xbox-scene.com - your xbox news information source
Quick Links: Main Forums | Xbox360 Forums | Xbox1 Forums | PS3 Forums
Xbox-Scene Forum Help  Search Xbox-Scene Forums   Xbox-Scene Forum Members   Xbox-Scene Calendar

Giganews Usenet Offers: +1150 days binary retention, 99%+ Completion, and Unlimited Speed/Access!

360 ODD Emulators: X360 Key $99 | Wasabi360 FAT $99 | Wasabi360 Slim $99
C4E's iXtreme Burner MAX Drive: LiteOn iHAS124 DROPPED TO JUST $17


Welcome Guest ( Log In | Register )

 Forum Rules Rules
6 Pages V  1 2 3 > »   
Reply to this topicStart new topic
> Wanted... "rmenhal-like" Skills For Development Of, UDDAE (Uber Double Dash Audio Exploit)
Ndure protagonist
post Sep 23 2005, 04:07 PM
Post #1


X-S Expert
***

Group: Members
Posts: 544
Joined: 30-July 05
Member No.: 237656
Xbox Version: v1.0
360 version: none



Ndure's fonts and retail Uber Double Dash setups seem to provide a unique Audio Exploit opportunity, that could enable a 'purely MS dash' way back to the softmod from the "full retail" (Live console compliant) dashboard!

On 5713 & 5838 kernels, that's currently only possible using SCEEE and MAEEE, which is far from ideal. Additionally, UDDAE wouldn't suffer from reset-on-eject...

It requires a suitably exploited ST.DB file plus the xboxdash.xbe and six XIP* files from the UberDash (or SlaYers 2.5's 4920, the XBE via a patch**).

The ST.DB's the challenge... since UDDAE's triggered first by easter-egging the xboxdash.xbe (as settings_adoc.xip in the 5960 dash) then triggering the audio exploit (via the Uber4920 dash) the memory layout isn't what the existing ST.DB was coded for,I presume, as the Xbox reboots.

Anyone interested in attempting to get it working (maybe by re-coding rmenhal's hulkstdb.asm***) and/or have any questions/comments?


* default, keyboard, mainmenu5, music_copy3, music_playedit2 and music2 (place in xboxdashdata.17cdc100).

** http://forums.xbox-scene.com/index.php?act...dpost&p=2351379 (place in xboxdashdata.185ead00).

*** http://forums.xbox-scene.com/index.php?act...dpost&p=1849661 (HULK audio exploit; suitable baseline?)

Edit: This pertains to the Ndure fonts setup too...

This post has been edited by Ndure protagonist: Sep 23 2005, 04:15 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Textbook
post Sep 23 2005, 04:14 PM
Post #2


X-S Hacker
******

Group: Last Chance
Posts: 2552
Joined: 30-August 04
From: Near Flint, Michigan
Member No.: 142871
Xbox Version: v1.0
360 version: v1 (xenon)



If this happens, which it probably will, will you have to change your name to UDDAE protagonist? I don't know anything about the whole development side of anything, I just know how to use the softmods, but this sounds like great news as I was a fan of SCEEE and even wrote a tutorial on it. Good luck with your next project, mr. UDDAE protagonist.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Ndure protagonist
post Sep 23 2005, 04:56 PM
Post #3


X-S Expert
***

Group: Members
Posts: 544
Joined: 30-July 05
Member No.: 237656
Xbox Version: v1.0
360 version: none



Addendum:

Re. the xboxdash.xbe being placed in xboxdashdata.185ead00: it needs to be named as settings_adoc.xip in there.

Re. the .xip's being placed in xboxdashdata.17cdc100: there will consequently be two xboxdashdata.{version#} directories; my tests found this one isn't affected by dashupdate.xbe runs.


{: Textbook, in not so many words (tee-hee) it was previously introduced re. "UD-eh!" :}
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
kingroach
post Sep 23 2005, 05:11 PM
Post #4


X-S Hacker
******

Group: Dev/Contributor
Posts: 2739
Joined: 9-February 04
Member No.: 98931
Xbox Version: v1.4
360 version: v5.0 (360S - trinity)



I never did any audio things.. whats the button sequence for activating settings_adoc..
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
krayzie
post Sep 23 2005, 05:20 PM
Post #5


X-S Elysian
*************

Group: Head Moderator
Posts: 9333
Joined: 3-January 04
Member No.: 88318
Xbox Version: unk
360 version: unknown



to trigger the easter egg (settings_adoc.xip):
QUOTE
This works best when you already have a soundtrack copied to your HD using the msdash.
Select music, the soundtrack you copied over, copy, copy, new soundtrack, and put in the following as name. This must be
exactly like this: <<Eggsßox>> ,Done (the <<>> are under symbols and the ß is under accents. Also note the capital E)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
xman954
post Sep 24 2005, 07:27 PM
Post #6


X-S Messiah
*******

Group: Dev/Contributor
Posts: 3028
Joined: 10-April 04
From: the bottom of Tampa Bay
Member No.: 113422
Xbox Version: v1.0
360 version: v1 (xenon)



QUOTE
since UDDAE's triggered first by easter-egging the xboxdash.xbe
(as settings_adoc.xip in the 5960 dash)

this xboxdash.xbe is from the uber4920 dash (17cdc100) ???
QUOTE
then triggering the audio exploit (via the Uber4920 dash)

how is it triggered ?
how many dirrerent types of exploited ST.DB are there ?

so what will happen:
5960 dash > st.db > (<<Eggsßox>>) > uber4920 > trigger? > st.db > habibi signed code

the 5960 dash must also see this st.db as valid ?
at what point does it reboot ?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Ndure protagonist
post Sep 25 2005, 01:45 AM
Post #7


X-S Expert
***

Group: Members
Posts: 544
Joined: 30-July 05
Member No.: 237656
Xbox Version: v1.0
360 version: none



QUOTE
this xboxdash.xbe is from the uber4920 dash (17cdc100) ???
Yes (which can also be made from 1012a700's with the patch)

QUOTE
how is it triggered ?
how many dirrerent types of exploited ST.DB are there ?
The audio exploit is triggered by pressing the button sequence below.
I know of only two "types" of exploited ST.DB; the 4920 dash (I've tried catfish's) and the HULK movie disc (rmenhal's).

QUOTE
so what will happen:
5960 dash > st.db > (<<Eggsßox>>) > uber4920 > trigger? > st.db > habibi signed code
Yes (the st.db being in E:\TDATA\fffe0000\music and "trigger?" as below)

QUOTE
the 5960 dash must also see this st.db as valid ?
at what point does it reboot ?
It will (the 5960 dash's easter-egg doesn't validate the st.db).
With the st.db's I've tried, the reboot occurs as soon as you press the last button:
CODE
A (MUSIC)
Down
A (blank)
Down
A (COPY)
Right
Right
A (COPY)
A (NEW SOUNDTRACK)
A (DONE)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
xman954
post Sep 25 2005, 08:29 PM
Post #8


X-S Messiah
*******

Group: Dev/Contributor
Posts: 3028
Joined: 10-April 04
From: the bottom of Tampa Bay
Member No.: 113422
Xbox Version: v1.0
360 version: v1 (xenon)



what makes the code start running from address 0 in the "hulk" st.db
from looking at it, that is what happens....

if codes is running the thing that is not known is where the Kernal table is ?

if so do you think it is possible to search for the "XePublicKeyData" the MS Key
using: [address] that has 31415352h for data, and [address+10h] must have 10001h for data...(maybe 1st, 2nd, 3rd or last instants of it)
start search at 80000000h ? (the lowest address it could be)

then calculate all the other Kernal table entrees on the fly from there ?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Ndure protagonist
post Sep 26 2005, 02:44 AM
Post #9


X-S Expert
***

Group: Members
Posts: 544
Joined: 30-July 05
Member No.: 237656
Xbox Version: v1.0
360 version: none



xman954, to be honest I have hardly any understanding of that ... wish I did!

I don't even know whether a 4920 dash audio exploit source might be a better baseline (than HULK's)?

It sure would be great if a generic ST.DB (which I think you're suggesting) is a possibility for Ndure though.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
dus
post Sep 26 2005, 08:09 AM
Post #10


X-S Young Member
*

Group: Members
Posts: 47
Joined: 13-November 04
Member No.: 166266



QUOTE(xman954 @ Sep 25 2005, 09:40 PM)
what makes the code start running from address 0 in the "hulk" st.db
from looking at it, that is what happens....


It doesn't start at 0. The three dd:s (HEAD012) are actually very important...
I don't know much, but I believe they are used to corrupt the stack when st.db is read.

Good luck!
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
PedrosPad
post Sep 26 2005, 03:37 PM
Post #11


X-S Freak
*****

Group: Moderator
Posts: 1859
Joined: 4-July 03
From: UK
Member No.: 47221
Xbox Version: v1.1
360 version: v1 (xenon)



QUOTE(Ndure protagonist @ Sep 25 2005, 02:56 AM)
It will (the 5960 dash's easter-egg doesn't validate the st.db).
*



A quote from rmenhal:
QUOTE(rmenhal @ May 24 2004, 04:51 AM)
You forgot that audio exploits don't work with post-4920 dashes
*


sad.gif

This post has been edited by PedrosPad: Sep 26 2005, 04:01 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Ndure protagonist
post Sep 26 2005, 04:01 PM
Post #12


X-S Expert
***

Group: Members
Posts: 544
Joined: 30-July 05
Member No.: 237656
Xbox Version: v1.0
360 version: none



PedrosPad, your pre-edit info. was correct, which is why UDDAE needs 5960's easter-egg capability to launch the Uber4920's skeleton, which is then audio exploited...

(Hopefully this clarifies your post-edit too.)

This post has been edited by Ndure protagonist: Sep 26 2005, 04:03 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
PedrosPad
post Sep 26 2005, 04:06 PM
Post #13


X-S Freak
*****

Group: Moderator
Posts: 1859
Joined: 4-July 03
From: UK
Member No.: 47221
Xbox Version: v1.1
360 version: v1 (xenon)



QUOTE(Ndure protagonist @ Sep 26 2005, 05:12 PM)
PedrosPad, your pre-edit info. was correct, which is why UDDAE needs 5960's easter-egg capability to launch the Uber4920's skeleton, which is then audio exploited...

(Hopefully this clarifies your post-edit too.)
*



5960 dash > (<<Eggsßox>>) > Uber4920 > trigger > audio exploit(st.db) > habibi signed code.
(correction to post #7! - tongue.gif )

This post has been edited by PedrosPad: Sep 26 2005, 04:18 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Ndure protagonist
post Sep 26 2005, 04:07 PM
Post #14


X-S Expert
***

Group: Members
Posts: 544
Joined: 30-July 05
Member No.: 237656
Xbox Version: v1.0
360 version: none



{: Yes, as per Post#7... :}
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
DaBiscuit
post Sep 26 2005, 04:19 PM
Post #15


X-S Senior Member
**

Group: Members
Posts: 243
Joined: 2-February 05
From: Derby, England.
Member No.: 194682
Xbox Version: v1.4



QUOTE(Ndure protagonist @ Sep 23 2005, 04:18 PM)
Ndure's fonts and retail Uber Double Dash setups seem to provide a unique Audio Exploit opportunity, that could enable a 'purely MS dash' way back to the softmod from the "full retail" (Live console compliant) dashboard!
*



Would you mind clarifying for me what exactly you wish to achieve? I don't entirely understand. NDURE allows a user to boot either a shadow C with retail MS dash, or a modded dash with a homebrew dash. Both work well, so what is it that this new exploit would add?

I'm not trying to be rude, I would like to understand.

This post has been edited by DaBiscuit: Sep 26 2005, 04:19 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post





6 Pages V  1 2 3 > » 
Reply to this topicStart new topic

 

Lo-Fi Version Time is now: 19th May 2013 - 08:22 PM