XboxHacker BBS
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
September 09, 2010, 03:15:45 AM


Login with username, password and session length


Pages: « 1 2 3 4 5 »
  Print  
Author Topic: Project started: rebooting into an(y) unsigned kernel + hypervisor  (Read 49264 times)
klipseracer
Master Hacker
****
Posts: 377


View Profile
« Reply #60 on: January 04, 2008, 02:10:39 AM »

OOooook.. Lets do a 180* turn here and get back on topic.

I'm sure that just 'booting' an unsigned XBE isn't so simple, but with the release of the new firmware that allows running xb1 games, maybe someone should look into this new part of the firmware a little and see how the files are laid out and what calls are loading them into memory. I'm sure they've added addition security in this area as well... Has anyone else thought to explore this new feature in this way? I do realize no matter how we TRY to load an xbe, there is still the underlying security preventing and unsigned xbe from running, but its a different approach to consider, and i'm sure it would be easier to hitch hike off of the xbox's own design.

As far as 'Fully Rebooting' into a modified Dash/HV I suppose we need to find this 'moving needle' that arnezami speaks of. Until then we're really at a standstill with all the XBE/XBMC crap. These ideas are comming from someone thats picturing the 'end user' end result. Which really isn't contributing toward the goal here.

« Last Edit: January 04, 2008, 02:21:32 AM by klipseracer » Logged
safety
Master Hacker
****
Posts: 296


View Profile
« Reply #61 on: January 19, 2008, 07:20:21 PM »

well, not the best place to post, but here it goes...
Whats the mechanism in the xbox emulator to determen wich disc is compatible and wich is not?

Ya i know its a shoot on the moon with a water pistol, but isn't there some solution to disquise  (or what I'm not english) so it boots up? (some code).

Those xbox1 games use the GPU too.
is there any chanse that an xbox1 version game can be patched and booted up by the emulator?

--nothing fancy, just would like to know if is it has any possibilities or not--
Logged
Arakon
Administrator
Xbox Hacker
*****
Posts: 6472


View Profile
« Reply #62 on: January 19, 2008, 07:32:55 PM »

There's two theories: one is that the emulator actually contains a list of disk IDs, the other that it checks what libraries and functions are used by the game, and runs only if all are supported.
the problem with patching would be that the game would very likely crash, because MS usually does check if the games work or not, and if not, they don't get added to the list.
Logged

I do NOT give support by email, PM, ICQ or whatever. Anyone annoying me that way will have his balls removed. With a rusty butterknife. Slowly. And I'll enjoy doing it.
loser
Member
**
Posts: 43


View Profile WWW
« Reply #63 on: February 05, 2008, 10:54:08 AM »

* the xbox emulator consists of a frontend and a backend.
* the backend is the actual emulator which does all the work (there are multiple of these).
* the frontend just decides if it should let the game play, and which backend to use.

* each xbox game has a unique titleid (embedded in the xbe).
* the emu frontend (xbox.xex) contains a list of titleids for supported games, if the game isn't in this list, it won't try to play it.
* this list matches the titleid to the emulator version, as well as containing info such as whether to use xbox live and whether to apply patches to the xex.

* each emu backend (xefu.xex) is self contained and has a small xbox1 kernel inside it. this kernel does the signature, hash, region, media checks, and doesnt play a game if they dont pass these check.

** so to summarise, the frontend decides whether to try to play the game or not, the backend enforces all restrictions. removing the frontend checks does indeed allow quite a few other games to play fine or almost fine, and removing the backend checks allows u to play any region game on any media such as your hdd.
Logged
safety
Master Hacker
****
Posts: 296


View Profile
« Reply #64 on: February 16, 2008, 09:21:01 AM »

//** so to summarise, the frontend decides whether to try to play the game or not, the backend enforces all restrictions. removing the frontend checks does indeed allow quite a few other games to play fine or almost fine, and removing the backend checks allows u to play any region game on any media such as your hdd.///

Thats more than intresting. So a well forged xbox1 xbe can be launched from any media.

Hmm..  emulator can acces the memory with the help of the gpu?

Allso i know that xbox1 games can call other xbe s, if an xbe passes the cheqs, and loads an other xbe, are the cheqs applyd again?
Logged
loser
Member
**
Posts: 43


View Profile WWW
« Reply #65 on: February 20, 2008, 09:29:01 AM »

a well "forged" xbe cannot be made as such since every xbe has to be signed with the xbox1 private key which no one has. as for loading of other xbe files, everytime an xbe is loaded in-game the backend performs checks upon them.
Logged
MastaG
Master Hacker
****
Posts: 255


Badr Hari FTW!


View Profile
« Reply #66 on: March 16, 2008, 06:16:40 PM »

wasnt the private key for signing xbe (xbox1) files cracked a while ago?
Logged

Anabolic steroids will make you feel real good about yourself:)
Sustanon 0wnz
Arakon
Administrator
Xbox Hacker
*****
Posts: 6472


View Profile
« Reply #67 on: March 17, 2008, 12:44:26 AM »

no, never. it's a 1024 bit encryption, it won't be cracked in a long, long time.
Logged

I do NOT give support by email, PM, ICQ or whatever. Anyone annoying me that way will have his balls removed. With a rusty butterknife. Slowly. And I'll enjoy doing it.
safety
Master Hacker
****
Posts: 296


View Profile
« Reply #68 on: May 10, 2008, 11:47:57 PM »

thats pretty bad..
I'm searching for bits of info, and PREY that You are wrong.
But probably You are not...

Anyways, 1024 vs 2048 is a pretty nice catch, LOL Smiley
trying to chear my self up a bit..

some sorth of information about this emulator would allso be nice.
Searching for it, but can not guarantee I'm going to find anything usefull..
probably a waist of time.. like most of my "bright" ideas.- expect the posts I made about overheating when the FIRST red light issues have seen daylight.. and the solution with PROPER heatsink, LOL..
2 out of a thousand.. much better than 1024..)
Logged
dieselboy
Hacker
***
Posts: 56


View Profile
« Reply #69 on: February 23, 2009, 04:08:56 AM »

keep up the good work all of you! this is fascinating stuff.
thanks!
Logged
.ISO
Xbox Hacker
*****
Posts: 734


View Profile
« Reply #70 on: March 01, 2009, 06:06:11 PM »

keep up the good work all of you! this is fascinating stuff.
thanks!
oi, check the date
Logged

you wish gigaturd, as if you even know how to tell the difference between a disassembler and your vagina
Gigabite: A fool who think he is always right, and talk about how useless others are when he is really addressing to himself.
Gigabite agreeing with the statement:
p.s nice comment in your sig
nickcas
Hacker
***
Posts: 73


View Profile
« Reply #71 on: July 12, 2009, 12:53:06 AM »

Shouldn't this be unstuck? It's obvious that this project was completed and is not going to be released, so what's the point of having it here still? Absolutely no disrespect to anyone involved in this project, but it seems as though most of these types of topics start out pouring with information, and then abruptly end?

I really don't understand why something like this couldn't be released now, considering the 4532 kernel is over two years old, and exploitable boxes are becoming a rarity. Not to mention that the only real form of a hack to date is modified dvd drive firmware, and that allows for ONLY piracy.

Just my two cents on the situation. Again, no disrespect to anyone involved in these projects. Your work is greatly appreciated.
Logged
masterluke
Member
**
Posts: 19


View Profile
« Reply #72 on: August 12, 2009, 03:56:08 AM »

<snip> It's obvious that this project was completed and is not going to be released<snip>

oh yes, the fact that no-one is posting on the thread is definitely conclusive proof that a complex technical hack was completed and then hidden in some kind of anti-linux pro-piracy conspiracy.

..that is definitely the most likely explanation..
Logged
SUDDEN73
Newbie
*
Posts: 4


View Profile
« Reply #73 on: August 14, 2009, 04:15:35 PM »

Team, who do you listen?  There is a lot of people, as well as opinions.
Disrespect from the side of one - does not yet mean not respecting from the side of others.
About your work the few knows yet, but nevertheless you already on the nosedive of popularity. Costs only information to spread, as all hear about your legendary work.

Ignore idiots! aspire to the primary purpose! enough already dramatize!! You are the best!

Biggest respect from Russia!!

p.s: sorry for my bad english)
« Last Edit: August 14, 2009, 04:30:54 PM by SUDDEN73 » Logged
nickcas
Hacker
***
Posts: 73


View Profile
« Reply #74 on: August 14, 2009, 04:58:51 PM »

Both of you should look at the date that I posted that, which was before this new hack was announced.

@masterluke: tmbinc himself said that one or more rebooter projects were completed, so get your facts straight.

@SUDDEN73: I don't know if your response was to me, I can't really understand what you said, but I was not disrespecting anybody in my post, just asking a question.
Logged
judokan
Newbie
*
Posts: 3


View Profile
« Reply #75 on: August 30, 2009, 04:33:24 PM »

Hi I have a xbox360 with kernel 4532 and created the reboot with the following files "reboot-readcd.bin CB.1903.bin CD.1888.bin xboxkrnl.4532.exe xboxkrnl.4532.edit.exe @ reboot_and_patch" and the xbox360 is hanging on "* Re-booting ...". Can anyone help me?
Logged
arnezami
Master Hacker
****
Posts: 214


View Profile
« Reply #76 on: August 30, 2009, 11:38:27 PM »

Hi I have a xbox360 with kernel 4532 and created the reboot with the following files "reboot-readcd.bin CB.1903.bin CD.1888.bin xboxkrnl.4532.exe xboxkrnl.4532.edit.exe @ reboot_and_patch" and the xbox360 is hanging on "* Re-booting ...". Can anyone help me?
You can help by debugging the problem  Wink. Do you have a RS23 cable attached? Are you measuring the POST output? With an LA maybe? Do you have RE-ing skills? Do you have ways to use the jtag exploit with an external flasher?

Or do you want it to work (right now) and want a quick answer by double posting?  Tongue

Regards,

arnezami

PS. I'm currently playing around with the rebooter again (using the jtag exploit as new base) and I'm making some progress...
« Last Edit: August 31, 2009, 12:52:36 AM by arnezami » Logged
MastaG
Master Hacker
****
Posts: 255


Badr Hari FTW!


View Profile
« Reply #77 on: August 31, 2009, 01:50:31 AM »

keep it up bro:D
We now have linux, libxenon, a snes emulator using libxenon and soon a rebooter thanks to you!:)
Logged

Anabolic steroids will make you feel real good about yourself:)
Sustanon 0wnz
arnezami
Master Hacker
****
Posts: 214


View Profile
« Reply #78 on: August 31, 2009, 02:24:02 AM »

keep it up bro:D
We now have linux, libxenon, a snes emulator using libxenon and soon a rebooter thanks to you!:)
Soon (tm)  Wink
Logged
judokan
Newbie
*
Posts: 3


View Profile
« Reply #79 on: August 31, 2009, 06:16:42 AM »


You can help by debugging the problem  Wink. Do you have a RS23 cable attached? Are you measuring the POST output? With an LA maybe? Do you have RE-ing skills? Do you have ways to use the jtag exploit with an external flasher?

Or do you want it to work (right now) and want a quick answer by double posting?  Tongue

Regards,

arnezami

PS. I'm currently playing around with the rebooter again (using the jtag exploit as new base) and I'm making some progress...
[/quote]


And finally the juicy stuff. Go here to try out (and help testing/developing) the rebooter itself:

http://www.xboxhacker.net/index.php?topic=8737.0

Ok. That was it. I'm totally and utterly exhausted now Wink. Going to get some sleep and/or vacation.

Regards,

arnezami

PS. Just to be clear: you can ask questions or post ideas or whathever you want in this thread. Smiley
Thank you for answering, I have welding skill, lpt jtag for testing it and infectus, I need the rs232 diagrams, the xploit works very well in my xenon, I only want to test. Sorry for my english
« Last Edit: August 31, 2009, 06:19:41 AM by judokan » Logged
Pages: « 1 2 3 4 5 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM