Hacking DVD Drive Vulnerability

Andrei1744

Member
OP
Newcomer
Joined
Sep 17, 2021
Messages
14
Trophies
0
Age
34
XP
123
Country
Romania
Hi everyone. I think that everyone knows how people used to play pirated games on the xbox 360. They would simply modify the dvd-drive's firmware to boot backup dvd's. What's stopping us from doing the same for the xbox one? Can someone explain this to me?
 

BigOnYa

Has A Very Big
Member
Joined
Jan 11, 2021
Messages
3,237
Trophies
1
Age
50
XP
7,652
Country
United States
I would also like to know more info about this or any potential exploits for the xbox one, if anyone knows. I'm now mostly curious because MS has stopped making them, and I have a one original collecting dust now, since getting a series x.
 

Andrei1744

Member
OP
Newcomer
Joined
Sep 17, 2021
Messages
14
Trophies
0
Age
34
XP
123
Country
Romania
I would also like to know more info about this or any potential exploits for the xbox one, if anyone knows. I'm now mostly curious because MS has stopped making them, and I have a one original collecting dust now, since getting a series x.
Exactly! I have an original XB1 too. I heard that the xbox 360 also had a supervisor, but it didn't interfere with the custom dvd drive firmware loading backup dvd's. I think that there might be a way to pull this off. And with access to dev mode, couldn't we extract the DVD Drive keys to overwrite it's firmware?
 
  • Like
Reactions: Finray

lisreal2401

Well-Known Member
Member
Joined
Jun 4, 2013
Messages
855
Trophies
1
Age
27
XP
2,937
Country
United States
It's not a Xbox - Xbox 360 deal where the security hardly changed. For reference, the final Xbox 360 DVD drives are not even hackable unless you get the key with a RGH - and this is just assuming they'd use the same security methods
 

Donnie-Burger

Well-Known Member
Member
Joined
Oct 27, 2021
Messages
927
Trophies
0
Website
www.youtube.com
XP
1,806
Country
United States
It's not a Xbox - Xbox 360 deal where the security hardly changed. For reference, the final Xbox 360 DVD drives are not even hackable unless you get the key with a RGH - and this is just assuming they'd use the same security methods
The final models winchester boards were never possible.
 
  • Like
Reactions: Andrei1744

Andrei1744

Member
OP
Newcomer
Joined
Sep 17, 2021
Messages
14
Trophies
0
Age
34
XP
123
Country
Romania
Thanks for explaining it to me everyone. If Microsoft didn't add the bounty feature, we would surely have a hacked xbox one. I think that most of the hackers report the vulnerability to Microsoft because they offer a huge amount of money. Could we make something like that? A site where people put bounties. Everyone could add some money to the bounty, and if someone makes the vulnerability work, they would get all the stashed money. I would add probably 250$ to get it started.
 

MrQQ

Well-Known Member
Newcomer
Joined
Feb 3, 2022
Messages
78
Trophies
0
Age
36
Location
Scotland
XP
429
Country
United Kingdom
The problem based on my own research is we have no way of working out the deviation angles on the disc geometry. The arm cpu on the dvd drive can be accessed I have found via spi and a bus pirate but I cannot interact with the chip at all but its still progress I have slowly been making. If anyone has the time i'd love someone to collaborate on this as I have way more research and progress that I am unwilling to share here for obvious reasons :)
 

Andrei1744

Member
OP
Newcomer
Joined
Sep 17, 2021
Messages
14
Trophies
0
Age
34
XP
123
Country
Romania
The problem based on my own research is we have no way of working out the deviation angles on the disc geometry. The arm cpu on the dvd drive can be accessed I have found via spi and a bus pirate but I cannot interact with the chip at all but its still progress I have slowly been making. If anyone has the time i'd love someone to collaborate on this as I have way more research and progress that I am unwilling to share here for obvious reasons :)
May I collaborate with you? Not here of course. And I am very interested in the progress that you've made.
 

TomChaai

Active Member
Newcomer
Joined
Oct 17, 2022
Messages
31
Trophies
0
Age
32
XP
404
Country
China
The challenge/response sequence hasn't changed drastically, Xbox still makes the characteristic seeking sounds when authentciating a disc.
The problem is the drive controller. MS used to not care about it and the drive vendors just used generic chips, then the 360 drive got hacked real bad and MS realized any generic ASICs won't work. They teamed up with MTK to custom design the drive controller chip.
It's still mostly based on existing MTK drive controllers but now it properly encrypts its firmware and controls flash access/booting securely. Reverse engineering the chip becomes much harder compared to when the 360 drives were originally being reverse engineered. Those Samsung drives are almost wide open.
 

MrQQ

Well-Known Member
Newcomer
Joined
Feb 3, 2022
Messages
78
Trophies
0
Age
36
Location
Scotland
XP
429
Country
United Kingdom
It actually has based on my own research AP 3.0 is mentioned in the code dumps I have and XGD4 has a wildly different geometry on the disc despite is being blu-ray. I have spent a year pouring over this. Yes they did use custom MTK chips but i have managed to interact with one via a spi bus pirate. Its all work in progress but trust me when I say the disc challenges/responses and very complex now. The 360 dvd drive was hacked mostly down to failures on the classic model. Sure they tried to improve with liteons etc. The xbox one uses secure fw crc checking on boot. Slims also did this...phats didnt. The firmware is also checked on boot to see if it is stock which also slims did. The decryption of the tool for the MTK chipset should be straight forward as I already have the maketools that were part of the xbox one leak and have figured out how to use firmcrypt for those and its all good but understanding the new PSN layer and disc AP 3.0 structure will take time. Finding a blu ray drive with an analogue controller so we can dump every bit with security sector's is what I have been doing. Tmbinc did this back in the day its actually how we understood how the 360 disc structure worked and allowed us to make 360 backup creator etc. As I say this is all work in progress but I have been researching this hard for the past year. Of course the video you posted is designed to make people like myself and other feel deterred... I wont be :) but you did reference some interesting stuff there I have been looking into
 

TomChaai

Active Member
Newcomer
Joined
Oct 17, 2022
Messages
31
Trophies
0
Age
32
XP
404
Country
China
I actually found a patent MS submitted, it involves burning two overlapping data tracks on the security region of the disc during glass mastering, the mechanical imperfections guaranteed true random results that couldn't be replicated reliably twice even in the mastering factory.
The overlapping tracks created intermittently unreadable regions that the patent stated to be measured for AP checks.
The patent number is EP 3 201 922 B1 if you are interested.
 
  • Like
Reactions: SylverReZ

MrQQ

Well-Known Member
Newcomer
Joined
Feb 3, 2022
Messages
78
Trophies
0
Age
36
Location
Scotland
XP
429
Country
United Kingdom
I actually found a patent MS submitted, it involves burning two overlapping data tracks on the security region of the disc during glass mastering, the mechanical imperfections guaranteed true random results that couldn't be replicated reliably twice even in the mastering factory.
The overlapping tracks created intermittently unreadable regions that the patent stated to be measured for AP checks.
The patent number is EP 3 201 922 B1 if you are interested.
you are absolutely correct - they earned well from XGD3 protection
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • BigOnYa @ BigOnYa:
    Biomutant looks cool tho, may have to try that
  • Quincy @ Quincy:
    Usually when such a big title leaks the Temp will be the first to report about it (going off of historical reports here, Pokemon SV being the latest one I can recall seeing pop up here)
  • K3Nv2 @ K3Nv2:
    I still like how a freaking mp3 file hacks webos all that security defeated by text yet again
  • BigOnYa @ BigOnYa:
    They have simulators for everything nowdays, cray cray. How about a sim that shows you playing the Switch.
  • K3Nv2 @ K3Nv2:
    That's called yuzu
    +1
  • BigOnYa @ BigOnYa:
    I want a 120hz 4k tv but crazy how more expensive the 120hz over the 60hz are. Or even more crazy is the price of 8k's.
  • K3Nv2 @ K3Nv2:
    No real point since movies are 30fps
  • BigOnYa @ BigOnYa:
    Not a big movie buff, more of a gamer tbh. And Series X is 120hz 8k ready, but yea only 120hz 4k games out right now, but thinking of in the future.
  • K3Nv2 @ K3Nv2:
    Mostly why you never see TV manufacturers going post 60hz
  • BigOnYa @ BigOnYa:
    I only watch tv when i goto bed, it puts me to sleep, and I have a nas drive filled w my fav shows so i can watch them in order, commercial free. I usually watch Married w Children, or South Park
  • K3Nv2 @ K3Nv2:
    Stremio ruined my need for nas
  • BigOnYa @ BigOnYa:
    I stream from Nas to firestick, one on every tv, and use Kodi. I'm happy w it, plays everything. (I pirate/torrent shows/movies on pc, and put on nas)
  • K3Nv2 @ K3Nv2:
    Kodi repost are still pretty popular
  • BigOnYa @ BigOnYa:
    What the hell is Kodi reposts? what do you mean, or "Wut?" -xdqwerty
  • K3Nv2 @ K3Nv2:
    Google them basically web crawlers to movie sites
  • BigOnYa @ BigOnYa:
    oh you mean the 3rd party apps on Kodi, yea i know what you mean, yea there are still a few cool ones, in fact watched the new planet of the apes movie other night w wifey thru one, was good pic surprisingly, not a cam
  • BigOnYa @ BigOnYa:
    Damn, only $2.06 and free shipping. Gotta cost more for them to ship than $2.06
  • BigOnYa @ BigOnYa:
    I got my Dad a firestick for Xmas and showed him those 3rd party sites on Kodi, he loves it, all he watches anymore. He said he has got 3 letters from AT&T already about pirating, but he says f them, let them shut my internet off (He wants out of his AT&T contract anyways)
  • K3Nv2 @ K3Nv2:
    That's where stremio comes to play never got a letter about it
  • BigOnYa @ BigOnYa:
    I just use a VPN, even give him my login and password so can use it also, and he refuses, he's funny.
  • BigOnYa @ BigOnYa:
    I had to find and get him an old style flip phone even without text, cause thats what he wanted. No text, no internet, only phone calls. Old, old school.
    K3Nv2 @ K3Nv2: @BigOnYa...