Slashdot Log In
Hackers Dodge Xbox Live Shutout
Posted by
Zonk
on Thursday May 31, @05:35PM
from the over-the-wall dept.
from the over-the-wall dept.
An Ars Technica post at their games column Opposable Thumbs points out that, despite Microsoft's best efforts, hacked Xbox 360s are once again playing on Xbox Live. "Steadfast in their pursuits, the hackers of the Xbox 360 scene have managed to best Microsoft's Xbox Live Banning protocol: a system of checks in place to identify hacked Xbox 360s and deny them access to the Xbox Live Network. The current method of hacking the 360 involves exploiting the firmware of the DVD drive (the preferable method), and this latest patch does just that. In fact, the creators are so confident in their breakthrough that the info file remarks that the new firmware 'defeats all current and some future Xbox Live detection attempts.'"
Related Stories
[+]
Microsoft Bans Modified Xbox 360s From Xbox Live 334 comments
An anonymous reader writes "Microsoft has now officially started banning Xbox 360s that have had their DVD drive firmware modified from Live, possibly using information brought in by the Crackdown-originated Halo 3 beta downloads. Scene site forums have already collapsed under traffic, and Microsoft has officially confirmed that they are banning modded Xbox 360s to keep the online playing field fair and level."
The Fine Print: The following comments are owned by whoever posted them. We are not responsible for them in any way.
How long until....
(Score:2, Funny)(http://theirishtoole.blogspot.com/)
Re:How long until....
(Score:5, Insightful)(http://slashdot.org/)
Eventually another unsigned code vulnerability may be found (which is what you would need to run a modfied client), but this will almost definately not be a result of modifying the DVD-ROM firmware.
Once again...
(Score:2)(http://www.holyhell.net/blog)
Even if Microsoft had 1000 people working on this, the hackers would still be ahead. It's impossible to estimate how many people take a shot at console hacking just for the hell of it.
Inevitably, the hackers dominate just about any platform. That's just the way it works.
Re:Once again...
(Score:5, Interesting)Case Study: A game I was part of the dev team for held an online, sponsored tournament. The four finalists were flown to Hawaii where they competed head to head on rigs provided by the company for the championship. One of the final four had been playing phenominally online, yet once he got to Hawaii, his game fell completely apart. He complained endlessly about how the computer he was playing on was different from what he was used to at home. Yet the other three players didn't complain at all. This guy got completely, embarassingly destroyed in the finals. And we eventually patched the hole he'd used to cheat his way to the finals.
But don't miss the fact that only 1 out of the 4 finalists was a cheater (I believe first place won $50,000 with a shot at a million-dollar challenge). The other three were simply legitimately good players.
Hmm
(Score:3, Insightful)(http://slashdot.org/ | Last Journal: Wednesday March 06, @04:46PM)
Only a Half-Win
(Score:1)Excellent
(Score:1)Trusted Computing
(Score:3, Funny)Trusted Computing: noun
The act of trusting that any possible attack vector against a computers expected behavior will be done so by those that have nothing better to do than to game the system.
Deja vu
(Score:1, Informative)Please stop saying cheating is impossible
(Score:2)I know that PGR3 and Gears of War being hacked in such a way its quite possible there are many more games.
Now this still may just be an excuse from MS though quite frankly they dont really need one, virtually the only other purpose of a modchip is piracy.
Either way cheating _is_ possible it _has_ been done and banning the modders _will_ stop it regardless of why you really think they have started the bannings.
*There may be other files you can use as well I cant say ive looked in to it much which is why im amazed at how many people claim to be knowledgable about these things yet seem to have missed the fact that there have been super supercars in PGR3 for months.
Can I
(Score:1)Clearing up some FUD
(Score:3, Informative)1) To re-iterate what others are saying, the firmware hack does not defeat executable signatures, so the integrity of game code has not been compromised, however, game data files can be, and have been, compromised (Exo's GoW hacks). The simple solution is to update the executable with hard-coded data file checksums to go along with their weak signature security (in this case, on the GoW data files). So it's not entirely true that the firmware hack doesn't allow cheaters - but Microsoft has other avenues they can pursue in preventing cheaters. This wave of bannings represents an escalation in Microsoft's policy toward modders.
2) Something that many here miss, is that Microsoft has no direct access to the firmware for some models of the DVD drive they are using. Toshiba-Samsung MS28 drives, for example, have "Firmguard" - an attempt to thwart modders that has backfired on Microsoft. Why? Because powercycling the DVD with the correct VIA SATA chipset bypasses Firmguard as part of it's "Bad Flash" recovery mode. Microsoft cannot do this on the 360. This means they cannot read, nor write firmware to these drives.
There were several techniques Microsoft employed against modders in this last wave, verified by special debugging firmware employed - Microsoft was using an anomaly in the firmware's fetch of special sectors to determine if backups were employed (moddded Hitachi drives gave up the goods on this one), as well as more strict checking of those sectors (catching non-"stealth" backups), and finally, using Challenge/Response commands to do threshold timing (many used slower or faster timings on the firmware, which was detectable as being outside of thresholds).
There are still less reliable checks Microsoft may employ, but that dragnet will scoop up some legitmate users, too (No DVD Error code check, used to see who's been using their Xbox 360 as a power supply for the drive as they flashed it). If I was on the team, I'd rule that one out. There are a few other techniques, which I won't mention, since they haven't been discussed publicly, as the others I mentioned have (besides, Microsoft KNOWS how they are checking currently) - which have been identified and "fixed" in the current iXtreme 1.0 firmware.
For what it's worth, many, many 360 modders have NOT been banned. It may be these checks were only performed when they were actively playing a backup on Live... no pattern has emerged, and much of the data is suspect (panicky users, usual liars, etc...).
If Microsoft wants to defeat cheaters, all they need to do is employ a couple of interns to surf the scene sites for hack news, then simply order up special bannin' updates for those hacked games, to detect cheater's data files and ban those specific machines. Future game releases could incorporate some security libraries to make data files more secure (the code currently cannot be hacked).
Re:Does it really even matter?
(Score:2, Funny)I assume that this will remain a theoretical maximum until such time as the 32nd PS3 is actually sold?
Re:Does it really even matter?
(Score:2, Informative)Re:Does it really even matter?
(Score:2)Complaints of them being laggy are anecdotal at best, exaggerations in general. I've played XBL since crimson skies was available on the original - normally on a comcast or better connection. Sometimes I have a laggy connection, but that's only if the game I'm playing uses a wrong/bad algorithm for picking a host or if the host becomes laggy after it's been picked.
Instead, a large portion of the games I play have so much going on, lag is the last thing I'm thinking about.
Indeed, the benefits of XBL over free-for-all networks are more than just a connection, mostly it's trueskill or some variant that games implement. If I'm a level 20+ player in halo2/cod3, etc. I'm all but guaranteed to play similarly leveled people. This means I'm not subject to my teammates/opponents fucking around (team killing, lagging, quitting, or other forms of douchebaggery) near as much as some free for all. I get to play with highly skilled people, AGAINST highly skilled people, and have fun.
Re:Does it really even matter?
(Score:1)Re:Does it really even matter?
(Score:2)(http://www.whyshouldihaveone.com/)
Re:Does it really even matter?
(Score:2)Take the stick out of your ass, slashbot.
Re:Future detection attempts?
(Score:2)(Last Journal: Sunday May 27, @04:41AM)
Re:Does it really even matter?
(Score:1)Re:Does it really even matter?
(Score:1)(http://catprog.tfcentral.com/)