Hacking RGH from king kong

DSUPERY92

Well-Known Member
OP
Member
Joined
Jul 3, 2018
Messages
109
Trophies
0
Age
28
XP
246
Country
Italy
Is it possible to create a modified system update with the RGH in it so that when the xbox installs the update, will it install the rgh in the nand?
 

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,471
Trophies
3
XP
29,180
Country
United States
that's what the su would be for, but it would be unsigned. the 360 would reject anything that wasn't signed. there appears to be a browser app, but I have no idea if there's anything that could be done with it. I actually didn't even know of its existence until I looked it up.
 

konsolenumbau.expert

Well-Known Member
Member
Joined
Feb 7, 2016
Messages
357
Trophies
0
Age
44
Location
Rieps
Website
konsolenumbau.expert
XP
370
Country
Germany
You totally misunderstand the function of an RGH Setup.

The chip isn't soldered in just to make someone who can solder a bit of money.

It is required to get the Console in a state where it can boot or run unsigned code.

With King Kong this is not possible as you ain't got "real" code execution. You need a freeboot image to run Backup Loaders, emus and stuff.

Gesendet von meinem SM-N9005 mit Tapatalk
 

Deleted member 668561

GBAtemp Official Psychonaut
Banned
Joined
Jan 29, 2008
Messages
1,875
Trophies
0
Location
somewhere within 4 dimensional space-time
XP
2,654
Country
United States
THE ONLY SOFT-MOD FOR XBOX 360 WAS THE JTAG, WHICH WAS JUST THE KING KONG EXPLOIT, BUT INSTEAD OF USING KING KONG YOU JUST FLASHED A NAND IMAGE THAT EXECUTES THE SAME EXPLOIT AT BOOT. RGH IS A HARDWARE MOD, MEANING THAT YOU'RE PHYSICALLY FUCKING WITH THE CPU DURING BOOT CHANGING THE WAY IT BEHAVES TO ALLOW NON ENCRYPTED CODE TO EXECUTE, MICROSOFT HAS BEEN AROUND SINCE THE 1970'S MAKING SOFTWARE, THE 360 SHOWS THIS EXPERIENCE, NO YOU CANNOT SOFT-MOD A 360 SINCE JTAG. JTAG WAS ONLY POSSIBLE ON NON SLIMS WITH A PRE 2008 (BLADES) DASHBOARD, IF YOU UPDATED OR HAVE A SLIM YOU HAVE TO MODIFY THE HARDWARE (RGH) IT TAKES ALOT MORE THAN JUST "UPDATING THE SYSTEM DASHBOARD", EVERYTHING ON THE XBOX IS ENCRYPTED, YOU DO NOT JUST SLAP A MODIFIED FILE THERE AND EXPECT IT TO LOAD AND GIVE YOU HARDWARE ACCESS, IF WERE THIS EASY WE WOULDN'T HAVE NO NEED FOR THE RGH, EVERYTHING IS ENCRYPTED MEANING IF YOU MODIFY ANYTHING IT WILL BREAK THE ENCRYPTION AND REFUSE BOOT/EXECUTE UNLESS YOU DISABLE ENCRYPTION CHECK WHICH IS WHAT EXACTLY THE POINT JTAG AND RGH ARE FOR, TO REMOVE ENCRYPTION CHECKS . YOU CAN NOT SOFTMOD A 360 BECAUSE THE SOFTWARE ON IT WAS DESIGNED SPECIFICALLY AGAINST SOFT-MODDING SINCE MICROSOFT HAS MORE MONEY THAN NINTENDO, PLUS NINTENDO PROFITS FROM EVERY CONSOLE SOLD MICROSOFT AND SONY DO NOT AND THIS IS WHY YOU PAY FOR LIVE/PS PLUS SINCE THEY AIM TO MAKE MONEY BACK FROM THE SALES OF SOFTWARE AND SERVICES. THE ONLY SOFTMOD FOR THE 360 IS TO SEE IF MICROSOFT WILL GIVE YOU THEIR PRIVATE ENCRYPTION KEY.


TLDR
softmod is not possible unless you have microsoft's encryption key ( not cpu key, its literally the master key) or a hardware exploit since the system software was designed by company with over 40 years of software development, so any 10 year old ideas for a softmod can be thrown out, this is not a nintendo console, this has alot more money put into it to keep it secure, since microsoft do not profit directly from console sales
 
Last edited by Deleted member 668561,

konsolenumbau.expert

Well-Known Member
Member
Joined
Feb 7, 2016
Messages
357
Trophies
0
Age
44
Location
Rieps
Website
konsolenumbau.expert
XP
370
Country
Germany
THE ONLY SOFT-MOD FOR XBOX 360 WAS THE JTAG, WHICH WAS JUST THE KING KONG EXPLOIT, BUT INSTEAD OF USING KING KONG YOU JUST FLASHED A NAND IMAGE THAT EXECUTES THE SAME EXPLOIT AT BOOT. RGH IS A HARDWARE MOD, MEANING THAT YOU'RE PHYSICALLY FUCKING WITH THE CPU DURING BOOT CHANGING THE WAY IT BEHAVES TO ALLOW NON ENCRYPTED CODE TO EXECUTE, MICROSOFT HAS BEEN AROUND SINCE THE 1970'S MAKING SOFTWARE, THE 360 SHOWS THIS EXPERIENCE, NO YOU CANNOT SOFT-MOD A 360 SINCE JTAG. JTAG WAS ONLY POSSIBLE ON NON SLIMS WITH A PRE 2008 (BLADES) DASHBOARD, IF YOU UPDATED OR HAVE A SLIM YOU HAVE TO MODIFY THE HARDWARE (RGH) IT TAKES ALOT MORE THAN JUST "UPDATING THE SYSTEM DASHBOARD", EVERYTHING ON THE XBOX IS ENCRYPTED, YOU DO NOT JUST SLAP A MODIFIED FILE THERE AND EXPECT IT TO LOAD AND GIVE YOU HARDWARE ACCESS, IF WERE THIS EASY WE WOULDN'T HAVE NO NEED FOR THE RGH, EVERYTHING IS ENCRYPTED MEANING IF YOU MODIFY ANYTHING IT WILL BREAK THE ENCRYPTION AND REFUSE BOOT/EXECUTE UNLESS YOU DISABLE ENCRYPTION CHECK WHICH IS WHAT EXACTLY THE POINT JTAG AND RGH ARE FOR, TO REMOVE ENCRYPTION CHECKS . YOU CAN NOT SOFTMOD A 360 BECAUSE THE SOFTWARE ON IT WAS DESIGNED SPECIFICALLY AGAINST SOFT-MODDING SINCE MICROSOFT HAS MORE MONEY THAN NINTENDO, PLUS NINTENDO PROFITS FROM EVERY CONSOLE SOLD MICROSOFT AND SONY DO NOT AND THIS IS WHY YOU PAY FOR LIVE/PS PLUS SINCE THEY AIM TO MAKE MONEY BACK FROM THE SALES OF SOFTWARE AND SERVICES. THE ONLY SOFTMOD FOR THE 360 IS TO SEE IF MICROSOFT WILL GIVE YOU THEIR PRIVATE ENCRYPTION KEY.


TLDR
softmod is not possible unless you have microsoft's encryption key ( not cpu key, its literally the master key) or a hardware exploit since the system software was designed by company with over 40 years of software development, so any 10 year old ideas for a softmod can be thrown out, this is not a nintendo console, this has alot more money put into it to keep it secure, since microsoft do not profit directly from console sales

Whoot?

JTAG needed soldering as well :-)
And as you stated yourself: "You just flashed a NAND Image..." How would you flash it without soldering Wires? :-)

So after all... nonsense.....
 
  • Like
Reactions: DinohScene

Deleted member 668561

GBAtemp Official Psychonaut
Banned
Joined
Jan 29, 2008
Messages
1,875
Trophies
0
Location
somewhere within 4 dimensional space-time
XP
2,654
Country
United States
Whoot?

JTAG needed soldering as well :-)
And as you stated yourself: "You just flashed a NAND Image..." How would you flash it without soldering Wires? :-)

So after all... nonsense.....

the jtag exploit is the same exploit used in the kk exploit but patched into a nand image, not into a game iso, once the nand is flashed you no longer need to write it, you no longer need any wiring except some jumpers no extra logic, no extra active hardware, its a true softmod and easier than to rgh and why you have instant boot, rgh requires some discreet logic (external cpld- active hardware) to glitch the cpu at a very specific time to make it think its has pass the encryption check , when it really doesn't, then boots into your unsigned code to disable it, jtag bypasses this check directly by a bug in hyper visor itself, Microsoft has made jtag impossible with a system update(note that blowing cpu fuses actually changes the cpu hardware/logic and how it runs internally, which the jtag hack depended on pre-4552 dashes) .

either way microsoft has much time and experience in software development (since 1975, back when pong was the hottest console) the point is that you don't even regard the dash when jtagging or rgh since the exploits happen before the dash is launched, it exploits the hypervisor, which you can think like when windows used to use ms-dos before the NT kernel, windows was the frontend (aka your dashboard), but ms-dos is in the background actually calling the shots (360 hyper-visor), so you have two "oses" with one you never see since you don't have any reason to need to (hypervisor) and one your actual os (dashboard), this isn't a Nintendo console, these are essentially small form factor PC's, more expensive hardware, more R&D money. I think Nintendo purposely leaves their systems weak since they directly profit from console sales, and you'd likely have a spike in sales if you have cfw available (then patch once you buy it, hoping you lose cfw, and have to go back to gamestop until its rexploited), microsoft do not profit from direct console sales and don't really NEED to (xbox is not Microsoft's breadwinner anyway), they recoup losses through paying for their online services and software, thus having a console that is secure is more important for them since they don't make profit unless people buy services or games, the 360 entire boot/execution process is encrypted, and any software modification is watched by the hypervisor so anything not permitted (ANY unsigned/unencrypted code/data) will refuse to run since it breaks encryption and the chain of command, this is why nintendo console are easy as fuck to softmod since its encryption is not strong, and those console are built at a lower cost.

Microsoft will actually learn what hackers have done in the past and move forward with it, even with the xbox one if it was exploited you most likely could not do anything but run homebrew, and since the hypervisor is built into the hardware (360 was in software) i wouldn't be surprised if they put a flag that when unsigned code is executed, it flags your system and even if the console was made stock probably would ban you next time you log in, and could tell microsoft hey someone hacked it and they'll release a patch, since everything that happened on the 360 will not happen on xb1. makes me think if they waited on announcing the RGH until the one was released it may have been susceptible to that aswell, and since it wasn't Microsoft can figure out how it worked and patch it going forward, which is why alot of "exploit artists" don't release them immediately.
 
Last edited by Deleted member 668561,

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    AncientBoi @ AncientBoi: :rofl2::rofl2::rofl2::rofl2: