Play-Asia.com - Your One-Stop-Shop for Asian Entertainment
 

Xbox 360 security partially broken again

Hackers will never stop hacking the 360 until it’s open for use to everyone, an ongoing cat-and-mouse game between Microsoft and the hackers. This time the hackers succeeded to downgrade the dashboard version. By downgrading the dashboard it is possible again to go back to the exploitable dashboard that got fixed last February.

The hack is really technical, and because of that we won’t go into it in too much detail. Every bit in the Xbox 360 is secured with a key, which is unique for every Xbox 360. Hackers already found a way to extract that with the old exploitable dashboard, but the main problem was that Microsoft patched this leak before it was made public. The following from quotearnezami will explain the hack:

It would be foolish to try to break SHA1-HMAC (ed: the core security hash key). However the output of a hash usually has to be checked against something that is stored. Thats usually the point of it. This takes (a tiny bit of) time. The thing is many memcmp (ed: data comparison) functions use a byte-wise compare: “as long as no difference in the current byte is detected go to the next byte, but if this byte is different stop”. In other words: it might take (a fraction of a second) longer if the output is similar at the beginning (to the stored value) as opposed to completely different 16-byte values. If it is possible to measure this time difference you could change the first stored byte (up to 256 times) until it takes this fraction longer for the Xbox360 to detect the (16 byte) values are not entirely the same. And you can go on with this until all bytes have been figured out this way.

In other words: When the Xbox boots up the dashboard, the uber SHA1-HMAC key from Microsoft is used for decrypting the kernel for the Xbox360 dashboard. A hash is used between the SHA1-HMAC key and the kernel to check if the data still is intact. The hash compares bytes between the cpu-key and the SHA1-HMAC key. Microsoft used memcmp to compare the bytes. But when memcmp compares the bytes, and the value that’s stored is wrong it will take a few milliseconds longer to continue depending on the first incorrect byte. This way it is possible to try out all the different combinations. This is 256 different combinations for each byte, so this will make 256 combinations times 16 bytes, reducing the possible values that need to be checked from 2 to the power 128 (a number with over 40 digits) possibilities to about 4000 worst case. After you successfully extracted the key, it’s possible to sign and old dashboard update with the extracted values and this way it’s possible to downgrade to an older dashboard.

It’s important to note that the Xbox 360 core security is still intact, so for example it’s still not possible to boot up copied games from the hard drive. The only interesting part about this hack is that they found a way to downgrade again to the old vulnerable dashboard, allowing them to explore other ways to get in control more structurally. The Xbox 360 hackers still have a long way to go, to get the same functionality found in hacked Xbox 1s. Microsoft will probably publish a patch in the coming weeks for fixing this security issue, until then we’ve got approximately 10 million vulnerable Xbox 360s in the world.

del.icio.us:Xbox 360 security partially broken again newsvine:Xbox 360 security partially broken again furl:Xbox 360 security partially broken again reddit:Xbox 360 security partially broken again fark:Xbox 360 security partially broken again Y!:Xbox 360 security partially broken again gamegrep:Xbox 360 security partially broken again

14 comments on 'Xbox 360 security partially broken again'

Subscribe to comments with RSS or Trackback to 'Xbox 360 security partially broken again'.

Comment by nuknuk on 2007-08-25 15:14:14 | Reply

i dont care either way.

Hackers suck balls

umm ok?, ill stick to the psp

Comment by steve perry on 2007-08-25 17:57:23 | Reply

I like the picture

Comment by x El Scorpio x on 2007-08-25 18:15:08 | Reply

hacking for playing pirate games or cheating online/for achievements is bad. hacking with sensible application is fine by me, it’s good if people can make homebrew apps or make little mods for games like you can on a pc.

someones gotta waste their life doing stupid shit like this… just glad its not me as I have better things to do with my precious time.

Comment by Mr. Bill Gates (GOD) on 2007-08-25 20:26:47 | Reply

Excellent!!! XBMC coming on Xbox 360 near you! ;D

Comment by Opium on 2007-08-25 23:02:36 | Reply

Those dodgy bastards

Comment by thryon on 2007-08-26 07:02:09 | Reply

yep, this is all about being able to play old Nintend…… oops, sorry, I ment to say, to play legit homebrew :P

Comment by strahd on 2007-08-26 22:01:55 | Reply

Wow this article was jibberish and i don’t see the big deal in hacking anyways.. i guess ill go play bioshock some more

Well we did our best to make it as understandable as possible, but indeed it may still be jibberish to many people… still, it’s news for those that can grasp the concepts ;)

…Go on then…?

Comment by darkrom on 2007-08-27 03:44:55 | Reply

Screw all of you who think hackers ruin anything. We don’t hack to cheat….they are called cheaters. “hackers” are really just people making their 360s do all sorts of cool shit and adding new programs and fun games. also just so u guys know there is no way to be on xbox live with any dashboard other than the current one. so they cant ruin shit for u so STFU

Comment by The_Glovner on 2007-08-27 16:13:39 | Reply

You shut the fuck up, if you were that sure of your angelic innocence why would you even feel the need to justify it?

XHTML: You can use these tags: <a href="" title=""> <abbr title=""> <acronym title=""> <b> <blockquote cite=""> <code> <em> <i> <strike> <strong>