xboxscene.org forums

OG Xbox Forums => No-Modchip Hacks (exploits) => XBE Exploits => Topic started by: PedrosPad on July 12, 2004, 07:51:00 AM

Title: UDE/5713+
Post by: PedrosPad on July 12, 2004, 07:51:00 AM
I'm feeling a bit left out here - not having my own PBL flavor to post wink.gif  so I thought I'd start one of me infamous rambling development threads (I've heard some people like to read them).  As always do feel free to join in and post your own thoughts - even if their not workable in themselves, they often inspire other ideas.

I've been focusing on finding an exploitable XBE for use as a new K:5713+ compatible UDE bootstrap.

Problem definition:
The existing UDE uses an XBE from the 4920 Dashboard family of XBEs (xodash\update.xbe - in fact).

xbedump reports the header of the update.xbe as:
CODE
Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3E306D50 Thu Jan 23 22:31:44 2003
Title ID                            : 0xFFFE0000
Title name                          : "Online Updater Application"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x7FFFFFFF
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE

It's the XBE_MEDIA_HDD that means it can be executed from the hard disk, thus can be used as the bootstrap for UDE.

The problem with the new kernels >=5713 is
QUOTE (rmenhal @ May 19 2004, 09:17 AM)
We know that kernels 5713 or higher won't allow dash downgrades.

Actually - while I didn't bother to trace out the logic exactly - there's a new check in 5713's XBE loader. It checks the XBE certificate structure. If the title ID is 0xFFFE0000 (dash's ID), the kernel then checks the time and date field and anything prior to about Aug 5 2003 causes it to bail out. So dash 4920 and prior versions are out.


So the search is on for an XBE that
  • Doesn't check the clock! (we don't want any clock loops back wink.gif) - thus excludes all Dashboard XBEs. sad.gif
  • has a title ID equal to 0xFFFE0000, and a date after Aug 5 2003 that is exploitable! (of course all the new Dashboard's support files (such as 5960's xodash\update.xbe) meet this criteria, but these are unlikely to be exploitable (M$ learns from its mistakes) sad.gif)
  • has Allowed media types = XBE_MEDIA_HDD, and a titleID not equal to 0xFFFE0000 biggrin.gif
The last point looks the most likely source of a UDE/5713 bootstrap.  Even files that meet these criteria are then only possible candidates.  There is a lot of work to do after a candidate has been identified to see it can be usefully exploited.

So far, the known candidates are:
XTMAXBOX.xbe
plus 2 MA utility XBEs devz3ro spotted in his cache.

Please feel free to post others.  The hunt is on. biggrin.gif
Title: UDE/5713+
Post by: PedrosPad on July 12, 2004, 07:52:00 AM
Candidate analysis.

(for completeness) 5960's xodash\update.xbe:
CODE
Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x409BCB24 Fri May 07 18:45:08 2004
Title ID                            : 0xFFFE0000
Title name                          : "Online Updater Application"
Alternate title ID's                :
   none
Allowed media types                 : 0x80000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x7FFFFFFF
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE

Title ID = Dashboard families 0xFFFE0000, and date > 05 Aug 2003, so smile.gif
Allowed media types = XBE_MEDIA_HDD smile.gif
(but all known holes closed sad.gif)

XMTAXBOX.xbe:
CODE
Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3E67B7E8 Thu Mar 06 21:04:40 2003
Title ID                            : 0xFFFD0001
Title name                          : "XMTAXBOX"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x80000000
                                   : XBE_REGION_DEBUG
Date old but Title ID <> to the Dashboard families 0xFFFE0000, so smile.gif
Allowed media types = XBE_MEDIA_HDD smile.gif
Allowed game regions = XBE_REGION_DEBUG sad.gif (Not too promising, but see here)

From MechAssault's downloaded content....
MA's /E/TDATA/4d530017/$u/default.xbe:
CODE
Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3F57CBAA Fri Sep 05 00:32:58 2003
Title ID                            : 0x4D530017
Title name                          : "MechAssault"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000005
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_ELSEWHERE

So far, so good smile.gif

MA's /E/TDATA/4d530017/$u/downloader.xbe:
CODE
Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3F57CBB8 Fri Sep 05 00:33:12 2003
Title ID                            : 0x4D530017
Title name                          : "Downloader"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000005
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_ELSEWHERE

So far, so good smile.gif
Title: UDE/5713+
Post by: adil786 on July 12, 2004, 08:17:00 AM
w.i.p. is good, ill try to help aswell,

pity i dont have a 5713+ xbox... only 5101 sad.gif
Title: UDE/5713+
Post by: Angerwound on July 12, 2004, 11:40:00 AM
What timestamp is located on the update.xbe that comes with a brand new (5713) box. It would have to have the XBE_MEDIA_HDD flag if it is located within /xodash/. I really need a 5713 box. I might be interested in someone swapping my virgin 1.0 box that I use for LiVE with a 5713.. Offers?

EDIT: pedro if you could post the xbedumps of the MA .xbe's. I don't have them readily available atm.

This post has been edited by Angerwound on Jul 12 2004, 06:42 PM
Title: UDE/5713+
Post by: krayzie on July 12, 2004, 10:43:00 AM
yeah the 5713 (5659) update.xbe would have the right timestamp I guess but it might not be exploitable. (at least not the way we are used to).
Title: UDE/5713+
Post by: Angerwound on July 12, 2004, 10:51:00 AM
Anyone with a 5713 dash that wants to post up the xbedump of the 5713 update.xbe?
Title: UDE/5713+
Post by: ripcurl on July 12, 2004, 11:56:00 AM
QUOTE (Angerwound @ Jul 12 2004, 06:37 PM)
What timestamp is located on the update.xbe that comes with a brand new (5713) box. It would have to have the XBE_MEDIA_HDD flag if it is located within /xodash/. I really need a 5713 box. I might be interested in someone swapping my virgin 1.0 box that I use for LiVE with a 5713.. Offers?

EDIT: pedro if you could post the xbedumps of the MA .xbe's. I don't have them readily available atm.

 i have a brand spanking new untouched xbox 5713 which i would trade for a 1.0 anyday!! Lets do it up.

MFG 03-03-2004
k 5713
d 5969..i think
Title: UDE/5713+
Post by: Flame2k on July 12, 2004, 12:17:00 PM
You know the live tab, this might sound abit lame at first cos i dont know anything! lol (and its prob already been suggested). but has anyone thought about hexing xboxdash.xbe or something, so that live tab will execute another xbe? is that possible?

EDIT: just realised it wud prob have 2 be ms signed....

This post has been edited by Flame2k on Jul 12 2004, 07:18 PM
Title: UDE/5713+
Post by: Angerwound on July 12, 2004, 12:20:00 PM
QUOTE (Flame2k @ Jul 12 2004, 03:14 PM)
You know the live tab, this might sound abit lame at first cos i dont know anything! lol (and its prob already been suggested). but has anyone thought about hexing xboxdash.xbe or something, so that live tab will execute another xbe? is that possible?

EDIT: just realised it wud prob have 2 be ms signed....

 This in general was the purpose of the double dashboard exploit. Search for the thread somewhere around if you would like to read up on it.
Title: UDE/5713+
Post by: krayzie on July 12, 2004, 11:28:00 AM
are xbe files the only type of files that can be exploited? Couldn't  there be  vulnarubilities (or however you write it) in other type of xbox files?
Title: UDE/5713+
Post by: adil786 on July 12, 2004, 12:38:00 PM
QUOTE (Flame2k @ Jul 12 2004, 08:14 PM)
You know the live tab, this might sound abit lame at first cos i dont know anything! lol (and its prob already been suggested). but has anyone thought about hexing xboxdash.xbe or something, so that live tab will execute another xbe? is that possible?

EDIT: just realised it wud prob have 2 be ms signed....

 yes but not on new kernels, m$ learn from their mistakes.
Title: UDE/5713+
Post by: mkjones on July 12, 2004, 12:52:00 PM
QUOTE (krayzie @ Jul 12 2004, 08:28 PM)
are xbe files the only type of files that can be exploited? Couldn't  there be  vulnarubilities (or however you write it) in other type of xbox files?

You mean like Audio? I too have wonderd, there must be something they missed, this is M$ after all smile.gif

How about (looks in some xbox folders)

The creditcard files in "\xodash\media\Content" (creditcard.csv) I have no idea how they are used but they are very simple text files:

QUOTE
VISA,0
MASTERCARD,1
AMERICAN_EXPRESS,2


Is an example of the content? Maybe some data can be "pushed" into such a file to cause an overflow? This is pure bull im speaking right now but you have to get ideas from somewhere smile.gif

The same files are used in the Content folders sub folders too? But I have no idea when they are loaded, they are something to do with the Live! Dash but as I have never used it...  uhh.gif

May be worth asking the tHc guys? I mean, they have decompiled and recompiled the whole xbox dash and remade it, maybe they saw something??
Another idea? Maybe the screensaver/visualisation file that runs when you play music?? I belive its the right thumbstick press that launches it. tHc has a replacement for it? Just an idea...

Hmm.... One last one before I give up  jester.gif

The WAV files in the Audio directory?? Has anyone looked at modding these? Surely they are not "signed" in anyway, as they are basic WAVs (surprisingly NOT WMAs) again, they are launched when certain buttons are pressed.. If the main "beep" that appers when A is press could be hacked then a single button style exploit could be made up??

I have no idea if these ideas will help, but I remember the old Live! exploit thread was a LOT of brainstorming and that led to something! smile.gif

See ya.....
Title: UDE/5713+
Post by: Spectracide on July 12, 2004, 02:18:00 PM
cool.gif I can't wait to test when something solid comes out.
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 12, 2004, 03:34:00 PM
maybe the dash has an anti speaker blow out thingy, if we put a really really loud wav in there.... or not? thats the only thig i can think we would be able to do with a wav

unless we can exploit the execution process to make it  read an error and load a back up file, which can be changed (or but then we need an exploit able xbe candidate, because the kernal would check the flags still)
Title: UDE/5713+
Post by: Australian Rat on July 12, 2004, 11:30:00 PM
QUOTE (Chicken Scratch Boy @ Jul 13 2004, 06:31 AM)
maybe the dash has an anti speaker blow out thingy, if we put a really really loud wav in there.... or not? thats the only thig i can think we would be able to do with a wav

unless we can exploit the execution process to make it  read an error and load a back up file, which can be changed (or but then we need an exploit able xbe candidate, because the kernal would check the flags still)

 I doubt it.  If MS didn't put a really loud WAV in there, they certainly wouldn't put in protection to blow out the speakers.

The only thing would be with CDs being copied.  But then again, I'm pretty sure all tracks are normalised when ripped.
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 12:36:00 AM
QUOTE (krayzie @ Jul 12 2004, 08:28 PM)
are xbe files the only type of files that can be exploited? Couldn't  there be  vulnarubilities (or however you write it) in other type of xbox files?

This is a big question.
Some excellent links to read are Project B (Hacking) Overview and the 6.5MB PDF XBOX Software Hacking (all interesting but page 37 onwards covers Dashboard exploits smile.gif ).
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 12:40:00 AM
QUOTE (mkjones @ Jul 12 2004, 09:52 PM)
You mean like Audio?
How about (looks in some xbox folders)

The creditcard files in "\xodash\media\Content" (creditcard.csv)

The WAV files in the Audio directory?? Has anyone looked at modding these?

I have no idea if these ideas will help, but I remember the old Live! exploit thread was a LOT of brainstorming and that led to something! smile.gif

Indeed it did smile.gif  This is just the brainstorming  I'm hoping for biggrin.gif
Title: UDE/5713+
Post by: adil786 on July 13, 2004, 12:59:00 AM
QUOTE (PedrosPad @ Jul 13 2004, 09:36 AM)
This is a big question.
Some excellent links to read are Project B (Hacking) Overview and the 6.5MB PDF XBOX Software Hacking (all interesting but page 37 onwards covers Dashboard exploits smile.gif ).

i  highly reccomend those 2 links, excellent pdf, well done xbox-linux, very very nice and intresting!

they should update it with ude etc etc aswell..

regards
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 01:36:00 AM
QUOTE (PedrosPad @ Jul 13 2004, 09:40 AM)
Heavily snipped quote:

Indeed it did smile.gif  This is just the brainstorming  I'm hoping for biggrin.gif

Thats good then Ped.. at least it wasnt a waste of my time  biggrin.gif

Im really interested in finding a new exploit in the dash, I mean were talking M$ here.. I belive the chances are high..  beerchug.gif
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 02:33:00 AM
QUOTE (PedrosPad @ Jul 12 2004, 04:52 PM)
From MechAssault's downloaded content....

This downloaded content sounds like it could be good place to search for suitable UDE/5713 XBE's (those with the XBE_MEDIA_HDD flag smile.gif ).

What we need is a homebrew utility XBE that'll search the XBOX hard disk drives, walking the directory trees, looking for any XBE's that meet the necessary criteria to be used an an UDE bootstrap, and drop their paths and filenames into a log file on C:\ (for FTPing off wink.gif ).

That sounds like it could speed up the search.  A nice little project, should anyone wish to contribute biggrin.gif.  (I'll have a go at putting something together myself if no one beats me to it and time allows).
Title: UDE/5713+
Post by: Australian Rat on July 13, 2004, 04:47:00 AM
QUOTE (mkjones @ Jul 13 2004, 06:36 PM)
Thats good then Ped.. at least it wasnt a waste of my time  biggrin.gif

Im really interested in finding a new exploit in the dash, I mean were talking M$ here.. I belive the chances are high..  beerchug.gif

Yeah there will always be flaws in m$ code smile.gif  Just a matter of finding them.  I mean, the UDE was available essentially as early as many of the original fonts.  It was just never explored before.

Wonder what else is lieing around we haven't prodded yet?
Title: UDE/5713+
Post by: adil786 on July 13, 2004, 04:48:00 AM
QUOTE (PedrosPad @ Jul 13 2004, 11:33 AM)
This downloaded content sounds like it could be good place to search for suitable UDE/5713 XBE's (those with the XBE_MEDIA_HDD flag smile.gif ).

What we need is a homebrew utility XBE that'll search the XBOX hard disk drives, walking the directory trees, looking for any XBE's that meet the necessary criteria to be used an an UDE bootstrap, and drop their paths and filenames into a log file on C:\ (for FTPing off wink.gif ).

That sounds like it could speed up the search.  A nice little project, should anyone wish to contribute biggrin.gif.  (I'll have a go at putting something together myself if no one beats me to it and time allows).

nice, i think ldots could make this kinda program cause he's good at these things...
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 05:14:00 AM
QUOTE (adil786 @ Jul 13 2004, 01:48 PM)
nice, i think ldots could make this kinda program cause he's good at these things...

True, maybe a little linux distro could do this, but dont pressure the penguin!

Im sure hes busy enuf smile.gif

I mean, he did turn down the Mod possition for the same reasons as me, no bloody time these days  sad.gif

I would love to find some time just to PLAY a little more on my xbox not just develop new softmod tools for it  jester.gif
Title: UDE/5713+
Post by: ldots on July 13, 2004, 05:24:00 AM
tongue.gif
I dont have a 5713, but I guess a freshly Live upgraded xbox would do?
Would every file need searching or could the file extension be narrowed down? (xbe, xip,...?).
Title: UDE/5713+
Post by: adil786 on July 13, 2004, 05:45:00 AM
QUOTE (ldots @ Jul 13 2004, 02:24 PM)
True, I'm a little short on time at the moment, but I think I could easily cook up a a little package to do this search. It would be linux based of course tongue.gif
I dont have a 5713, but I guess a freshly Live upgraded xbox would do?
Would every file need searching or could the file extension be narrowed down? (xbe, xip,...?).

i would say that all files should be searched, just to add the chance of finding a vunerability...
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 05:58:00 AM
QUOTE (ldots @ Jul 13 2004, 02:24 PM)
very file need searching or could the file extension be narrowed down? (xbe, xip,...?).

I was thinking of simply scanning for *.xbe, and checking the media type for XBE_MEDIA_HDD smile.gif, but I guess crafty software houses may have renamed their XBEs...
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 06:14:00 AM
QUOTE (PedrosPad @ Jul 13 2004, 02:58 PM)
I was thinking of simply scanning for *.xbe, and checking the media type for XBE_MEDIA_HDD smile.gif, but I guess crafty software houses may have renamed their XBEs...

Hmm, do you think there are any games around or maybe even game demos (lots of MS ones on certain CDs like Halo/Links2004) that use the exploitable fonts?

I mean, you would need an origional game CD, as before but has anyone tried ever just copying a game default.xbe and folders to C and renaming the file to xboxdash?

Would it load? Or does DVD2Xbox and other such tools patch the XBE_MEDIA string??
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 06:31:00 AM
QUOTE (mkjones @ Jul 13 2004, 03:14 PM)
Or does DVD2Xbox and other such tools patch the XBE_MEDIA string??

Yes, it does (breaking the signature).   XBEs from DVDs have the XBE_MEDIA_XBOX_DVD media type, and wouldn't be able to be launched from the HDD of an XBOX with a retail BIOS sad.gif.

I've every OXM cover disk - just in case a demo XBE has both MEDIA types set wink.gif.  (and I'll search all again if Ldots produces an XBE searcher smile.gif )

Please, do keep on thinking...biggrin.gif
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 06:45:00 AM
QUOTE (PedrosPad @ Jul 13 2004, 03:31 PM)
I've every OXM cover disk - just in case a demo XBE has both MEDIA types set wink.gif.

Which reminds me, Ldots, it'll be the lower significant bit of the media type flag that needs to be checked - not simply the whole flag (XBE media flag ANDed with 0x00000001).  It's possible to set the media flag to support multiple medias.  The LSB is the HDD bit.
Title: UDE/5713+
Post by: ldots on July 13, 2004, 07:11:00 AM
I simply thought of doing a simple linux script using xbedump to search all xbe's for the XBE_MEDIA_HDD flag. Would still be automatic - as in run the default.xbe (bootloader) and afterwards ftp out the log-file.
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 07:28:00 AM
QUOTE (ldots @ Jul 13 2004, 04:11 PM)
I simply thought of doing a simple linux script using xbedump to search all xbe's for the XBE_MEDIA_HDD flag. Would still be automatic - as in run the default.xbe (bootloader) and afterwards ftp out the log-file.

That'd be ace. biggrin.gif
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 07:35:00 AM
Finally, the post I started this thread to post. biggrin.gif

Having backup up everything and taken every precaution, I have actually executed XTMAXBOX.xbe on my modded XBOX, networked to my PC with Ethereal (a Network Protocol Analyzer) running.

All that appeared to happened was that I was returned to the Evox Dashboard. sad.gif
I was hoping that ethereal would catch a DNS lookup or IP address but no, sad.gif
ethereal did actually catch a network ARC broadcast message that was sent - so I believe the XBE did run smile.gif. I'm working on the limits of my knowledge here, but the network ARC broadcast message appears to be a "Hey! I'm here"/network enrolment message.  The regular Dashboard's send these too.

I theorized that this quick-exit behavior was caused by the XBE failing to find a configuration file, and exiting.  And since it didn't try to contact any kind of server, I suspected that the DNS server/server IP address would be in that file.

I've now disassembled the file and started looking in to it.  From my interpretation of the disassembly, it appears that the program first checks the Kernel version - to ensure that it's one supported by the XTMA program (the XTMAXBOX.xbe I've got only appears to support up to K:5101 sad.gif ), then does indeed go on to look for a configuration file, one named XTMA.INI.  What's particularly interesting is that it appears to not look for this file on the HDD, but on a memory card!.  I can speculate why this might be.  I can imagine the manufacturing line operators plugging in different memcards into different XBOXs to ensure that localized copies of the operating software are sucked down from appropriate servers, etc.

Obviously we don't have a copy of this XTMA.INI file, but I'm currently trying to rebuild one from looking at how the XBE processes it.  It appears to be a text based name/value pair INI file - like a traditional Windows one.

What's potentially neat about this is, if my speculation above is correct, the XTMA.INI file can't be a signed file, and therefore the first candidate for modification and overflow investigation. smile.gif

More news as it breaks...
Title: UDE/5713+
Post by: []V[]nm6687 on July 13, 2004, 09:22:00 AM
the default.xbe file in the mechassault Tdata folder is the actual game xbe right? the internal xbe name is MechAssault.  and since this file is signed to run from the HD and also after the valid downgrade date, can't you really put the whole game on the HD and launch it as xboxdash.xbe or something like that and just go on with your savegame hack? that'd be quicker than loading up the game for a savegame hack everytime.  i dont know, this is just a thought that crossed my mind.
Title: UDE/5713+
Post by: Tomilius on July 13, 2004, 09:35:00 AM
I'm a noob, watch me be a noob in 7 colors.

And hold on.

... Okay, I still don't know what TDATA folder you're talking about. I thought maybe you meant on the DVD itself but nope.

If you mean the gamesave (which is in the UDATA folder) that default.xbe isn't MechAssault ...
Title: UDE/5713+
Post by: krayzie on July 13, 2004, 09:44:00 AM
I tried to figure out what he meant also. Put the whole game on the hd? That would ofcourse definately be a no-go. Run the xbe file from the save folder? Does the MA save even contain xbe files? don't you mean the evox xbe files or something??
Title: UDE/5713+
Post by: []V[]nm6687 on July 13, 2004, 10:00:00 AM
look at pedrospad's first post, he shows where both TDATA xbe's are.  u might not have them if you've never downloaded content from xbox live using mechassault.  this is what disables the gamesave from working i think too, but that's not the point.  anyways, i dont have the original MA game, but i would definately like to compare the default.xbe's and see if it is the actual MA exectuable.  if it is, then you could put all the media from the dvd onto the hd and launch it b/c it's hd signed.  and it would launch right away.  just rambling still though...
Title: UDE/5713+
Post by: krayzie on July 13, 2004, 10:06:00 AM
Oh you mean those MA xbe's. I'm sure they are not the same as the game xbe and it would just run some installation stuff for the extra content. They could be usefull however cuz they are supose to run on any xbox and must have a hdd flag.
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 10:06:00 AM
[]V[]nm6687 is talking about MA's /E/TDATA/4d530017/$u/default.xbe from this threads second post, and originally spotted by devz3ro.

Interesting idea []V[]nm6687.  I don't know that the default.xbe is a updated MA game engine - the xbe title may simply mean it's from MA suite of files - and I haven't had a chance to look into it yet.  But if it is, that's a very interesting idea - you could boot into MA, load the save game, and end up at Evox with no ROE! (since ROE isn't set for the boot xbe) biggrin.gif - If I had MA I'd try it.  I'll take a peek into the default.xbe when time allows to find out more.

Edit: Ok the /E/TDATA/4d530017/$u/default.xbe is 3,727,360 bytes - certainly big enough to be an updated game engine I'd have thought - although this updated game engine may have MA's savegame bug fixed  unsure.gif.
Title: UDE/5713+
Post by: Tomilius on July 13, 2004, 10:14:00 AM
I'm a noob in 7 colors.
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 13, 2004, 10:14:00 AM
it may be a n upgraded version

but replaceing it with the one from the disc would probaly cause err21 (due to media flags)
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 10:16:00 AM
QUOTE (Tomilius @ Jul 13 2004, 07:14 PM)
What's the file size? In bytes? Even better, MD5 it.

/E/TDATA/4d530017/$u/default.xbe is 3,727,360 bytes - certainly big enough to be an updated game engine I'd have thought.
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 13, 2004, 10:17:00 AM
unplug the network and try launching it? (dont want to get banned from live?)
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 10:19:00 AM
QUOTE (Chicken Scratch Boy @ Jul 13 2004, 07:14 PM)
it may be a n upgraded version

but replaceing it with the one from the disc would probaly cause err21 (due to media flags)

True, but copying MA's DVD content onto the HDD wouldn't. smile.gif
(Obviously we'd not need all the DVD contents - later levels, etc. could be left out)
Title: UDE/5713+
Post by: Tomilius on July 13, 2004, 10:19:00 AM
QUOTE (PedrosPad @ Jul 13 2004, 12:16 PM)
/E/TDATA/4d530017/$u/default.xbe is 3,727,360 bytes - certainly big enough to be an updated game engine I'd have thought.

For some reason I missed your huge post, PedrosPad. Hmm.
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 10:28:00 AM
smile.gif

Also if someone want to PM me the "xbedump d:\default.xbe -da >MAretail.txt" - that'd be good. biggrin.gif
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 10:49:00 AM
unsure.gif .

Also, info req: can you still save games on downloaded MA levels?
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 10:56:00 AM
QUOTE

Allowed media types                  : 0x00000002
                                               : XBE_MEDIA_XBOX_DVD


Info sad.gif the files are:

FuzionFrenzyDemo.xbe
MunchFinal.xbe
XDemos.xbe


Worth a shot I suppose  wink.gif
Title: UDE/5713+
Post by: adil786 on July 13, 2004, 11:08:00 AM
hi guys,

I just found out that the game "Frogger Beyond" is also exploitable, ie, gamesave wise.

You can buy it for a few pounds here in UK.

The game was made by a cheap-ass company who messed up a few files and therefore the game did not get distributed massively.

But the game still runs from original, untouched xbox.  There may be a vunerable file here... if any1 has it.?

hope something comes outta this.
Title: UDE/5713+
Post by: Angerwound on July 13, 2004, 11:10:00 AM
I placed the default.xbe onto my E partition and launched it. It boots straight to a blue screen. I even attempted launching with the original game disc within the dvdrom, this produced the same results. More testing.....
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 11:10:00 AM
smile.gif I have something:

This is the xbedump header info from the Update.xbe file taken from the game Shadow Ops: Red Mercury more info about the game: http://www.xbox.com/en-gb/shadowops/

QUOTE
Certificate
~~~~~~~~~~~
Size of certificate           : 0x000001EC
Certificate timestamp     : 0x40AA006D Tue May 18 13:24:13 2004
Title ID                         : 0x49470041
Title name                     : "Online Updater Application"
Alternate title ID's          : none
Allowed media types      : 0xC00001FF
                                    : XBE_MEDIA_HDD
                                    : XBE_MEDIA_XBOX_DVD
                                    : XBE_MEDIA_ANY_CD_OR_DVD
                                    : XBE_MEDIA_CD
                                    : XBE_MEDIA_1LAYER_DVDROM
                                    : XBE_MEDIA_2LAYER_DVDROM
                                    : XBE_MEDIA_1LAYER_DVDR
                                    : XBE_MEDIA_2LAYER_DVDR
                                    : XBE_MEDIA_USB
                                    : XBE_MEDIA_ALLOW_UNLOCKED_HDD
Allowed game regions     : 0x00000004
                                    : XBE_REGION_ELSEWHERE
Allowed game rating       : 0x00000000
Disk number                  : 0x00000000
Version                         : 0x00000001


What I wanna know is, what the HELL do:

QUOTE
: XBE_MEDIA_USB
and
: XBE_MEDIA_ALLOW_UNLOCKED_HDD


Mean  blink.gif

I REALLY hope this helps, if you need any more info PED then PM me  biggrin.gif
Title: UDE/5713+
Post by: adil786 on July 13, 2004, 11:15:00 AM
QUOTE
XBE_MEDIA_ALLOW_UNLOCKED_HDD?



HUH??? what????
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 11:16:00 AM
QUOTE (adil786 @ Jul 13 2004, 08:15 PM)


HUH??? what????

tell me about it  jester.gif

When I saw that I just though "HOLY SHIT"

And just look at the rest of em:

QUOTE
                                    : XBE_MEDIA_HDD
                                    : XBE_MEDIA_XBOX_DVD
                                    : XBE_MEDIA_ANY_CD_OR_DVD
                                    : XBE_MEDIA_CD
                                    : XBE_MEDIA_1LAYER_DVDROM
                                    : XBE_MEDIA_2LAYER_DVDROM
                                    : XBE_MEDIA_1LAYER_DVDR
                                    : XBE_MEDIA_2LAYER_DVDR
                                    : XBE_MEDIA_USB
                                    : XBE_MEDIA_ALLOW_UNLOCKED_HDD


Its like ALL the types you could ever dream off  rotfl.gif

AND this is a BRAND new game, only been out since e3 smile.gif so its bound to run on new Kernals, well some of them maybe?

Dont wanna get too excited, see what Ped has to say..
Title: UDE/5713+
Post by: YoshiKool on July 13, 2004, 11:26:00 AM
i'm pretty sure that won't be exploitable, dream broken basically - it's a newer update.xbe so the font exploits won't be there, unless some other exploit comes into being...
Title: UDE/5713+
Post by: adil786 on July 13, 2004, 11:31:00 AM
QUOTE (YoshiKool @ Jul 13 2004, 08:26 PM)
i'm pretty sure that won't be exploitable, dream broken basically - it's a newer update.xbe so the font exploits won't be there, unless some other exploit comes into being...

let the guy have his 2 mins m8...
Title: UDE/5713+
Post by: Tomilius on July 13, 2004, 11:32:00 AM
QUOTE (YoshiKool @ Jul 13 2004, 01:26 PM)
i'm pretty sure that won't be exploitable, dream broken basically - it's a newer update.xbe so the font exploits won't be there, unless some other exploit comes into being...

We're looking for new exploits. That's kind of the point.

I think?
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 11:37:00 AM
QUOTE (YoshiKool @ Jul 13 2004, 08:26 PM)
i'm pretty sure that won't be exploitable, dream broken basically - it's a newer update.xbe so the font exploits won't be there, unless some other exploit comes into being...

Yeh but that doesnt mean it cant be exploited using something else, I mean it can be run from the HD, by the looks of it anyway.. So that means it can hopefully be run as a replacement for xboxdash.xbe much like UDE is run now with the OLD update file..

All that needs to be done is find a flaw in this file and it could at very least be another update.xbe to add to the list if you are finding it hard to find another..

I have no idea if anything will come of it, but we do have some kind of recent exploits in the form of the EEE so you never know!

If not, it was still nice to see all those strange media flags in an XBE, I mean, USB? and Unlocked HD?

Either M$ really have there system locked and these are in for a reason or it could be of use to someone...

Also, its a decent game smile.gif and works with Kai ;P
Title: UDE/5713+
Post by: YoshiKool on July 13, 2004, 11:42:00 AM
i guess just about anyone here with a way to recover could try booting that updatexbe up on boot with an unlocked hdd... i don't think the kernel passes a "unlocked hdd" parameter to theboot xbe but who knows...
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 11:43:00 AM
QUOTE (Tomilius @ Jul 13 2004, 08:32 PM)
We're looking for new exploits. That's kind of the point.

I think?

I hope its the point anyway smile.gif

I was sure M$ had us all screwd with the dash updates etc a few months ago, a few clever new members later and here we are with a new PBL an updated NKPatcher and the UDE and EEE exploits, its been a non stop few weeks!

Hopefully we can all ride the wave to another exploit of some kind, something that runs on the latest kernels and will re-open the exploits as a real option other than getting a chip..

Its a shame the Linux guys dont seem to be working on anything anymore, maybe we pissed them off hacking the MA fonts  jester.gif
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 11:44:00 AM
QUOTE (Dark Master Sephiroth @ Jul 13 2004, 08:41 PM)
: XBE_MEDIA_ALLOW_UNLOCKED_HDD
but why in the world would this be there it makes no since

Who knows? My 120gb is locked up so I cant test it but like Yoshi says, someone give it a try smile.gif

Any idea what the USB thing could be? I assume memory card support but why?
Title: UDE/5713+
Post by: YoshiKool on July 13, 2004, 11:51:00 AM
that update.xbe is taunting us imo, i can understand most of the tags but dual layer and stuff like that? the fuck?
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 11:53:00 AM
QUOTE (YoshiKool @ Jul 13 2004, 08:51 PM)
that update.xbe is taunting us imo, i can understand most of the tags but dual layer and stuff like that? the fuck?

True, its a very evil little file full of false hope and cruelness  cool.gif

Pedro PMed me, seems very interested smile.gif hope he can work his magic..
Title: UDE/5713+
Post by: cyberplague on July 13, 2004, 11:56:00 AM
Only thing I can think as far as all the new media flags is... xbox 2(next) whatever...

Just a thought...hopefully this works out, running out of local stores with old versions to mod for friends and family.

CP
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 11:59:00 AM
QUOTE (cyberplague @ Jul 13 2004, 08:56 PM)
Only thing I can think as far as all the new media flags is... xbox 2(next) whatever...

Just a thought...hopefully this works out, running out of local stores with old versions to mod for friends and family.

CP

Xbox 2 eh? well yes, I suppose? That would help back up the idea of backwards compatibility wink.gif

Wish I had some more files with interesting headers, but nope, the rest are very boring sad.gif

I urge anyone out there to start looking now smile.gif
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 12:18:00 PM
smile.gif

Tested 3 more games....

QUOTE

Full Spectrum Warriar: Good news smile.gif

Allowed media types                 : 0x400001FF
                                    : XBE_MEDIA_HDD
                                    : XBE_MEDIA_XBOX_DVD
                                    : XBE_MEDIA_ANY_CD_OR_DVD
                                    : XBE_MEDIA_CD
                                    : XBE_MEDIA_1LAYER_DVDROM
                                    : XBE_MEDIA_2LAYER_DVDROM
                                    : XBE_MEDIA_1LAYER_DVDR
                                    : XBE_MEDIA_2LAYER_DVDR
                                    : XBE_MEDIA_USB
                                    : XBE_MEDIA_ALLOW_UNLOCKED_HDD



QUOTE

Rainbow 6 3: More Good news smile.gif

Allowed media types                 : 0x400001FF
                                    : XBE_MEDIA_HDD
                                    : XBE_MEDIA_XBOX_DVD
                                    : XBE_MEDIA_ANY_CD_OR_DVD
                                    : XBE_MEDIA_CD
                                    : XBE_MEDIA_1LAYER_DVDROM
                                    : XBE_MEDIA_2LAYER_DVDROM
                                    : XBE_MEDIA_1LAYER_DVDR
                                    : XBE_MEDIA_2LAYER_DVDR
                                    : XBE_MEDIA_USB
                                    : XBE_MEDIA_ALLOW_UNLOCKED_HDD


BUT:

QUOTE

Driv3r: Not so good sad.gif

Allowed media types                 : 0x00000202
                                    : XBE_MEDIA_XBOX_DVD



ALL these tests are on the udate.xbe found on the ROOT of the DVDs smile.gif

If anyone needs info, PM me... or check your game collection wink.gif
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 12:30:00 PM
sad.gif

Sorry for jumping to conclusions!

Its also worth mensioning I used Quix to extract the Update.xbe from the Special Ops DVD? I am not sure if that does patching on-the-fly??

Oh dear! Im starting to doubt this "finding"  blink.gif

I knew it seemed too good to be true...  ph34r.gif

------------------------------------------------------------
EDIT:
------------------------------------------------------------

A quick google has shown me the error of my ways sad.gif

FROM: http://dvd2xbox.xbox.../changelog.html

QUOTE
v0.4.3
Changed set media type from 0x000000FF to 0x400001FF to enable start of app even from  unlocked hdd.


AHH!  unsure.gif  bugger, looks like I may have been duped!

Does anyone know if Quix patches files it takes from DVDs in the SAME way? if so, the Specual Ops file is useless!  sad.gif

Ohh well, at least I tried..

If this has shown one thing it will at least help ldots produce his searching app so he doesnt fall for the same mistake..

I do however hold a hope that the Special Ops file is for real, it was taken from a real DVD not my HD unlike the rest of the files....

unsure.gif feell kinda foolish now, guess I got caught up in the excitement!!!

Hope I dont put people off looking  dry.gif  I will go and stick my head in a door for a moment, see if I can knock some scence back in  unsure.gif
Title: UDE/5713+
Post by: devz3ro on July 13, 2004, 12:41:00 PM
CODE

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3E306D50 Thu Jan 23 17:31:44 2003
Title ID                            : 0xFFFE0000
Title name                          : "Online Updater Application"
Alternate title ID's                : none
Allowed media types                 : 0x00000001
                                    : XBE_MEDIA_HDD
Allowed game regions                : 0x7FFFFFFF
                                    : XBE_REGION_US_CANADA
                                    : XBE_REGION_JAPAN
                                    : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x1012A700


&

s1914880:

CODE

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3D5D3C09 Fri Aug 16 13:53:13 2002
Title ID                            : 0xFFFE0000
Title name                          : "Online Updater Application"
Alternate title ID's                : none
Allowed media types                 : 0x00000001
                                    : XBE_MEDIA_HDD
Allowed game regions                : 0x7FFFFFFF
                                    : XBE_REGION_US_CANADA
                                    : XBE_REGION_JAPAN
                                    : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x10027100


as rmenhal stated before K:5713+ first checks the Title ID which must be 0xFFFE0000, if true it then checks the timestamp (thanks to PedrosPad for pointing out) which has to be later than around august 2003. If either of the two aren't true, it isn't going to boot (unless you're a eeprom hacker wink.gif).

-devz3ro

http://sh0x.tk/
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 12:42:00 PM
mkjones, pity - but well spotted - want me to zap your posts to tidy the thread up?
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 12:46:00 PM
QUOTE (devz3ro @ Jul 13 2004, 09:41 PM)
as rmenhal stated before K:5713+ first checks the Title ID which must be 0xFFFE0000, if true it then checks the timestamp (thanks to PedrosPad for pointing out) which has to be later than around august 2003. If either of the two aren't true, it isn't going to boot (unless you're a eeprom hacker wink.gif).

-devz3ro

http://sh0x.tk/

Yeh, I noticed the 0xFFFE0000 seemed ok, but this may again be either DVD2XBOX or Quix, I am guessing you missed my last post above  rolleyes.gif

Im kinda pissed off now sad.gif I should have reserched before posting, but I was SURE the Special Ops file wouldnt be un-hacked? Now im pretty sure Qwix has messed with it..

Sorry guys!  unsure.gif  Hopefully I havent put us behind sad.gif
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 12:49:00 PM
QUOTE (PedrosPad @ Jul 13 2004, 09:42 PM)
mkjones, pity - but well spotted - want me to zap your posts to tidy the thread up?

Could be worth it man  unsure.gif

Or it could serve as a lesson for others  rolleyes.gif

Up to you smile.gif its your thread!
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 02:12:00 PM
smile.gif. - doesn't let me load a savegame sad.gif, but that's normal for the demo content.

Moved E:\MA to C:\.  Renamed HDD MA's default.xbe to xboxdash.xbe, and booted.  Doesn't work - (interesting symptoms through - blue screen and the HDD sounds like it is trying to locate a missing file). – same symptom with mod chip on or off.

Moved E:\MA to E:\ - doesn’t work.  Hmmmm. It seems the HDD MA engine won’t run from the root folder on any drive, but works fine in a folder.  Hmmmm.

I know where a folder is on C:\ - the C:\xodash folder!.  Popped the E:\MA contents into C:\xodash folder, renamed default.xbe – xboxonline.xbe – and rebooted.

Got Error21 on boot – odd.  Hadn’t even pressed the XBOX Live Dashboard option. – it seems that Dash 5960 must have the CRC of the C:\xodash\xonlinedash.xbe in C:\xboxdash.xbe, or C:\xboxdash.xbe checksums the C:\xodash\xonlinedash.xbe on launch.  Errrr.

Downgraded to 5659 – (that’ll still work on K:5713 I’m sure).  Booted fine and now when I press the XBOX Live option, the MA demo runs – mod chip off biggrin.gif

This is looking good.  I powered on the XBOX using the DVD-tray eject, and popped in a backup DVD-RW.  Left the tray open while the Dashboard 5659 booted.  Closed the tray and the same time I pressed the XBOX Live option.  Upshot? – I was running the MA demo on a retail XBOX, with a backup DVD-RW in the closed DVD-tray!.

Unfortunately, the demo MA won’t let me load a gamesav, but if the retail MA can be stripped down to fit in C:\xodash, with just enough to load the gamesav – I think we’ve got it cracked.  Not quite as pretty as UDE, but it would give K:5713+ owners a way to play backup DVD-RWs.

PS. And because we’re hijacking C:\xodash\xonlinedash.xbe, there’s no chance of it updating to Dashboard 5960 biggrin.gif

[]V[]nm6687, your contribution may just have cracked this smile.gif

Edit: Hey! what da you know - deleting the MA demos "LiveDemo.mgf" get's you the load game options back biggrin.gif

Edit2: Bugger - I selected the "Run Linux" save game, and MA pops up a dialog saying it can't load that save game  sad.gif.  Looks like they have fixed this hole in the new XBE.
Title: UDE/5713+
Post by: Mate98 on July 13, 2004, 02:33:00 PM
QUOTE (PedrosPad @ Jul 13 2004, 11:12 PM)
[]V[]nm6687, your contribution may just have cracked this smile.gif


well done the both of u i wish i could help in some way but im a n00b when it comes to the tech stuff i mean i can get it all to work no probs but i just dont know where to go to find leaks in the xbes and stuff =(
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 02:56:00 PM
QUOTE ([)
V[]nm6687,Jul 13 2004, 11:31 PM] hey pedrospad look at my post above yours about the splinter cell 2 xbe's

Is there a GameSav exploit for SC2?  If so, go for it - some of the ideas voiced above may be helpful.

PS. You do know that 4920's update.xbe won't work on K:5713+?
Title: UDE/5713+
Post by: []V[]nm6687 on July 13, 2004, 03:11:00 PM
QUOTE (PedrosPad @ Jul 13 2004, 06:56 PM)
PS. You do know that 4920's update.xbe won't work on K:5713+?

i thought that 5713+ would still launch the gamesave hack for 007 wouldn't it? so you're saying that any xbe that has a timestamp prior to Aug 3, 2003 will never boot on a 5713+ K?? fuck
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 03:18:00 PM
QUOTE ([)
V[]nm6687,Jul 14 2004, 12:11 AM]i thought that 5713+ would still launch the gamesave hack for 007 wouldn't it? so you're saying that any xbe that has a timestamp prior to Aug 3, 2003 will never boot on a 5713+ K?? fuck

007 GameSav should work fine.  It uses 007 AUF, not 4290's update.xbe.
and
No, only XBEs that have the Dashboard's title ID, AND a date < Aug 3, 2003 won't boot on K:5713+.  Other early XBEs will.
Title: UDE/5713+
Post by: Angerwound on July 13, 2004, 03:23:00 PM
The HDD-signed xbe incorporates the gamesave bug fix.
Title: UDE/5713+
Post by: ldots on July 13, 2004, 03:51:00 PM
sad.gif
I could start to see if it's possible to strip MA to something like 300-400 MB though.

Back to the original topic smile.gif
I made the XBE media flag scanner, but again, as I'm not on XBOX!Live the result from my own scan was not that useful. Currently it locates every xbe in C: and E: and checks the media flag. If its XBE_MEDIA_HDD flagged the certificate will be printed. The log file with first hit looks like this :
CODE
--------------------------------------------------
  Scanning HDD for xbe's with XBE_MEDIA_HDD flag
--------------------------------------------------



----------------
Entering /mnt/C:
----------------


***************************************************************************
Correct Media flag found in : /mnt/C/xodash/update.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x409BCB24 Fri May  7 17:45:08 2004
Title ID                            : 0xFFFE0000
Title name                          : "Online Updater Application"
Alternate title ID's                :
       none
Allowed media types                 : 0x80000001
                                    : XBE_MEDIA_HDD
Allowed game regions                : 0x7FFFFFFF
                                    : XBE_REGION_US_CANADA
                                    : XBE_REGION_JAPAN
                                    : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x185EAD00


So, what else would you guys like?
To check more file extensions : xip's ?
To check X,Y,Z drives ?

Let me know and I'll add the changes. Then other users with a (soft)modded xbox could run this to build up a database of HDD flaggged xbe's.
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 13, 2004, 03:55:00 PM
yes so the second idea would be a no also.... (2 strikes, damn)

it appears that unless SC or AUF have hdd launchable variants, signed after the date specified, we(you?) need to find a new exploit (even if is a boot strap for 4920's update.xbe
Title: UDE/5713+
Post by: afon on July 13, 2004, 06:24:00 PM
I was thinking, and what if we used some kind of file from the xboxlive update disc itself? The way it shifts from dashboard to update app to demo makes me suscpicious. Anyone have a new xbox live update disc?
Title: UDE/5713+
Post by: chimpanzee on July 13, 2004, 06:30:00 PM
QUOTE (afon @ Jul 14 2004, 03:24 AM)
I was thinking, and what if we used some kind of file from the xboxlive update disc itself? The way it shifts from dashboard to update app to demo makes me suscpicious. Anyone have a new xbox live update disc?

But these are usually 'plugged' like newer dashboard. The chances of exploit for 5713+ still seems to be in older games MA/SC/007AUF.
Title: UDE/5713+
Post by: afon on July 13, 2004, 06:46:00 PM
Pedro, did you check for any files that MA has that are unsigned?
Title: UDE/5713+
Post by: Australian Rat on July 13, 2004, 06:56:00 PM
tongue.gif

Aw well, making progress anyway.  You all will get it, just a matter of time.
Title: UDE/5713+
Post by: mkjones on July 13, 2004, 11:26:00 PM
QUOTE (Australian Rat @ Jul 14 2004, 03:56 AM)
lol, reading pages 2 & 3 is such a killjoy.  First it looks like it's nearly there, with loads of hopeful stuff being posted, then finally coming to page 3 where everything hits a brick wall tongue.gif

Aw well, making progress anyway.  You all will get it, just a matter of time.

Yawn  unsure.gif  tell me about it, I was up all nite trying to come up with any new ideas but it seems it was all down to Qwix patching the file which I didnt think it would do sad.gif what a bummer  blink.gif

ANYWAY (trying to change the subject rolleyes.gif )

The MA thing sounds amazing, booting a game insted of the xbox dash from C has always been a cool idea, it would just mean:

a) finding a hackable game
cool.gif finding a very small game
c) finding a universaly availiable game

Of course it would need to be run from the HDD. So its gonna have to be a game update or something from Live! or maybe even from a Magazine CD... But this is gonna take a while!

I hope ldots tool comes up with something, I fear it would only be good for Live! users and possibly heavy duty ones at that. We need someone that has shit loads of live! games with downloadable content and all that...

I mean, lets try and list all the games that have downloadable content that we know of:

- Ninja Gaiden
- MechAssault
- Rainbow 6 3
- Spinter Cell (?)
- Prince of Persia (?)

Any others? I kinda lost the track of things by the end....


Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 11:28:00 PM
QUOTE (ldots @ Jul 14 2004, 12:51 AM)
I made the XBE media flag scanner, but again, as I'm not on XBOX!Live the result from my own scan was not that useful. Currently it locates every xbe in C: and E: and checks the media flag. If its XBE_MEDIA_HDD flagged the certificate will be printed.
<snip/>
So, what else would you guys like?
To check more file extensions : xip's ?
To check X,Y,Z drives ?

Let me know and I'll add the changes. Then other users with a (soft)modded xbox could run this to build up a database of HDD flaggged xbe's.

Hi ldots, good work smile.gif,

Given the problems mkjones found, with DVD2XBOX (and other utils) ticking-all-the-boxes for media types, I think we'll need a way to discard this noise or nearly every XBE will be reported.  Can you discard xbedump outputs that contain the very odd media types (USB, etc)?

Also, The X,Y,Z drives are tiny, so there's no harm including them in the search.  I say this because titles like Shemue II has an "Outrun" Easter egg, and I believe this is temporarily cached in X,Y, or Z.
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 11:43:00 PM
QUOTE (afon @ Jul 14 2004, 03:46 AM)
Pedro, did you check for any files that MA has that are unsigned?

Well that is an interesting question.

Had this thought as soon as I shutdown last night....

When the original Linux guys were looking for exploits, they were limited to HDD and memory card files, as they knew they couldn't change any files on the DVD, not because of file signing issues, but solely because they knew they couldn't burn a DVD media that would boot on a retail XBOX!.

Now that I've got MA booting on a retail XBOX from the HDD, this opens up a whole load of support data files that could now be altered and possibly exploited - graphic files, font files, level files, etc.

The fact that I managed to get the retail MA engine to work with my MA demo content, implies to me that the signatures of the support files aren't compiled into the XBE game engine (It's highly likely that demo files are different to the retail ones).  So even if the support files are runtime checksum'ed, it would be through the game engine at runtime (like GameSavs) - meaning that they may be able to be altered and then the right checksum recalculated smile.gif.  (Although I suspect that even this level of checksuming is not actually going on biggrin.gif).

I think this is a promising avenue, and I'll look into tampering with the MA demo support files next.
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 11:53:00 PM
QUOTE ([)
V[]nm6687,Jul 14 2004, 07:24 AM]good news guys, i just downloaded some levels from Xbox LIVE for Splinter Cell (the first one) and it too has its own default.xbe in TDATA that is HDD signed!  the only bad thing is that the timestamp is from 2002.

Since Splinter Cell 1 won't have the Dashboard's title ID, the date won't matter (and it's age predates the SC GameSav exploit so it may mean that the GameSav hasn't been fixed smile.gif).  This could be another good candidate biggrin.gif.
Title: UDE/5713+
Post by: PedrosPad on July 13, 2004, 11:53:00 PM
unsure.gif
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 12:06:00 AM
QUOTE (ldots @ Jul 14 2004, 12:51 AM)
I could start to see if it's possible to strip MA to something like 300-400 MB though.

That'd be good - Angerwound is already is looking into this too.

But I found that the MA Demo content appears to be significant get the HDD MA engine to the point where a GameSav could be loaded.  Not sure how big that is - may already be < 400MBs (or could be a better candidate to strip further) smile.gif.

If an exploit can be found in one of the early MA content files the engine loads, what's eventually needed could turn out to be a very small bootstrap indeed. biggrin.gif
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 12:09:00 AM
QUOTE (Australian Rat @ Jul 14 2004, 03:56 AM)
lol, reading pages 2 & 3 is such a killjoy.  First it looks like it's nearly there, with loads of hopeful stuff being posted, then finally coming to page 3 where everything hits a brick wall tongue.gif

Exciting, wasn't it?  hehe  smile.gif   tongue.gif
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 12:17:00 AM
QUOTE (mkjones @ Jul 14 2004, 08:26 AM)
The MA thing sounds amazing, booting a game insted of the xbox dash from C has always been a cool idea, it would just mean:

a ) finding a hackable game
b ) finding a very small game
c ) finding a universaly availiable game

Of course it would need to be run from the HDD. So its gonna have to be a game update or something from Live! or maybe even from a Magazine CD... But this is gonna take a while!

Why "c) finding a universaly availiable game"?  Didn't this only apply when original DVD media was required (like MA)?  If it can be FTPed onto the HDD, it could be, er,  distributed universally wink.gif.

Edit: 2nd thought - I guess we should keep an eye on the region codes.
Title: UDE/5713+
Post by: chimpanzee on July 14, 2004, 12:22:00 AM
QUOTE (PedrosPad @ Jul 14 2004, 09:17 AM)
Why "c) finding a universaly availiable game"?  Didn't this only apply when original DVD media was required (like MA)?  If it can be FTPed onto the HDD, it could be, er,  distributed universally wink.gif.

If I were a game developer, I would introduce a game that is 'not perfect' but still it will sell like hotcake, regardless of whatever game critics say :-).
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 12:27:00 AM
QUOTE ([)
V[]nm6687,Jul 14 2004, 09:00 AM] Ok everyone I think I may have solved this, but I don't have a newer box so I cannot test it.  Like i said before, the downloadable content from Splinter Cell (first one) gives you an XBE that is HDD-signed, but unlike the MA HDD-signed XBE, it has not been fixed by MS so you cannot load the hacked savegame.  This means that we can do exactly what PedrosPad did with MA, but instead we can use the first Splinter Cell and still be able to load a hacked game!  I've cut the original Splinter Cell down to about 200 MB or so, so it fits on the C partition no problem running with only the bare essential files.  This file also does not boot directly from the C drive so it has to be put in the xodash folder and renamed xonlinedash.xbe like PedrosPad did.

I'm just wondering though, PedrosPad, will this file work even tho it's timestamp is in 2002?

QUOTE (PedrosPad @ Jul 14 2004, 08:53 AM)
Since Splinter Cell 1 won't have the Dashboard's title ID, the date won't matter (and it's age predates the SC GameSav exploit so it may mean that the GameSav hasn't been fixed smile.gif).  This could be another good candidate biggrin.gif.


Does it work on your BIOS? - Does the the GameSav get you into Evox?
If it doesn't work on your BIOS, it won't work on a later one. sad.gif
If it does work on your BIOS, it has a good chance of working on a later one. biggrin.gif

PS. I bet 200MB compresses down really well wink.gif
Title: UDE/5713+
Post by: Dan Wysocki on July 14, 2004, 12:36:00 AM
QUOTE (ldots @ Jul 14 2004, 12:51 AM)
This all sounds very interresting, but of course if the HDD flagged xbe is the non-exploitable one it's a no go. I have MA but I'm not on  XBOX!Live so I dont have the HDD engine to test sad.gif
I could start to see if it's possible to strip MA to something like 300-400 MB though.

Back to the original topic smile.gif
I made the XBE media flag scanner, but again, as I'm not on XBOX!Live the result from my own scan was not that useful. Currently it locates every xbe in C: and E: and checks the media flag. If its XBE_MEDIA_HDD flagged the certificate will be printed. The log file with first hit looks like this :
CODE
--------------------------------------------------
  Scanning HDD for xbe's with XBE_MEDIA_HDD flag
--------------------------------------------------



----------------
Entering /mnt/C:
----------------


***************************************************************************
Correct Media flag found in : /mnt/C/xodash/update.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x409BCB24 Fri May  7 17:45:08 2004
Title ID                            : 0xFFFE0000
Title name                          : "Online Updater Application"
Alternate title ID's                :
       none
Allowed media types                 : 0x80000001
                                    : XBE_MEDIA_HDD
Allowed game regions                : 0x7FFFFFFF
                                    : XBE_REGION_US_CANADA
                                    : XBE_REGION_JAPAN
                                    : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x185EAD00


So, what else would you guys like?
To check more file extensions : xip's ?
To check X,Y,Z drives ?

Let me know and I'll add the changes. Then other users with a (soft)modded xbox could run this to build up a database of HDD flaggged xbe's.

This seems like a really cool app, is there any way of developing a PC version cause I have numerous backups of my whole xbox hdd on my pc and it may be nice to be able to run an app to search within folders in windows...
beerchug.gif
Title: UDE/5713+
Post by: Australian Rat on July 14, 2004, 12:49:00 AM
wink.gif
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 12:50:00 AM
QUOTE (mcjules @ Jul 14 2004, 09:43 AM)
The only files necessary to get to the menu screen are movies.mgf, text.mgf and of course default.xbe.

Without those 2 mgf files I get a blue screen. This would be quite a nice solution if the save game hack still worked cos it loads quick with no movies.

Is it possible to exploit those mgf files maybe?

[]V[]nm6687, may have this cracked with SC1.

But if not, your information will help me when I come to look at the MA content.  cheers.
Title: UDE/5713+
Post by: chimpanzee on July 14, 2004, 12:53:00 AM
QUOTE (Australian Rat @ Jul 14 2004, 09:49 AM)
lol, I bet whoever is responsible for all the bugs in MA is smacking themself in head about now...

Or Bill's smacking him in the head...? wink.gif

May be Bill himself is, after all he still codes according to some report   cool.gif
Title: UDE/5713+
Post by: Raebis on July 14, 2004, 01:02:00 AM
looks like there hasn't been newbie chatter for a while, so here goes:

wouldn't the downloaded content xbe look for support files on the cd rather than in the local dir?

meaning if you ran the hdd default.xbe wouldn't it look for the dvd with movies and other support files? what happens if it doesn't find these files on the dvd drive?
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 01:08:00 AM
QUOTE (Raebis @ Jul 14 2004, 10:02 AM)
wouldn't the downloaded content xbe look for support files on the cd rather than in the local dir?

Understandable conclusion, but one already disproved in the posts above.
Title: UDE/5713+
Post by: Raebis on July 14, 2004, 01:36:00 AM
QUOTE (Angerwound @ Jul 13 2004, 09:15 PM)
I have launched the MA .xbe that is HDD Signed with the game files along side it on the HDD. The game does launch however, the true test would be to launch it from a retail bios. This would be impossible at the moment for the entire game will not fit on the c partition.

musta missed it.

is this true for other games to? namely sc?
Title: UDE/5713+
Post by: ldots on July 14, 2004, 01:39:00 AM
QUOTE (PedrosPad @ Jul 14 2004, 08:28 AM)
Hi ldots, good work smile.gif,

Given the problems mkjones found, with DVD2XBOX (and other utils) ticking-all-the-boxes for media types, I think we'll need a way to discard this noise or nearly every XBE will be reported.  Can you discard xbedump outputs that contain the very odd media types (USB, etc)?

Also, The X,Y,Z drives are tiny, so there's no harm including them in the search.  I say this because titles like Shemue II has an "Outrun" Easter egg, and I believe this is temporarily cached in X,Y, or Z.

Will try to make these changes. Then some volunteers should try and run this scan.
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 01:56:00 AM
QUOTE (Raebis @ Jul 14 2004, 10:36 AM)
is this true for other games to? namely sc?

QUOTE (Vnm6687 @ Jul 14 2004, 09:00 AM)
I've cut the original Splinter Cell down to about 200 MB or so, so it fits on the C partition no problem running with only the bare essential files.


Raebis, are you reading the same thread as the rest of us? wink.gif
Title: UDE/5713+
Post by: Raebis on July 14, 2004, 02:05:00 AM
smile.gif lordy i must be tired, neurons aren't firing like they should be...


noobie out.
Title: UDE/5713+
Post by: ldots on July 14, 2004, 03:14:00 AM
OK - make some changes to the xbe scanner.

Will scan C,E,X,Y,Z for xbe and xip files.
Will check if they are xbe executables (relevant for xip's)
Will check for the XBE_MEDIA_HDD flag but filter those with the XBE_MEDIA_USB or XBE_MEDIA_ALLOW_UNLOCKED_HDD flag (or both).

Will dump the certificate for those hits to E:\XBE_SCAN.LOG

Procedure for running this would be upload the scan dir. to your modded xbox and run the scan\default.xbe from your dash or filemanager. When it's done reboot and ftp out the E:\XBE_SCAN.LOG files.

PM me if you want to run this scan. It's linux based (open-source) so there shouldn't be any copyright issues.

Did the scan myself but nothing interresting turned up. I havent been on Live though!
Title: UDE/5713+
Post by: mkjones on July 14, 2004, 04:00:00 AM
QUOTE (ldots @ Jul 14 2004, 12:14 PM)
OK - make some changes to the xbe scanner.
Title: UDE/5713+
Post by: ldots on July 14, 2004, 04:42:00 AM
smile.gif
It's linux based so it includes a linux kernel. I could probably strip it down, but dont see the point in spending time on that for this purpose.
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 04:46:00 AM
QUOTE (ldots @ Jul 14 2004, 01:42 PM)
I could, and it wouldn't be risky. It's just that the package is too big to be posted here smile.gif

It's a 2MB RAR - Can anyone host this for ldots?
Title: UDE/5713+
Post by: BluhDeBluh on July 14, 2004, 05:36:00 AM
QUOTE (ldots @ Jul 14 2004, 01:42 PM)
I could, and it wouldn't be risky. It's just that the package is too big to be posted here smile.gif
It's linux based so it includes a linux kernel. I could probably strip it down, but dont see the point in spending time on that for this purpose.

Assuming there is nothing made with the Xbox SDK (so it's legal), couldn't you just start a new Sourceforge project?

Another thing I've got to mention is the hard-disk drive limits that people have mentioned - does it matter what size each partition is? Couldn't you rebuild another HDD with different sized partitions (resulting in a larger C drive that you could fit more game data on)?

QUOTE
Edit: Hey! what da you know - deleting the MA demos "LiveDemo.mgf" get's you the load game options back


I have another question based on this - would LiveDemo.mgf from MechAssault be exploitable?
Title: UDE/5713+
Post by: chimpanzee on July 14, 2004, 06:12:00 AM
QUOTE (BluhDeBluh @ Jul 14 2004, 02:36 PM)
Assuming there is nothing made with the Xbox SDK (so it's legal), couldn't you just start a new Sourceforge project?

Another thing I've got to mention is the hard-disk drive limits that people have mentioned - does it matter what size each partition is? Couldn't you rebuild another HDD with different sized partitions (resulting in a larger C drive that you could fit more game data on)?



I have another question based on this - would LiveDemo.mgf from MechAssault be exploitable?

The xbedump used is already on xbox-linux cvs, ldots may have written some shell scripts for that which doesn't honour a sourceforge project. Having the xbox-linux cvs to host it is an option but there may be more admin job than needed. may be better to just put them on the usual place.

For the HD limit,  not everyone would buy a new larger HD so not practical.
Title: UDE/5713+
Post by: chimpanzee on July 14, 2004, 06:15:00 AM
QUOTE (ldots @ Jul 14 2004, 01:42 PM)
I could, and it wouldn't be risky. It's just that the package is too big to be posted here smile.gif
It's linux based so it includes a linux kernel. I could probably strip it down, but dont see the point in spending time on that for this purpose.

since most people is going to use your package to install UDE, why not just add them to it ? All one need is telnet into it and run it.
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 06:24:00 AM
QUOTE (BluhDeBluh @ Jul 14 2004, 02:36 PM)
Another thing I've got to mention is the hard-disk drive limits that people have mentioned - does it matter what size each partition is?

The HDD partition table is hardcoded into the BIOS, unlike PCs.
Title: UDE/5713+
Post by: eh. on July 14, 2004, 06:42:00 AM
QUOTE (PedrosPad @ Jul 14 2004, 09:50 AM)
[]V[]nm6687, may have this cracked with SC1.

But if not, your information will help me when I come to look at the MA content.  cheers.

This earlier version might then be of interest too:
CODE

Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3EDD3F96 Tue Jun 03 18:38:46 2003
Title ID                            : 0x4D530017
Title name                          : "MechAssault"
Alternate title ID's                :
       none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000005
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000003
Disk number                         : 0x00000000
Version                             : 0x00000401
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 06:47:00 AM
QUOTE (eh. @ Jul 14 2004, 03:42 PM)
This earlier version might then be of interest too:
CODE

Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3EDD3F96 Tue Jun 03 18:38:46 2003
Title ID                            : 0x4D530017
Title name                          : "MechAssault"
Alternate title ID's                :
       none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000005
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000003
Disk number                         : 0x00000000
Version                             : 0x00000401

Very! - it may predate the GameSav fix - and since me HDD is still currently set up to test it wink.gif
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 07:05:00 AM
QUOTE (Vnm6687 @ Jul 14 2004, 03:55 PM)
hey PedrosPad, this method using SC1 boots me to the MS dash, then i select Xbox LIVE and it boots me to SC1, then i load up the LINUX save and Evox loads right up! it works flawlessly! This MUST be the answer for newer kernel users.  i dont see why it wouldn't be? except ROE is on so you have to open it b4 u launch SC1.  but yes it works on my kernel perfectly.

Now that's the feedback we've been waiting for biggrin.gif.

Now you need to get ya 200MB package to someone with a K:5713, Dash <5960 and  who is confident they can recover (but since you leave the boot dashboard process alone, this is actually fairly safe to test. smile.gif )

I've no doubt brave some volunteers will present themselves smile.gif
Title: UDE/5713+
Post by: chimpanzee on July 14, 2004, 07:10:00 AM
QUOTE (PedrosPad @ Jul 14 2004, 04:05 PM)
Now that's the feedback we've been waiting for biggrin.gif.

Now you need to get ya 200MB package to someone with a K:5713, Dash <5960 and  who is confident that can recover (but since you leave the boot dashboard process alone, this is actually fairly safe to test. smile.gif )

I see this as an enhanced game save exploit but see a number of issues :

1. ROE - better than starting from DVD as we can have one more chance to use a different DVD/CD whatever.

2. copyright - this still means a legal copy of SC1(?)
Title: UDE/5713+
Post by: ldots on July 14, 2004, 07:12:00 AM
QUOTE (chimpanzee @ Jul 14 2004, 03:12 PM)
The xbedump used is already on xbox-linux cvs, ldots may have written some shell scripts for that which doesn't honour a sourceforge project. Having the xbox-linux cvs to host it is an option but there may be more admin job than needed. may be better to just put them on the usual place.


That is just what it is. A script that finds, and checks for executables and Media flags and dumps the certificate with xbedump to a log file. No point in making a sourceforge project or even to setup a new host. If someone can host a 2MB file that would be great - otherwise the usual places could probably host it. But if it's just a few persons who want to scan their HDD's even that is kind of pointless.
Edit : I dont want to update 4 UDE installer packages just to add this scanner smile.gif
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 07:22:00 AM
QUOTE (ldots @ Jul 14 2004, 04:12 PM)
Nice! Will be exiting to see how a 5713 kernel will react to the timestamp.

I'm sure it'll work fine - it's just legacy Dashboards that won't run on K:5713+, not all old XBEs - otherwise legacy games wouldn't work. smile.gif
Title: UDE/5713+
Post by: cyberplague on July 14, 2004, 07:24:00 AM
ldots - Send me the file @ [email protected] and I will host it for ya.

Keep up the great work guys, I wouldn't mind testing it out, I have a box sitting at home just waiting to be used and abused.  Won't be able to test it for 10 hrs as I am still at work.

Pmsg me the instructions or whatever I need.

CP
Title: UDE/5713+
Post by: chimpanzee on July 14, 2004, 07:29:00 AM
QUOTE (PedrosPad @ Jul 14 2004, 04:22 PM)
I'm sure it'll work fine - it's just legacy Dashboards that won't run on K:5713+, not all old XBEs - otherwise legacy games wouldn't work. smile.gif

MS is plugging this hole too as it was mentioned that newer dash check for xondash  sad.gif

So it is 5713+ kernel and some not so new dash would work.
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 07:38:00 AM
QUOTE (chimpanzee @ Jul 14 2004, 04:29 PM)
MS is plugging this hole too as it was mentioned that newer dash check for xondash  sad.gif

So it is 5713+ kernel and some not so new dash would work.

Correct - the C:\xodash\xonlinedash.xbe check only came in with Dash 5960!.
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 14, 2004, 07:47:00 AM
all that is needed now is a tester...

you think it can be stripped down further (200mb doesnt seem to appealing)
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 14, 2004, 08:11:00 AM
aight

i bet it'll be like 6mb or osomthing like that

i hope, rather
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 14, 2004, 08:25:00 AM
make sure you can still load the save!
Title: UDE/5713+
Post by: Angerwound on July 14, 2004, 08:28:00 AM
smile.gif Excellant job.
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 14, 2004, 08:30:00 AM
yeah about 12 o'clock i felt a bit sick, went to bed early... wake up.... bam 4 pages.
Title: UDE/5713+
Post by: Angerwound on July 14, 2004, 08:53:00 AM
If you find a 5713 tester, have them test it booting to PBLMe2, loading a bios, and then in turn launching evox or another dash.
Title: UDE/5713+
Post by: Angerwound on July 14, 2004, 09:09:00 AM
QUOTE (mikeinnj @ Jul 14 2004, 01:03 PM)
I've got an extra, brand new 5713 box laying around with dash 5659. If any of you guys want me to test this with PBLME2 or w/e just reply or PM me. I CAN run a MA gamesave exploit on it, too. I have used UDE on 14 different boxes so far, and upgraded 3 hard drives, so I'm not a total newb. Just tell me what I have to do.   biggrin.gif

sounds great, contact []V[]nm6687.
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 14, 2004, 09:20:00 AM
whats the point in adding all these layers of complication, angerwood?
why not just do the straight exploit to evox?
less chance of error, thats for sure
Title: UDE/5713+
Post by: BeMoreOpenXBox on July 14, 2004, 09:33:00 AM
This is very exciting, man. I cannot wait to test it out, for one, to run Splinter Cell (SC1) on the hard drive. The kernel of MY xbox is 5713. But MY dash board got updated by the snikey m\s to 5960. So how can I get a slightly lower version dash back and try it out?

Secondly what is in the SC1 package to run on the hard drive? Can I get all the content from MY original SC1 DVD? What is the location on C: I put the pcakage?

Thanks for the superb work. Enjoy, every one.

Title: UDE/5713+
Post by: Chicken Scratch Boy on July 14, 2004, 09:44:00 AM
all content is from sc1 disc except the .xbe any maybe a few files. MNM can give you the full rundown
Title: UDE/5713+
Post by: devz3ro on July 14, 2004, 10:15:00 AM
sad.gif
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 10:31:00 AM
QUOTE (devz3ro @ Jul 14 2004, 07:15 PM)
I guess this is where I come into play.

I'd had you in mind since the off wink.gif.  (Wondered where you'd been.)
Title: UDE/5713+
Post by: devz3ro on July 14, 2004, 10:37:00 AM
sad.gif.

-devz3ro

http://sh0x.tk/
Title: UDE/5713+
Post by: afon on July 14, 2004, 10:43:00 AM
Imagine distubiting this package. Half of the n00b 5713 users wouldnt know where to get it...
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 10:58:00 AM
QUOTE (afon @ Jul 14 2004, 07:43 PM)
Imagine distubiting this package. Half of the n00b 5713 users wouldnt know where to get it...

Been thinking about this too.  Got a few ideas brewing (as always wink.gif).
Title: UDE/5713+
Post by: Angerwound on July 14, 2004, 11:05:00 AM
beerchug.gif
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 11:19:00 AM
QUOTE (Angerwound @ Jul 14 2004, 08:05 PM)
I could see a n00b tutorial as the best way of going about it on X-S.

That was one of them - accompanied by a DOS batch file to delete unwanted files, rename and move others.  smile.gif  Surly that'd pass inspection?
Title: UDE/5713+
Post by: Angerwound on July 14, 2004, 11:32:00 AM
QUOTE (PedrosPad @ Jul 14 2004, 03:19 PM)
That was one of them - accompanied by a DOS batch file to delete unwanted files, rename and move others.  smile.gif  Surly that'd pass inspection?

Sounds good here.

BTW, changed the pinned folders around a bit. Better Look? or should we stick with the one pinned 'Pinned Topics' thread.

EDIT: LOL, dumbass free hosting company decided to not let me link to my sig anymore. Off to either make new sig or sign up for new web hosting.
Title: UDE/5713+
Post by: Angerwound on July 14, 2004, 12:11:00 PM
Nope that would break the RSA Signature. If it were that easy, there would be no need for UDE.
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 12:22:00 PM
QUOTE (Angerwound @ Jul 14 2004, 09:11 PM)
Nope that would break the RSA Signature. If it were that easy, there would be no need for UDE.

Not if the ppf patch also patched the signature back to what was required - after all it's only bytes as well. smile.gif

MA DVD ->PPFGen<- MA HDD = ppf file.
Everyone has MA DVD, applies PPF, gets MA HDD. smile.gif

(However I suspect the ppf file would turn out to be almost as big as MA HDD though wink.gif )
Title: UDE/5713+
Post by: PedrosPad on July 14, 2004, 01:07:00 PM
QUOTE (ldots @ Jul 14 2004, 12:14 PM)
OK - make some changes to the xbe scanner.

Will scan C,E,X,Y,Z for xbe and xip files.
Will check if they are xbe executables (relevant for xip's)
Will check for the XBE_MEDIA_HDD flag but filter those with the XBE_MEDIA_USB or XBE_MEDIA_ALLOW_UNLOCKED_HDD flag (or both).

Will dump the certificate for those hits to E:\XBE_SCAN.LOG

Procedure for running this would be upload the scan dir. to your modded xbox and run the scan\default.xbe from your dash or filemanager. When it's done reboot and ftp out the E:\XBE_SCAN.LOG files.

PM me if you want to run this scan. It's linux based (open-source) so there shouldn't be any copyright issues.

Did the scan myself but nothing interresting turned up. I havent been on Live though!

ldots XBE candidate scanner can now be downloaded from here (all Linux, all legal)
(Many thanks to cyberplague for the hosting beerchug.gif)
Title: UDE/5713+
Post by: Musashi on July 14, 2004, 07:28:00 PM
I have SC and Mechassault, a friend of mine is willing to lend me his xbox for a week, and guess what  !!!its a 5713!!!

I would just need the HD signed xbes and info on what files can be deleted from the complete game to reap it. PM me to test this.
Title: UDE/5713+
Post by: []V[]nm6687 on July 14, 2004, 07:57:00 PM
wink.gif) we'll see how it goes.  this is still a WIP!   biggrin.gif ;
Title: UDE/5713+
Post by: chimpanzee on July 16, 2004, 02:28:00 AM
QUOTE ([]V[]nm6687 @ Jul 16 2004, 11:25 AM)
newer kernels first look at the Title ID to see if it is a dashboard file (FFFE0000), then if it is, they look at the timestamp, and if it is prior to Aug 5, 2003, then it will fail to launch.

the thing with this update.xbe file is that it is a very old file (from 2002), but it does not have a dashboard Title ID.  this means that the timestamp will not matter. And if this thing works, then we will be able to BOOT UP to it, then exploit with the fonts, then boot our dash, and ROE will not be enabled.  this would be the perfect UDE/5713+ bootstrap for NTSC users.

get it?

the question left is, is this an updater that only share the same name or it is the same updater appears in the dashboard. I believe if there is some reference to the "Xbox Book" fonts in the file, there is a 90% probability that it is exploitable.
Title: UDE/5713+
Post by: SargeZT on July 16, 2004, 02:36:00 AM
Alright, I understand now.  However, anyone have any idea of the source of this file, as of yet?
Title: UDE/5713+
Post by: chimpanzee on July 16, 2004, 02:41:00 AM
QUOTE (SargeZT @ Jul 16 2004, 11:36 AM)
Alright, I understand now.  However, anyone have any idea of the source of this file, as of yet?

A WAG:

The XDK has some sample codes for the updater(as they have live in mind and need to help the developer on how to do it) which every live game vendor would use(and modify) to suite its need. So there could be more than one game having this probably exploitable xbe. just dreaming.
Title: UDE/5713+
Post by: chimpanzee on July 16, 2004, 02:44:00 AM
QUOTE ([)
V[]nm6687,Jul 16 2004, 11:32 AM] yeah i wish i could get this file somehow to experiment with it.  if anyone has this file... eh. *ahem* then please contact me.

AIM handle: mnm6687
Email: [email protected]

or PM me

May be we can ask ldots to do us one more favour and add a bit more functionality to the scanner to scan for the reference of "Xbox Book" or whatever fonts in the file as that is still the most prabable exploitable route.

EDIT: I just tried ldots' patcher on the update.xbe found in my MA retail DVD(that is not exploitable as it is a 'run from DVD' one) but it did find the font reference. So whoever found this updater, you can do a easy test to see if it does refer to the fonts by running the patcher against it.
Title: UDE/5713+
Post by: adil786 on July 16, 2004, 04:32:00 AM
QUOTE ([]V[]nm6687 @ Jul 16 2004, 11:27 AM)
ok guys, i finally finished my SC1 package and am trying to get it hosted at the usual places.  IT'S ONLY 1 MB.   here is the readme:

CODE

============================
SC1_5713 NTSC Dashboard Hack
============================


Info:
-----
We know that kernels 5713 or higher won't allow dash downgrades.

There's a new check in 5713's XBE loader. It checks the XBE certificate structure. If the title ID is 0xFFFE0000 (dash's ID), the kernel then checks the time and date field and anything prior to about Aug 5 2003 causes it to bail out. So dash 4920 and prior versions are out of the question.

Recently, it has been found that games that download content from Xbox LIVE also download an HDD-MS-signed default.xbe that is the actual game.  These files are located in the /E/TDATA/%TITLEID%/$u/ folder of your xbox.



Installation:
-------------
1. Downgrade your dashboard to the lowest possible version your kernel will allow (for k:5713 this is d:5659)
2. Gain FTP access to your Xbox via the Splinter Cell gamesave exploit.
3. From the Splinter Cell DVD currently inserted, FTP the necessary files below to your PC so that you can place them in your C:\xodash in a few steps.

**NOTE: The necessary files are not included in this package because they are illegal to distribute due to copyrights and whatnot. About 95% of the files that come with this package are legal to distribute because they are 0 bytes!

/LMaps/000_menu/common.lin
/LMaps/000_menu/menu.lin
/dynamicxbox.umd
/splintercellxboxretail.umd
/ThirdEchelonSettings.ini
/ThirdEchelonUser.ini
/UW.ini
/default.xbe

4. Once you have transfered all the above files from your SC1 dvd to your PC, you must use the default.xbe.ppf  patch included in this package to convert your dvd-signed default.xbe to an hdd-signed default.xbe.
5. Rename default.xbe to xonlinedash.xbe
6. Place all the the files that you just transfered to your PC back to the Xbox HDD in the directory /C/xodash.  Overwrite if needed.
7. FTP all the contents of the C folder in this package to your C:\ drive on the Xbox
8. FTP all the contents of the E folder in this package to your E:\ drive on the Xbox
9. Turn your Xbox console off.



Usage:
------
1. Your Xbox will boot the the normal M$ Dashboard and the XBOX LIVE tab will be visible.
2. Click on the XBOX LIVE tab and wait for Splinter Cell to boot up to a black screen with a loading bar. You will now be at the Splinter Cell main menu screen.
3. Select Start Game, select Linux, select Check Points
4. nkpatcher will now boot up and will load C:\evoxdash.xbe
5. enjoy and stay tuned for more on the search for a perfect UDE/5713+ bootstrap from xbox-scene.com


Issues:
-------
-currently, the only issue is that ROE (Reset On Eject) is enabled because this is a "double-dash" type of hack.




Shoutouts/Thanks:
-----------------
-PedrosPad
-devz3ro
-rmenhal
-angerwound
-Ldots
-Tomilius
-all who helped and contributed to this thread http://forums.xbox-scene.com/index.php?showtopic=241936&st=0



 -----------
// mnm6687 //
-----------

great work , your awesome,

When you click xbox live tab, does xbox need to be connected to net for exploit to work?

regards
Title: UDE/5713+
Post by: Flame2k on July 16, 2004, 06:17:00 AM
i dont think u need 2 be connected 2 the net, all the live tab does is launch xonlinedash.xbe (which is what trys to connect to live), but thats not really xonlinedash.xbe anymore, its really default.xbe and this default.xbe wont connect to the net.

you can also hex the xboxdash.xbe and get the xbox live tab to say something other than xbox live. You can modify it to say something else. i think its around offset 00143474 or just below that...  you could change it to say evo x or whatever.
Title: UDE/5713+
Post by: Infamous_One on July 16, 2004, 07:10:00 AM
Does MechAssault works with this too?
Title: UDE/5713+
Post by: Australian Rat on July 16, 2004, 07:27:00 AM
QUOTE (Infamous_One @ Jul 17 2004, 12:10 AM)
Does MechAssault works with this too?

Nope, the updated MA xbe is patched so it doesn't work with the GameSave
Title: UDE/5713+
Post by: eh. on July 16, 2004, 07:59:00 AM
QUOTE ([)
V[]nm6687,Jul 16 2004, 11:32 AM]yeah i wish i could get this file somehow to experiment with it.  if anyone has this file... eh. *ahem* then please contact me.

Hope you're not offended but I wanted Pedro to have it first; UDE's his baby eh.  

(BTW: It ref's the fonts etc. bdaybiggrin.gif )
Title: UDE/5713+
Post by: chimpanzee on July 16, 2004, 08:17:00 AM
QUOTE (eh. @ Jul 16 2004, 04:59 PM)
Hope you're not offended but I wanted Pedro to have it first; UDE's his baby eh.  

(BTW: It ref's the fonts etc. bdaybiggrin.gif )

rmenhal is the man to have it then. If it really looks for Xbox fonts, I believe the solution has been found.
Title: UDE/5713+
Post by: eh. on July 16, 2004, 08:26:00 AM
(It certainly seems to be a strong candidate for XBE_REGION_US_CANADA boxes eh.)
Title: UDE/5713+
Post by: PedrosPad on July 16, 2004, 08:47:00 AM
I'm looking into it now.  eh.  where did you find it?  Any idea how it got on your XBOX? What path on your XBOX did you find it in?
Title: UDE/5713+
Post by: krayzie on July 16, 2004, 08:52:00 AM
QUOTE
Any idea how it got on your XBOX? What path on your XBOX did you find it in?
yeah please share. Us lonely PAL users want candy too.
Title: UDE/5713+
Post by: eh. on July 16, 2004, 09:11:00 AM
QUOTE (PedrosPad @ Jul 16 2004, 05:47 PM)
I'm looking into it now.  eh.  where did you find it?  Any idea how it got on your XBOX? What path on your XBOX did you find it in?

I guess my box has an unusual past and thanks to ldots scan it's (hopefully) presently contributing to the future too eh.  cool.gif

CODE

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/4d530028/$u/update.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3DC83440 Tue Nov  5 21:12:32 2002
Title ID                            : 0x4D530028
Title name                          : "Online Updater Application"
Alternate title ID's                : none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000001
                                   : XBE_REGION_US_CANADA
Allowed game rating                 : 0x00000004
Disk number                         : 0x00000000
Version                             : 0x00010004

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/4d530028/$u/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3DC83422 Tue Nov  5 21:12:02 2002
Title ID                            : 0x4D530028
Title name                          : "NFL Fever 2003"
Alternate title ID's                : none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000001
                                   : XBE_REGION_US_CANADA
Allowed game rating                 : 0x00000004
Disk number                         : 0x00000000
Version                             : 0x00010004
Title: UDE/5713+
Post by: chimpanzee on July 16, 2004, 09:14:00 AM
"NFL Fever 2003", this is the game. Can you recall if you do something for this game(going live) or something ?

EDIT: And why the update.xbe is there ? Because it is yet another MS game, too bad MechAssault doesn't have this HDD runnable update.xbe :-)

http://www.xbox.com/...003/default.htm

check who wrote it. So may be we can focus our search on those MS titles that is live enabled to look for pontential update.xbe
Title: UDE/5713+
Post by: adil786 on July 16, 2004, 09:23:00 AM
QUOTE
Correct Media flag found in : /mnt/E/TDATA/4d530028/$u/update.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3DC83440 Tue Nov  5 21:12:32 2002
Title ID                            : 0x4D530028
Title name                          : "Online Updater Application"
Alternate title ID's                : none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000001
                                   : XBE_REGION_US_CANADA
Allowed game rating                 : 0x00000004
Disk number                         : 0x00000000
Version                             : 0x00010004


this is a breaktrhough,
Title: UDE/5713+
Post by: SSJ4Gohan on July 16, 2004, 09:59:00 AM
any chance there will be a 007AUF version? or a way to put those files on the "usual places" Because I definatly dont have SC...
Title: UDE/5713+
Post by: krayzie on July 16, 2004, 10:03:00 AM
It's not like we can pick any game we want. Since auf isn't live compatible it doesn't create xbe files with downloadable content so i don't think auf would ever be an option. Anyway maybe with any luck we don't even need a game and let the UDE do it's work.
Title: UDE/5713+
Post by: SSJ4Gohan on July 16, 2004, 10:56:00 AM
well do you think there is a possibility the files that are all needed would be uploaded? or Do I need to go rent SC or see if one of my friends has it?
Title: UDE/5713+
Post by: SSJ4Gohan on July 16, 2004, 11:19:00 AM
I did read it a few times, I just wanted to know if you were gonna upload those files that were all needed and I dont need to get the original disk. But that question is answered and I will start looking for a friend with a copy of SC.
Title: UDE/5713+
Post by: chimpanzee on July 16, 2004, 11:22:00 AM
I would put my hope on the update.xbe found as it could be the UDE for 5713+ instead of just a HDD run game save hack (SC1)
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 16, 2004, 11:25:00 AM
smile.gif
Title: UDE/5713+
Post by: -=MiNuS=- on July 16, 2004, 11:40:00 AM
QUOTE ([)
V[]nm6687,Jul 16 2004, 08:27 PM]I'm not sure if it is, but I don't see why you coldn't download some PAL levels from XboxLIVE.  If you have a any access to XboxLIVE please download some levels and see if any xbe's are in /E/TDATA/5553000c/$u/.  You can't have a modded box when you connect to XBL so a way to get into FTP is through a gamesave exploit.  That would really help us out, minus!

I don't have any acces to XboxLive.
Than i can't download PAL level.
I can see 2 files "/E/TDATA/5553000c/" directory on my Xbox :
 ->  /E/TDATA/5553000c/audiovideo.par
 -> /E/TDATA/5553000c/contentimage.xbx

I can give you more details if you need informations.
Title: UDE/5713+
Post by: []V[]nm6687 on July 16, 2004, 12:05:00 PM
Ok everybody, until the new update.xbe exploit is further investigated, you can try my super stripped down version of the SC1_5713+_NTSC package for all NTSC 5713 kernel users.  It comes with thurough instructions, but you will need to supply your own dashboard to be placed at /C/evoxdash.xbe and your own copyrighted NTSC Splinter Cell files. The only file in the E folder of this package is install.xbe which is Nkpatcher.  Use This at your own risk! This will overwrite the current install.xbe in your gamesave hack for Splinter Cell.  If you want to use something besides Nkpatcher (such as the PBLME2 edition of phoenix) than be my guest, but don't blame me for anything.  Read the readme.txt and post back here with feedback.

CODE

UEsDBBQAAAAIAHYC8TCpx4FYhyQAANM0AAAZAAAAU0MxXzU3MTNwbHVzX05UU0NfeC1zLnJhcu2Z
dVSUXff3hxLpDglp6W6ku7t76JGhhw4paSQkpUMBaSSkU5SQlm4EKQHplHfU+zZ+j/fz3j/W++d7
1pqZa63Z38/eZ+9znXOuc6kDnSmIEAGDsS4AABrgexv2gizG3gP83WC/fvXa7LHhssEAMKHXEoAK
ygaLJBaoFfPvVh3frG5/tzL0cLAAutgA9kwHdOVdIdmxwr8bl+HtsZGy3QGQ/2JsaO5gD7G0h4Ds
gNaWLB5mHoA9dOIQIV+oK84/uUL/zZWhohLQ0eWbQ08IVCL4JwnBHySGbGxsJnaW9q7ftAFi/9Kd
naUFCPhNsqEM7Z/o75Iymx1o/4h/7983iaGYMwgI1rIHsWhCrAB71a+CKCP+U1/6z3oLsLmrC8TB
jsXD0RlQAW5B7CeA6oX+pCf8k17DwdXegsXDxeyb2JEcKv4fufouJviTWAfoBi2N+3etSgQ0V3y/
a8tgPkNzhfN7rlzMnS0t7V1sHCCAvTEZrI5nUJ9Kf/JJ97vPnzpDcUsbkL2FiaaNpYmGuaW9JQvE
GvgtiFIzKEzxTzDaf4R9HWjODmCwpbOJGdDc9ger7zGUpfAn1r1/ZEl5QJyBJtKWQIirs6XLD1RZ
BRQl9ycU9T+ipIHmEBcTdaC9BbS6f4O8Q6EglT+BGP4RpOgAtADZW5tIOrjbg6HXls4/cJqb33Lv
BOVgt2EDYK+HmtraoDUj5fzn3IP/wjk6O1hD+/hXJxvYDDADMFtiayafaD6IUuvMLmFiKMhVEF7d
qePcA/z/9v/b/+vWduZm+r+/q/4evRBLF8iP26A5BApS/hOI/h9BWmYgFwcriImmMxD0de74ebPT
NkNpEn+i3f1Hmqu9I9jV+gcCRAKdS7l+R3xfdzB+n0u/Td/Qda6tkIN08z8X1u9u/8fC+l1jyG7C
acLJoqHB8c0jnt+/XHb+Ulu4uEAsrDxYzED23/Tqlf87vZS5jSXYwZ5FQ/W7f6fGf7lK/61XllGU
05AF7PHoScyhQ31L/sk32Z99f9caspmwsSj+1f+WAChD+k8Miv8bw4TjB8V/8+YUzh+UKPqb9Yfd
hP0H4+nlzSKBMn7JSn7yzSk/YylgujnlZ241pW5K4fglFp0vN6f8jIWv6qYUzl8ot6ZuTvk5Wnwu
bjZafs2K2A0j4fhttDy8YVY4fhstPkg3p/zMbYzpTSm/5iVq5uaUn7FUVdyc8rPOPWc3o3D9lt1e
8ZtTfvYoa/VmY47rFwY/400j+bVCArE3p/yMJefxTfvzsz42qDeNhPOXe0jb+uaUn1nRmr055WdW
DrBvlhXuXyJpJbxZJNy/jdqmvJtTfvbn6useRep3SvE3Cvl/pSiJqWqwKCpxAPZSHrgqACD/7gns
f0JcXUDmJuIgZzugPcjyR0yU//bp9484CQc7O+gm6m8Y4AHk3+1j/wiTsXRwtv4lNPiv6ZL/E43m
X9C0XIA/SN0kkH93JvEX6VvCNZS+iy8OoGKZ38XfD1Qo/yz+PdFfN7hfz1UetP9n8cv+S/F/S/Df
ED+S/xyHZf9lHP6e2L8pkSNQivifKKT/hfI1oX8TMnmhBJE/EYj+SNDQVJcSU/ohr8v5z2O9jl+O
9aQAe/ZHJoEKUCum361mv1khfrcy1JIU0xQDVNj4hr0qhNpy/247/c0W81dbQw52bj5ubm4uQAUR
Crc3MlT0P/KgC/v1xIj0j6KvZ3M/GmCPjkMwnAGS7S8L+Hr2+PUDG6Os7gMI+/Dj7vmvBEMrBweI
pTML0MUOCQgGWduTs/MgI0upSAggaypqQL/klKQ0yNk82PnIJcWhv2xf/5QWQGaf+eZ0GwEAMMeA
Op1LiL/9zSnnv3FqY/ntBAbqFJVUtb9/uCn1fWPaqRquKkkm2JHfImmYt+jtTE0M8+OQ+RnR3G2E
/Dxrs0O2OHUZv6Pce6vRuZlAuucWzmXRzS8QiRTYDtjS17zIul1OxS7SL2XJqdY3jFptJ666Kmfa
TQUu3l84z3X6pwuX0vJfPtnqA2deuNkZtKgkpp3KGav0YjhgMWjDsPo+qKjHT13AnhirwVL1Mgwt
7cDIZHozKjcKTy2shGjPOvhi+jEOGU8s2CHh3CBR7lxATNeZyLjtoqpmQzMQSAa/SQKWYARdxT8q
CWZmYxxJqcw7CxYLKPgwh3hVj3Sa88hPffNM40WnKRxVfoh0ylBLlsAopS7a6QBsUg2NTx9yRuME
47kvNwNYutndD4Ax9WlasQ0+e2lj8aiuYzTjAL10QH8iy9N/1ZtZj6Uw+ArZBOGu6Wde5VYE5f7d
zDUdc4KPBbof0fruHzIre8y/ZkIoIfniInopHu93FZjCJSsxer8Uu9sniBhhp8U8pewpZZgYy/1S
rqgdvi9BvNK6aEuhKA9xDqw2RCoWI4Vn0mf9+gRr6CkyKifiJdOyDCZ6JiM42Ivnngx+uRt+4AhA
3YcNXgXIf+BL6ELdyodDg3eMYyUlF0jLdUBwLSROev+R5VY4rQRBVMoIQhiG/H35dUKJtgxPfUFL
V1m8vsZ9Pj9C6lfOFOHGMqY2eJRJjuHs4Om47N3+2o5s1xD52WIJIdHTps8xa/duNya6KOVVn/eW
0DYjVabuNy7PT51J9iwfaBJJaojgOtiR+RLxvYXzHZYN7LQ3i7lrJBWL9wnDE7EtvmYXJ1W8zjdy
j/5JJa9AzezF48MHYQub0xw+Pi2NhtqCyAnPNa7zb3nWywqhBfqV0o5oIbUSzsEeb59rZUjVES6X
eZCVj9U6pgvY7Fa5Z/DQySP7AnmLM0Hvhe9KSmiol7B3a1vPfhFtZS8/ernfqFiaEUQC/7osOTK5
O8Yaqyqfev/Jk/pFftQL5W6OaN6ByiKt1GhMGKEEGqmBkZg5cqCJnSZW2Mp1CO8ofHYUofW8+NJJ
miISSvSU6sqKKIPqUCJHNritFbaHweizG/xdm7Un6mtdy3ZIWvfZB8R1lN/wdS4HI3nj5OkUduhe
kVmaKITGRO6uExEh6Fe2cLBoNt/ypTHy0m6T80XDfV8h1XCZ6+3Jclf86BUFexdaOq8fzx7DqNaJ
EAVlWmNfAcCpJz08AF41WnZRWrFjovtRTsCqC6TQF4mIxkudUG4uwIl3vf366dwh0HmXO+vWicg2
EG7eruVDTV9BMFyjQelrJ8boZx2gyCeZMJR2pLNjgmNx/N5wNkHH+S3Fvjn5Odso7LfWzQ4NI+s5
7Ti1mpNrkRimCw4IPk8xpSjxECV9es7+YAUIC/py2Y+gODTTLvUJfriLoPshEYQcrStxiyVDnwbt
Aoyhw0KDUuF2K3nlrF9bffJYTqijrWWNfwH5Eo/uGHf59eSRPpeRxgh7DPiQ8LOFloYQ45aH1npb
U3BgLH8tZc4V/AZ9CvMBdQ4jMypZXZJZr67C3YeF9SsCupJprIzDUTjL/M3V+hvIxq0L3VuRr/cd
sQi1rjTn9dLlHPNRBw1Eax7X98Me8A3GtsCLDNp06z1oIoVxNbKIEEnNUcaEWIQuNi12ITSK2hE4
J64Ort6SZZqyDvRs6hZd40BnW+pP18JrWWI1AyWev06+V1JSqqnSIPuasPUe9kCqOnP94Eqc7zRq
yau76/qLO4oY60hzqZmP5kFyzep0y/YQMJ+qh3ExDmtYOEZO1VTlZsKycxOlJ8OY+glimfSLiiQM
F6+J0hkDr1ry0wWXjDlnfMQzAFwzXQ9TWjxcsoyvtgea8Bi9gQ+3TDpKjdEGPBJrqfd5i7LteOk4
BqrwBUQecVR+wLBx0H7ichVVBucsL4vtsNMpgCrZzWd39yzsiRdgHG3MvXNnY1nPweyNOJPGgEmt
zpDgnacZ6aT8fB8UOZVh7uAYYKb5j6Kny4juotM1hz1RcAPEr21Wnpbepv+iuCozi3Qq++BuYXHD
ZxDew7HF2G87sx14AGASF7pmWD3UUnlQC12wOen/xZoBsneBAMFgFg8zS0BFdrwhNowW7tuYdwEr
I2QIjgpk/ig2MmSPSuUvGZiSXqkx2mkj68eSBcdREoZRxxLRedA7VVNXdVUy5EU6FQelSmEXMwyH
Rwezx2vmoT5nuE2TqqBWwwL8XNARQU5N8243HJbJvcfe8pL5GsGd07tp/iJt3sH706X7w36XxgV3
/oFdz7ljl4uMtO002ubdDpVuK0nhgReEazsqj6Q2icOKQDrmFfxPHllHMjQTbegGy1yD/dLeWeM2
TdWnPyOwPahItErcYjqhywmt76g5o2vW5fNFo5FUmLiX19kVMbPFet5V0rKhkjlf3nh576j/REP5
wPA08wXLufFsqIvabhuhz0cP2hUeMOuX7c2swF5scxe4tDhB99D64Tdu3CK4c+VBUhtNRbS5zjna
MnD9daD+VwHn4BxvNv4BKTRNamnBWZ1b586RrKXWn/Leyjsl5X7AIXi6faEpeFwl8tzBF+BOZXbd
FX9/iJ/k6kBZbBYCFFrxtPviVh+MmrxwOzVG/nogrfh9t62NYPCe2cvL81W1p5r1b7tqjomM9cu7
6zIksh+SB6EzxT4V5luTZmm2PSkPT2HeIEY0a2ISnEjq2WsnOzA7EqEbIPDcYxOhxZfwW+g7Fxcz
yZ0szCINsQshF7kURnUj7SGkyKsnnFUXBJFWvvI8ws0jXcs2A3m/rxg/ulAYzIpS9sO9aNmbeQiK
pwqLoRQND/nSQGlxT47q+iiY4rY4ZjAF4rBNWP5n9duFWbJz4iyqSUg2Ccj++k9geNoY8sbeKtLM
yFKFTPe+efMsKX44TyRCTn4p4QQSNjuW3+83rncvwkpANOrOaP3SEfyLw4k3A3fjUzRuJaKRRzek
FsRFRtwbrI9LEfG35Xh7nT1Vi2OuV6tb+pxy+S3RBbf9BqrF7HEGRTm2D3AyBT+raBXf9C1HvWjl
cgnq2qOr/dxqgjuHeh9NJVsR4ggM2QnpP2VuH0tMnRzn3H5/qiagMAhXViVqZmKIU/9IG3stlt+9
4wM43F9HuXSVPZjohAqA4MamWCTrzmDMpH44xZ7MGINQi3criPDi3qAqG59ewV14yMLSOuhMqLJP
fn63e5x4qZJnA28l8XOYkZ24COLmi1T3zmZm6WVmsdm9AyaxoL5qLtVtrQXxj3dmRUh1MOKD272T
jOqlv/g0PF1ULjMecPc8xKAsqOkzehJvza1ergXJxct+32/+ZJjgMbYUgZVGw51runmHGNO298Uc
7YfmiofGHR2oVNQJ7s9SZmHeY9PUHENQsaLDcEju0BGSkOTw5rM7khYQDeev5ejJqLwzEhL68Mms
8amrMEG8cTIJyx1FD1yiBzIyNjYndegh1cai1yKnIjqK7njb4GT8T9RYVq4X1MT47N0+MoYKqOLJ
5NuMwt0EcdoOZCg6Qp690bVmaUhNG3tYvAmV3uysJYQ6JuydCaM7KywkEP7q6KjI/Y7zctKc926n
w4iEgZhMQ85XQHezRuw10RKUgGCSYntpSwzRZ3jD8c+DS7b0Q5JnYKm0aQ86FqMYnzLTbz2EY03R
7ndNlnqejHLM0j73gAAEJhqfCexiaLeK4QU10DB2dIdsduIHiBrTWZPwzT+qx2PLDqIHXHmoHZYe
Gy1/yQIpufvki+nROhOJQZBtgMq28OPEaDpj9HPN9JqUTTGPxCkl94jLy4hrxiw3nwV8GdYR04/Q
5Mu85iEXeJggvgXdbysAFFGgTwdk0LmzW0sp9ft+m/FfzJ32to5AiLnNX1tuGCzU/mHBxLnWZT9c
bxl2qrVpxB6P9s5AuiczeYbRhw5ZotRmsHH0T7BkS6mfjy40O+pq2FHKN/UL09cI8sq4H1fTPrMy
GjeaN4nLImhtRzDW1lLX05V3uD72CAkdLW99wlnOC+kv6YzdkRnoi+FkBzq9YrJpm3N460C8nT6a
JwwebMelNZ+6Y+DdJ78M+pyeuoFxYUks3mcDUoMbGsmV2agOlOFMLDWb1t7GJMkaHPO3JghNeG6a
rK1vzaVULT5+aIVxSRalqqSGvVE65H646icuF+isSYrJOzG70rAEI2vaansNF1cRPknqd5cYx7Vi
ZnZ52dom1Rbvwk73mbVek3L//JvNtVOfw7cFAxMVzZnG6MGmo7CjlfK12sbZm3FZhsz+41WiVo9y
cdO/UGxmxI8PLQdkMadzfOY08HvYYJrlnzvpE0PLpDq5RPEJQjv3bvd4fvWs+N270YN1kys0rAQm
14an6gt+9MRj1QX34dmdYqKTtVMfvYurHY+YazAE26Txz4fx1935lJr+ORRI6ISx7JdHX9V74qmb
HE64aOsTPD6VkRQAasLl2O011LMpCz+7VR/VtGvRdw9keP2RK/U4CNIGf/yh6WBwadrcfXWeHinT
CnhcF3d6f2IYwtsPysMYBu9f3g/7wDRFUXdmz+J+f8lNSchLrG2WbbevlJrpREoGZWwbyzpearFu
jWct7SBW+MxkkNuXtZKawx0uLdBgnUF5sffhB/TeVpkavVebE5y7EbiC89puq49eP0fKdPPm7UrT
S44p66xbY0AhTB3sZK72f5nxisKNsBW1Y6q12O/YwuVhPtnLOdbSNAxG39Jmdw/t6HZUw/IT+UOv
+dip5N0QxEO/CkvvQhvqtl0kdSn2W2cHi56zHCfzPCbN0vEaDjTv2QaB71ZtYof6E8HcTaLuFC1+
U9nj023uxR+qZ+S9H7L2k/mWFpiLrA6WdMnmyKxWPVe1zEu+Lo460G4ePjuEXJzpnBAufErf3erh
U10I6oVzVKpoGq+fnJXy+TKtuR1z3KPkELOypu/VRTn5GQcsvNWqMtvDTm8tOrkMwFHk51TScVnC
uMYk31ppX6BGF0Wm5llSzpMTwcswDomXlJK1TzElqToYc/TemYBP5vGt6b4zxCX10VqTe0eQjczA
sS0DiTvGvMsowPwRA6w9e6wOn3x0frDVAVy9tz49wW52cCL9xlBAIm2FFFrBft19yjs266cokC3Q
bYVnYoB1OTKBOhJkPRn9KOdp2Ff9YMh6TIbBYwTRlVJpPry7j2sIFzWnBcZMwSTEG88JYKtCdXvP
eEn7Ju0Um8jH/T7v8VN0L/jdcly5ZHlaQi3qMxiHPbfD7xc+zbMXyUvqVYTgGh94GvgoM4JiEz5/
UZ2qfor3aCPRdHf/rWYmvrcBadCgMI5jLLVQ0vYud/J7mnkIA3PlNpHOVTmW90uvrSzrWwEwnUpY
HGQVF4WToP0O1N2VIJVc2sE5I/eDyFswfI/mqO9LGjrQrd5jup+MN301RlbZ5z8PqMV6KZQZkmt1
VjRRdsTkP9j0Vn+KDn4m/aKkk46TxL/G/D31wGb90UaprC1lt7vBkWANy6GyT1buPoJnr3483tl5
w5Yr0nkiYIvn2VhIAw+NbBGP42MFKuAQDykFzt5j3Zh2hUg53QlKsgvvt/c7mfrN5t3Dhe3f4A37
+Pi8V1jg2VZsONzaXn9r50RRm1nlfo7u5dbzyvfDqBaClr4oJvqGJRcoSKHHXS4okjl0CunNxAbs
acfOQfFLLBDFKnmA/Qf1I9X7Z2GqJrcysINVbkUsWmHvkaZOJTtMdVwvNo2iC3NWwXTSSi2kNoNv
IfqqEdEI5txGynd25RuExeNugX/g5Adfd2+SszI6iQoYS93G3BbGf6rBS5QMazpKoCXN6tHDv6Hi
omYJHJcLxz2WxWXaNW5E93QO3uyJdRJ7KKt4YdJ/0EgWkmjCHR87Nc+QwoncK30XNG6M++LeK6Y3
h1y57yCX9Xdj0MWXrqVphqKJ3ZkJ89QfD4cLJKj2phPQJ9UA1Pjkb8FjxVBWJJ7dQdiZ9//o5ZU8
sYBKzv8SQ7t9Ieedp3FhGEoMndnZ7Ic8rwikNMG7sBZMnudq6A26dgKGOiJVvubm8EgHq/yPfWqN
ByeRZyki72GtNBCGLnkmSxQ8DnuSQsp0jD+V4+jfKQa7vCjnBKt2a6TYvJnA0cheMNmSmOks3NTH
FfY2xhJi9y45uv8oXZBjiLFSXWzKp0DbqI9tXkhSCP6rIW2XW2cAbkrjSAULUlOr4gqGK/d0B2wn
QiMVS8drvN45zqAWBYnbB1Z8zujPiV0v1XiFjezcat6OoT9yZhcYVUGIIja8JuFBHo3Ihi3UEidw
lmdkQ5MjpmSceVllsXgwfje94jyHvEmiqrD2tugp0qdW00Q5FHF/mAs8Ovh0TaC4RFri8xqJmrGT
NWw9C4K1a19eRSOHod0dF5qeJpt6PEExEyUr64pa++2HKnwx0WGwioayR0n2GhvoroKi2xbV29O2
+AaOtkMTE6aY16nc9SiNnfoTaiNM6Ett4ANferzpPKIopfRSMdOGIgV7e1VeNLxeW0RTMxwtUQw1
A8Z7D2OXIB/922BlZFXxZwjGajyI1OjtgEn5LJzWtxplGbYZgrA3o/x4cWqf9VjFIMNAwi2RpBQ/
JOmEvIBXeXH7LmIya/04igv82VKKJe0GH5+CQxwGHEpNCt87N3/cfq4MGUiJyDJqD42a5qNT6yIW
WYo32mRw4/cSnQ7W5QVP18hrKitn0VKMT+j470PCsFGwAioaQxICN7wvMSG6aRYkrHZjSwQgTzey
XOW9nfNZucZL64Z+zEZExysivoxhjYVtPk6sLaTHM/Oa22cFnjjoIaHCsJXahb57n+kdrt2nYXB2
u9Wblp7Jbr30ZshkCYnG/MKIR8P9Ahj/+aKOOE/Ree85pyttH/Fi15c8OObkrLfAmrtDrEKBWp0v
Ds13A+QK9LdyKu2wV6eEFvkjePpm3ex6/RUh5oiYTSNGZ3xIhBQOqNltFxuYXXabgS8ousiiXRUk
wt/Zzn9KG5yDCw6Y7JcS7+FEY3yY+ZHo0UfHhNe5n2Rwql/kWggWTlaOPNWeLTkteIfX2JslqRvF
UyyOK+qG9NGj/bhZ7TjsmYCsCX4hzSwhcfQONRJFs9eL8Sy3HNNz84z2NcxtMW0PiemyDyru6bjt
XXjofXjaz+QZTeSAsQWJAKY0d5CoXOxnKmX8nh3DU2PPUAjCADFKBaOHwHPZXG0uf5dx5dQ7GVvl
dGUc8mQhVVTGCqFUGpoH86VavfefexduVJ/7laUpo92baPng2+DFo+YS5cdQDmIHi2zFJejqj3SG
bXGlgGm251mWk5krRaJX8fKULGjRgZFeGsiCaUoTQSNi8rxwr2G48bHUeLCqmQujel/Z+fAV+DP4
aje+mL0qOtbWxsaVP23NWFLQt1FizSxxskCQzS8IlMJbkZX3yw+uPKVhLmHpJlYp3d1LcgB0VFZO
smg5Xoy72nlPvFZ4UZhQRUukPELkRvp2rJhZ1G3s/d5HBzoyCTjhVTRniYEyhSMUjn724/sc03jj
GkLIayM46S6qmkrwQ9haYkaHr/FHPZRHBNRl1Wwpq0vCc7sTdlC+YEydka1NPqU8raV3NGKOYH1m
RI/0nL4ib71dEXE5g5E3uDokvznt83lo7bJIxwPlod0ceaJc201FvdaPoVPONUUGz9Tr7TN48NP5
8WJGLSFN9K4RpiJEd/1ZizLUby/vaeuqbDMGCKS8Fl7deu77OtePkl1RpEjwfY0I11mvdEXCcd9D
5hA2OiKn99iVUaweSvI0uPFYzXUyi5Z3k0YeEpwwuXMimqzpOW/qXCv1i21NRl+POX19N84FAMIA
vn1gtQIxxaxyvr6DwPi2LbewtAK6giFfDy1YHB2tABUlSJqqqtKcbLCqXzfk5ObOlkCIpQW5Owhi
Qw79g1kD4moBciB3Y2dhYyf/vX19MwD/12uCgIKI+R0F3n1UBqV1x4yyQi0EZmSUa3MdQJZwcdX7
t1vaxijRaLtxSF5eJuSClKGPU96avK96ocwd9pS18L7k2obtmzitWP49rNJCt+m0w764bWfTkwe6
WGqoT+kxP8+xi1ckj7egNYpvSz3wTWFNI9uT8ZPAMevKqonEk6EtHmDOkK8J+SsSP+Gww6dK1PpS
dpqJMcX8LjVYn+OQD5T2u/fBuxsrQh6MSUXZ3uQRME7DzKJ0bFUGuFeV2IxHAtPXC617GvEnRu1p
9G0bB86Yr784Amo6Aoa6UvFZHgVlMR+yhu6K1I7Q75tEnc0ZnpehkgMPhco5+1gx9hBpbasi66kz
2BVNDElgv4cBA8P84+oVA7QorIDJWwAABjq0KAvTQ8jb4D3osxLyt6JAc25hZ8kC8YB8ewODSjqM
+nZ0gGLipMgEcUarycCDGlm1GpuAKj9pMs6G/FFd/IcXk/M9pMReZztVcvNHfYFD0TtN/eNL5KTe
bQp4JN5pWX07vv2C1iIdrFnCVn6vXra517XuHnQufqipPJo+2ganrXhzcL8sxjvM1Hm3e3+2O6uu
ldelqA42M3hPMtzdRcl+cCB+IwYrT/4dAx6luSbBkljFPQ3zLs8RqlUOS9ahnAF12bD+6jQGq4yW
aAyKUkQ1LpUuc2da2GWF3fa7OIJeaL7BLi+ROb5Yh5bnInMRIlbyUSc2zVnxsodOyRWiw3wa+ti3
dZxLvlhjSVCBC7P7BvYz9/odb1Srq8fMId7e+KAQ76yiwskQ+dAdaeSa6tvPvTzU9qg0++VIqfAE
5mZsULH1sSSozWgzm7QFhREflr0J4O4ta1wLFYpcry9i4RJ/gxwKn26FOu1syyyiSoDZkQ4kLMYU
i3JBLfCtwR7fo6RSj7ybOSyqH4iwHJWQ8+nc7wRNWoxDX76hzoXuzjoLQYFlu3I55+ycQtKTpPkh
JEKkW166Gvdru9knej5tstge3jtAiSzMXjzYjL+fFbAfIxUgkyumwvvap8cGZydbbdWYIktdAdaS
aN17I7V09x2/HfHIW9BRIfyg6jvAaosH4SI5t59kg+h5HR09Q3oOgLCshRvPEE/e8Ppag407FEbe
nqdsokiEpbDUiU31dvaJKcOpxgXS8obCW+vbfdIxMsQTWmLPFJWxmwj8dGBD6IXC/Kl9jz9tScGN
4bu3NVulhnDBg6Nwo1HcenzRDUQ3WBzTS+BTPxCkvmDAoLyupMgpjxbH7eNlmq9r9fYbTDqamSVg
mdmf2leyIPMQL0JVFWskjyhre62cjfKYfTyjN8x50spt6zb6jkjmFX5WNwCE5Aii556w1VxwttN6
SewYkkO/Rvx+bQ5zcYsGI2Ztxtsg081o49r3zW3WGe8wqtDAOa7d5Ey4JyrxsjbM9wdqU1bypx+/
64960mCqK+HNRDXNRdCQ6rAKHmQ7ky+Hr1NFkxR5oUShZNcx/uyyRtlgnWC8jiBiOCFZbe8ijrVy
fCTgkyQXbpyd/TU/Nke2L/MbgIF8KvXjV2QyeSudXmsb5e5R7S/E1SF661Z+DWXUwfAJPnSIXKGm
L6viHWZzD69vN2EMufYhnAUOZqXCbXhyWK6zLeuHPQx3hj1ur+sdcudpqomp45XHz3WieN2aP4lv
4tWzI0B0kKQ3Z0wRUbLng6FcKxrQUqLOXxK4Q14LyJmbZ79+sfSQyRqFjEKJSyX0mZYmbWB2zCs0
UdanZQrvMnV2YGjEu88A06KReOYlQTWve/Gel7uzDpSjoUAIWt+bzrI3SWRPBtNp0K9oAzgJuowb
VqZOhJzbyrOLwyxMBw9as5GO5BQwF/eLRPJ8tKmfwATaM2+bnBggZ3fjZ2kjBQQsYD2QTGQXmd8H
OE0/U+aCH5JxKIqL7gTQ+hdA/GdyBCU5GSMuRG2AsG/tg5OGKiNXHm+GqZZVo2RWpfghEx4ew+Vs
boNReIMpmpzbqtEtniqgb4rtHU0yRpV2Fb7X0i2u0bN2j29o9LXc1qRnMB9Yg12YGs5ReeYsamVI
Lhbg/ahQiFkKuxC8uuQCB0P3MaM4cbFy9nJXaSCmDOLyXDKWb12q4LnvOQrm/ukBpjLJHLpw5WOd
7pQOzzxA78NLTvE3cqT8Zk+FEOxG2l85M2K2que8XoWdldyEZXezCZLdG3XBmMtDxWCHpSDV834n
IE89OWGeXKCEpop6UNONFBQkTOepiYXuo4RPfR11BevjAl/OVxHN0YWgtLdvYyfMjTZttndFmiqV
eWVU8ToKITINIfRCte2Ex4ssP1M6xDFIhlDfhRvkEs4V9MFnBCcwUUVegBj3Gb+S39MLNTqEd58n
REk4GwCj+iN82k7sEYks3W+oD/GTJ7jJKWIcNe30zubLkEl5FK8NpMo+Ytql1GDZfYQXQHuaJR7y
cqLt7jRVfjha5tWThLg26TWUFLl8C0kjYye/Af20ycg5pX2OKNiV/Zl6C5e58ydcbM6eJNaUngJj
Vd1qpmyc2nG9qrYYU/miHlybB4afYnEI1xbV5ooIFcqEiUMOnELy9JJR5OqPb9WlewKaO0pEciJ0
bBYnBB2emy6PE8a8ub8aK5HqYJ5+/0gwoMWsczkICfegv2w+70iQRDGYu2+Zz4w9NC/rYuqdRLdq
AVkgWYNJZzf75LZwOuqijVvNplMg4T0yCqpLcFFmLn7Uki51wnbFmLoUbi9+sZh2PS8Y+kTKJV9Z
wLbdLj0c35WSf1Wkx7feHyvUvHEEtgd/+hJhfNzs2B79DFAxKkViAJ1k9F4y08VcinYJeQNEEQH/
B1BLAQIUABQAAAAIAHYC8TCpx4FYhyQAANM0AAAZAAAAAAAAAAAAIAAAAAAAAABTQzFfNTcxM3Bs
dXNfTlRTQ194LXMucmFyUEsFBgAAAAABAAEARwAAAL4kAAAAAA==

Title: UDE/5713+
Post by: EthanHunt_IMF on July 16, 2004, 03:54:00 PM
does the install.xbe have to be signed? and if so habibi?
Title: UDE/5713+
Post by: EthanHunt_IMF on July 16, 2004, 05:09:00 PM
QUOTE ([]V[]nm6687 @ Jul 17 2004, 01:37 AM)
the install.xbe is already signed with -habibi.  but remember, that is Nkpatcher and if you dont want Nkpatcher then use PBLME2 or something.  but yea no need sign anything in my package.

That's the reason i was asking, I got this working, but I didn't want to replace it before i knew, I hate hotswapping.

I don't think anyone has posted about it, or if it even matters, this works on K:5838 also, seems like everyone else is using 5713
Title: UDE/5713+
Post by: krayzie on July 16, 2004, 05:13:00 PM
this things runs from the live tab right? So hotswapping shouldn't ever be nescesary. Also since both the gamesave exploit and the nkpatcher works on kernel 5838 this should work fine too. That probably explains the little + sign behind the 5713 in the topics name.
Title: UDE/5713+
Post by: EthanHunt_IMF on July 16, 2004, 05:21:00 PM
QUOTE ([]V[]nm6687 @ Jul 17 2004, 02:15 AM)
what xboxdash version are you currently using with your k:5838?

D 5659.03

QUOTE
this things runs from the live tab right? So hotswapping shouldn't ever be nescesary. Also since both the gamesave exploit and the nkpatcher works on kernel 5838 this should work fine too. That probably explains the little + sign behind the 5713 in the topics name.


ok, but if you replace the install.xbe with one that is un-signed, what do you think will happen?
Title: UDE/5713+
Post by: []V[]nm6687 on July 16, 2004, 05:38:00 PM
QUOTE (Protocol_Unknown @ Jul 16 2004, 09:25 PM)

when you click the live tab an Error 21 i think...

No that won't happen.  Clicking the LIVE tab will just launch splinter cell and then when you perform the gamesave it will shoot out an error because install.xbe is activated when you launch the gamesave within SC
Title: UDE/5713+
Post by: EthanHunt_IMF on July 16, 2004, 05:47:00 PM
I was just trying to make a point to krayzie that if i messed up with the install.xbe there would be no way for me to fix it other than hotswapping as the spintercell dvd as well at this exploit loads the same savegame.  Which is why I asked about the signing.  And personally i consider anything that hasn't been tested theory so even though the "+" is there in the thread title, i though i'd let you guys know it works on higher kernels also.

EDIT:Just some spelling mistakes
Title: UDE/5713+
Post by: PedrosPad on July 16, 2004, 06:01:00 PM
Ok, quick status update on UDE/5713+:

We’re getting closer to UDE, but not quite there yet.

[]V[]nm6687 has put together a Splinter Cell 1 double-dash package, that allows homebrew wink.gif programs on DVD-RW media to the played.  However, currently this is limited to USA XBOXs only, and suffers from ROE (so the exploit has to be re-triggered to change games).  We’re still hoping a PAL XBOX!Live user will have a PAL HDD flagged SC1 game engine on their XBOXs HDD.  Yell if you find one smile.gif.
(btw - It is possible to use ConfigMagic to modify the EEPROM and change a PAL XBOX into a US XBOX – I’ve done this in order to help with testing – but then PAL originals no longer play  sad.gif ).

Working has also been progressing on a Mech Assault based solution.  rmenhal adjusted the GameSav, and now this can also be launched via double-dash.  It also suffers from ROE, but works on both US and PAL XBOXs smile.gif.  This work has progressed and it is now possible to boot directly into MA, which gets you into Evox with ROE off! smile.gif  However the way this is achieved is ‘involved!’.

Most promising is the HDD update.xbe that eh. discovered with the odd xbe non-dashboard titleID.  I’ve verified that the font hole still exists biggrin.gif, but memory layout is slightly different, meaning that the existing UDE fonts don’t work.  Hopefully rmenhal will be able to perform his magic here.  This would make an ideal UDE/5713 bootstrap.  But note that eh.’s update xbe is only flagged for the USA, so we still need a PAL one.

So there's K:5713+ solutions for all - they're just being refined!
Edit: Soz. not sure on the JAPAN status.  Will need to check.
Title: UDE/5713+
Post by: devz3ro on July 16, 2004, 10:29:00 PM
Now we need to test on K:5838, I doubt it is much different from K:5713 but you never know what M$ threw in there.

-devz3ro

http://sh0x.tk/
Title: UDE/5713+
Post by: EthanHunt_IMF on July 16, 2004, 10:53:00 PM
What do you need to test on K5838?
Title: UDE/5713+
Post by: xman954 on July 16, 2004, 10:58:00 PM
********************************************************************
Title: UDE/5713+
Post by: chimpanzee on July 16, 2004, 11:02:00 PM
QUOTE (xman954 @ Jul 17 2004, 07:58 AM)
********************************************************************
Correct Media flag found in : /mnt/E/TDATA/4d530036/$u/update.xbe
********************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3FDA11E8 Fri Dec 12 19:07:20 2003
Title ID                            : 0x4D530036
Title name                          : "Downloader"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000003
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
Allowed game rating                 : 0x00000002
Disk number                         : 0x00000000
Version                             : 0x00000101


there are 2 downloader.xbe also

yet another MS title game that has the update.xbe. But this one has a late 2003 date. Since it is after the July 4 date, the font hole may have been plugged.

Beside, it is still a NTSC one, we are in need of a PAL one.
Title: UDE/5713+
Post by: krayzie on July 16, 2004, 11:24:00 PM
QUOTE (EthanHunt_IMF @ Jul 17 2004, 02:47 AM)
I was just trying to make a point to krayzie that if i messed up with the install.xbe there would be no way for me to fix it other than hotswapping as the spintercell dvd as well at this exploit loads the same savegame.  Which is why I asked about the signing.  And personally i consider anything that hasn't been tested theory so even though the "+" is there in the thread title, i though i'd let you guys know it works on higher kernels also.

EDIT:Just some spelling mistakes

So you are saying that if you mess up it wouldn't be possible to delete the gamesave and put in another gamesave to grant you acces back to your evox dash. I didn't mean to offend you on the 5838 kernel part I was just spitting out a theory. I'm happy it works for you.
Title: UDE/5713+
Post by: EthanHunt_IMF on July 16, 2004, 11:34:00 PM
QUOTE (krayzie @ Jul 17 2004, 03:24 AM)
So you are saying that if you mess up it wouldn't be possible to delete the gamesave and put in another gamesave to grant you acces back to your evox dash. I didn't mean to offend you on the 5838 kernel part I was just spitting out a theory. I'm happy it works for you.

No offense taken, just saying since that was my only way of putting the gamesave on there to begin with, if i screwed up putting an install.xbe that wasn't signed or wrong signature in the game save directory, the only way for me to fix it would be hotswapping since i don't have a memory card/mod chip etc...  

hopefully the super geniuses we have here (no that's not sarcasm, I'm dead serious) will get this thing cracked soon (again).  Makes me laugh that M$ has some of the brightest ppl in the USA(or at least they should) and they still can't make the xbox unmoddable (via software for crying out loud).  Sometimes I wonder why they even bother.  7 revisions to the hardware and they still can't get it right.

Anyway, i'm rambling how...
Title: UDE/5713+
Post by: krayzie on July 16, 2004, 11:42:00 PM
Ahh okay I wasn't aware you didn't have a memcard. You should back up your hd key right away so you never have to hotswap anymore.
Title: UDE/5713+
Post by: EthanHunt_IMF on July 17, 2004, 12:11:00 AM
already done, which brings about a question, Is it possible to upgrade the hd on a 1.6 using only softmods. seems ms changed something, now config magic doesn't work, so i had to used evox to get the eeprom image, which isn't the problem anymore, but liveinfo doesn't work with the eeprom image i get. so how am i supposed to calc a new hd password if i were to try and upgrade?

didn't mean to crap on the thread, so if anyone has any idea's pm me, don't want to fill this thread with my useless dribble.
Title: UDE/5713+
Post by: adil786 on July 17, 2004, 02:19:00 AM
QUOTE (EthanHunt_IMF @ Jul 17 2004, 09:11 AM)
already done, which brings about a question, Is it possible to upgrade the hd on a 1.6 using only softmods. seems ms changed something, now config magic doesn't work, so i had to used evox to get the eeprom image, which isn't the problem anymore, but liveinfo doesn't work with the eeprom image i get. so how am i supposed to calc a new hd password if i were to try and upgrade?

didn't mean to crap on the thread, so if anyone has any idea's pm me, don't want to fill this thread with my useless dribble.

i think it is possible with the new sc exploit,

read back a few pages.
Title: UDE/5713+
Post by: PedrosPad on July 17, 2004, 03:24:00 AM
QUOTE (chimpanzee @ Jul 17 2004, 08:02 AM)
QUOTE (xman954 @ Jul 17 2004, 07:58 AM)
********************************************************************
Correct Media flag found in : /mnt/E/TDATA/4d530036/$u/update.xbe
********************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3FDA11E8 Fri Dec 12 19:07:20 2003
Title ID                            : 0x4D530036
Title name                          : "Downloader"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                    : XBE_MEDIA_HDD
Allowed game regions                : 0x00000003
                                    : XBE_REGION_US_CANADA
                                    : XBE_REGION_JAPAN
Allowed game rating                 : 0x00000002
Disk number                         : 0x00000000
Version                             : 0x00000101


there are 2 downloader.xbe also

yet another MS title game that has the update.xbe. But this one has a late 2003 date. Since it is after the July 4 date, the font hole may have been plugged.

Beside, it is still a NTSC one, we are in need of a PAL one.

Ah! but has got HDD, a non-Dashboard titleID, US and the JAPAN region flag.  This is an improvement! We need this, for our eastern friends smile.gif. Although chimpanzee may be right about the known font hole being closed sad.gif
Title: UDE/5713+
Post by: gronne on July 17, 2004, 03:46:00 AM
Couldn't some of you guy's with authority ask live users to use ldot's scan-program to find new xbe's? Especially pal users. Ask them to run everything with mechassault or what game you needed a pal xbe for. Isn't there a chance M$ will be able to update these files before it's too late? I mean they're probably checking this thread like crazy now.

Couldn't someone ask for this on the front page or something also?
Title: UDE/5713+
Post by: adil786 on July 17, 2004, 04:59:00 AM
QUOTE (gronne @ Jul 17 2004, 12:46 PM)
Couldn't some of you guy's with authority ask live users to use ldot's scan-program to find new xbe's? Especially pal users. Ask them to run everything with mechassault or what game you needed a pal xbe for. Isn't there a chance M$ will be able to update these files before it's too late? I mean they're probably checking this thread like crazy now.

Couldn't someone ask for this on the front page or something also?

i dont see why live users would want to do it,  probally to scared to get banned or summat.

ya cant force em...
Title: UDE/5713+
Post by: krayzie on July 17, 2004, 05:56:00 AM
damnit. we need pal live users with nfl fever. I don't want to switch to ntsc.
Title: UDE/5713+
Post by: PedrosPad on July 17, 2004, 07:12:00 AM
QUOTE (Kyro @ Jul 17 2004, 03:41 PM)
hi i m a pal live user
but before being a live user i was an exploit user  rolleyes.gif  and still now i m switching from time to time, from my live configuration to an exploited configuration.

but i only got top spin, if my help is needed just PM me

Hi m8, got friend with SC1 or a blockbuster nearby?
Title: UDE/5713+
Post by: chimpanzee on July 17, 2004, 08:50:00 AM
QUOTE (gronne @ Jul 17 2004, 12:46 PM)
Couldn't some of you guy's with authority ask live users to use ldot's scan-program to find new xbe's? Especially pal users. Ask them to run everything with mechassault or what game you needed a pal xbe for. Isn't there a chance M$ will be able to update these files before it's too late? I mean they're probably checking this thread like crazy now.

Couldn't someone ask for this on the front page or something also?

I hope anyone have games(live enabled) in this page http://www.MS.com/ga...ox/default.aspx and live access to scan for the occurence of update.xbe in their game download areas.
Title: UDE/5713+
Post by: adil786 on July 17, 2004, 09:21:00 AM
QUOTE (chimpanzee @ Jul 17 2004, 05:50 PM)
I hope anyone have games(live enabled) in this page http://www.MS.com/ga...ox/default.aspx and live access to scan for the occurence of update.xbe in their game download areas.

since you asked nicely,

ill try and get my friend to do it,

been on live for over 1 year.
Title: UDE/5713+
Post by: eh. on July 17, 2004, 11:03:00 AM
QUOTE (PedrosPad @ Jul 17 2004, 03:01 AM - MA paragraph)
Working has also been progressing on a Mech Assault based solution.  rmenhal adjusted the GameSav, and now this can also be launched via double-dash.  It also suffers from ROE, but works on both US and PAL XBOXs smile.gif.  This work has progressed and it is now possible to boot directly into MA, which gets you into Evox with ROE off! smile.gif  However the way this is achieved is ‘involved!’.

That sounds like ground-breaking stuff yet again; awesome work guys!  Presuming that's based on the "v401" (per page 9 and below) then my box sure had some hidden treasures in it eh.   bdaybiggrin.gif

(Let me know if you're interested in its "Downloader" too, but it doesn't seem to have the font feature.)
CODE

***************************************************************************
Correct Media flag found in : /mnt/C/T4d530017/$u/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3EDD3F96 Wed Jun  4 00:38:46 2003
Title ID                            : 0x4D530017
Title name                          : "MechAssault"
Alternate title ID's                : none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000005
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000003
Disk number                         : 0x00000000
Version                             : 0x00000401

***************************************************************************
Correct Media flag found in : /mnt/C/T4d530017/$u/downloader.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3EDD3FA5 Wed Jun  4 00:39:01 2003
Title ID                            : 0x4D530017
Title name                          : "Downloader"
Alternate title ID's                : none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000005
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000003
Disk number                         : 0x00000000
Version                             : 0x00000401

Edit: it's "C" not "E/TDATA" as I'd saved it there (before installing mech-fonts) eh.
Title: UDE/5713+
Post by: BluhDeBluh on July 17, 2004, 12:26:00 PM
I have managed to get hold of the PAL Splinter Cell HDD-signed XBE from someone who is on Live!. biggrin.gif Unfortunately, I don't have the original version to make a comparison patch at the moment. sad.gif

From XBEDump.exe:
QUOTE

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3DC88AEE Wed Nov 06 03:22:22 2002
Title ID                            : 0x5553000C
Title name                          : "Splinter Cell"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                    : XBE_MEDIA_HDD
Allowed game regions                : 0x00000004
                                    : XBE_REGION_ELSEWHERE
Title: UDE/5713+
Post by: BluhDeBluh on July 17, 2004, 01:06:00 PM
I have a copy of it now thanks to krayzie. I'm creating the PPF patch now smile.gif
Title: UDE/5713+
Post by: BluhDeBluh on July 17, 2004, 01:21:00 PM
SCPALDVD2HDD.ppf - created using ApplyPPF3, Winrar to create the rar then UUE encode with PowerArchiver.  Thanks to Krayzie for sending me the original, the original sender of HDD-signed XBE and the usual suspects for creating all the exploits!

Copy/paste the below into scpaldvd2hdd.uue then decode with Iceows, then uncompress the rar, then apply with PPF-O-Matic 3.

CODE
UUEncode  6.5 (ZipTV components: www.ziptv.com)

begin 644 scpaldvd2hdd.rar
M4F%R(1H'`,^0B\3`=
M,Q``(````'-C<&%L9'9D,FAD9"YP<&8`L`XG!PP=D1#,R\V!G[FW9.D.*V[9
M$G"PME2A"PJJ5"4@Z.$);([44L#HV/T6"=%?1!0@)2Q-L(K"$LO2U6+DU9`+
M\87T`BHM4(`@54H2HBXEEL:*R1VV)3F2*#0I0T'2J%(K6#;O"FQ3T-]7O.>B
MQ6WXW[[\>W<6>?MW/,SOYW<\SS,W-SSMXPQGAOU6IR524>N(+[1[=+7UM*,NP<+`//UM2F;)C!GV@^TF0AV4#Y.(E&+N4V^-;Z!`0E]L4!H.M1,5\,P;3OB5(%-CRWJ&QJ40.4(A]=[M8=(24+\'8O\V2J"M+PT:`HRA>M%C+>!D3T!$:5@0[*$K.!,AHX.NPM@D1&B77HE+92)O"WO9$W2+8W]:$1-FA+
MG%<@M6:(%SEEC07T;D;C:+@'HV+DGWIYD4>E-(F!A5R.,>H,PW&YEX9L,00!
M-%&B,5P-9]$F*J2<<6J"J)BO`I^G*^MJR6]]FFF(8+!Q"[$+?GMHXKMM\B($
MN`+=$958TAQ*B\;D1#^\\\]V*Y8L3$<3M3BW*@-D=\2D@N-WAM<5T%_%X'D?$Z@80^C[K)$0.YUPT74@X[SO,5F!#)<"T
MLL[#[MK(-U?.DQD;,NZR)-'"3D7T5W%#8A&_ZVC1<('V8\$RG%)RO6VOJF=1
MI<*AK#(&!G5+ZJN&ZA>Q930OXT9_<7J"GKN)GFRR$V]ZA+HGG>UQI;+/-L_?
M4&;/Z%R*AXK$$0@8#P[/*DPV7JTIN;L[N`E<<:U]AT79U.G6[/<>TIIX[R+/
M!8??/2/W4\ANW9\YXB:WZ1E'?JMMSGJR_F+.\<2?[5&CJ/0T7Z'/%*N%;>MV/])/4W4&PY^]W>G]_TK%HS@P9[+_:PR
MP:ZE+1^OS_JX%/*XGC$]'$N_UW'7_#W7\R"#T^M??YJ/9H?FTR>6V7DSB
MO0^SRIM-.7$>YZF%^]3M6N#]>9
  • K*'=>HZW&VZQ.U\>CM6D.+3F,[:>[5(
    M-;X,W6^C6_#.K^FTL9'RRX"SL_/K-)-^\XA:KCR];\MG?\6"FPZCRC.!"^#S
    B?^O:;Q93@[KXU\+^>;R:J?E4F64./JL[;_Z`Q#U[`$`'````
    `
    end
    1069 bytes
Title: UDE/5713+
Post by: krayzie on July 17, 2004, 01:25:00 PM
nice job. will test the whole stuff soon. Now let's go find that pal update.xbe
Title: UDE/5713+
Post by: adil786 on July 17, 2004, 02:07:00 PM
QUOTE (BluhDeBluh @ Jul 17 2004, 10:21 PM)
SCPALDVD2HDD.ppf - created using ApplyPPF3, Winrar to create the rar then UUE encode with PowerArchiver.  Thanks to Krayzie for sending me the original, the original sender of HDD-signed XBE and the usual suspects for creating all the exploits!

Copy/paste the below into scpaldvd2hdd.uue then decode with Iceows, then uncompress the rar, then apply with PPF-O-Matic 3.

CODE
UUEncode  6.5 (ZipTV components: www.ziptv.com)

begin 644 scpaldvd2hdd.rar
M4F%R(1H'`,^0B\3`=
M,Q``(````'-C<&%L9'9D,FAD9"YP<&8`L`XG!PP=D1#,R\V!G[FW9.D.*V[9
M$G"PME2A"PJJ5"4@Z.$);([44L#HV/T6"=%?1!0@)2Q-L(K"$LO2U6+DU9`+
M\87T`BHM4(`@54H2HBXEEL:*R1VV)3F2*#0I0T'2J%(K6#;O"FQ3T-]7O.>B
MQ6WXW[[\>W<6>?MW/,SOYW<\SS,W-SSMXPQGAOU6IR524>N(+[1[=+7UM*,NP<+`//UM2F;)C!GV@^TF0AV4#Y.(E&+N4V^-;Z!`0E]L4!H.M1,5\,P;3OB5(%-CRWJ&QJ40.4(A]=[M8=(24+\'8O\V2J"M+PT:`HRA>M%C+>!D3T!$:5@0[*$K.!,AHX.NPM@D1&B77HE+92)O"WO9$W2+8W]:$1-FA+
MG%<@M6:(%SEEC07T;D;C:+@'HV+DGWIYD4>E-(F!A5R.,>H,PW&YEX9L,00!
M-%&B,5P-9]$F*J2<<6J"J)BO`I^G*^MJR6]]FFF(8+!Q"[$+?GMHXKMM\B($
MN`+=$958TAQ*B\;D1#^\\\]V*Y8L3$<3M3BW*@-D=\2D@N-WAM<5T%_%X'D?$Z@80^C[K)$0.YUPT74@X[SO,5F!#)<"T
MLL[#[MK(-U?.DQD;,NZR)-'"3D7T5W%#8A&_ZVC1<('V8\$RG%)RO6VOJF=1
MI<*AK#(&!G5+ZJN&ZA>Q930OXT9_<7J"GKN)GFRR$V]ZA+HGG>UQI;+/-L_?
M4&;/Z%R*AXK$$0@8#P[/*DPV7JTIN;L[N`E<<:U]AT79U.G6[/<>TIIX[R+/
M!8??/2/W4\ANW9\YXB:WZ1E'?JMMSGJR_F+.\<2?[5&CJ/0T7Z'/%*N%;>MV/])/4W4&PY^]W>G]_TK%HS@P9[+_:PR
MP:ZE+1^OS_JX%/*XGC$]'$N_UW'7_#W7\R"#T^M??YJ/9H?FTR>6V7DSB
MO0^SRIM-.7$>YZF%^]3M6N#]>9
  • K*'=>HZW&VZQ.U\>CM6D.+3F,[:>[5(
    M-;X,W6^C6_#.K^FTL9'RRX"SL_/K-)-^\XA:KCR];\MG?\6"FPZCRC.!"^#S
    B?^O:;Q93@[KXU\+^>;R:J?E4F64./JL[;_Z`Q#U[`$`'````
    `
    end
    1069 bytes

nice work!
Title: UDE/5713+
Post by: anu|b|iss on July 17, 2004, 05:16:00 PM
has rmenhal begun new fonts?
Title: UDE/5713+
Post by: PedrosPad on July 17, 2004, 08:21:00 PM
UDE/5713+ update:

Excellent news! Using eh.’s HDD based, USA flagged, update.xbe from the US NFL Fever 2003, rmenhal has performed the necessary font adjustment, and we now have a true UDE/USA package that works on all US XBOXs (v1.0-to-v1.6) and Kernels (tested all the way up to K:5838) biggrin.gif  devz3ro has built on rmenhal’s work (adding NKPatcher, etc.) and produced a distribution – this will be made available very soon.  This kind’a supersedes []V[]nm6687’s Splinter Cell 1 double-dash package, however some may still prefer this method of invocation.

Since no one has found a PAL flagged update.xbe like the US NFL Fever 2003 one sad.gif (anyone got a PAL copy of this and !Live? – yell if you find one!) For PAL users…

Using BluhDeBluh’s PAL HDD Splinter Cell 1 game engine, and PAL SC1 content, I’ve managed to duplicate []V[]nm6687’s Splinter Cell 1 double-dash packages’ functionality for PAL owners smile.gif.   And now put together the equivalent PAL distribution biggrin.gif.  Like []V[]nm6687’s original, it allows homebrew wink.gif programs on DVD-RW media to the played.  However, it suffers from ROE  - so the exploit has to be re-triggered to change games.

Since the launch of UDE/USA, booting into Mech Assault is no longer of any interest to our US friends, but investigation into this is continuing for PAL users – as this technique gets you into Evox with ROE off! smile.gif  However the way this is currently achieved is ‘involved!’.
Title: UDE/5713+
Post by: anu|b|iss on July 17, 2004, 08:28:00 PM
HALELUJAH!

Ok, this is the part where everyone gets a the cheat and starts breakdancing.

Here guys, have a trophy! No.. better, a pizza trophy!



Well done guys.
Title: UDE/5713+
Post by: devz3ro on July 17, 2004, 08:35:00 PM
Ultimate Dashboard Exploit 2 released into the wild.

Enjoy smile.gif

-devz3ro

http://sh0x.tk/
Title: UDE/5713+
Post by: db-ie on July 17, 2004, 08:45:00 PM
and i hunt this guy down where?
Title: UDE/5713+
Post by: devz3ro on July 17, 2004, 08:57:00 PM
I could tell you, but then I would have to kill you laugh.gif. The hint states "Not the usual places, but the 'other' usual places" wink.gif.

-devz3ro

http://sh0x.tk/
Title: UDE/5713+
Post by: PedrosPad on July 17, 2004, 08:57:00 PM
QUOTE (devz3ro @ Jul 18 2004, 05:35 AM)
Ultimate Dashboard Exploit 2 released into the wild.

devz3ro, since this is really a WIP thread, I think you should start a new thread with the announcement of UDE/USA, or Ultimate Dashboard Exploit 2, (or whatever you finally christen it) wink.gif.
Title: UDE/5713+
Post by: chimpanzee on July 17, 2004, 08:58:00 PM
QUOTE (db-ie @ Jul 18 2004, 05:45 AM)
and i hunt this guy down where?

I assume usual place. However, I wish the root post of UDE can be updated to include the latest version of fonts so people want DIY can get from there.

Further, it would be great to have a ppf diff of the update.xbe with a known update.xbe as well.
Title: UDE/5713+
Post by: Dolfhin on July 17, 2004, 09:07:00 PM
Congratulations guys you guys have done it once again!
Title: UDE/5713+
Post by: BluhDeBluh on July 17, 2004, 09:08:00 PM
The week or so surely has been a busy one with the whole softmodding scene and this thread:
* The "impossible" is overcome with PBL: Metoo Edition
* Hope over XTMAXBOX.xbe that seems to be fruitless
* Potentially a file is found that is signed for everything, but it turned out to be patched by the ripping app
* Release of ldot's XBE finder
* Hope over a MechAssault binary but it turns out MS have already patched it
* Turns out you can still do it with the HDD-signed Live! Splinter Cell, making the newer NTSC Xboxes finally exploitable
* Discovery of the US NTSC updater.xbe that may work for the UDE
* HDD-signed Live! Splinter Cell for PAL boxes found, making newer PAL 'boxes finally exploitable
* Release of the new version of the UDE for NTSC boxes.

Absolutely amazing everybody. Well done to everybody involved smile.gif

The race is now on to find someone to get the PAL NFL Fever 2003 update.xbe... Anybody who has a modded PAL box, and Live! please go and buy/rent this game to obtain the file.
Title: UDE/5713+
Post by: BluhDeBluh on July 17, 2004, 09:09:00 PM
QUOTE (chimpanzee @ Jul 18 2004, 05:58 AM)
Further, it would be great to have a ppf diff of the update.xbe with a known update.xbe as well.

Now that's a good idea  biggrin.gif

A PPF patch means you can post it anywhere as it's legal.
Title: UDE/5713+
Post by: Deciphile on July 17, 2004, 09:14:00 PM
I would just like to know where to get this at I've looked at the usual places and unusual  places but i'm not coming up with much
Title: UDE/5713+
Post by: chimpanzee on July 17, 2004, 09:22:00 PM
QUOTE (BluhDeBluh @ Jul 18 2004, 06:09 AM)
Now that's a good idea  biggrin.gif

A PPF patch means you can post it anywhere as it's legal.

Actually, my ideal situation is to find a ppf equivalent in linux so ldots can make his stuff better by including most possible combinations of diffs in his package and patch up a machine like that.
Title: UDE/5713+
Post by: BluhDeBluh on July 17, 2004, 09:26:00 PM
QUOTE (chimpanzee @ Jul 18 2004, 06:22 AM)
Actually, my ideal situation is to find a ppf equivalent in linux so ldots can make his stuff better by including most possible combinations of diffs in his package and patch up a machine like that.

You could use an IPS patcher.

http://www.zophar.ne.../patchutil.html has one (uIPS) with its source written in C.

I've just noticed on the PPF website there is the sources for ApplyPPF and MakePPF which will work in Linux.
Title: UDE/5713+
Post by: chimpanzee on July 17, 2004, 09:30:00 PM
QUOTE (BluhDeBluh @ Jul 18 2004, 06:26 AM)
You could use an IPS patcher.

http://www.zophar.ne.../patchutil.html has one (uIPS) with its source written in C.

thanks. Do I use the same program to produce the diff ? Will grab it and have a look anyway.

EDIT: got the ppf sources,  thanks.
Title: UDE/5713+
Post by: Angerwound on July 17, 2004, 09:34:00 PM
Yep, UDE has really transformed itself into the Ultimate exploit. Too bad this didn't happen before mods were rebuilt for the new console.
Title: UDE/5713+
Post by: Deciphile on July 17, 2004, 09:36:00 PM
could somebody give me a hint as to where it is?
Title: UDE/5713+
Post by: SargeZT on July 17, 2004, 10:01:00 PM
Quite nifty indeed.  I'll have to install this as soon as I can find the damn 'other usual sources'. dry.gif  I feel left out.  However, this is truly extraordinary.  I had NO doubt that Pedro and the others would find this.  I went to work today at 4:00'ish, and I was telling myself that it would be figured out by now.

Hip-Hip Hooray!
Title: UDE/5713+
Post by: krayzie on July 18, 2004, 12:25:00 AM
Damn I feel left out in this freekin european country. If it wasn't for your president I would move to the states. Guess I'm gonna have to ask around some more on the pal nfl fever copy.
Title: UDE/5713+
Post by: chimpanzee on July 18, 2004, 12:30:00 AM
QUOTE (krayzie @ Jul 18 2004, 09:25 AM)
Damn I feel left out in this freekin european country. If it wasn't for your president I would move to the states. Guess I'm gonna have to ask around some more on the pal nfl fever copy.

there is country north to it and I love it very much, share everything except the president :-)
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 18, 2004, 12:33:00 AM
nfl fever pal?

i wonder if they would import it to europe

since football isnt that popular.

then again EA whould do anything for a little money
Title: UDE/5713+
Post by: krayzie on July 18, 2004, 12:33:00 AM
QUOTE
there is country north to it and I love it very much, share everything except the president :-)
I'm packin right now  biggrin.gif
Title: UDE/5713+
Post by: krayzie on July 18, 2004, 12:36:00 AM
QUOTE (Chicken Scratch Boy @ Jul 18 2004, 09:33 AM)
nfl fever pal?

i wonder if they would import it to europe

since football isnt that popular.

then again EA whould do anything for a little money

Please don't kill my dreams. Anyway I saw other nfl games in stores here.
Title: UDE/5713+
Post by: chimpanzee on July 18, 2004, 12:37:00 AM
QUOTE (krayzie @ Jul 18 2004, 09:36 AM)
Please don't kill my dreams. Anyway I saw other nfl games in stores here.

It has to be a MS title as the update.xbe is from them, sharing the same bug :-)
Title: UDE/5713+
Post by: BluhDeBluh on July 18, 2004, 12:38:00 AM
NFL Fever 2003 was definately released in the UK. GAME sell it for £10 - I checked earlier.

I don't have any money, nor Live! though.
Title: UDE/5713+
Post by: chimpanzee on July 18, 2004, 12:45:00 AM
QUOTE (BluhDeBluh @ Jul 18 2004, 09:38 AM)
NFL Fever 2003 was definately released in the UK. GAME sell it for £10 - I checked earlier.

I don't have any money, nor Live! though.

could someone just grab a copy of it and applies for one or two months of live to get the update.xbe ?
Title: UDE/5713+
Post by: krayzie on July 18, 2004, 12:45:00 AM
I would definately buy it but I don't know anyone using live
Title: UDE/5713+
Post by: BluhDeBluh on July 18, 2004, 12:52:00 AM
QUOTE (chimpanzee @ Jul 18 2004, 09:45 AM)
could someone just grab a copy of it and applies for one or two months of live to get the update.xbe ?

Yes. They'd have to:
Subscribe to Live!
Run the game in Live!
Use the gamesave exploit to FTP the file over
Title: UDE/5713+
Post by: krayzie on July 18, 2004, 01:00:00 AM
maybe there are other games too that share the same weakness. We must find a way to let die hard (PAL) live users run ldots hdscan.
Title: UDE/5713+
Post by: chimpanzee on July 18, 2004, 01:07:00 AM
QUOTE (krayzie @ Jul 18 2004, 10:00 AM)
maybe there are other games too that share the same weakness. We must find a way to let die hard (PAL) live users run ldots hdscan.

I have posted a link that shows MS titles which has potential to contain this update.xbe
Title: UDE/5713+
Post by: chimpanzee on July 18, 2004, 03:15:00 AM
QUOTE (Kyro @ Jul 18 2004, 12:10 PM)
I can do all of that  smile.gif


but i just have 007, mechassault & top spin (but i can get a hand on splinter cell 1 from a friend)
so basically i can get live contents of topsin, splintercell & mechassault and retrieve this content with the 007 save xploit

tell me if i can be of any help

try MechAssault, that has an update.xbe on the DVD. So we can check to see if there is also a downloadable update.xbe that can run from HDD. The only problem is, the game has been fixed before so may be the font hole(even in update.xbe) may have also been fixed.

Basically all those 4d53xxxx has pontential.
Title: UDE/5713+
Post by: gronne on July 18, 2004, 04:33:00 AM
biggrin.gif

EDIT: isn't it possible, as I said earlier, that M$ have updated the files that could be exploitable now? I mean they're definitely reading all these posts, so they might've just updated them now. Guess we'll see that if the files have a very new date.
Title: UDE/5713+
Post by: chimpanzee on July 18, 2004, 04:48:00 AM
QUOTE (gronne @ Jul 18 2004, 01:33 PM)
Wouldn't the best be to go to the live-forum in here and ask them to do this? there must be some europeans having the game, right? And some must be interested in helping out. Well I won't do it as I am afraid of the guy's at live... they seem bloody scary, you know biggrin.gif

EDIT: isn't it possible, as I said earlier, that M$ have updated the files that could be exploitable now? I mean they're definitely reading all these posts, so they might've just updated them now. Guess we'll see that if the files have a very new date.

That is why the quicker, the better. Well, at least I believe the MechAssault double dash style has been cracked, just not as elegant as UDE.
Title: UDE/5713+
Post by: krayzie on July 18, 2004, 05:45:00 AM
QUOTE (Kyro @ Jul 18 2004, 12:10 PM)
I can do all of that  smile.gif


but i just have 007, mechassault & top spin (but i can get a hand on splinter cell 1 from a friend)
so basically i can get live contents of topsin, splintercell & mechassault and retrieve this content with the 007 save xploit

tell me if i can be of any help

would you be willing to sacrifice a few bucks and go to the store and buy a copy of nfl fever 2003 and go live with it. You could save the pal users out there before it's too late. The game will not cost more than € 15 since it's old anyway. Small price for a big acomplishment.
Title: UDE/5713+
Post by: PedrosPad on July 18, 2004, 08:14:00 AM
QUOTE (Kyro @ Jul 18 2004, 04:49 PM)
QUOTE
***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/4d530035/$u/update.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x40A133BD Tue May 11 20:12:45 2004
Title ID                            : 0x4D530035
Title name                          : "TopSpin (Training)"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                    : XBE_MEDIA_HDD
Allowed game regions                : 0x00000004
                                    : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x00000702

can this xbe be of any help?
otherwise i might have a friend that can have nfl fever 2003 but that s not sure, i ll wait & see

It's got the non-dash titleID smile.gif, but I think the recent date of the xbe means that the font hole would be closed in this version. sad.gif
Title: UDE/5713+
Post by: Spectracide on July 18, 2004, 09:00:00 AM
wink.gif Ignore me...
Title: UDE/5713+
Post by: chimpanzee on July 18, 2004, 09:40:00 AM
NTSC-Japan, is it the same as NTSC ? Evox says my machine is NTSC-Japan. It is a K5101 one(well actually a M7 on modchip) so I have no problem modding it. Just want to see if any new one on sale now would be about to use the newest update.xbe found.
Title: UDE/5713+
Post by: YoshiKool on July 18, 2004, 09:40:00 AM
tongue.gif they need a nfl update.xbe that is non-US
Title: UDE/5713+
Post by: krayzie on July 18, 2004, 09:58:00 AM
QUOTE (YoshiKool @ Jul 18 2004, 06:40 PM)
hmmm - kyro you are from france - if you download some content from nfl and end up getting an update.xbe then reply in the UDE2 thread tongue.gif they need a nfl update.xbe that is non-US

That's what we were askin the whole day allready
Title: UDE/5713+
Post by: YoshiKool on July 18, 2004, 10:05:00 AM
tongue.gif
Title: UDE/5713+
Post by: krayzie on July 18, 2004, 10:13:00 AM
You actually think he wasn't aware of that allready?
Title: UDE/5713+
Post by: eh. on July 18, 2004, 11:55:00 AM
QUOTE (PedrosPad @ Jul 18 2004, 05:21 AM)
UDE/5713+ update:

Excellent news! Using eh.’s HDD based, USA flagged, update.xbe from the US NFL Fever 2003, rmenhal has performed the necessary font adjustment, and we now have a true UDE/USA package that works on all US XBOXs (v1.0-to-v1.6) and Kernels (tested all the way up to K:5838) biggrin.gif  devz3ro has built on rmenhal’s work (adding NKPatcher, etc.) and produced a distribution – this will be made available very soon.  This kind’a supersedes []V[]nm6687’s Splinter Cell 1 double-dash package, however some may still prefer this method of invocation.

Since no one has found a PAL flagged update.xbe like the US NFL Fever 2003 one sad.gif (anyone got a PAL copy of this and !Live? – yell if you find one!) For PAL users…

Using BluhDeBluh’s PAL HDD Splinter Cell 1 game engine, and PAL SC1 content, I’ve managed to duplicate []V[]nm6687’s Splinter Cell 1 double-dash packages’ functionality for PAL owners smile.gif.   And now put together the equivalent PAL distribution biggrin.gif.  Like []V[]nm6687’s original, it allows homebrew wink.gif programs on DVD-RW media to the played.  However, it suffers from ROE  - so the exploit has to be re-triggered to change games.

Since the launch of UDE/USA, booting into Mech Assault is no longer of any interest to our US friends, but investigation into this is continuing for PAL users – as this technique gets you into Evox with ROE off! smile.gif  However the way this is currently achieved is ‘involved!’.

Awesome!  You (Pedro), rmenhal and ldots have put a huge amount of effort into UDE et al for the benefit of others - thank you, tHaNk yOu, THANK YOU eh.  wub.gif
Title: UDE/5713+
Post by: YoshiKool on July 18, 2004, 12:30:00 PM
Hmm... i'm having a bad thought right now... PAL 1.6's aren't released yet right? Maybe when they are M$ will patch up the kernel and dash again...
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 18, 2004, 12:33:00 PM
mmm

i guess it's too bad for our european friends

they always seem to be getting shafted  sad.gif
Title: UDE/5713+
Post by: YoshiKool on July 18, 2004, 12:34:00 PM
well, i have my PAL 1.0 so im good smile.gif are there any differences between PAL/NTSC boxes besides the eeprom and PSU?
Title: UDE/5713+
Post by: krayzie on July 18, 2004, 12:36:00 PM
well at least we would have a fix for the 5713 xboxes. The next series of xboxes in the usa/canada would be patched also then so there's really no big difference.
Title: UDE/5713+
Post by: YoshiKool on July 18, 2004, 12:42:00 PM
hmm, true.
Title: UDE/5713+
Post by: YoshiKool on July 18, 2004, 01:15:00 PM
yay!
Title: UDE/5713+
Post by: PedrosPad on July 18, 2004, 01:19:00 PM
QUOTE (YoshiKool @ Jul 18 2004, 09:30 PM)
Hmm... i'm having a bad thought right now... PAL 1.6's aren't released yet right? Maybe when they are M$ will patch up the kernel and dash again...

Own up - You're just worried that then I'd inflict another long, boring, thread on you in order to find another exploit - lol biggrin.gif wink.gif.
Title: UDE/5713+
Post by: YoshiKool on July 18, 2004, 01:22:00 PM
Hehe, well, if we do find a dash exploit for PAL xboxes (and we probably will with the pal nhl 2k3 fever...) then there's going to be a sense of... emptiness... what will there be left to do?
Title: UDE/5713+
Post by: chimpanzee on July 18, 2004, 04:37:00 PM
QUOTE (krayzie @ Jul 18 2004, 09:36 PM)
well at least we would have a fix for the 5713 xboxes. The next series of xboxes in the usa/canada would be patched also then so there's really no big difference.

Devicing a fix for this is a bit more difficult than before. They cannot blindly disable 4d53xxxx title id or game won't run. There will be quite some ugly patches in the kernel to disable this.
Title: UDE/5713+
Post by: []V[]nm6687 on July 18, 2004, 05:29:00 PM
QUOTE (ThE MaSTeR 3 @ Jul 18 2004, 08:52 PM)
So when can we expect a package??

i guess i'll post the X-S legal version of the SC1 PAL release by PedrosPad.  here it is for all you PAL users, read the readme.

CODE

UmFyIRoHAM+QcwAADQAAAAAAAAAzXHTgkCYAAAAAAAAAAAACAAAAAEl88jAUMAEAEAAAAEMA8PL7
Uib4dOCQLQAAAAAAAAAAAAIAAAAAkH3yMBQwCAAQAAAAQ1x4b2Rhc2gAsMIOZkp1dKCQPgAAAAAA
AAAAAAIAAAAArhXwMB0wGQAgAAAAQ1x4b2Rhc2hcY29udGVudGltYWdlLnhieADwDhuG0Yd04JAz
AAAAAAAAAAAAAgAAAABAfPIwFDAOABAAAABDXHhvZGFzaFxMTWFwcwCwGjoQy9904JA8AAAAAAAA
AAAAAgAAAAAEgPIwFDAXABAAAABDXHhvZGFzaFxMTWFwc1wwMDBfbWVudQDwrm+Hbbt04JAzAAAA
AAAAAAAAAgAAAABAfPIwFDAOABAAAABDXHhvZGFzaFxtZWRpYQCwGjoQ6U50oJBAAAAAAAAAAAAA
AgAAAACuaO4wHTAbACAAAABDXHhvZGFzaFxtZWRpYVxBcmlhbFVuaS5UdGYA8LS4gyKKdKCQQAAA
AAAAAAAAAAIAAAAArWjuMB0wGwAgAAAAQ1x4b2Rhc2hcbWVkaWFcZGxjdXN0b20ueHByALBsvgfM
F3SgkD0AAAAAAAAAAAACAAAAAK1o7jAdMBgAIAAAAENceG9kYXNoXG1lZGlhXFNvdW5kLnhzYgCw
bL4HcCB0oJA8AAAAAAAAAAAAAgAAAACtaO4wHTAXACAAAABDXHhvZGFzaFxtZWRpYVxXYXZlLnh3
YgCwbL4HM8h04JA4AAAAAAAAAAAAAgAAAABAfPIwFDATABAAAABDXHhvZGFzaFxzY3JlZW5zaG90
ALDA1w3CpXSgkE0AAAAAAAAAAAACAAAAAK1o7jAdMCgAIAAAAENceG9kYXNoXHNjcmVlbnNob3Rc
QmVoaW5kX1RoZV9TY2VuZS50Z2EAsGy+B61idKCQTAAAAAAAAAAAAAIAAAAArWjuMB0wJwAgAAAA
Q1x4b2Rhc2hcc2NyZWVuc2hvdFxjb250cm9sbGVyX2JhY2sudGdhALBsvgfLjnSgkEsAAAAAAAAA
AAACAAAAAK1o7jAdMCYAIAAAAENceG9kYXNoXHNjcmVlbnNob3RcRXh0cmFfRmVhdHVyZXMudGdh
ALBsvgeusHSgkEkAAAAAAAAAAAACAAAAAK1o7jAdMCQAIAAAAENceG9kYXNoXHNjcmVlbnNob3Rc
RmFjdHNfUmFuZG9tLnRnYQCwbL4He4d0oJBPAAAAAAAAAAAAAgAAAACtaO4wHTAqACAAAABDXHhv
ZGFzaFxzY3JlZW5zaG90XExvYWRpbmdfRG93bmxvYWRlci50Z2EAsGy+B1TqdKCQTQBxAgAAEsAS
AAL/0LzAwAHxMB0zKAAgAAAAQ1x4b2Rhc2hcc2NyZWVuc2hvdFxsb2FkaW5nX3Byb2dyZXNzLnRn
YQCwujBbEIEQvpC12JNUaoxRw6CsLCqnoks+5e63M/AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAA
AADA+XZgdKCQSQAAAAAAAAAAAAIAAAAArWjuMB0wJAAgAAAAQ1x4b2Rhc2hcc2NyZWVuc2hvdFxs
b2FkaW5nX3Rlc3QudGdhALBsvge9hnSgkE4AAAAAAAAAAAACAAAAAK1o7jAdMCkAIAAAAENceG9k
YXNoXHNjcmVlbnNob3RcVWJpc29mdF9UcmFpbGxlcnMudGdhALBsvgcnvXSgkEMAAAAAAAAAAAAC
AAAAAK1o7jAdMB4AIAAAAENceG9kYXNoXHNjcmVlbnNob3RcdW5wbHVnLnRnYQCwbL4HaEp04JA0
AAAAAAAAAAAAAgAAAAA9fPIwFDAPABAAAABDXHhvZGFzaFxTb3VuZHMA8Bb5kB3qdKCQPgAAAAAA
AAAAAAIAAAAArWjuMB0wGQAgAAAAQ1x4b2Rhc2hcU291bmRzXDFfM18zLlNTMgCwbL4HFX50oJBA
AAAAAAAAAAAAAgAAAACtaO4wHTAbACAAAABDXHhvZGFzaFxTb3VuZHNcZHNzdGRmeC5iaW4AsGy+
B1KxdKCQQAAAAAAAAAAAAAIAAAAArWjuMB0wGwAgAAAAQ1x4b2Rhc2hcU291bmRzXEVjaGVsb24u
U1AyALBsvgfn83TgkDwAAAAAAAAAAAACAAAAAEB88jAUMBcAEAAAAENceG9kYXNoXFNvdW5kc1xF
TkdMSVNIALCysAbdDnSgkEQAAAAAAAAAAAACAAAAAK1o7jAdMB8AIAAAAENceG9kYXNoXFNvdW5k
c1xFTkdMSVNIXDBfMC5MUzIAsGy+B76BdKCQRgAAAAAAAAAAAAIAAAAArWjuMB0wIQAgAAAAQ1x4
b2Rhc2hcU291bmRzXEVOR0xJU0hcMF8wXzIuTFMyALBsvgeA6nSgkEYAAAAAAAAAAAACAAAAAK1o
7jAdMCEAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNIXDBfMF8zLkxTMgCwbL4HjCl0oJBEAAAA
AAAAAAAAAgAAAACtaO4wHTAfACAAAABDXHhvZGFzaFxTb3VuZHNcRU5HTElTSFwxXzEuTFMyALBs
vgea/HSgkEYAAAAAAAAAAAACAAAAAK1o7jAdMCEAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNI
XDFfMV8wLkxTMgCwbL4HpJd0oJBGAAAAAAAAAAAAAgAAAACtaO4wHTAhACAAAABDXHhvZGFzaFxT
b3VuZHNcRU5HTElTSFwxXzFfMS5MUzIAsGy+B6csdKCQRgAAAAAAAAAAAAIAAAAArWjuMB0wIQAg
AAAAQ1x4b2Rhc2hcU291bmRzXEVOR0xJU0hcMV8xXzIuTFMyALBsvgdURXSgkEYAAAAAAAAAAAAC
AAAAAK1o7jAdMCEAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNIXDFfMl8xLkxTMgCwbL4HV/50
oJBGAAAAAAAAAAAAAgAAAACtaO4wHTAhACAAAABDXHhvZGFzaFxTb3VuZHNcRU5HTElTSFwxXzJf
Mi5MUzIAsGy+BziydKCQRgAAAAAAAAAAAAIAAAAArWjuMB0wIQAgAAAAQ1x4b2Rhc2hcU291bmRz
XEVOR0xJU0hcMV8zXzIuTFMyALBsvgcG2XSgkEYAAAAAAAAAAAACAAAAAK1o7jAdMCEAIAAAAENc
eG9kYXNoXFNvdW5kc1xFTkdMSVNIXDFfM18zLkxTMgCwbL4HfPt0oJBEAAAAAAAAAAAAAgAAAACt
aO4wHTAfACAAAABDXHhvZGFzaFxTb3VuZHNcRU5HTElTSFwyXzEuTFMyALBsvgdB2XSgkEYAAAAA
AAAAAAACAAAAAK1o7jAdMCEAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNIXDJfMV8wLkxTMgCw
bL4Hf7J0oJBGAAAAAAAAAAAAAgAAAACtaO4wHTAhACAAAABDXHhvZGFzaFxTb3VuZHNcRU5HTElT
SFwyXzFfMS5MUzIAsGy+B3wJdKCQRgAAAAAAAAAAAAIAAAAArWjuMB0wIQAgAAAAQ1x4b2Rhc2hc
U291bmRzXEVOR0xJU0hcMl8xXzIuTFMyALBsvgePYHSgkEYAAAAAAAAAAAACAAAAAK1o7jAdMCEA
IAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNIXDJfMl8xLkxTMgCwbL4HjNt0oJBGAAAAAAAAAAAA
AgAAAACtaO4wHTAhACAAAABDXHhvZGFzaFxTb3VuZHNcRU5HTElTSFwyXzJfMi5MUzIAsGy+B7Kw
dKCQRgAAAAAAAAAAAAIAAAAArWjuMB0wIQAgAAAAQ1x4b2Rhc2hcU291bmRzXEVOR0xJU0hcMl8y
XzMuTFMyALBsvgfJ+XSgkEYAAAAAAAAAAAACAAAAAK1o7jAdMCEAIAAAAENceG9kYXNoXFNvdW5k
c1xFTkdMSVNIXDRfMV8xLkxTMgCwbL4HykJ0oJBGAAAAAAAAAAAAAgAAAACtaO4wHTAhACAAAABD
XHhvZGFzaFxTb3VuZHNcRU5HTElTSFw0XzFfMi5MUzIAsGy+B5/ldKCQRAAAAAAAAAAAAAIAAAAA
rWjuMB0wHwAgAAAAQ1x4b2Rhc2hcU291bmRzXEVOR0xJU0hcNF8yLkxTMgCwbL4HOSt0oJBGAAAA
AAAAAAAAAgAAAACtaO4wHTAhACAAAABDXHhvZGFzaFxTb3VuZHNcRU5HTElTSFw0XzJfMS5MUzIA
sGy+BzqQdKCQRgAAAAAAAAAAAAIAAAAArWjuMB0wIQAgAAAAQ1x4b2Rhc2hcU291bmRzXEVOR0xJ
U0hcNF8yXzIuTFMyALBsvgehjnSgkEQAAAAAAAAAAAACAAAAAK1o7jAdMB8AIAAAAENceG9kYXNo
XFNvdW5kc1xFTkdMSVNIXDRfMy5MUzIAsGy+B2gMdKCQRgAAAAAAAAAAAAIAAAAArWjuMB0wIQAg
AAAAQ1x4b2Rhc2hcU291bmRzXEVOR0xJU0hcNF8zXzAuTFMyALBsvgdWZ3SgkEYAAAAAAAAAAAAC
AAAAAK1o7jAdMCEAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNIXDRfM18xLkxTMgCwbL4HVdx0
oJBGAAAAAAAAAAAAAgAAAACtaO4wHTAhACAAAABDXHhvZGFzaFxTb3VuZHNcRU5HTElTSFw0XzNf
Mi5MUzIAsGy+B/MSdKCQRAAAAAAAAAAAAAIAAAAArWjuMB0wHwAgAAAAQ1x4b2Rhc2hcU291bmRz
XEVOR0xJU0hcNV8xLkxTMgCwbL4Hvxh0oJBGAAAAAAAAAAAAAgAAAACtaO4wHTAhACAAAABDXHhv
ZGFzaFxTb3VuZHNcRU5HTElTSFw1XzFfMS5MUzIAsGy+B7yjdKCQRgAAAAAAAAAAAAIAAAAArWju
MB0wIQAgAAAAQ1x4b2Rhc2hcU291bmRzXEVOR0xJU0hcNV8xXzIuTFMyALBsvgf9sXSgkEUAAAAA
AAAAAAACAAAAAKto7jAdMCAAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNIXE1BUFMuTE0yAPCY
anVLAHSgkE8AAAAAAAAAAAACAAAAAK1o7jAdMCoAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNI
XE11c2ljX0Jpcm1hbmllLkxTMgCwbL4HIqV0oJBNAAAAAAAAAAAAAgAAAACtaO4wHTAoACAAAABD
XHhvZGFzaFxTb3VuZHNcRU5HTElTSFxNdXNpY19Db21tb24uTFMyALBsvgcAanSgkE4AAAAAAAAA
AAACAAAAAK1o7jAdMCkAIAAAAENceG9kYXNoXFNvdW5kc1xFTkdMSVNIXE11c2ljX0dlb3JnaWUu
TFMyALBsvgcEsXSgkEoAAAAAAAAAAAACAAAAAK1o7jAdMCUAIAAAAENceG9kYXNoXFNvdW5kc1xF
TkdMSVNIXE11c2ljX1VzYS5MUzIAsGy+B8YcdKCQPQAAAAAAAAAAAAIAAAAArWjuMB0wGAAgAAAA
Q1x4b2Rhc2hcU291bmRzXE1BUFMuU00yALBsvgf783SgkEcAAAAAAAAAAAACAAAAAK5o7jAdMCIA
IAAAAENceG9kYXNoXFNvdW5kc1xNdXNpY19CaXJtYW5pZS5TUzIA8LS4g2rBdKCQRQAAAAAAAAAA
AAIAAAAArmjuMB0wIAAgAAAAQ1x4b2Rhc2hcU291bmRzXE11c2ljX0NvbW1vbi5TUzIA8LS4g34c
dKCQRgAAAAAAAAAAAAIAAAAArmjuMB0wIQAgAAAAQ1x4b2Rhc2hcU291bmRzXE11c2ljX0dlb3Jn
aWUuU1MyAPC0uIOL0nSgkEIAAAAAAAAAAAACAAAAAK5o7jAdMB0AIAAAAENceG9kYXNoXFNvdW5k
c1xNdXNpY19Vc2EuU1MyAPC0uIOeN3SgkD8AAAAAAAAAAAACAAAAAK5o7jAdMBoAIAAAAENceG9k
YXNoXFNvdW5kc1xTVFJFQU0uU1MyAPC0uIPr8XTgkCYAAAAAAAAAAAACAAAAAEB88jAUMAEAEAAA
AEUAsExeVbCfdOCQLAAAAAAAAAAAAAIAAAAAYH3yMBQwBwAQAAAARVxVREFUQQDwKGEXalN04JA1
AAAAAAAAAAAAAgAAAABiffIwFDAQADAAAABFXFVEQVRBXDIxNTg1NTU0ALDy+1KRpHTgkEIAAAAA
AAAAAAACAAAAADCb8jAUMB0AMAAAAEVcVURBVEFcMjE1ODU1NTRcMDAwMDAwMDAwMDAwALBOclOJ
KnSggEgALQAAAC0AAAACj05SfACI5DAdMCgAIAAAAEVcVURBVEFcMjE1ODU1NTRcMDAwMDAwMDAw
MDAwXGZvb3Rlci5hc20JYWxpZ24gMTYKCkVPQzoKVExTOgpUSU1FUyAweDE4IERCIDB4MAoKRU9G
Ogox23SggEgA7AUAAGMPAAAC3ZSSCACI5DAdMygAIAAAAEVcVURBVEFcMjE1ODU1NTRcMDAwMDAw
MDAwMDAwXGhlYWRlci5hc20MHVDMzNG8mdW7m/hRFFAcnmxwOWSW0TepyNu1jy2Oht7bQKLsBaSj
Z2L0MJFSR371oibljaKeYSimZHKujb2qBxpLMPMwnOZ6H8Zz+EH7nPxIICPo6V2/a9f9xLHbwWA6
+9X7ct3DgJw+rSc5/JPry2ye+3ZtW75PlZv4SV5Pyg9vESpWAS99arC5FpnfEtfUtRFQelyHrcIP
nizH00nTBCQ+TQduL8+q2o4THzaQbG+U+luVSfo6QVhyGl7A+7K16VSCYR8E6hxsQytp/ZKFrIQt
MCvSmLGj+YRBgafk3Qf9uQn4oYV+Uur5U6rDYAMjpIZGmNC+nzrTIlgN+M4ClrUlfMsKnbvXK/p9
NSpsRr13fgAP2e3aTMAEoOHp4PW3wtOd8w6tzlrXn3mA5XstWS6ohP0KXwUeYPE3Tr8FTszvnuZX
Yxfnp1jnDcs79C1OeN7FLAWsHP5zQPxCkn79gpg0SEPTO60SxnyDGwXuvmOYrpoiiEEuO600jO44
/oM3RlgN4YcLfxPzZuk/sOCLPtuc3H7LPLUpIZ2x15JEm59b18nYijIxq92Tz/4eifNwAAzyAoTl
AErkOJTEDOukAw0EcJEvHSA6m6JvBXWoG5bV5y4GiSdDF4yY0gWID0o7SugYQ8CdeVo8ZXVIFcu7
8jh+GCS4ciGJXkdgaBUilnCJMWzakaDvzLbCoHWGStyrQz1A+Lzxj+YmCLuVc02jtPrKrCe9CbGZ
8rvi3tn5RMni81QaRFM/FG9tH30aOMgDfdFIgsNuYo8eXUWQFe0PeQfAkrXvE5lCt32L8CmTsTc6
tdz7jvRqiN/q2jJ8fL67XFY8CpSmU/+kBnm5SD0Ngn6tJ9JVCb8Y3QL27PpVnUW3GOKueB+v1LZw
nDpo77J3nTYoSgp9YTernmnVPh5EQ1NSrDHGVmfc/kC/Ma/1s/K7TK2dgxwExa6Xi5fGj2cRsqQk
8pOTueA5DPtOxjKNN86xqVWZjRABPZQlRc7Sj90gYV9tVBGI4/+GN9MEoIwYZ95C4febTAkLjdlQ
4+NAKlDQlTKgbMC/AskqXfF2BB5o5pNS5sTibQlVOzHOQldOxzjD4oQJexOjV6jCWP0fZV9Lh4+L
7+gaGgVasb4yLlS9Bn0lXXpWwEl9DRTVsEW6/KJ7eS4eQvW4ITHEDZw3fjbwKtNV9z0hIpu7y6cA
ccmciYEEUI1I4EZMwtfGhaGB5XN0qH0JGiV6UhhJ3YFxN+jB/5rd9GFy7zWfBvc/7GED3m2+5LXL
p4QDu1utxXErjaXCaYuTngEibR3c1DzUkTl7A2iD9qS+q32hpKHsCzEG6GL0XIu5M20zVb2Xtgkq
2qfzF/HZLJhNNhqW7aYxauNhAmn+/MwFTNDbwUXtBNHEF8Z/GnQgDcSV6y6dWiUN+2wPVy4lC7B2
Bpfj+cxWUtj2ST3CwL7mOd8K/BUo9hTixdj1WjRdU9Ixj2z0GPFkVVM9K+t4VejAvISCkDm2IqH9
BOkpmC3zJKErLQwft5ZiylhLHn+oueM6WESbLyvRjBPiOb20WukKXr/fxuuLxfJwERhV/VTeWZxJ
cKQMz1tAtY65zALzOM+QvgQ/z2jGWWq8HQF1XWSKP5mhThB0ZIfgvODEBbtAbRdyleXP5QZILNln
gnm8xkDmMg4w4cycVRW+4S9iaZX6xZcmrKytVE+6SMUYvyYSzplSLbnP45F92gysuB7oWuDuTA/o
Cd2ZnoXeaUm9UijibnRsOFB4XqsTL4iJD6Gy2bHqlOJyvCJ5KtRS9weuRqqwlg9zetet21t6tiD4
33Od3XIWB/kAA70oySybkgOXR31WeA0+1ClbfDVHnAu1XekECS+te/q+TmvWrdYPDD77dEoH00rO
XLvPbtf85QxHE/mjnzD0w3GBI5d2fO/v+YiTegDWDdR3w+7p4llvYsdCLFPOX7ZX0DwZmp2cHTk4
5EwzTgEZE1sQm4DTDpxHQO8OKL2Ik0t2AJLm6rH4rQgp/kzlR9wJ+EhqHqiruvFpFX/U4JB0oJBO
AO4EAADYFAAAAmZ/VU9qtu4wHTMpACAAAABFXFVEQVRBXDIxNTg1NTU0XDAwMDAwMDAwMDAwMFxp
bnN0YWxsLnhiZQCwoJJcEgFVFMiPzYHj0h8FcEsfgAtoRx+FrUr8KiyWuFErbVYKWpAfhJEiGIgk
kBooeClxtCSyxLEqo4txq4OZRRKrKtGJjYQxklSjDKYqCCWZS1G1LmHxp8KKICQlze+JAix3yW5l
/C3/BXcze7ze+5veb3vt/Hd/zHO733c5zu953fZz+52b7Jsnve/CT8ZmRD7Oqhjm7k+FReobiKlp
V2OwOZOFZ4sqvRrpWIRH/2x+m81nFLzZuZylF2vzsJVmless9yihh7nCtfkovVg4fQ0lREvXJqPD
xIrb6y/6xKy+6U+e3q+7/Cb1zPdTTvNc+J6qLvpe3IdzUe/AGHzneCfjNmwv/uzqn4LKEmNzA5uR
PHeHudHHdjU/FN2vg0XpvKknonKhVkcDzLdpzLiB+myhezA5zkUNVCRGPNxXBvpyiy+tZ+2jyEpx
lqLkExea7PtUPPayP6ZvfQB3I2L/xJI70Dkc/fNOQdx0YT3jeW3+drmEDJffCJmPSv/Om6vVxmto
PITwYrP8+uVRmlS5yMS19hpeWq/Gt51DoH8ggw4skJo+OOZGLr1r96+JmC3pGwdivCw815bJ8MEf
82L1PyjOF3nwMD8nFkN+38v6QkFfotionx2GbYYgP/w+DHYdyRgho7kY3FI8aR2xuHn1FKMd5qBi
aXvVsNb1+0vPn4xOfhT7vvDbf2mSI4iPIkCJhv66ImQmSSP/9YQhCEIQhCEH0WiIpPFSCKifSN1C
LlCWCWiUCoBakwE2wCqj1MhMJdtII4baysfHpZaS0aM/iklK4ZT3dIjc1KTMftZZJopmOkCMGdO5
4fUEqvTXx84ekphTBpUNII26maeRi4omz7mRmD+AazLI/6DZthNjWbZYraYi4sga+zVu6Qxk3Pad
Ia8SfGHYmBafqeUWYMgyuUCx4qwM5oX98qK0Fxn0WedgRL8FkRdcMRgp7Z7s9kPZ9/ahCNX4UTpL
zwOuskBiX1wTuYVWEuaQOXfC5GyJgFdOreUxhBr3IwAFdjBMqUh3Kl4sUvTZMZcrjwW2FQaDGPsm
z1AwOFmnHgR03+Hoafk9sctK3u/G1hvhsTbpFeOV8YhdbUI/B+qqmXfDvS1G4i1B3PDzLEGDy7Q0
UOxV30LnGdw/HVcPkoTBe5ZduUb+fLqa4E6uXs53efQPIqe1y12Tkmc1Uq9VdKIVoNXMY5PRF44S
RRdmU7oZ/yjeb49gwNWrMsH0Y0z0XsLCDCMklHelmNwB1RIltfZ0DBGNiBMcGSgYHByhN6QxcB2n
GtGk5qFZR0/NXT095O1iu5p1PheSXpccLhlMeBQaakdHaGj3tw6GtF5A/z/4P1dMdxXsbJcW7SQR
ZnX7JBsWMcZ8R1xLDEKXIOwrPsYXkVZvHwtXPXnKjbZimwm86fARN5SxezEvrBhXXzHDlNPu4y4c
dDm0jYyL8sL6rx2h1Xb40QcYghAs0HL9YXdiuxLmQKwLgYQcq25GZQ9ApRXRkqaErOtahpfbAiNW
J/PC4Iwrmi0p638DL5hWzHWXRaaXC/Yuwd1qF2lsGtbbgsQqwWaPN2m6JSvCxobqwxaBQF4oZxw4
3oW5FTCggykA/XhR9K32XeL+n2lNd3ykQVknchpBdApoYU5rBNYbDVfUKd29KVQivI+FQiJE8Buv
rhu11GXqpYH+0VdBWopUOJ7/NiA6f5RC63SggEsATAsAAFgfAAACxlVNmQCI5DAdMysAIAAAAEVc
VURBVEFcMjE1ODU1NTRcMDAwMDAwMDAwMDAwXG5rcGF0Y2hlci5hc20MAREMzNE8ld2/4n4Ue0cx
I+baB8l4wcOCKJPbo1yN9G+fQCRiApEpkxFIrSSm09+9cFhTbSJKvMw+KbU8N0d39rQnpWZd1l3e
X5GfF7/BBV5WVVJZWEpv//Z4hofTr7+TM683dMysw5DuR87LjzMxYXG4LGjA3W/IbxvsnNOjPmzP
wRQnY9kZW3vLSuJp8ZyZ6Q/7ZRtCy2hpUQPQ0qJH6bSCRzOVrWLaVuwQHJ/P1IBnF4eUpmCXVlpn
NE20Qtb0Zg/8H4xQTVES6a3Qd/TlfkJJgnJUHRA319zjuuEBSGC/a/8DkbCJ2B1+HhsTdbDb3OLi
Z2iZaxX7bVilZ1m8Tszex+rm+Hz0yKfO17C9nl4OhGDTAtOxSrZWXqDqkZ9cLYDWskBmhaIUnP4h
6p2S1tDigZ8tnDLxM1t+f7pgn4Ci2HyPJyxQ2OEh7XQn3c3v9t7l+avNzdPz6F/9DRGULHW6mlLf
fikb1LSnOwQxcY+Nl1aZhc2RttaK3bpcbGibOd6IObcZ7Zmc8YdhGHEP4n6jKbLK93lYl4kY4Gt8
hNbZnZaBabwUMu/KXFloron5BrmMvO9kyyZpXP/nNJn2g3TABPbkvPPP4dpjd+XeKQmeZmH2t5H4
O9fRdDfMaaMP0Wzy/DuI5CzZIbf5bi53O+F2TT16QcDcMO/LrSQs90VHC9TsEWeSReC35jbmm/OQ
PvlfzzV9L7EkMncDm4Jb6CpO4Mp/5A7Kv0e1Wbjq1zPvihQ83lZ25YXFpgmedns3xJtZl4+uw7fm
KgsYmc/DLbSAs524IXYYvwzC2b+rfvZkc3+kH7PdL62bDyt9rb13eFaNwQxcr/dK9HrekNmX74YH
9H6wZXuoaCTA7wlSRTEG+fPgedwy9942X71GklNvJdUwz2HN5WiQ0MyVbDW8QHchvn7ZoNbawHer
5LTbSnt/L8wffa2nYz/lz6zESKFH5bKmUGWjl/+rjPNWvdH59HT7+Vf3GN/tnO/ryThQ34PKA3BN
sLzWudjcRXz+2lTsj/bJTW+P4+ZaesQi2PETbD7rv0/cyTEpZ0DY4gATTDkzTVdz4Q//ECDr48Hf
JA5ACiQ24U6jST8VnV6GkkRFSG6YYByy89Rwe+7XBJc2fbXGGdA0RednVDXuPDAfW3DAnQk1j2PE
XYFjhSoCbjGQVzhKjaSEZvMDuXtaKRfvoISVKenQgZUnsEUNp/K3OyIZaOj4C3TraQhLpUEA6Ekf
OrccCllHWoxy2gK4zGx06I+dW44FQOOtRjgVHo61GOBU2jrUYGwcG+mmFwKyh1jK+Tcdy9htTLwg
1n7x8Dkhxt9+BnDj/C6arCRAfM+REt3uOX6J2jbwizcdeqkFdZKC+IKFnooh6gSk4FIjudk39emV
YO/yyFSeFntbHYPPPhNwkCQ9luzvNZfVJd50Ki2x7BpX/a8Re7N6659nBoEBw00RMh+w+6jYafLC
DO/jg0+iJ8/dXXfziwYBOIXdJDtEXG8o5SYsO5cV2v3UH7HLgN4AthGzPZ6Gomb5qdeu9SyAz7zI
WtkoBNuc+6zDKDMcgLVj1STO6rn16a1IayLGd1v1PLUu9E58n6LyBXnKWpIV+fq663UJ+pUA6zal
1Ia6NiVIqTZwjksjYdA2HSET8I5Yj8FLi0lY1yIf+3vIO8MszGLed4k+bscV0Xx8fNVL3zbsTLr0
6+zoyG1xIbaesnf6Dnp2ybh95NNVBVVaQBAO6WU0aYNLyXdJg4sth9kJx9fpAvjC7vOrsxFpIeUg
gW7kUvVQO/mIUF8GnRKETwaK4GYS8B2Z2Zdv2cL/4LzTDj4zsgHDJ0Xfmb1sBgd9URolPKEICaRy
dTjPAhU1vgRqcX4EtybYM7GNliNhkCTALcCIOfhTNxqXAmDTF1VGL3jJOelPc1FlYdZJiRT2SBQs
7167DnlyhOrJkHFBf0hM+1/M87sfhpVfNZKQ2d4qmDMKykYeadZeFKomuCzH9DSizXT8uR6PDkLh
/0Yl0I0bdy0Yo1KO0Yk6lFDKnBcplrUAUThKBgQRjyKwlfkZBe7egOd6epfX3wwgObMPVsHfoc15
XqiIC48oYvnc5KN6igmbPB4CZCx5+lEOulhtOlxXP7J9Y2MECfPlOY58tl7P2ArcIYsmEeO6GIfh
eZdDp46Ik5gdLPYW2aFwgMNBAuLgSXECUQbSq2O9F3BdbjyXZRss+YlgfHUCCA/hB8bvIA6A0yiD
cIZeTbeQmO2Ca4znwHoJRQWA5YbA/Ov5ADUiXotLZB1gZquwKv13nG8ScRhdT2Vw/xXK3TODvktD
CPNmOHIOpht1/FE3Pl1tdrXI1A6FcjE6008FjBtc/xw2CtOKoAKoVUIXckorMA1JGyIr27OyZODz
1h6csPqhILxDsqi2CED4Ce2/YJVJC0KAAfsVKAScVGFCQ5uVprVDtdT35hJZZBfm/303TF1v0O/u
cyXJvGi5FTxBX01mZ7C2bux/TziPjYgCTFxI9ZZuU+kOdTxA7GS07NprFltwa9DX12AQ/5k1uQu7
w1rXUdIsDuHAbPN9KRXaoxqMTZytQWC6qUtublA3DRXKawdgYhNVQA9RWysmf5DhdOeAwAJHSFAW
2xfUtXgaUSltYZakLjNnBrtIKuwqgxLqjH43E7alyWaPCgF0iWUJRUzklleGqgRPqggeB5cvudYL
cwT54ZhlJ+k4OEtvkQ8DC7WYOM12gBTMNJ1HdKw/4gzJJVFUhfhnqS5IIcdWHwPWJpVx8+hKPPjm
ILWxsdwNmF73KDk7dIgSCxGBsLuGlILpe/wQdFibZBwvbdThF2l5dh+iTvDu+txJu/xnuswQuwdw
/Ro4ndFT3+w4MxHrCY7b3lTs+ad5Ew6Ghz4CsVaoffDxKW//d9oBE+/GUrzhpUjrs3sqni6GjRD+
KxUlNaphkvH7txujTHLwpjN1J8sb4MT+owMtl5/IYbUe0C89glXDqvRj74FJp1rrobFtEuXZPeA5
ijbL3HZtyoBMdGMHELzSXfk4CRghbwygwPvpEMRt6oKqIcQfjXVLQ4nNa97tm8/dA4SB2MxFQskz
DSt/nucahedwlMWi7UcTtKqiZDyo2LHSmlbcrPinzRW7yp9EWIw2q0IUQHYJ53jB9r1R9oilOkhf
Fqgl3Bgbje4kCSG9eqrWn3ahYPpjncHmEOxBVnhD2q7kT3ecFMHEFQ7LFValSitfSWGQp5UALJt3
aUBJkPEjThbJ7lz4XnmHdAXOGwuwK3g6pkiiVjSAc9ZOmRmd668orjJKH4ayI15LhyNTVPPerVXK
O6Z7qOm0+n6um04NJte+5H26ejZRc4x+Kq9pMWw/65GUWFrSw4jrNJhsJezeLuKXLbE/jeUVo01k
Jw5hi3pTCjybTdeD0kFKNwPFATUWEVE2EbQtqIzKuG18OKeAKn1Wu6rc/an2VlYSFEr4v53hS1po
TS+erHFkBUikp4JFFeNISn6khLH4JS2sLsYbT63v8JZvAMKxsdguVXD71nVte9fFS6qolLInGk7S
GnYdyNSrLUB21NXw528oH0MDPuUNckPOrkv1CzLMMfY7MtoV1lM9CubSE5xzUFRNBNASVUFd9MUW
03hO0jpSSFFrIrSsiaLGlO4L/g/Z+R/m2Joi+LYpcF0tii+lXSkJpimwo+jBTAfinSs3hLSGpL2b
8fqHtuI/wmpO0O+hShqia+pMWb/nh9lytalbpVK5bp02Fpw5FY/TZXS8KXWKYD8aHoAvqZ1SCOLw
VlhP7CuBOpjFPuXrpn3Fon4iMUw/qTzVtT80+cpGsJT2y38thjAoGnHVErGML3hNSiUUkhG9t0fg
ZR6W0n8X9yx3Mwdf5lly6lf/TcxB69iN/9RaCnSgkC8A4QYAAAUOAAACsffU59Ka8jAdMwoAIAAA
AHJlYWRtZS50eHQAsDicHAwZkRDI0byZmX/6lvA9yKTyBNBs9EJNBIWo1tzY0iQEDJJqWpRW8y28
yGZl55l3g29561aBAeZd5VVeNjYEm8AkaC3d1dXXo7ruqnDNfBF111Vf2lXAO/v/e/Pz/LltbP03
PZs7ZuPg4TWzqgvpPM+b3He5zUbv/h7XY24VPRHhjRNvZZr9351F0x4zSJWaZCpUyKhvxINgTMbF
AehIz5DJmL+Ch0FLKiQy0myJnob5tCxmtB1E0z8hjcqcC40vvwyYTPHpNfYR0Mwpy/leHt6YKNDg
HsUAklbz9pid4w7lRiA4B7dLny+v1piDAtWUW4CgDfxQrga9Cy9hjN+5hbDPb0GWYaLo6qo0AwUD
+ysFWtoEc71EKPgRrGYkjqGKnW7ttAYJNSilkrET0V5LH5/k7/XZMCc0Ku2+SHNYvpueouRETHCk
YEHGYM2oJrLT/QC4iiTiB8VQA5jHMMx321EtbwIiPRTY9XaKQtQQLRSEpQ3fn+9w1OQTJqirq3cy
g89BcL1DLhq1eZ7l6lzVHLb2gEjASDRSwlndti+Oxj9vYXNjpTagsL6FBwausSO5uB1SaPgU+jQU
c3xXzJaRPukFJkXAMepZoUzDPQ99M7W+Cegtw20yGr1qARPUMUA5b54WOAgNX5UugD6t2kpKpyhA
Biu3kUU3BVKXN//+dgaw4ChNyNXa9Ufk1hWsDBQCKDXYCn4UfsJ4+pLUMYRho0enjeuypNMmNwle
G78bgSMUnuRAEj7rdvXjhepLQ+Beu0zDIgH2RgqGibtjvoctoXQXOEZWAl55BeZqisPIt+xIZGvj
MIUyzcs3rfBe4LPnvXb3Dcu2/PZ809kG3iCaQvQQbsYiq7gxVagC44v1p1KiHLZZnbzBAd3H89ea
0/bADSEODS1Guq1ri+5NrnZibhFWJTUGtXn3hDg6iUPj+Xevc3dVl21/v8HBy/be4wfh4KdNOuXo
hOXp8ssVJat6FtMcdBtR2bmRjodMKwdvbYR7RkL4Uy38bZnmHzFN4IbqAaiH9YvSFNbcPrVP5K4y
30C2uZheO0ZSXSfD7kS+x1tKB7UYyFJFtb39Y0jCgdluOAKaVMkldUD6fT8OK9c3jXvE8wZpCUnT
Z6Kd/NNcSQgJKPhQDGkOwfOyEm9ZTer+IWgfpOuaG/OFHz86B2Xky5OkwwLUQ/xLkBe2DcBUg7u5
58w+3e6TrUzjQ4t/S9gfL8XyfAyGxQWSh1eQXqs8PvPVrZAgb6MUknsgu4wpgCR3h4x/VfC/kkOF
D5CmnjfDZVXMJ4JgjvAagFc1fJebPM/cAkqJjfKBtIEWKsdpD3uLmCdNe9zfKvRoU6C1/qsG4pHi
HQaAQoVSnkVgAzF8ReuqPZ90ZoYFXQU8QuLGf6H9AE+sSljGx5XB8ynpesBF2oH37EsuAIuLeg+/
OwpgyBSfXYmDteMRakSVIH/F5ADjuVKciAigjv9TGxuKEE8BTugB66U8ZDMzPX3gNC6BXDdCC2hQ
xfG3dWQoVVoFz5imH4aWPUWA6Hs1DYFm8QO3imhWgbyTSWHdiDYeywVRmZhKzVVZhV2sxZ3iQuzU
+svYqEpUyZ2MBb/r06EvpnJAXlwcQXF8Bag9L0KJVDRy8LGBYJR0UNmheCx3fxtTc6frnTzpkSQu
OhH09M+/QWIavhzkE4b3Q2+sQ3XxljEeeQAyn/4M0K3SR05WppNBW3SsbhyKgFupkOLyhW4idQEY
uvRBhHhhuYetpwwPKQIhHFl8TDpJ5NnYY5eoTQxQDPOxxgiDgz2oeZQPDntNFaT/nP0CbHKErziw
kTNGBU3v82hlPDMN2GLxfN15RZ79fbC1jCVrmwVn+1FC9z55H6SeRoZwc0bYWnE1aXMJPKOo+WRH
BSqemHA2KEpyiv1V9qJOC73xx0AYM7nA01rUOE5xMYrVLrbHLRQUl9s1ICGP4CY2tRztrhpdPjz/
W0WO5xhlmLURbecEOh7NbaE7WefgD20R0kSGz36pyEjgI3KFziTSMCI+zzi/Zy1N6At6q+VlGAWH
5rdyyN+79C80LHJ5XGcieTr1MsZRYCwzXhHKUGMP3YRAaGnZr1zskBMg3uBR3YkYQ65OK4bU5AxG
sq4mk3PqHrao8gF7hNh/QtSuwcGueV9M4cWuLx+Wh8kohzLOxzh37HlDPMWHxQWSKuedXfxH62g4
2Qhjl8ZwtGMPR0f3t5aGmYJcfYi60v+PGIcjsPpws4GR2veqxhihnHV+8U8FtA/s2pLTvohf7x8J
S21RVPU4mqGC2g3Bw1hJ0deLrK8KCcwU/0lWuXes2QkbPGqxpxtsw07RjsSwS/spiGKnMsL2/ter
Z3dv1/+Uvf2P8SltdKCQNQDwAwAAYQUAAAK78O2UB6LxMB0zEAAgAAAAc2NwYWxkdmQyaGRkLnBw
ZgCwDicHDB1RVQiP1Z/e3fIeC+Dd1Qk0oMQsKUaxkbS0ujoiRTRlalvjdu7pSzWyrSwpbYGzd2BB
RQfKxJ6bEG1+itkrLWbWRtsYtoyk9RKm2u0dVJH2oQuywbfS61jWkDa7unlesBN3zvfaGiRbZY/f
vx9nsmc5nc5nO/zvczOd5mdzO872fuczOTPhnyzPt26YzAAgVhTWXGwEoBwaYCAAAANE6EBWS7FD
LmSC5JfApGRVTAxKuURA1WStgBBVtQGarAjRJBDYCUj6XACSaeg1CSb8e4IKIIXKP1Om7yoJPWjl
ZB7ZLb2ksWsyps/K5p6u+TbnRJA0GQ9aqInhK4Vc3WGEl352/wjz6KyGajFiPtB9hElDsk6f4KUQ
q9G3RjbQICEPtcgNBzhuoxCnI9TExbwzO9j/kYZIlPUNjEoSGWIh1NjMCW9YRnFC81aG/JkGagBd
gaE8fqie6OkJKh+djYMegpAcoFVCeg6CvnJt/eMa2KgIPrFrGNBSsI18iprCF3fGO4CODp8seU4l
0D0gS8WbFLd5VgHcSrSBIO4aVLEM441H+WOld81Iz6joiAhnXcjCcLKnuYLWYQAkCNBDQaxlkEeI
0I69CC1UBTRT3HCnSKb7u2AInZgC97jnNNr0FmAhgNFQD0dFyz71s2aLWmDzwgcyKIenL67f3J2G
a/FCTkVMaYwWnWvGlw5EjJFicmpYLjvh+nL9FaENulHOmAEFikLsUp+e1kCThgpWVADEuBUOJoPS
ZMJftdWe7DssLRItJlhRAlSlNuvIF8JrrEA6bpg6mlOU4IP0wfXQH+TwFyMTqBg76Rvu8Ik/gtww
Nidw3niNWXjsVv+zPsp+MuIjpLvbxJossch+h2pO1HR3+uo03EO+vJQUcb1nH9rY+yX1GV4pEuMo
Xl9Urqqobp1zBjQB9Gi/6i9QU254GeTDEKcYCEuhef+Js/fU0ev1DkOERWIIS2Ic8NzwoYTM5xa7
l7C/gJW/C5HvOinFlOLNhs/gUV8h5rjDX/dSyf218lZuz6PyRrvoF1eCp9v8HqvBnnHOby/7M9Ez
9PQ/oa8UKoV1qlWu/lJ69hBuOZuLOc33q3LKqgfPyRZKfqtl+fPUGzo5GlkDqDm0nJp6rX/5ty7h
ppktX7vM428r5rF8sjn4t/+uz7H37V/pToPR63S/ufsYXpSvzaRNN6/zqNVK+/x6EajvJFz1MT97
LYtMP6s3uFzSYN7DPrcLZK0zTzKvkMoccXlVV1S5FYJd4dDbepbfHSLuiyuZP0SoCvH+j0Jmh2ze
Fp+HO23yuMHgwRuuz88veQvi1PZwK7RzG9sPkXQv45fE2mtmkmYeCi6fOh7SxD17AEAHAA==

Title: UDE/5713+
Post by: gronne on July 18, 2004, 06:27:00 PM
Don't want to sound too stupid but I don't understand what I shall call the file after I've copy/pasted it to notepad. The other files I've done this with it says what it's supposed to be called in the first line. Sorry, but please explain.
Title: UDE/5713+
Post by: ThE MaSTeR 3 on July 18, 2004, 09:11:00 PM
I'm speaking 4 newbs around the world on this one...


So its now possible 2 soft mod any NTSC Xbox with UDE2?

Will there be a all in one package with all the needed files like the first UDE?

Why isnt this a headline on Xbox-Scene Main page?

Ive modded 10 Xboxs with the original UDE but I cant make sence of what UDE2 is about due 2 all this talk about Pal compatability??
Title: UDE/5713+
Post by: RiceCake on July 18, 2004, 09:52:00 PM
UDE2 is only compatible with NTSC (North American) Xboxes.

This is because MS included some code to prevent say, PAL (European, Japanese, etc.) Xboxes from running NTSC Xbox executables, to prevent you from using import CD's. UDE2 only works with NTSC Xboxes because the flag in the file thats being exploited is set to only run on NTSC Xboxes. It would cause an error if you run it on a PAL Xbox.

However the fix is to edit the EEPROM to turn your PAL (Or other) Xbox into an NTSC Xbox so the file runs fine. The problem with this is it changes the way that the Xbox works, and now your Xbox will only run NTSC executables! Meaning your Xbox games probably won't work right.
Title: UDE/5713+
Post by: as1986 on July 18, 2004, 10:01:00 PM
is this UDE2 compatible with NTSC-J?
I think it's a sub-standard of NTSC, but I'm not pretty sure...
The J stands for"Japan" AFAIK. However I've heard that in Japan they use PAL...weird.
Title: UDE/5713+
Post by: RiceCake on July 18, 2004, 10:19:00 PM
QUOTE (ThE MaSTeR 3 @ Jul 18 2004, 10:14 PM)
Ive modded 10 Xboxs with the original UDE but I cant make sence of what UDE2 is about due 2 all this talk about Pal compatability??

^ Not everyone...


And NTSC-J won't work, because it has a different region code.
Title: UDE/5713+
Post by: krayzie on July 18, 2004, 10:55:00 PM
ude 2 just uses another update.xbe for allowing it to play on newer xboxes. since the update.xbe is different it must have it's own fonts. the rest is completely the same and there is no advantage of using it if your kernel is below 5713.
Title: UDE/5713+
Post by: ThE MaSTeR 3 on July 19, 2004, 01:06:00 AM
So when a package is made it will include Update.xbe and the fonts?

and I would just use the replace the update.xbe and the fonts and it would work

thats it?
Title: UDE/5713+
Post by: PedrosPad on July 19, 2004, 02:43:00 AM
QUOTE (ThE MaSTeR 3 @ Jul 19 2004, 09:09 AM)
So when a package is made it will include Update.xbe and the fonts?

and I would just use the replace the update.xbe and the fonts and it would work

thats it?

along with NKPatcher, since only this works on K:5317+, but, basically, yes.

(The use of the very specific M$ copyright update.xbe is hampering the distribution.  Unlike UDE1 most people won't have this file already.)
Title: UDE/5713+
Post by: gronne on July 19, 2004, 05:16:00 AM
Seriously, doesn't nfl fever exist in Europe or what?? Europeans with live should try to rent it, this is too important to miss out.
Title: UDE/5713+
Post by: m.e on July 19, 2004, 05:48:00 AM
here it is but it is very expensive


link 1

Title: UDE/5713+
Post by: YoshiKool on July 19, 2004, 09:31:00 AM
hah, 55 euros is about £35... pretty much standard price for the UK (most games are £40)
Title: UDE/5713+
Post by: BluhDeBluh on July 19, 2004, 09:37:00 AM
QUOTE (gronne @ Jul 19 2004, 01:19 PM)
Seriously, doesn't nfl fever exist in Europe or what?? Europeans with live should try to rent it, this is too important to miss out.

As I stated earlier shop.game.net are selling it for £10 + postage.
Title: UDE/5713+
Post by: krayzie on July 19, 2004, 09:42:00 AM
yeah I saw an nfl fever 2004 for € 20,- here.
Title: UDE/5713+
Post by: YoshiKool on July 19, 2004, 09:42:00 AM
Another thing - we better hurry, because who can be sure M$ isn't patching up the xbe as we speak... or even just simply replacing it with a newer one. I wish i had live...
Title: UDE/5713+
Post by: krayzie on July 19, 2004, 09:43:00 AM
Yeah where is that kyro dude. He has live and a buddy workin in a gamestore. Seemed like a winner combo.
Title: UDE/5713+
Post by: YoshiKool on July 19, 2004, 09:47:00 AM
I'm just killing myself right now over how damn easy it is for M$ to update every xbe on live...
Title: UDE/5713+
Post by: krayzie on July 19, 2004, 09:48:00 AM
yeah. I hope they all on vacation right now
Title: UDE/5713+
Post by: YoshiKool on July 19, 2004, 09:50:00 AM
tongue.gif hehehe
Title: UDE/5713+
Post by: PedrosPad on July 19, 2004, 10:10:00 AM
QUOTE (YoshiKool @ Jul 19 2004, 05:53 PM)
everyone, edit your posts right now so they don't notice tongue.gif hehehe

Please! smile.gif wink.gif

ssssh!
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 19, 2004, 12:45:00 PM
QUOTE (YoshiKool @ Jul 19 2004, 07:50 AM)
I'm just killing myself right now over how damn easy it is for M$ to update every xbe on live...

yes, so we better get that pal xbe fast, hope it still has the exploit (if it ever did, but it's almost 100% that it did)
Title: UDE/5713+
Post by: YoshiKool on July 19, 2004, 12:48:00 PM
i'm more concerned that there ever was a pal update.xbe
Title: UDE/5713+
Post by: krayzie on July 19, 2004, 12:48:00 PM
damnit. I would definatly buy it. Any dutch livers around that want a free game???
Title: UDE/5713+
Post by: krayzie on July 19, 2004, 01:25:00 PM
I said I saw nfl fever 2004 for € 20,- Haven't found a cheap 2003 yet as it's old.
Title: UDE/5713+
Post by: Angerwound on July 19, 2004, 01:29:00 PM
I believe Pedros went out and purchased the game and a live subscription. Give him a bit and I bet he'll come up with the .xbe. If not, everyone keep looking.
Title: UDE/5713+
Post by: krayzie on July 19, 2004, 01:37:00 PM
biggrin.gif
Title: UDE/5713+
Post by: krayzie on July 19, 2004, 01:48:00 PM
guys quickly what was the exact path for the nfl fever update.xbe??? I might have found someone owning the game and plays live. I will send him a mail and hope he will respond.
Title: UDE/5713+
Post by: YoshiKool on July 19, 2004, 01:49:00 PM
er... it would prolly be different with the ntsc.
Title: UDE/5713+
Post by: krayzie on July 19, 2004, 01:53:00 PM
would it?
Title: UDE/5713+
Post by: PedrosPad on July 20, 2004, 12:49:00 AM
My current thoughts are that the US NFL Fever 2003 was launched while XBL service was still stabilizing.  Therefore the retail DVD contained a minimal bootstrap, which would bring down as much as it needed from XBL.  In this way stable XBL support could be streamed down to the XBOX, once the XBL service launched.

Because here in Europe we get everything months after our US (and Japanese) cousins,  the XBL service was stable by this point, and they felt confident enough to commit a DVD flagged update.xbe to the DVD media (there is a DVD flagged one on the media).

To progress this speculation, I'd be intrested is seeing a list of the xbe's from the US NFL Fever 2003 DVD media, and their lengths.
Title: UDE/5713+
Post by: ThE MaSTeR 3 on July 20, 2004, 01:07:00 AM
This is driving me crazy how this whole thing is draging out..
Title: UDE/5713+
Post by: gronne on July 20, 2004, 05:59:00 AM
Should the the game with the potential flaw we're looking for be one of the first games released on live? I have no idea what the first games was. Is this assumption correct, Pedro?
Title: UDE/5713+
Post by: PedrosPad on July 20, 2004, 06:12:00 AM
QUOTE (gronne @ Jul 20 2004, 02:02 PM)
Should the the game with the potential flaw we're looking for be one of the first games released on live? I have no idea what the first games was. Is this assumption correct, Pedro?

Early PAL XBOX!Live games would now look to be the next best hunting ground.

Although M$'s XBL servers probably no longer send out the update.xbe's we're looking for.  So they now may only exist on peoples HDDs.

(I suspect that this now may also be true for the US NFL Fever 2003.  If someone in the US has the US NFL Fever 2003 and XBL, I'd be interested to know if the update.xbe is still being sent out.)
Title: UDE/5713+
Post by: gronne on July 20, 2004, 06:24:00 AM
Yeah, I think the US nfl fever might be patched by now also. If it the pal update.xbe has existed and we really want it, I'd say we should adress the issue on the front page, because we're not reaching enough people in here. Some people watching the main page haven't visited live for a week or so, and who knows what the last game they tried was, right? Xantium or someone should ask for this. Add a link tp ldots scanner or the direct path.
Title: UDE/5713+
Post by: Slrpgeit on July 20, 2004, 06:54:00 AM
QUOTE (PedrosPad @ Jul 14 2004, 12:49 PM)
It's a 2MB RAR - Can anyone host this for ldots?

Don't know if its still needed, but i don't file like reading through alot of pages wink.gif
but i might be able to host the 2mb rar.
Title: UDE/5713+
Post by: m.e on July 20, 2004, 06:58:00 AM
wink.gif
Title: UDE/5713+
Post by: mkjones on July 20, 2004, 07:32:00 AM
QUOTE (m.e @ Jul 20 2004, 03:01 PM)
I know Unreal Championship(PAL) was released before there where xbox live in Europe.

So this game is likely to have a hdd-signed update.xbe wink.gif

Its also a very old game.. So it wont have what we are looking for, probably  sad.gif
Title: UDE/5713+
Post by: Slrpgeit on July 20, 2004, 08:01:00 AM
i have the pal splinter cell content, with the 2 /xbe's in the $u dir. don't know if its still needed..
Title: UDE/5713+
Post by: chimpanzee on July 20, 2004, 08:05:00 AM
QUOTE (Slrpgeit @ Jul 20 2004, 04:04 PM)
i have the pal splinter cell content, with the 2 /xbe's in the $u dir. don't know if its still needed..

needs or not, please back up the files ASAP, just in case it would be 'updated' again if you go live.
Title: UDE/5713+
Post by: Slrpgeit on July 20, 2004, 08:06:00 AM
biggrin.gif
Title: UDE/5713+
Post by: chimpanzee on July 20, 2004, 08:10:00 AM
QUOTE (Slrpgeit @ Jul 20 2004, 04:09 PM)
already have, they're in a nice zip file on my pc hard drive  biggrin.gif

there is a scanner written by ldots which will give us more info for the given file. Can't find the link off-hand.

Or if you know how to run unix or know about the xbedump program, you can also run :

xbedump <your file> -dc

Title: UDE/5713+
Post by: Slrpgeit on July 20, 2004, 08:14:00 AM
CODE
--------------------------------------------------
  Scanning HDD for xbe's with XBE_MEDIA_HDD flag
--------------------------------------------------



----------------
Entering /mnt/C:
----------------


***************************************************************************
Correct Media flag found in : /mnt/C/xodash/update.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x409BCB24 Fri May  7 17:45:08 2004
Title ID                            : 0xFFFE0000
Title name                          : "Online Updater Application"
Alternate title ID's                :
   none
Allowed media types                 : 0x80000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x7FFFFFFF
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x185EAD00

***************************************************************************
Correct Media flag found in : /mnt/C/xodash/xonlinedash.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x409BCB2A Fri May  7 17:45:14 2004
Title ID                            : 0xFFFE0000
Title name                          : "Xbox Dashboard"
Alternate title ID's                :
   none
Allowed media types                 : 0x80000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x7FFFFFFF
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x185EAD00

***************************************************************************
Correct Media flag found in : /mnt/C/xboxdash.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x409BCB27 Fri May  7 17:45:11 2004
Title ID                            : 0xFFFE0000
Title name                          : "Xbox Dashboard"
Alternate title ID's                :
   none
Allowed media types                 : 0x80000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x7FFFFFFF
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x185EAD00

***************************************************************************
Correct Media flag found in : /mnt/C/evoxdash.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001DC
Certificate timestamp               : 0x3F75746A Sat Sep 27 11:28:42 2003
Title ID                            : 0x586F7645
Title name                          : "RemoteX"
Alternate title ID's                :
   none
Allowed media types                 : 0x800000FF
                                   : XBE_MEDIA_HDD
                                   : XBE_MEDIA_XBOX_DVD
                                   : XBE_MEDIA_ANY_CD_OR_DVD
                                   : XBE_MEDIA_CD
                                   : XBE_MEDIA_1LAYER_DVDROM
                                   : XBE_MEDIA_2LAYER_DVDROM
                                   : XBE_MEDIA_1LAYER_DVDR
                                   : XBE_MEDIA_2LAYER_DVDR
Allowed game regions                : 0x80000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
                                   : XBE_REGION_DEBUG
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x00000000

***************************************************************************
Correct Media flag found in : /mnt/C/xboxdashdata.185ead00/settings_adoc.xip
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3D5942BB Tue Aug 13 17:32:43 2002
Title ID                            : 0xFFFE0000
Title name                          : ""
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0xFFFFFFFF
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
                                   : XBE_REGION_DEBUG
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x10025300

***************************************************************************
Correct Media flag found in : /mnt/C/settings_adoc.xip
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001D0
Certificate timestamp               : 0x3B8D594A Wed Aug 29 21:06:18 2001
Title ID                            : 0xFFFE0000
Title name                          : ""
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0xFFFFFFFF
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
                                   : XBE_REGION_DEBUG
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x00000000

----------------
Entering /mnt/E:
----------------


***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/4d53002a/$u/downloader.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3F8C628E Tue Oct 14 20:54:38 2003
Title ID                            : 0x4D53002A
Title name                          : "Downloader"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000004
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x00000103

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/4d53002a/$u/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3F8C6283 Tue Oct 14 20:54:27 2003
Title ID                            : 0x4D53002A
Title name                          : "Midtown Madness 3"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000004
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x00000103

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/4d530021/$u/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x40746F96 Wed Apr  7 21:16:06 2004
Title ID                            : 0x4D530021
Title name                          : "Crimson Skies"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000004
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x00000203

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/4d530021/$u/downloader.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x40746FAC Wed Apr  7 21:16:28 2004
Title ID                            : 0x4D530021
Title name                          : "Downloader"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000004
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x00000203

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/4d53004b/$u/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x40E0938B Mon Jun 28 21:54:19 2004
Title ID                            : 0x4D53004B
Title name                          : "Project Gotham Racing 2"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000004
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x00000202

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/4d53004b/$u/downloader.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x40E093B6 Mon Jun 28 21:55:02 2004
Title ID                            : 0x4D53004B
Title name                          : "Downloader"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000004
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x00000202

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/4c410003/$u/downloader.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x403BE480 Tue Feb 24 23:55:44 2004
Title ID                            : 0x4C410003
Title name                          : "Downloader"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000004
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x05AB8502

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/4c410003/$u/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x403BE471 Tue Feb 24 23:55:29 2004
Title ID                            : 0x4C410003
Title name                          : "Star Wars: KotOR"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000004
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x05AB8502

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/41430019/$u/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3F01ED43 Tue Jul  1 20:21:23 2003
Title ID                            : 0x41430019
Title name                          : "Burnout 2"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000004
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x00000104

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/5553000c/$u/downloader.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3DC88AEE Wed Nov  6 03:22:22 2002
Title ID                            : 0x5553000C
Title name                          : "Downloader"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000004
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x0000010A

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/5553000c/$u/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3DC88AEE Wed Nov  6 03:22:22 2002
Title ID                            : 0x5553000C
Title name                          : "Splinter Cell"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000004
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x0000010A

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/55530013/$u/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x404FAC76 Thu Mar 11 00:01:58 2004
Title ID                            : 0x55530013
Title name                          : "RainbowSix 3"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000002
Disk number                         : 0x00000000
Version                             : 0x00000501

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/55530013/$u/downloader.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x404FAC84 Thu Mar 11 00:02:12 2004
Title ID                            : 0x55530013
Title name                          : "Downloader"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000002
Disk number                         : 0x00000000
Version                             : 0x00000501

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/55530019/$u/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x40A134E8 Tue May 11 20:17:44 2004
Title ID                            : 0x55530019
Title name                          : "Splinter Cell 2"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000003
Disk number                         : 0x00000000
Version                             : 0x00000302

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/55530019/$u/downloader.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x40A134F6 Tue May 11 20:17:58 2004
Title ID                            : 0x55530019
Title name                          : "Downloader"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000003
Disk number                         : 0x00000000
Version                             : 0x00000302

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/55530019/$u/offline.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x40A13501 Tue May 11 20:18:09 2004
Title ID                            : 0x55530019
Title name                          : "Splinter Cell 2"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000003
Disk number                         : 0x00000000
Version                             : 0x00000302

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/55530019/$u/online.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x40A1350E Tue May 11 20:18:22 2004
Title ID                            : 0x55530019
Title name                          : "Splinter Cell 2"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000003
Disk number                         : 0x00000000
Version                             : 0x00000302

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/55530019/$u/update.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x40A1351A Tue May 11 20:18:34 2004
Title ID                            : 0x55530019
Title name                          : "Splinter Cell 2"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000003
Disk number                         : 0x00000000
Version                             : 0x00000302

***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/434d0011/$u/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x40A1338C Tue May 11 20:11:56 2004
Title ID                            : 0x434D0011
Title name                          : "Race Driver 2"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000004
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x00000104

***************************************************************************
Correct Media flag found in : /mnt/E/Apps/NTSC-PAL/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001D0
Certificate timestamp               : 0x3CE92450 Mon May 20 16:29:04 2002
Title ID                            : 0xFFFF000D
Title name                          : "Enigmah Videomode Switchdisc"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000205
                                   : XBE_MEDIA_HDD
                                   : XBE_MEDIA_ANY_CD_OR_DVD
Allowed game regions                : 0x80000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
                                   : XBE_REGION_DEBUG
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x00000000

***************************************************************************
Correct Media flag found in : /mnt/E/Apps/Dvd2XboX/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x404F93AE Wed Mar 10 22:16:14 2004
Title ID                            : 0x0FACFAC0
Title name                          : "dvd2xbox"
Alternate title ID's                :
   none
Allowed media types                 : 0x80000007
                                   : XBE_MEDIA_HDD
                                   : XBE_MEDIA_XBOX_DVD
                                   : XBE_MEDIA_ANY_CD_OR_DVD
Allowed game regions                : 0x80000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
                                   : XBE_REGION_DEBUG
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x00000000

***************************************************************************
Correct Media flag found in : /mnt/E/Apps/BiosCheck/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001DC
Certificate timestamp               : 0x3F752809 Sat Sep 27 06:02:49 2003
Title ID                            : 0xF001601D
Title name                          : "BiosCheck"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000205
                                   : XBE_MEDIA_HDD
                                   : XBE_MEDIA_ANY_CD_OR_DVD
Allowed game regions                : 0x80000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
                                   : XBE_REGION_DEBUG
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x00000000

***************************************************************************
Correct Media flag found in : /mnt/E/Apps/Avalaunch/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x40309F78 Mon Feb 16 10:46:16 2004
Title ID                            : 0x080299FF
Title name                          : "Avalaunch"
Alternate title ID's                :
   none
Allowed media types                 : 0x80000007
                                   : XBE_MEDIA_HDD
                                   : XBE_MEDIA_XBOX_DVD
                                   : XBE_MEDIA_ANY_CD_OR_DVD
Allowed game regions                : 0x80000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
                                   : XBE_REGION_DEBUG
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x00000000

***************************************************************************
Correct Media flag found in : /mnt/E/Apps/boXplorer/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001DC
Certificate timestamp               : 0x3D5D004D Fri Aug 16 13:38:21 2002
Title ID                            : 0xFFFF051F
Title name                          : "boXplorer (G-patched)"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000205
                                   : XBE_MEDIA_HDD
                                   : XBE_MEDIA_ANY_CD_OR_DVD
Allowed game regions                : 0x80000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
                                   : XBE_REGION_DEBUG
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x00000000

***************************************************************************
Correct Media flag found in : /mnt/E/Apps/boXplorer/unpatched for G 0.96 default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001DC
Certificate timestamp               : 0x3D5D004D Fri Aug 16 13:38:21 2002
Title ID                            : 0xFFFF051F
Title name                          : "boXplorer"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000205
                                   : XBE_MEDIA_HDD
                                   : XBE_MEDIA_ANY_CD_OR_DVD
Allowed game regions                : 0x80000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
                                   : XBE_REGION_DEBUG
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x00000000

***************************************************************************
Correct Media flag found in : /mnt/E/Apps/scan/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001D0
Certificate timestamp               : 0x00000000 Thu Jan  1 00:00:00 1970
Title ID                            : 0x21585554
Title name                          : "Linux"
Alternate title ID's                :
   none
Allowed media types                 : 0x800000FF
                                   : XBE_MEDIA_HDD
                                   : XBE_MEDIA_XBOX_DVD
                                   : XBE_MEDIA_ANY_CD_OR_DVD
                                   : XBE_MEDIA_CD
                                   : XBE_MEDIA_1LAYER_DVDROM
                                   : XBE_MEDIA_2LAYER_DVDROM
                                   : XBE_MEDIA_1LAYER_DVDR
                                   : XBE_MEDIA_2LAYER_DVDR
Allowed game regions                : 0x80000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
                                   : XBE_REGION_DEBUG
Allowed game rating       &n
Title: UDE/5713+
Post by: chimpanzee on July 20, 2004, 08:22:00 AM
QUOTE (Slrpgeit @ Jul 20 2004, 04:17 PM)
***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/55530019/$u/update.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x40A1351A Tue May 11 20:18:34 2004
Title ID                            : 0x55530019
Title name                          : "Splinter Cell 2"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000007
                                   : XBE_REGION_US_CANADA
                                   : XBE_REGION_JAPAN
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000003
Disk number                         : 0x00000000
Version                             : 0x00000302


Unfortunately, this one seems to be a plugged one given the date/time
Title: UDE/5713+
Post by: Slrpgeit on July 20, 2004, 08:27:00 AM
is there any way to test it?
Title: UDE/5713+
Post by: chimpanzee on July 20, 2004, 08:32:00 AM
QUOTE (Slrpgeit @ Jul 20 2004, 04:30 PM)
is there any way to test it?

Given the date (May, 2004), I have a feeling that MS explicitly fixed the hole and released it through live. It just coincide with the discovering of this update.xbe hole !

Hello MS, I know you are reading.

BTW, I think it is worthless now to use any game to go live and try to download. In fact, I would say going live now would just diminishing the chance. Our hope lies in some old HD which is not ruined by MS.
Title: UDE/5713+
Post by: Slrpgeit on July 20, 2004, 08:40:00 AM
CODE
***************************************************************************
Correct Media flag found in : /mnt/E/TDATA/55530013/$u/default.xbe
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x404FAC76 Thu Mar 11 00:01:58 2004
Title ID                            : 0x55530013
Title name                          : "RainbowSix 3"
Alternate title ID's                :
none
Allowed media types                 : 0x00000001
                                  : XBE_MEDIA_HDD
Allowed game regions                : 0x00000007
                                  : XBE_REGION_US_CANADA
                                  : XBE_REGION_JAPAN
                                  : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000002
Disk number                         : 0x00000000
Version                             : 0x00000501
Title: UDE/5713+
Post by: YoshiKool on July 20, 2004, 08:46:00 AM
QUOTE
Certificate timestamp               : 0x404FAC76 Thu Mar 11 00:01:58 2004


Too new probably.
Title: UDE/5713+
Post by: krayzie on July 20, 2004, 08:47:00 AM
nah too new too.
Title: UDE/5713+
Post by: Slrpgeit on July 20, 2004, 08:49:00 AM
before what date should it be then?
Title: UDE/5713+
Post by: chimpanzee on July 20, 2004, 08:51:00 AM
QUOTE (Slrpgeit @ Jul 20 2004, 04:52 PM)
before what date should it be then?

Before 2003. You finding is not worthless though. As I said in the previous post, our hope now lies in live users who has not gone online recently.
Title: UDE/5713+
Post by: Slrpgeit on July 20, 2004, 08:52:00 AM
are there any other things but the date that matter?
Title: UDE/5713+
Post by: krayzie on July 20, 2004, 08:53:00 AM
yeah it should run of hdd and contain the elsewhere region type
Title: UDE/5713+
Post by: YoshiKool on July 20, 2004, 08:54:00 AM
tongue.gif you should have broken it up or something smile.gif
Title: UDE/5713+
Post by: Slrpgeit on July 20, 2004, 08:56:00 AM
CODE
***************************************************************************
Correct Media flag found in : /mnt/C/settings_adoc.xip
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001D0
Certificate timestamp               : 0x3B8D594A Wed Aug 29 21:06:18 2001
Title ID                            : 0xFFFE0000
Title name                          : ""
Alternate title ID's                :
none
Allowed media types                 : 0x00000001
                                  : XBE_MEDIA_HDD
Allowed game regions                : 0xFFFFFFFF
                                  : XBE_REGION_US_CANADA
                                  : XBE_REGION_JAPAN
                                  : XBE_REGION_ELSEWHERE
                                  : XBE_REGION_DEBUG
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x00000000
Title: UDE/5713+
Post by: YoshiKool on July 20, 2004, 08:57:00 AM
that's the easter egg XBE, it's just a renamed XBE, we need xbe's from 2003 because dash xbe's before then won't run on new kernel xboxes...
Title: UDE/5713+
Post by: chimpanzee on July 20, 2004, 08:59:00 AM
QUOTE (Slrpgeit @ Jul 20 2004, 04:59 PM)
yeah, sry bout that, didn't know. but, does it have to be an .xbe? because there is a .xip from 2001 with all regions, and runs from hd, like this one:

CODE
***************************************************************************
Correct Media flag found in : /mnt/C/settings_adoc.xip
***************************************************************************

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001D0
Certificate timestamp               : 0x3B8D594A Wed Aug 29 21:06:18 2001
Title ID                            : 0xFFFE0000
Title name                          : ""
Alternate title ID's                :
none
Allowed media types                 : 0x00000001
                                  : XBE_MEDIA_HDD
Allowed game regions                : 0xFFFFFFFF
                                  : XBE_REGION_US_CANADA
                                  : XBE_REGION_JAPAN
                                  : XBE_REGION_ELSEWHERE
                                  : XBE_REGION_DEBUG
Allowed game rating                 : 0xFFFFFFFF
Disk number                         : 0x00000000
Version                             : 0x00000000

this is the easter egg XBE, has found any hole in it so far.
Title: UDE/5713+
Post by: Slrpgeit on July 20, 2004, 08:59:00 AM
ah, i see, but somewhere in this thread, i saw something that makes the date not matter for newer kernels. is this true?
Title: UDE/5713+
Post by: YoshiKool on July 20, 2004, 09:01:00 AM
uhh, no... on dashboard XBE's it checks to see if the date is before a certain point and if not you get error 21
Title: UDE/5713+
Post by: PedrosPad on July 20, 2004, 09:12:00 AM
Correction: The date is only important if the titleID is the Dashboard titleID of 0xfffe000.  Otherwise the date doesn't matter.
Title: UDE/5713+
Post by: YoshiKool on July 20, 2004, 09:13:00 AM
that's what i meant by saying "dashboard XBE's"... unless some don't have that title ID?
Title: UDE/5713+
Post by: chimpanzee on July 20, 2004, 09:15:00 AM
QUOTE (PedrosPad @ Jul 20 2004, 05:15 PM)
Correction: The date is only important if the titleID is the Dashboard titleID of 0xfffe000.  Otherwise the date doesn't matter.

But it is a good indication whether the font bug is fixed. This May 2004 version is just to close to your annoncement of UDE. Do you think a previous one that is signed for region 1,2 of date Dec 2003 has any chance to be exploitable ? It may be good for Japan/Singapore/Hong Kong(not that much users though).
Title: UDE/5713+
Post by: PedrosPad on July 20, 2004, 09:22:00 AM
QUOTE (YoshiKool @ Jul 20 2004, 05:16 PM)
that's what i meant by saying "dashboard XBE's"... unless some don't have that title ID?

Most update.xbe's have the Dashboard titleID (oxfffe000), and are considered part of the Dashboard suite of programs.  However some update.xbe's have been found that don't have this titleID - and one of them is used for UDE2 wink.gif

So what we're looking for is an old PAL update.xbe - old so it still has the font flaw - but one that doesn't have the Dashboard's titleID - so K:5713+ won't prevent it running.
Title: UDE/5713+
Post by: YoshiKool on July 20, 2004, 09:23:00 AM
smile.gif
Title: UDE/5713+
Post by: YoshiKool on July 20, 2004, 09:55:00 AM
chimpanzee: i think every update.xbe dated after that "special date" isn't exploitable which is why we need a non-dashboard titled one that is also before the "special date"

ok this is annoying me now, someone remind me what the "special date" is
Title: UDE/5713+
Post by: m.e on July 20, 2004, 11:16:00 AM
QUOTE (m.e @ Jul 20 2004, 03:01 PM)
I know Unreal Championship(PAL) was released before there where xbox live in Europe.

So this game is likely to have a hdd-signed update.xbe wink.gif

I'll repeat myself.
This was the first PAL game that was xbox live compatible.  I don't have it myself so I can't check if it has a good update.xbe.
Title: UDE/5713+
Post by: gronne on July 20, 2004, 04:52:00 PM
Are you guys sure the SC2 update.xbe isn't working? Ok, it's a new timestamp, since it was released last fall or something. But UDE wasn't released until the end of May if I'm not all wrong. Probably they fixed it when the easter-egg was released then. But if you think there is someone that hasn't been on live since early May, we better hope sc2 was the last game he played? Maybe they plugged several games at the same time, meaning other games might work as well? The only chance of finding that file is by announcing the issue on the front-page, right?
Title: UDE/5713+
Post by: EthanHunt_IMF on July 20, 2004, 05:01:00 PM
QUOTE (gronne @ Jul 20 2004, 07:55 PM)
Are you guys sure the SC2 update.xbe isn't working? Ok, it's a new timestamp, since it was released last fall or something. But UDE wasn't released until the end of May if I'm not all wrong. Probably they fixed it when the easter-egg was released then. But if you think there is someone that hasn't been on live since early May, we better hope sc2 was the last game he played? Maybe they plugged several games at the same time, meaning other games might work as well? The only chance of finding that file is by announcing the issue on the front-page, right?

the patch did not comeout when UDE came out.  The hole was plugged when the original fonts exploit came out.  UDE uses this same premise(sp?) on a different file to avoid the clock loop.

Edit: Forgot to add this: Correct me if i'm wrong.
Title: UDE/5713+
Post by: gronne on July 20, 2004, 05:13:00 PM
The original font exploit came on the 4:th of July 2003, so I don't see why they patch the file as late as 11 May 2004, as the game was out late 2003(I think). There must've been some other reason they patched it that late.

Are you guys officially certain that the sc2 update.xbe is a no-go?
Title: UDE/5713+
Post by: chimpanzee on July 20, 2004, 05:16:00 PM
QUOTE (gronne @ Jul 21 2004, 01:16 AM)
The original font exploit came on the 4:th of July 2003, so I don't see why they patch the file as late as 11 May 2004, as the game was out late 2003(I think). There must've been some other reason they patched it that late.

Are you guys officially certain that the sc2 update.xbe is a no-go?

Nothing is official until the pros said so :-)

But May 2004 is way to suspicious a date. I wish I am wrong and my other dream is true.
Title: UDE/5713+
Post by: gronne on July 20, 2004, 05:41:00 PM
I suppose it takes a lot of work to find out if it's working or not. Let's hope they're trying it.


EDIT: As I don't know when the easter egg was released, does anyone have an idea of why they had the need to update the update.xbe in 11 may? If it wasn't because they discovered the flaw by themselves, or someone here posted something that was related to the issue back then, it might just be that they updated it for other reasons and the flaw is still there.
Title: UDE/5713+
Post by: SSJ4Gohan on July 20, 2004, 05:59:00 PM
I know this has prolly been asked a few times, but is there any chance at an installer?
Title: UDE/5713+
Post by: chimpanzee on July 20, 2004, 06:04:00 PM
QUOTE (SSJ4Gohan @ Jul 21 2004, 02:02 AM)
I know this has prolly been asked a few times, but is there any chance at an installer?

what installer ? there is already an installer. If you mean for 5713+, not yet as ldots is waiting for hopefully PAL version to make it complete.
Title: UDE/5713+
Post by: gronne on July 21, 2004, 07:59:00 AM
Did this thread just die or something? Will someone officially say the file didn't work or what?
Title: UDE/5713+
Post by: chimpanzee on July 21, 2004, 08:07:00 AM
QUOTE (gronne @ Jul 21 2004, 04:02 PM)
Did this thread just die or something? Will someone officially say the file didn't work or what?

something, but don't know what it is.
Title: UDE/5713+
Post by: PedrosPad on July 21, 2004, 08:14:00 AM
QUOTE (YoshiKool @ Jul 20 2004, 05:58 PM)
chimpanzee: i think every update.xbe dated after that "special date" isn't exploitable which is why we need a non-dashboard titled one that is also before the "special date"

ok this is annoying me now, someone remind me what the "special date" is

QUOTE (rmenhal @ May 19 2004, 09:17 AM)
We know that kernels 5713 or higher won't allow dash downgrades.

Actually - while I didn't bother to trace out the logic exactly - there's a new check in 5713's XBE loader. It checks the XBE certificate structure. If the title ID is 0xFFFE0000 (dash's ID), the kernel then checks the time and date field and anything prior to about Aug 5 2003 causes it to bail out. So dash 4920 and prior versions are out.

So it's a fair guess that M$ was confident that the font flaw was fixed post 5th Aug, 2003.
Title: UDE/5713+
Post by: PedrosPad on July 21, 2004, 08:15:00 AM
QUOTE (gronne @ Jul 21 2004, 01:44 AM)
does anyone have an idea of why they had the need to update the update.xbe in 11 may?

The release of Dashboard 5960 (would be my guess).
Title: UDE/5713+
Post by: eh. on July 21, 2004, 08:55:00 AM
QUOTE (PedrosPad @ Jul 20 2004, 08:52 AM - last paragraph)
To progress this speculation, I'd be intrested is seeing a list of the xbe's from the US NFL Fever 2003 DVD media, and their lengths.

The following are on mine eh.
CODE

5,496,832 \default.xbe
1,560,576 \Update.xbe
  962,560 \xdemos\xdemos.xbe
2,121,728 \XODash\XOnlineDash.xbe
Title: UDE/5713+
Post by: PedrosPad on July 21, 2004, 10:04:00 AM
biggrin.gif
Title: UDE/5713+
Post by: YoshiKool on July 21, 2004, 11:27:00 AM
tongue.gif at least now i know the "special date" eh smile.gif thanks pedro
Title: UDE/5713+
Post by: eh. on July 21, 2004, 01:19:00 PM
Nope, all those media types indicate that it's no longer suitably signed (due to a transfer proggie having changed it).  Thanks for trying though eh.
Title: UDE/5713+
Post by: PedrosPad on July 22, 2004, 10:13:00 AM
QUOTE
To progress this speculation, I'd be intrested is seeing a list of the xbe's from the US NFL Fever 2003 DVD media, and their lengths.

QUOTE (eh. @ Jul 21 2004, 04:58 PM)
The following are on mine eh.
CODE

5,496,832 \default.xbe
1,560,576 \Update.xbe
  962,560 \xdemos\xdemos.xbe
2,121,728 \XODash\XOnlineDash.xbe

Thanks eh.
The xbes and file lengths of off the PAL NFL Fever 2003 are
CODE

5,496,832 \default.xbe
1,560,576 \Update.xbe
  962,560 \xdemos\xdemos.xbe
2,121,728 \XODash\XOnlineDash.xbe

Yup - they match exactly.

Just to prove I was using the PAL default.xbe, here is the certificate:
CODE
Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001DC
Certificate timestamp               : 0x3D824600 Fri Sep 13 21:09:36 2002
Title ID                            : 0x4D530028
Title name                          : "NFL Fever 2003"
Alternate title ID's                :
   none
Allowed media types                 : 0x00000002
                                   : XBE_MEDIA_XBOX_DVD
Allowed game regions                : 0x00000004
                                   : XBE_REGION_ELSEWHERE
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x00000005


I'm now interested is seeing the US NFL default.xbe's certificate.
Title: UDE/5713+
Post by: YoshiKool on July 22, 2004, 10:20:00 AM
does the update.xbe in the root only run from dvd?
Title: UDE/5713+
Post by: eh. on July 22, 2004, 10:37:00 AM
QUOTE (PedrosPad @ Jul 22 2004, 10:16 AM - partial)
Thanks eh.

I'm now interested is seeing the US NFL default.xbe's certificate.

You're welcome eh.  smile.gif
CODE
Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001DC
Certificate timestamp               : 0x3D4730E5 Tue Jul 30 18:35:49 2002
Title ID                            : 0x4D530028
Title name                          : "NFL Fever 2003"
Alternate title ID's                : none
Allowed media types                 : 0x00000002
                                   : XBE_MEDIA_XBOX_DVD
Allowed game regions                : 0x00000001
                                   : XBE_REGION_US_CANADA
Allowed game rating                 : 0x00000004
Disk number                         : 0x00000000
Version                             : 0x00000004
Title: UDE/5713+
Post by: eh. on July 22, 2004, 10:41:00 AM
CODE
Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001DC
Certificate timestamp               : 0x3D4730E5 Tue Jul 30 18:35:49 2002
Title ID                            : 0xFFFE0000
Title name                          : "Online Updater Application"
Alternate title ID's                : none
Allowed media types                 : 0x00000002
                                   : XBE_MEDIA_XBOX_DVD
Allowed game regions                : 0x00000001
                                   : XBE_REGION_US_CANADA
Allowed game rating                 : 0x00000004
Disk number                         : 0x00000000
Version                             : 0x00000004
Title: UDE/5713+
Post by: YoshiKool on July 22, 2004, 10:46:00 AM
sad.gif
Title: UDE/5713+
Post by: krayzie on July 22, 2004, 10:51:00 AM
would it even be possible to find a dvd xbe that does not only have the dvd media type?
Title: UDE/5713+
Post by: anu|b|iss on July 22, 2004, 11:03:00 AM
from reading this thread, nothing is impossible, it just isn't likely.
Title: UDE/5713+
Post by: YoshiKool on July 22, 2004, 11:03:00 AM
i'm sure i've seen a few...
Title: UDE/5713+
Post by: eh. on July 22, 2004, 11:06:00 AM
biggrin.gif
CODE
Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3DC83440 Tue Nov 05 14:12:32 2002
Title ID                            : 0x4D530028
Title name                          : "Online Updater Application"
Alternate title ID's                : none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000001
                                   : XBE_REGION_US_CANADA
Allowed game rating                 : 0x00000004
Disk number                         : 0x00000000
Version                             : 0x00010004
Title: UDE/5713+
Post by: eh. on July 22, 2004, 11:19:00 AM
muhaha.gif
CODE
Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3DC83422 Tue Nov 05 14:12:02 2002
Title ID                            : 0x4D530028
Title name                          : "NFL Fever 2003"
Alternate title ID's                : none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000001
                                   : XBE_REGION_US_CANADA
Allowed game rating                 : 0x00000004
Disk number                         : 0x00000000
Version                             : 0x00010004
Title: UDE/5713+
Post by: krayzie on July 22, 2004, 11:22:00 AM
I think it's fair to say now we need a freekin miracle.
Title: UDE/5713+
Post by: eh. on July 22, 2004, 11:47:00 AM
mellow.gif
Title: UDE/5713+
Post by: PedrosPad on July 22, 2004, 03:29:00 PM
QUOTE (eh. @ Jul 22 2004, 07:09 PM)

CODE
Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001EC
Certificate timestamp               : 0x3DC83440 Tue Nov 05 14:12:32 2002
Title ID                            : 0x4D530028
Title name                          : "Online Updater Application"
Alternate title ID's                : none
Allowed media types                 : 0x00000001
                                   : XBE_MEDIA_HDD
Allowed game regions                : 0x00000001
                                   : XBE_REGION_US_CANADA
Allowed game rating                 : 0x00000004
Disk number                         : 0x00000000
Version                             : 0x00010004

This the eh.'s NFL update.xbe that was used for US UDE2.

eh.'s quip about  "Guy Fawkes day" (Nov 5th) caught my eye.

This file from the NFL Fever 2003 DVD...
CODE

2,121,728 \XODash\XOnlineDash.xbe

...is a fake Dashboard - when you run it it simply shows a static image saying that XBOX is due to launch in November 2002.  Interesting date eh?

The dates imply that the update.xbe that eh.'s NFL Fever 2003 downloaded must have been the first one published on the XBL servers.  So if a PAL XBL game also connected around that time, it too may have an update.xbe, with a titleID of the game.  It would seem that M$ decided that update.xbe was, in fact, part of the Dashboard suite after this time.

eh., any chance you could delete your NFL downloaded content, and see if the game sucks the same update.xbe it down again?  (I doubt it would, but would like to know).
Title: UDE/5713+
Post by: PedrosPad on July 23, 2004, 09:28:00 AM
QUOTE (Dan Wysocki @ Jul 14 2004, 08:39 AM)
This seems like a really cool app, is there any way of developing a PC version cause I have numerous backups of my whole xbox hdd on my pc and it may be nice to be able to run an app to search within folders in windows...

Re: ldots XBE scanner

Like Dan, I've realised I've a complete backup of my brothers XBOX HDD that I'd FTPed across, zipped up, and tucked away on a CD somewhere (and he was an early XBL user smile.gif) - I recall I backed everything up (C & E) before I attempted any exploits on his XBOX. (I'll try and find it tonight).

So in preparation, I've ported the idea of ldots XBE scanner to a Windows batch file.
(Tested on Windows XP - but should also work on Windows NT)

Usage:
Put a copy of xbedump.exe at C:\
Pop the HDDXBESrch.bat batch file at the top of the folder tree you wish to search (C:\Games)
and double click on HDDXBESrch.bat.
The output is written to the file C:\HDDXBEs.txt.

Cut and paste the following into Notepad and save as HDDXBESrch.bat (with word-wrap off it should just be 5 lines).
CODE
REM HDDXBESrch.bat
REM Requires C:\xbedump.exe to work
REM
DEL C:\HDDXBEs.txt
FOR /R %%i IN (*.XBE) DO C:\XBEDUMP.EXE "%%i" -dc | FIND "XBE_MEDIA_HDD" && IF NOT ERRORLEVEL 1 ECHO %%i >>C:\HDDXBEs.txt && C:\XBEDUMP.EXE "%%i" -dc >>C:\HDDXBEs.txt


Remember, if it reports that every allowed media type is on, it'll be junk, as the xbe must have been modifed by DVD2XBOX or some such.
Title: UDE/5713+
Post by: krayzie on July 23, 2004, 09:51:00 AM
Uhmm neat app pedro. It just gives me errors though instead of creating a log.

*edit* Actually it does create a log but only with the default.xbe names and locations instead of the xbe info itself
Title: UDE/5713+
Post by: PedrosPad on July 23, 2004, 09:55:00 AM
QUOTE (krayzie @ Jul 23 2004, 05:54 PM)
Uhmm neat app pedro. It just gives me errors though instead of creating a log.

*edit* Actually it does create a log but only with the default.xbe names and locations instead of the xbe info itself

Try cutting and pasting it again - I edited the code section a few times since first posting biggrin.gif (and make sure the long FOR line is kept on one line (no C/Rs)).
Title: UDE/5713+
Post by: ldots on July 23, 2004, 10:01:00 AM
CODE
REM HDDXBESrch.bat
REM Requires C:\xbedump.exe to work
REM
DEL C:\HDDXBEs.txt
FOR /R %%i IN (*.XBE) DO C:\XBEDUMP.EXE "%%i" -dc | FIND "XBE_MEDIA_HDD" && IF NOT ERRORLEVEL 1 ECHO "%%i" >>C:\HDDXBEs.txt && C:\XBEDUMP.EXE "%%i" -dc >>C:\HDDXBEs.txt

And add the .exe extension to xbedump smile.gif
Title: UDE/5713+
Post by: PedrosPad on July 23, 2004, 10:04:00 AM
QUOTE (ldots @ Jul 23 2004, 06:04 PM)
Could be you need to add quotes around the last set of %i variable :
CODE
REM HDDXBESrch.bat
REM Requires C:\xbedump.exe to work
REM
DEL C:\HDDXBEs.txt
FOR /R %%i IN (*.XBE) DO C:\XBEDUMP.EXE "%%i" -dc | FIND "XBE_MEDIA_HDD" && IF NOT ERRORLEVEL 1 ECHO "%%i" >>C:\HDDXBEs.txt && C:\XBEDUMP.EXE "%%i" -dc >>C:\HDDXBEs.txt

And add the .exe extension to xbedump smile.gif

Ta.  Done. biggrin.gif
Title: UDE/5713+
Post by: krayzie on July 23, 2004, 10:36:00 AM
Okay works great now. Too bad I didn't found anything interesting.
Title: UDE/5713+
Post by: krayzie on July 23, 2004, 11:21:00 AM
no. But it would be the best I guess since it doesn't execute any clock setting stuff.
Title: UDE/5713+
Post by: YoshiKool on July 23, 2004, 11:23:00 AM
also, update.xbe is a known exploitable XBE - other stuff such as mechassault's downloader will help also but they have not been exploited as of yet...

edit: i think i smell 500 posts... seems that exploits for 5713+ are already very very popular after only 11 days...
Title: UDE/5713+
Post by: eh. on July 23, 2004, 10:22:00 PM
QUOTE (PedrosPad @ Jul 22 2004, 03:32 PM - partial)
The dates imply that the update.xbe that eh.'s NFL Fever 2003 downloaded must have been the first one published on the XBL servers.  So if a PAL XBL game also connected around that time, it too may have an update.xbe, with a titleID of the game.  It would seem that M$ decided that update.xbe was, in fact, part of the Dashboard suite after this time.
Excellent theory Pedro.

Regarding the last sentence ... they potentially just messed up though, if this is an indicator of what was intended eh.  uhh.gif
CODE
Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001DC
Certificate timestamp               : 0x3D484652 Wed Jul 31 14:19:30 2002
Title ID                            : 0x4D530037
Title name                          : "NFL Fever 2003 Online Beta"
Alternate title ID's                : none
Allowed media types                 : 0x00000002
                                   : XBE_MEDIA_XBOX_DVD
Allowed game regions                : 0x00000001
                                   : XBE_REGION_US_CANADA
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x00000002

Certificate
~~~~~~~~~~~
Size of certificate                 : 0x000001DC
Certificate timestamp               : 0x3D484652 Wed Jul 31 14:19:30 2002
Title ID                            : 0xFFFE0000
Title name                          : "Online Updater Application"
Alternate title ID's                : none
Allowed media types                 : 0x00000002
                                   : XBE_MEDIA_XBOX_DVD
Allowed game regions                : 0x00000001
                                   : XBE_REGION_US_CANADA
Allowed game rating                 : 0x00000000
Disk number                         : 0x00000000
Version                             : 0x00000002
Title: UDE/5713+
Post by: eh. on July 24, 2004, 09:53:00 AM
QUOTE (PedrosPad @ Jul 22 2004, 03:32 PM - remainder)
This the eh.'s NFL update.xbe that was used for US UDE2.

eh.'s quip about  "Guy Fawkes day" (Nov 5th) caught my eye.

This file from the NFL Fever 2003 DVD...
CODE

2,121,728 \XODash\XOnlineDash.xbe

...is a fake Dashboard - when you run it it simply shows a static image saying that XBOX is due to launch in November 2002.  Interesting date eh?

eh., any chance you could delete your NFL downloaded content, and see if the game sucks the same update.xbe it down again?  (I doubt it would, but would like to know).

Initially I reverted to 4817 and "connecting" did indeed display the pre-live fake XOnlineDash.xbe as you described (and consequently didn't download anything).  I then replaced it with 4920 and it attempts to download ... without success ...  I think my network setup's incompatible and will try changing that when I can eh.  comp.gif

Edit (outcome):
Changed the network setup and received 5960 but nothing more, alas.  My tests proved to be somewhat futile, as I don't have Live!  Consequently, I could only gain access to it via the dash.

Learned that my version of Fever2k3 doesn't facilitate the initial connection, it just displays a message about visiting the XBL website for more info.  The owner needs to have subscribed by another means, before this version of the game can use it eh.
Title: UDE/5713+
Post by: scrupul0us on July 25, 2004, 11:25:00 PM
::skips to page 15 and adds his two cents::

Can't you use configmagic? Then ude2?
Title: UDE/5713+
Post by: devz3ro on July 25, 2004, 11:40:00 PM
QUOTE (scrupul0us @ Jul 26 2004, 07:28 AM)
::skips to page 15 and adds his two cents::

Can't you use configmagic? Then ude2?

Yes, obviously you can if you don't have a 1.6 xbox. I'm sure pedro, krazie, ldots and the others are well aware of that. There are many issues with changing eeproms:

1. It's sensative, if you mess it up it can be either very simple or extremely difficult to repair.

2. Far from everyone is comfortable with editing their eeprom.

3. If the instructions I re-wrote aren't followed exactly, you can run into other non-eeprom problems.

-devz3ro
Title: UDE/5713+
Post by: BluhDeBluh on July 25, 2004, 11:42:00 PM
QUOTE (scrupul0us @ Jul 26 2004, 07:28 AM)
::skips to page 15 and adds his two cents::

Can't you use configmagic? Then ude2?

::replies sarcastically:

Read back a few pages, and the UDE2 thread and this has already been mentioned several times and isn't very helpful for a variety of reasons. Since Configmagic also dosn't work on v1.6 'boxes, apparently, people with PAL 1.6ers have a problem. It also means if you mess up your 'box, you also might struggle to revert it without picking up a copy of MechAssault and you'd also have to wait for EvoX to launch so you can play PAL games.

Not really ideal.
Title: UDE/5713+
Post by: YoshiKool on July 26, 2004, 03:17:00 AM
scrupul0us: 1.4 or maybe 1.5 - 1.6's have kernel 5838 for the new video encoder
Title: UDE/5713+
Post by: PedrosPad on July 26, 2004, 04:47:00 AM
QUOTE (BluhDeBluh @ Jul 26 2004, 07:45 AM)
Since Configmagic also dosn't work on v1.6 'boxes, apparently, people with PAL 1.6ers have a problem.

The source code for ConfigMagic can be found here smile.gif (You never know - look that happened when I pointed people to the source of PBL wink.gif )
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 26, 2004, 07:36:00 AM
blink.gif right

why not just extract the eeprom manually? if you can get 1 pal and 1 ntsc, finding the right bytes to change should be a snap (or trial and error if you have nice failsafe like a modchip  biggrin.gif ) or is the archetecture of the eeprom circut and drivers radicly different so reading a writeing would be a pain?
Title: UDE/5713+
Post by: PedrosPad on July 26, 2004, 09:06:00 AM
QUOTE (Atreyu @ Jul 26 2004, 05:02 PM)
i sent my friend Idots search proggy.. and he ran it.. and he said it found some files but does the program write a log? if so.. where does it write it to?

E:\SCAN_LOG.TXT (or a filename very close to that)
Title: UDE/5713+
Post by: eh. on July 26, 2004, 09:08:00 AM
QUOTE (PedrosPad @ Jul 23 2004, 09:31 AM - partial)
Usage:
Put a copy of xbedump.exe at C:\
Pop the HDDXBESrch.bat batch file at the top of the folder tree you wish to search (C:\Games)
and double click on HDDXBESrch.bat.
The output is written to the file C:\HDDXBEs.txt.

Remember, if it reports that every allowed media type is on, it'll be junk, as the xbe must have been modifed by DVD2XBOX or some such.

Thanks for this Pedro; it worked well (on win2Kpro) for me eh.  To increase the chance of others seeing it, could Angerwound add a link in the "Exploit Tools" sticky, along with one to ldots scanner?

(Edit: P.S.  The outcome of my Fever2k3 tests is now in the related post.)
Title: UDE/5713+
Post by: Angerwound on July 26, 2004, 11:57:00 AM
I'm sure I can do that for you. I meant to throw that in there sooner but it must have slipped past me.
Title: UDE/5713+
Post by: PedrosPad on July 27, 2004, 01:50:00 AM
QUOTE (Atreyu @ Jul 27 2004, 09:42 AM)
I got my friend to run Idots search tool, and he posted me his log.. i don't think any of the files he found are useful but just incase, can someone who knows.. please check the log to confirm?
thanx

FRIENDS XBE_SCAN.LOG

Unfortunately, in this instance, you're right - there's nothing remarkable in the log, but many thanks for taking the trouble and posting the results. smile.gif
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 27, 2004, 01:57:00 AM
QUOTE (Chicken Scratch Boy @ Jul 26 2004, 06:39 AM)
why not just extract the eeprom manually?

like... back it up and look at people..
good idea, bad idea? tried it? i'm a genius?
Title: UDE/5713+
Post by: mkjones on July 27, 2004, 03:16:00 AM
smile.gif
Title: UDE/5713+
Post by: YoshiKool on July 27, 2004, 03:18:00 AM
If you changed a PAL xbox's EEPROM to NTSC xbe region - then you wouldn't be able to boot retail PAL games before the exploit triggered (in case you screwed anything up.) You could still hotswap or use MA though (i think MA is elsewhere and us_canada region).

Of course once the exploit triggers you can run any game, backup or retail.
Title: UDE/5713+
Post by: chimpanzee on July 27, 2004, 03:19:00 AM
QUOTE (mkjones @ Jul 27 2004, 11:19 AM)
Sounds Risky but could an EEPROM switch be "Scripted" in any dash language? Or a Linux distro?

I assume AVA would have this potential, if so it could help in ensuring its done right.

OR it could go wrong 1/2 way through and kill the box!

However, what disadvantages are there to a changed eeppom?

Is one that you cannot boot orig games? OR can you still boot them from a dash like a backup? I cant see why it would make a difference as this would efectivly make the box regoin free anyway smile.gif

the linux guys only tell us how to read/write eeprom but not how to 'change' it as they don't see the need for it and consider it to be purely 'pirate' related activity :-(
Title: UDE/5713+
Post by: PedrosPad on July 27, 2004, 03:21:00 AM
QUOTE (chimpanzee @ Jul 27 2004, 11:22 AM)
the linux guys only tell us how to read/write eeprom but not how to 'change' it as they don't see the need for it and consider it to be purely 'pirate' related activity :-(

QUOTE (PedrosPad @ Jul 26 2004, 12:50 PM)
The source code for ConfigMagic can be found here smile.gif
Title: UDE/5713+
Post by: chimpanzee on July 27, 2004, 03:36:00 AM
laugh.gif
Title: UDE/5713+
Post by: mkjones on July 27, 2004, 04:03:00 AM
blink.gif
Title: UDE/5713+
Post by: ldots on July 27, 2004, 04:12:00 AM
QUOTE (chimpanzee @ Jul 27 2004, 11:39 AM)
Ah, too complicate for me. I am sure if ldots has the time and is willing to do it, should be easy for him.

Can we now pray to our god  laugh.gif

The reading of the eeprom is one thing. The decryption is another. We need to decrypt the eeprom to start editing it.
The eeprom decryption needs an update (both LiveInfo, ConfigMagic and all linux tools use the "Friday 13th" hack to do this). Once the eeprom is decrypted it not a big deal to change the XBE region

Edit : Sorry! I was thinking v1.6. The current code available decrypt the v1.0-1.5 eeproms just fine. So making the XBE region swith could be automated. I was considering doing this for the UDE2 installer. But decided not to. Imagine if there was a bug  in the code. Automatic eeprom editing sounds a bit risky to me. I could try to make a tool that :
- reads eeprom
- decrypts eeprom
- Sets xbe  region
- encrypts eeprom and dumps to a file.
- tests the encrypted eeprom (decrypt again and extract various information, like XBE region).

Then one could use official tools to write back the eeprom (linux, ConfigMagic or a dashboard).
Title: UDE/5713+
Post by: PedrosPad on July 27, 2004, 04:14:00 AM
QUOTE (chimpanzee @ Jul 27 2004, 11:39 AM)
Ah, too complicate for me. I am sure if ldots has the time and is willing to do it, should be easy for him.

Can we now pray to our god  laugh.gif

If anyone knows where the source is for the Enigmah video switcher, it may be easier to modify - it already toggles the 'video mode', the EEPROM byte right next to the 'xbe region' byte. smile.gif

Edit: Just read that apparently both XBMC and AvaLaunch also contain the ability to toggle the video EEPROM byte - so there's more source to checkout. smile.gif
Title: UDE/5713+
Post by: chimpanzee on July 27, 2004, 05:08:00 AM
QUOTE (PedrosPad @ Jul 27 2004, 12:17 PM)
If anyone knows where the source is for the Enigmah video switcher, it may be easier to modify - it already toggles the 'video mode', the EEPROM byte right next to the 'xbe region' byte. smile.gif

Edit: Just read that apparently both XBMC and AvaLaunch also contain the ability to toggle the video EEPROM byte - so there's more source to checkout. smile.gif

The code in configure magic is good enough, just that I haven't done any of those eeprom encrypt/decrypt mod before but ldots just did for the HD locking so it should be a piece of cake for him.
Title: UDE/5713+
Post by: rmenhal on July 27, 2004, 08:42:00 AM
QUOTE (ldots @ Jul 27 2004, 12:15 PM)
I could try to make a tool that :
- reads eeprom
- decrypts eeprom
- Sets xbe  region
- encrypts eeprom and dumps to a file.
- tests the encrypted eeprom (decrypt again and extract various information, like XBE region).

Assuming you know what the current xbe region is you could (since it is encrypted with RC4) just xor the encrypted region with the known region value and xor again with 0x00000001. cool.gif

Most probably Config Magic just needs to be updated to have the v1.6 EEPROM key (or the corresponding middle message hashes).

Xbe region is apparently a bit field. Why can't we just make it have bits set for all regions? Or if the box is not US/Canada region, then xor the byte at offset 0x2c with 0x01 so that it has also the US/Canada region in addition to the native one?

EDIT: oh, xbe region is also hashed into data_hash. So the EEPROM key (or the middle message hashes) is required. But the multiple-region idea still stands.

EDIT2: multi-region won't work.

Title: UDE/5713+
Post by: krayzie on July 27, 2004, 08:50:00 AM
QUOTE (rmenhal @ Jul 27 2004, 04:45 PM)
Assuming you know what the current xbe region is you could Xbe region is apparently a bit field. Why can't we just make it have bits set for all regions? Or if the box is not US/Canada region, then xor the byte at offset 0x2c with 0x01 so that it has also the US/Canada region in addition to the native one?

If you can acomplish this you are truly the best.
Title: UDE/5713+
Post by: ldots on July 27, 2004, 09:55:00 AM
QUOTE (rmenhal @ Jul 27 2004, 04:45 PM)
Xbe region is apparently a bit field. Why can't we just make it have bits set for all regions? Or if the box is not US/Canada region, then xor the byte at offset 0x2c with 0x01 so that it has also the US/Canada region in addition to the native one?

Indeed with the region codes (0x01, 0x02, 0x04) it does look a lot like its bit packed biggrin.gif

Hmm - that would be neat. So you are saying having the byte at 0x2c set to 0x05 the xbox would function both as a Europe and North America region box?
Should be easy to test, but I'm not sure I'm brave enough. I dont have a modchip sad.gif
Title: UDE/5713+
Post by: chimpanzee on July 27, 2004, 10:11:00 AM
QUOTE (ldots @ Jul 27 2004, 05:58 PM)
Indeed with the region codes (0x01, 0x02, 0x04) it does look a lot like its bit packed biggrin.gif

Hmm - that would be neat. So you are saying having the byte at 0x2c set to 0x05 the xbox would function both as a Europe and North America region box?
Should be easy to test, but I'm not sure I'm brave enough. I dont have a modchip sad.gif

no, please set it to 7 so we NTSC-J users can be benefitted too :-)

However, just found out that running a game hack is not an easy task for NTSC-J, the three known exploitable games either don't have NTSC-J version or don't have the necessary game save :-(

Would it be that simple though ? That would mean any Xbox can run all region original games by design.
Title: UDE/5713+
Post by: YoshiKool on July 27, 2004, 11:11:00 AM
Hmm.... i think i'll say it now so noone tries it
Don't try to xor video modes together...
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 27, 2004, 12:00:00 PM
i was thinking once we get the region for a pal one changed, we can do a diff patch

but if configmagic only needs the key... then do that
Title: UDE/5713+
Post by: ldots on July 27, 2004, 12:27:00 PM
QUOTE (Rmenhal)
EDIT: oh, xbe region is also hashed into data_hash. So the EEPROM key (or the middle message hashes) is required


I'm not suggesting everyone does this, but it is possible that xor'ing your current region with 0x01 will make it multi-region. Someone with a chip could test this out.
Title: UDE/5713+
Post by: YoshiKool on July 28, 2004, 08:40:00 AM
Damn...
Title: UDE/5713+
Post by: adil786 on July 28, 2004, 09:32:00 AM
QUOTE (rmenhal @ Jul 28 2004, 03:10 AM)
The multi-region idea doesn't work. MS checks that (region AND (region - 1)) is zero.

crap   mad.gif
Title: UDE/5713+
Post by: eh. on July 28, 2004, 12:24:00 PM
Yep that's a bummer; the genius minds seemed to have identified a huge opportunity there eh.

@Angerwound: thanks for putting the link to ldots scanner in the Tools post ... hopefully someone, somewhere find even more treasures with it.

@PedrosPad: might it be worthwhile the first post referring to the PC and/or Xbox HDD XBE scanners too?
Title: UDE/5713+
Post by: as1986 on July 28, 2004, 08:20:00 PM
QUOTE (chimpanzee @ Jul 28 2004, 01:14 AM)
no, please set it to 7 so we NTSC-J users can be benefitted too :-)

However, just found out that running a game hack is not an easy task for NTSC-J, the three known exploitable games either don't have NTSC-J version or don't have the necessary game save :-(

Would it be that simple though ? That would mean any Xbox can run all region original games by design.

Yes there are NTSC/J version exploitable games. the NTSC/J MechAssault is exploitable -- and they haven't bothered to patch it beerchug.gif
but i haven't seen 007:AUF here(in Taiwan)
and i don't know whether the NTSC/J splinter cell is exploitable or not.
Title: UDE/5713+
Post by: farbird on July 28, 2004, 09:53:00 PM
Great work..

but for NTSC J users , there will always be the fear of screwups which will not enable them to run the NTSCJ original MA after the region coding has been changed...

I am one of those unlucky twats.
[idiotic dumbass[myself] deleted e:\default.xbe accidentally]

and after I got it working for less than 10 mins..

Been punching myself since last week.
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 28, 2004, 10:03:00 PM
how do you delete somthing off a dvd?

please tell
Title: UDE/5713+
Post by: farbird on July 28, 2004, 10:11:00 PM
haha..

ok the punching did many things to my brains and fingers..

actually is E:\default.xbe

already modified the original post.
Title: UDE/5713+
Post by: Chicken Scratch Boy on July 28, 2004, 10:27:00 PM
you can ALWAYS import a pal/ntsc copy of MA
Title: UDE/5713+
Post by: farbird on July 28, 2004, 11:25:00 PM
will a US NTSC MA allow me to boot ?

I mean, this UDE2 , will it look for d:\default.xbe first before it reads c:\xboxdash.xbe?

If so, I will be frantically looking for one..
Title: UDE/5713+
Post by: farbird on July 28, 2004, 11:28:00 PM
tried booting ntscJ MA.. it still went on to error 21
Title: UDE/5713+
Post by: farbird on July 29, 2004, 02:31:00 AM
anyone have a MA ntsc in SG?
Title: UDE/5713+
Post by: adil786 on July 29, 2004, 03:39:00 AM
QUOTE (farbird @ Jul 29 2004, 10:34 AM)
anyone have a MA ntsc in SG?

sg?

and try ebay m8
Title: UDE/5713+
Post by: farbird on July 29, 2004, 03:48:00 AM
no have in sg..

sigh..

its a very expensive paperweight
Title: UDE/5713+
Post by: John Hoek on September 20, 2004, 12:32:00 AM
ph34r.gif

FACTS:

I know that there are Xbox regio's
1 = ntsc
2 = ntsc j (if I'm right)
4 = Pal
0 = multiregion  

the bios is NOT regio hashed.


So, what about regio 3 or 5? those are not documented yet.  blink.gif
Or OR ONLY the regios NTSC, NTSC-J and PAL together, (NOT REGION 0!)   cool.gif
My believe is that this SCHOULD work well; see below...  wink.gif

============================================
If It look at the routine above closely; i can make this out of it  uhh.gif

I assume that:
0  AND 0 = 0
 0 AND 1 = 0
 1 AND 0 = 0
 1 AND 1 = 1

example A)
regio 4 = PAL = binary       00000100

BIOS checks; 00000100 AND (00000100 - 00000001) = 0? (correct)
 so this gives 00000100 AND 00000011  = 00000000 = 0 (correct, PAL box boot)


example cool.gif
regio = 1 = NTSC = binary   00000001

BIOS checks; 00000001 AND (00000001 - 00000001) = 0?
 so this gives 00000001 AND 00000000 = 0 (correct, NTSC box boot)


example C)
regio = 0 = Multiregion = binary 00000000

BIOS checks; 00000000 AND (00000000 - 00000001) = 0?
 so this gives 00000000 AND 111111111 = 0 (CORRECT!, multi region box boot!)


So as i see it; it doesn't matter what the regioncode is; by using the extraction of 1 and the operator AND i get always 0 (correct), so the xbox must boot. So that's why i believe that above routine is NOT correct!So because of this reason, i can't know any reason WHY the xbox still seems to be non booting, if regiosetting = 0(all regions), EXCEPT:
As I see it, this can only be done with the bios testing;
  If the regiosetting <> 0 then ok -> boot
   ; else refuse and get XBOX to trashcan  huh.gif .



So if my conclusion is CORRECT, it SHOULD be possible to boot ANY xbox, when the regiocode is set to ANY regiocode, EXCEPT 0.
(In this case I believe that regiosetting to 0 (zero) already was checked into the past, but till now, NO-ONE has confirmed this by real facts and also NO-ONE has tried to use other settings!! )

OR operandi means :
 0 XOR 0 = 0
 0 XOR 1 = 1
 1 XOR 0 = 1
 1 XOR 1 = 1

So this gives:
regio 1 NTSC = 00000001  OR  regio 4 PAL 00000100
 gives 00000101  (regio 5!!!!)

regio 1, 4 and 2 together gives
00000001 OR 00000100 OR 00000010  
 gives 00000111 (regio 7!)

regio 1 and 2 together gives
00000001 OR 00000010
 gives 00000011 (regio 3!)
"

CONCLUSION:

In my believe the XBOX must be boot well, if we set the region to 5 (PAL and NTSC), or 3 (NTSC and NTSC-J), or 7 (NTSC, NTSC-J and PAL), the xbox must boot well, and IS then made regionfree!

Also this numbers comply with above regiosettings. precicely 3, 5 and 7 are NOT used by XBOX normally, only 1, 2 or 4.

CAN ANYBODY WITH A MODCHIP CONFIRM THIS CONCLUSION!  beerchug.gif
Title: UDE/5713+
Post by: BluhDeBluh on September 20, 2004, 12:58:00 AM
You're confusing DVD Video regions with Xbox regions. What you've stated are various different DVD regions, which MS doesn't use as part of its copy protection. There are only 3 regions as far as the Xbox is concerned.

Plus, you got a couple of them wrong (R1 = US/Can, R2 = Europe (PAL)/Japan(NTSC), R3 = Asia, R4 = Australia, R5 = Russia, R6 = Other, R0 = Regionfree)
Title: UDE/5713+
Post by: John Hoek on September 20, 2004, 02:04:00 AM
QUOTE (BluhDeBluh @ Sep 20 2004, 09:01 AM)
You're confusing DVD Video regions with Xbox regions. What you've stated are various different DVD regions, which MS doesn't use as part of its copy protection. There are only 3 regions as far as the Xbox is concerned.
Title: UDE/5713+
Post by: John Hoek on September 20, 2004, 10:45:00 PM
QUOTE (rmenhal @ Sep 20 2004, 11:48 AM)
Well, not really. The check passes if and only if at most one bit is set.