XboxHacker BBS
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 25, 2013, 05:43:27 AM


Login with username, password and session length


Pages: 1
  Print  
Author Topic: Searching xbox360 vulnerabilities  (Read 1769 times)
bluemimmos
Hacker
***
Posts: 70

Its me, me, me and only me...... :D


View Profile
« on: July 27, 2010, 11:57:17 PM »

well the hypervisor exploit is fixed or its still there on latest kernel, i dont know.

But if its still there and only the way to call it is blocked by blowing efuses then we could search for vectors to call it....

as we have seen many vectors used in many consoles like tiff exploits in psp, iphone, web browser vuln in iphone etc..
and we have also seen savegames buffer overflow etc,, doesnt that apply to xbox360??

Please make me clear on this,

and opne question more , how do i extract the hypervisor off my nand image using my cpukey so i can feed it into ida64 and disassmble and reverse it.....

i can understand ppc64 assembly codes...
 Smiley
Logged
inspuration
Master Hacker
****
Posts: 184


View Profile
« Reply #1 on: July 28, 2010, 12:33:11 AM »

You can't use that old hypervisor exploit on a new system regardless of whether you can find a new attack vector .  Dig through the hypervisor and find a new exploit.
Logged
Blackaddr
Xbox Hacker
*****
Posts: 677


View Profile
« Reply #2 on: July 28, 2010, 08:23:47 AM »

Only two kernel versions had the HV bug that allows the KK exploit to work.  It was the first and only exploit ever found to bypass the HV security and run unsigned code.  It is worth noting that the console was originally secure and MS *introduced* a new bug.  MS promptly fixed the HV bug and uses CB revocation to prevent downgrading.  

The 2007 timing attack method was a way to downgrade back to the exploitable HV, MS promptly fixed it.

The 2009 JTAG hack was yet another method to effectively downgrade and run the exploitable HV, MS promptly fixed it.

We need to find yet another way to run the old, exploitable HV again, or we need to find a new vulnerability in the HV.

The problem with searching for new vulnerabilities is the new, creative, enthusiastic people are optimistic because they don't actually know very much about the system.

The true experts who spent years dissecting the system are pessimistic because they DO know the system that well.  I suspect very few if any of the original people are actively working on it.

btw, I'm in the former group.  I'm still motivated because I'm still too ignorant of the system, but I enjoy the learning nonetheless.

« Last Edit: July 28, 2010, 08:52:57 AM by Blackaddr » Logged

360 Info Collection -> http://www.xboxhacker.org/index.php?topic=12940.0

Do not take anything I say as gospel, use your own judgement, make your own decisions.

Please pay attention to which sub-forums are for Research and Technical discussion. The following are NOT for help with and troubleshooting existing hacks.
- Hardware (Technical)
- DVD-ROM Drive and Media
- Hard Disk
- Software (Technical)
q36
Master Hacker
****
Posts: 325


View Profile
« Reply #3 on: July 28, 2010, 10:30:58 AM »

This is the very technical area of these boards, meaning only people with technical ability should post here, specifically related to kernel hacking. Keep your bull$#!t useless threads out of here. There won't be another way to downgrade after updating past 8498, it's not hard to google that and figure out why. We need a god damn private forum on here.
Logged
Xumpy
Master Hacker
****
Posts: 310


View Profile
« Reply #4 on: July 28, 2010, 01:07:08 PM »

@q36: Oké I agree that some boards should be read only for the public but don't close them down.

Personaly I'm also getting tired of reading to some amazing posts and then some noob comes in asking the same damn question over and over again.

But keep in mind that there are still people here who read what you guys post to learn from...

If you take that away, I don't believe there is any point in keeping this (or any) forum online...
Logged

Once your mind is running, returning to its original state feels like standing still.
xboxtech
Hacker
***
Posts: 89


View Profile
« Reply #5 on: July 28, 2010, 01:50:37 PM »

I also agree I still like coming to the threads for maybe something I dont know or need to refresh on doing.  After all I think what alot of us do makes the systems more open and can do alot more then what MS blocks out. 
Logged
q36
Master Hacker
****
Posts: 325


View Profile
« Reply #6 on: July 28, 2010, 05:12:34 PM »

Well, there are many topics that just don`t get discussed because these forums are full of idiots who join randomly to post their opinion. I think that the kernel hacking section should be limited to the people who actually hack the kernel.....which is very few and even some who claim they do just know func names and brag about it...... I find it hard to believe that anyone learns anything from these forums anymore because if they did, they`d  learn to keep their f***ing mouths shut.
Logged
tex1ntux
Hacker
***
Posts: 50


View Profile
« Reply #7 on: August 03, 2010, 01:49:29 AM »

I find it hard to believe that anyone learns anything from these forums anymore because if they did, they`d  learn to keep their f***ing mouths shut.
The thing about keeping your mouth shut is no one knows you're doing it.  I'm sure there are plenty of people who come here to read/learn; I've been doing it for years.
Logged
Gastgeber
Member
**
Posts: 10


View Profile
« Reply #8 on: August 23, 2010, 03:44:57 PM »

Sorry for Offtopic

Well it is not on the topic but on the discussion.

I would accept a read only function in forum, cuz i only read and learn. And i aggree that a lot of people post bu*&%it, that i dont wanna read. So I just filter the important messages from the important people. i would write more if i had the time and if i was faster then the pros here. I enjoy the time and the information in this board cuz there is more tech stuff than somewhere else.

@the pro's
Keep writing!
Logged
Pages: 1
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM