Tilted Forum Project Discussion Community  

Go Back   Tilted Forum Project Discussion Community > Interests > Tilted Gaming


 
 
LinkBack Thread Tools
Old 06-14-2003, 11:26 AM   #1 (permalink)
Pro Libertate
 
Location: City Gecko
WTF is this "Download new content" to my XBOX...

All,
Lookin' for a bit of help, I just ran up my connx to the web for the first time in a month.

I have recently rerouted my broadband thru private IP on DHCP and my XBOX wouldn't let me connect till I let "them" download something to my "box"...

Now I know I am para', but I won't let some thing go to my PC unless I know whats going on (generally).

Does anyone know what updates happened between 14/05/03 and 14/06/03 in microsoft Xbox line?

I don't wanna hack it 2 find out (yet)...
__________________
[color=bright blue]W[/color]e Stick To Glass

"If three of us travel together, I shall find two teachers."
Confucious

Mad_Gecko is offline  
Old 06-15-2003, 05:57 AM   #2 (permalink)
Upright
 
I doubt you can get details on what updates have been sent out.
I have yet to see any sort of revision history list for any xbox game, which kinda sucks.
Did you have to do the updates to Live itself or to a game? If its a game, its most likely just a patch/update. If its to Live, who knows...
heh.
geeky is offline  
Old 06-15-2003, 06:29 AM   #3 (permalink)
Pro Libertate
 
Location: City Gecko
It was to get onto Live, I guess I'll have to live with the fact the Mr. Gates is really intrusive.

Argh...
__________________
[color=bright blue]W[/color]e Stick To Glass

"If three of us travel together, I shall find two teachers."
Confucious

Mad_Gecko is offline  
Old 06-23-2003, 11:40 PM   #4 (permalink)
Banned
 
Location: OlyWa
maybe he was just trying to make it run better? or steal your sould... maybe both...
Ogre840 is offline  
Old 06-24-2003, 05:37 AM   #5 (permalink)
Oracle & Apollyon
 
Prophecy's Avatar
 
Location: Limbus Patrum
Live is getting a complete overhaul. Live 2.0 should be released in the nxt month or so. As far as I know though, M$ said they were gonna update Live but haven't said what that means. Hope u figured out what that did your box. Check the game memory perhaps...
__________________
La Disciplina È La Mia Spada,
La Fede È Il Mio Schermo,
Non salti Ciecamente In Incertezza,
E Potete Raccogliere Le Ricompense.
Prophecy is offline  
Old 06-25-2003, 12:35 PM   #6 (permalink)
Pro Libertate
 
Location: City Gecko
Proph

Would do if I knew how.. Just got a move in my job so I'm findin' less time to post here, and even less to fool around with my Xbox.

Although might have a look over the long weekend coming up. With a hangover I might just be pissed enough to fuck around in the console.
__________________
[color=bright blue]W[/color]e Stick To Glass

"If three of us travel together, I shall find two teachers."
Confucious

Mad_Gecko is offline  
Old 06-25-2003, 11:24 PM   #7 (permalink)
Crazy
 
Consoles were not made to have a "download new content" feature. What's up with that?
__________________
-radonman
radonman is offline  
Old 06-28-2003, 02:19 AM   #8 (permalink)
Upright
 
Location: Michigan, US of A
my guess is partly because the xbox functions as a small computer, above and beyond the gaming capabilities.
AngelofDeathXbl is offline  
Old 07-04-2003, 03:15 AM   #9 (permalink)
Pro Libertate
 
Location: City Gecko
UPDATE:

Well, I guess I'll be getting another "download" from Microsoft .

XBOX Security

-= Security Advisory =-



Advisory: XBOX Dashboard local vulnerability
Release Date: 2003/07/04
Last Modified: 2003/07/04
Author: Stefan Esser [se@nopiracy.de]

Application: Microsoft XBOX Dashboard (up to today)
Severity: A vulnerability within the XBOX Dashboard allows to
totally compromise the security features of the XBOX.
Risk: Critical
Vendor Status: Vendor is not willing to talk about XBOX vulnerabilities.


Overview:

The XBOX Dashboard is what appears when you turn the XBOX on without a
disc in the DVD drive. It will let you adjust system settings, manage
your save games, play and rip audio CDs and configure your XBOX Live
account. It is the heart of the XBOX and its most vulnerable point,
because it lacks several security restrictions which are enforced on
games. This includes the lack of the reboot-on-eject-button "feature",
which is obligatory for all games.

The existance of an exploitable vulnerability within the dashboard could
totally compromises the XBOX security system. It will make the box
independent from Microsoft signed code and therefore this information is
released to the public now on the 4th of July 2003, the day of the XBOX
Independence.


Details:

Microsoft knows that a vulnerability within the XBOX dashboard could
have serious impact. This is underlined by the fact that the dashboard
checks most of its files against an internal stored SHA1 hash value
before it uses them.

For an unknown reason this check is not performed on the audio (.wav)
and font (.xtf) files. Unfourtunately for Microsoft there exists an
exploitable integer underflow vulnerabilitiy within the font file loader
which can be exploited with a malformed font file. When the XTF header
is processed the dashboards reads a 4 byte blocksize field from the font
file. This is expected to represent the size of some datablock including
the 4 bytes of the size field itself. The blocksize is then allocated
and the sizefield is copied into the beginning of the buffer. This is
already a possible overflow bug when the field contains the values 0..3.
Due to memory alignment this is not exploitable. But then the blocksize
is decreased by 4 because the dashboard wants to read the rest of the
block into memory. Obviously values of 0..3 will underflow when
decreased by 4 and this results in the dashboard wanting to read up to
~4 gigabytes of data from the font file in a f.e. 3 bytes buffer.

Because the XBOX malloc()/free() implementation is also storing control
information inbound and is similiar to the Windows 2000/XP heap
allocators this bug is exploitable and allows execution of arbitrary
code. The attached proof of concept code shows that exploiting is
possible with offsets that are equal on all dashboards and XBOX versions
known.

BTW: the dashboard loads its font files directly after the XBOX start
animation. This means the exploit does not need any user
interaction and when the code is executed only part of the
dashboard background is on screen.


Proof of Concept:

Attached you will find a proof of concept exploit which will start
linux. To install it you have to rename the 2 XBOX font files within the
font directory of the dashboard partition and then copy ernie.xtf and
bert.xtf into this directory. (If you have an XBOX with an older
dashboard the font directory does not exist and you must do the renaming
and file adding work in the main directory). Once the new fonts are in
place you copy the default.xbe (which is a copy of xbeboot) into the
main directory and add your favourite linux to it.


Trustworthy Computing:

Trustworthy Computing at its best. Nearly 2 Years ago I reported an SSL
vulnerability within IE to Microsoft. 1 month later I released
information about this bug to the public because MS did absolutely
nothing. The vulnerability was nearly forgotten, it only exists on the
list of 19 unpatched IE vulnerabilities anymore. But this is wrong, the
vulnerability was indeed fixed with one of the many IE patches in the
middle of last year. Well is secretly fixing bugs without an official
advisory trustworthy?


Anticipated Questions:

Q1: How do I get the files onto the harddisk?

A1: There are several ways. You could f.e. install the files with the
Mechassault or 007 hacks. This requires one of the games and the
files on a memorycard. The other way is to open the box and do the
harddisk swap trick which is described all over the net.


Q2: This vulnerability is in the dashboard, isn't it? So Microsoft can
simply update the dashboard with XBOX Live or with the help of new
games.

A2: Yes Microsoft could try to upgrade the dashboard and fix the
vulnerability with such an update, but keep in mind that this
vulnerability is like a "local root" hole. You can do nearly
everything with it and this includes redirecting reads and writes to
the xboxdash.xbe file. Additionally people who do not play games on
their box will not be reachable with such updates. And groups who
pirate games can always disable the update feature.


Q3: Well but MS can make the kernel block the vulnerable dashboard.

A3: Indeed they can. But until boxes with new kernels reach the market
we will have the end of this year (You can still get 1.0 boxes in
shops over here) and they can only fix the bugs they know about.


Q4: Is it possible to play "backed-up" games with this?

A4: Yes it is possible to play pirated games by using this vulnerability
but my proof of concept code will not allow this. You have to change
the exploit to patch the kernel in memory. This is not very hard and
I am not going to help you with this.


Q5: Can I go "Live" with this hack?

A5: You have full control over the box with this vulnerability. You can
modify the exploit to allow XBOX Live playing but this will only
start a cat & mouse game with Microsoft.


Q6: I have read that I can solder my mainboard with this hack...

A6: This exploit has nothing to do with soldering, It will just run
everything you want on unmodded (and even unopened) XBOXes. Infact
when this hack is installed you do not need to solder anything to
get your homebrew or whatever applications to run.
__________________
[color=bright blue]W[/color]e Stick To Glass

"If three of us travel together, I shall find two teachers."
Confucious

Mad_Gecko is offline  
 

Tags
content, download, wtf, xbox


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On



All times are GMT -8. The time now is 11:00 AM.

Tilted Forum Project

Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2024, vBulletin Solutions, Inc.
Search Engine Optimization by vBSEO 3.6.0 PL2
© 2002-2012 Tilted Forum Project

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 95 96 97 98 99 100 101 102 103 104 105 106 107 108 109 110 111 112 113 114 115 116 117 118 119 120 121 122 123 124 125 126 127 128 129 130 131 132 133 134 135 136 137 138 139 140 141 142 143 144 145 146 147 148 149 150 151 152 153 154 155 156 157 158 159 160 161 162 163 164 165 166 167 168 169 170 171 172 173 174 175 176 177 178 179 180 181 182 183 184 185 186 187 188 189 190 191 192 193 194 195 196 197 198 199 200 201 202 203 204 205 206 207 208 209 210 211 212 213 214 215 216 217 218 219 220 221 222 223 224 225 226 227 228 229 230 231 232 233 234 235 236 237 238 239 240 241 242 243 244 245 246 247 248 249 250 251 252 253 254 255 256 257 258 259 260 261 262 263 264 265 266 267 268 269 270 271 272 273 274 275 276 277 278 279 280 281 282 283 284 285 286 287 288 289 290 291 292 293 294 295 296 297 298 299 300 301 302 303 304 305 306 307 308 309 310 311 312 313 314 315 316 317 318 319 320 321 322 323 324 325 326 327 328 329 330 331 332 333 334 335 336 337 338 339 340 341 342 343 344 345 346 347 348 349 350 351 352 353 354 355 356 357 358 359 360