xbox-scene.com - your xbox news information source
Quick Links: Main Forums | Xbox360 Forums | Xbox1 Forums | PS3 Forums
Xbox-Scene Forum Help  Search Xbox-Scene Forums   Xbox-Scene Forum Members   Xbox-Scene Calendar

Giganews Usenet Offers: +1150 days binary retention, 99%+ Completion, and Unlimited Speed/Access!

360 ODD Emulators: X360 Key $99 | Wasabi360 FAT $99 | Wasabi360 Slim $99
C4E's iXtreme Burner MAX Drive: LiteOn iHAS124 DROPPED TO JUST $17


Welcome Guest ( Log In | Register )

 Forum Rules Rules
 
Closed TopicStart new topic
> Xbox 360 Softmod(theory)
f34rther34pr
post Oct 3 2010, 03:00 AM
Post #1


X-S Member
*

Group: Members
Posts: 71
Joined: 2-May 10
Member No.: 437229
Xbox Version: v1.4
360 version: v5.0 (360S - trinity)



i remember a while back reading something about how it could be possible to hack a 360 through a system update. the only problem(well maybe not just one) would be that if you modified the update code at all it'd break the signature, making it useless.


well i thought perhaps if one could be able to extract an ms-signed signature from an update and then inject it to a modified update (much like the psp's custom firmware) it could be possible foll the 360 into thinking it of an actual update. thus allowing us to run unsigned code on most consoles. it would be much more efficient(and far less time consuming) than a jtag. please don't torch me if this has already been proven impossible.


btw, im pretty sure if we really did some research and experimenting this could very well be possible. post your thoughts, but like i said please don't torch me if its been disproven.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Heimdall
post Oct 3 2010, 03:29 AM
Post #2


X-S Legend
*********

Group: Members
Posts: 5749
Joined: 27-August 08
From: UK
Member No.: 388964
Xbox Version: v1.4
360 version: v4.0 (jasper)



You clearly don't understand how digital signatures work. The signature signs the actual code, it isn't an abstract thing that can be extracted and reused. If you change even one byte of the code then the signature doesn't match the code and it fails, so you can't just attach a known signature to a random piece of code and expect it to work.

The only way it might work would be if Microsoft had implemented their digital signature system incorrectly - and they haven't. Consequently, change a byte = signature fails = code doesn't run.

This article might help you understand the basics of digital signatures.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
f34rther34pr
post Oct 3 2010, 03:44 AM
Post #3


X-S Member
*

Group: Members
Posts: 71
Joined: 2-May 10
Member No.: 437229
Xbox Version: v1.4
360 version: v5.0 (360S - trinity)



it just my theory. perhaps some could build on that though. and u are rite about me knowing nothing about how signing works, i just assumed how it worked lol.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
No_Name
post Oct 3 2010, 02:37 PM
Post #4


X-S Freak
*****

Group: Members
Posts: 1154
Joined: 28-January 03
Member No.: 21640



There is nothing to build on.

Just FYI, this attack vector has been thought off before and back in 2005 the answer was no wont work due to the signature on the updates which is the same as today.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Haze666
post Oct 28 2010, 03:25 PM
Post #5


X-S Enthusiast


Group: Members
Posts: 15
Joined: 15-July 10
Member No.: 440879
Xbox Version: v1.1
360 version: v1 (xenon)



QUOTE(No_Name @ Oct 3 2010, 08:37 AM) *

There is nothing to build on.

Just FYI, this attack vector has been thought off before and back in 2005 the answer was no wont work due to the signature on the updates which is the same as today.


I believe there is something to build on here.
A little far fetched, yes. Impossible, no.

If one could code a re-signer, to then sign that modified code, then one could then install the modified code.
Therefore making this a very good theory, although i personally do not have the knowledge to build a re-signer.
I'm sure there is someone around that could do it.
But would be damn hard, laugh.gif

I'm sure you guys modified Xbox Originals, back when they were top of the line, maybe even modified Halo2 game content, and if you did, you would know that you need to resign the maps proper prior to playing on those modified maps, or you would get a "Failed to load map" message.

It can be done, it's just a matter of will it happen.

Hope my input helps with those who aren't optimistic. rolleyes.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Heimdall
post Oct 28 2010, 03:35 PM
Post #6


X-S Legend
*********

Group: Members
Posts: 5749
Joined: 27-August 08
From: UK
Member No.: 388964
Xbox Version: v1.4
360 version: v4.0 (jasper)



Yet another noob who can't read, can't code, and knows nothing about digital signatures.

Again, for those like you who can't read - THERE IS NOTHING TO BUILD ON.

The difficulty isn't writing the "re-signer", the difficulty is that we don't have the key to sign the code with. Only Microsoft have that key.

If you'd bothered to read the link in my previous post you'd have spotted that you need the signing key, and a bit of common sense would lead to to work out that Microsoft is unlikely to make such a vital piece of information publicly available.

Your "input" hasn't helped at all, because you provided no input - only baseless and uneducated speculation about something you know nothing about.

This post has been edited by Heimdall: Oct 28 2010, 03:37 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Haze666
post Oct 28 2010, 05:19 PM
Post #7


X-S Enthusiast


Group: Members
Posts: 15
Joined: 15-July 10
Member No.: 440879
Xbox Version: v1.1
360 version: v1 (xenon)



QUOTE(Heimdall @ Oct 28 2010, 09:35 AM) *

Your "input" hasn't helped at all, because you provided no input - only baseless and uneducated speculation about something you know nothing about.


Well, at least I'm not being a douche-bag about it.
And sure I can't code, but I do know a thing or two about digital sig's.
And hell, the more you talk about it, the more I think you know less about what your talking about.

And I'm sure one of the coders at Bungie just waltzed out and handed somebody the "formula" to the sig's for Halo2 Maps? And the same with Halo3 Map Variants?
But whatever, I'm going to play some Halo Reach, with some RTH.
Love swaping automatic weapon projectiles with sticky grenades, now if only there were nukes in that game.

[Edit]
Forgot to include this.

http://www.eurasia.nu/wiki/index.php/Xbox360Kernel

Download the system updates, all of the.
compare the sigs
find a pattern
????????
Profit.

This post has been edited by Haze666: Oct 28 2010, 05:22 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Heimdall
post Oct 28 2010, 05:35 PM
Post #8


X-S Legend
*********

Group: Members
Posts: 5749
Joined: 27-August 08
From: UK
Member No.: 388964
Xbox Version: v1.4
360 version: v4.0 (jasper)



QUOTE(Haze666 @ Oct 28 2010, 05:19 PM) *
but I do know a thing or two about digital sig's.
Obviously not, as your next statement proves.

QUOTE(Haze666 @ Oct 28 2010, 05:19 PM) *
Download the system updates, all of the.
compare the sigs
find a pattern
????????
Profit.

There is no "pattern" with digital signatures, and if you knew anything about digital signatures you would know that - it's in every "Digital Signature Design 101" course, book and article as one of the requirements for a good digital signature system. Digital signatures are cryptographic representations of a file, and they remain secure precisely because there is no feasible computational method of creating a signature without the original key, nomatter how many signed files you examine. Get it - there is no pattern.

Now, go back to shooting aliens in your bedroom and leave the real engineering to people who know what they are talking about.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Haze666
post Nov 2 2010, 03:50 PM
Post #9


X-S Enthusiast


Group: Members
Posts: 15
Joined: 15-July 10
Member No.: 440879
Xbox Version: v1.1
360 version: v1 (xenon)



QUOTE(Heimdall @ Oct 28 2010, 11:35 AM) *

Obviously not, as your next statement proves.


Sarcasm my friend.

Wouldn't put it like that if i were being serious, Sir.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
inspuration
post Nov 4 2010, 11:57 AM
Post #10


X-S Member
*

Group: Members
Posts: 131
Joined: 7-June 10
Member No.: 438964



QUOTE(Haze666 @ Nov 2 2010, 03:50 PM) *

Sarcasm my friend.

Wouldn't put it like that if i were being serious, Sir.


You are an idiot. Stop talking.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
f34rther34pr
post Nov 30 2010, 04:40 AM
Post #11


X-S Member
*

Group: Members
Posts: 71
Joined: 2-May 10
Member No.: 437229
Xbox Version: v1.4
360 version: v5.0 (360S - trinity)



yes i revived this postg deal with it.

anyways. in defense of the person who actually supported my idea. it could be possible. namly because the ms digutal signiture has to be stored somewhere rite? if it wasnt then how would the 360 know it is a valid code and not some user made one?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Heimdall
post Nov 30 2010, 09:58 AM
Post #12


X-S Legend
*********

Group: Members
Posts: 5749
Joined: 27-August 08
From: UK
Member No.: 388964
Xbox Version: v1.4
360 version: v4.0 (jasper)



Not again.

You either haven't bothered to read up on digital signatures, or haven't understood them, in spite of the simplicity of the article I linked to in my first reply.

The digital signature is different for every single file. I'll say it again in a different order in the hope that it might sink in - every single file has a different digital signature. The signature for one file is of no use with another file, because it simply won't match the second file.

It's the public key that's stored on the Xbox, and the public key is used to VERIFY the digital signature of the file. To sign the file you need the private key. Microsoft's private key is probably not stored in one place, is definitely only accessible to a handful of people, and is therefore unlikely to ever be seen outside of Redmond. I'll say that again as well, in the hope that it might sink in; you can only sign a file with the private key, and only Microsoft has the private key, and the private key ISN'T on your Xbox, it's held at a secure Microsoft location.

FYI, in case you were wondering, JTAGs can run unsigned code because they bypass the signature check - broadly the same method that was used on the Xbox 1. That's the only feasible method to get round the signature problem.

So please, stop flogging this dead horse. Your idea (it was never a theory, in spite of the title) simply won't work. To summarise what I said to your equally misguided supporter, if you can't even grasp the basics of digital signatures then you should stop digging yourself further into this hole, and leave the real engineering to people who know what they are talking about.

This post has been edited by Heimdall: Nov 30 2010, 10:45 AM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
No_Name
post Nov 30 2010, 10:09 PM
Post #13


X-S Freak
*****

Group: Members
Posts: 1154
Joined: 28-January 03
Member No.: 21640



Yes idiot, it is stored somewhere, how the **** do you expect them to sign the games we play.
Its probably stored on a secure stand alone system in a secure room, within a secure room within a secure floor of a secure building.

So there you go got going to steal it and then you dont need your 'theory' which as I said is not a new or unique idea people smarter than you had the same idea the very day the 360 came out.

O and before you think of a new idea, no the old game save hacks from the xbox day wont work either.

User is offlineProfile CardPM
Go to the top of the page
+Quote Post





Closed TopicStart new topic

 

Lo-Fi Version Time is now: 19th May 2013 - 07:19 PM