M for Mature

New Xbox 360 Dashboard Update Patches Security Hole, Free60 Devs Advise Against Installing

by eXophase Mirror on Aug.11, 2009 at 4:20 pm, under Gaming, Xbox 360 | Thread ID: 5231
, , ,

mamexbox3602 New Xbox 360 Dashboard Update Patches Security Hole, Free60 Devs Advise Against Installing
The latest Xbox 360 dashboard update adds support for Microsoft’s Game on Demand service, but that isn’t all it does. According to Free60 project leads Felix Domke and Michael Steil, this update stealthily patches up a security hole that allows execution of unsigned code.

Apparently, “a complete end user compatible hack has been in development for some time” and will be distributed across public channels shortly according to the two devs. That translates to homebrew access for 360 owners who haven’t upgraded to the latest firmware.

Should be interesting to see how things develop. For those unaware, the last known Xbox 360 exploit was limited to an older kernel build that majority of folks already had upgraded past. Not for the technically squeamish, it also required users to connect to their 360 via serial port and have a copy of King Kong. This time around, it sounds like more people will benefit.

New Xbox 360 Dashboard Update Patches Security Hole, Free60 Devs Advise Against Installing - [eXophase.com]

 New Xbox 360 Dashboard Update Patches Security Hole, Free60 Devs Advise Against Installing

Comments

Filter comments by:
[ ] [ ] [ ] [ ] [ ] [ ]

  1. agentnnc

    Oh well...too bad I didn't know about that king kong thing earlier...


  2. eighty4

    Poor how they tell you not to update - after the update.


  3. yolarrydabomb

    crap!!!



    wait this is good, my other xbox is being repair. I hope they don't get me the latest update.


  4. Lachrymose

    Sweet!! I didn't update mine yet, but I have 2 so I can just use the one I didn't update.

    I really wish a POC video would be released or something.


  5. eighty4

    Also, the project has been being worked on for 3 years with no release, and when you use this - you can't use Xbox Live. Hopefully another year will follow with better updates. :D


  6. Pokemanz master

    Dose anyone else dislike the new game rateing system?
    Such a game can be rated bad by fanboy,then when you're suggest new game its always going be high rep stuff.


  7. x3sphere

    These are the facts from tmbinc:

    We kept on working on this idea, and it worked out. pretty well. We use JTAG to program the DMA target addr, and then SMC to trigger the DMA read. The exploit itself is based on the old 4532 exploit.

    The magic is how we launch 4532 - there is a "backdoor" for manufacturing since CB 1920. We have been able to restore the newer CD versions for all hardware types.

    This means:
    - We can boot own code in HV context ~5s after boot, before any video output, right after the kernel runs.
    - we need to reflash the flash, and add 3 resistors for the JTAG (no modchip required! but you might want a dual-nand modchip),
    - 8498 kills this by updating the bootloader - it blacklists 4532/4548. it also does hw init stuff which might interefere with the jtag hack, we don't know yet.
    - we have a proof of concept hack, we will release it SOON (a matter of hours/days, not more - promised.).
    - DON'T UPDATE to summer 09. Did i already say this?
    - you don't need to know your cpu key. You can update to all BUT summer '09. you don't need a dvdrom.
    - It works on all xenon, zephyr, falcon, opus, jasper. Unless you have updated to 849x. Then you're screwed.


    It sounds like the hack is not purely software based - seeing as he's talking about adding resistors.

Login with your username and password below. New User?





Looking for something?

Use the form below to search the site:

Still not finding what you're looking for? Drop a comment on a post or Contact Us so we can take care of it!

Visit our friends!

A few highly recommended friends...