Advertisement
Help Keep Boards Alive. Support us by going ad free today. See here: https://subscriptions.boards.ie/.
If we do not hit our goal we will be forced to close the site.

Current status: https://keepboardsalive.com/

Annual subs are best for most impact. If you are still undecided on going Ad Free - you can also donate using the Paypal Donate option. All contribution helps. Thank you.
https://www.boards.ie/group/1878-subscribers-forum

Private Group for paid up members of Boards.ie. Join the club.

Xbox 360 Reset Glitch Hack - Unsigned Code on current Kernels incl. X360 SLIM

  • 28-08-2011 04:22PM
    #1
    Posts: 2,032 ✭✭✭ [Deleted User]


    Wow :D


    The reset glitch in a few words
    ===============================

    We found that by sending a tiny reset pulse to the processor while it is slowed down does not reset it but instead changes the way the code runs, it seems it's very efficient at making bootloaders memcmp functions always return "no differences". memcmp is often used to check the next bootloader SHA hash against a stored one, allowing it to run if they are the same. So we can put a bootloader that would fail hash check in NAND, glitch the previous one and that bootloader will run, allowing almost any code to run.
    http://libxenon.org/index.php?topic=145.msg614


«1345

Comments

  • Closed Accounts Posts: 33,733 ✭✭✭✭Myrddin


    Aw, now I'm not gonna be l33t cuz I have a jtag :(

    Poor MS!


  • Registered Users, Registered Users 2 Posts: 8,581 ✭✭✭TouchingVirus


    It. Has. Happened!? OMG!

    *drools*


  • Closed Accounts Posts: 33,733 ✭✭✭✭Myrddin


    Whats the c-mod pcb thingy?


  • Registered Users, Registered Users 2 Posts: 1,686 ✭✭✭RealistSpy


    More Info:
    This hack cannot be patched :)

    But at the moment you cannot play any backup, just any applications compiled under LibXenon


  • Registered Users, Registered Users 2 Posts: 1,914 ✭✭✭megaten


    Looking forward to this maturing. I don't really use my xbox and it'd make a great emulation machine.


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 8,581 ✭✭✭TouchingVirus


    RealistSpy wrote: »
    More Info:
    This hack cannot be patched :)

    I'm curious as to why the bootloader (CB) can't be patched so that memcmp returns the actual memcmp value, and not "no difference" all the time. Unless the reason memcmp is returning no difference is because of the glitch, if so then epic win :P
    But at the moment you cannot play any backup, just any applications compiled under LibXenon

    Good. Doubtless there are already smart people thinking how to get FreeBOOT running though :P


  • Registered Users, Registered Users 2 Posts: 8,581 ✭✭✭TouchingVirus


    I just read through it all there, absolutely epic stuff from the researchers, really. It is astonishing they were able to figure it all out and yes, it appears there is no way to patch this.

    The CPLD starter kit is rather pricey, and it's getting used every time the glitch happens so I'm going to wait until there's a smaller ARM/PIC version and then I'll get soldering. Fawking SWEEEEEEEEEEET!


  • Closed Accounts Posts: 33,733 ✭✭✭✭Myrddin


    it appears there is no way to patch this.

    I've heard that far too many times in Sony circles, MS will come up with something I'm sure. Though they're tipped to annouce the 360's successor at next years E3 so they may not invest too heavily in fixing this if it proves so.


  • Registered Users, Registered Users 2 Posts: 8,581 ✭✭✭TouchingVirus


    There might be a way to fix it, but it involves changing CB at the very least. So in other words, don't update :D But it's opened up pretty much all consoles to Xell/Homebrew, we're back to 2009 again :P


  • Closed Accounts Posts: 33,733 ✭✭✭✭Myrddin


    There might be a way to fix it, but it involves changing CB at the very least. So in other words, don't update :D But it's opened up pretty much all consoles to Xell/Homebrew, we're back to 2009 again :P

    Indeed, I wonder how long it'll take before we see the likes of FSD on a slim? Not long given how smart some of these guys are. That really came outta the blue!


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 8,581 ✭✭✭TouchingVirus


    EnterNow wrote: »
    Indeed, I wonder how long it'll take before we see the likes of FSD on a slim? Not long given how smart some of these guys are. That really came outta the blue!

    A real team effort over on XBH it seems, completely out of the blue though with no hints or "preview videos" or anything. Love the info dump :pac:


  • Registered Users, Registered Users 2 Posts: 808 ✭✭✭Jimbobjoeyman


    Wahey :D
    I knew it would eventually happen

    downside-there goes the jtag trade with its ridiculous prices

    edit-just looked at the install -thats some delicate soldering in places (makes the jtag hack look like childsplay).
    But Im going to do this to my jasper once this hack matures a bit more and theres more info on it
    Sickened xenons aren't compatible though


  • Registered Users, Registered Users 2 Posts: 1,582 ✭✭✭docentore


    finally something new to do.

    I'm going to deeper study it after my dissertation. can't wait!


  • Registered Users, Registered Users 2 Posts: 1,582 ✭✭✭docentore


    The CPLD starter kit is rather pricey, ...

    not really if you shop around. Farnell has one for £35 and I just found this. Time to buy one before they will be sold out!


  • Registered Users, Registered Users 2 Posts: 8,581 ✭✭✭TouchingVirus


    docentore wrote: »
    finally something new to do.

    I'm going to deeper study it after my dissertation. can't wait!

    Hope it's going well for you docentore :) Thanks for the link too ;)
    downside-there goes the jtag trade with its ridiculous prices

    A JTAG takes at least 2 hours to do between disassembly, soldering the nand, reading the nand, writing the nand, soldering the JTAG, testing and reassembly. Some boards are fussy and take much longer, I've had boards take me 5 hours trying this and that because the regular way doesn't work. This is free time, and I don't know about you but I'm not working in my spare time for free, or even remotely near minimum wage.
    Sickened xenons aren't compatible though

    Me too, but I have Jasper I can try it on :D


  • Closed Accounts Posts: 2,828 ✭✭✭Reamer Fanny


    Great news a little more than a year since the Slims release and they have already managed to crack it open


  • Registered Users, Registered Users 2 Posts: 8,581 ✭✭✭TouchingVirus


    Ordered a JTAG programmer and two C-mod boards (same ones used by the libxenon folks) so I've got one spare if anybody feels up for a challenge - PM me :)

    *Edit: Mods - if this breaks any rules or lies borderline, then work away. I'll post it for sale on adverts instead [when it arrives]*


  • Closed Accounts Posts: 2,828 ✭✭✭Reamer Fanny


    Ordered a JTAG programmer and two C-mod boards (same ones used by the libxenon folks) so I've got one spare if anybody feels up for a challenge - PM me :)

    *Edit: Mods - if this breaks any rules or lies borderline, then work away. I'll post it for sale on adverts instead [when it arrives]*

    First in line when it arrives how much did you get them for?


  • Registered Users, Registered Users 2 Posts: 8,581 ✭✭✭TouchingVirus


    Total price was €64 for two C-mod boards and the JTAG3 LPT programmer - USB XilinX programmers are definitely not cheap at €45+. Taking off the price of the JTAG3 cable, and splitting the costs down the middle it works out at €26.50 inc shipping each.

    Obviously ordering in bulk is the thing to do as shipping wasn't cheap but there's not much point in ordering lots as I'd say there are people converting it to work on other cheaper setups and Xecutor will likely come up with a nice fancy PCB job soon. I just couldn't wait :D


  • Registered Users, Registered Users 2 Posts: 1,582 ✭✭✭docentore


    I'm just after going through ebay and other sites in search for cheap jasper/slim with broken dvd etc. There are some cheap slim mobos on fleabay. Might pick up one to play around with it


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 8,581 ✭✭✭TouchingVirus


    I thought about that too but it'd be dodgy enough buying a slim mobo on ebay - never know what some guy has done to it like heatgunned the crap outta it :D

    I have a Jasper on the latest dash I'm going to test this on, got my eye out for somebody willing to loan me their slim too :P
    Thank you for your order.

    Because of an unexpected great demand for C-Mod we have a delivery bottleneck. At the moment we can't say a deliver time.
    We hope that we know more until tomorrow and inform you about a delivery time than.

    Your credit card reservation has not been booked yet.

    Thank your for understanding.

    Best regards

    LOL! :D


  • Registered Users, Registered Users 2 Posts: 8,581 ✭✭✭TouchingVirus


    FFplay360 was released - a homebrew media player based on ffmpeg that'll play 720p and they're working on 1080p too. This week just gets better!

    *Edit:* With the board being out of stock I might be able to amend my order to add more people on and split the cost better. Failing that I'll just go to the supplier myself, they deal with the public but it takes a bit longer for delivery. So yeah, if you're in any way interested in jumping on the early glitch train, PM me :)


  • Registered Users, Registered Users 2 Posts: 14,308 ✭✭✭✭wotzgoingon


    This is brilliant news! EPIC!


  • Closed Accounts Posts: 17,661 ✭✭✭✭Helix


    any relation between this and the new banwave thats just kicked off?


  • Closed Accounts Posts: 33,733 ✭✭✭✭Myrddin


    Helix wrote: »
    any relation between this and the new banwave thats just kicked off?

    Unlikely surely? Seeing as it cannot run backups at the moment it wouldn't be of interest to most of the folks the banwave would be targeting...


  • Registered Users, Registered Users 2 Posts: 8,581 ✭✭✭TouchingVirus


    Cmod supplies just dried up until October ... o_O :eek:


  • Closed Accounts Posts: 2,828 ✭✭✭Reamer Fanny


    Cmod supplies just dried up until October ... o_O :eek:

    Oh no! :O


  • Registered Users, Registered Users 2 Posts: 8,581 ✭✭✭TouchingVirus


    It's all right, I just trawled through a thread over on TX that said they've designed a Nand-x Add-on (like the Probe is an Add-on to the CK3) already. I guess the next stage is production of a few boards, testing, refinement and mass production. Should be seeing low-cost activity by then, and there'll probably be a rebooter available too :D


  • Closed Accounts Posts: 2,828 ✭✭✭Reamer Fanny


    It's all right, I just trawled through a thread over on TX that said they've designed a Nand-x Add-on (like the Probe is an Add-on to the CK3) already. I guess the next stage is production of a few boards, testing, refinement and mass production. Should be seeing low-cost activity by then, and there'll probably be a rebooter available too :D

    So TX have jumped on the glitch hack?


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 1,582 ✭✭✭docentore


    justryan wrote: »
    So TX have jumped on the glitch hack?

    thats excellent news for them. No more solutions one box for multiple consoles. They can sell thousands of modchips again


Advertisement