Archive for January, 2010
Freestyle Dash v1.03
Freestyle Dash v1.03 has been released by Axc97, for xbox 350 homebrew dashboard.
Whats fixed and new for Freestyle Dash v1.03:
* Fixed content saving bug in dash
* XML saving in dash quicker
* Added usb0:\applications and hdd1:\application paths. Please delete your config.xml for these to be added to existing installs. (The one in fsdata not base)
To Add (future features):
* Add buttons working on indexer, allow you to add custom graphics to a title when none have been automatically downloaded
* Background image support (Element ‘Background’ in xbox360.xui and gamedetails.xui if your making a skin)
* Preview.wmv support. Put preview.wmv in the artwork folder for a game and it will play when selecting the game
* Pick all/xbox 360/xbla/homebrew/emu on indexer to help sorting out your content.
Download Freestyle Dash v1.03
* Fixed content saving bug in dash
* XML saving in dash quicker
* Added usb0:\applications and hdd1:\application paths. Please delete your config.xml for these to be added to existing installs. (The one in fsdata not base)
To Add (future features):
* Add buttons working on indexer, allow you to add custom graphics to a title when none have been automatically downloaded
* Background image support (Element ‘Background’ in xbox360.xui and gamedetails.xui if your making a skin)
* Preview.wmv support. Put preview.wmv in the artwork folder for a game and it will play when selecting the game
* Pick all/xbox 360/xbla/homebrew/emu on indexer to help sorting out your content.
StreetskaterFU say’s PS3 exploit nothing more than an Urban Legend!
A well known hacker in the console hacking scene has said that the Geohots’s PS3 exploit will not lead to a proper hack that allow fro PS3 homebrew or backup games.
[Quote]
So the PS3 is hacked ? Well that’s nothing more than an urban legend.
“Altough it’s nice to capture all these HV calls and stuff from a plain (not encrypted) lv1 binary, but this will never lead to a hacked PS3.
Let’s have a look.
The major security architecture on the PS3 is called the “Secure Processing Vault” and is the most important thing regarding “hacking” the PS3.
There is NO WAY for the PPU or even the HV to gain access to the SPU, which is an application running inside of an isolated SPU.
Well you can kick out the isolated SPU, like geohot mentioned, but this gives you nothing, as ALL the encryption and execution of applications (HDD encryption, app encryption, decryption, executing, signature checking, root key extraction) happens inside the isolated SPU.
To run homebrew on the PS3 you would have to reassemble the whole functionality from the SPU inside a binary running on the PPU.
For this you will need the root key. The root key is stored in hardware (not even close to the things on the iPhone). The root key cannot be extracted by any software or hardware means and is essential to ALL encryption/decryption, executing and checking routines.
The only way to get the root key is inside of an isolated SPU, as it is kick-starting the hardware encryption facility. There is no other way to do that !
Let’s just assume that geohot or some other guys are able to break into the local store of the isolated SPE. There they will just find some encrypted binaries.
The key for decryption is encrypted by the root key !
You won’t get anywhere without the root key.
Let’s assume that someone managed to do all those stuff from the isolated SPU on the PPU and creates a CFW.
There is still a secure booting environment. The first module loaded/bootet is integrity checked by the hardware crypto facility utilizing the root key. So you have also to address this booting stuff. Again, no root key, no booting.
So there’s always runtime patching you might ask ? Not possible on the PS3 because the hardware crypto facility is able to check the signatures whenever it wants to. And which part is responsible for this ? Exactly, the isolated SPU.
So if you kick out the isolated SPU the system will not boot/run anymore.
The PS3 is neither an PSP nor an iPhone. It’s the most secure system architecture of this time !
The girl behind this stuff, Kanna Shimizu, is not somebody. Messing around with this is not like saying Bruce Schneier is a n00b.
Btw.: forget about all those stories, that certain hackers are or will be employed by SONY. That’s nothing more than another urban legend.
@geohot It is OBVIOUS that the HV is PPC. The Cell BE is a PPC architecture, you know
Better read those IBM papers in first place !”
Nandpro GUI
Nand pro GUI Released
This is a nand flasher for the Xbox360 in a nice graphic user interface (GUI) . great if you need to backup or write to your nand flash.
How To Use:
* Dev: is what type to read aka “From File: LPT: or USB:
* File: to load the Source file, like the NAND. ‘Make sure the file that is loaded is in the same folder as the program or it will not work’
* options: really need to explain read, write, erase, ECC, No ECC, Fix ECC, ADD ECC.
* NAND Size: use the xbox nand size XD
* File2: Read/Write file to NAND or to File:
* Hex Start block/Count: what blocks to start and how many.
Xbr Flasher v0.2
Xbr Flasher v0.2 released – Download
A new version of XBR flasher has been released. It a simple batch file for flashing and restoring your Xbox 360 nand chips. compatible with all revisions to date. nand backups along with kv and config seperate and log files from nandpro all kept in the directory /backups as for restoring he hasnt finished that yet.
Features:
* Automatic CB Detection
* Automatic dumping (2 times)
* Automatic checksum compare
* Automatic Keyvault and config extraction and injection
* Automatic XBR.bin selection
* Keeps backups in tidy folders
* Supports 16mb and 256/512mb nands
XBRFlasher will now dump 1 sector from the NAND and run cbcheck.exe to determine the CB Version, it will then (based on your board revision you picked) decide if the xbox is exploitable or not, it will continue if exploitable and go back to start with an error if your xbox has an unexploitable CB version
Looking further into GUI idea… have a rough draft layed out still deciding on alot of things…
**PLEASE NOTE ** I recommend that when XBRFlasher tells you to press any key to continue flashing, you run 1 of the backup files through Degraded or similar to check for badblocks!
What’s new/fixed:
* Added Automatic CB Checking, cleaned up some of batch script fixed some misc errors coming upp
Freestyle Dash v1.02
Freestyle Dash v1.02 Released
A new dashboard has been released for the Xbox 360 homebrew scene. This new dashbaord adds a host of features to your Homebrew enabled Xbox 360 in an excellent GUI.
I decided that instead of focusing of file copying and browsing operations, i would make the game launching and browsing as good as i could.
Features:
* FTP Support.
* List XBOX 360, XBOX Live, Application and Emulators, and launch them.
* Support for artwork for each title, including boxart, screenshots and icon.
* Use pc to download artwork to xbox either via usb drive or ftp.
* Browse games by genre.
* Favourite games support.
* Game details including no of players, resolution, sound and online options,
* Fullscreen screenshot viewer.
* Fully skinable.
* Uses indexer to allow you to download artwork, and edit the metadata with
each game.
* Customizable overscan so you can set the dash to display all its information even when other launchers cant.
* Source code released too.
v1.02 Much faster ftp and cooler gpu usage.
v1.01 Fixed minor mistake
v1.0 Initial Release
Heres a comprehensive view from the original nfo file.
Freestyle XBOX 360 Dashboard
————————-
2010/01/25
axc97c
version 1.0
————————-
I decided that instead of focusing of file copying and browsing operations,
i would make the game launching and browsing as good as i could.
Features:-
FTP Support. (Slow at moment)
List XBOX 360, XBOX Live, Application and Emulators, and launch them.
Support for artwork for each title, including boxart, screenshots and icon.
Use pc to download artwork to xbox either via usb drive or ftp.
Browse games by genre.
Favourite games support.
Game details including no of players, resolution, sound and online options,
Fullscreen screenshot viewer.
Fully skinable.
Uses indexer to allow you to download artwork, and edit the metadata with
each game.
Customizable overscan so you can set the dash to display all its information
even when other launchers cant.
Source code released too.
When first launching, you will be asked if you want the dashboard data
storing on the usb drive or xbox hdd. If you choose usb, you can run the
indexer with the drive connected to a pc, or via ftp while its still
connected to the xbox. If you use the internal xbox drive, you can still
run the indexer on the xbox via ftp.
The ftp server is quickly thrown together and needs a fair bit of work
still but it works great for copying small stuff to the xbox. I would
suggest launching xexmenu for now to copy games via ftp. It is mainly
included to allow the indexer to be run without having to disconnect the
usb drive every time you add a new game.
Artwork wise, i have hosted all the icons i have available, so if any are
missing let me know which. For the boxart and screenshots, the indexer
uses the xbox marketplace for most content. Games that arent listed use
an alternate url for the main xbox site, but these need to be added manually
so some may be missing. The file for this is automatically updated so
if games have no info you can either wait for me to add them to the list or
edit the altgames.xml file yourself.
When the dash first scans your content, it takes a while as it extracts any
icons etc it finds. This is all cached though so subsequent launches of the
dashboard are quick.
The first run of the indexer will take quite some time, as it has got a lot
of artwork to get, so please be patient with it.
Thanks to dstruktiv for the XBLA launching code and network enable code.
Thanks to all feedback from 360 dashit indexer users, as this is what that
project has turned into.
Check out the screens:
Download Freestyle Dash v1.02
XeXMenu v1.1
XeXMenu v1.1 released
XeXMenu v1.1 has been released by Team XeDev. XeXMenu v1.1 is an update of XexMenu which is a xbox 360 homebrew dashboard.
What’s news/fixed :
- Added HFS+ drive support
- Added ip adress information to the configuration menu
- Added skin loading verify routine to output errors on the screen while starting XeXmenu
- Added some user skins
- Improved ftp upload speed
- Loads nxebg.dds and icon.dds even if nxeart isn’t present
Some other bugs fixed
Download XeXMenu v1.1
Download Geohot’s ps3 exploit
Download Geohot’s ps3 exploit in zip format
there are 5 files contained in the zip file, two of which are just instruction’s in the form of a picture and .txt file.
the following are a list of files in the .zip folder
- pokemehere.jpg
- run.sh
- exploit.c
- makefile
- instructions.txt
Geohot’s PS3 exploit instructions
These are the instructions that come with Geohot’s PS3 exploit.
!!EXPLOIT IS FOR RESEARCH PURPOSES ONLY!!
Usage Instructions:
Compile and run the kernel module.
When the “PRESS THE BUTTON IN THE MIDDLE OF THIS” comes on, pulse the line circled in the picture low for ~40ns.
Try this multiple times, I rigged an FPGA button to send the pulse.
Sometimes it kernel panics, sometimes it lv1 panics, but sometimes you get the exploit!!
If the module exits, you are now exploited.
This adds two new HV calls,
u64 lv1_peek(16)(u64 address)
void lv1_poke(20)(u64 address, u64 data)
which allow any access to real memory.
The PS3 is hacked, its your job to figure out something useful to do with it.
Geohot’s PS3 exploit released
Geohot’s PS3 Exploit released for download
Geohot has released the exploit that will allow for the PS3 to be hacked. This is what the hacking community have been waiting for. Geohot’s PS3 exploit will have the console hacking scene raving in hours. This is not for the average user only experienced hackers will be comfortable with this code.
[Quote]
“In the interest of openness, I’ve decided to release the exploit. Hopefully, this will ignite the PS3 scene, and you will organize and figure out how to use this to do practical things, like the iPhone when jailbreaks were first released. I have a life to get back to and can’t keep working on this all day and night.
Please document your findings on the psDevWiki. They have been a great resource so far, and with the power this exploit gives, opens tons of new stuff to document. I’d like to see the missing HV calls filled in, nice memory maps, the boot chain better documented, and progress on a 3D GPU driver. And of course, the search for a software exploit.
This is the coveted PS3 exploit, gives full memory access and therefore ring 0 access from OtherOS. Enjoy your hypervisor dumps. This is known to work with version 2.4.2 only, but I imagine it works on all current versions. Maybe later I’ll write up how it works
Good luck!”
Download Geohot’s PS3 exploit
Geohot’s PS3 exploit instructions
First signs of PS3 hack code
PS3 hack code
Geohot has upadated his blog and released the first snippet of code related to the PS3 hack. We cant wait for you to try it out and start experimenting. Get the PS3 hack code





