xbox-scene.com - your xbox news information source
Quick Links: Main Forums | Xbox360 Forums | Xbox1 Forums | PS3 Forums
Xbox-Scene Forum Help  Search Xbox-Scene Forums   Xbox-Scene Forum Members   Xbox-Scene Calendar

Special Limited Offer: SuperNews Unlimited Usenet Access, Unlimited Speed for $11.99
256-bit SSL, 350 Days Retention, 30 Connections - Join Today! - ONLY $11.99

Support this site - buy the X-Scene Tshirt $17.95

Welcome Guest ( Log In | Register )

 Forum Rules Rules
2 Pages V  1 2 >  
Reply to this topicStart new topic
> ConSign
Xbox-Scene
post Jun 29 2008, 05:58 PM
Post #1


Memba Numero Uno
Group Icon

Group: Admin
Posts: 4177
Joined: 17-May 02
From: Yurop
Member No.: 1
Xbox Version: unk
360 version: unknown



ConSign
Posted by Iriez | June 29 12:58 EST | News Category: Xbox360
 
A container file signature tool finally goes public....
What is it?
============
The CON file tool updates signatures found in Xbox 360 user content files ("CON" file). CON is the format used for saved games and settings. The tool requires a valid keyvault file to work.
How it works:
=============
In the keyvault of every Xbox 360 is a unique CON keypair that is used for signing CON files. The public key component of this keypair is signed by Microsoft to ensure that arbitrary keypairs cannot be used.
A copy of the public key and its signature is stored in each CON file. This allows Xbox 360 consoles to verify CON files that may be signed by other Xbox 360 consoles.Because the signing keys are per-box, individual consoles can have their keypair revoked in firmware updates.
For more information, see the source code included in the archive.

What can it do?
===============
The tool is not very interesting from the perspective of running unsigned code or Linux. It would require an exploit that is unlikely given the architecture of the Xbox 360.It is useful for activities such as porting saved game content from PC to Xbox.

Credits
=======
roofus & angerwound for proving it was possible and posting on xboxhacker.net the basic outline of how it works.
Rene Ladan for package file research, including hash table research.

No Credit
=========
superaison & haxalot88 (ie Michael Kaufman of Talent, Oregon 97540) who stole this work in order to try to live up to fantasies of messing with Xbox Live and somehow making financial gain out of it, then trying to claim it as their own work.


Official Site: http://xss.ath.cx
Download: n/a (May be illegal under EULA/DMCA)
News-Source: xbins.org




User is offlineProfile CardPM
Go to the top of the page
+Quote Post
xboxjason
post Jun 29 2008, 06:49 PM
Post #2


X-S Senior Member
**

Group: Members
Posts: 218
Joined: 7-October 04
Member No.: 153891
Xbox Version: v1.0
360 version: v1 (xenon)



Hmm... This may lead to more exploit discoveries. Or maybe it's just wishful thinking. happy.gif

~Jason
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Chimp5000
post Jun 29 2008, 07:28 PM
Post #3


X-S X-perience
**

Group: XS-BANNED
Posts: 303
Joined: 22-April 08
From: Hillsborough, NJ
Member No.: 379151
Xbox Version: v1.0
360 version: v1 (xenon)





I am a little lost as to what this is...
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
CreisoN
post Jun 29 2008, 07:43 PM
Post #4


X-S Young Member
*

Group: Members
Posts: 30
Joined: 11-June 04
Member No.: 124883



Please correct me if im wrong.



with this i might be able to get or change the key from a 360 that lost for some reason the dvd drive ?

rolleyes.gif Thanks in advance !
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
I'dkickurass@cod2
post Jun 29 2008, 08:07 PM
Post #5


X-S Young Member
*

Group: Members
Posts: 49
Joined: 10-September 06
Member No.: 299442



Ok, first off. I know superaison personally and he did not steal the code to write his own resigner. I've known this guy for 4 years and I would trust him over my friends I know in person. They also said he stole the code to write a Halo 3 forge map rehasher, but I can tell you he did not steal that either. Is it so hard to believe that he can write his own resigner? but yeah he was trying to sell it, I know that much. But so what, Any one of u would have done the exact same thing if u were offered $500 for it. So don't get all pissy just because someone else figured it out.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
leorimolo
post Jun 29 2008, 09:01 PM
Post #6


X-S Expert
***

Group: Members
Posts: 579
Joined: 13-March 05
From: Costa Rica
Member No.: 205713
Xbox Version: v1.3
360 version: v1 (xenon)





QUOTE(I'dkickurass@cod2 @ Jun 29 2008, 02:43 PM) *

Ok, first off. I know superaison personally and he did not steal the code to write his own resigner. I've known this guy for 4 years and I would trust him over my friends I know in person. They also said he stole the code to write a Halo 3 forge map rehasher, but I can tell you he did not steal that either. Is it so hard to believe that he can write his own resigner? but yeah he was trying to sell it, I know that much. But so what, Any one of u would have done the exact same thing if u were offered $500 for it. So don't get all pissy just because someone else figured it out.


Yes he did, Haxalot basically killed two sites when he STOLE derived CON resigner, he started releasing then tout suparison how to make it...

User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Burgleflickle
post Jun 29 2008, 09:04 PM
Post #7


X-S Young Member
*

Group: Members
Posts: 41
Joined: 3-May 04
From: MN
Member No.: 117849
Xbox Version: unk



No Credit
=========
superaison & haxalot88 (ie Michael Kaufman of Talent, Oregon 97540) who stole this work in order to try to live up to fantasies of messing with Xbox Live and somehow making financial gain out of it, then trying to claim it as their own work.

Name and addy nice!

. === )~ p3wned
_)
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
No_Name
post Jun 29 2008, 09:14 PM
Post #8


X-S Genius
****

Group: Members
Posts: 866
Joined: 28-January 03
Member No.: 21640



QUOTE(CreisoN @ Jun 29 2008, 12:19 PM) *

Please correct me if im wrong.
with this i might be able to get or change the key from a 360 that lost for some reason the dvd drive ?

rolleyes.gif Thanks in advance !

Myabe if you would read the description of what this tool is for you would see you are so wrong to not even be close to to being right.

There is at the time of me making this post THERE IS NO WAY TO GET THE DRIVE KEY OFF THE MOTHERBOARD WITHOUT A WORKING DVD DRIVE.

Hopefully this will stop any more idiots who failed to read the description from posting the same question time and time again but I doubt it will.

This post has been edited by No_Name: Jun 29 2008, 09:15 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Iriez
post Jun 29 2008, 10:17 PM
Post #9


XBINS TOTALITARIAN
******

Group: Head Moderator
Posts: 2705
Joined: 11-December 02
Member No.: 12951
Xbox Version: v1.0
360 version: v1 (xenon)



QUOTE(I'dkickurass@cod2 @ Jun 29 2008, 02:43 PM) *

Ok, first off. I know superaison personally and he did not steal the code to write his own resigner. I've known this guy for 4 years and I would trust him over my friends I know in person. They also said he stole the code to write a Halo 3 forge map rehasher, but I can tell you he did not steal that either. Is it so hard to believe that he can write his own resigner? but yeah he was trying to sell it, I know that much. But so what, Any one of u would have done the exact same thing if u were offered $500 for it. So don't get all pissy just because someone else figured it out.


Sorry, but superaison did not write this. He contacted me recently to tell me about his having it, and when I asked him if i could check it out he just responded with this:
"[13:06] superaison1: skatezero says :
[13:06] superaison1: Daniel =] - [-oh-em-gee--thats-hXc!-] says:
and dont give it out"

So apparentlly whoever daniel is (perhaps haxalot88) is the supposed 'author' of this tool. Please bear in mind that this tool was functional well over a year ago, with angerwound and 360gamesaves.net, just never public.

And as far as im concerned, anyone trying to SELL a tool that utilized public information is nothing but a complete low life. The information on how to resign containers was made public by angerwound a long time ago, just no one's bothered to give the effort until somewhat recently.

Im glad that their efforts have been crushed. Its people like these two that should not be involved in ANY type of development, nor recieve any credit for their obviously inappropriate actions.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Ed_209
post Jun 29 2008, 10:56 PM
Post #10


X-S Senior Member
**

Group: Members
Posts: 245
Joined: 12-May 03
From: Central Florida
Member No.: 37448
Xbox Version: v1.0
360 version: unknown





Is this a tool to authenticate public gamesaves to work on your 360? If that's the case, I guess we are going to see a flood of people such as "StripClubDJ" that had a gamerscore of 120,000+. This will end up with Microsoft being more strict with how gamesaves are shared between consoles.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
TheSchonk
post Jun 29 2008, 11:46 PM
Post #11


X-S Expert
***

Group: Members
Posts: 562
Joined: 8-November 05
From: Florida
Member No.: 257173
Xbox Version: none
360 version: unknown





QUOTE(Ed_209 @ Jun 29 2008, 06:32 PM) *

Is this a tool to authenticate public gamesaves to work on your 360? If that's the case, I guess we are going to see a flood of people such as "StripClubDJ" that had a gamerscore of 120,000+. This will end up with Microsoft being more strict with how gamesaves are shared between consoles.

Im not sure if gamesaves is in the CON folder but it allows you to edit halo forge maps or whatever else is in there.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Yappadappadu1000
post Jun 30 2008, 01:30 AM
Post #12


X-S Young Member
*

Group: Members
Posts: 50
Joined: 4-January 04
Member No.: 88795



Would be great, if that way, I could use the same save games which I created for an earlier GT. Kinda sucks to have different save games for different profiles/GT's.
I'd also love it if that made it possible to download Top Spin 3 characters for those who are too lazy (read me) to play the career mode and are only interested in the online aspect of the game.

This post has been edited by Yappadappadu1000: Jun 30 2008, 01:32 AM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
JimmyGoon
post Jun 30 2008, 03:26 AM
Post #13


X-S Expert
***

Group: Members
Posts: 589
Joined: 15-June 04
Member No.: 125413
Xbox Version: v1.6
360 version: v1 (xenon)



Who is derived? Their email address appears in the source.
*edit* Found out myself. Nevermind.

This post has been edited by JimmyGoon: Jun 30 2008, 03:37 AM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Agent ME
post Jun 30 2008, 04:22 AM
Post #14


X-S Senior Member
**

Group: Members
Posts: 230
Joined: 8-May 05
From: CA, USA
Member No.: 219553
Xbox Version: v1.6
360 version: unknown





I know this is what lets hacked forge saves work for Halo3, so I assume now that all gamesaves are editable. I'm curious to see what this will bring with everyone able to mod things like forge saves (assuming they have the right hardware to interface to the HD or mem card), but I'm sure it's only a matter of time before we get hundreds of people with hacked gamerscores. (Even if you can't edit the profile directly, people could edit saves for games to mark that they should have an achievement or be right about to get achievements.)


But... ugh, where can we download it from? Is it at #xbins? The other site linked to needs registration...

This post has been edited by Agent ME: Jun 30 2008, 04:23 AM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
I'dkickurass@cod2
post Jun 30 2008, 05:36 AM
Post #15


X-S Young Member
*

Group: Members
Posts: 49
Joined: 10-September 06
Member No.: 299442



QUOTE(Iriez @ Jun 29 2008, 04:53 PM) *

Sorry, but superaison did not write this. He contacted me recently to tell me about his having it, and when I asked him if i could check it out he just responded with this:
"[13:06] superaison1: skatezero says :
[13:06] superaison1: Daniel =] - [-oh-em-gee--thats-hXc!-] says:
and dont give it out"

So apparentlly whoever daniel is (perhaps haxalot88) is the supposed 'author' of this tool. Please bear in mind that this tool was functional well over a year ago, with angerwound and 360gamesaves.net, just never public.

And as far as im concerned, anyone trying to SELL a tool that utilized public information is nothing but a complete low life. The information on how to resign containers was made public by angerwound a long time ago, just no one's bothered to give the effort until somewhat recently.

Im glad that their efforts have been crushed. Its people like these two that should not be involved in ANY type of development, nor recieve any credit for their obviously inappropriate actions.



Daniel is skate if u haven't figured that by urself by now. They both wrote it. He was obviously telling him not to give out their resigner to anyone. And no skate is not hax. Superaison has hardly anything to do with hax ever since he shelled his server and stole the SDK he had. Hax did not help in anyway with this. U do not have rock solid evidence to back up ur statement. All u are going by is what one person said. So u shouldn't be so hasty to yell out 'witch' in a matter of speaking.

FYI: superaison and skates resigner is sooo much better than derived's anyway. Rehashes, resigns, can change id's, saves ur id's, and has a keyvault already built in. =P

This post has been edited by I'dkickurass@cod2: Jun 30 2008, 05:44 AM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post





2 Pages V  1 2 >
Reply to this topicStart new topic

 

Lo-Fi Version Time is now: 21st November 2009 - 12:59 PM