|
jelle2503
|
 |
« Reply #20 on: August 15, 2010, 11:07:37 AM » |
|
get rich quick scheme take 3 get ready geremia 
|
|
|
|
|
Logged
|
*
|
|
|
|
Oggy
|
 |
« Reply #21 on: August 15, 2010, 11:44:19 AM » |
|
get rich quick scheme take 3 get ready geremia  HAHAHAHAHAHAHAHAHA ! the irony....
You're at the very top of that "$#!t post list".........
|
|
|
|
« Last Edit: August 15, 2010, 11:46:50 AM by Oggy »
|
Logged
|
|
|
|
|
jelle2503
|
 |
« Reply #22 on: August 15, 2010, 12:01:59 PM » |
|
thanks for that ego boost, I knew you'd reply to me
|
|
|
|
|
Logged
|
*
|
|
|
|
Geremia
|
 |
« Reply #23 on: August 15, 2010, 12:29:15 PM » |
|
Does anyone knows a cheap decapping service in europe?
If only they still used the MT1319L, eh?  What's exactly the problem you have with me? About the video, at least it proves the dvdkey displacement was found inside the dump, obtained by decapping. I will not be surprised if a spoofed DG-16D2S is running inside that slim, anyway i don't care too much.
|
|
|
|
|
Logged
|
|
|
|
|
Oggy
|
 |
« Reply #24 on: August 15, 2010, 12:43:23 PM » |
|
I do not have a problem with you, you just assume I do. If I had a problem, I wouldnt have shared my dumps for blank 3c000 data, with you, would I.
I just find it ironic you need it decapped and you were the author of the thread that led to MRA .....
|
|
|
|
|
Logged
|
|
|
|
|
sweet_hemp
|
 |
« Reply #25 on: August 15, 2010, 01:15:32 PM » |
|
that video doesn't prove anything! ok it's C4E, but until a reproducible method to dump the dvdkey is found and released, fake or not this video is just a hype generator. hopefully they'll share some more details about dumping this drive.
best regards
|
|
|
|
|
Logged
|
|
|
|
|
q36
|
 |
« Reply #26 on: August 15, 2010, 03:06:01 PM » |
|
The issue comes down to the new authentication, which is not really implemented yet.
|
|
|
|
|
Logged
|
|
|
|
|
|
|
misterfly
|
 |
« Reply #28 on: August 15, 2010, 04:09:44 PM » |
|
strange this i think is little different 
|
|
|
|
|
Logged
|
|
|
|
|
Usuario-X
|
 |
« Reply #29 on: August 15, 2010, 05:04:21 PM » |
|
Here We go!
|
|
|
|
|
Logged
|
|
|
|
|
oc
|
 |
« Reply #30 on: August 15, 2010, 09:50:49 PM » |
|
feel like MRA method will work.
|
|
|
|
|
Logged
|
|
|
|
|
asapreta
|
 |
« Reply #31 on: August 16, 2010, 09:20:15 AM » |
|
We only can wait and especulate.
Bets on a device permanently attached to drive/console.
|
|
|
|
|
Logged
|
|
|
|
|
BoNg420
|
 |
« Reply #32 on: August 16, 2010, 10:27:55 AM » |
|
We only can wait and especulate.
Bets on a device permanently attached to drive/console.
It will probably be something along the lines of the MRA method with the 93450c. I don't imagine them producing a chip for it, but something like they did for the 93450 and other liteons that LT Clip piece of $#!t thing that more noobs f*** up then the Boxxdr method. I can't believe that so many people mess up a solution that is supposed to be noob friendly, but they are always ripping pads and traces or bad cuts. I don't know whats so hard about cutting a few traces and exposing some traces/pads. If you never have picked up a solder iron before, then you should stay clear of one. Guess I can't detour everyone from soldering, as I am self taught thanks to xbox1 modchips, but some people should not touch electronics or they should practice on broken stuff first. I've successfully recovered about 4-5 drives now from ripped up pads/traces. There was one I could not get though, every pad for the LT clip was ripped up, the traces were overcut to the trace below for one of the cuts. Dunno what the hell was up with that one, just had no luck.
|
|
|
|
|
Logged
|
|
|
|
|
Pacote-san
|
 |
« Reply #33 on: August 17, 2010, 04:50:46 AM » |
|
We only can wait and especulate.
Bets on a device permanently attached to drive/console.
It will probably be something along the lines of the MRA method with the 93450c. I don't imagine them producing a chip for it, but something like they did for the 93450 and other liteons that LT Clip piece of $#!t thing that more noobs f*** up then the Boxxdr method. I can't believe that so many people mess up a solution that is supposed to be noob friendly, but they are always ripping pads and traces or bad cuts. I don't know whats so hard about cutting a few traces and exposing some traces/pads. If you never have picked up a solder iron before, then you should stay clear of one. Guess I can't detour everyone from soldering, as I am self taught thanks to xbox1 modchips, but some people should not touch electronics or they should practice on broken stuff first. I've successfully recovered about 4-5 drives now from ripped up pads/traces. There was one I could not get though, every pad for the LT clip was ripped up, the traces were overcut to the trace below for one of the cuts. Dunno what the hell was up with that one, just had no luck. OggyUK already stated on X-S that the way they did is out of reach for 99,9% of the modders so my guess is that they used professional industrial skills to get the dump, but now are researching a way to make easier (and profitable to them) to the end user and modders... My guess is some kind of modchip too....
|
|
|
|
|
Logged
|
|
|
|
|
mat989
|
 |
« Reply #34 on: August 17, 2010, 11:30:37 AM » |
|
OggyUK already stated on X-S that the way they did is out of reach for 99,9% of the modders so my guess is that they used professional industrial skills to get the dump, but now are researching a way to make easier (and profitable to them) to the end user and modders... My guess is some kind of modchip too....
When Geremia made a thread asking for beta LT to test, OggyUK was making fun of him in #fw, days later Geremia decrypted the LT....So dont worry much about what OggyUK says...
|
|
|
|
|
Logged
|
|
|
|
|
Oggy
|
 |
« Reply #35 on: August 17, 2010, 03:02:30 PM » |
|
Just take solace in knowing I know how it was done, so I can comment on the difficulty level.
|
|
|
|
|
Logged
|
|
|
|
|
Geremia
|
 |
« Reply #36 on: August 17, 2010, 06:44:15 PM » |
|
..but, from what misterfly told to be doing, can be easily guessed
-find 3-4 drops of fuming nitric acid, > 90%, difficulty= depends on money and black market -apply on top of the IC, difficulty=depends on how much you take care of your life, better to find a chemical laboratory that does it for you - disconnect the bonding wires and connect to an external programmer, difficulty=hight, you need a very steady hand, a microscope, some conductive silver/gold paste -dump the spi flash -take a pc dvdrom with MT1339, see if it uses the same scrambling algo, if yes, no more need of the mt1335 -if different scrambling algo, you have to reuse the mt1335, reconnect wires, resolder the IC on the pcb, very difficult -if the drive is still alive, rewrite dvdkey (with the kown MS-standard atapi cmd) with your own dvdkey, something like 010203040506....., redump flash back. on old liteon ,the dvdkeyarea was not scrambled and probably is still not for security measure (fw has to be able to reflash it without exposing the mediatek scrambling algo), it was semirandom data created by the fw during dvdkey reflashing, based on (if i remember well) the only first dvdkey byte, so, hope it's the same, and change 1 bit in the first dvdkey byte and rewrite it, dump back, compare with other dump. If things are changed, needs more flash and redump, difficulty=hight if you have to use the MT1335, low if you can use the MT1339
if you have the fw descrambled, there is no need to tell misterfly to get mad to find dvdkey displacement, it's all explained inside fw. So, my best guess is that the slim drive is not hacked at all, you found the dvdkey of that damn drive and inserted into a spoofed old liteon, but there is still the need of:
-find the fw scrambling algo -find a way to easily dump at least dvdkey -find a way to easily erase the spi -find a way to easily write the spi
Hat off to the steady hand, the slim console booted a backup, but the slim liteon is not hacked yet.
|
|
|
|
|
Logged
|
|
|
|
|
Rogero
|
 |
« Reply #37 on: August 17, 2010, 08:04:36 PM » |
|
Thanks Geremia for the most logical explanation  exactly what I thought when I first saw the video keep it up man and good luck with your new research.
|
|
|
|
|
Logged
|
|
|
|
|
mat989
|
 |
« Reply #38 on: August 17, 2010, 09:35:54 PM » |
|
..but, from what misterfly told to be doing, can be easily guessed
-find 3-4 drops of fuming nitric acid, > 90%, difficulty= depends on money and black market -apply on top of the IC, difficulty=depends on how much you take care of your life, better to find a chemical laboratory that does it for you - disconnect the bonding wires and connect to an external programmer, difficulty=hight, you need a very steady hand, a microscope, some conductive silver/gold paste -dump the spi flash -take a pc dvdrom with MT1339, see if it uses the same scrambling algo, if yes, no more need of the mt1335 -if different scrambling algo, you have to reuse the mt1335, reconnect wires, resolder the IC on the pcb, very difficult -if the drive is still alive, rewrite dvdkey (with the kown MS-standard atapi cmd) with your own dvdkey, something like 010203040506....., redump flash back. on old liteon ,the dvdkeyarea was not scrambled and probably is still not for security measure (fw has to be able to reflash it without exposing the mediatek scrambling algo), it was semirandom data created by the fw during dvdkey reflashing, based on (if i remember well) the only first dvdkey byte, so, hope it's the same, and change 1 bit in the first dvdkey byte and rewrite it, dump back, compare with other dump. If things are changed, needs more flash and redump, difficulty=hight if you have to use the MT1335, low if you can use the MT1339
if you have the fw descrambled, there is no need to tell misterfly to get mad to find dvdkey displacement, it's all explained inside fw. So, my best guess is that the slim drive is not hacked at all, you found the dvdkey of that damn drive and inserted into a spoofed old liteon, but there is still the need of:
-find the fw scrambling algo -find a way to easily dump at least dvdkey -find a way to easily erase the spi -find a way to easily write the spi
Hat off to the steady hand, the slim console booted a backup, but the slim liteon is not hacked yet.
If you needed paypal donations that will help you in your research -paying for hardware/services-...make sure to PM pls.... thnx,
|
|
|
|
|
Logged
|
|
|
|
|
misterfly
|
 |
« Reply #39 on: August 17, 2010, 10:48:04 PM » |
|
..but, from what misterfly told to be doing, can be easily guessed -find 3-4 drops of fuming nitric acid, > 90%, difficulty= depends on money and black market -apply on top of the IC, difficulty=depends on how much you take care of your life, better to find a chemical laboratory that does it for you - disconnect the bonding wires and connect to an external programmer, difficulty=hight, you need a very steady hand, a microscope, some conductive silver/gold paste -dump the spi flash -take a pc dvdrom with MT1339, see if it uses the same scrambling algo, if yes, no more need of the mt1335 -if different scrambling algo, you have to reuse the mt1335, reconnect wires, resolder the IC on the pcb, very difficult -if the drive is still alive, rewrite dvdkey (with the kown MS-standard atapi cmd) with your own dvdkey, something like 010203040506....., redump flash back. on old liteon ,the dvdkeyarea was not scrambled and probably is still not for security measure (fw has to be able to reflash it without exposing the mediatek scrambling algo), it was semirandom data created by the fw during dvdkey reflashing, based on (if i remember well) the only first dvdkey byte, so, hope it's the same, and change 1 bit in the first dvdkey byte and rewrite it, dump back, compare with other dump. If things are changed, needs more flash and redump, difficulty=hight if you have to use the MT1335, low if you can use the MT1339  if you have the fw descrambled, there is no need to tell misterfly to get mad to find dvdkey displacement, it's all explained inside fw. So, my best guess is that the slim drive is not hacked at all, you found the dvdkey of that damn drive and inserted into a spoofed old liteon, but there is still the need of: -find the fw scrambling algo -find a way to easily dump at least dvdkey -find a way to easily erase the spi -find a way to easily write the spi Hat off to the steady hand, the slim console booted a backup, but the slim liteon is not hacked yet. lol but, and perhaps have a dream? stop dreaming
|
|
|
|
|
Logged
|
|
|
|
|