Hacking DVD Drive Vulnerability

TomChaai

Active Member
Newcomer
Joined
Oct 17, 2022
Messages
31
Trophies
0
Age
32
XP
410
Country
China
you are absolutely correct - they earned well from XGD3 protection
So I think we have two topics:
1: Figure out how to gain debug access to the "MSODDDSP" chip to figure out how it boots securely, for example how it encrypts, integrity protects and restricts access to its firmware flash chip. Find a way to dump the drive key and compile new firmware to flash it like on the 360. This should at least help with drive repairs even if loading backup discs aren't possible yet.
According to you at least getting into the chip is possible now?

2: Figure out the disc logical structure and topology layout to understand the possibility of C/R spoofing. From what I understand, XGD3 used a variety of "bad" sectors that are crafted in a certain way that a normal drive won't be able to read and write back identically, the drive reads raw channel bitstream and also measures angular distances between some of them, compare to the prerecorded C/R table to verify if the disc is genuine.
Is the dual overlapping track technology already present on XGD3? Or is it XGD4 exclusive? If the similar technology is already present on XGD3, we can probably move the similar "topology data" countermeasure used in LTU firmware to here.
 
  • Like
Reactions: Torus and Kopimist

MrQQ

Well-Known Member
Newcomer
Joined
Feb 3, 2022
Messages
78
Trophies
0
Age
36
Location
Scotland
XP
439
Country
United Kingdom
So I think we have two topics:
1: Figure out how to gain debug access to the "MSODDDSP" chip to figure out how it boots securely, for example how it encrypts, integrity protects and restricts access to its firmware flash chip. Find a way to dump the drive key and compile new firmware to flash it like on the 360. This should at least help with drive repairs even if loading backup discs aren't possible yet.
According to you at least getting into the chip is possible now?

2: Figure out the disc logical structure and topology layout to understand the possibility of C/R spoofing. From what I understand, XGD3 used a variety of "bad" sectors that are crafted in a certain way that a normal drive won't be able to read and write back identically, the drive reads raw channel bitstream and also measures angular distances between some of them, compare to the prerecorded C/R table to verify if the disc is genuine.
Is the dual overlapping track technology already present on XGD3? Or is it XGD4 exclusive? If the similar technology is already present on XGD3, we can probably move the similar "topology data" countermeasure used in LTU firmware to here.
To a degree but you forget that every deviation angle now is truly random. Rip it once thats fine but rip those same sectors or angles again and it will be truly random. This is I assume how the "silver bullet method" was discovered when it came to AP25 challenges and responses. Firmware CRC checking is also a clear reality and has been since the slims but its good to discuss this to someone who has clear knowledge of this. Could you send me a PM. Myself and a few others have been looking into this in private channels :) and regarding XGD4 it is exclusive from what I can see and again, truly random your entire premise is all correct provided even step one can be completed.
 

Finray

New Member
Newbie
Joined
Aug 30, 2022
Messages
4
Trophies
0
Age
41
Location
home
XP
53
Country
United States
Yes!..I would hope research continues in this. It is very suprising to me that there doesnt seem to be much interest in this. I think it would be extremely useful for booting backups of OG and 360 disc's. Especially because Xenia is still wonky. Just imagine, you pop in your backup of SH-Downpour because your original is scratched to all heck and it recognizes it as legit and grabs the license.
 
Last edited by Finray,
  • Like
Reactions: BigOnYa

blinkoutatime

New Member
Newbie
Joined
Jul 23, 2023
Messages
2
Trophies
0
Age
39
XP
12
Country
United States
I do not think the BD is the key to finding exploits here, I honestly believe the drive itself has nothing to do with getting an exploit working. Not that it isn't a possible route to take, but I think there are more than one. These checks would be irrelevant on systems without the disc drive. It may be a way to find an exploit on original systems, but how that would affect non disc systems can't be predicted. I believe web exploit in the web apps is the key to running unsigned code on this system, considering the possible vulnerabilities here. The key(s) needed to do so would need to be found first, which I am told they have been by the real people who hacked PS3 and WiiU, they are the same group of 3 people. There is a ton of misinformation on who actually helped hack these systems and the real people do not want their names given out, I can tell you that some people on this forum claim to have been these people but they are not.

On a serious side note: I am wondering how you can 'overlap' tracks while burning to BD. BDs have two layers on bigger games, not every BD has multiple layers and both layers cannot/do not overlap or touch. The tracks cannot overlap on a single layer for obvious reasons, so then they would need to overlap between the two layers to accomplish some type of security feature, but those layers could still be read separately and then looked at from this angle after dumping. Then we would would probably need to do this again with another disc and compare the two dumped layers of each BD looking for byte similarities, that would be a clue as to where these 'keys' are and how/when they are used by the system.
 

TomChaai

Active Member
Newcomer
Joined
Oct 17, 2022
Messages
31
Trophies
0
Age
32
XP
410
Country
China
I do not think the BD is the key to finding exploits here, I honestly believe the drive itself has nothing to do with getting an exploit working. Not that it isn't a possible route to take, but I think there are more than one. These checks would be irrelevant on systems without the disc drive. It may be a way to find an exploit on original systems, but how that would affect non disc systems can't be predicted. I believe web exploit in the web apps is the key to running unsigned code on this system, considering the possible vulnerabilities here. The key(s) needed to do so would need to be found first, which I am told they have been by the real people who hacked PS3 and WiiU, they are the same group of 3 people. There is a ton of misinformation on who actually helped hack these systems and the real people do not want their names given out, I can tell you that some people on this forum claim to have been these people but they are not.

On a serious side note: I am wondering how you can 'overlap' tracks while burning to BD. BDs have two layers on bigger games, not every BD has multiple layers and both layers cannot/do not overlap or touch. The tracks cannot overlap on a single layer for obvious reasons, so then they would need to overlap between the two layers to accomplish some type of security feature, but those layers could still be read separately and then looked at from this angle after dumping. Then we would would probably need to do this again with another disc and compare the two dumped layers of each BD looking for byte similarities, that would be a clue as to where these 'keys' are and how/when they are used by the system.
Drive hacks ONLY allow you to run backups that have identical content as authentic discs, nothing more, it does not allow unsigned code execution in any way. Oh maybe it also helps console repair effort, there are many consoles without a matching drives bricked during an update, if we can rekey the drives we can repair them.

Overlapping tracks are not burned onto a burnable BD, instead it's burned onto the master disc and stamped onto production stamped discs instead.

The master disc is a truly flat surface, with only data pits aligned to form a spiral data track, it can be burned twice to create overlapping features. "Burnable" BDs that you can buy from retail channels and burn with consumer burners are "pre-tracked" with valley-like blank data tracks so consumer burner lasers can track them. Since consumer burnable discs are already built, the track feature cannot be changed in any way.

It is not very useful to compare "byte streams", some features are truly random on a physical level, meaning for the SAME drive and SAME disc, read it twice and the byte streams can be different because those features are built to trick the drive electronics to measure them incorrectly and often randomly. A successful firmware hack needs not only to replay captured answers, but also replay different possible answers, or know how the answers will probably be generated on a physical level and simulate that.
 
  • Like
Reactions: MrQQ

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Minox @ Minox:
    No idea what any of those things you mention are
    +1
  • K3Nv2 @ K3Nv2:
    Cholesterol and Triglycerides? Basically a way they measure fatty cells in your blood
  • AncientBoi @ AncientBoi:
    Cholesterol is sorta high, according to my doc
    +1
  • K3Nv2 @ K3Nv2:
    I've been taking fiber pills, eating more grapes, switched to wheat bread in hopes to lower it
    +1
  • BigOnYa @ BigOnYa:
    I like wheat bread, I even like the chunky wheat bread with pieces of whole grain in it.
  • K3Nv2 @ K3Nv2:
    Been getting this honey wheat bread from aldis pretty decent not very sweet to out do it
  • K3Nv2 @ K3Nv2:
    Me making any food at home is an improvement to how I use to be
    +1
  • BigOnYa @ BigOnYa:
    I have an bread machine and use it alot, better than breads you buy, but don't last as long, cause no bs preservatives
  • K3Nv2 @ K3Nv2:
    I got compliments about my weight loss and thought well guess I can pig out again now I'm the piggy
  • BigOnYa @ BigOnYa:
    My biggest prob is alcohol, definitely is fattening
  • K3Nv2 @ K3Nv2:
    I know when to stop at least honestly don't get those that go and go with food
  • BigOnYa @ BigOnYa:
    Or those that order 2 big macs , large fry, ice cream sundie, then a diet coke
  • K3Nv2 @ K3Nv2:
    I might get downing two big macs but nah that's it
  • BigOnYa @ BigOnYa:
    Ok that will be $15.99, cash or charge?
  • K3Nv2 @ K3Nv2:
    My go to orders usually a mcdouble and a mcchicken and I'm happy rarely mess with fries
  • K3Nv2 @ K3Nv2:
    Pro tip ask for that clowns jizzmac sauce on your mcdouble
    +1
  • BigOnYa @ BigOnYa:
    Do they charge extra when you add sauce,etc? I know burger king used to not, but don't know nowadays
  • K3Nv2 @ K3Nv2:
    They may squrit it for free if you ask nice
    +1
  • K3Nv2 @ K3Nv2:
    Last time I got bk it was 35c per sauce fuck you king of my nutsack
    +1
  • K3Nv2 @ K3Nv2:
    I'll buy a bottle of baby rays BBQ for $2 and add it from home out of spite
    +1
  • BigOnYa @ BigOnYa:
    I like baby rays, my favorite is KC masterpiece tho. Figured all you could buy is that there.
  • K3Nv2 @ K3Nv2:
    The metro doesn't discriminate good sauce
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    Baby Rays isn't that what killed the crocodile hunter?
  • Psionic Roshambo @ Psionic Roshambo:
    If only he had done an endorsement for them....
  • Psionic Roshambo @ Psionic Roshambo:
    Oy mate don't let a bad bbq sauce kill your party! Baby Rays are killing it!! The flavor hits you right in the chest!
    Psionic Roshambo @ Psionic Roshambo: Oy mate don't let a bad bbq sauce kill your party! Baby Rays are killing it!! The flavor hits...