XboxHacker BBS
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
June 19, 2013, 01:54:22 AM


Login with username, password and session length


Pages: « 1 2
  Print  
Author Topic: RGH 2.0 Released by Team SQUIRT  (Read 4113 times)
Tony_Amigozs
Hacker
***
Posts: 85


View Profile
« Reply #20 on: April 18, 2012, 06:17:04 PM »

Thanks cory1492,

So both TX and Team Squirt can shoot themself in the foot one day claiming it's unpatchable.
If MS changes it so it won't be able to extract they cpu-key anymore then we're still screwed.

good thing is is that we can always decrypt the upcoming cb_b.. by simply upgrading a console that we already have cpu key for so we can see precisely what they changed.
Logged
PetrozPL
Member
**
Posts: 35


View Profile
« Reply #21 on: April 19, 2012, 02:18:33 AM »


let me elaborate a bit further wrt 15$ profits... how come you're defending not only one but two teams? IMHO they should release the sources for the vhdl, mainly because of this:


constant POST_B8 : integer := 12;
constant POST_BA : integer := 13;
constant POST_BB : integer := 14;


(well f*** me, I found this out myself using my LA, you're very welcome)

this is all you need between trinity and "RGH 2.0"...

So, thats the main difference between CB_A glitching on fat and slim? Does it mean, than slim I2C slowdown command is the same and the slowdown CPU frequency is the same as on SLIM consoles?
Logged
uf6667
Member
**
Posts: 15


View Profile
« Reply #22 on: April 19, 2012, 02:33:03 AM »


let me elaborate a bit further wrt 15$ profits... how come you're defending not only one but two teams? IMHO they should release the sources for the vhdl, mainly because of this:


constant POST_B8 : integer := 12;
constant POST_BA : integer := 13;
constant POST_BB : integer := 14;


(well f*** me, I found this out myself using my LA, you're very welcome)

this is all you need between trinity and "RGH 2.0"...

So, thats the main difference between CB_A glitching on fat and slim? Does it mean, than slim I2C slowdown command is the same and the slowdown CPU frequency is the same as on SLIM consoles?

aye  Grin
Logged
cory1492
Xbox Hacker
*****
Posts: 616


View Profile
« Reply #23 on: April 19, 2012, 04:58:29 AM »

no you said they can change everything and that is not true..  Cheesy
Its absolutely true, they have the private keys and can change any piece of write-able software they want at any time (including the dvd firmware which many said they couldn't do... until they did.) They could even go and modify the CPU ROM on new units so we can't decrypt the second stage BL on them. To think otherwise is simply not sane. Read what I said again, instead of just the first sentence and consider your post which I was replying to. It would be trivial for them to replace RC4 with something that isn't vulnerable to a plaintext substitution and thus can't be loaded by current CB_A - having decrypted BLs didn't magically give us any CPU key, it's always taken a lot of work (even if some wilfully ignore that).

Personally I'm not all that interested in speculating, whatever they do I have my CPU key and unrevokeable CB_A and am not worried - the simple fact is they will try to limit the hacks impact/scope at some point, they always have (in the least) broke current solutions if not outright blocked them. Sometimes all it takes is abandoning the platform.
« Last Edit: April 19, 2012, 05:11:12 AM by cory1492 » Logged
damox
Master Hacker
****
Posts: 484


View Profile
« Reply #24 on: April 19, 2012, 05:18:10 AM »

Personally I'm not all that interested in speculating, whatever they do I have my CPU key and unrevokeable CB_A and am not worried - the simple fact is they will try to limit the hacks impact/scope at some point, they always have (in the least) broke current solutions if not outright blocked them. Sometimes all it takes is abandoning the platform.

QFT.
Logged
Tony_Amigozs
Hacker
***
Posts: 85


View Profile
« Reply #25 on: April 19, 2012, 06:09:06 AM »

no you said they can change everything and that is not true..  Cheesy
Its absolutely true, they have the private keys and can change any piece of write-able software they want at any time (including the dvd firmware which many said they couldn't do... until they did.) They could even go and modify the CPU ROM on new units so we can't decrypt the second stage BL on them. To think otherwise is simply not sane. Read what I said again, instead of just the first sentence and consider your post which I was replying to. It would be trivial for them to replace RC4 with something that isn't vulnerable to a plaintext substitution and thus can't be loaded by current CB_A - having decrypted BLs didn't magically give us any CPU key, it's always taken a lot of work (even if some wilfully ignore that).

Personally I'm not all that interested in speculating, whatever they do I have my CPU key and unrevokeable CB_A and am not worried - the simple fact is they will try to limit the hacks impact/scope at some point, they always have (in the least) broke current solutions if not outright blocked them. Sometimes all it takes is abandoning the platform.

I have seen people stated here on xboxhacker that 1bl key the one on cpu rom is not changeable.. and ms did not changed it after latest update.. so if its takes them more then 8 months to change that key.  Smiley if they could they would have done it by now don't you think ?

edit.. just noticed that you said on new units.. but ofcourse I was talking about the currents units they can not change it.. duh ofcourse on new units they can change anything they want.
« Last Edit: April 19, 2012, 06:14:30 AM by Tony_Amigozs » Logged
uf6667
Member
**
Posts: 15


View Profile
« Reply #26 on: April 19, 2012, 07:48:22 AM »

don't you hunderstand? the crypto doesn't have to remain RC4!
if this is the case, we'll need to find a fail inside kernel to get the cpu key Sad
feelsbadman
Logged
Tony_Amigozs
Hacker
***
Posts: 85


View Profile
« Reply #27 on: April 19, 2012, 07:57:52 AM »

don't you hunderstand? the crypto doesn't have to remain RC4!
if this is the case, we'll need to find a fail inside kernel to get the cpu key Sad
feelsbadman

I wasn't talking about the RC4 crypto.. I was talking about 1bl key in cpu rom..
Logged
asapreta
Hacker
***
Posts: 92


View Profile
« Reply #28 on: April 19, 2012, 12:04:26 PM »

I think I got an incompatible CB B: 5773:

Dual CB detected for Falcon CB_B 5773
Traceback (most recent call last):
  File "common/imgbuild/build.py", line 466, in <module>
    CB_B = calc_keystream(CB_B, open("common\\CB\\CBB" + str(build(CB_B)
n", "rb").read(), patch_CB(open(cbbpath, "rb").read()))
IOError: [Errno 2] No such file or directory: 'common\\CB\\CBB5773.bin'

I've checked and there is no CBB5773.BIN on that folder.
« Last Edit: April 19, 2012, 12:06:56 PM by asapreta » Logged
Tony_Amigozs
Hacker
***
Posts: 85


View Profile
« Reply #29 on: April 19, 2012, 12:29:33 PM »

look http://team-xecuter.com/forums/showthread.php?t=85470

try that batch tool it has 5773  included should work
Logged
asapreta
Hacker
***
Posts: 92


View Profile
« Reply #30 on: April 19, 2012, 12:31:39 PM »

look http://team-xecuter.com/forums/showthread.php?t=85470

try that batch tool it has 5773  included should work

will try, thanks

Edit >>>>
Just to mention the BAT was able to create the rgh2_.ecc
« Last Edit: April 19, 2012, 12:42:59 PM by asapreta » Logged
Tony_Amigozs
Hacker
***
Posts: 85


View Profile
« Reply #31 on: April 19, 2012, 01:11:38 PM »

Great when its glitching tell us which chip you have and how long does it take to glitch.  Smiley
« Last Edit: April 19, 2012, 01:14:20 PM by Tony_Amigozs » Logged
asapreta
Hacker
***
Posts: 92


View Profile
« Reply #32 on: April 19, 2012, 02:05:16 PM »

Great when its glitching tell us which chip you have and how long does it take to glitch.  Smiley

Wasn't able to make it glitch. As soon as I start the console with the .ECC created I get 3RL.

Flashed back the original nand and its fine.
Logged
guerrierodipace
Hacker
***
Posts: 78


View Profile
« Reply #33 on: April 20, 2012, 08:15:26 AM »

Oh my god.... messiah is come... thANks TO you

ROTFL
 Cheesy Cheesy Cheesy Cheesy Cheesy
Logged

Tony_Amigozs
Hacker
***
Posts: 85


View Profile
« Reply #34 on: May 16, 2012, 09:05:36 AM »

http://www.360squirt.com/news.php

squirt new information

    SQUIRTER DONGLE device “preview” (MAGICDONGLE hardware)
    RGH 2.0 STORY ...
    SQUIRT SUPPORT FORUM
    SQUIRT DUAL NAND technical notes
Logged
Pages: « 1 2
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM