XboxHacker BBS
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
June 19, 2013, 10:45:04 PM


Login with username, password and session length


Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 »
  Print  
Author Topic: xb360 jtag exploit - Discussion  (Read 87305 times)
nickcas
Master Hacker
****
Posts: 123


View Profile
« Reply #20 on: August 11, 2009, 04:48:42 PM »

  - Right now, the only way to support both gaming and hacking would be a dual-nand modchip, which switches between nand contents. Note that you still couldn't update to 8498, as it likely (haven't tried) doesn't run without R6T3.

Get a cygnos 360 if anyone needs a dual nand feature

You would need one anyway to run the exploit if you didn't have an infectus right? This isn't software based is it?
Logged
Straßenkampf
Hacker
***
Posts: 81



View Profile
« Reply #21 on: August 11, 2009, 04:53:19 PM »

I think you will have to use a JTAG-Adapter, no Infectus or Cygnos or other NAND Programmer needed?!
Logged
B1N4RY
Xbox Hacker
*****
Posts: 790


View Profile
« Reply #22 on: August 11, 2009, 05:25:04 PM »

According to what tmbinc said, it sounds like that you'll need a jtag adaptor.This isn't timing attack.

EDIT:
Didn't read Straßenkampf 's post...

And no, Infectus will not be needed. This isn't timing attack
« Last Edit: August 11, 2009, 05:48:52 PM by B1N4RY » Logged
tmbinc
Global Moderator
Master Hacker
*****
Posts: 286


View Profile
« Reply #23 on: August 11, 2009, 05:29:08 PM »

you don't need a "jtag adapter". What you need is a way to reprogram the NAND flash. This can be an external programmer, a linux tool (if it already runs), or a yet-to-be-announced project which uses a special southbridge mode (details will be coming soon) with just an LPT port. Or a nand-modchip.
Logged

Please don't copy/quote full text outside this board. Instead, summarize and link to this post. Thanks! This lets me keep information updated and doesn't pull things out of context.
nickcas
Master Hacker
****
Posts: 123


View Profile
« Reply #24 on: August 11, 2009, 05:33:53 PM »

you don't need a "jtag adapter". What you need is a way to reprogram the NAND flash. This can be an external programmer, a linux tool (if it already runs), or a yet-to-be-announced project which uses a special southbridge mode (details will be coming soon) with just an LPT port. Or a nand-modchip.

Thanks. yet-to-be-announced project sounds good  Wink.
Logged
B1N4RY
Xbox Hacker
*****
Posts: 790


View Profile
« Reply #25 on: August 11, 2009, 05:45:30 PM »

Tmbinc your foreshadowings are killing me
Logged
jz_5_3
Master Hacker
****
Posts: 119


View Profile
« Reply #26 on: August 11, 2009, 06:32:17 PM »

"We kept on working on this idea, and it worked out. pretty well. We use JTAG to program the DMA target addr, and then SMC to trigger the DMA read. The exploit itself is based on the old 4532 exploit."

It seems originally we use 4532/4548 HV bug to inject the code. Now if we could use jtag and smc to inject the code, why do we still need to rely on 4532? 

Logged
nickcas
Master Hacker
****
Posts: 123


View Profile
« Reply #27 on: August 11, 2009, 06:43:39 PM »

Tmbinc: I've heard wind that this whole announcement was a leak and is not being released. Is this true? If so, why are you still acting like it is being released? I'm pretty confused right now. Sorry if what I'm hearing is bull$#!t.
Logged
tmbinc
Global Moderator
Master Hacker
*****
Posts: 286


View Profile
« Reply #28 on: August 11, 2009, 06:48:09 PM »

Because *I* do have everything required for the exploit on my harddisk, and *I* still have the intention to release it. I don't know where this "it's a leak" comes from, but I consider it as bull$#!t.

jz_5_3: Because DMA attacks alone don't help on 360, due to memory encryption. All we can do using DMA is to trigger an exploit in privileged code, i.e. the 4532 HV, because that's the only privileged code we know that has a bug.
Logged

Please don't copy/quote full text outside this board. Instead, summarize and link to this post. Thanks! This lets me keep information updated and doesn't pull things out of context.
nickcas
Master Hacker
****
Posts: 123


View Profile
« Reply #29 on: August 11, 2009, 06:52:03 PM »

Because *I* do have everything required for the exploit on my harddisk, and *I* still have the intention to release it. I don't know where this "it's a leak" comes from, but I consider it as bull$#!t.

Quite possibly the greatest news I've heard in a while. You're the man.
Logged
B1N4RY
Xbox Hacker
*****
Posts: 790


View Profile
« Reply #30 on: August 11, 2009, 06:56:48 PM »

Tmbinc, is everything ready to be released, or are you still preparing some final touches?

When you release it, it is going to be a POC initially, or an actual "Hack" ?
« Last Edit: August 11, 2009, 07:01:05 PM by B1N4RY » Logged
XeNoN.7
Newbie
*
Posts: 8


View Profile
« Reply #31 on: August 11, 2009, 07:00:34 PM »

Deleted.
« Last Edit: August 11, 2009, 11:30:33 PM by XeNoN.7 » Logged
B1N4RY
Xbox Hacker
*****
Posts: 790


View Profile
« Reply #32 on: August 11, 2009, 07:16:47 PM »

Xenon, can you provide a reliable source to what you have just said?
Logged
gamerfreak1727
Member
**
Posts: 17


View Profile
« Reply #33 on: August 11, 2009, 07:23:54 PM »

nice job tmbinc and team.
« Last Edit: August 11, 2009, 11:30:45 PM by gamerfreak1727 » Logged
tmbinc
Global Moderator
Master Hacker
*****
Posts: 286


View Profile
« Reply #34 on: August 11, 2009, 07:33:13 PM »

wtf, drama Wink
Logged

Please don't copy/quote full text outside this board. Instead, summarize and link to this post. Thanks! This lets me keep information updated and doesn't pull things out of context.
Redline99
Global Moderator
Xbox Hacker
*****
Posts: 774


View Profile
« Reply #35 on: August 11, 2009, 07:39:50 PM »

It doesn't matter now anyways, people looking to at this news with any continued seriousness need to know not up update. Whatever the drama, its too late and time to move on.

No more bashing will be tolerated above what has already been mentioned.
Logged

Where's Waldo
jester
Master Hacker
****
Posts: 192


View Profile
« Reply #36 on: August 11, 2009, 08:23:27 PM »

It doesn't matter now anyways, people looking to at this news with any continued seriousness need to know not up update. Whatever the drama, its too late and time to move on.

No more bashing will be tolerated above what has already been mentioned.
Good choice and I agree. Whether its released or not, the fact that a person/persons has accomplished this, is still good news.
Logged
B1N4RY
Xbox Hacker
*****
Posts: 790


View Profile
« Reply #37 on: August 11, 2009, 08:29:21 PM »

wtf, drama Wink

damnit tmbinc, don't tell me that this thread is just a joke
« Last Edit: August 11, 2009, 08:33:05 PM by B1N4RY » Logged
ddxcb
Xbox Hacker
*****
Posts: 614


meh, who buys or own ""JTAGS""


View Profile
« Reply #38 on: August 11, 2009, 08:32:13 PM »

Just releace it Ms patch with the 8498 update or aka Summer 09 update and go on I want linux so bad Smiley
Logged

I'm a ADD modder, got to mod or be bored xD
G0t m4xx 21
Master Hacker
****
Posts: 187

t('.'t)


View Profile
« Reply #39 on: August 11, 2009, 09:30:17 PM »

Wow.

Not sure what I'd use this hack for (besides resurrecting 360's that have lost their dvd key), but it's still amazing that it was finally cracked.

Besides that, linux on the 360 is cool, a novelty for us techies, but not very practical, I can do the same thing on my laptop/pc without all the hackery

a supercomputing cluster made out of 360's would be awesome though (until one RRoD's  Shocked )
Logged

"Absolute freedom can exist only in a state of anarchy"
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM