AHk3+1j/wiTsXRwtv4lNPiv6ZL/E43m X9C0XIA/SN0kkH93JvEX6VvCNZS+iy8OoGKZ38XfD1Qo/yz+PdFfN7hfz1UetP9n8cv+S/F/S/Df ED+S/xyHZf9lHP6e2L8pkSNQivifKKT/hfI1oX8TMnmhBJE/EYj+SNDQVJcSU/ohr8v5z2O9jl+O 9aQAe/ZHJoEKUCum361mv1khfrcy1JIU0xQDVNj4hr0qhNpy/247/c0W81dbQw52bj5ubm4uQAUR Crc3MlT0P/KgC/v1xIj0j6KvZ3M/GmCPjkMwnAGS7S8L+Hr2+PUDG6Os7gMI+/Dj7vmvBEMrBweI pTML0MUOCQgGWduTs/MgI0upSAggaypqQL/klKQ0yNk82PnIJcWhv2xf/5QWQGaf+eZ0GwEAMMeA Op1LiL/9zSnnv3FqY/ntBAbqFJVUtb9/uCn1fWPaqRquKkkm2JHfImmYt+jtTE0M8+OQ+RnR3G2E /Dxrs0O2OHUZv6Pce6vRuZlAuucWzmXRzS8QiRTYDtjS17zIul1OxS7SL2XJqdY3jFptJ666Kmfa TQUu3l84z3X6pwuX0vJfPtnqA2deuNkZtKgkpp3KGav0YjhgMWjDsPo+qKjHT13AnhirwVL1Mgwt 7cDIZHozKjcKTy2shGjPOvhi+jEOGU8s2CHh3CBR7lxATNeZyLjtoqpmQzMQSAa/SQKWYARdxT8q CWZmYxxJqcw7CxYLKPgwh3hVj3Sa88hPffNM40WnKRxVfoh0ylBLlsAopS7a6QBsUg2NTx9yRuME 47kvNwNYutndD4Ax9WlasQ0+e2lj8aiuYzTjAL10QH8iy9N/1ZtZj6Uw+ArZBOGu6Wde5VYE5f7d zDUdc4KPBbof0fruHzIre8y/ZkIoIfniInopHu93FZjCJSsxer8Uu9sniBhhp8U8pewpZZgYy/1S rqgdvi9BvNK6aEuhKA9xDqw2RCoWI4Vn0mf9+gRr6CkyKifiJdOyDCZ6JiM42Ivnngx+uRt+4AhA 3YcNXgXIf+BL6ELdyodDg3eMYyUlF0jLdUBwLSROev+R5VY4rQRBVMoIQhiG/H35dUKJtgxPfUFL V1m8vsZ9Pj9C6lfOFOHGMqY2eJRJjuHs4Om47N3+2o5s1xD52WIJIdHTps8xa/duNya6KOVVn/eW 0DYjVabuNy7PT51J9iwfaBJJaojgOtiR+RLxvYXzHZYN7LQ3i7lrJBWL9wnDE7EtvmYXJ1W8zjdy j/5JJa9AzezF48MHYQub0xw+Pi2NhtqCyAnPNa7zb3nWywqhBfqV0o5oIbUSzsEeb59rZUjVES6X eZCVj9U6pgvY7Fa5Z/DQySP7AnmLM0Hvhe9KSmiol7B3a1vPfhFtZS8/ernfqFiaEUQC/7osOTK5 O8Yaqyqfev/Jk/pFftQL5W6OaN6ByiKt1GhMGKEEGqmBkZg5cqCJnSZW2Mp1CO8ofHYUofW8+NJJ miISSvSU6sqKKIPqUCJHNritFbaHweizG/xdm7Un6mtdy3ZIWvfZB8R1lN/wdS4HI3nj5OkUduhe kVmaKITGRO6uExEh6Fe2cLBoNt/ypTHy0m6T80XDfV8h1XCZ6+3Jclf86BUFexdaOq8fzx7DqNaJ EAVlWmNfAcCpJz08AF41WnZRWrFjovtRTsCqC6TQF4mIxkudUG4uwIl3vf366dwh0HmXO+vWicg2 EG7eruVDTV9BMFyjQelrJ8boZx2gyCeZMJR2pLNjgmNx/N5wNkHH+S3Fvjn5Odso7LfWzQ4NI+s5 7Ti1mpNrkRimCw4IPk8xpSjxECV9es7+YAUIC/py2Y+gODTTLvUJfriLoPshEYQcrStxiyVDnwbt Aoyhw0KDUuF2K3nlrF9bffJYTqijrWWNfwH5Eo/uGHf59eSRPpeRxgh7DPiQ8LOFloYQ45aH1npb U3BgLH8tZc4V/AZ9CvMBdQ4jMypZXZJZr67C3YeF9SsCupJprIzDUTjL/M3V+hvIxq0L3VuRr/cd sQi1rjTn9dLlHPNRBw1Eax7X98Me8A3GtsCLDNp06z1oIoVxNbKIEEnNUcaEWIQuNi12ITSK2hE4 J64Ort6SZZqyDvRs6hZd40BnW+pP18JrWWI1AyWev06+V1JSqqnSIPuasPUe9kCqOnP94Eqc7zRq yau76/qLO4oY60hzqZmP5kFyzep0y/YQMJ+qh3ExDmtYOEZO1VTlZsKycxOlJ8OY+glimfSLiiQM F6+J0hkDr1ry0wWXjDlnfMQzAFwzXQ9TWjxcsoyvtgea8Bi9gQ+3TDpKjdEGPBJrqfd5i7LteOk4 BqrwBUQecVR+wLBx0H7ichVVBucsL4vtsNMpgCrZzWd39yzsiRdgHG3MvXNnY1nPweyNOJPGgEmt zpDgnacZ6aT8fB8UOZVh7uAYYKb5j6Kny4juotM1hz1RcAPEr21Wnpbepv+iuCozi3Qq++BuYXHD ZxDew7HF2G87sx14AGASF7pmWD3UUnlQC12wOen/xZoBsneBAMFgFg8zS0BFdrwhNowW7tuYdwEr I2QIjgpk/ig2MmSPSuUvGZiSXqkx2mkj68eSBcdREoZRxxLRedA7VVNXdVUy5EU6FQelSmEXMwyH Rwezx2vmoT5nuE2TqqBWwwL8XNARQU5N8243HJbJvcfe8pL5GsGd07tp/iJt3sH706X7w36XxgV3 /oFdz7ljl4uMtO002ubdDpVuK0nhgReEazsqj6Q2icOKQDrmFfxPHllHMjQTbegGy1yD/dLeWeM2 TdWnPyOwPahItErcYjqhywmt76g5o2vW5fNFo5FUmLiX19kVMbPFet5V0rKhkjlf3nh576j/REP5 wPA08wXLufFsqIvabhuhz0cP2hUeMOuX7c2swF5scxe4tDhB99D64Tdu3CK4c+VBUhtNRbS5zjna MnD9daD+VwHn4BxvNv4BKTRNamnBWZ1b586RrKXWn/Leyjsl5X7AIXi6faEpeFwl8tzBF+BOZXbd FX9/iJ/k6kBZbBYCFFrxtPviVh+MmrxwOzVG/nogrfh9t62NYPCe2cvL81W1p5r1b7tqjomM9cu7 6zIksh+SB6EzxT4V5luTZmm2PSkPT2HeIEY0a2ISnEjq2WsnOzA7EqEbIPDcYxOhxZfwW+g7Fxcz yZ0szCINsQshF7kURnUj7SGkyKsnnFUXBJFWvvI8ws0jXcs2A3m/rxg/ulAYzIpS9sO9aNmbeQiK pwqLoRQND/nSQGlxT47q+iiY4rY4ZjAF4rBNWP5n9duFWbJz4iyqSUg2Ccj++k9geNoY8sbeKtLM yFKFTPe+efMsKX44TyRCTn4p4QQSNjuW3+83rncvwkpANOrOaP3SEfyLw4k3A3fjUzRuJaKRRzek FsRFRtwbrI9LEfG35Xh7nT1Vi2OuV6tb+pxy+S3RBbf9BqrF7HEGRTm2D3AyBT+raBXf9C1HvWjl cgnq2qOr/dxqgjuHeh9NJVsR4ggM2QnpP2VuH0tMnRzn3H5/qiagMAhXViVqZmKIU/9IG3stlt+9 4wM43F9HuXSVPZjohAqA4MamWCTrzmDMpH44xZ7MGINQi3criPDi3qAqG59ewV14yMLSOuhMqLJP fn63e5x4qZJnA28l8XOYkZ24COLmi1T3zmZm6WVmsdm9AyaxoL5qLtVtrQXxj3dmRUh1MOKD272T jOqlv/g0PF1ULjMecPc8xKAsqOkzehJvza1ergXJxct+32/+ZJjgMbYUgZVGw51runmHGNO298Uc 7YfmiofGHR2oVNQJ7s9SZmHeY9PUHENQsaLDcEju0BGSkOTw5rM7khYQDeev5ejJqLwzEhL68Mms 8amrMEG8cTIJyx1FD1yiBzIyNjYndegh1cai1yKnIjqK7njb4GT8T9RYVq4X1MT47N0+MoYKqOLJ 5NuMwt0EcdoOZCg6Qp690bVmaUhNG3tYvAmV3uysJYQ6JuydCaM7KywkEP7q6KjI/Y7zctKc926n w4iEgZhMQ85XQHezRuw10RKUgGCSYntpSwzRZ3jD8c+DS7b0Q5JnYKm0aQ86FqMYnzLTbz2EY03R 7ndNlnqejHLM0j73gAAEJhqfCexiaLeK4QU10DB2dIdsduIHiBrTWZPwzT+qx2PLDqIHXHmoHZYe Gy1/yQIpufvki+nROhOJQZBtgMq28OPEaDpj9HPN9JqUTTGPxCkl94jLy4hrxiw3nwV8GdYR04/Q 5Mu85iEXeJggvgXdbysAFFGgTwdk0LmzW0sp9ft+m/FfzJ32to5AiLnNX1tuGCzU/mHBxLnWZT9c bxl2qrVpxB6P9s5AuiczeYbRhw5ZotRmsHH0T7BkS6mfjy40O+pq2FHKN/UL09cI8sq4H1fTPrMy GjeaN4nLImhtRzDW1lLX05V3uD72CAkdLW99wlnOC+kv6YzdkRnoi+FkBzq9YrJpm3N460C8nT6a JwwebMelNZ+6Y+DdJ78M+pyeuoFxYUks3mcDUoMbGsmV2agOlOFMLDWb1t7GJMkaHPO3JghNeG6a rK1vzaVULT5+aIVxSRalqqSGvVE65H646icuF+isSYrJOzG70rAEI2vaansNF1cRPknqd5cYx7Vi ZnZ52dom1Rbvwk73mbVek3L//JvNtVOfw7cFAxMVzZnG6MGmo7CjlfK12sbZm3FZhsz+41WiVo9y cdO/UGxmxI8PLQdkMadzfOY08HvYYJrlnzvpE0PLpDq5RPEJQjv3bvd4fvWs+N270YN1kys0rAQm 14an6gt+9MRj1QX34dmdYqKTtVMfvYurHY+YazAE26Txz4fx1935lJr+ORRI6ISx7JdHX9V74qmb HE64aOsTPD6VkRQAasLl2O011LMpCz+7VR/VtGvRdw9keP2RK/U4CNIGf/yh6WBwadrcfXWeHinT CnhcF3d6f2IYwtsPysMYBu9f3g/7wDRFUXdmz+J+f8lNSchLrG2WbbevlJrpREoGZWwbyzpearFu jWct7SBW+MxkkNuXtZKawx0uLdBgnUF5sffhB/TeVpkavVebE5y7EbiC89puq49eP0fKdPPm7UrT S44p66xbY0AhTB3sZK72f5nxisKNsBW1Y6q12O/YwuVhPtnLOdbSNAxG39Jmdw/t6HZUw/IT+UOv +dip5N0QxEO/CkvvQhvqtl0kdSn2W2cHi56zHCfzPCbN0vEaDjTv2QaB71ZtYof6E8HcTaLuFC1+ U9nj023uxR+qZ+S9H7L2k/mWFpiLrA6WdMnmyKxWPVe1zEu+Lo460G4ePjuEXJzpnBAufErf3erh U10I6oVzVKpoGq+fnJXy+TKtuR1z3KPkELOypu/VRTn5GQcsvNWqMtvDTm8tOrkMwFHk51TScVnC uMYk31ppX6BGF0Wm5llSzpMTwcswDomXlJK1TzElqToYc/TemYBP5vGt6b4zxCX10VqTe0eQjczA sS0DiTvGvMsowPwRA6w9e6wOn3x0frDVAVy9tz49wW52cCL9xlBAIm2FFFrBft19yjs266cokC3Q bYVnYoB1OTKBOhJkPRn9KOdp2Ff9YMh6TIbBYwTRlVJpPry7j2sIFzWnBcZMwSTEG88JYKtCdXvP eEn7Ju0Um8jH/T7v8VN0L/jdcly5ZHlaQi3qMxiHPbfD7xc+zbMXyUvqVYTgGh94GvgoM4JiEz5/ UZ2qfor3aCPRdHf/rWYmvrcBadCgMI5jLLVQ0vYud/J7mnkIA3PlNpHOVTmW90uvrSzrWwEwnUpY HGQVF4WToP0O1N2VIJVc2sE5I/eDyFswfI/mqO9LGjrQrd5jup+MN301RlbZ5z8PqMV6KZQZkmt1 VjRRdsTkP9j0Vn+KDn4m/aKkk46TxL/G/D31wGb90UaprC1lt7vBkWANy6GyT1buPoJnr3483tl5 w5Yr0nkiYIvn2VhIAw+NbBGP42MFKuAQDykFzt5j3Zh2hUg53QlKsgvvt/c7mfrN5t3Dhe3f4A37 +Pi8V1jg2VZsONzaXn9r50RRm1nlfo7u5dbzyvfDqBaClr4oJvqGJRcoSKHHXS4okjl0CunNxAbs acfOQfFLLBDFKnmA/Qf1I9X7Z2GqJrcysINVbkUsWmHvkaZOJTtMdVwvNo2iC3NWwXTSSi2kNoNv IfqqEdEI5txGynd25RuExeNugX/g5Adfd2+SszI6iQoYS93G3BbGf6rBS5QMazpKoCXN6tHDv6Hi omYJHJcLxz2WxWXaNW5E93QO3uyJdRJ7KKt4YdJ/0EgWkmjCHR87Nc+QwoncK30XNG6M++LeK6Y3 h1y57yCX9Xdj0MWXrqVphqKJ3ZkJ89QfD4cLJKj2phPQJ9UA1Pjkb8FjxVBWJJ7dQdiZ9//o5ZU8 sYBKzv8SQ7t9Ieedp3FhGEoMndnZ7Ic8rwikNMG7sBZMnudq6A26dgKGOiJVvubm8EgHq/yPfWqN ByeRZyki72GtNBCGLnkmSxQ8DnuSQsp0jD+V4+jfKQa7vCjnBKt2a6TYvJnA0cheMNmSmOks3NTH FfY2xhJi9y45uv8oXZBjiLFSXWzKp0DbqI9tXkhSCP6rIW2XW2cAbkrjSAULUlOr4gqGK/d0B2wn QiMVS8drvN45zqAWBYnbB1Z8zujPiV0v1XiFjezcat6OoT9yZhcYVUGIIja8JuFBHo3Ihi3UEidw lmdkQ5MjpmSceVllsXgwfje94jyHvEmiqrD2tugp0qdW00Q5FHF/mAs8Ovh0TaC4RFri8xqJmrGT NWw9C4K1a19eRSOHod0dF5qeJpt6PEExEyUr64pa++2HKnwx0WGwioayR0n2GhvoroKi2xbV29O2 +AaOtkMTE6aY16nc9SiNnfoTaiNM6Ett4ANferzpPKIopfRSMdOGIgV7e1VeNLxeW0RTMxwtUQw1 A8Z7D2OXIB/922BlZFXxZwjGajyI1OjtgEn5LJzWtxplGbYZgrA3o/x4cWqf9VjFIMNAwi2RpBQ/ JOmEvIBXeXH7LmIya/04igv82VKKJe0GH5+CQxwGHEpNCt87N3/cfq4MGUiJyDJqD42a5qNT6yIW WYo32mRw4/cSnQ7W5QVP18hrKitn0VKMT+j470PCsFGwAioaQxICN7wvMSG6aRYkrHZjSwQgTzey XOW9nfNZucZL64Z+zEZExysivoxhjYVtPk6sLaTHM/Oa22cFnjjoIaHCsJXahb57n+kdrt2nYXB2 u9Wblp7Jbr30ZshkCYnG/MKIR8P9Ahj/+aKOOE/Ree85pyttH/Fi15c8OObkrLfAmrtDrEKBWp0v Ds13A+QK9LdyKu2wV6eEFvkjePpm3ex6/RUh5oiYTSNGZ3xIhBQOqNltFxuYXXabgS8ousiiXRUk wt/Zzn9KG5yDCw6Y7JcS7+FEY3yY+ZHo0UfHhNe5n2Rwql/kWggWTlaOPNWeLTkteIfX2JslqRvF UyyOK+qG9NGj/bhZ7TjsmYCsCX4hzSwhcfQONRJFs9eL8Sy3HNNz84z2NcxtMW0PiemyDyru6bjt XXjofXjaz+QZTeSAsQWJAKY0d5CoXOxnKmX8nh3DU2PPUAjCADFKBaOHwHPZXG0uf5dx5dQ7GVvl dGUc8mQhVVTGCqFUGpoH86VavfefexduVJ/7laUpo92baPng2+DFo+YS5cdQDmIHi2zFJejqj3SG bXGlgGm251mWk5krRaJX8fKULGjRgZFeGsiCaUoTQSNi8rxwr2G48bHUeLCqmQujel/Z+fAV+DP4 aje+mL0qOtbWxsaVP23NWFLQt1FizSxxskCQzS8IlMJbkZX3yw+uPKVhLmHpJlYp3d1LcgB0VFZO smg5Xoy72nlPvFZ4UZhQRUukPELkRvp2rJhZ1G3s/d5HBzoyCTjhVTRniYEyhSMUjn724/sc03jj GkLIayM46S6qmkrwQ9haYkaHr/FHPZRHBNRl1Wwpq0vCc7sTdlC+YEydka1NPqU8raV3NGKOYH1m RI/0nL4ib71dEXE5g5E3uDokvznt83lo7bJIxwPlod0ceaJc201FvdaPoVPONUUGz9Tr7TN48NP5 8WJGLSFN9K4RpiJEd/1ZizLUby/vaeuqbDMGCKS8Fl7deu77OtePkl1RpEjwfY0I11mvdEXCcd9D 5hA2OiKn99iVUaweSvI0uPFYzXUyi5Z3k0YeEpwwuXMimqzpOW/qXCv1i21NRl+POX19N84FAMIA vn1gtQIxxaxyvr6DwPi2LbewtAK6giFfDy1YHB2tABUlSJqqqtKcbLCqXzfk5ObOlkCIpQW5Owhi Qw79g1kD4moBciB3Y2dhYyf/vX19MwD/12uCgIKI+R0F3n1UBqV1x4yyQi0EZmSUa3MdQJZwcdX7 t1vaxijRaLtxSF5eJuSClKGPU96avK96ocwd9pS18L7k2obtmzitWP49rNJCt+m0w764bWfTkwe6 WGqoT+kxP8+xi1ckj7egNYpvSz3wTWFNI9uT8ZPAMevKqonEk6EtHmDOkK8J+SsSP+Gww6dK1PpS dpqJMcX8LjVYn+OQD5T2u/fBuxsrQh6MSUXZ3uQRME7DzKJ0bFUGuFeV2IxHAtPXC617GvEnRu1p 9G0bB86Yr784Amo6Aoa6UvFZHgVlMR+yhu6K1I7Q75tEnc0ZnpehkgMPhco5+1gx9hBpbasi66kz 2BVNDElgv4cBA8P84+oVA7QorIDJWwAABjq0KAvTQ8jb4D3osxLyt6JAc25hZ8kC8YB8ewODSjqM +nZ0gGLipMgEcUarycCDGlm1GpuAKj9pMs6G/FFd/IcXk/M9pMReZztVcvNHfYFD0TtN/eNL5KTe bQp4JN5pWX07vv2C1iIdrFnCVn6vXra517XuHnQufqipPJo+2ganrXhzcL8sxjvM1Hm3e3+2O6uu ldelqA42M3hPMtzdRcl+cCB+IwYrT/4dAx6luSbBkljFPQ3zLs8RqlUOS9ahnAF12bD+6jQGq4yW aAyKUkQ1LpUuc2da2GWF3fa7OIJeaL7BLi+ROb5Yh5bnInMRIlbyUSc2zVnxsodOyRWiw3wa+ti3 dZxLvlhjSVCBC7P7BvYz9/odb1Srq8fMId7e+KAQ76yiwskQ+dAdaeSa6tvPvTzU9qg0++VIqfAE 5mZsULH1sSSozWgzm7QFhREflr0J4O4ta1wLFYpcry9i4RJ/gxwKn26FOu1syyyiSoDZkQ4kLMYU i3JBLfCtwR7fo6RSj7ybOSyqH4iwHJWQ8+nc7wRNWoxDX76hzoXuzjoLQYFlu3I55+ycQtKTpPkh JEKkW166Gvdru9knej5tstge3jtAiSzMXjzYjL+fFbAfIxUgkyumwvvap8cGZydbbdWYIktdAdaS aN17I7V09x2/HfHIW9BRIfyg6jvAaosH4SI5t59kg+h5HR09Q3oOgLCshRvPEE/e8Ppag407FEbe nqdsokiEpbDUiU31dvaJKcOpxgXS8obCW+vbfdIxMsQTWmLPFJWxmwj8dGBD6IXC/Kl9jz9tScGN 4bu3NVulhnDBg6Nwo1HcenzRDUQ3WBzTS+BTPxCkvmDAoLyupMgpjxbH7eNlmq9r9fYbTDqamSVg mdmf2leyIPMQL0JVFWskjyhre62cjfKYfTyjN8x50spt6zb6jkjmFX5WNwCE5Aii556w1VxwttN6 SewYkkO/Rvx+bQ5zcYsGI2Ztxtsg081o49r3zW3WGe8wqtDAOa7d5Ey4JyrxsjbM9wdqU1bypx+/ 64960mCqK+HNRDXNRdCQ6rAKHmQ7ky+Hr1NFkxR5oUShZNcx/uyyRtlgnWC8jiBiOCFZbe8ijrVy fCTgkyQXbpyd/TU/Nke2L/MbgIF8KvXjV2QyeSudXmsb5e5R7S/E1SF661Z+DWXUwfAJPnSIXKGm L6viHWZzD69vN2EMufYhnAUOZqXCbXhyWK6zLeuHPQx3hj1ur+sdcudpqomp45XHz3WieN2aP4lv 4tWzI0B0kKQ3Z0wRUbLng6FcKxrQUqLOXxK4Q14LyJmbZ79+sfSQyRqFjEKJSyX0mZYmbWB2zCs0 UdanZQrvMnV2YGjEu88A06KReOYlQTWve/Gel7uzDpSjoUAIWt+bzrI3SWRPBtNp0K9oAzgJuowb VqZOhJzbyrOLwyxMBw9as5GO5BQwF/eLRPJ8tKmfwATaM2+bnBggZ3fjZ2kjBQQsYD2QTGQXmd8H OE0/U+aCH5JxKIqL7gTQ+hdA/GdyBCU5GSMuRG2AsG/tg5OGKiNXHm+GqZZVo2RWpfghEx4ew+Vs boNReIMpmpzbqtEtniqgb4rtHU0yRpV2Fb7X0i2u0bN2j29o9LXc1qRnMB9Yg12YGs5ReeYsamVI Lhbg/ahQiFkKuxC8uuQCB0P3MaM4cbFy9nJXaSCmDOLyXDKWb12q4LnvOQrm/ukBpjLJHLpw5WOd 7pQOzzxA78NLTvE3cqT8Zk+FEOxG2l85M2K2que8XoWdldyEZXezCZLdG3XBmMtDxWCHpSDV834n IE89OWGeXKCEpop6UNONFBQkTOepiYXuo4RPfR11BevjAl/OVxHN0YWgtLdvYyfMjTZttndFmiqV eWVU8ToKITINIfRCte2Ex4ssP1M6xDFIhlDfhRvkEs4V9MFnBCcwUUVegBj3Gb+S39MLNTqEd58n REk4GwCj+iN82k7sEYks3W+oD/GTJ7jJKWIcNe30zubLkEl5FK8NpMo+Ytql1GDZfYQXQHuaJR7y cqLt7jRVfjha5tWThLg26TWUFLl8C0kjYye/Af20ycg5pX2OKNiV/Zl6C5e58ydcbM6eJNaUngJj Vd1qpmyc2nG9qrYYU/miHlybB4afYnEI1xbV5ooIFcqEiUMOnELy9JJR5OqPb9WlewKaO0pEciJ0 bBYnBB2emy6PE8a8ub8aK5HqYJ5+/0gwoMWsczkICfegv2w+70iQRDGYu2+Zz4w9NC/rYuqdRLdq AVkgWYNJZzf75LZwOuqijVvNplMg4T0yCqpLcFFmLn7Uki51wnbFmLoUbi9+sZh2PS8Y+kTKJV9Z wLbdLj0c35WSf1Wkx7feHyvUvHEEtgd/+hJhfNzs2B79DFAxKkViAJ1k9F4y08VcinYJeQNEEQH/ B1BLAQIUABQAAAAIAHYC8TCpx4FYhyQAANM0AAAZAAAAAAAAAAAAIAAAAAAAAABTQzFfNTcxM3Bs dXNfTlRTQ194LXMucmFyUEsFBgAAAAABAAEARwAAAL4kAAAAAA==
|
does the install.xbe have to be signed? and if so habibi?
| QUOTE ([]V[]nm6687 @ Jul 17 2004, 01:37 AM) | | the install.xbe is already signed with -habibi. but remember, that is Nkpatcher and if you dont want Nkpatcher then use PBLME2 or something. but yea no need sign anything in my package. |
That's the reason i was asking, I got this working, but I didn't want to replace it before i knew, I hate hotswapping.
I don't think anyone has posted about it, or if it even matters, this works on K:5838 also, seems like everyone else is using 5713
this things runs from the live tab right? So hotswapping shouldn't ever be nescesary. Also since both the gamesave exploit and the nkpatcher works on kernel 5838 this should work fine too. That probably explains the little + sign behind the 5713 in the topics name.
| QUOTE ([]V[]nm6687 @ Jul 17 2004, 02:15 AM) | | what xboxdash version are you currently using with your k:5838? |
D 5659.03
| QUOTE | | this things runs from the live tab right? So hotswapping shouldn't ever be nescesary. Also since both the gamesave exploit and the nkpatcher works on kernel 5838 this should work fine too. That probably explains the little + sign behind the 5713 in the topics name. |
ok, but if you replace the install.xbe with one that is un-signed, what do you think will happen?
| QUOTE (Protocol_Unknown @ Jul 16 2004, 09:25 PM) | when you click the live tab an Error 21 i think... |
No that won't happen. Clicking the LIVE tab will just launch splinter cell and then when you perform the gamesave it will shoot out an error because install.xbe is activated when you launch the gamesave within SC
I was just trying to make a point to krayzie that if i messed up with the install.xbe there would be no way for me to fix it other than hotswapping as the spintercell dvd as well at this exploit loads the same savegame. Which is why I asked about the signing. And personally i consider anything that hasn't been tested theory so even though the "+" is there in the thread title, i though i'd let you guys know it works on higher kernels also.
EDIT:Just some spelling mistakes
Ok, quick status update on UDE/5713+:
Were getting closer to UDE, but not quite there yet.
[]V[]nm6687 has put together a Splinter Cell 1 double-dash package, that allows homebrew programs on DVD-RW media to the played. However, currently this is limited to USA XBOXs only, and suffers from ROE (so the exploit has to be re-triggered to change games). Were still hoping a PAL XBOX!Live user will have a PAL HDD flagged SC1 game engine on their XBOXs HDD. Yell if you find one . (btw - It is possible to use ConfigMagic to modify the EEPROM and change a PAL XBOX into a US XBOX Ive done this in order to help with testing but then PAL originals no longer play ).
Working has also been progressing on a Mech Assault based solution. rmenhal adjusted the GameSav, and now this can also be launched via double-dash. It also suffers from ROE, but works on both US and PAL XBOXs . This work has progressed and it is now possible to boot directly into MA, which gets you into Evox with ROE off! However the way this is achieved is involved!.
Most promising is the HDD update.xbe that eh. discovered with the odd xbe non-dashboard titleID. Ive verified that the font hole still exists , but memory layout is slightly different, meaning that the existing UDE fonts dont work. Hopefully rmenhal will be able to perform his magic here. This would make an ideal UDE/5713 bootstrap. But note that eh.s update xbe is only flagged for the USA, so we still need a PAL one.
So there's K:5713+ solutions for all - they're just being refined! Edit: Soz. not sure on the JAPAN status. Will need to check.
Now we need to test on K:5838, I doubt it is much different from K:5713 but you never know what M$ threw in there.
-devz3ro
http://sh0x.tk/
What do you need to test on K5838?
********************************************************************
| QUOTE (xman954 @ Jul 17 2004, 07:58 AM) | ******************************************************************** Correct Media flag found in : /mnt/E/TDATA/4d530036/$u/update.xbe ********************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3FDA11E8 Fri Dec 12 19:07:20 2003 Title ID : 0x4D530036 Title name : "Downloader" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000003 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN Allowed game rating : 0x00000002 Disk number : 0x00000000 Version : 0x00000101
there are 2 downloader.xbe also |
yet another MS title game that has the update.xbe. But this one has a late 2003 date. Since it is after the July 4 date, the font hole may have been plugged.
Beside, it is still a NTSC one, we are in need of a PAL one.
| QUOTE (EthanHunt_IMF @ Jul 17 2004, 02:47 AM) | I was just trying to make a point to krayzie that if i messed up with the install.xbe there would be no way for me to fix it other than hotswapping as the spintercell dvd as well at this exploit loads the same savegame. Which is why I asked about the signing. And personally i consider anything that hasn't been tested theory so even though the "+" is there in the thread title, i though i'd let you guys know it works on higher kernels also.
EDIT:Just some spelling mistakes |
So you are saying that if you mess up it wouldn't be possible to delete the gamesave and put in another gamesave to grant you acces back to your evox dash. I didn't mean to offend you on the 5838 kernel part I was just spitting out a theory. I'm happy it works for you.
| QUOTE (krayzie @ Jul 17 2004, 03:24 AM) | | So you are saying that if you mess up it wouldn't be possible to delete the gamesave and put in another gamesave to grant you acces back to your evox dash. I didn't mean to offend you on the 5838 kernel part I was just spitting out a theory. I'm happy it works for you. |
No offense taken, just saying since that was my only way of putting the gamesave on there to begin with, if i screwed up putting an install.xbe that wasn't signed or wrong signature in the game save directory, the only way for me to fix it would be hotswapping since i don't have a memory card/mod chip etc...
hopefully the super geniuses we have here (no that's not sarcasm, I'm dead serious) will get this thing cracked soon (again). Makes me laugh that M$ has some of the brightest ppl in the USA(or at least they should) and they still can't make the xbox unmoddable (via software for crying out loud). Sometimes I wonder why they even bother. 7 revisions to the hardware and they still can't get it right.
Anyway, i'm rambling how...
Ahh okay I wasn't aware you didn't have a memcard. You should back up your hd key right away so you never have to hotswap anymore.
already done, which brings about a question, Is it possible to upgrade the hd on a 1.6 using only softmods. seems ms changed something, now config magic doesn't work, so i had to used evox to get the eeprom image, which isn't the problem anymore, but liveinfo doesn't work with the eeprom image i get. so how am i supposed to calc a new hd password if i were to try and upgrade?
didn't mean to crap on the thread, so if anyone has any idea's pm me, don't want to fill this thread with my useless dribble.
| QUOTE (EthanHunt_IMF @ Jul 17 2004, 09:11 AM) | already done, which brings about a question, Is it possible to upgrade the hd on a 1.6 using only softmods. seems ms changed something, now config magic doesn't work, so i had to used evox to get the eeprom image, which isn't the problem anymore, but liveinfo doesn't work with the eeprom image i get. so how am i supposed to calc a new hd password if i were to try and upgrade?
didn't mean to crap on the thread, so if anyone has any idea's pm me, don't want to fill this thread with my useless dribble. |
i think it is possible with the new sc exploit,
read back a few pages.
| QUOTE (chimpanzee @ Jul 17 2004, 08:02 AM) | | QUOTE (xman954 @ Jul 17 2004, 07:58 AM) | ******************************************************************** Correct Media flag found in : /mnt/E/TDATA/4d530036/$u/update.xbe ********************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3FDA11E8 Fri Dec 12 19:07:20 2003 Title ID : 0x4D530036 Title name : "Downloader" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000003 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN Allowed game rating : 0x00000002 Disk number : 0x00000000 Version : 0x00000101
there are 2 downloader.xbe also |
yet another MS title game that has the update.xbe. But this one has a late 2003 date. Since it is after the July 4 date, the font hole may have been plugged.
Beside, it is still a NTSC one, we are in need of a PAL one.
|
Ah! but has got HDD, a non-Dashboard titleID, US and the JAPAN region flag. This is an improvement! We need this, for our eastern friends  . Although chimpanzee may be right about the known font hole being closed
Couldn't some of you guy's with authority ask live users to use ldot's scan-program to find new xbe's? Especially pal users. Ask them to run everything with mechassault or what game you needed a pal xbe for. Isn't there a chance M$ will be able to update these files before it's too late? I mean they're probably checking this thread like crazy now.
Couldn't someone ask for this on the front page or something also?
| QUOTE (gronne @ Jul 17 2004, 12:46 PM) | Couldn't some of you guy's with authority ask live users to use ldot's scan-program to find new xbe's? Especially pal users. Ask them to run everything with mechassault or what game you needed a pal xbe for. Isn't there a chance M$ will be able to update these files before it's too late? I mean they're probably checking this thread like crazy now.
Couldn't someone ask for this on the front page or something also? |
i dont see why live users would want to do it, probally to scared to get banned or summat.
ya cant force em...
damnit. we need pal live users with nfl fever. I don't want to switch to ntsc.
| QUOTE (Kyro @ Jul 17 2004, 03:41 PM) | hi i m a pal live user but before being a live user i was an exploit user and still now i m switching from time to time, from my live configuration to an exploited configuration.
but i only got top spin, if my help is needed just PM me |
Hi m8, got friend with SC1 or a blockbuster nearby?
| QUOTE (gronne @ Jul 17 2004, 12:46 PM) | Couldn't some of you guy's with authority ask live users to use ldot's scan-program to find new xbe's? Especially pal users. Ask them to run everything with mechassault or what game you needed a pal xbe for. Isn't there a chance M$ will be able to update these files before it's too late? I mean they're probably checking this thread like crazy now.
Couldn't someone ask for this on the front page or something also? |
I hope anyone have games(live enabled) in this page http://www.MS.com/ga...ox/default.aspx and live access to scan for the occurence of update.xbe in their game download areas.
| QUOTE (chimpanzee @ Jul 17 2004, 05:50 PM) | | I hope anyone have games(live enabled) in this page http://www.MS.com/ga...ox/default.aspx and live access to scan for the occurence of update.xbe in their game download areas. |
since you asked nicely,
ill try and get my friend to do it,
been on live for over 1 year.
| QUOTE (PedrosPad @ Jul 17 2004, 03:01 AM - MA paragraph) | Working has also been progressing on a Mech Assault based solution. rmenhal adjusted the GameSav, and now this can also be launched via double-dash. It also suffers from ROE, but works on both US and PAL XBOXs . This work has progressed and it is now possible to boot directly into MA, which gets you into Evox with ROE off! However the way this is achieved is involved!.
|
That sounds like ground-breaking stuff yet again; awesome work guys! Presuming that's based on the "v401" (per page 9 and below) then my box sure had some hidden treasures in it eh. (Let me know if you're interested in its "Downloader" too, but it doesn't seem to have the font feature.) | CODE | *************************************************************************** Correct Media flag found in : /mnt/C/T4d530017/$u/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3EDD3F96 Wed Jun 4 00:38:46 2003 Title ID : 0x4D530017 Title name : "MechAssault" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000005 : XBE_REGION_US_CANADA : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000003 Disk number : 0x00000000 Version : 0x00000401
*************************************************************************** Correct Media flag found in : /mnt/C/T4d530017/$u/downloader.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3EDD3FA5 Wed Jun 4 00:39:01 2003 Title ID : 0x4D530017 Title name : "Downloader" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000005 : XBE_REGION_US_CANADA : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000003 Disk number : 0x00000000 Version : 0x00000401
|
Edit: it's "C" not "E/TDATA" as I'd saved it there (before installing mech-fonts) eh.
I have managed to get hold of the PAL Splinter Cell HDD-signed XBE from someone who is on Live!. Unfortunately, I don't have the original version to make a comparison patch at the moment. 
From XBEDump.exe:
| QUOTE | Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3DC88AEE Wed Nov 06 03:22:22 2002 Title ID : 0x5553000C Title name : "Splinter Cell" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000004 : XBE_REGION_ELSEWHERE
|
I have a copy of it now thanks to krayzie. I'm creating the PPF patch now
SCPALDVD2HDD.ppf - created using ApplyPPF3, Winrar to create the rar then UUE encode with PowerArchiver. Thanks to Krayzie for sending me the original, the original sender of HDD-signed XBE and the usual suspects for creating all the exploits!
Copy/paste the below into scpaldvd2hdd.uue then decode with Iceows, then uncompress the rar, then apply with PPF-O-Matic 3.
| CODE | UUEncode 6.5 (ZipTV components: www.ziptv.com)
begin 644 scpaldvd2hdd.rar M4F%R(1H'`,^0B\3`= M,Q``(````'-C<&%L9'9D,FAD9"YP<&8`L`XG!PP=D1#,R\V!G[FW9.D.*V[9 M$G"PME2A"PJJ5"4@Z.$);([44L#HV/T6"=%?1!0@)2Q-L(K"$LO2U6+DU9`+ M\87T`BHM4(`@54H2HBXEEL:*R1VV)3F2*#0I0T'2J%(K6#;O"FQ3T-]7O.>B MQ6WXW[[\>W<6>?MW/,SOYW<\SS,W-SSMXPQGAOU6IR524>N(+[1[=+7UM*,NP<+`//UM2F;)C!GV@^TF0AV4#Y.(E&+N4V^-;Z!`0E]L4!H.M1,5\,P;3OB5(%-CRWJ&QJ40.4(A]=[M8=(24+\'8O\V2J"M+PT:`HRA>M%C+>!D3T!$:5@0[*$K.!,AHX.NPM@D1&B77HE+92)O"WO9$W2+8W]:$1-FA+ MG%<@M6:(%SEEC07T;D;C:+@'HV+DGWIYD4>E-(F!A5R.,>H,PW&YEX9L,00! M-%&B,5P-9]$F*J2<<6J"J)BO`I^G*^MJR6]]FFF(8+!Q"[$+?GMHXKMM\B($ MN`+=$958TAQ*B\;D1#^\\\]V*Y8L3$<3M3BW*@-D=\2D@N-WAM<5T%_%X'D?$Z@80^C[K)$0.YUPT74@X[SO,5F!#)<"T MLL[#[MK(-U?.DQD;,NZR)-'"3D7T5W%#8A&_ZVC1<('V8\$RG%)RO6VOJF=1 MI<*AK#(&!G5+ZJN&ZA>Q930OXT9_<7J"GKN)GFRR$V]ZA+HGG>UQI;+/-L_? M4&;/Z%R*AXK$$0@8#P[/*DPV7JTIN;L[N`E<<:U]AT79U.G6[/<>TIIX[R+/ M!8??/2/W4\ANW9\YXB:WZ1E'?JMMSGJR_F+.\<2?[5&CJ/0T7Z'/%*N%;>MV/])/4W4&PY^]W>G]_TK%HS@P9[+_:PR MP:ZE+1^OS_JX%/*XGC$]'$N_UW'7_#W7\R"#T^M??YJ/9H?FTR>6V7DSB MO0^SRIM-.7$>YZF%^]3M6N#]>9- K*'=>HZW&VZQ.U\>CM6D.+3F,[:>[5(
M-;X,W6^C6_#.K^FTL9'RRX"SL_/K-)-^\XA:KCR];\MG?\6"FPZCRC.!"^#S B?^O:;Q93@[KXU\+^>;R:J?E4F64./JL[;_Z`Q#U[`$`'```` ` end 1069 bytes
|
nice job. will test the whole stuff soon. Now let's go find that pal update.xbe
| QUOTE (BluhDeBluh @ Jul 17 2004, 10:21 PM) | SCPALDVD2HDD.ppf - created using ApplyPPF3, Winrar to create the rar then UUE encode with PowerArchiver. Thanks to Krayzie for sending me the original, the original sender of HDD-signed XBE and the usual suspects for creating all the exploits!
Copy/paste the below into scpaldvd2hdd.uue then decode with Iceows, then uncompress the rar, then apply with PPF-O-Matic 3.
| CODE | UUEncode 6.5 (ZipTV components: www.ziptv.com)
begin 644 scpaldvd2hdd.rar M4F%R(1H'`,^0B\3`= M,Q``(````'-C<&%L9'9D,FAD9"YP<&8`L`XG!PP=D1#,R\V!G[FW9.D.*V[9 M$G"PME2A"PJJ5"4@Z.$);([44L#HV/T6"=%?1!0@)2Q-L(K"$LO2U6+DU9`+ M\87T`BHM4(`@54H2HBXEEL:*R1VV)3F2*#0I0T'2J%(K6#;O"FQ3T-]7O.>B MQ6WXW[[\>W<6>?MW/,SOYW<\SS,W-SSMXPQGAOU6IR524>N(+[1[=+7UM*,NP<+`//UM2F;)C!GV@^TF0AV4#Y.(E&+N4V^-;Z!`0E]L4!H.M1,5\,P;3OB5(%-CRWJ&QJ40.4(A]=[M8=(24+\'8O\V2J"M+PT:`HRA>M%C+>!D3T!$:5@0[*$K.!,AHX.NPM@D1&B77HE+92)O"WO9$W2+8W]:$1-FA+ MG%<@M6:(%SEEC07T;D;C:+@'HV+DGWIYD4>E-(F!A5R.,>H,PW&YEX9L,00! M-%&B,5P-9]$F*J2<<6J"J)BO`I^G*^MJR6]]FFF(8+!Q"[$+?GMHXKMM\B($ MN`+=$958TAQ*B\;D1#^\\\]V*Y8L3$<3M3BW*@-D=\2D@N-WAM<5T%_%X'D?$Z@80^C[K)$0.YUPT74@X[SO,5F!#)<"T MLL[#[MK(-U?.DQD;,NZR)-'"3D7T5W%#8A&_ZVC1<('V8\$RG%)RO6VOJF=1 MI<*AK#(&!G5+ZJN&ZA>Q930OXT9_<7J"GKN)GFRR$V]ZA+HGG>UQI;+/-L_? M4&;/Z%R*AXK$$0@8#P[/*DPV7JTIN;L[N`E<<:U]AT79U.G6[/<>TIIX[R+/ M!8??/2/W4\ANW9\YXB:WZ1E'?JMMSGJR_F+.\<2?[5&CJ/0T7Z'/%*N%;>MV/])/4W4&PY^]W>G]_TK%HS@P9[+_:PR MP:ZE+1^OS_JX%/*XGC$]'$N_UW'7_#W7\R"#T^M??YJ/9H?FTR>6V7DSB MO0^SRIM-.7$>YZF%^]3M6N#]>9- K*'=>HZW&VZQ.U\>CM6D.+3F,[:>[5(
M-;X,W6^C6_#.K^FTL9'RRX"SL_/K-)-^\XA:KCR];\MG?\6"FPZCRC.!"^#S B?^O:;Q93@[KXU\+^>;R:J?E4F64./JL[;_Z`Q#U[`$`'```` ` end 1069 bytes
|
|
nice work!
has rmenhal begun new fonts?
UDE/5713+ update:
Excellent news! Using eh.s HDD based, USA flagged, update.xbe from the US NFL Fever 2003, rmenhal has performed the necessary font adjustment, and we now have a true UDE/USA package that works on all US XBOXs (v1.0-to-v1.6) and Kernels (tested all the way up to K:5838) devz3ro has built on rmenhals work (adding NKPatcher, etc.) and produced a distribution this will be made available very soon. This kinda supersedes []V[]nm6687s Splinter Cell 1 double-dash package, however some may still prefer this method of invocation.
Since no one has found a PAL flagged update.xbe like the US NFL Fever 2003 one (anyone got a PAL copy of this and !Live? yell if you find one!) For PAL users
Using BluhDeBluhs PAL HDD Splinter Cell 1 game engine, and PAL SC1 content, Ive managed to duplicate []V[]nm6687s Splinter Cell 1 double-dash packages functionality for PAL owners . And now put together the equivalent PAL distribution . Like []V[]nm6687s original, it allows homebrew programs on DVD-RW media to the played. However, it suffers from ROE - so the exploit has to be re-triggered to change games.
Since the launch of UDE/USA, booting into Mech Assault is no longer of any interest to our US friends, but investigation into this is continuing for PAL users as this technique gets you into Evox with ROE off! However the way this is currently achieved is involved!.
HALELUJAH!
Ok, this is the part where everyone gets a the cheat and starts breakdancing.
Here guys, have a trophy! No.. better, a pizza trophy!
Well done guys.
Ultimate Dashboard Exploit 2 released into the wild.
Enjoy 
-devz3ro
http://sh0x.tk/
and i hunt this guy down where?
I could tell you, but then I would have to kill you . The hint states "Not the usual places, but the 'other' usual places" .
-devz3ro
http://sh0x.tk/
| QUOTE (devz3ro @ Jul 18 2004, 05:35 AM) | Ultimate Dashboard Exploit 2 released into the wild. |
devz3ro, since this is really a WIP thread, I think you should start a new thread with the announcement of UDE/USA, or Ultimate Dashboard Exploit 2, (or whatever you finally christen it)  .
| QUOTE (db-ie @ Jul 18 2004, 05:45 AM) | | and i hunt this guy down where? |
I assume usual place. However, I wish the root post of UDE can be updated to include the latest version of fonts so people want DIY can get from there. Further, it would be great to have a ppf diff of the update.xbe with a known update.xbe as well.
Congratulations guys you guys have done it once again!
The week or so surely has been a busy one with the whole softmodding scene and this thread: * The "impossible" is overcome with PBL: Metoo Edition * Hope over XTMAXBOX.xbe that seems to be fruitless * Potentially a file is found that is signed for everything, but it turned out to be patched by the ripping app * Release of ldot's XBE finder * Hope over a MechAssault binary but it turns out MS have already patched it * Turns out you can still do it with the HDD-signed Live! Splinter Cell, making the newer NTSC Xboxes finally exploitable * Discovery of the US NTSC updater.xbe that may work for the UDE * HDD-signed Live! Splinter Cell for PAL boxes found, making newer PAL 'boxes finally exploitable * Release of the new version of the UDE for NTSC boxes.
Absolutely amazing everybody. Well done to everybody involved 
The race is now on to find someone to get the PAL NFL Fever 2003 update.xbe... Anybody who has a modded PAL box, and Live! please go and buy/rent this game to obtain the file.
| QUOTE (chimpanzee @ Jul 18 2004, 05:58 AM) | | Further, it would be great to have a ppf diff of the update.xbe with a known update.xbe as well. |
Now that's a good idea  A PPF patch means you can post it anywhere as it's legal.
I would just like to know where to get this at I've looked at the usual places and unusual places but i'm not coming up with much
| QUOTE (BluhDeBluh @ Jul 18 2004, 06:09 AM) | Now that's a good idea 
A PPF patch means you can post it anywhere as it's legal. |
Actually, my ideal situation is to find a ppf equivalent in linux so ldots can make his stuff better by including most possible combinations of diffs in his package and patch up a machine like that.
| QUOTE (chimpanzee @ Jul 18 2004, 06:22 AM) | | Actually, my ideal situation is to find a ppf equivalent in linux so ldots can make his stuff better by including most possible combinations of diffs in his package and patch up a machine like that. |
You could use an IPS patcher. http://www.zophar.ne.../patchutil.html has one (uIPS) with its source written in C. I've just noticed on the PPF website there is the sources for ApplyPPF and MakePPF which will work in Linux.
thanks. Do I use the same program to produce the diff ? Will grab it and have a look anyway. EDIT: got the ppf sources, thanks.
Yep, UDE has really transformed itself into the Ultimate exploit. Too bad this didn't happen before mods were rebuilt for the new console.
could somebody give me a hint as to where it is?
Quite nifty indeed. I'll have to install this as soon as I can find the damn 'other usual sources'. I feel left out. However, this is truly extraordinary. I had NO doubt that Pedro and the others would find this. I went to work today at 4:00'ish, and I was telling myself that it would be figured out by now.
Hip-Hip Hooray!
Damn I feel left out in this freekin european country. If it wasn't for your president I would move to the states. Guess I'm gonna have to ask around some more on the pal nfl fever copy.
| QUOTE (krayzie @ Jul 18 2004, 09:25 AM) | | Damn I feel left out in this freekin european country. If it wasn't for your president I would move to the states. Guess I'm gonna have to ask around some more on the pal nfl fever copy. |
there is country north to it and I love it very much, share everything except the president :-)
nfl fever pal?
i wonder if they would import it to europe
since football isnt that popular.
then again EA whould do anything for a little money
| QUOTE | | there is country north to it and I love it very much, share everything except the president :-) |
I'm packin right now
| QUOTE (Chicken Scratch Boy @ Jul 18 2004, 09:33 AM) | nfl fever pal?
i wonder if they would import it to europe
since football isnt that popular.
then again EA whould do anything for a little money |
Please don't kill my dreams. Anyway I saw other nfl games in stores here.
| QUOTE (krayzie @ Jul 18 2004, 09:36 AM) | | Please don't kill my dreams. Anyway I saw other nfl games in stores here. |
It has to be a MS title as the update.xbe is from them, sharing the same bug :-)
NFL Fever 2003 was definately released in the UK. GAME sell it for £10 - I checked earlier.
I don't have any money, nor Live! though.
| QUOTE (BluhDeBluh @ Jul 18 2004, 09:38 AM) | NFL Fever 2003 was definately released in the UK. GAME sell it for £10 - I checked earlier.
I don't have any money, nor Live! though. |
could someone just grab a copy of it and applies for one or two months of live to get the update.xbe ?
I would definately buy it but I don't know anyone using live
| QUOTE (chimpanzee @ Jul 18 2004, 09:45 AM) | | could someone just grab a copy of it and applies for one or two months of live to get the update.xbe ? |
Yes. They'd have to: Subscribe to Live! Run the game in Live! Use the gamesave exploit to FTP the file over
maybe there are other games too that share the same weakness. We must find a way to let die hard (PAL) live users run ldots hdscan.
| QUOTE (krayzie @ Jul 18 2004, 10:00 AM) | | maybe there are other games too that share the same weakness. We must find a way to let die hard (PAL) live users run ldots hdscan. |
I have posted a link that shows MS titles which has potential to contain this update.xbe
| QUOTE (Kyro @ Jul 18 2004, 12:10 PM) | I can do all of that
but i just have 007, mechassault & top spin (but i can get a hand on splinter cell 1 from a friend) so basically i can get live contents of topsin, splintercell & mechassault and retrieve this content with the 007 save xploit
tell me if i can be of any help |
try MechAssault, that has an update.xbe on the DVD. So we can check to see if there is also a downloadable update.xbe that can run from HDD. The only problem is, the game has been fixed before so may be the font hole(even in update.xbe) may have also been fixed. Basically all those 4d53xxxx has pontential.

EDIT: isn't it possible, as I said earlier, that M$ have updated the files that could be exploitable now? I mean they're definitely reading all these posts, so they might've just updated them now. Guess we'll see that if the files have a very new date.
| QUOTE (gronne @ Jul 18 2004, 01:33 PM) | Wouldn't the best be to go to the live-forum in here and ask them to do this? there must be some europeans having the game, right? And some must be interested in helping out. Well I won't do it as I am afraid of the guy's at live... they seem bloody scary, you know 
EDIT: isn't it possible, as I said earlier, that M$ have updated the files that could be exploitable now? I mean they're definitely reading all these posts, so they might've just updated them now. Guess we'll see that if the files have a very new date. |
That is why the quicker, the better. Well, at least I believe the MechAssault double dash style has been cracked, just not as elegant as UDE.
| QUOTE (Kyro @ Jul 18 2004, 12:10 PM) | I can do all of that
but i just have 007, mechassault & top spin (but i can get a hand on splinter cell 1 from a friend) so basically i can get live contents of topsin, splintercell & mechassault and retrieve this content with the 007 save xploit
tell me if i can be of any help |
would you be willing to sacrifice a few bucks and go to the store and buy a copy of nfl fever 2003 and go live with it. You could save the pal users out there before it's too late. The game will not cost more than 15 since it's old anyway. Small price for a big acomplishment.
| QUOTE (Kyro @ Jul 18 2004, 04:49 PM) | | QUOTE | *************************************************************************** Correct Media flag found in : /mnt/E/TDATA/4d530035/$u/update.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x40A133BD Tue May 11 20:12:45 2004 Title ID : 0x4D530035 Title name : "TopSpin (Training)" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000004 : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x00000702 |
can this xbe be of any help? otherwise i might have a friend that can have nfl fever 2003 but that s not sure, i ll wait & see
|
| QUOTE (YoshiKool @ Jul 18 2004, 06:40 PM) | hmmm - kyro you are from france - if you download some content from nfl and end up getting an update.xbe then reply in the UDE2 thread they need a nfl update.xbe that is non-US |
That's what we were askin the whole day allready
You actually think he wasn't aware of that allready?
| QUOTE (PedrosPad @ Jul 18 2004, 05:21 AM) | UDE/5713+ update:
Excellent news! Using eh.s HDD based, USA flagged, update.xbe from the US NFL Fever 2003, rmenhal has performed the necessary font adjustment, and we now have a true UDE/USA package that works on all US XBOXs (v1.0-to-v1.6) and Kernels (tested all the way up to K:5838) devz3ro has built on rmenhals work (adding NKPatcher, etc.) and produced a distribution this will be made available very soon. This kinda supersedes []V[]nm6687s Splinter Cell 1 double-dash package, however some may still prefer this method of invocation.
Since no one has found a PAL flagged update.xbe like the US NFL Fever 2003 one (anyone got a PAL copy of this and !Live? yell if you find one!) For PAL users
Using BluhDeBluhs PAL HDD Splinter Cell 1 game engine, and PAL SC1 content, Ive managed to duplicate []V[]nm6687s Splinter Cell 1 double-dash packages functionality for PAL owners . And now put together the equivalent PAL distribution . Like []V[]nm6687s original, it allows homebrew programs on DVD-RW media to the played. However, it suffers from ROE - so the exploit has to be re-triggered to change games.
Since the launch of UDE/USA, booting into Mech Assault is no longer of any interest to our US friends, but investigation into this is continuing for PAL users as this technique gets you into Evox with ROE off! However the way this is currently achieved is involved!. |
| QUOTE (YoshiKool @ Jul 18 2004, 09:30 PM) | | Hmm... i'm having a bad thought right now... PAL 1.6's aren't released yet right? Maybe when they are M$ will patch up the kernel and dash again... |
Own up - You're just worried that then I'd inflict another long, boring, thread on you in order to find another exploit - lol  .
Hehe, well, if we do find a dash exploit for PAL xboxes (and we probably will with the pal nhl 2k3 fever...) then there's going to be a sense of... emptiness... what will there be left to do?
| QUOTE (krayzie @ Jul 18 2004, 09:36 PM) | | well at least we would have a fix for the 5713 xboxes. The next series of xboxes in the usa/canada would be patched also then so there's really no big difference. |
Devicing a fix for this is a bit more difficult than before. They cannot blindly disable 4d53xxxx title id or game won't run. There will be quite some ugly patches in the kernel to disable this.
| QUOTE (ThE MaSTeR 3 @ Jul 18 2004, 08:52 PM) | | So when can we expect a package?? |
i guess i'll post the X-S legal version of the SC1 PAL release by PedrosPad. here it is for all you PAL users, read the readme.
| CODE | UmFyIRoHAM+QcwAADQAAAAAAAAAzXHTgkCYAAAAAAAAAAAACAAAAAEl88jAUMAEAEAAAAEMA8PL7 Uib4dOCQLQAAAAAAAAAAAAIAAAAAkH3yMBQwCAAQAAAAQ1x4b2Rhc2gAsMIOZkp1dKCQPgAAAAAA AAAAAAIAAAAArhXwMB0wGQAgAAAAQ1x4b2Rhc2hcY29udGVudGltYWdlLnhieADwDhuG0Yd04JAz AAAAAAAAAAAAAgAAAABAfPIwFDAOABAAAABDXHhvZGFzaFxMTWFwcwCwGjoQy9904JA8AAAAAAAA AAAAAgAAAAAEgPIwFDAXABAAAABDXHhvZGFzaFxMTWFwc1wwMDBfbWVudQDwrm+Hbbt04JAzAAAA AAAAAAAAAgAAAABAfPIwFDAOABAAAABDXHhvZGFzaFxtZWRpYQCwGjoQ6U50oJBAAAAAAAAAAAAA AgAAAACuaO4wHTAbACAAAABDXHhvZGFzaFxtZWRpYVxBcmlhbFVuaS5UdGYA8LS4gyKKdKCQQAAA AAAAAAAAAAIAAAAArWjuMB0wGwAgAAAAQ1x4b2Rhc2hcbWVkaWFcZGxjdXN0b20ueHByALBsvgfM F3SgkD0AAAAAAAAAAAACAAAAAK1o7jAdMBgAIAAAAENceG9kYXNoXG1lZGlhXFNvdW5kLnhzYgCw bL4HcCB0oJA8AAAAAAAAAAAAAgAAAACtaO4wHTAXACAAAABDXHhvZGFzaFxtZWRpYVxXYXZlLnh3 YgCwbL4HM8h04JA4AAAAAAAAAAAAAgAAAABAfPIwFDATABAAAABDXHhvZGFzaFxzY3JlZW5zaG90 ALDA1w3CpXSgkE0AAAAAAAAAAAACAAAAAK1o7jAdMCgAIAAAAENceG9kYXNoXHNjcmVlbnNob3Rc QmVoaW5kX1RoZV9TY2VuZS50Z2EAsGy+B61idKCQTAAAAAAAAAAAAAIAAAAArWjuMB0wJwAgAAAA Q1x4b2Rhc2hcc2NyZWVuc2hvdFxjb250cm9sbGVyX2JhY2sudGdhALBsvgfLjnSgkEsAAAAAAAAA AAACAAAAAK1o7jAdMCYAIAAAAENceG9kYXNoXHNjcmVlbnNob3RcRXh0cmFfRmVhdHVyZXMudGdh ALBsvgeusHSgkEkAAAAAAAAAAAACAAAAAK1o7jAdMCQAIAAAAENceG9kYXNoXHNjcmVlbnNob3Rc RmFjdHNfUmFuZG9tLnRnYQCwbL4He4d0oJBPAAAAAAAAAAAAAgAAAACtaO4wHTAqACAAAABDXHhv ZGFzaFxzY3JlZW5zaG90XExvYWRpbmdfRG93bmxvYWRlci50Z2EAsGy+B1TqdKCQTQBxAgAAEsAS AAL/0LzAwAHxMB0zKAAgAAAAQ1x4b2Rhc2hcc2NyZWVuc2hvdFxsb2FkaW5nX3Byb2dyZXNzLnRn YQCwujBbEIEQvpC12JNUaoxRw6CsLCqnoks+5e63M/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA AADA+XZgdKCQSQAAAAAAAAAAAAIAAAAArWjuMB0wJAAgAAAAQ1x4b2Rhc2hcc2NyZWVuc2hvdFxs b2FkaW5nX3Rlc3QudGdhALBsvge9hnSgkE4AAAAAAAAAAAACAAAAAK1o7jAdMCkAIAAAAENceG9k YXNoXHNjcmVlbnNob3RcVWJpc29mdF9UcmFpbGxlcnMudGdhALBsvgcnvXSgkEMAAAAAAAAAAAAC AAAAAK1o7jAdMB4AIAAAAENceG9kYXNoXHNjcmVlbnNob3RcdW5wbHVnLnRnYQCwbL4HaEp04JA0 AAAAAAAAAAAAAgAAAAA9fPIwFDAPABAAAABDXHhvZGFzaFxTb3VuZHMA8Bb5kB3qdKCQPgAAAAAA AAAAAAIAAAAArWjuMB0wGQAgAAAAQ1x4b2Rhc2hcU291bmRzXDFfM18zLlNTMgCwbL4HFX50oJBA AAAAAAAAAAAAAgAAAACtaO4wHTAbACAAAABDXHhvZGFzaFxTb3VuZHNcZHNzdGRmeC5iaW4AsGy+ B1KxdKCQQAAAAAAAAAAAAAIAAAAArWjuMB0wGwAgAAAAQ1x4b2Rhc2hcU291bmRzXEVjaGVsb24u U1AyALBsvgfn83TgkDwAAAAAAAAAAAACAAAAAEB88jAUMBcAEAAAAENceG9kYXNoXFNvdW5kc1xF TkdMSVNIALCysAbdDnSgkEQAAAAAAAAAAAACAAAAAK1o7jAdMB8AIAAAAENceG9kYXNoXFNvdW5k c1xFTkdMSVNIXDBfMC5MUzIAsGy+B76BdKCQRgAAAAAAAAAAAAIAAAAArWjuMB0wIQAgAAAAQ1x4 b2Rhc2hcU291bmRzXEVOR0xJU0hcMF8wXzIuTFMyALBsvgeA6nSgkEYAAAAAAAAAAAACAAAAAK1o 7jAdMCEAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNIXDBfMF8zLkxTMgCwbL4HjCl0oJBEAAAA AAAAAAAAAgAAAACtaO4wHTAfACAAAABDXHhvZGFzaFxTb3VuZHNcRU5HTElTSFwxXzEuTFMyALBs vgea/HSgkEYAAAAAAAAAAAACAAAAAK1o7jAdMCEAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNI XDFfMV8wLkxTMgCwbL4HpJd0oJBGAAAAAAAAAAAAAgAAAACtaO4wHTAhACAAAABDXHhvZGFzaFxT b3VuZHNcRU5HTElTSFwxXzFfMS5MUzIAsGy+B6csdKCQRgAAAAAAAAAAAAIAAAAArWjuMB0wIQAg AAAAQ1x4b2Rhc2hcU291bmRzXEVOR0xJU0hcMV8xXzIuTFMyALBsvgdURXSgkEYAAAAAAAAAAAAC AAAAAK1o7jAdMCEAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNIXDFfMl8xLkxTMgCwbL4HV/50 oJBGAAAAAAAAAAAAAgAAAACtaO4wHTAhACAAAABDXHhvZGFzaFxTb3VuZHNcRU5HTElTSFwxXzJf Mi5MUzIAsGy+BziydKCQRgAAAAAAAAAAAAIAAAAArWjuMB0wIQAgAAAAQ1x4b2Rhc2hcU291bmRz XEVOR0xJU0hcMV8zXzIuTFMyALBsvgcG2XSgkEYAAAAAAAAAAAACAAAAAK1o7jAdMCEAIAAAAENc eG9kYXNoXFNvdW5kc1xFTkdMSVNIXDFfM18zLkxTMgCwbL4HfPt0oJBEAAAAAAAAAAAAAgAAAACt aO4wHTAfACAAAABDXHhvZGFzaFxTb3VuZHNcRU5HTElTSFwyXzEuTFMyALBsvgdB2XSgkEYAAAAA AAAAAAACAAAAAK1o7jAdMCEAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNIXDJfMV8wLkxTMgCw bL4Hf7J0oJBGAAAAAAAAAAAAAgAAAACtaO4wHTAhACAAAABDXHhvZGFzaFxTb3VuZHNcRU5HTElT SFwyXzFfMS5MUzIAsGy+B3wJdKCQRgAAAAAAAAAAAAIAAAAArWjuMB0wIQAgAAAAQ1x4b2Rhc2hc U291bmRzXEVOR0xJU0hcMl8xXzIuTFMyALBsvgePYHSgkEYAAAAAAAAAAAACAAAAAK1o7jAdMCEA IAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNIXDJfMl8xLkxTMgCwbL4HjNt0oJBGAAAAAAAAAAAA AgAAAACtaO4wHTAhACAAAABDXHhvZGFzaFxTb3VuZHNcRU5HTElTSFwyXzJfMi5MUzIAsGy+B7Kw dKCQRgAAAAAAAAAAAAIAAAAArWjuMB0wIQAgAAAAQ1x4b2Rhc2hcU291bmRzXEVOR0xJU0hcMl8y XzMuTFMyALBsvgfJ+XSgkEYAAAAAAAAAAAACAAAAAK1o7jAdMCEAIAAAAENceG9kYXNoXFNvdW5k c1xFTkdMSVNIXDRfMV8xLkxTMgCwbL4HykJ0oJBGAAAAAAAAAAAAAgAAAACtaO4wHTAhACAAAABD XHhvZGFzaFxTb3VuZHNcRU5HTElTSFw0XzFfMi5MUzIAsGy+B5/ldKCQRAAAAAAAAAAAAAIAAAAA rWjuMB0wHwAgAAAAQ1x4b2Rhc2hcU291bmRzXEVOR0xJU0hcNF8yLkxTMgCwbL4HOSt0oJBGAAAA AAAAAAAAAgAAAACtaO4wHTAhACAAAABDXHhvZGFzaFxTb3VuZHNcRU5HTElTSFw0XzJfMS5MUzIA sGy+BzqQdKCQRgAAAAAAAAAAAAIAAAAArWjuMB0wIQAgAAAAQ1x4b2Rhc2hcU291bmRzXEVOR0xJ U0hcNF8yXzIuTFMyALBsvgehjnSgkEQAAAAAAAAAAAACAAAAAK1o7jAdMB8AIAAAAENceG9kYXNo XFNvdW5kc1xFTkdMSVNIXDRfMy5MUzIAsGy+B2gMdKCQRgAAAAAAAAAAAAIAAAAArWjuMB0wIQAg AAAAQ1x4b2Rhc2hcU291bmRzXEVOR0xJU0hcNF8zXzAuTFMyALBsvgdWZ3SgkEYAAAAAAAAAAAAC AAAAAK1o7jAdMCEAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNIXDRfM18xLkxTMgCwbL4HVdx0 oJBGAAAAAAAAAAAAAgAAAACtaO4wHTAhACAAAABDXHhvZGFzaFxTb3VuZHNcRU5HTElTSFw0XzNf Mi5MUzIAsGy+B/MSdKCQRAAAAAAAAAAAAAIAAAAArWjuMB0wHwAgAAAAQ1x4b2Rhc2hcU291bmRz XEVOR0xJU0hcNV8xLkxTMgCwbL4Hvxh0oJBGAAAAAAAAAAAAAgAAAACtaO4wHTAhACAAAABDXHhv ZGFzaFxTb3VuZHNcRU5HTElTSFw1XzFfMS5MUzIAsGy+B7yjdKCQRgAAAAAAAAAAAAIAAAAArWju MB0wIQAgAAAAQ1x4b2Rhc2hcU291bmRzXEVOR0xJU0hcNV8xXzIuTFMyALBsvgf9sXSgkEUAAAAA AAAAAAACAAAAAKto7jAdMCAAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNIXE1BUFMuTE0yAPCY anVLAHSgkE8AAAAAAAAAAAACAAAAAK1o7jAdMCoAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNI XE11c2ljX0Jpcm1hbmllLkxTMgCwbL4HIqV0oJBNAAAAAAAAAAAAAgAAAACtaO4wHTAoACAAAABD XHhvZGFzaFxTb3VuZHNcRU5HTElTSFxNdXNpY19Db21tb24uTFMyALBsvgcAanSgkE4AAAAAAAAA AAACAAAAAK1o7jAdMCkAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNIXE11c2ljX0dlb3JnaWUu TFMyALBsvgcEsXSgkEoAAAAAAAAAAAACAAAAAK1o7jAdMCUAIAAAAENceG9kYXNoXFNvdW5kc1xF TkdMSVNIXE11c2ljX1VzYS5MUzIAsGy+B8YcdKCQPQAAAAAAAAAAAAIAAAAArWjuMB0wGAAgAAAA Q1x4b2Rhc2hcU291bmRzXE1BUFMuU00yALBsvgf783SgkEcAAAAAAAAAAAACAAAAAK5o7jAdMCIA IAAAAENceG9kYXNoXFNvdW5kc1xNdXNpY19CaXJtYW5pZS5TUzIA8LS4g2rBdKCQRQAAAAAAAAAA AAIAAAAArmjuMB0wIAAgAAAAQ1x4b2Rhc2hcU291bmRzXE11c2ljX0NvbW1vbi5TUzIA8LS4g34c dKCQRgAAAAAAAAAAAAIAAAAArmjuMB0wIQAgAAAAQ1x4b2Rhc2hcU291bmRzXE11c2ljX0dlb3Jn aWUuU1MyAPC0uIOL0nSgkEIAAAAAAAAAAAACAAAAAK5o7jAdMB0AIAAAAENceG9kYXNoXFNvdW5k c1xNdXNpY19Vc2EuU1MyAPC0uIOeN3SgkD8AAAAAAAAAAAACAAAAAK5o7jAdMBoAIAAAAENceG9k YXNoXFNvdW5kc1xTVFJFQU0uU1MyAPC0uIPr8XTgkCYAAAAAAAAAAAACAAAAAEB88jAUMAEAEAAA AEUAsExeVbCfdOCQLAAAAAAAAAAAAAIAAAAAYH3yMBQwBwAQAAAARVxVREFUQQDwKGEXalN04JA1 AAAAAAAAAAAAAgAAAABiffIwFDAQADAAAABFXFVEQVRBXDIxNTg1NTU0ALDy+1KRpHTgkEIAAAAA AAAAAAACAAAAADCb8jAUMB0AMAAAAEVcVURBVEFcMjE1ODU1NTRcMDAwMDAwMDAwMDAwALBOclOJ KnSggEgALQAAAC0AAAACj05SfACI5DAdMCgAIAAAAEVcVURBVEFcMjE1ODU1NTRcMDAwMDAwMDAw MDAwXGZvb3Rlci5hc20JYWxpZ24gMTYKCkVPQzoKVExTOgpUSU1FUyAweDE4IERCIDB4MAoKRU9G Ogox23SggEgA7AUAAGMPAAAC3ZSSCACI5DAdMygAIAAAAEVcVURBVEFcMjE1ODU1NTRcMDAwMDAw MDAwMDAwXGhlYWRlci5hc20MHVDMzNG8mdW7m/hRFFAcnmxwOWSW0TepyNu1jy2Oht7bQKLsBaSj Z2L0MJFSR371oibljaKeYSimZHKujb2qBxpLMPMwnOZ6H8Zz+EH7nPxIICPo6V2/a9f9xLHbwWA6 +9X7ct3DgJw+rSc5/JPry2ye+3ZtW75PlZv4SV5Pyg9vESpWAS99arC5FpnfEtfUtRFQelyHrcIP nizH00nTBCQ+TQduL8+q2o4THzaQbG+U+luVSfo6QVhyGl7A+7K16VSCYR8E6hxsQytp/ZKFrIQt MCvSmLGj+YRBgafk3Qf9uQn4oYV+Uur5U6rDYAMjpIZGmNC+nzrTIlgN+M4ClrUlfMsKnbvXK/p9 NSpsRr13fgAP2e3aTMAEoOHp4PW3wtOd8w6tzlrXn3mA5XstWS6ohP0KXwUeYPE3Tr8FTszvnuZX Yxfnp1jnDcs79C1OeN7FLAWsHP5zQPxCkn79gpg0SEPTO60SxnyDGwXuvmOYrpoiiEEuO600jO44 /oM3RlgN4YcLfxPzZuk/sOCLPtuc3H7LPLUpIZ2x15JEm59b18nYijIxq92Tz/4eifNwAAzyAoTl AErkOJTEDOukAw0EcJEvHSA6m6JvBXWoG5bV5y4GiSdDF4yY0gWID0o7SugYQ8CdeVo8ZXVIFcu7 8jh+GCS4ciGJXkdgaBUilnCJMWzakaDvzLbCoHWGStyrQz1A+Lzxj+YmCLuVc02jtPrKrCe9CbGZ 8rvi3tn5RMni81QaRFM/FG9tH30aOMgDfdFIgsNuYo8eXUWQFe0PeQfAkrXvE5lCt32L8CmTsTc6 tdz7jvRqiN/q2jJ8fL67XFY8CpSmU/+kBnm5SD0Ngn6tJ9JVCb8Y3QL27PpVnUW3GOKueB+v1LZw nDpo77J3nTYoSgp9YTernmnVPh5EQ1NSrDHGVmfc/kC/Ma/1s/K7TK2dgxwExa6Xi5fGj2cRsqQk 8pOTueA5DPtOxjKNN86xqVWZjRABPZQlRc7Sj90gYV9tVBGI4/+GN9MEoIwYZ95C4febTAkLjdlQ 4+NAKlDQlTKgbMC/AskqXfF2BB5o5pNS5sTibQlVOzHOQldOxzjD4oQJexOjV6jCWP0fZV9Lh4+L 7+gaGgVasb4yLlS9Bn0lXXpWwEl9DRTVsEW6/KJ7eS4eQvW4ITHEDZw3fjbwKtNV9z0hIpu7y6cA ccmciYEEUI1I4EZMwtfGhaGB5XN0qH0JGiV6UhhJ3YFxN+jB/5rd9GFy7zWfBvc/7GED3m2+5LXL p4QDu1utxXErjaXCaYuTngEibR3c1DzUkTl7A2iD9qS+q32hpKHsCzEG6GL0XIu5M20zVb2Xtgkq 2qfzF/HZLJhNNhqW7aYxauNhAmn+/MwFTNDbwUXtBNHEF8Z/GnQgDcSV6y6dWiUN+2wPVy4lC7B2 Bpfj+cxWUtj2ST3CwL7mOd8K/BUo9hTixdj1WjRdU9Ixj2z0GPFkVVM9K+t4VejAvISCkDm2IqH9 BOkpmC3zJKErLQwft5ZiylhLHn+oueM6WESbLyvRjBPiOb20WukKXr/fxuuLxfJwERhV/VTeWZxJ cKQMz1tAtY65zALzOM+QvgQ/z2jGWWq8HQF1XWSKP5mhThB0ZIfgvODEBbtAbRdyleXP5QZILNln gnm8xkDmMg4w4cycVRW+4S9iaZX6xZcmrKytVE+6SMUYvyYSzplSLbnP45F92gysuB7oWuDuTA/o Cd2ZnoXeaUm9UijibnRsOFB4XqsTL4iJD6Gy2bHqlOJyvCJ5KtRS9weuRqqwlg9zetet21t6tiD4 33Od3XIWB/kAA70oySybkgOXR31WeA0+1ClbfDVHnAu1XekECS+te/q+TmvWrdYPDD77dEoH00rO XLvPbtf85QxHE/mjnzD0w3GBI5d2fO/v+YiTegDWDdR3w+7p4llvYsdCLFPOX7ZX0DwZmp2cHTk4 5EwzTgEZE1sQm4DTDpxHQO8OKL2Ik0t2AJLm6rH4rQgp/kzlR9wJ+EhqHqiruvFpFX/U4JB0oJBO AO4EAADYFAAAAmZ/VU9qtu4wHTMpACAAAABFXFVEQVRBXDIxNTg1NTU0XDAwMDAwMDAwMDAwMFxp bnN0YWxsLnhiZQCwoJJcEgFVFMiPzYHj0h8FcEsfgAtoRx+FrUr8KiyWuFErbVYKWpAfhJEiGIgk kBooeClxtCSyxLEqo4txq4OZRRKrKtGJjYQxklSjDKYqCCWZS1G1LmHxp8KKICQlze+JAix3yW5l /C3/BXcze7ze+5veb3vt/Hd/zHO733c5zu953fZz+52b7Jsnve/CT8ZmRD7Oqhjm7k+FReobiKlp V2OwOZOFZ4sqvRrpWIRH/2x+m81nFLzZuZylF2vzsJVmless9yihh7nCtfkovVg4fQ0lREvXJqPD xIrb6y/6xKy+6U+e3q+7/Cb1zPdTTvNc+J6qLvpe3IdzUe/AGHzneCfjNmwv/uzqn4LKEmNzA5uR PHeHudHHdjU/FN2vg0XpvKknonKhVkcDzLdpzLiB+myhezA5zkUNVCRGPNxXBvpyiy+tZ+2jyEpx lqLkExea7PtUPPayP6ZvfQB3I2L/xJI70Dkc/fNOQdx0YT3jeW3+drmEDJffCJmPSv/Om6vVxmto PITwYrP8+uVRmlS5yMS19hpeWq/Gt51DoH8ggw4skJo+OOZGLr1r96+JmC3pGwdivCw815bJ8MEf 82L1PyjOF3nwMD8nFkN+38v6QkFfotionx2GbYYgP/w+DHYdyRgho7kY3FI8aR2xuHn1FKMd5qBi aXvVsNb1+0vPn4xOfhT7vvDbf2mSI4iPIkCJhv66ImQmSSP/9YQhCEIQhCEH0WiIpPFSCKifSN1C LlCWCWiUCoBakwE2wCqj1MhMJdtII4baysfHpZaS0aM/iklK4ZT3dIjc1KTMftZZJopmOkCMGdO5 4fUEqvTXx84ekphTBpUNII26maeRi4omz7mRmD+AazLI/6DZthNjWbZYraYi4sga+zVu6Qxk3Pad Ia8SfGHYmBafqeUWYMgyuUCx4qwM5oX98qK0Fxn0WedgRL8FkRdcMRgp7Z7s9kPZ9/ahCNX4UTpL zwOuskBiX1wTuYVWEuaQOXfC5GyJgFdOreUxhBr3IwAFdjBMqUh3Kl4sUvTZMZcrjwW2FQaDGPsm z1AwOFmnHgR03+Hoafk9sctK3u/G1hvhsTbpFeOV8YhdbUI/B+qqmXfDvS1G4i1B3PDzLEGDy7Q0 UOxV30LnGdw/HVcPkoTBe5ZduUb+fLqa4E6uXs53efQPIqe1y12Tkmc1Uq9VdKIVoNXMY5PRF44S RRdmU7oZ/yjeb49gwNWrMsH0Y0z0XsLCDCMklHelmNwB1RIltfZ0DBGNiBMcGSgYHByhN6QxcB2n GtGk5qFZR0/NXT095O1iu5p1PheSXpccLhlMeBQaakdHaGj3tw6GtF5A/z/4P1dMdxXsbJcW7SQR ZnX7JBsWMcZ8R1xLDEKXIOwrPsYXkVZvHwtXPXnKjbZimwm86fARN5SxezEvrBhXXzHDlNPu4y4c dDm0jYyL8sL6rx2h1Xb40QcYghAs0HL9YXdiuxLmQKwLgYQcq25GZQ9ApRXRkqaErOtahpfbAiNW J/PC4Iwrmi0p638DL5hWzHWXRaaXC/Yuwd1qF2lsGtbbgsQqwWaPN2m6JSvCxobqwxaBQF4oZxw4 3oW5FTCggykA/XhR9K32XeL+n2lNd3ykQVknchpBdApoYU5rBNYbDVfUKd29KVQivI+FQiJE8Buv rhu11GXqpYH+0VdBWopUOJ7/NiA6f5RC63SggEsATAsAAFgfAAACxlVNmQCI5DAdMysAIAAAAEVc VURBVEFcMjE1ODU1NTRcMDAwMDAwMDAwMDAwXG5rcGF0Y2hlci5hc20MAREMzNE8ld2/4n4Ue0cx I+baB8l4wcOCKJPbo1yN9G+fQCRiApEpkxFIrSSm09+9cFhTbSJKvMw+KbU8N0d39rQnpWZd1l3e X5GfF7/BBV5WVVJZWEpv//Z4hofTr7+TM683dMysw5DuR87LjzMxYXG4LGjA3W/IbxvsnNOjPmzP wRQnY9kZW3vLSuJp8ZyZ6Q/7ZRtCy2hpUQPQ0qJH6bSCRzOVrWLaVuwQHJ/P1IBnF4eUpmCXVlpn NE20Qtb0Zg/8H4xQTVES6a3Qd/TlfkJJgnJUHRA319zjuuEBSGC/a/8DkbCJ2B1+HhsTdbDb3OLi Z2iZaxX7bVilZ1m8Tszex+rm+Hz0yKfO17C9nl4OhGDTAtOxSrZWXqDqkZ9cLYDWskBmhaIUnP4h 6p2S1tDigZ8tnDLxM1t+f7pgn4Ci2HyPJyxQ2OEh7XQn3c3v9t7l+avNzdPz6F/9DRGULHW6mlLf fikb1LSnOwQxcY+Nl1aZhc2RttaK3bpcbGibOd6IObcZ7Zmc8YdhGHEP4n6jKbLK93lYl4kY4Gt8 hNbZnZaBabwUMu/KXFloron5BrmMvO9kyyZpXP/nNJn2g3TABPbkvPPP4dpjd+XeKQmeZmH2t5H4 O9fRdDfMaaMP0Wzy/DuI5CzZIbf5bi53O+F2TT16QcDcMO/LrSQs90VHC9TsEWeSReC35jbmm/OQ PvlfzzV9L7EkMncDm4Jb6CpO4Mp/5A7Kv0e1Wbjq1zPvihQ83lZ25YXFpgmedns3xJtZl4+uw7fm KgsYmc/DLbSAs524IXYYvwzC2b+rfvZkc3+kH7PdL62bDyt9rb13eFaNwQxcr/dK9HrekNmX74YH 9H6wZXuoaCTA7wlSRTEG+fPgedwy9942X71GklNvJdUwz2HN5WiQ0MyVbDW8QHchvn7ZoNbawHer 5LTbSnt/L8wffa2nYz/lz6zESKFH5bKmUGWjl/+rjPNWvdH59HT7+Vf3GN/tnO/ryThQ34PKA3BN sLzWudjcRXz+2lTsj/bJTW+P4+ZaesQi2PETbD7rv0/cyTEpZ0DY4gATTDkzTVdz4Q//ECDr48Hf JA5ACiQ24U6jST8VnV6GkkRFSG6YYByy89Rwe+7XBJc2fbXGGdA0RednVDXuPDAfW3DAnQk1j2PE XYFjhSoCbjGQVzhKjaSEZvMDuXtaKRfvoISVKenQgZUnsEUNp/K3OyIZaOj4C3TraQhLpUEA6Ekf OrccCllHWoxy2gK4zGx06I+dW44FQOOtRjgVHo61GOBU2jrUYGwcG+mmFwKyh1jK+Tcdy9htTLwg 1n7x8Dkhxt9+BnDj/C6arCRAfM+REt3uOX6J2jbwizcdeqkFdZKC+IKFnooh6gSk4FIjudk39emV YO/yyFSeFntbHYPPPhNwkCQ9luzvNZfVJd50Ki2x7BpX/a8Re7N6659nBoEBw00RMh+w+6jYafLC DO/jg0+iJ8/dXXfziwYBOIXdJDtEXG8o5SYsO5cV2v3UH7HLgN4AthGzPZ6Gomb5qdeu9SyAz7zI WtkoBNuc+6zDKDMcgLVj1STO6rn16a1IayLGd1v1PLUu9E58n6LyBXnKWpIV+fq663UJ+pUA6zal 1Ia6NiVIqTZwjksjYdA2HSET8I5Yj8FLi0lY1yIf+3vIO8MszGLed4k+bscV0Xx8fNVL3zbsTLr0 6+zoyG1xIbaesnf6Dnp2ybh95NNVBVVaQBAO6WU0aYNLyXdJg4sth9kJx9fpAvjC7vOrsxFpIeUg gW7kUvVQO/mIUF8GnRKETwaK4GYS8B2Z2Zdv2cL/4LzTDj4zsgHDJ0Xfmb1sBgd9URolPKEICaRy dTjPAhU1vgRqcX4EtybYM7GNliNhkCTALcCIOfhTNxqXAmDTF1VGL3jJOelPc1FlYdZJiRT2SBQs 7167DnlyhOrJkHFBf0hM+1/M87sfhpVfNZKQ2d4qmDMKykYeadZeFKomuCzH9DSizXT8uR6PDkLh /0Yl0I0bdy0Yo1KO0Yk6lFDKnBcplrUAUThKBgQRjyKwlfkZBe7egOd6epfX3wwgObMPVsHfoc15 XqiIC48oYvnc5KN6igmbPB4CZCx5+lEOulhtOlxXP7J9Y2MECfPlOY58tl7P2ArcIYsmEeO6GIfh eZdDp46Ik5gdLPYW2aFwgMNBAuLgSXECUQbSq2O9F3BdbjyXZRss+YlgfHUCCA/hB8bvIA6A0yiD cIZeTbeQmO2Ca4znwHoJRQWA5YbA/Ov5ADUiXotLZB1gZquwKv13nG8ScRhdT2Vw/xXK3TODvktD CPNmOHIOpht1/FE3Pl1tdrXI1A6FcjE6008FjBtc/xw2CtOKoAKoVUIXckorMA1JGyIr27OyZODz 1h6csPqhILxDsqi2CED4Ce2/YJVJC0KAAfsVKAScVGFCQ5uVprVDtdT35hJZZBfm/303TF1v0O/u cyXJvGi5FTxBX01mZ7C2bux/TziPjYgCTFxI9ZZuU+kOdTxA7GS07NprFltwa9DX12AQ/5k1uQu7 w1rXUdIsDuHAbPN9KRXaoxqMTZytQWC6qUtublA3DRXKawdgYhNVQA9RWysmf5DhdOeAwAJHSFAW 2xfUtXgaUSltYZakLjNnBrtIKuwqgxLqjH43E7alyWaPCgF0iWUJRUzklleGqgRPqggeB5cvudYL cwT54ZhlJ+k4OEtvkQ8DC7WYOM12gBTMNJ1HdKw/4gzJJVFUhfhnqS5IIcdWHwPWJpVx8+hKPPjm ILWxsdwNmF73KDk7dIgSCxGBsLuGlILpe/wQdFibZBwvbdThF2l5dh+iTvDu+txJu/xnuswQuwdw /Ro4ndFT3+w4MxHrCY7b3lTs+ad5Ew6Ghz4CsVaoffDxKW//d9oBE+/GUrzhpUjrs3sqni6GjRD+ KxUlNaphkvH7txujTHLwpjN1J8sb4MT+owMtl5/IYbUe0C89glXDqvRj74FJp1rrobFtEuXZPeA5 ijbL3HZtyoBMdGMHELzSXfk4CRghbwygwPvpEMRt6oKqIcQfjXVLQ4nNa97tm8/dA4SB2MxFQskz DSt/nucahedwlMWi7UcTtKqiZDyo2LHSmlbcrPinzRW7yp9EWIw2q0IUQHYJ53jB9r1R9oilOkhf Fqgl3Bgbje4kCSG9eqrWn3ahYPpjncHmEOxBVnhD2q7kT3ecFMHEFQ7LFValSitfSWGQp5UALJt3 aUBJkPEjThbJ7lz4XnmHdAXOGwuwK3g6pkiiVjSAc9ZOmRmd668orjJKH4ayI15LhyNTVPPerVXK O6Z7qOm0+n6um04NJte+5H26ejZRc4x+Kq9pMWw/65GUWFrSw4jrNJhsJezeLuKXLbE/jeUVo01k Jw5hi3pTCjybTdeD0kFKNwPFATUWEVE2EbQtqIzKuG18OKeAKn1Wu6rc/an2VlYSFEr4v53hS1po TS+erHFkBUikp4JFFeNISn6khLH4JS2sLsYbT63v8JZvAMKxsdguVXD71nVte9fFS6qolLInGk7S GnYdyNSrLUB21NXw528oH0MDPuUNckPOrkv1CzLMMfY7MtoV1lM9CubSE5xzUFRNBNASVUFd9MUW 03hO0jpSSFFrIrSsiaLGlO4L/g/Z+R/m2Joi+LYpcF0tii+lXSkJpimwo+jBTAfinSs3hLSGpL2b 8fqHtuI/wmpO0O+hShqia+pMWb/nh9lytalbpVK5bp02Fpw5FY/TZXS8KXWKYD8aHoAvqZ1SCOLw VlhP7CuBOpjFPuXrpn3Fon4iMUw/qTzVtT80+cpGsJT2y38thjAoGnHVErGML3hNSiUUkhG9t0fg ZR6W0n8X9yx3Mwdf5lly6lf/TcxB69iN/9RaCnSgkC8A4QYAAAUOAAACsffU59Ka8jAdMwoAIAAA AHJlYWRtZS50eHQAsDicHAwZkRDI0byZmX/6lvA9yKTyBNBs9EJNBIWo1tzY0iQEDJJqWpRW8y28 yGZl55l3g29561aBAeZd5VVeNjYEm8AkaC3d1dXXo7ruqnDNfBF111Vf2lXAO/v/e/Pz/LltbP03 PZs7ZuPg4TWzqgvpPM+b3He5zUbv/h7XY24VPRHhjRNvZZr9351F0x4zSJWaZCpUyKhvxINgTMbF AehIz5DJmL+Ch0FLKiQy0myJnob5tCxmtB1E0z8hjcqcC40vvwyYTPHpNfYR0Mwpy/leHt6YKNDg HsUAklbz9pid4w7lRiA4B7dLny+v1piDAtWUW4CgDfxQrga9Cy9hjN+5hbDPb0GWYaLo6qo0AwUD +ysFWtoEc71EKPgRrGYkjqGKnW7ttAYJNSilkrET0V5LH5/k7/XZMCc0Ku2+SHNYvpueouRETHCk YEHGYM2oJrLT/QC4iiTiB8VQA5jHMMx321EtbwIiPRTY9XaKQtQQLRSEpQ3fn+9w1OQTJqirq3cy g89BcL1DLhq1eZ7l6lzVHLb2gEjASDRSwlndti+Oxj9vYXNjpTagsL6FBwausSO5uB1SaPgU+jQU c3xXzJaRPukFJkXAMepZoUzDPQ99M7W+Cegtw20yGr1qARPUMUA5b54WOAgNX5UugD6t2kpKpyhA Biu3kUU3BVKXN//+dgaw4ChNyNXa9Ufk1hWsDBQCKDXYCn4UfsJ4+pLUMYRho0enjeuypNMmNwle G78bgSMUnuRAEj7rdvXjhepLQ+Beu0zDIgH2RgqGibtjvoctoXQXOEZWAl55BeZqisPIt+xIZGvj MIUyzcs3rfBe4LPnvXb3Dcu2/PZ809kG3iCaQvQQbsYiq7gxVagC44v1p1KiHLZZnbzBAd3H89ea 0/bADSEODS1Guq1ri+5NrnZibhFWJTUGtXn3hDg6iUPj+Xevc3dVl21/v8HBy/be4wfh4KdNOuXo hOXp8ssVJat6FtMcdBtR2bmRjodMKwdvbYR7RkL4Uy38bZnmHzFN4IbqAaiH9YvSFNbcPrVP5K4y 30C2uZheO0ZSXSfD7kS+x1tKB7UYyFJFtb39Y0jCgdluOAKaVMkldUD6fT8OK9c3jXvE8wZpCUnT Z6Kd/NNcSQgJKPhQDGkOwfOyEm9ZTer+IWgfpOuaG/OFHz86B2Xky5OkwwLUQ/xLkBe2DcBUg7u5 58w+3e6TrUzjQ4t/S9gfL8XyfAyGxQWSh1eQXqs8PvPVrZAgb6MUknsgu4wpgCR3h4x/VfC/kkOF D5CmnjfDZVXMJ4JgjvAagFc1fJebPM/cAkqJjfKBtIEWKsdpD3uLmCdNe9zfKvRoU6C1/qsG4pHi HQaAQoVSnkVgAzF8ReuqPZ90ZoYFXQU8QuLGf6H9AE+sSljGx5XB8ynpesBF2oH37EsuAIuLeg+/ OwpgyBSfXYmDteMRakSVIH/F5ADjuVKciAigjv9TGxuKEE8BTugB66U8ZDMzPX3gNC6BXDdCC2hQ xfG3dWQoVVoFz5imH4aWPUWA6Hs1DYFm8QO3imhWgbyTSWHdiDYeywVRmZhKzVVZhV2sxZ3iQuzU +svYqEpUyZ2MBb/r06EvpnJAXlwcQXF8Bag9L0KJVDRy8LGBYJR0UNmheCx3fxtTc6frnTzpkSQu OhH09M+/QWIavhzkE4b3Q2+sQ3XxljEeeQAyn/4M0K3SR05WppNBW3SsbhyKgFupkOLyhW4idQEY uvRBhHhhuYetpwwPKQIhHFl8TDpJ5NnYY5eoTQxQDPOxxgiDgz2oeZQPDntNFaT/nP0CbHKErziw kTNGBU3v82hlPDMN2GLxfN15RZ79fbC1jCVrmwVn+1FC9z55H6SeRoZwc0bYWnE1aXMJPKOo+WRH BSqemHA2KEpyiv1V9qJOC73xx0AYM7nA01rUOE5xMYrVLrbHLRQUl9s1ICGP4CY2tRztrhpdPjz/ W0WO5xhlmLURbecEOh7NbaE7WefgD20R0kSGz36pyEjgI3KFziTSMCI+zzi/Zy1N6At6q+VlGAWH 5rdyyN+79C80LHJ5XGcieTr1MsZRYCwzXhHKUGMP3YRAaGnZr1zskBMg3uBR3YkYQ65OK4bU5AxG sq4mk3PqHrao8gF7hNh/QtSuwcGueV9M4cWuLx+Wh8kohzLOxzh37HlDPMWHxQWSKuedXfxH62g4 2Qhjl8ZwtGMPR0f3t5aGmYJcfYi60v+PGIcjsPpws4GR2veqxhihnHV+8U8FtA/s2pLTvohf7x8J S21RVPU4mqGC2g3Bw1hJ0deLrK8KCcwU/0lWuXes2QkbPGqxpxtsw07RjsSwS/spiGKnMsL2/ter Z3dv1/+Uvf2P8SltdKCQNQDwAwAAYQUAAAK78O2UB6LxMB0zEAAgAAAAc2NwYWxkdmQyaGRkLnBw ZgCwDicHDB1RVQiP1Z/e3fIeC+Dd1Qk0oMQsKUaxkbS0ujoiRTRlalvjdu7pSzWyrSwpbYGzd2BB RQfKxJ6bEG1+itkrLWbWRtsYtoyk9RKm2u0dVJH2oQuywbfS61jWkDa7unlesBN3zvfaGiRbZY/f vx9nsmc5nc5nO/zvczOd5mdzO872fuczOTPhnyzPt26YzAAgVhTWXGwEoBwaYCAAAANE6EBWS7FD LmSC5JfApGRVTAxKuURA1WStgBBVtQGarAjRJBDYCUj6XACSaeg1CSb8e4IKIIXKP1Om7yoJPWjl ZB7ZLb2ksWsyps/K5p6u+TbnRJA0GQ9aqInhK4Vc3WGEl352/wjz6KyGajFiPtB9hElDsk6f4KUQ q9G3RjbQICEPtcgNBzhuoxCnI9TExbwzO9j/kYZIlPUNjEoSGWIh1NjMCW9YRnFC81aG/JkGagBd gaE8fqie6OkJKh+djYMegpAcoFVCeg6CvnJt/eMa2KgIPrFrGNBSsI18iprCF3fGO4CODp8seU4l 0D0gS8WbFLd5VgHcSrSBIO4aVLEM441H+WOld81Iz6joiAhnXcjCcLKnuYLWYQAkCNBDQaxlkEeI 0I69CC1UBTRT3HCnSKb7u2AInZgC97jnNNr0FmAhgNFQD0dFyz71s2aLWmDzwgcyKIenL67f3J2G a/FCTkVMaYwWnWvGlw5EjJFicmpYLjvh+nL9FaENulHOmAEFikLsUp+e1kCThgpWVADEuBUOJoPS ZMJftdWe7DssLRItJlhRAlSlNuvIF8JrrEA6bpg6mlOU4IP0wfXQH+TwFyMTqBg76Rvu8Ik/gtww Nidw3niNWXjsVv+zPsp+MuIjpLvbxJossch+h2pO1HR3+uo03EO+vJQUcb1nH9rY+yX1GV4pEuMo Xl9Urqqobp1zBjQB9Gi/6i9QU254GeTDEKcYCEuhef+Js/fU0ev1DkOERWIIS2Ic8NzwoYTM5xa7 l7C/gJW/C5HvOinFlOLNhs/gUV8h5rjDX/dSyf218lZuz6PyRrvoF1eCp9v8HqvBnnHOby/7M9Ez 9PQ/oa8UKoV1qlWu/lJ69hBuOZuLOc33q3LKqgfPyRZKfqtl+fPUGzo5GlkDqDm0nJp6rX/5ty7h ppktX7vM428r5rF8sjn4t/+uz7H37V/pToPR63S/ufsYXpSvzaRNN6/zqNVK+/x6EajvJFz1MT97 LYtMP6s3uFzSYN7DPrcLZK0zTzKvkMoccXlVV1S5FYJd4dDbepbfHSLuiyuZP0SoCvH+j0Jmh2ze Fp+HO23yuMHgwRuuz88veQvi1PZwK7RzG9sPkXQv45fE2mtmkmYeCi6fOh7SxD17AEAHAA==
|
Don't want to sound too stupid but I don't understand what I shall call the file after I've copy/pasted it to notepad. The other files I've done this with it says what it's supposed to be called in the first line. Sorry, but please explain.
I'm speaking 4 newbs around the world on this one...
So its now possible 2 soft mod any NTSC Xbox with UDE2?
Will there be a all in one package with all the needed files like the first UDE?
Why isnt this a headline on Xbox-Scene Main page?
Ive modded 10 Xboxs with the original UDE but I cant make sence of what UDE2 is about due 2 all this talk about Pal compatability??
UDE2 is only compatible with NTSC (North American) Xboxes.
This is because MS included some code to prevent say, PAL (European, Japanese, etc.) Xboxes from running NTSC Xbox executables, to prevent you from using import CD's. UDE2 only works with NTSC Xboxes because the flag in the file thats being exploited is set to only run on NTSC Xboxes. It would cause an error if you run it on a PAL Xbox.
However the fix is to edit the EEPROM to turn your PAL (Or other) Xbox into an NTSC Xbox so the file runs fine. The problem with this is it changes the way that the Xbox works, and now your Xbox will only run NTSC executables! Meaning your Xbox games probably won't work right.
is this UDE2 compatible with NTSC-J? I think it's a sub-standard of NTSC, but I'm not pretty sure... The J stands for"Japan" AFAIK. However I've heard that in Japan they use PAL...weird.
| QUOTE (ThE MaSTeR 3 @ Jul 18 2004, 10:14 PM) | | Ive modded 10 Xboxs with the original UDE but I cant make sence of what UDE2 is about due 2 all this talk about Pal compatability?? |
^ Not everyone...
And NTSC-J won't work, because it has a different region code.
ude 2 just uses another update.xbe for allowing it to play on newer xboxes. since the update.xbe is different it must have it's own fonts. the rest is completely the same and there is no advantage of using it if your kernel is below 5713.
So when a package is made it will include Update.xbe and the fonts?
and I would just use the replace the update.xbe and the fonts and it would work
thats it?
| QUOTE (ThE MaSTeR 3 @ Jul 19 2004, 09:09 AM) | So when a package is made it will include Update.xbe and the fonts?
and I would just use the replace the update.xbe and the fonts and it would work
thats it? |
along with NKPatcher, since only this works on K:5317+, but, basically, yes. (The use of the very specific M$ copyright update.xbe is hampering the distribution. Unlike UDE1 most people won't have this file already.)
Seriously, doesn't nfl fever exist in Europe or what?? Europeans with live should try to rent it, this is too important to miss out.
here it is but it is very expensive
link 1
hah, 55 euros is about £35... pretty much standard price for the UK (most games are £40)
| QUOTE (gronne @ Jul 19 2004, 01:19 PM) | | Seriously, doesn't nfl fever exist in Europe or what?? Europeans with live should try to rent it, this is too important to miss out. |
As I stated earlier shop.game.net are selling it for £10 + postage.
yeah I saw an nfl fever 2004 for 20,- here.
Another thing - we better hurry, because who can be sure M$ isn't patching up the xbe as we speak... or even just simply replacing it with a newer one. I wish i had live...
Yeah where is that kyro dude. He has live and a buddy workin in a gamestore. Seemed like a winner combo.
I'm just killing myself right now over how damn easy it is for M$ to update every xbe on live...
yeah. I hope they all on vacation right now
hehehe
| QUOTE (YoshiKool @ Jul 19 2004, 05:53 PM) | everyone, edit your posts right now so they don't notice hehehe |
Please!  ssssh!
| QUOTE (YoshiKool @ Jul 19 2004, 07:50 AM) | | I'm just killing myself right now over how damn easy it is for M$ to update every xbe on live... |
yes, so we better get that pal xbe fast, hope it still has the exploit (if it ever did, but it's almost 100% that it did)
i'm more concerned that there ever was a pal update.xbe
damnit. I would definatly buy it. Any dutch livers around that want a free game???
I said I saw nfl fever 2004 for 20,- Haven't found a cheap 2003 yet as it's old.
I believe Pedros went out and purchased the game and a live subscription. Give him a bit and I bet he'll come up with the .xbe. If not, everyone keep looking.
guys quickly what was the exact path for the nfl fever update.xbe??? I might have found someone owning the game and plays live. I will send him a mail and hope he will respond.
er... it would prolly be different with the ntsc.
would it?
My current thoughts are that the US NFL Fever 2003 was launched while XBL service was still stabilizing. Therefore the retail DVD contained a minimal bootstrap, which would bring down as much as it needed from XBL. In this way stable XBL support could be streamed down to the XBOX, once the XBL service launched.
Because here in Europe we get everything months after our US (and Japanese) cousins, the XBL service was stable by this point, and they felt confident enough to commit a DVD flagged update.xbe to the DVD media (there is a DVD flagged one on the media).
To progress this speculation, I'd be intrested is seeing a list of the xbe's from the US NFL Fever 2003 DVD media, and their lengths.
This is driving me crazy how this whole thing is draging out..
Should the the game with the potential flaw we're looking for be one of the first games released on live? I have no idea what the first games was. Is this assumption correct, Pedro?
| QUOTE (gronne @ Jul 20 2004, 02:02 PM) | | Should the the game with the potential flaw we're looking for be one of the first games released on live? I have no idea what the first games was. Is this assumption correct, Pedro? |
Early PAL XBOX!Live games would now look to be the next best hunting ground.
Although M$'s XBL servers probably no longer send out the update.xbe's we're looking for. So they now may only exist on peoples HDDs.
(I suspect that this now may also be true for the US NFL Fever 2003. If someone in the US has the US NFL Fever 2003 and XBL, I'd be interested to know if the update.xbe is still being sent out.)
Yeah, I think the US nfl fever might be patched by now also. If it the pal update.xbe has existed and we really want it, I'd say we should adress the issue on the front page, because we're not reaching enough people in here. Some people watching the main page haven't visited live for a week or so, and who knows what the last game they tried was, right? Xantium or someone should ask for this. Add a link tp ldots scanner or the direct path.
| QUOTE (PedrosPad @ Jul 14 2004, 12:49 PM) | | It's a 2MB RAR - Can anyone host this for ldots? |
Don't know if its still needed, but i don't file like reading through alot of pages  but i might be able to host the 2mb rar.
| QUOTE (m.e @ Jul 20 2004, 03:01 PM) | I know Unreal Championship(PAL) was released before there where xbox live in Europe.
So this game is likely to have a hdd-signed update.xbe |
Its also a very old game.. So it wont have what we are looking for, probably
i have the pal splinter cell content, with the 2 /xbe's in the $u dir. don't know if its still needed..
| QUOTE (Slrpgeit @ Jul 20 2004, 04:04 PM) | | i have the pal splinter cell content, with the 2 /xbe's in the $u dir. don't know if its still needed.. |
needs or not, please back up the files ASAP, just in case it would be 'updated' again if you go live.
| QUOTE (Slrpgeit @ Jul 20 2004, 04:09 PM) | already have, they're in a nice zip file on my pc hard drive |
there is a scanner written by ldots which will give us more info for the given file. Can't find the link off-hand.
Or if you know how to run unix or know about the xbedump program, you can also run :
xbedump <your file> -dc
| CODE | -------------------------------------------------- Scanning HDD for xbe's with XBE_MEDIA_HDD flag --------------------------------------------------
---------------- Entering /mnt/C: ----------------
*************************************************************************** Correct Media flag found in : /mnt/C/xodash/update.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x409BCB24 Fri May 7 17:45:08 2004 Title ID : 0xFFFE0000 Title name : "Online Updater Application" Alternate title ID's : none Allowed media types : 0x80000001 : XBE_MEDIA_HDD Allowed game regions : 0x7FFFFFFF : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE Allowed game rating : 0xFFFFFFFF Disk number : 0x00000000 Version : 0x185EAD00
*************************************************************************** Correct Media flag found in : /mnt/C/xodash/xonlinedash.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x409BCB2A Fri May 7 17:45:14 2004 Title ID : 0xFFFE0000 Title name : "Xbox Dashboard" Alternate title ID's : none Allowed media types : 0x80000001 : XBE_MEDIA_HDD Allowed game regions : 0x7FFFFFFF : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE Allowed game rating : 0xFFFFFFFF Disk number : 0x00000000 Version : 0x185EAD00
*************************************************************************** Correct Media flag found in : /mnt/C/xboxdash.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x409BCB27 Fri May 7 17:45:11 2004 Title ID : 0xFFFE0000 Title name : "Xbox Dashboard" Alternate title ID's : none Allowed media types : 0x80000001 : XBE_MEDIA_HDD Allowed game regions : 0x7FFFFFFF : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE Allowed game rating : 0xFFFFFFFF Disk number : 0x00000000 Version : 0x185EAD00
*************************************************************************** Correct Media flag found in : /mnt/C/evoxdash.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001DC Certificate timestamp : 0x3F75746A Sat Sep 27 11:28:42 2003 Title ID : 0x586F7645 Title name : "RemoteX" Alternate title ID's : none Allowed media types : 0x800000FF : XBE_MEDIA_HDD : XBE_MEDIA_XBOX_DVD : XBE_MEDIA_ANY_CD_OR_DVD : XBE_MEDIA_CD : XBE_MEDIA_1LAYER_DVDROM : XBE_MEDIA_2LAYER_DVDROM : XBE_MEDIA_1LAYER_DVDR : XBE_MEDIA_2LAYER_DVDR Allowed game regions : 0x80000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE : XBE_REGION_DEBUG Allowed game rating : 0xFFFFFFFF Disk number : 0x00000000 Version : 0x00000000
*************************************************************************** Correct Media flag found in : /mnt/C/xboxdashdata.185ead00/settings_adoc.xip ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3D5942BB Tue Aug 13 17:32:43 2002 Title ID : 0xFFFE0000 Title name : "" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0xFFFFFFFF : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE : XBE_REGION_DEBUG Allowed game rating : 0xFFFFFFFF Disk number : 0x00000000 Version : 0x10025300
*************************************************************************** Correct Media flag found in : /mnt/C/settings_adoc.xip ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001D0 Certificate timestamp : 0x3B8D594A Wed Aug 29 21:06:18 2001 Title ID : 0xFFFE0000 Title name : "" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0xFFFFFFFF : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE : XBE_REGION_DEBUG Allowed game rating : 0xFFFFFFFF Disk number : 0x00000000 Version : 0x00000000
---------------- Entering /mnt/E: ----------------
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/4d53002a/$u/downloader.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3F8C628E Tue Oct 14 20:54:38 2003 Title ID : 0x4D53002A Title name : "Downloader" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000004 : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x00000103
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/4d53002a/$u/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3F8C6283 Tue Oct 14 20:54:27 2003 Title ID : 0x4D53002A Title name : "Midtown Madness 3" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000004 : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x00000103
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/4d530021/$u/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x40746F96 Wed Apr 7 21:16:06 2004 Title ID : 0x4D530021 Title name : "Crimson Skies" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000004 : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x00000203
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/4d530021/$u/downloader.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x40746FAC Wed Apr 7 21:16:28 2004 Title ID : 0x4D530021 Title name : "Downloader" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000004 : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x00000203
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/4d53004b/$u/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x40E0938B Mon Jun 28 21:54:19 2004 Title ID : 0x4D53004B Title name : "Project Gotham Racing 2" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000004 : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x00000202
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/4d53004b/$u/downloader.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x40E093B6 Mon Jun 28 21:55:02 2004 Title ID : 0x4D53004B Title name : "Downloader" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000004 : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x00000202
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/4c410003/$u/downloader.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x403BE480 Tue Feb 24 23:55:44 2004 Title ID : 0x4C410003 Title name : "Downloader" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000004 : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x05AB8502
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/4c410003/$u/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x403BE471 Tue Feb 24 23:55:29 2004 Title ID : 0x4C410003 Title name : "Star Wars: KotOR" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000004 : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x05AB8502
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/41430019/$u/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3F01ED43 Tue Jul 1 20:21:23 2003 Title ID : 0x41430019 Title name : "Burnout 2" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000004 : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x00000104
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/5553000c/$u/downloader.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3DC88AEE Wed Nov 6 03:22:22 2002 Title ID : 0x5553000C Title name : "Downloader" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000004 : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x0000010A
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/5553000c/$u/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3DC88AEE Wed Nov 6 03:22:22 2002 Title ID : 0x5553000C Title name : "Splinter Cell" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000004 : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x0000010A
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/55530013/$u/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x404FAC76 Thu Mar 11 00:01:58 2004 Title ID : 0x55530013 Title name : "RainbowSix 3" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000002 Disk number : 0x00000000 Version : 0x00000501
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/55530013/$u/downloader.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x404FAC84 Thu Mar 11 00:02:12 2004 Title ID : 0x55530013 Title name : "Downloader" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000002 Disk number : 0x00000000 Version : 0x00000501
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/55530019/$u/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x40A134E8 Tue May 11 20:17:44 2004 Title ID : 0x55530019 Title name : "Splinter Cell 2" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000003 Disk number : 0x00000000 Version : 0x00000302
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/55530019/$u/downloader.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x40A134F6 Tue May 11 20:17:58 2004 Title ID : 0x55530019 Title name : "Downloader" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000003 Disk number : 0x00000000 Version : 0x00000302
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/55530019/$u/offline.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x40A13501 Tue May 11 20:18:09 2004 Title ID : 0x55530019 Title name : "Splinter Cell 2" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000003 Disk number : 0x00000000 Version : 0x00000302
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/55530019/$u/online.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x40A1350E Tue May 11 20:18:22 2004 Title ID : 0x55530019 Title name : "Splinter Cell 2" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000003 Disk number : 0x00000000 Version : 0x00000302
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/55530019/$u/update.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x40A1351A Tue May 11 20:18:34 2004 Title ID : 0x55530019 Title name : "Splinter Cell 2" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000003 Disk number : 0x00000000 Version : 0x00000302
*************************************************************************** Correct Media flag found in : /mnt/E/TDATA/434d0011/$u/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x40A1338C Tue May 11 20:11:56 2004 Title ID : 0x434D0011 Title name : "Race Driver 2" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000004 : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x00000104
*************************************************************************** Correct Media flag found in : /mnt/E/Apps/NTSC-PAL/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001D0 Certificate timestamp : 0x3CE92450 Mon May 20 16:29:04 2002 Title ID : 0xFFFF000D Title name : "Enigmah Videomode Switchdisc" Alternate title ID's : none Allowed media types : 0x00000205 : XBE_MEDIA_HDD : XBE_MEDIA_ANY_CD_OR_DVD Allowed game regions : 0x80000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE : XBE_REGION_DEBUG Allowed game rating : 0xFFFFFFFF Disk number : 0x00000000 Version : 0x00000000
*************************************************************************** Correct Media flag found in : /mnt/E/Apps/Dvd2XboX/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x404F93AE Wed Mar 10 22:16:14 2004 Title ID : 0x0FACFAC0 Title name : "dvd2xbox" Alternate title ID's : none Allowed media types : 0x80000007 : XBE_MEDIA_HDD : XBE_MEDIA_XBOX_DVD : XBE_MEDIA_ANY_CD_OR_DVD Allowed game regions : 0x80000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE : XBE_REGION_DEBUG Allowed game rating : 0xFFFFFFFF Disk number : 0x00000000 Version : 0x00000000
*************************************************************************** Correct Media flag found in : /mnt/E/Apps/BiosCheck/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001DC Certificate timestamp : 0x3F752809 Sat Sep 27 06:02:49 2003 Title ID : 0xF001601D Title name : "BiosCheck" Alternate title ID's : none Allowed media types : 0x00000205 : XBE_MEDIA_HDD : XBE_MEDIA_ANY_CD_OR_DVD Allowed game regions : 0x80000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE : XBE_REGION_DEBUG Allowed game rating : 0xFFFFFFFF Disk number : 0x00000000 Version : 0x00000000
*************************************************************************** Correct Media flag found in : /mnt/E/Apps/Avalaunch/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x40309F78 Mon Feb 16 10:46:16 2004 Title ID : 0x080299FF Title name : "Avalaunch" Alternate title ID's : none Allowed media types : 0x80000007 : XBE_MEDIA_HDD : XBE_MEDIA_XBOX_DVD : XBE_MEDIA_ANY_CD_OR_DVD Allowed game regions : 0x80000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE : XBE_REGION_DEBUG Allowed game rating : 0xFFFFFFFF Disk number : 0x00000000 Version : 0x00000000
*************************************************************************** Correct Media flag found in : /mnt/E/Apps/boXplorer/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001DC Certificate timestamp : 0x3D5D004D Fri Aug 16 13:38:21 2002 Title ID : 0xFFFF051F Title name : "boXplorer (G-patched)" Alternate title ID's : none Allowed media types : 0x00000205 : XBE_MEDIA_HDD : XBE_MEDIA_ANY_CD_OR_DVD Allowed game regions : 0x80000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE : XBE_REGION_DEBUG Allowed game rating : 0xFFFFFFFF Disk number : 0x00000000 Version : 0x00000000
*************************************************************************** Correct Media flag found in : /mnt/E/Apps/boXplorer/unpatched for G 0.96 default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001DC Certificate timestamp : 0x3D5D004D Fri Aug 16 13:38:21 2002 Title ID : 0xFFFF051F Title name : "boXplorer" Alternate title ID's : none Allowed media types : 0x00000205 : XBE_MEDIA_HDD : XBE_MEDIA_ANY_CD_OR_DVD Allowed game regions : 0x80000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE : XBE_REGION_DEBUG Allowed game rating : 0xFFFFFFFF Disk number : 0x00000000 Version : 0x00000000
*************************************************************************** Correct Media flag found in : /mnt/E/Apps/scan/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001D0 Certificate timestamp : 0x00000000 Thu Jan 1 00:00:00 1970 Title ID : 0x21585554 Title name : "Linux" Alternate title ID's : none Allowed media types : 0x800000FF : XBE_MEDIA_HDD : XBE_MEDIA_XBOX_DVD : XBE_MEDIA_ANY_CD_OR_DVD : XBE_MEDIA_CD : XBE_MEDIA_1LAYER_DVDROM : XBE_MEDIA_2LAYER_DVDROM : XBE_MEDIA_1LAYER_DVDR : XBE_MEDIA_2LAYER_DVDR Allowed game regions : 0x80000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE : XBE_REGION_DEBUG Allowed game rating &n
| QUOTE (Slrpgeit @ Jul 20 2004, 04:17 PM) | *************************************************************************** Correct Media flag found in : /mnt/E/TDATA/55530019/$u/update.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x40A1351A Tue May 11 20:18:34 2004 Title ID : 0x55530019 Title name : "Splinter Cell 2" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000003 Disk number : 0x00000000 Version : 0x00000302
|
Unfortunately, this one seems to be a plugged one given the date/time
is there any way to test it?
| QUOTE (Slrpgeit @ Jul 20 2004, 04:30 PM) | | is there any way to test it? |
Given the date (May, 2004), I have a feeling that MS explicitly fixed the hole and released it through live. It just coincide with the discovering of this update.xbe hole !
Hello MS, I know you are reading.
BTW, I think it is worthless now to use any game to go live and try to download. In fact, I would say going live now would just diminishing the chance. Our hope lies in some old HD which is not ruined by MS.
| CODE | *************************************************************************** Correct Media flag found in : /mnt/E/TDATA/55530013/$u/default.xbe ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x404FAC76 Thu Mar 11 00:01:58 2004 Title ID : 0x55530013 Title name : "RainbowSix 3" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000007 : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000002 Disk number : 0x00000000 Version : 0x00000501
|
| QUOTE | Certificate timestamp : 0x404FAC76 Thu Mar 11 00:01:58 2004
|
Too new probably.
nah too new too.
before what date should it be then?
| QUOTE (Slrpgeit @ Jul 20 2004, 04:52 PM) | | before what date should it be then? |
Before 2003. You finding is not worthless though. As I said in the previous post, our hope now lies in live users who has not gone online recently.
are there any other things but the date that matter?
yeah it should run of hdd and contain the elsewhere region type
you should have broken it up or something
| CODE | *************************************************************************** Correct Media flag found in : /mnt/C/settings_adoc.xip ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001D0 Certificate timestamp : 0x3B8D594A Wed Aug 29 21:06:18 2001 Title ID : 0xFFFE0000 Title name : "" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0xFFFFFFFF : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE : XBE_REGION_DEBUG Allowed game rating : 0xFFFFFFFF Disk number : 0x00000000 Version : 0x00000000
|
that's the easter egg XBE, it's just a renamed XBE, we need xbe's from 2003 because dash xbe's before then won't run on new kernel xboxes...
| QUOTE (Slrpgeit @ Jul 20 2004, 04:59 PM) | yeah, sry bout that, didn't know. but, does it have to be an .xbe? because there is a .xip from 2001 with all regions, and runs from hd, like this one:
| CODE | *************************************************************************** Correct Media flag found in : /mnt/C/settings_adoc.xip ***************************************************************************
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001D0 Certificate timestamp : 0x3B8D594A Wed Aug 29 21:06:18 2001 Title ID : 0xFFFE0000 Title name : "" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0xFFFFFFFF : XBE_REGION_US_CANADA : XBE_REGION_JAPAN : XBE_REGION_ELSEWHERE : XBE_REGION_DEBUG Allowed game rating : 0xFFFFFFFF Disk number : 0x00000000 Version : 0x00000000
|
|
this is the easter egg XBE, has found any hole in it so far.
ah, i see, but somewhere in this thread, i saw something that makes the date not matter for newer kernels. is this true?
uhh, no... on dashboard XBE's it checks to see if the date is before a certain point and if not you get error 21
Correction: The date is only important if the titleID is the Dashboard titleID of 0xfffe000. Otherwise the date doesn't matter.
that's what i meant by saying "dashboard XBE's"... unless some don't have that title ID?
| QUOTE (PedrosPad @ Jul 20 2004, 05:15 PM) | | Correction: The date is only important if the titleID is the Dashboard titleID of 0xfffe000. Otherwise the date doesn't matter. |
But it is a good indication whether the font bug is fixed. This May 2004 version is just to close to your annoncement of UDE. Do you think a previous one that is signed for region 1,2 of date Dec 2003 has any chance to be exploitable ? It may be good for Japan/Singapore/Hong Kong(not that much users though).
| QUOTE (YoshiKool @ Jul 20 2004, 05:16 PM) | | that's what i meant by saying "dashboard XBE's"... unless some don't have that title ID? |
Most update.xbe's have the Dashboard titleID (oxfffe000), and are considered part of the Dashboard suite of programs. However some update.xbe's have been found that don't have this titleID - and one of them is used for UDE2  So what we're looking for is an old PAL update.xbe - old so it still has the font flaw - but one that doesn't have the Dashboard's titleID - so K:5713+ won't prevent it running.
chimpanzee: i think every update.xbe dated after that "special date" isn't exploitable which is why we need a non-dashboard titled one that is also before the "special date"
ok this is annoying me now, someone remind me what the "special date" is
| QUOTE (m.e @ Jul 20 2004, 03:01 PM) | I know Unreal Championship(PAL) was released before there where xbox live in Europe.
So this game is likely to have a hdd-signed update.xbe |
I'll repeat myself. This was the first PAL game that was xbox live compatible. I don't have it myself so I can't check if it has a good update.xbe.
Are you guys sure the SC2 update.xbe isn't working? Ok, it's a new timestamp, since it was released last fall or something. But UDE wasn't released until the end of May if I'm not all wrong. Probably they fixed it when the easter-egg was released then. But if you think there is someone that hasn't been on live since early May, we better hope sc2 was the last game he played? Maybe they plugged several games at the same time, meaning other games might work as well? The only chance of finding that file is by announcing the issue on the front-page, right?
| QUOTE (gronne @ Jul 20 2004, 07:55 PM) | | Are you guys sure the SC2 update.xbe isn't working? Ok, it's a new timestamp, since it was released last fall or something. But UDE wasn't released until the end of May if I'm not all wrong. Probably they fixed it when the easter-egg was released then. But if you think there is someone that hasn't been on live since early May, we better hope sc2 was the last game he played? Maybe they plugged several games at the same time, meaning other games might work as well? The only chance of finding that file is by announcing the issue on the front-page, right? |
the patch did not comeout when UDE came out. The hole was plugged when the original fonts exploit came out. UDE uses this same premise(sp?) on a different file to avoid the clock loop.
Edit: Forgot to add this: Correct me if i'm wrong.
The original font exploit came on the 4:th of July 2003, so I don't see why they patch the file as late as 11 May 2004, as the game was out late 2003(I think). There must've been some other reason they patched it that late.
Are you guys officially certain that the sc2 update.xbe is a no-go?
| QUOTE (gronne @ Jul 21 2004, 01:16 AM) | The original font exploit came on the 4:th of July 2003, so I don't see why they patch the file as late as 11 May 2004, as the game was out late 2003(I think). There must've been some other reason they patched it that late.
Are you guys officially certain that the sc2 update.xbe is a no-go? |
Nothing is official until the pros said so :-)
But May 2004 is way to suspicious a date. I wish I am wrong and my other dream is true.
I suppose it takes a lot of work to find out if it's working or not. Let's hope they're trying it.
EDIT: As I don't know when the easter egg was released, does anyone have an idea of why they had the need to update the update.xbe in 11 may? If it wasn't because they discovered the flaw by themselves, or someone here posted something that was related to the issue back then, it might just be that they updated it for other reasons and the flaw is still there.
I know this has prolly been asked a few times, but is there any chance at an installer?
| QUOTE (SSJ4Gohan @ Jul 21 2004, 02:02 AM) | | I know this has prolly been asked a few times, but is there any chance at an installer? |
what installer ? there is already an installer. If you mean for 5713+, not yet as ldots is waiting for hopefully PAL version to make it complete.
Did this thread just die or something? Will someone officially say the file didn't work or what?
| QUOTE (gronne @ Jul 21 2004, 04:02 PM) | | Did this thread just die or something? Will someone officially say the file didn't work or what? |
something, but don't know what it is.
| QUOTE (YoshiKool @ Jul 20 2004, 05:58 PM) | chimpanzee: i think every update.xbe dated after that "special date" isn't exploitable which is why we need a non-dashboard titled one that is also before the "special date"
ok this is annoying me now, someone remind me what the "special date" is |
| QUOTE (rmenhal @ May 19 2004, 09:17 AM) | We know that kernels 5713 or higher won't allow dash downgrades.
Actually - while I didn't bother to trace out the logic exactly - there's a new check in 5713's XBE loader. It checks the XBE certificate structure. If the title ID is 0xFFFE0000 (dash's ID), the kernel then checks the time and date field and anything prior to about Aug 5 2003 causes it to bail out. So dash 4920 and prior versions are out. |
So it's a fair guess that M$ was confident that the font flaw was fixed post 5th Aug, 2003.
| QUOTE (gronne @ Jul 21 2004, 01:44 AM) | | does anyone have an idea of why they had the need to update the update.xbe in 11 may? |
The release of Dashboard 5960 (would be my guess).
| QUOTE (PedrosPad @ Jul 20 2004, 08:52 AM - last paragraph) | | To progress this speculation, I'd be intrested is seeing a list of the xbe's from the US NFL Fever 2003 DVD media, and their lengths. |
The following are on mine eh.
| CODE | 5,496,832 \default.xbe 1,560,576 \Update.xbe 962,560 \xdemos\xdemos.xbe 2,121,728 \XODash\XOnlineDash.xbe
|
at least now i know the "special date" eh thanks pedro
Nope, all those media types indicate that it's no longer suitably signed (due to a transfer proggie having changed it). Thanks for trying though eh.
| QUOTE | | To progress this speculation, I'd be intrested is seeing a list of the xbe's from the US NFL Fever 2003 DVD media, and their lengths. |
| QUOTE (eh. @ Jul 21 2004, 04:58 PM) | The following are on mine eh.
| CODE | 5,496,832 \default.xbe 1,560,576 \Update.xbe 962,560 \xdemos\xdemos.xbe 2,121,728 \XODash\XOnlineDash.xbe
|
|
Thanks eh. The xbes and file lengths of off the PAL NFL Fever 2003 are
| CODE | 5,496,832 \default.xbe 1,560,576 \Update.xbe 962,560 \xdemos\xdemos.xbe 2,121,728 \XODash\XOnlineDash.xbe
|
Yup - they match exactly.
Just to prove I was using the PAL default.xbe, here is the certificate:
| CODE | Certificate ~~~~~~~~~~~ Size of certificate : 0x000001DC Certificate timestamp : 0x3D824600 Fri Sep 13 21:09:36 2002 Title ID : 0x4D530028 Title name : "NFL Fever 2003" Alternate title ID's : none Allowed media types : 0x00000002 : XBE_MEDIA_XBOX_DVD Allowed game regions : 0x00000004 : XBE_REGION_ELSEWHERE Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x00000005 |
I'm now interested is seeing the US NFL default.xbe's certificate.
does the update.xbe in the root only run from dvd?
| QUOTE (PedrosPad @ Jul 22 2004, 10:16 AM - partial) | Thanks eh.
I'm now interested is seeing the US NFL default.xbe's certificate. |
You're welcome eh. | CODE | Certificate ~~~~~~~~~~~ Size of certificate : 0x000001DC Certificate timestamp : 0x3D4730E5 Tue Jul 30 18:35:49 2002 Title ID : 0x4D530028 Title name : "NFL Fever 2003" Alternate title ID's : none Allowed media types : 0x00000002 : XBE_MEDIA_XBOX_DVD Allowed game regions : 0x00000001 : XBE_REGION_US_CANADA Allowed game rating : 0x00000004 Disk number : 0x00000000 Version : 0x00000004
|
| CODE | Certificate ~~~~~~~~~~~ Size of certificate : 0x000001DC Certificate timestamp : 0x3D4730E5 Tue Jul 30 18:35:49 2002 Title ID : 0xFFFE0000 Title name : "Online Updater Application" Alternate title ID's : none Allowed media types : 0x00000002 : XBE_MEDIA_XBOX_DVD Allowed game regions : 0x00000001 : XBE_REGION_US_CANADA Allowed game rating : 0x00000004 Disk number : 0x00000000 Version : 0x00000004
|
would it even be possible to find a dvd xbe that does not only have the dvd media type?
from reading this thread, nothing is impossible, it just isn't likely.
i'm sure i've seen a few...
| CODE | Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3DC83440 Tue Nov 05 14:12:32 2002 Title ID : 0x4D530028 Title name : "Online Updater Application" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000001 : XBE_REGION_US_CANADA Allowed game rating : 0x00000004 Disk number : 0x00000000 Version : 0x00010004
|
| CODE | Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3DC83422 Tue Nov 05 14:12:02 2002 Title ID : 0x4D530028 Title name : "NFL Fever 2003" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000001 : XBE_REGION_US_CANADA Allowed game rating : 0x00000004 Disk number : 0x00000000 Version : 0x00010004
|
I think it's fair to say now we need a freekin miracle.
| QUOTE (eh. @ Jul 22 2004, 07:09 PM) |
| CODE | Certificate ~~~~~~~~~~~ Size of certificate : 0x000001EC Certificate timestamp : 0x3DC83440 Tue Nov 05 14:12:32 2002 Title ID : 0x4D530028 Title name : "Online Updater Application" Alternate title ID's : none Allowed media types : 0x00000001 : XBE_MEDIA_HDD Allowed game regions : 0x00000001 : XBE_REGION_US_CANADA Allowed game rating : 0x00000004 Disk number : 0x00000000 Version : 0x00010004
|
|
This the eh.'s NFL update.xbe that was used for US UDE2.
eh.'s quip about "Guy Fawkes day" (Nov 5th) caught my eye.
This file from the NFL Fever 2003 DVD...
| CODE | 2,121,728 \XODash\XOnlineDash.xbe
|
...is a fake Dashboard - when you run it it simply shows a static image saying that XBOX is due to launch in November 2002. Interesting date eh?
The dates imply that the update.xbe that eh.'s NFL Fever 2003 downloaded must have been the first one published on the XBL servers. So if a PAL XBL game also connected around that time, it too may have an update.xbe, with a titleID of the game. It would seem that M$ decided that update.xbe was, in fact, part of the Dashboard suite after this time.
eh., any chance you could delete your NFL downloaded content, and see if the game sucks the same update.xbe it down again? (I doubt it would, but would like to know).
| QUOTE (Dan Wysocki @ Jul 14 2004, 08:39 AM) | This seems like a really cool app, is there any way of developing a PC version cause I have numerous backups of my whole xbox hdd on my pc and it may be nice to be able to run an app to search within folders in windows...
|
Re: ldots XBE scanner Like Dan, I've realised I've a complete backup of my brothers XBOX HDD that I'd FTPed across, zipped up, and tucked away on a CD somewhere (and he was an early XBL user  ) - I recall I backed everything up (C & E) before I attempted any exploits on his XBOX. (I'll try and find it tonight). So in preparation, I've ported the idea of ldots XBE scanner to a Windows batch file. (Tested on Windows XP - but should also work on Windows NT) Usage: Put a copy of xbedump.exe at C:\ Pop the HDDXBESrch.bat batch file at the top of the folder tree you wish to search (C:\Games) and double click on HDDXBESrch.bat. The output is written to the file C:\HDDXBEs.txt. Cut and paste the following into Notepad and save as HDDXBESrch.bat (with word-wrap off it should just be 5 lines). | CODE | REM HDDXBESrch.bat REM Requires C:\xbedump.exe to work REM DEL C:\HDDXBEs.txt FOR /R %%i IN (*.XBE) DO C:\XBEDUMP.EXE "%%i" -dc | FIND "XBE_MEDIA_HDD" && IF NOT ERRORLEVEL 1 ECHO %%i >>C:\HDDXBEs.txt && C:\XBEDUMP.EXE "%%i" -dc >>C:\HDDXBEs.txt |
Remember, if it reports that every allowed media type is on, it'll be junk, as the xbe must have been modifed by DVD2XBOX or some such.
Uhmm neat app pedro. It just gives me errors though instead of creating a log.
*edit* Actually it does create a log but only with the default.xbe names and locations instead of the xbe info itself
| QUOTE (krayzie @ Jul 23 2004, 05:54 PM) | Uhmm neat app pedro. It just gives me errors though instead of creating a log.
*edit* Actually it does create a log but only with the default.xbe names and locations instead of the xbe info itself |
Try cutting and pasting it again - I edited the code section a few times since first posting  (and make sure the long FOR line is kept on one line (no C/Rs)).
| CODE | REM HDDXBESrch.bat REM Requires C:\xbedump.exe to work REM DEL C:\HDDXBEs.txt FOR /R %%i IN (*.XBE) DO C:\XBEDUMP.EXE "%%i" -dc | FIND "XBE_MEDIA_HDD" && IF NOT ERRORLEVEL 1 ECHO "%%i" >>C:\HDDXBEs.txt && C:\XBEDUMP.EXE "%%i" -dc >>C:\HDDXBEs.txt |
And add the .exe extension to xbedump
| QUOTE (ldots @ Jul 23 2004, 06:04 PM) | Could be you need to add quotes around the last set of %i variable :| CODE | REM HDDXBESrch.bat REM Requires C:\xbedump.exe to work REM DEL C:\HDDXBEs.txt FOR /R %%i IN (*.XBE) DO C:\XBEDUMP.EXE "%%i" -dc | FIND "XBE_MEDIA_HDD" && IF NOT ERRORLEVEL 1 ECHO "%%i" >>C:\HDDXBEs.txt && C:\XBEDUMP.EXE "%%i" -dc >>C:\HDDXBEs.txt |
And add the .exe extension to xbedump |
Ta. Done.
Okay works great now. Too bad I didn't found anything interesting.
no. But it would be the best I guess since it doesn't execute any clock setting stuff.
also, update.xbe is a known exploitable XBE - other stuff such as mechassault's downloader will help also but they have not been exploited as of yet...
edit: i think i smell 500 posts... seems that exploits for 5713+ are already very very popular after only 11 days...
| QUOTE (PedrosPad @ Jul 22 2004, 03:32 PM - partial) | The dates imply that the update.xbe that eh.'s NFL Fever 2003 downloaded must have been the first one published on the XBL servers. So if a PAL XBL game also connected around that time, it too may have an update.xbe, with a titleID of the game. It would seem that M$ decided that update.xbe was, in fact, part of the Dashboard suite after this time.
|
Excellent theory Pedro. Regarding the last sentence ... they potentially just messed up though, if this is an indicator of what was intended eh. | CODE | Certificate ~~~~~~~~~~~ Size of certificate : 0x000001DC Certificate timestamp : 0x3D484652 Wed Jul 31 14:19:30 2002 Title ID : 0x4D530037 Title name : "NFL Fever 2003 Online Beta" Alternate title ID's : none Allowed media types : 0x00000002 : XBE_MEDIA_XBOX_DVD Allowed game regions : 0x00000001 : XBE_REGION_US_CANADA Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x00000002
Certificate ~~~~~~~~~~~ Size of certificate : 0x000001DC Certificate timestamp : 0x3D484652 Wed Jul 31 14:19:30 2002 Title ID : 0xFFFE0000 Title name : "Online Updater Application" Alternate title ID's : none Allowed media types : 0x00000002 : XBE_MEDIA_XBOX_DVD Allowed game regions : 0x00000001 : XBE_REGION_US_CANADA Allowed game rating : 0x00000000 Disk number : 0x00000000 Version : 0x00000002
|
| QUOTE (PedrosPad @ Jul 22 2004, 03:32 PM - remainder) | This the eh.'s NFL update.xbe that was used for US UDE2.
eh.'s quip about "Guy Fawkes day" (Nov 5th) caught my eye.
This file from the NFL Fever 2003 DVD...
| CODE | 2,121,728 \XODash\XOnlineDash.xbe
|
...is a fake Dashboard - when you run it it simply shows a static image saying that XBOX is due to launch in November 2002. Interesting date eh?
eh., any chance you could delete your NFL downloaded content, and see if the game sucks the same update.xbe it down again? (I doubt it would, but would like to know).
|
Initially I reverted to 4817 and "connecting" did indeed display the pre-live fake XOnlineDash.xbe as you described (and consequently didn't download anything). I then replaced it with 4920 and it attempts to download ... without success ... I think my network setup's incompatible and will try changing that when I can eh.  Edit (outcome): Changed the network setup and received 5960 but nothing more, alas. My tests proved to be somewhat futile, as I don't have Live! Consequently, I could only gain access to it via the dash. Learned that my version of Fever2k3 doesn't facilitate the initial connection, it just displays a message about visiting the XBL website for more info. The owner needs to have subscribed by another means, before this version of the game can use it eh.
::skips to page 15 and adds his two cents::
Can't you use configmagic? Then ude2?
| QUOTE (scrupul0us @ Jul 26 2004, 07:28 AM) | ::skips to page 15 and adds his two cents::
Can't you use configmagic? Then ude2? |
Yes, obviously you can if you don't have a 1.6 xbox. I'm sure pedro, krazie, ldots and the others are well aware of that. There are many issues with changing eeproms:
1. It's sensative, if you mess it up it can be either very simple or extremely difficult to repair.
2. Far from everyone is comfortable with editing their eeprom.
3. If the instructions I re-wrote aren't followed exactly, you can run into other non-eeprom problems.
-devz3ro
| QUOTE (scrupul0us @ Jul 26 2004, 07:28 AM) | ::skips to page 15 and adds his two cents::
Can't you use configmagic? Then ude2? |
::replies sarcastically:
Read back a few pages, and the UDE2 thread and this has already been mentioned several times and isn't very helpful for a variety of reasons. Since Configmagic also dosn't work on v1.6 'boxes, apparently, people with PAL 1.6ers have a problem. It also means if you mess up your 'box, you also might struggle to revert it without picking up a copy of MechAssault and you'd also have to wait for EvoX to launch so you can play PAL games.
Not really ideal.
scrupul0us: 1.4 or maybe 1.5 - 1.6's have kernel 5838 for the new video encoder
| QUOTE (BluhDeBluh @ Jul 26 2004, 07:45 AM) | | Since Configmagic also dosn't work on v1.6 'boxes, apparently, people with PAL 1.6ers have a problem. |
| QUOTE (Atreyu @ Jul 26 2004, 05:02 PM) | | i sent my friend Idots search proggy.. and he ran it.. and he said it found some files but does the program write a log? if so.. where does it write it to? |
E:\SCAN_LOG.TXT (or a filename very close to that)
| QUOTE (PedrosPad @ Jul 23 2004, 09:31 AM - partial) | Usage: Put a copy of xbedump.exe at C:\ Pop the HDDXBESrch.bat batch file at the top of the folder tree you wish to search (C:\Games) and double click on HDDXBESrch.bat. The output is written to the file C:\HDDXBEs.txt.
Remember, if it reports that every allowed media type is on, it'll be junk, as the xbe must have been modifed by DVD2XBOX or some such. |
Thanks for this Pedro; it worked well (on win2Kpro) for me eh. To increase the chance of others seeing it, could Angerwound add a link in the "Exploit Tools" sticky, along with one to ldots scanner?
(Edit: P.S. The outcome of my Fever2k3 tests is now in the related post.)
I'm sure I can do that for you. I meant to throw that in there sooner but it must have slipped past me.
| QUOTE (Atreyu @ Jul 27 2004, 09:42 AM) | I got my friend to run Idots search tool, and he posted me his log.. i don't think any of the files he found are useful but just incase, can someone who knows.. please check the log to confirm? thanx
FRIENDS XBE_SCAN.LOG |
Unfortunately, in this instance, you're right - there's nothing remarkable in the log, but many thanks for taking the trouble and posting the results.
| QUOTE (Chicken Scratch Boy @ Jul 26 2004, 06:39 AM) | | why not just extract the eeprom manually? |
like... back it up and look at people.. good idea, bad idea? tried it? i'm a genius?
If you changed a PAL xbox's EEPROM to NTSC xbe region - then you wouldn't be able to boot retail PAL games before the exploit triggered (in case you screwed anything up.) You could still hotswap or use MA though (i think MA is elsewhere and us_canada region).
Of course once the exploit triggers you can run any game, backup or retail.
| QUOTE (mkjones @ Jul 27 2004, 11:19 AM) | Sounds Risky but could an EEPROM switch be "Scripted" in any dash language? Or a Linux distro?
I assume AVA would have this potential, if so it could help in ensuring its done right.
OR it could go wrong 1/2 way through and kill the box!
However, what disadvantages are there to a changed eeppom?
Is one that you cannot boot orig games? OR can you still boot them from a dash like a backup? I cant see why it would make a difference as this would efectivly make the box regoin free anyway |
the linux guys only tell us how to read/write eeprom but not how to 'change' it as they don't see the need for it and consider it to be purely 'pirate' related activity :-(
| QUOTE (chimpanzee @ Jul 27 2004, 11:22 AM) | | the linux guys only tell us how to read/write eeprom but not how to 'change' it as they don't see the need for it and consider it to be purely 'pirate' related activity :-( |
| QUOTE (PedrosPad @ Jul 26 2004, 12:50 PM) | The source code for ConfigMagic can be found here  |
| QUOTE (chimpanzee @ Jul 27 2004, 11:39 AM) | Ah, too complicate for me. I am sure if ldots has the time and is willing to do it, should be easy for him.
Can we now pray to our god |
The reading of the eeprom is one thing. The decryption is another. We need to decrypt the eeprom to start editing it. The eeprom decryption needs an update (both LiveInfo, ConfigMagic and all linux tools use the "Friday 13th" hack to do this). Once the eeprom is decrypted it not a big deal to change the XBE region
Edit : Sorry! I was thinking v1.6. The current code available decrypt the v1.0-1.5 eeproms just fine. So making the XBE region swith could be automated. I was considering doing this for the UDE2 installer. But decided not to. Imagine if there was a bug in the code. Automatic eeprom editing sounds a bit risky to me. I could try to make a tool that : - reads eeprom - decrypts eeprom - Sets xbe region - encrypts eeprom and dumps to a file. - tests the encrypted eeprom (decrypt again and extract various information, like XBE region).
Then one could use official tools to write back the eeprom (linux, ConfigMagic or a dashboard).
| QUOTE (chimpanzee @ Jul 27 2004, 11:39 AM) | Ah, too complicate for me. I am sure if ldots has the time and is willing to do it, should be easy for him.
Can we now pray to our god |
If anyone knows where the source is for the Enigmah video switcher, it may be easier to modify - it already toggles the 'video mode', the EEPROM byte right next to the 'xbe region' byte.  Edit: Just read that apparently both XBMC and AvaLaunch also contain the ability to toggle the video EEPROM byte - so there's more source to checkout.
| QUOTE (PedrosPad @ Jul 27 2004, 12:17 PM) | If anyone knows where the source is for the Enigmah video switcher, it may be easier to modify - it already toggles the 'video mode', the EEPROM byte right next to the 'xbe region' byte. 
Edit: Just read that apparently both XBMC and AvaLaunch also contain the ability to toggle the video EEPROM byte - so there's more source to checkout. |
The code in configure magic is good enough, just that I haven't done any of those eeprom encrypt/decrypt mod before but ldots just did for the HD locking so it should be a piece of cake for him.
| QUOTE (ldots @ Jul 27 2004, 12:15 PM) | I could try to make a tool that : - reads eeprom - decrypts eeprom - Sets xbe region - encrypts eeprom and dumps to a file. - tests the encrypted eeprom (decrypt again and extract various information, like XBE region). |
Assuming you know what the current xbe region is you could (since it is encrypted with RC4) just xor the encrypted region with the known region value and xor again with 0x00000001.  Most probably Config Magic just needs to be updated to have the v1.6 EEPROM key (or the corresponding middle message hashes). Xbe region is apparently a bit field. Why can't we just make it have bits set for all regions? Or if the box is not US/Canada region, then xor the byte at offset 0x2c with 0x01 so that it has also the US/Canada region in addition to the native one? EDIT: oh, xbe region is also hashed into data_hash. So the EEPROM key (or the middle message hashes) is required. But the multiple-region idea still stands. EDIT2: multi-region won't work.
| QUOTE (rmenhal @ Jul 27 2004, 04:45 PM) | | Assuming you know what the current xbe region is you could Xbe region is apparently a bit field. Why can't we just make it have bits set for all regions? Or if the box is not US/Canada region, then xor the byte at offset 0x2c with 0x01 so that it has also the US/Canada region in addition to the native one? |
If you can acomplish this you are truly the best.
| QUOTE (rmenhal @ Jul 27 2004, 04:45 PM) | | Xbe region is apparently a bit field. Why can't we just make it have bits set for all regions? Or if the box is not US/Canada region, then xor the byte at offset 0x2c with 0x01 so that it has also the US/Canada region in addition to the native one? |
Indeed with the region codes (0x01, 0x02, 0x04) it does look a lot like its bit packed  Hmm - that would be neat. So you are saying having the byte at 0x2c set to 0x05 the xbox would function both as a Europe and North America region box? Should be easy to test, but I'm not sure I'm brave enough. I dont have a modchip
| QUOTE (ldots @ Jul 27 2004, 05:58 PM) | Indeed with the region codes (0x01, 0x02, 0x04) it does look a lot like its bit packed 
Hmm - that would be neat. So you are saying having the byte at 0x2c set to 0x05 the xbox would function both as a Europe and North America region box? Should be easy to test, but I'm not sure I'm brave enough. I dont have a modchip |
no, please set it to 7 so we NTSC-J users can be benefitted too :-)
However, just found out that running a game hack is not an easy task for NTSC-J, the three known exploitable games either don't have NTSC-J version or don't have the necessary game save :-(
Would it be that simple though ? That would mean any Xbox can run all region original games by design.
Hmm.... i think i'll say it now so noone tries it Don't try to xor video modes together...
i was thinking once we get the region for a pal one changed, we can do a diff patch
but if configmagic only needs the key... then do that
| QUOTE (Rmenhal) | | EDIT: oh, xbe region is also hashed into data_hash. So the EEPROM key (or the middle message hashes) is required |
I'm not suggesting everyone does this, but it is possible that xor'ing your current region with 0x01 will make it multi-region. Someone with a chip could test this out.
Damn...
| QUOTE (rmenhal @ Jul 28 2004, 03:10 AM) | | The multi-region idea doesn't work. MS checks that (region AND (region - 1)) is zero. |
crap
Yep that's a bummer; the genius minds seemed to have identified a huge opportunity there eh.
@Angerwound: thanks for putting the link to ldots scanner in the Tools post ... hopefully someone, somewhere find even more treasures with it.
@PedrosPad: might it be worthwhile the first post referring to the PC and/or Xbox HDD XBE scanners too?
| QUOTE (chimpanzee @ Jul 28 2004, 01:14 AM) | no, please set it to 7 so we NTSC-J users can be benefitted too :-)
However, just found out that running a game hack is not an easy task for NTSC-J, the three known exploitable games either don't have NTSC-J version or don't have the necessary game save :-(
Would it be that simple though ? That would mean any Xbox can run all region original games by design. |
Yes there are NTSC/J version exploitable games. the NTSC/J MechAssault is exploitable -- and they haven't bothered to patch it but i haven't seen 007:AUF here(in Taiwan) and i don't know whether the NTSC/J splinter cell is exploitable or not.
Great work..
but for NTSC J users , there will always be the fear of screwups which will not enable them to run the NTSCJ original MA after the region coding has been changed...
I am one of those unlucky twats. [idiotic dumbass[myself] deleted e:\default.xbe accidentally]
and after I got it working for less than 10 mins..
Been punching myself since last week.
how do you delete somthing off a dvd?
please tell
haha..
ok the punching did many things to my brains and fingers..
actually is E:\default.xbe
already modified the original post.
you can ALWAYS import a pal/ntsc copy of MA
will a US NTSC MA allow me to boot ?
I mean, this UDE2 , will it look for d:\default.xbe first before it reads c:\xboxdash.xbe?
If so, I will be frantically looking for one..
tried booting ntscJ MA.. it still went on to error 21
anyone have a MA ntsc in SG?
| QUOTE (farbird @ Jul 29 2004, 10:34 AM) | | anyone have a MA ntsc in SG? |
sg? and try ebay m8
no have in sg..
sigh..
its a very expensive paperweight
FACTS:
I know that there are Xbox regio's 1 = ntsc 2 = ntsc j (if I'm right) 4 = Pal 0 = multiregion
the bios is NOT regio hashed.
So, what about regio 3 or 5? those are not documented yet. Or OR ONLY the regios NTSC, NTSC-J and PAL together, (NOT REGION 0!) My believe is that this SCHOULD work well; see below... ============================================ If It look at the routine above closely; i can make this out of it
I assume that: 0 AND 0 = 0 0 AND 1 = 0 1 AND 0 = 0 1 AND 1 = 1
example A) regio 4 = PAL = binary 00000100
BIOS checks; 00000100 AND (00000100 - 00000001) = 0? (correct) so this gives 00000100 AND 00000011 = 00000000 = 0 (correct, PAL box boot)
example  regio = 1 = NTSC = binary 00000001
BIOS checks; 00000001 AND (00000001 - 00000001) = 0? so this gives 00000001 AND 00000000 = 0 (correct, NTSC box boot)
example C) regio = 0 = Multiregion = binary 00000000
BIOS checks; 00000000 AND (00000000 - 00000001) = 0? so this gives 00000000 AND 111111111 = 0 (CORRECT!, multi region box boot!)
So as i see it; it doesn't matter what the regioncode is; by using the extraction of 1 and the operator AND i get always 0 (correct), so the xbox must boot. So that's why i believe that above routine is NOT correct!So because of this reason, i can't know any reason WHY the xbox still seems to be non booting, if regiosetting = 0(all regions), EXCEPT: As I see it, this can only be done with the bios testing; If the regiosetting <> 0 then ok -> boot ; else refuse and get XBOX to trashcan .
So if my conclusion is CORRECT, it SHOULD be possible to boot ANY xbox, when the regiocode is set to ANY regiocode, EXCEPT 0. (In this case I believe that regiosetting to 0 (zero) already was checked into the past, but till now, NO-ONE has confirmed this by real facts and also NO-ONE has tried to use other settings!! )
OR operandi means : 0 XOR 0 = 0 0 XOR 1 = 1 1 XOR 0 = 1 1 XOR 1 = 1
So this gives: regio 1 NTSC = 00000001 OR regio 4 PAL 00000100 gives 00000101 (regio 5!!!!)
regio 1, 4 and 2 together gives 00000001 OR 00000100 OR 00000010 gives 00000111 (regio 7!)
regio 1 and 2 together gives 00000001 OR 00000010 gives 00000011 (regio 3!) "
CONCLUSION:
In my believe the XBOX must be boot well, if we set the region to 5 (PAL and NTSC), or 3 (NTSC and NTSC-J), or 7 (NTSC, NTSC-J and PAL), the xbox must boot well, and IS then made regionfree!
Also this numbers comply with above regiosettings. precicely 3, 5 and 7 are NOT used by XBOX normally, only 1, 2 or 4. CAN ANYBODY WITH A MODCHIP CONFIRM THIS CONCLUSION!
You're confusing DVD Video regions with Xbox regions. What you've stated are various different DVD regions, which MS doesn't use as part of its copy protection. There are only 3 regions as far as the Xbox is concerned.
Plus, you got a couple of them wrong (R1 = US/Can, R2 = Europe (PAL)/Japan(NTSC), R3 = Asia, R4 = Australia, R5 = Russia, R6 = Other, R0 = Regionfree)
| QUOTE (BluhDeBluh @ Sep 20 2004, 09:01 AM) | You're confusing DVD Video regions with Xbox regions. What you've stated are various different DVD regions, which MS doesn't use as part of its copy protection. There are only 3 regions as far as the Xbox is concerned.
| QUOTE (rmenhal @ Sep 20 2004, 11:48 AM) | Well, not really. The check passes if and only if at most one bit is set.
|
|
|
|