|
Tiros
|
 |
« Reply #100 on: June 10, 2010, 10:23:11 AM » |
|
or can't one use it without challenge response from M$ servers?
BINGO! Manufacturing mode is nothing new. Thats what the red/green up/dn blinkers means. mfgbootlauncher.xex is on flash, and and can be made to execute a number of different ways. Hook up a serial port and you should see the messages about contacting the server etc. Naturally if your about to get a new KV, youd need to be in contact with the mothership. imho the whole thing is a dead end.
|
|
|
|
|
Logged
|
|
|
|
|
q36
|
 |
« Reply #101 on: June 10, 2010, 11:22:11 AM » |
|
"It does parse values for av/game/dvd region so ms must have left out the code that actually does something with them. Probally for this exact reason."
TheFallen, no, there is no mysterious missing code. As I said before, this is the same structure as xbox.xex/xefu.xex etc. Those are generic checks in the start sequence. Nothing is being set or ever intended to be set there. Those are just xconfig settings, we can change those by hand by editing the config blocks in the nand, they don't really have that much control over anything important, and if I remember correctly, ExConsoleGameRegion is grabbed from xconfig at kernel init. This is not doing anything interesting at all. There are much better known routes to explore for new exploits.
|
|
|
|
|
Logged
|
|
|
|
thealtaf
Newbie

Posts: 4
|
 |
« Reply #102 on: June 10, 2010, 11:46:29 AM » |
|
is it possible to recover lost dvdkeys  ? what if internet cable is connected and what is the risk if connected to some kind of server
|
|
|
|
|
Logged
|
|
|
|
|
ddxcb
|
 |
« Reply #103 on: June 10, 2010, 12:29:00 PM » |
|
is it possible to recover lost dvdkeys  ? what if internet cable is connected and what is the risk if connected to some kind of server its probly trying to connect to a local server or a secure one, and Tiros what terminal do you use for the xbox 360?
|
|
|
|
|
Logged
|
I'm a ADD modder, got to mod or be bored xD
|
|
|
|
q36
|
 |
« Reply #104 on: June 10, 2010, 12:48:23 PM » |
|
no, this is not going to recover lost dvd keys or do anything with the dvd drive at all.
|
|
|
|
|
Logged
|
|
|
|
|
TheFallen93
|
 |
« Reply #105 on: June 10, 2010, 02:20:05 PM » |
|
"It does parse values for av/game/dvd region so ms must have left out the code that actually does something with them. Probally for this exact reason."
TheFallen, no, there is no mysterious missing code. As I said before, this is the same structure as xbox.xex/xefu.xex etc. Those are generic checks in the start sequence. Nothing is being set or ever intended to be set there. Those are just xconfig settings, we can change those by hand by editing the config blocks in the nand, they don't really have that much control over anything important, and if I remember correctly, ExConsoleGameRegion is grabbed from xconfig at kernel init. This is not doing anything interesting at all. There are much better known routes to explore for new exploits.
It reads values for av/game/dvd region, I looked at the code. It reads them from the ini. Go look around 0x92058C1C. They are not being grabbed from xconfig, they are read from the ini.
|
|
|
|
|
Logged
|
|
|
|
|
dtrmad2004
|
 |
« Reply #106 on: June 10, 2010, 02:21:21 PM » |
|
How do you put this on a MU, noob question I know but I like messing with stuff
|
|
|
|
|
Logged
|
|
|
|
|
stoker25
|
 |
« Reply #107 on: June 10, 2010, 03:27:30 PM » |
|
I've gone through the dump and extracted the contents of both partitions inside, along with the extended partition, because not all people can understand dumps ;P You can simply throw the files in the Data partition folder onto any other MU's Data partition, and it will boot. Download: http://stoker25.com/xbox/ManufacturingMU.7z
|
|
|
|
|
Logged
|
|
|
|
|
ReverseAffect
|
 |
« Reply #108 on: June 10, 2010, 03:40:33 PM » |
|
going through all the info on this mu is ok but worthless...lol
|
|
|
|
|
Logged
|
sick like a mofo..not reballing for a while...
|
|
|
|
xbox360noob
|
 |
« Reply #109 on: June 10, 2010, 06:01:48 PM » |
|
going through all the info on this mu is ok but worthless...lol
why that?
|
|
|
|
|
Logged
|
|
|
|
|
ReverseAffect
|
 |
« Reply #110 on: June 10, 2010, 06:06:41 PM » |
|
well because ...as the bigger guys said challenge response is the main goal! i did see some generic emulator info in it though... might be something for someone though. just not my thing.... I don't play with live at all ..only on a legit level... not to mention if the challenge response is found, it's holy war time with Live and this BS in a bad way anyways just some random pic's of the utill screens with and without a game in the dvd drive for odd...         
|
|
|
|
« Last Edit: June 10, 2010, 07:14:46 PM by ReverseAffect »
|
Logged
|
sick like a mofo..not reballing for a while...
|
|
|
Zellcorp
Newbie

Posts: 5
|
 |
« Reply #111 on: June 11, 2010, 03:47:01 AM » |
|
Ahhh test discs arent they cool!!! pity they are useless without the server software lol I still have my Ping 17 Test disc that was left inside a repaired unit years ago, anyone remember this?  It would play 1 level of PGR over and over with cars racing really fast but then it would try and send some info about performance to a network server and then hang. Without the server side software to make these utilities work they are useless. I was thinking it would be good if someone with better network coding skills could somehow code a server side app for these utilities.
|
|
|
|
« Last Edit: June 11, 2010, 04:29:28 AM by Zellcorp »
|
Logged
|
|
|
|
Dabman
Newbie

Posts: 9
|
 |
« Reply #112 on: June 11, 2010, 04:23:10 AM » |
|
Someone try replace default.xex for other ( signed ) one?
|
|
|
|
|
Logged
|
|
|
|
|
TheFallen93
|
 |
« Reply #113 on: June 12, 2010, 06:27:01 PM » |
|
Lawl at maxconsole: An interesting thread at XBH gives hope that an Xbox 360 memory unit can be used to trigger manufacturing modes on an UNMODIFIED Xbox 360 console. Apparently dumps of the specific MU have already been posted and the race for possible exploits has started.
|
|
|
|
|
Logged
|
|
|
|
|
ReverseAffect
|
 |
« Reply #114 on: June 12, 2010, 06:51:28 PM » |
|
lmfao...wow as the world turns... I think as of now the only sort of default we should be working on is for dumping the nand... but for why..if it isn't a exploitable unit...unless we can re-hash and re-sign it..it's worthless but the work load continues ...
|
|
|
|
« Last Edit: June 12, 2010, 06:54:26 PM by ReverseAffect »
|
Logged
|
sick like a mofo..not reballing for a while...
|
|
|
|
sonic-iso
|
 |
« Reply #115 on: June 13, 2010, 01:33:41 AM » |
|
unless these xexs can revive blown efuses, it is as tiros said a "deadend".
|
|
|
|
|
Logged
|
|
|
|
|
l_oliveira
|
 |
« Reply #116 on: June 13, 2010, 09:29:24 AM » |
|
I remember reading on some IBM datasheet that they're capable of making flash based EFUSES which could be reverted to the original state if needed.
If this is the case, these flash based "EFUSES" would be reversible through the JTAG port. But then again access to the XENON CPU JTAG port requires authentication, making the EFUSES effectively one-way for everyone but Microsoft. Still I think it's wrong to automatically assume that the EFUSES on the XENON CPU are of the PROM (real blowing) type.
|
|
|
|
|
Logged
|
 It's a Rough World
|
|
|
|
ReverseAffect
|
 |
« Reply #117 on: June 13, 2010, 09:44:46 AM » |
|
why would you think different? as far as i am concerned working IBM cpus in the past...since 1984 they been securing it like this... and it was because of a low maintance core issue if one went back it would blow the efuse for that, core and resort to a unused one and set up a diagnose state... Similar EXAMPLE: glass fuse gets blown... 2 options. 1)replace it...easy to do... 2)open the end and replace the wire element with a re-solder...(kinda useless but only a example)..
why would m$ make a switchable on/off(programed/deprogrammed Efuse? I mean they do make them but why for the X360.. or it could be like you stated but a special port hookup so when set to manufacturing mode they can see whats going on, and resort back to a past fuse state for troubleshooting a dash or creating a patch when a update goes wrong..
but being just my opinion it's just that...
|
|
|
|
|
Logged
|
sick like a mofo..not reballing for a while...
|
|
|
|
damox
|
 |
« Reply #118 on: June 13, 2010, 08:47:50 PM » |
|
why would m$ make a switchable on/off(programed/deprogrammed Efuse? I mean they do make them but why for the X360..
First thing that came to mind: when they run out of fuse bits to blow.
|
|
|
|
|
Logged
|
|
|
|
|
TheFallen93
|
 |
« Reply #119 on: June 13, 2010, 08:59:24 PM » |
|
There are 768 efuses in total, with a possible 512 for updates. Doubt we will run out any time soon.
|
|
|
|
« Last Edit: June 13, 2010, 09:06:06 PM by TheFallen93 »
|
Logged
|
|
|
|
|