xbox-scene.com - your xbox news information source
Quick Links: Main Forums | Xbox360 Forums | Xbox1 Forums | PS3 Forums
Xbox-Scene Forum Help  Search Xbox-Scene Forums   Xbox-Scene Forum Members   Xbox-Scene Calendar

Giganews Usenet Offers: +1150 days binary retention, 99%+ Completion, and Unlimited Speed/Access!

360 ODD Emulators: X360 Key $99 | Wasabi360 FAT $99 | Wasabi360 Slim $99
C4E's iXtreme Burner MAX Drive: LiteOn iHAS124 DROPPED TO JUST $17


Welcome Guest ( Log In | Register )

 Forum Rules Rules
> Warning: Consoles Still Connect To Xbox Live Despite Family Settings, Confirmed by sniffing outgoing UDP network traffic
Kiewee123
post Jul 29 2010, 08:09 PM
Post #1


X-S Young Member
*

Group: Members
Posts: 54
Joined: 4-December 08
From: UK
Member No.: 398062
Xbox Version: unk
360 version: v3.0 (falcon)



I can confirm that only enabling restrictions 'Xbox LIVE Access' and 'Xbox Live Membership Creation' in 'Console Control' (in Family Settings) is NOT adequate protection for your Jtag flashed console.

I sniffed outgoing connections whilst running an Xbox1 game (this is in FSD if anyone is interested) because I was curious as to why I was greeted with 'you need to update' despite not being logged in to any profile, let alone on xbox live. This message would disappear if I removed the Ethernet cable (used to update FSD + FTP on LAN).

The console successfully connects to 65.55.42.183 using the kerbose service (handshake?), then connecting again afterward on 65.55.42.180 on UDP port 3074. The IP range 65.55.42.* is owned by Microsoft Corp, and is located in Bellevue in the US.

Evidently, despite the suggested precautions, our consoles are still capable of connecting online beknown to us. Microsoft could quite easily pull one off again and 'surprise us', as they did with the Ixtreme banning, with a forced update or such.

I highly suggest you either block all outgoing/incoming WAN traffic on your console's MAC address, or remove the ethernet cable entirely, particular if your console's R3T6 resistor has not been removed/shorted.

Finally, exercise extreme caution in all future updates, 9199 onwards. Microsoft could quite easily not only impose a ban on your Xbox LIVE account and console, but could remove your console's exploitabilty therefore rendering your jtag useless.

I thought I aught to share my findings with the community - please share your thoughts, I hope someone can prove me wrong.

This post has been edited by Ranger72: Aug 1 2010, 09:33 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
 
Reply to this topicStart new topic
Replies
brandogg
post Aug 1 2010, 07:19 AM
Post #2


X-S Messiah
*******

Group: Members
Posts: 3091
Joined: 24-October 02
Member No.: 5972
Xbox Version: v1.6
360 version: v4.0 (jasper)



I've run FSD on my JTAG'ed Jasper, and XBL is blocked in the family settings. This console is connected to my home network 100% of the time - I can still install to NXE the regular way, my profile and HDD work fine on other consoles. I'm pretty sure it's just the dashboard saying, "Hey Xbox Live, are you awake?" and Xbox Live replying "Yep!" I don't think your console is sending any specific information to the service, especially if you don't have any XBL accounts on the HDD at all (I don't), since you have not agreed to the XBL TOS if you don't have a Live account.
User is offlineProfile CardPM
Go to the top of the page
+Quote Post
Haygar
post Aug 1 2010, 02:35 PM
Post #3


X-S X-perience
**

Group: Members
Posts: 471
Joined: 19-November 06
From: Australia
Member No.: 312258
Xbox Version: v1.1
360 version: v3.0 (falcon)



QUOTE(brandogg @ Aug 1 2010, 04:19 PM) *

I've run FSD on my JTAG'ed Jasper, and XBL is blocked in the family settings. This console is connected to my home network 100% of the time - I can still install to NXE the regular way, my profile and HDD work fine on other consoles. I'm pretty sure it's just the dashboard saying, "Hey Xbox Live, are you awake?" and Xbox Live replying "Yep!" I don't think your console is sending any specific information to the service, especially if you don't have any XBL accounts on the HDD at all (I don't), since you have not agreed to the XBL TOS if you don't have a Live account.



QUOTE(old engineer @ Aug 1 2010, 10:03 PM) *

This should be stickied.

Either way we need to build up a clear picture of what has happened and could happen.

@ Maximize: You say u got banned in 15 seconds. Do u know the entire history of your jtag? Did u mod it yourself/never used it online? ...It's strange that your ban doesn't corrupt saves/achievement's between consoles, a 'normal' ban would corrupt data/not sign off trusted content.

...Have you redumped your NAND and checked the secdata to compare before and after?
What brandogg said makes sense, i.e. the 'yes I'm alive' handshake, but without any h/w or user specific console data going out/in.
I really hope you guys are right !!! But are'nt we being a bit naive thinking that no console specific info is being transfered?

Does anyone know how we could check/interpret the traffic while in this idle state?

This post has been edited by Haygar: Aug 1 2010, 02:42 PM
User is offlineProfile CardPM
Go to the top of the page
+Quote Post

Posts in this topic
Kiewee123   Warning: Consoles Still Connect To Xbox Live Despite Family Settings   Jul 29 2010, 08:09 PM
inspuration   I can confirm that only enabling restrictions ...   Jul 29 2010, 08:27 PM
Inuyasha152   Interesting. If people still wanted to download ce...   Jul 29 2010, 09:00 PM
Maximize   is 3074 the port the xbox 360 uses? Id it possibl...   Jul 29 2010, 09:15 PM
Kiewee123   I too tried blocking certain ports, but this is st...   Jul 30 2010, 11:31 PM
ketty_yijun   So I came to this conclusion - the best way to b...   Nov 15 2010, 11:14 PM
stevec25   Thank you very much for taking the time to sniff a...   Jul 30 2010, 11:37 PM
Maximize   Ok I did some more to try to disable my connection...   Jul 31 2010, 03:11 AM
brandogg   Does this only happen if you launch the game from ...   Jul 31 2010, 07:01 AM
Spegs12   I thought this was the case. Had an unbanned jtag ...   Jul 31 2010, 07:12 AM
Haygar   Thats exactly what I feared and stupidly removed t...   Jul 31 2010, 09:29 AM
Kiewee123   Thats exactly what I feared and stupidly removed ...   Jul 31 2010, 09:51 PM
Maximize   yeah I pretty sure they have consoles search for a...   Jul 31 2010, 05:49 PM
Maximize   ok I can still copy games to hdd, can still play ...   Jul 31 2010, 11:51 PM
ZerOneX   ok I can still copy games to hdd, can still play...   Nov 6 2010, 10:52 PM
old engineer   This should be stickied. Either way we need to b...   Aug 1 2010, 01:03 PM
thwack   Agree it should be stickied. AFAIK when a JTAG get...   Aug 1 2010, 02:46 PM
Maximize   the console wasnt modded or jtagged when I bought ...   Aug 1 2010, 05:54 PM
thwack   9199 just restores the 360's ability to save t...   Aug 1 2010, 06:07 PM
Kiewee123   Yes, the first connection is indeed a handshake as...   Aug 1 2010, 08:21 PM
GISJason   Try #FreeStyleDash on EFNet ;)   Aug 1 2010, 10:10 PM
Kiewee123   Try #FreeStyleDash on EFNet ;) I'll get at ...   Aug 2 2010, 12:53 AM
Mattie   I'll get at them tomorrow afternoon - it...   Aug 3 2010, 12:22 AM
Kiewee123   We're on the forums too :P NTP goes to pool.n...   Aug 3 2010, 02:23 PM
Aldanga   I know of consoles that haven't ever connected...   Sep 13 2010, 12:44 AM
dotfortun3   I am no lawyer, nor do I claim to know anything ab...   Oct 25 2010, 05:32 PM
LiTHiUM0XiD3   from what i can gather... u own the hardware... u ...   Nov 3 2010, 03:43 AM
jockthecock   I doubt anyone one get banned for connecting to li...   Nov 5 2010, 03:06 PM
danthaman673   The new TOS allows for silent updates! If the ...   Nov 7 2010, 05:33 AM
mechgamer123   sorry to gravedig here, but is there a list of dom...   Feb 18 2011, 09:41 PM
Magimaster   Sorry if this is a stupid question but, is the new...   May 6 2011, 05:04 PM
x Yo1nK x   im sure dashlaunch doesn't block live in the l...   May 6 2011, 07:46 PM
Magimaster   im sure dashlaunch doesn't block live in the ...   May 7 2011, 10:10 AM
firebuddie   For what it's worth...I am another poor sucker...   Sep 15 2011, 02:06 PM
Morning Call   im unsure why you guys arent just blocking the por...   Oct 3 2011, 10:56 PM
filter4ever   Remove or bypass R6T3! Castrate the bitch. M...   May 1 2013, 01:59 AM






Reply to this topicStart new topic

 

Lo-Fi Version Time is now: 19th June 2013 - 09:47 AM