xbox-scene.com - your xbox news information source
Quick Links: Main Forums | Xbox360 Forums | Xbox1 Forums | PS3 Forums
Xbox-Scene Forum Help  Search Xbox-Scene Forums   Xbox-Scene Forum Members   Xbox-Scene Calendar

Giganews Usenet Offers: +1150 days binary retention, 99%+ Completion, and Unlimited Speed/Access!

360 ODD Emulators: X360 Key $99 | Wasabi360 FAT $99 | Wasabi360 Slim $99
C4E's iXtreme Burner MAX Drive: LiteOn iHAS124 DROPPED TO JUST $17


Welcome Guest ( Log In | Register )

 Forum Rules Rules
3 Pages V  1 2 3 >  
Closed TopicStart new topic
> Commodore4eva Explains Stealth Media
Xbox-Scene
post Aug 15 2006, 05:57 AM
Post #1


Memba Numero Uno
Group Icon

Group: Admin
Posts: 5201
Joined: 17-May 02
From: Yurop
Member No.: 1
Xbox Version: unk
360 version: unknown



Commodore4eva Explains Stealth Media
Posted by XanTium | August 15 00:57 EST

 
Commodore4eva implemented "Stealth Media" into the lastest version of his TS-H943 DVD firmware (Xtreme firmware 3.0 for TS-H943 Xbox 360). Today he posted more details about what this exactly means:
[QUOTE]
* Stealth Media
This is to clear up a few misconceptions about what Stealth Media is and how it works. This is not firmware stealth. Reading the firmware itself for changes is not controlled by the firmware itself, it is a low level hardware function which cannot be stopped by firrmware code.
A firmware check routine which calculated a checksum and returned that to the host was already found in V1 and was modified to always return the correct unmodified firmware value. I think this was a last minute check incorporated by MS as they knew the firmware code was not signed.
Stealth Media is all about making a backup disc appear to the Xbox360 host exactly the same as an original. Although this was already done by the Security Sector and the challenge/response, there remained a number of differences on the disc that are currently not checked for. It would be very easy for the dash or the particular game to perform these extra disc checks. There are four main aspects to Stealth Media:

* PSN Lockdown:
This is a two part process:
-Before disc authentication (security sector,challenge response) is performed the drive will only allow vaild PSN reads as defined in the PFI sector. This is currently the standard video partition. Any request to read outside this range is not allowed - as per originals. (No more reading of the backup PFI,DMI,SS sectors.)
-After disc authentication is performed and the drive is unlocked only valid PSN reads are allowed from the range defined by the Security Sector, this is the standard game partition. Any request to read outside this range is not allowed - as per originals.

* PFI Sector (Physical Format Information):
This sector is contained within the lead-in and contains information about its physical format. Disc booktype, start PSN and end PSN and Layerbreak are contained here. Currently all Xbox360 and Xbox1 games have the same PFI information, but that may change.
On Writable media (our backups), this also contains media specific information such as Media Code/Manufacturer ID and Media Product Revision number.
Any requestes for this information is now redirected to the the PFI sector now at $04FB1D (for Xbox 360 backups) or $0605FD (Xbox 1 backups), if it exists. If it does not exist (pre V3 backup) a seperate embedded PFI is used for Xbox 360 and Xbox 1.

* DMI Sector (Disk Manufacturing Information):
This sector is also contained within the lead-in and contains information about the Disc manufacturer, such as Company name, batch id etc. This is currently different for each Xbox360 and Xbox1 game in each region.
Any requestes for this information is now redirected to the the DMI sector now at $04FB1E (for Xbox 360 backups) or $0605FE (Xbox 1 backups).
A pre V3 backup will always return blank information for this. (A possible detection method.)

* Video Partition:
When Extreme V1 was released ,the disc build included a blanc video partition as it wasnt required for games to boot. As this can be checked by the XBox360 host, the standard video partition from any game was included with the stealth firmware. This is nothing new, just put back in for correctness!

* Conclusion:
As of today , none of these extra disc checks are being performed, but it is only a matter of time before a game will. The same sort of checks were introduced to XBox1 games a while ago. I performed an exhaustive check of every command that the Samsung firmware can respond to and these differences were discovered.
The Samsung firmware only supports a limited subset of commands from the MMC-3/4 standards so not all commands exist compared to a standard PC drive, so anyone testing for media specific information should bear this in mind.
Non-Stealth backups will still boot with stealth firmware and will be enhanced with the PSN Lockdown and PFI Sector embedded in the firmware. These backups will have no DMI and possibly have a blank video partition, both of which can be checked for.
Stealth backups will still boot with non-stealth firmware but will be exposed to the above top three differences (PSN Lockdown,PFI,DMI) making the backup detectable. Correct Video partition is present.
[/QUOTE]

News-Source: xboxhacker.net (this is posted in the XBH tech section - please keep discussion there serious/tech only - thx)


User is offlineProfile CardPM
Go to the top of the page
+Quote Post
SAPHiREX
post Aug 15 2006, 05:56 AM
Post #2


X-S Member
*

Group: Members
Posts: 147
Joined: 26-February 03
Member No.: 25353



thanks for the headsup.
now it makes sense happy.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Nailed
post Aug 15 2006, 06:07 AM
Post #3


X-S Expert
***

Group: Members
Posts: 577
Joined: 3-September 02
Member No.: 3413



Good write-up. Any word on when the Hitachi drives will be updated with Stealth?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
J0RD4N 007
post Aug 15 2006, 06:22 AM
Post #4


X-S Young Member
*

Group: Members
Posts: 47
Joined: 18-January 05
From: New Orleans, LA
Member No.: 189237
Xbox Version: v1.0
360 version: v1 (xenon)



QUOTE

A firmware check routine which calculated a checksum and returned that to the host was already found in V1 and was modified to always return the correct unmodified firmware value.


does this mean that a modified firmware cannot be detected? sorry if this is a retarded question, but thats the impression it gave me
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
ILLusions0fGrander
post Aug 15 2006, 06:24 AM
Post #5


third echelon agent
***********

Group: Head Moderator
Posts: 7500
Joined: 24-June 04
From: Post Apocalyptic DC Vault No. 101
Member No.: 127163
Xbox Version: v1.4
360 version: v4.0 (jasper)



QUOTE(J0RD4N 007 @ Aug 15 2006, 12:29 AM) *


does this mean that a modified firmware cannot be detected? sorry if this is a retarded question, but thats the impression it gave me

QUOTE

Reading the firmware itself for changes is not controlled by the firmware itself, it is a low level hardware function which cannot be stopped by firrmware code.


anyways.. nice info... a real scene hero for this aspect of modding.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
halikus
post Aug 15 2006, 06:41 AM
Post #6


X-S Young Member
*

Group: Members
Posts: 53
Joined: 14-June 06
Member No.: 286048



You must be tired by now Commodore4eva, for the love of god, go get shitfaced drunk the rest of the week...
Thanks for your commitment to the scene. Get some rest before you tackle the new XDK shiz. wink.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Base8
post Aug 15 2006, 08:24 AM
Post #7


X-S Member
*

Group: Members
Posts: 146
Joined: 16-March 05
Member No.: 206500
Xbox Version: v1.0
360 version: unknown



Thanks again comadore4eva, I have yet to mod my drive. I will soon but I am too lazy. I am waiting to get an adapter so I dont have to run a linux boot cd and read up on things so I understand it a bit better. Im going to read ths again while I'm sober to see if I want to use a curent firmware or wait for this for the LG. After more reaserch I am sure I will be doing this soon though I am sure.

Thanks
BaseEight biggrin.gif

Edit:

Seems really cool I hope this mod lasts forever, I hope we win the cat and mouse game permanately. Sorry for my spelling, I have a GED. wink.gif

Edit 2:

Oh god, you gotta love the last sentence of the first paragraph, I'll leave it there for all to enjoy.

This post has been edited by Base8: Aug 15 2006, 08:33 AM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
tom_mandory
post Aug 15 2006, 09:19 AM
Post #8


X-S Member
*

Group: Members
Posts: 144
Joined: 27-June 03
Member No.: 46002



i see
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
pickie
post Aug 15 2006, 10:08 AM
Post #9


X-S Young Member
*

Group: Members
Posts: 30
Joined: 23-July 04
Member No.: 132713



?? so the backups of my games which i have as image files on my pc, can these be patched with slealth or do i need to re rip them again in a different way to make them stealth ?

cheers
pickie
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
mist4fun
post Aug 15 2006, 11:06 AM
Post #10


X-S Young Member
*

Group: Members
Posts: 54
Joined: 3-February 06
Member No.: 270991



QUOTE(Base8 @ Aug 15 2006, 12:31 AM) *

Thanks again comadore4eva, I have yet to mod my drive. I will soon but I am too lazy. I am waiting to get an adapter so I dont have to run a linux boot cd and read up on things so I understand it a bit better. Im going to read ths again while I'm sober to see if I want to use a curent firmware or wait for this for the LG. After more reaserch I am sure I will be doing this soon though I am sure.

Thanks
BaseEight biggrin.gif

Edit:

Seems really cool I hope this mod lasts forever, I hope we win the cat and mouse game permanately. Sorry for my spelling, I have a GED. wink.gif

Edit 2:

Oh god, you gotta love the last sentence of the first paragraph, I'll leave it there for all to enjoy.


lmfao.. thanks I needed a good laugh
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
bucko
post Aug 15 2006, 11:11 AM
Post #11


Super Moderator
***********

Group: Head Moderator
Posts: 7981
Joined: 22-March 03
From: England
Member No.: 28278
Xbox Version: v1.6
360 version: v5.0 (360S - trinity)



Very nice work biggrin.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
infamous_Q
post Aug 15 2006, 11:42 AM
Post #12


X-S Senior Member
**

Group: Members
Posts: 237
Joined: 29-December 05
Member No.: 265796
Xbox Version: unk
360 version: v1 (xenon)



i wonder if its possible to merge this new stealth stuff onto one of the on-the-fly chips....theoretically wouldn't that make detection next to impossible?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
jo7a
post Aug 15 2006, 12:20 PM
Post #13


X-S Member
*

Group: Members
Posts: 67
Joined: 16-October 05
Member No.: 252708
Xbox Version: unk
360 version: unknown



thks Commodore4eva smile.gif
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
KUNFUCHOPSTICKS
post Aug 15 2006, 12:47 PM
Post #14


X-S X-perience
**

Group: XS-BANNED
Posts: 472
Joined: 23-July 06
From: USA
Member No.: 290951
Xbox Version: none
360 version: unknown



* DMI Sector (Disk Manufacturing Information):
This sector is also contained within the lead-in and contains information about the Disc manufacturer, such as Company name, batch id etc. This is currently different for each Xbox360 and Xbox1 game in each region.
Any requestes for this information is now redirected to the the DMI sector now at $04FB1E (for Xbox 360 backups) or $0605FE (Xbox 1 backups).
A pre V3 backup will always return blank information for this. (A possible detection method.)



I think this is where the threat will be if MS wanted to disable all backups up to this date. all i have to say is, dont plug your box in (ethernet).
peace
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Textbook
post Aug 15 2006, 12:48 PM
Post #15


X-S Hacker
******

Group: Last Chance
Posts: 2552
Joined: 30-August 04
From: Near Flint, Michigan
Member No.: 142871
Xbox Version: v1.0
360 version: v1 (xenon)



QUOTE(J0RD4N 007 @ Aug 15 2006, 01:29 AM) *

does this mean that a modified firmware cannot be detected? sorry if this is a retarded question, but thats the impression it gave me


I'd like to know the answer as well. Everybody has been weary of flashing their drive because "it's just stealth backups, not stealth firmware." Well, does this prove that incorrect? Is this why MS hasn't been able to block the firmware hacks? Maybe we've had stealth firmware all along and nobody realized it? That's what I interpreted, or was I wrong?
User is offlineProfile CardPM
Go to the top of the page
+Quote Post





3 Pages V  1 2 3 >
Closed TopicStart new topic

 

Lo-Fi Version Time is now: 19th June 2013 - 12:19 PM