Hacking DVD Drive Vulnerability

Andrei1744

Member
OP
Newcomer
Joined
Sep 17, 2021
Messages
14
Trophies
0
Age
34
XP
123
Country
Romania
Hi everyone. I think that everyone knows how people used to play pirated games on the xbox 360. They would simply modify the dvd-drive's firmware to boot backup dvd's. What's stopping us from doing the same for the xbox one? Can someone explain this to me?
 

BigOnYa

Has A Very Big
Member
Joined
Jan 11, 2021
Messages
3,207
Trophies
1
Age
50
XP
7,577
Country
United States
I would also like to know more info about this or any potential exploits for the xbox one, if anyone knows. I'm now mostly curious because MS has stopped making them, and I have a one original collecting dust now, since getting a series x.
 

Andrei1744

Member
OP
Newcomer
Joined
Sep 17, 2021
Messages
14
Trophies
0
Age
34
XP
123
Country
Romania
I would also like to know more info about this or any potential exploits for the xbox one, if anyone knows. I'm now mostly curious because MS has stopped making them, and I have a one original collecting dust now, since getting a series x.
Exactly! I have an original XB1 too. I heard that the xbox 360 also had a supervisor, but it didn't interfere with the custom dvd drive firmware loading backup dvd's. I think that there might be a way to pull this off. And with access to dev mode, couldn't we extract the DVD Drive keys to overwrite it's firmware?
 
  • Like
Reactions: Finray

lisreal2401

Well-Known Member
Member
Joined
Jun 4, 2013
Messages
855
Trophies
1
Age
27
XP
2,924
Country
United States
It's not a Xbox - Xbox 360 deal where the security hardly changed. For reference, the final Xbox 360 DVD drives are not even hackable unless you get the key with a RGH - and this is just assuming they'd use the same security methods
 

Donnie-Burger

Well-Known Member
Member
Joined
Oct 27, 2021
Messages
927
Trophies
0
Website
www.youtube.com
XP
1,799
Country
United States
It's not a Xbox - Xbox 360 deal where the security hardly changed. For reference, the final Xbox 360 DVD drives are not even hackable unless you get the key with a RGH - and this is just assuming they'd use the same security methods
The final models winchester boards were never possible.
 
  • Like
Reactions: Andrei1744

Andrei1744

Member
OP
Newcomer
Joined
Sep 17, 2021
Messages
14
Trophies
0
Age
34
XP
123
Country
Romania
Thanks for explaining it to me everyone. If Microsoft didn't add the bounty feature, we would surely have a hacked xbox one. I think that most of the hackers report the vulnerability to Microsoft because they offer a huge amount of money. Could we make something like that? A site where people put bounties. Everyone could add some money to the bounty, and if someone makes the vulnerability work, they would get all the stashed money. I would add probably 250$ to get it started.
 

MrQQ

Well-Known Member
Newcomer
Joined
Feb 3, 2022
Messages
78
Trophies
0
Age
36
Location
Scotland
XP
427
Country
United Kingdom
The problem based on my own research is we have no way of working out the deviation angles on the disc geometry. The arm cpu on the dvd drive can be accessed I have found via spi and a bus pirate but I cannot interact with the chip at all but its still progress I have slowly been making. If anyone has the time i'd love someone to collaborate on this as I have way more research and progress that I am unwilling to share here for obvious reasons :)
 

Andrei1744

Member
OP
Newcomer
Joined
Sep 17, 2021
Messages
14
Trophies
0
Age
34
XP
123
Country
Romania
The problem based on my own research is we have no way of working out the deviation angles on the disc geometry. The arm cpu on the dvd drive can be accessed I have found via spi and a bus pirate but I cannot interact with the chip at all but its still progress I have slowly been making. If anyone has the time i'd love someone to collaborate on this as I have way more research and progress that I am unwilling to share here for obvious reasons :)
May I collaborate with you? Not here of course. And I am very interested in the progress that you've made.
 

TomChaai

Active Member
Newcomer
Joined
Oct 17, 2022
Messages
31
Trophies
0
Age
32
XP
397
Country
China
The challenge/response sequence hasn't changed drastically, Xbox still makes the characteristic seeking sounds when authentciating a disc.
The problem is the drive controller. MS used to not care about it and the drive vendors just used generic chips, then the 360 drive got hacked real bad and MS realized any generic ASICs won't work. They teamed up with MTK to custom design the drive controller chip.
It's still mostly based on existing MTK drive controllers but now it properly encrypts its firmware and controls flash access/booting securely. Reverse engineering the chip becomes much harder compared to when the 360 drives were originally being reverse engineered. Those Samsung drives are almost wide open.
 

MrQQ

Well-Known Member
Newcomer
Joined
Feb 3, 2022
Messages
78
Trophies
0
Age
36
Location
Scotland
XP
427
Country
United Kingdom
It actually has based on my own research AP 3.0 is mentioned in the code dumps I have and XGD4 has a wildly different geometry on the disc despite is being blu-ray. I have spent a year pouring over this. Yes they did use custom MTK chips but i have managed to interact with one via a spi bus pirate. Its all work in progress but trust me when I say the disc challenges/responses and very complex now. The 360 dvd drive was hacked mostly down to failures on the classic model. Sure they tried to improve with liteons etc. The xbox one uses secure fw crc checking on boot. Slims also did this...phats didnt. The firmware is also checked on boot to see if it is stock which also slims did. The decryption of the tool for the MTK chipset should be straight forward as I already have the maketools that were part of the xbox one leak and have figured out how to use firmcrypt for those and its all good but understanding the new PSN layer and disc AP 3.0 structure will take time. Finding a blu ray drive with an analogue controller so we can dump every bit with security sector's is what I have been doing. Tmbinc did this back in the day its actually how we understood how the 360 disc structure worked and allowed us to make 360 backup creator etc. As I say this is all work in progress but I have been researching this hard for the past year. Of course the video you posted is designed to make people like myself and other feel deterred... I wont be :) but you did reference some interesting stuff there I have been looking into
 

TomChaai

Active Member
Newcomer
Joined
Oct 17, 2022
Messages
31
Trophies
0
Age
32
XP
397
Country
China
I actually found a patent MS submitted, it involves burning two overlapping data tracks on the security region of the disc during glass mastering, the mechanical imperfections guaranteed true random results that couldn't be replicated reliably twice even in the mastering factory.
The overlapping tracks created intermittently unreadable regions that the patent stated to be measured for AP checks.
The patent number is EP 3 201 922 B1 if you are interested.
 
  • Like
Reactions: SylverReZ

MrQQ

Well-Known Member
Newcomer
Joined
Feb 3, 2022
Messages
78
Trophies
0
Age
36
Location
Scotland
XP
427
Country
United Kingdom
I actually found a patent MS submitted, it involves burning two overlapping data tracks on the security region of the disc during glass mastering, the mechanical imperfections guaranteed true random results that couldn't be replicated reliably twice even in the mastering factory.
The overlapping tracks created intermittently unreadable regions that the patent stated to be measured for AP checks.
The patent number is EP 3 201 922 B1 if you are interested.
you are absolutely correct - they earned well from XGD3 protection
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • AncientBoi @ AncientBoi:
    Uhh, It's 🌯 Saturday dude. :) js
  • BigOnYa @ BigOnYa:
    Nope that for tomorrow, cinco de mayo, today is bbq chicken on the grill.
  • K3Nv2 @ K3Nv2:
    Juan's new years I forgot
    +2
  • AncientBoi @ AncientBoi:
    :hrth::toot::grog::grog::grog::bow: HAPPY BIRTHDAY to me :bow::grog::grog::toot::hrth:
  • K3Nv2 @ K3Nv2:
    One day away from Juan's birthday
  • K3Nv2 @ K3Nv2:
    Only if you send him feet
    +1
  • BigOnYa @ BigOnYa:
    Happy birthday!
    +1
  • AncientBoi @ AncientBoi:
    Thank You :D
  • realtimesave @ realtimesave:
    heh I got a guy who created an account just yesterday asking me where to find mig switch roms
  • realtimesave @ realtimesave:
    too much FBI watching this website to answer that kind of question lol
  • K3Nv2 @ K3Nv2:
    Has the mig switch found loopholes without requiring game keys?
  • Xdqwerty @ Xdqwerty:
    @AncientBoi, happy birthday
  • Xdqwerty @ Xdqwerty:
    Yawn
  • Xdqwerty @ Xdqwerty:
    Lonely here
  • Xdqwerty @ Xdqwerty:
    Anybody?
  • Psionic Roshambo @ Psionic Roshambo:
    I want my money back... Drug test? No drugs to test but they want me to pee in a cup! Lol
  • K3Nv2 @ K3Nv2:
    Better call Pedro you're up in smoke
    +2
  • C @ Clayton44333:
    hey any1 know if there is a new version of the ps4 homebrew store ?
  • Xdqwerty @ Xdqwerty:
    Finally there are people here
  • K3Nv2 @ K3Nv2:
    We're figments of your imagination
    +1
  • Xdqwerty @ Xdqwerty:
    @K3Nv2, prove it
    Xdqwerty @ Xdqwerty: @K3Nv2, prove it