Xbox Hypervisor Security Protection Hacked
ACTRAiSER writes "A recent Post on Bugtraq claims the hack of the Xbox 360 Security Protection Hypervisor. It includes sample code as well."
From Bugtraq
"We have discovered a vulnerability in the Xbox 360 hypervisor that allows
privilege escalation into hypervisor mode. Together with a method to
inject data into non-privileged memory areas, this vulnerability allows
an attacker with physical access to an Xbox 360 to run arbitrary code
such as alternative operating systems with full privileges and full
hardware access."
Will it run DOOM?
Physics is nothing like religion. If it was, we'd have an easier time trying to raise money!
A recent Post on Bugtraq claims the hack of the Xbox 360 Security Protection Hypervisor.
Is that like some primitive version of what Geordi Laforge wears?
The theory of relativity doesn't work right in Arkansas.
Wait. Don't you mean this allows an Xbox 360 user to run arbitrary code such as alternative operating systems with full privileges and full hardware access on the machine they rightfully own ?
How is this an attack, except in the eyes of MS?
Oct 31, 2006 - release of 4532 kernel, which is the first version
containing the bug
Nov 16, 2006 - proof of concept completed; unsigned code running in
hypervisor context
Nov 30, 2006 - release of 4548 kernel, bug still not fixed
Dec 15, 2006 - first attempt to contact vendor to report bug
Dec 30, 2006 - public demonstration
Jan 03, 2007 - vendor contact established, full details disclosed
Jan 09, 2007 - vendor releases patch
Feb 28, 2007 - full public release
Patch Development Time (In Days): 6
Does MS force updates for things like this?
[Fuck Beta]
o0t!
For a site about things like basic rights, Slashdot users sure do like to censor "dissent".
"Bug was fixed in version 4552 (released Jan 09, 2007 - not a
Patch Tuesday)."
Fixed already for most people , anyone who's connected to xbox live.
I'm not sure why there still protecting the system like they are though, 'backup' games are already rife due to hacked DVD rom firmware (which they seem to be unable to back fix), so why not let it run arbitary code, didnt hurt the xbox 1?
Sadly, unless you haven't updated your machine in the last two months, this wouldn't matter as MS has already patched it. As for those of you with an "unpatched" kernel, let's just say this is like v1.5 PSPs.
Timeline:
..
..
Jan 03, 2007 - vendor contact established, full details disclosed
Jan 09, 2007 - vendor releases patch
Patch Development Time (In Days): 6
Interesting to compare timelines affecting Microsoft's users to timelines affecting Microsoft's control schemes.
Wait. Don't you mean this allows an Xbox 360 user to run arbitrary code such as alternative operating systems with full privileges and full hardware access on the machine they rightfully own ?
It's a joke!
The guy who caught the bug is using techie humor in perfect hacker tradition. He's pretending to take things utterly literally and following them to a redicuilous extreme.
In this case he's doing it by publishing a report of how to crack an Xbox and run an arbitrary OS on it - with complete details on how to replicate it - as a bug report. And he went through the entire procedure:
- Identify and diagnose the problem.
- Build a proof-of-concept test.
- Check it against the latest release (and find the bug still there).
- Notify the vendor (who ignores the report, as usual).
- Give him time to respond (which he doesn't).
- Give a public demonstration.
- Respond in friendly fashion to the vendor-initiated contact (after the public demo lights a fire), giving him the details of the proof-of-concept.
- Give the vendor some time to generate and publish a patch.
- Publish the complete details of the exploit.
He did this just as if it were a bug, rather than a "feature".
Now there is "improved" firmware that fixes the hole. And the complete details are out there. If anybody who actually owns an Xbox who doesn't want to "fix" the "bug" and leaves his firmware backdated, so he can "be exploited by himself" by loading Linux, *BSD, or whatever on his own Xbox, well, that's what he gets for not staying up to date on patch levels.
ROTFLMAO!
Meanwhile the "anonymous hacker" has published (on Bugtraq no less) complete details of how to crack the Xbox (with a backdated firmware load) and run an arbitrary OS on it with full privileges. Yet when it comes to the DMCA he's squeaky-clean. The MAFIAAs and Microsoft have absolutely no claim against him if anybody out there happens to "exploit himself" and use this "bug" to break their "trusted" computing platform.
But there's one thing I don't understand:
Why didn't samzenpus use "The Foot" when he approved this article? B-)
Bantam Dominique roosters crow a four-note song. Once you've heard it as "Happy BIRTHday" you can't NOT hear it that way