Xbox 360 downgrading from any kernel without CPU-Key now possible

Posted Aug 24, 2007 at 3:34AM by QJ Staff Listed in: Xbox 360 Tags: Custom Firmware, Linux, robinsod
Ó


Downgrading an Xbox 360 from any Kernel without CPU-Key now possible - Image 1Downgrading your Xbox 360 firmware from any Kernel without using your CPU key used to be just a legend. However, some enterprising hackers on the xboxhacker.net had plans on doing just that.

After much thought they were able to successfully do so using a method that has been dubbed a "timing attack". A hacker by the handle Robinsod managed to successfully boot his Xbox360 using a flashed eFuse with kernel 1888.

While less experienced (and less daring) individuals might not be able to do this for now, the hackers are currently working on a way to simplify the process.

Here's a little quote from Robinsod explaining how the process works:

The timing attack does not try to "bruteforce" the cpu key itself. It tries to find/bruteforce a hash value which is a result of the usage of the cpu key (so even if you have that hash you still cannot backwards compute the cpu key). But finding this hash value (I usually refer to it as the CB-auth value) will enable the xbox to boot the original kernel (v 1888).


This then allows you to upgrade to a vulnerable kernel (eg 4532) and THEN you can extract the cpu key using the kk exploit. Since -on average- you will find the correct value at roughly half of the possible byte values you only need to try (approx) 128 values for each of the 16 bytes.


Thats why vax is talking about 16 * 128 total number if byte changes... There is a theoretical minimum to the reboot time of about 1 second. So in theory you could find the 16 bytes in 34 minutes. Thats probably not gonna happen. Grin And installing the hardware will probably take even more time so its not a really big issue. But this is basically where the time speculations are based on.


This could be good news for the hacking community considering that further refinements on this technique will eventually lead to homebrew, Linux, and possibly even custom firmware for the Xbox 360. For more details on this, feel free to click on our read link which will send you to the forums where this was announced.


 
 
 

Comments [refresh]

by .. - 2007-08-23 22:48
» ..

Sounds good, I can bet MS already knows about this and will be putting up measures to ban the hackers. Seriously though they're so sad, why not put your skills to some use? Have some fun developing an XNA game instead of making *****ty hacks which no one will use..

by gfhgfh - 2007-08-23 22:59
» Bioshock worth every penny

Yer who cares anyway, with games like Bioshock and Blue dragon relesed today I will be buying both.

The quality of the 360 games are now by far the best and with the Elite released today in Europe etc it will be a good time ahead for the 360 owners..

by Devise - 2007-08-23 23:23
» ...

I understand what you are saying and why you are saying that but you are wrong.



The homebrew community went nuts with the original xbox and XBMC (Xbox Media Center) turned out to be an amazing good application which I still use today. The only problem is the original xbox isn't powerful enough to stream high definition video format well enough to enough them. Hopefully they can get it going on the 360. Plus all the emulators like SNES, N64, MAME, PS1 etc...You just can't do that stuff with XNA.

by AoxomamoxoA - 2007-08-24 03:00
» MAMEs

if you wanted to play MAME games, why not download them onto your PC and play with a 360 controller? Its the same thing, and you wont get a bricked console when MS patch the hole.

by Devise - 2007-08-24 03:12
» ...

Cause you can sit on the couch with your friends and play multiplayer on a big screen tv.

by Lemony Vengeance - 2007-08-24 04:12
» Thanx

[Sarcasm] Thank you for giving me credit for tiping you off on this... [/Sarcasm]

by tank - 2007-08-24 07:10
» jb jhb

who gives a slimy ***** whether u can downgrade, pointless or what

by Bob - 2007-08-24 07:48
» Downgrading

I belive this is good news for the 360 owners that have been black listed, they may be able to get back on live. My console is still 100% working with no hacks. But I think microsoft cut their own throats by banning tyhe consoles, they cannot get any money from XBOX Arcade, remeber you have to buy points to buy games online. With a hacked or banned unit, you simply cannot log in to get any of these games. If home brew does come out, then the XBOX Arcade will plummet down to zero.



Well thats my thoughts anyway.



Have fun everyone!!



Bob

by Dirty Hacker - 2007-08-24 08:21
» If one were really devilish

you could spoof other ppls Xbox serial numbers and get them banned off of Live

by Spectre - 2007-08-24 08:23
» LMAO

Noobs. Why do you think XBLA is going to suffer? What makes you think M$ won't just allow you to get on, make a purchase, and not allow you to play the game? It's in their terms that you can't modify a console, so you're at risk although you may be benefiting in the short-run.



M$ will take the same approach Sony did for the PSP hackers and threaten the hackers...they'll soon do what they have to.



I hope the hackers allow the playback of XBlowx711 images/roms. Soon everyone will have pirated versions of all leaked games, and it will surely become the next Dreamcast. ROFL! I remember when so many noobs thought the DC was going to kill the PS2....

by Spectre - 2007-08-24 08:48
» LMAO

Noobs. Why do you think XBLA is going to suffer? What makes you think M$ won't just allow you to get on, make a purchase, and not allow you to play the game? It's in their terms that you can't modify a console, so you're at risk although you may be benefiting in the short-run.



M$ will take the same approach Sony did for the PSP hackers and threaten the hackers...they'll soon do what they have to.



I hope the hackers allow the playback of XBlowx711 images/roms. Soon everyone will have pirated versions of all leaked games, and it will surely become the next Dreamcast. ROFL! I remember when so many noobs thought the DC was going to kill the PS2....

by Developed Hornet - 2007-08-24 10:11
» !

if any of the hackers involved in the XBOX 360 modding community is reading: dont listen to any of these morons bad mouthing u'r work > they are most probably just jealous that they dont have the technical knowledge get any mods/hacks to run on their system ; )



i have enjoyed all of the hacks,mods & exploits uncovered by the XBOX 360 modding community



keep up the great work : )

by Devise - 2007-08-24 17:06
» ...

I doubt it.

by Devise - 2007-08-24 17:17
» ...

MS main goal has been to disable Xbox Live for users that modify their consoles. Sony and Nintendo decide to take legal action against the hackers. MS invites them to a presentation to show off their work. MS will not fight against the mode, they will just work on disabling Live if you are using the mod. Currently you need to downgrade the kernel version of the 360 to exploit the kernel and thus you can not access Live.



And if the Dreamcast had the money behind it that MS has. PS3 couldn't even outsell the 360 last month with a $100 price cut and the PS3 is going to get it's ass kicked the rest of 2007 and beyond.

by Djhg2000 - 2007-08-25 11:29
» -

...like you could with the old XBox...

Add QJ.NET
Add to My Yahoo!
Google Reader Subscribe with Bloglines
Add  to your Kinja digest Subscribe in NewsGator Online
Subscribe with Pluck RSS reader Add 'www.qj.net' to Newsburst from CNET News.com
Subscribe with SearchFox RSS del.icio.us www.qj.net
Add to Technorati Favorite! Add to My AOL
furl! it Stumble for Treehugger!