You are viewing our Forum Archives. To view or take place in current topics click here.
How To Downgrade Dashboard
Posted:

How To Downgrade DashboardPosted:

muffmagnet09
  • TTG Senior
Status: Offline
Joined: Feb 17, 201014Year Member
Posts: 1,586
Reputation Power: 66
Status: Offline
Joined: Feb 17, 201014Year Member
Posts: 1,586
Reputation Power: 66
I have heard this was impossible quite a few times
well no its not im going to give some links and tell how to do it


[ Register or Signin to view external links. ] (downloads for downgrades)


When you remove the Xbox Live patches, you can do all the glitches that were patched, but this removes the patches for all of your games. No saved game data will be lost, but you will need to repatch everything when you sign-in to Xbox Live.Go to the system blade on the dashboard. Select memory and push the GREEN button. Select hard drive. Press YELLOW to view device options. When the page opens press BLUE, BLUE, LB, RB, BLUE, BLUE. A message, "This will perform maintenance on your xbox 360 storage devices. Do you want to continue?" Select "yes" and press GREEN to execute. Restart your Xbox 360 with the uninstall.this is how you dupe items with the updated patch though.

----

Robinsod managed to successfully boot his Xbox360 with one flashed eFuse with kernel 1888 using the timing attack we talked about some weeks ago. It's not something everyone out there can do yet, but as more information gets released (it's an open source project ) and things get optimized and developed further it might open homebrew and linux for the Xbox360 on a much larger scale soon. Of course once your 360 is back to an (older) vulnerable kernel (4532,4548), you won't be able to go on LIVE anymore (it only accepts the latest kernel (5766 atm)) ... but a dual kernel system is a possibility (using a xD memory card even).
From Robinsod on XBH:


Done it! My bricked box - one blown eFuse but no CPU key and no valid flash dump that would boot (I did have a valid 2241 dump though that would no longer boot because of the eFuse) - is now alive and well and booting 2.0.1888 with a patched CB (LD count = 1) and a "guessed" hash. Even doing it "manually" only took 3 evenings ;) Now, sleep

Just to be clear, the timing attack will allow you to downgrade to 2.0.1888. You can then upgrade to 4532 & run the KK sploit and obtain your CPU keys. You should be able to replace the original CB after the upgrade (this needs to be confirmed) and then the only "clue" to what happened is that you may have 1 or 2 more burned eFuses for the HV/Kernel version you are running.

It should be possible, soon, for anyone with an Infectus modchip and 20 Euros worth of homebrew hardware to downgrade. Dont forget the Kiosk disk is usable again too!



Here's a bit more info about his "proof of concept" downgrader hardware:


I'm using the Infectus chip (with a dll interface provided by them) to rewrite one NAND block with sequential hash guesses. The process takes approx 1 second. The Hynix data sheet quotes a 100,000 read write cycles, our worst case is 4096 or 4%. Since this is a one time operation I think 4% wear is acceptable.
Some PIC processors have CCP modules that allow an internal 16 bit counter to be sampled when a +ve or -ve edge is detected, the counter is claimed to have a 50nS resolution although I'm not convinced ;) Simple software in the PIC allows me to detect the end of CE and the POST port changing from 0x21 => 0xA4 (the end of hashing). The PIC also drives the JTAG reset line. A couple of cheap interface ICs and some passives complete the design - you will definitely be able to build your own hardware from easy to obtain parts, on stripboard, for around 20 Euros.
Controlling all this is some PC software that can generate the required CB section patch, control the infectus and the PIC. It would seem that the "cycle" time should be less than 3 seconds. To test this I am using the 360 I "bricked" at christmas, I don't know the CPU key for this box so I cant "cheat" and test each correctly "guessed" hash byte.

Once I finish testing I will post more info followed by a complete, open source package of hardware and software so you can build your own in a few hours. Now might be a good time to get that infectus chip.

One final point, a lot of the people who want to downgrade will probably have recent versions of the applications (dash, media player etc etc). Some of the latest dashes definitely completely replaced the dash.xex (and possibly others) rather than write new xexp files. These newer versions of the applications definitely require newer system libs and I doubt they will boot on a 2.0.1888 machine. We will need to obtain an image of a clean 2.0.1888 file system.



More useful information by Arnezami explaining the attack:


The timing attack does not try to "bruteforce" the cpu key itself. It tries to find/bruteforce a hash value which is a result of the usage of the cpu key (so even if you have that hash you still cannot backwards compute the cpu key). But finding this hash value (I usually refer to it as the CB-auth value) will enable the xbox to boot the original kernel (v 1888). This then allows you to upgrade to a vulnerable kernel (eg 4532) and THEN you can extract the cpu key using the kk exploit.

Since -on average- you will find the correct value at roughly half of the possible byte values you only need to try (approx) 128 values for each of the 16 bytes. Thats why vax is talking about 16 * 128 total number if byte changes...
There is a theoretical minimum to the reboot time of about 1 second. So in theory you could find the 16 bytes in 34 minutes. Thats probably not gonna happen. Grin And installing the hardware will probably take even more time so its not a really big issue. But this is basically where the time speculations are based on.



News-Source/More Details: xboxhacker.net(1) | xboxhacker.net(2)



I was not saying I have done it, I am just saying that it is in fact possible.




However, you can do a typical downgrad to the original DASHBOARD of your Xbox by doing a factory dump, memory-erase, and re-boot. You can do that by the first method I posted above.

credit to DiggityISback for this amazing stuff i didnt know this and doubt alot of people did so decided to share with you guys
#2. Posted:
Yizzy
  • TTG Senior
Status: Offline
Joined: Mar 07, 201014Year Member
Posts: 1,677
Reputation Power: 70
Status: Offline
Joined: Mar 07, 201014Year Member
Posts: 1,677
Reputation Power: 70
haha, why wuld u ask for a sticky in da chat box?
#3. Posted:
ShyGuy
  • Blind Luck
Status: Offline
Joined: Apr 03, 201014Year Member
Posts: 2,224
Reputation Power: 807
Status: Offline
Joined: Apr 03, 201014Year Member
Posts: 2,224
Reputation Power: 807
This is patched.... Dum A$$


- Shy :p
#4. Posted:
IncrediBowl
  • TTG Senior
Status: Offline
Joined: Aug 22, 201013Year Member
Posts: 1,318
Reputation Power: 66
Status: Offline
Joined: Aug 22, 201013Year Member
Posts: 1,318
Reputation Power: 66
This is fake the e-fuse went boom...
#5. Posted:
muffmagnet09
  • TTG Senior
Status: Offline
Joined: Feb 17, 201014Year Member
Posts: 1,586
Reputation Power: 66
Status: Offline
Joined: Feb 17, 201014Year Member
Posts: 1,586
Reputation Power: 66
Assination wrote haha, why wuld u ask for a sticky in da chat box?

why wouldnt i if its very useful ?
and if it dusnt work im very sorry this is just what i heard
#6. Posted:
ShyGuy
  • TTG Addict
Status: Offline
Joined: Apr 03, 201014Year Member
Posts: 2,224
Reputation Power: 807
Status: Offline
Joined: Apr 03, 201014Year Member
Posts: 2,224
Reputation Power: 807
muffmagnet09 wrote
Assination wrote haha, why wuld u ask for a sticky in da chat box?

why wouldnt i if its very useful ?
and if it dusnt work im very sorry this is just what i heard



Your retarded for thinking it works.... Dont troll other sites just to steal their tutorials...


- Shy :p
#7. Posted:
Uzi
  • TTG Elite
Status: Offline
Joined: Apr 05, 200915Year Member
Posts: 12,208
Reputation Power: 885
Status: Offline
Joined: Apr 05, 200915Year Member
Posts: 12,208
Reputation Power: 885
Wow to get everything a Jtag is needed

-uzi
#8. Posted:
RizzJizz
  • TTG Senior
Status: Offline
Joined: Jan 24, 201014Year Member
Posts: 1,668
Reputation Power: 70
Status: Offline
Joined: Jan 24, 201014Year Member
Posts: 1,668
Reputation Power: 70
yeah do not troll dude........
#9. Posted:
Fnatic-Fenix
  • Challenger
Status: Offline
Joined: Oct 30, 201013Year Member
Posts: 148
Reputation Power: 5
Status: Offline
Joined: Oct 30, 201013Year Member
Posts: 148
Reputation Power: 5
if this works then nice find dude
Jump to:
You are viewing our Forum Archives. To view or take place in current topics click here.