View Single Post
  #1  
Old 12-12-2005, 05:25
Sabor Sabor is offline
Friend
 
Join Date: Sep 2005
Posts: 68
Rept. Given: 0
Rept. Rcvd 3 Times in 3 Posts
Thanks Given: 0
Thanks Rcvd at 2 Times in 2 Posts
Sabor Reputation: 3
xbox unhackable..?

Apparantely, its suppose to be generically unhackable. See article..
http://arstechnica.com/news.ars/post/20050910-5296.html

However, since its release , a full game dumper has been made and released via underground group PI. Also posts such as this have been popping up.
http://www.xboxhacker.net/forums/index.php?topic=57.0

Now with MS's track record on piracy and security how long will they last? Unhackable? Hm.. dont think so. Lets see how long it lasts. Now question here, anybody have any ideas on how to approach this hack, as the checksums are within the actual cpu core.

"possible attack
HV code can read itself, and can read unencrypted data in RAM, like
plaintext hashing
change single bits -> destroy 16 bytes in hypervisor
at system call address
SC
illegal instruction
do this over and over again
might be a jump instruction
32 MB of NOPs then out code
destroy
hope that it's jump
there can be no protection if network writes
because security system is in the CPU
this needs to work ONCE to dump the Hpossible attack
HV code can read itself, and can read unencrypted data in RAM, like
plaintext hashing
change single bits -> destroy 16 bytes in hypervisor
at system call address
SC
illegal instruction
do this over and over again
might be a jump instruction
32 MB of NOPs then out code
destroy
hope that it's jump
there can be no protection if network writes
because security system is in the CPU
this needs to work ONCE to dump the HV"

this was the posters suggestion. The key to this is dumping HV and understanding points of attack.
Reply With Quote