Looking for testers for potential xbox one vulnerabilities

XboxModder2

Well-Known Member
OP
Newcomer
Joined
Feb 12, 2022
Messages
54
Trophies
0
Age
22
Location
a desert
XP
278
Country
Libya
1669742937038.png



Hello there, It has been confirmed that the BD-JB Blu-ray Disc Java Sandbox Escape by TheFlow can be used on the xbox one family and potentially xbox series x/s, even on the current firmware of each of the consoles, so the tech is available on the Xbox One. We would need to dump the interpreter's binary and look for vulnerabilities. As for reversing & exploiting the interpreter: it's very easy to obtain the binaries from a dev-mode console nowadays, so it isn't a far-fetched idea to maybe look up for vulns.


How? (quoted from torus)

"You'll likely need to do static reverse engineering of that application, using tools like Ghidra, IDA Pro, or radare2.
To do that, you first also need to find the application itself in your devmode console, and extract it to your PC. Where can you find the binary in charge of executing BD-J in the xbox one? Honestly no idea. I took a quick look at the drivers in C:\Windows\System32 in the Xb1 to see if I could quickly identify something related to ODD, BD, BluRay but I saw nothing. I'll let you know if I stumble upon it, or, if someone knows where to look into, don't hesitate to share w/ all of us :)"

Post automatically merged:
 
Last edited by XboxModder2,
  • Like
Reactions: Kopimist

Kopimist

Well-Known Member
Member
Joined
Nov 6, 2019
Messages
357
Trophies
0
Age
36
XP
995
Country
United States
If I had a blu-ray burner I'd be a tester but alas I do not. I do have Durango ftp installed on retail mode on my Xbox one, not sure if that's of any help at all for poking around inside the system files.

If I can be of assistance in anyway please let me know :)
 
  • Like
Reactions: XboxModder2

XboxModder2

Well-Known Member
OP
Newcomer
Joined
Feb 12, 2022
Messages
54
Trophies
0
Age
22
Location
a desert
XP
278
Country
Libya
Post automatically merged:

If I had a blu-ray burner I'd be a tester but alas I do not. I do have Durango ftp installed on retail mode on my Xbox one, not sure if that's of any help at all for poking around inside the system files.

If I can be of assistance in anyway please let me know :)
will do!
 
  • Like
Reactions: Kopimist

Kopimist

Well-Known Member
Member
Joined
Nov 6, 2019
Messages
357
Trophies
0
Age
36
XP
995
Country
United States
Post automatically merged:


will do!
Just to clarify, I don't have access to dev mode nor can I afford it at this point in time. I wish Microsoft was still doing free dev accounts for students, I'd be all set. Oh well, I missed that boat on that offer
 

MrQQ

Well-Known Member
Newcomer
Joined
Feb 3, 2022
Messages
78
Trophies
0
Age
36
Location
Scotland
XP
429
Country
United Kingdom
This isnt going to lead to anything sadly based on my own research. No sandbox escape or hyperv escape. ODD key is stored in NVram on the ODD and cannot be read as registers for the flash arent known. You may be able to achieve some sort of userland exploit but the ryzen co processor will be watching. Much more research needed sadly.
 

XboxModder2

Well-Known Member
OP
Newcomer
Joined
Feb 12, 2022
Messages
54
Trophies
0
Age
22
Location
a desert
XP
278
Country
Libya
This isnt going to lead to anything sadly based on my own research. No sandbox escape or hyperv escape. ODD key is stored in NVram on the ODD and cannot be read as registers for the flash arent known. You may be able to achieve some sort of userland exploit but the ryzen co processor will be watching. Much more research needed sadly.
Oh alright, thank you for the information, but can this be considered as some sort of escape from the sandbox?
 

TomChaai

Active Member
Newcomer
Joined
Oct 17, 2022
Messages
31
Trophies
0
Age
32
XP
404
Country
China
Oh alright, thank you for the information, but can this be considered as some sort of escape from the sandbox?

He said the escalation happened on dev consoles, so it won't work on retail.
Escaping the BD app probably does nothing as the administrator privilege only happens in appOS, it can't reach down into the hostOS, it probably isn't able to see the real hardware, only the virtual ones presented to the appOS by the hostOS.
You can mess with the appOS all you want, still nothing gets to the hostOS to alter the gameOS from what I know.
And the fact that this is dev mode only probably means you have zero insight into the retail side of things, which uses totally different key trees enforced by the hostOS and the security processor on the SoC, can't even get to the files in this situation.
 

fringle

Well-Known Member
Member
Joined
Apr 16, 2009
Messages
704
Trophies
1
XP
1,108
Country
Canada
He said the escalation happened on dev consoles, so it won't work on retail.
Escaping the BD app probably does nothing as the administrator privilege only happens in appOS, it can't reach down into the hostOS, it probably isn't able to see the real hardware, only the virtual ones presented to the appOS by the hostOS.
You can mess with the appOS all you want, still nothing gets to the hostOS to alter the gameOS from what I know.
And the fact that this is dev mode only probably means you have zero insight into the retail side of things, which uses totally different key trees enforced by the hostOS and the security processor on the SoC, can't even get to the files in this situation.
He said Dev mode not Dev console. If you are not aware Dev mode is an option available on retail consoles. It use to be free but MS started charging for access to it.
 

XboxModder2

Well-Known Member
OP
Newcomer
Joined
Feb 12, 2022
Messages
54
Trophies
0
Age
22
Location
a desert
XP
278
Country
Libya
He said the escalation happened on dev consoles, so it won't work on retail.
Escaping the BD app probably does nothing as the administrator privilege only happens in appOS, it can't reach down into the hostOS, it probably isn't able to see the real hardware, only the virtual ones presented to the appOS by the hostOS.
You can mess with the appOS all you want, still nothing gets to the hostOS to alter the gameOS from what I know.
And the fact that this is dev mode only probably means you have zero insight into the retail side of things, which uses totally different key trees enforced by the hostOS and the security processor on the SoC, can't even get to the files in this situation.



it is dev mode
 

lolki

Member
Newcomer
Joined
Nov 22, 2022
Messages
6
Trophies
0
Age
36
XP
42
Country
United States
Is there something we can do? If yes, how? Otherwise, let's wait for news, one day there will be for sure, and it's a matter of time.
 
  • Like
Reactions: XboxModder2

lolki

Member
Newcomer
Joined
Nov 22, 2022
Messages
6
Trophies
0
Age
36
XP
42
Country
United States
Are the keys in dev the same keys in retail mode? asking another way: if I get the keys in dev mode, I believe that dev mode is superior to retail mode and provides the basis for this or because it has more privileges than retail mode: so should it work or are the systems completely different? thanks for the patience
 

MrQQ

Well-Known Member
Newcomer
Joined
Feb 3, 2022
Messages
78
Trophies
0
Age
36
Location
Scotland
XP
429
Country
United Kingdom
Are the keys in dev the same keys in retail mode? asking another way: if I get the keys in dev mode, I believe that dev mode is superior to retail mode and provides the basis for this or because it has more privileges than retail mode: so should it work or are the systems completely different? thanks for the patience
No they are not. Retails keys are not known as I said earlier
 

Kopimist

Well-Known Member
Member
Joined
Nov 6, 2019
Messages
357
Trophies
0
Age
36
XP
995
Country
United States
Are the keys in dev the same keys in retail mode? asking another way: if I get the keys in dev mode, I believe that dev mode is superior to retail mode and provides the basis for this or because it has more privileges than retail mode: so should it work or are the systems completely different? thanks for the patience
Dev mode runs in a sandbox so it's limited in comparison to retail mode. Major difference is it lets you run unsigned homebrew etc though. I mean theoretically if someone could write an exploit to break out of said sandbox that would be another option. Much easier said than done though I'm afraid. The Xbox One is pretty damn locked down against software exploits. I wonder if attacking via hardware might be a better option. Perhaps some sort of hardware mod to enable a coldboot exploit or something. Of course I'm just brainstorming here. Retail keys may still need to be dumped for even that to work but I'm honestly not sure
 
  • Like
Reactions: MrQQ

TomChaai

Active Member
Newcomer
Joined
Oct 17, 2022
Messages
31
Trophies
0
Age
32
XP
404
Country
China
He said Dev mode not Dev console. If you are not aware Dev mode is an option available on retail consoles. It use to be free but MS started charging for access to it.
Doesn't change anything, dev mode is the same on retail or dev consoles, as long as it is the "same" dev mode, SRA/UWA or ERA. We have retail consoles activated as ERA just fine, not the free/cheap SRA stuff MS gives out to the general public.
Dev mode runs on seperate keychains entirely, anyting done dev mode can't be decrypted by retail keychains.
If there is no hostOS exploit, any dev mode changes are useless.
Post automatically merged:




it is dev mode

Doesn't change anything. A retail console in dev mode is an entirely separate instance, reaching sideways from appOS into gameOS isn't possible, you need to reach down into hostOS, hypervisor or even SP then reach up into gameOS for any useful exploit to happen.
 
Last edited by TomChaai,
  • Like
Reactions: Torus

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • No one is chatting at the moment.
  • Quincy @ Quincy:
    Usually when such a big title leaks the Temp will be the first to report about it (going off of historical reports here, Pokemon SV being the latest one I can recall seeing pop up here)
  • K3Nv2 @ K3Nv2:
    I still like how a freaking mp3 file hacks webos all that security defeated by text yet again
  • BigOnYa @ BigOnYa:
    They have simulators for everything nowdays, cray cray. How about a sim that shows you playing the Switch.
  • K3Nv2 @ K3Nv2:
    That's called yuzu
    +1
  • BigOnYa @ BigOnYa:
    I want a 120hz 4k tv but crazy how more expensive the 120hz over the 60hz are. Or even more crazy is the price of 8k's.
  • K3Nv2 @ K3Nv2:
    No real point since movies are 30fps
  • BigOnYa @ BigOnYa:
    Not a big movie buff, more of a gamer tbh. And Series X is 120hz 8k ready, but yea only 120hz 4k games out right now, but thinking of in the future.
  • K3Nv2 @ K3Nv2:
    Mostly why you never see TV manufacturers going post 60hz
  • BigOnYa @ BigOnYa:
    I only watch tv when i goto bed, it puts me to sleep, and I have a nas drive filled w my fav shows so i can watch them in order, commercial free. I usually watch Married w Children, or South Park
  • K3Nv2 @ K3Nv2:
    Stremio ruined my need for nas
  • BigOnYa @ BigOnYa:
    I stream from Nas to firestick, one on every tv, and use Kodi. I'm happy w it, plays everything. (I pirate/torrent shows/movies on pc, and put on nas)
  • K3Nv2 @ K3Nv2:
    Kodi repost are still pretty popular
  • BigOnYa @ BigOnYa:
    What the hell is Kodi reposts? what do you mean, or "Wut?" -xdqwerty
  • K3Nv2 @ K3Nv2:
    Google them basically web crawlers to movie sites
  • BigOnYa @ BigOnYa:
    oh you mean the 3rd party apps on Kodi, yea i know what you mean, yea there are still a few cool ones, in fact watched the new planet of the apes movie other night w wifey thru one, was good pic surprisingly, not a cam
  • BigOnYa @ BigOnYa:
    Damn, only $2.06 and free shipping. Gotta cost more for them to ship than $2.06
    +1
  • BigOnYa @ BigOnYa:
    I got my Dad a firestick for Xmas and showed him those 3rd party sites on Kodi, he loves it, all he watches anymore. He said he has got 3 letters from AT&T already about pirating, but he says f them, let them shut my internet off (He wants out of his AT&T contract anyways)
  • K3Nv2 @ K3Nv2:
    That's where stremio comes to play never got a letter about it
  • BigOnYa @ BigOnYa:
    I just use a VPN, even give him my login and password so can use it also, and he refuses, he's funny.
  • BigOnYa @ BigOnYa:
    I had to find and get him an old style flip phone even without text, cause thats what he wanted. No text, no internet, only phone calls. Old, old school.
  • Psionic Roshambo @ Psionic Roshambo:
    @BigOnYa, Lol I bought a new USB card reader thing on AliExpress last month for I think like 87 cents. Free shipping from China... It arrived it works and honestly I don't understand how it was so cheap.
    +1
    Psionic Roshambo @ Psionic Roshambo: @BigOnYa, Lol I bought a new USB card reader thing on AliExpress last month for I think like 87... +1