<?xml version="1.0"?>
<rss version="2.0"><channel><title>Gaming News</title><link>https://ibotmodz.net/gaming_news/</link><description>Manage articles</description><language>en</language><item><title>Xenia - Xbox 360 Emulator Research Project</title><link>https://ibotmodz.net/gaming_news/xenia-xbox-360-emulator-research-project-r44/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/0f8d094ee144ea0e4ffe3a717035db1c.png.be33648c22c9c76482b6e442f4d72954.png" /></p>
<p>Just thought I'd give everyone an update on what I believe is a big part of 2013 and 360 modding. Ben Vanik has begun work on an Xbox 360 Emulator. Currently, it does nothing but some XEX print outs, but the immense amount of time and research put into this project is amazing and shows that 2013 will be the year for 360 Modding.</p><p> </p><p>If you have a GitHub account, you can star this REPO and watch as development progresses. Its open source, as you probably guessed. Whats even more interesting is that Ben's previous jobs include working at Google and Microsoft. </p><p> </p><p><a href="https://github.com/benvanik/xenia" rel="external nofollow">https://github.com/benvanik/xenia</a> -&gt; <a href="http://www.twitter.com/benvanik" class="bbc_url" rel="external nofollow">@benvanik</a></p>]]></description><guid isPermaLink="false">44</guid><pubDate>Sun, 24 Feb 2013 20:00:00 +0000</pubDate></item><item><title>Destiny The Game</title><link>https://ibotmodz.net/gaming_news/destiny-the-game-r43/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/d89117ac3bf76234ed4ea0946f69efbf.jpg.2ddc95c9b57235cde942a8568e193fda.jpg" /></p>
<a href="http://www.youtube.com/watch?feature=player_embedded&amp;v=EwOUi4JDC4o" rel="external nofollow">http://www.youtube.com/watch?feature=player_embedded&amp;v=EwOUi4JDC4o</a>]]></description><guid isPermaLink="false">43</guid><pubDate>Sun, 17 Feb 2013 19:20:00 +0000</pubDate></item><item><title>Bungie's new game?</title><link>https://ibotmodz.net/gaming_news/bungie39s-new-game-r42/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/648d337f4f4ab8591a593697fc28c7e4.jpg.249087dc3257eedec003f6b26b767aa9.jpg" /></p>
<p><span>http://i46.tinypic.com/24yweac.jpg</span></p><p> </p><p>Looks like Skyrim to me.</p>]]></description><guid isPermaLink="false">42</guid><pubDate>Wed, 28 Nov 2012 21:30:00 +0000</pubDate></item><item><title>Return of the Forerunners</title><link>https://ibotmodz.net/gaming_news/return-of-the-forerunners-r41/</link><description><![CDATA[<a href="http://www.youtube.com/watch?v=55zOTemj03k&amp;feature=related" rel="external nofollow">http://www.youtube.com/watch?v=55zOTemj03k&amp;feature=related</a>]]></description><guid isPermaLink="false">41</guid><pubDate>Fri, 05 Oct 2012 14:26:00 +0000</pubDate></item><item><title>A little bit of hype</title><link>https://ibotmodz.net/gaming_news/a-little-bit-of-hype-r40/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/d543d67fd4e34daebc8f5a9a24838a88.jpg.a08fa2c42d12c838606e8dc64f38e974.jpg" /></p>
Just prepping a little hype.]]></description><guid isPermaLink="false">40</guid><pubDate>Tue, 31 Jul 2012 19:25:00 +0000</pubDate></item><item><title>Bungie is no more.</title><link>https://ibotmodz.net/gaming_news/bungie-is-no-more-r38/</link><description><![CDATA[<blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="cms" data-ipsquote-contenttype="records1" data-ipsquote-contentid="38" data-ipsquote-contentclass="cms_Records1"><div>This weekâ€™s Mail Sack marks an important milestone for the Bungie Community. For more than a decade, gamers have been clashing on the virtual battlefields of Halo multiplayer. Ever since Halo 2 brought them together via Xbox LIVE, the statistical analysis enabled by Bungie.net has tracked all of the fragging, shooting, splattering, pummeling, capturing, detonating, controlling, betraying, and assisting you brought to the virtual battlefield. Itâ€™s been a glorious run.<p> </p><p>On Sunday, that comes to a close as we yield the stage to developers who will be ensuring that the legacy of Halo lives on. As the curtain closes on the number crunching and hero making that has been a fixture of this website, we must look back fondly on the wealth of combat achievements that have been tabulated. We must also make sure that your inquiring minds are prepared for closing night. To make sure that we are answering your more complicated questions with the same accuracy that your Sniper Rifles have exhibited these many years, I have enlisted some support from the Bungie.net ensemble.</p></div></blockquote><p> </p><p><span>&lt;!--url{0}--&gt;</span></p>]]></description><guid isPermaLink="false">38</guid><pubDate>Sun, 01 Apr 2012 13:55:00 +0000</pubDate></item><item><title>New Xbox 360</title><link>https://ibotmodz.net/gaming_news/new-xbox-360-r36/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/17ebc2c5e6116dacfac15b2278c473da.jpg.06b6f87e98ec41fd4b50549c11c4c012.jpg" /></p>
<p><span>&lt;!--url{0}--&gt;</span></p><p> </p><p><span>&lt;!--url{1}--&gt;</span></p>]]></description><guid isPermaLink="false">36</guid><pubDate>Wed, 09 Nov 2011 17:05:00 +0000</pubDate></item><item><title>Halo 4 = New Trilogy?</title><link>https://ibotmodz.net/gaming_news/halo-4-new-trilogy-r37/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/8a2a3878cd6ea17dbc4a2cc5358d2543.png.bdbc98dc28f2b4903421f3bc342f0c21.png" /></p>
<blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="cms" data-ipsquote-contenttype="records1" data-ipsquote-contentid="37" data-ipsquote-contentclass="cms_Records1"><div>Halo 4 is the next blockbuster installment in the iconic franchise that's shaped entertainment history and defined a decade of gaming. Set in the aftermath of Halo 3, Master Chief returns to confront his own destiny and face an ancient evil that threatens the fate of the entire universe. <strong>Halo 4 marks the start of a new trilogy </strong>that begins with its release in 2012</div></blockquote>]]></description><guid isPermaLink="false">37</guid><pubDate>Sun, 04 Mar 2012 16:15:00 +0000</pubDate></item><item><title>Horde Command Pack delayed</title><link>https://ibotmodz.net/gaming_news/horde-command-pack-delayed-r35/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/75de41d47a15395cc101726ccc23471a.jpg.882cd0a1e991f028b0aeb39f1ad19f66.jpg" /></p>
<blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="cms" data-ipsquote-contenttype="records1" data-ipsquote-contentid="35" data-ipsquote-contentclass="cms_Records1"><div>The scheduled Horde Command Pack release for Gears of War 3 is temporarily delayed due to a technical issue. We apologize to those of you who are anxiously awaiting to play. We know this is disappointing news as weâ€™ve seen a lot of posts today showing excitement for this content. We have folks working around the clock to resolve this issue ASAP so you can all play and enjoy the Command Pack.<p> </p><p>The Epic Games Community team will stick around and keep you posted with any further information. Stay tuned for updates!</p></div></blockquote><p> </p><p>What a joke. They promise the 1st, and now this.</p>]]></description><guid isPermaLink="false">35</guid><pubDate>Tue, 01 Nov 2011 13:00:00 +0000</pubDate></item><item><title>RAAM is coming to Gears 3</title><link>https://ibotmodz.net/gaming_news/raam-is-coming-to-gears-3-r34/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/a84750272e0a70bdce74020a1bce8414.jpg.f58ec8878912aab76e443044cd4172a0.jpg" /></p>
<blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="cms" data-ipsquote-contenttype="records1" data-ipsquote-contentid="34" data-ipsquote-contentclass="cms_Records1"><div>Microsoft and Epic Games announced â€œ<strong>RAAMâ€™s Shadow</strong>,â€ the new campaign experience for the award-winning blockbuster, "Gears of War 3", Starring a cast of characters both new and eerily familiar to the series, â€œRAAMâ€™s Shadowâ€ will deliver more than <strong>three hours of gameplay set in a storyline that precedes the events of the first â€œGears of War,â€ as well as six new multiplayer characters, the Chocolate Weapon Set and an additional 250 Gamerscore. â€œRAAMâ€™s Shadowâ€ will launch Dec. 13 for 1,200 Microsoft Points on Xbox LIVE Marketplace</strong>, marking the second major game add-on for this yearâ€™s critically-acclaimed blockbuster, â€œGears of War 3.â€</div></blockquote><p> </p><blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="cms" data-ipsquote-contenttype="records1" data-ipsquote-contentid="34" data-ipsquote-contentclass="cms_Records1"><div>RAAMâ€™s Shadow drops players into the events of Sera post-Emergence Day, as Zeta Squad is enlisted to evacuate Ilima City and protect the citizens against a Locust Kryll storm. Taking on the infamous Locust leader from Gears 1, General RAAM, Zeta is led by Michael Barrick (from Gears comics fame) and comprised of familiar faces such as Lt. Minh Young Kim (Gears 1) and Tai Kaliso (Gears 2), and also includes a new female comrade, Alicia Valera.</div></blockquote><span style="font-size:10px"> (roughly 3 hours of extra gameplay)</span><p> </p><p>Yes, if you have the Season Pass you are fine.</p><p> </p><p>New characters:</p><ul><li><span style="color:#000000"><strong>RAAM</strong></span> - General RAAM was a silent and savage Locust general. Once a Theron Guard, the cunning and ambitious RAAM usurped the military leadership of the Locust Horde through skill and intellect. When using him in campaign, it has been confirmed you are able to use the Kryll as a shield.<br></li><li><span style="color:#0000FF"><strong>Minh Young Kim</strong></span> - Lieutenant Minh Young Kim was a Gear officer who served in the Coalition of Ordered Governments army during the Locust War, most notably during the Lightmass Offensive. A firm, honorable soldier with a "by-the-book" leadership style. If you remember, he got sliced by RAAM.<br></li><li><span style="color:#0000FF"><strong>Michael Barrick</strong></span>- Corporal Michael Barrick was a former Stranded who enlisted with the Coalition of Ordered Governments army using Operation Lifeboat, becoming a Gear soldier.<br></li><li><span style="color:#0000FF"><strong>Tai Kaliso</strong></span> - Corporal Tai Kaliso was a Gear soldier who hailed from Irohma Island in the South Islands. He joined the Coalition of Ordered Governments army after his hometown was wiped out by Union of Independent Republics forces during the Pendulum Wars. A boulder of a man, Tai's muscular appearance stands in contrast to his quiet, meditative personality. If you remember, he killed himself after being tortured by locust.<br></li><li><span style="color:#0000FF"><strong>Alicia Valera</strong></span> - No information given, except she is voiced by Aisha Tyler.<br></li></ul><p></p>]]></description><guid isPermaLink="false">34</guid><pubDate>Fri, 21 Oct 2011 15:40:00 +0000</pubDate></item><item><title>Battlefield 3 Xbox 360 is 'Standard-Def' without Texture Pack</title><link>https://ibotmodz.net/gaming_news/battlefield-3-xbox-360-is-39standard-def39-without-texture-pack-r33/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/e9fc84091a8adf598134e892bc3ba85f.jpg.35caab1d3cf112c97b2cca406a074748.jpg" /></p>
<blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="cms" data-ipsquote-contenttype="records1" data-ipsquote-contentid="33" data-ipsquote-contentclass="cms_Records1"><div>360 owners are going to want to clear some space on their hard-drive ahead of next week's Battlefield 3 launch.<p> </p><p>As previously reported, the 360 version of Battlefield 3 will ship with an additional DVD containing a texture pack for optional installation to the 360's hard-drive. These high-definition textures will be streamed from the hard-drive during the game to enhance DICE's visual representation of its own take on modern warfare.</p><p> </p><p>The original story raised a number of questions concerning a possible disparity between the different versions of Battlefield 3 and so at this week's EA showcase in London, Gamerzines asked executive producer, Patrick Bach, to clarify the purpose of the optional texture pack.</p><p> </p><p>"There's nothing magic about it," explained Bach. "It's the same thing we do for PC and PS3, so there's nothing extra."</p><p>"I think the controversy about this is that we actually let you do it on 360 for once. So what it does is it gives you the same abilities, kind of, as the PC and PS3. You can actually stream information from the hard drive.</p><p></p></div></blockquote><p> </p><p>Whats this? I don't have extra GBs laying around my harddrive. I only have the stupid internal 4gb. If they pack a 500mb texture file onto my hdd. I'm gonna be pissed.</p>]]></description><guid isPermaLink="false">33</guid><pubDate>Thu, 20 Oct 2011 12:45:00 +0000</pubDate></item><item><title>Gears of War DLC Pack 1</title><link>https://ibotmodz.net/gaming_news/gears-of-war-dlc-pack-1-r32/</link><description><![CDATA[<p>Adding three new Horde maps, the Horde Command Pack also includes new  fortification upgrades and new characters, making it a worthwhile  addition to the Horde 2.0 mayhem, as well as adding 250 Gamerscore of  new achievements to unlock. Here's the complete list of Horde Command  Pack contents:</p><p> </p><p><strong>Three new maps:</strong></p><ul><li><strong>Blood Drive</strong>  â€“ The Jacinto Medical Plaza was overwhelmed by evacuated citizens after  the government-sanctioned Hammer Strikes, and the ensuing riots quickly  turned this safe haven into a dangerous inferno. An abundance of high  ground and funneled choke points make this map a returning favorite to  Horde<br></li><li><strong>Rustlung</strong> â€“ Once the  pride of the Royal Tyran Navy, the foredecks of this decommissioned  battleship are now riddled with bullet holes. Any team with the  fortitude to hold the exposed central torpedo bay will find that the  shipâ€™s Loader has been replaced with a battle-ready Silverback mech  suit.<br></li><li><strong>Azura</strong> â€“ This island  resort was once the exclusive domain of Seraâ€™s educated elite, but the  tranquil water gardens and lush foliage have become a hotly contested  combat zone. Dual snipers overlook a powerful explosive weapon, while  the defensive central platform may be your last resort of retreat.<br></li></ul><p></p><p><strong>New fortification upgrades:</strong></p><ul><li><strong>Command Center</strong>  â€“ A brand new type of fortification that allows you to call in fire  support from sniper teams, mortar strikes and even multiple Hammers of  Dawn.<br></li><li><strong>Decoy Upgrade</strong> â€“ A new fortification level that turns your decoy into an Onyx Guard bot that will fight in your defense.<br></li><li><strong>Sentry Upgrade</strong> â€“ This upgrade adds a fire bolt sentry that deals much more damage and is very effective against Berserkers.<br></li><li><strong>Silverback Upgrade</strong>  â€“ This advancement allows you to upgrade your Silverback exo-suit with  devastating rockets and extra levels of repair cost reduction.<br></li></ul><p></p><p><strong>New characters:</strong></p><ul><li><strong>Onyx Guard</strong><br></li><li><strong>Big Rig Dizzy</strong><br></li><li><strong>Bernie</strong><br></li></ul><p></p><p><strong>New weapon skins:</strong></p><ul><li><strong>Team Plasma</strong><br></li><li><strong>Jungle Camo</strong><br></li></ul><p></p><p>This is also playable in Beast Mode and private Versus matches, which  means the Gears of War 3 Horde Command Pack is a snip at 800 Microsoft  Points or at a 33% discount as part of a Season Pass purchase. You'll be  able to grab it from November 1st. Check out four new screens from the  add-on right here.</p><p> </p><p><em>NEW CHARACTERS</em></p><p><a href="http://i52.tinypic.com/dq6sg8.jpg" rel="external nofollow">http://i52.tinypic.com/dq6sg8.jpg</a></p><p> </p><p>RUSTLUNG</p><p><a href="http://i55.tinypic.com/3313h1w.jpg" rel="external nofollow">http://i55.tinypic.com/3313h1w.jpg</a></p><p> </p><p>BLOOD DRIVE</p><p><a href="http://i56.tinypic.com/2mwuslh.jpg" rel="external nofollow">http://i56.tinypic.com/2mwuslh.jpg</a></p><p> </p><p>AZURA</p><p><a href="http://i56.tinypic.com/16746lk.jpg" rel="external nofollow">]http://i56.tinypic.com/16746lk.jpg</a></p>]]></description><guid isPermaLink="false">32</guid><pubDate>Tue, 04 Oct 2011 15:10:00 +0000</pubDate></item><item><title>343i Reveals Gameplay Footage For New Skull</title><link>https://ibotmodz.net/gaming_news/343i-reveals-gameplay-footage-for-new-skull-r31/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/df764dba23aa357a74ffe4dc1a8b4c70.jpg.6519cda612cbf621d1938e79e2e9f96a.jpg" /></p>
<p>343i has revealed the gameplay footage for the pre-order exclusive skull, Grunt Funeral.</p><p><a href="http://www.youtube.com/watch?v=UYfNBCHYHFE" rel="external nofollow">http://www.youtube.com/watch?v=UYfNBCHYHFE</a></p>]]></description><guid isPermaLink="false">31</guid><pubDate>Thu, 29 Sep 2011 23:31:00 +0000</pubDate></item><item><title>Xbox 360 Reset Glitch Hack - Unsigned Code on current Kernels incl. X360 SLIM</title><link>https://ibotmodz.net/gaming_news/xbox-360-reset-glitch-hack-unsigned-code-on-current-kernels-incl-x360-slim-r30/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/92e10c7b40906980e3b1e58670a52f45.png.982edbaf4aea50c7157668a250295beb.png" /></p>
<p>GliGli &amp; Tiros are proving the opposite! They developed a Hack which glitches all recent Xbox360 Kernels to run unsigned Code on:</p><p> </p><p>ZEPHYR, JASPER .......and...... TRINITY (aka SLIM!).</p><p>(no matter which Dashboard/Kernel they are running)</p><p> </p><p><a href="http://www.youtube.com/watch?v=JyYdL4L6vwE" rel="external nofollow">http://www.youtube.com/watch?v=JyYdL4L6vwE</a></p><p> </p><p> </p><p> </p><p> </p><p></p><pre class="ipsCode">**********************************
* The Xbox 360 reset glitch hack *
**********************************

Introduction / some important facts
===================================

tmbinc said it himself, software based approaches of running unsigned code on the 360 mostly don't work, it was designed to be secure from a software point of view.

The processor starts running code from ROM (1bl) , which then starts loading a RSA signed and RC4 crypted piece of code from NAND (CB).

CB then initialises the processor security engine, its task will be to do real time encryption and hash check of physical DRAM memory. From what we found, it's using AES128 for crypto and strong (Toeplitz ?) hashing. The crypto is different each boot because it is seeded at least from:
 - A hash of the entire fuseset.
 - The timebase counter value.
 - A truly random value that comes from the hardware random number generator the processor embeds. on fats, that RNG could be electronically deactivated, but there's a check for "apparent randomness" (merely a count of 1 bits) in CB, it just waits for a seemingly proper random number.

CB can then run some kind of simple bytecode based software engine whose task will mainly be to initialise DRAM, CB can then load the next bootloader (CD) from NAND into it, and run it.

Basically, CD will load a base kernel from NAND, patch it and run it.

That kernel contains a small privileged piece of code (hypervisor), when the console runs, this is the only code that would have enough rights to run unsigned code.
In kernel versions 4532/4548, a critical flaw in it appeared, and all known 360 hacks needed to run one of those kernels and exploit that flaw to run unsigned code.
On current 360s, CD contains a hash of those 2 kernels and will stop the boot process if you try to load them.
The hypervisor is a relatively small piece of code to check for flaws and apparently no newer ones has any flaws that could allow running unsigned code.

On the other hand, tmbinc said the 360 wasn't designed to withstand certain hardware attacks such as the timing attack and "glitching".

Glitching here is basically the process of triggering processor bugs by electronical means.

This is the way we used to be able to run unsigned code.

The reset glitch in a few words
===============================

We found that by sending a tiny reset pulse to the processor while it is slowed down does not reset it but instead changes the way the code runs, it seems it's very efficient at making bootloaders memcmp functions always return "no differences". memcmp is often used to check the next bootloader SHA hash against a stored one, allowing it to run if they are the same. So we can put a bootloader that would fail hash check in NAND, glitch the previous one and that bootloader will run, allowing almost any code to run.

Details for the fat hack
========================

On fats, the bootloader we glitch is CB, so we can run the CD we want.

cjak found that by asserting the CPU_PLL_BYPASS signal, the CPU clock is slowed down a lot, there's a test point on the motherboard that's a fraction of CPU speed, it's 200Mhz when the dash runs, 66.6Mhz when the console boots, and 520Khz when that signal is asserted.

So it goes like that:
- We assert CPU_PLL_BYPASS around POST code 36 (hex).
- We wait for POST 39 start (POST 39 is the memcmp between stored hash and image hash), and start a counter.
- When that counter has reached a precise value (it's often around 62% of entire POST 39 length), we send a 100ns pulse on CPU_RESET.
- We wait some time and then we deassert CPU_PLL_BYPASS.
- The cpu speed goes back to normal, and with a bit of luck, instead of getting POST error AD, the boot process continues and CB runs our custom CD.

The NAND contains a zero-paired CB, our payload in a custom CD, and a modified SMC image.
A glitch being unreliable by nature, we use a modified SMC image that reboots infinitely (ie stock images reboot 5 times and then go RROD) until the console has booted properly.
In most cases, the glitch succeeds in less than 30 seconds from power on that way.

Details for the slim hack
=========================

The bootloader we glitch is CB_A, so we can run the CB_B we want.

On slims, we weren't able to find a motherboard track for CPU_PLL_BYPASS.
Our first idea was to remove the 27Mhz master 360 crystal and generate our own clock instead but it was a difficult modification and it didn't yield good results.
We then looked for other ways to slow the CPU clock down and found that the HANA chip had configurable PLL registers for the 100Mhz clock that feeds CPU and GPU differential pairs.
Apparently those registers are written by the SMC through an I2C bus.
I2C bus can be freely accessed, it's even available on a header (J2C3).
So the HANA chip will now become our weapon of choice to slow the CPU down (sorry tmbinc, you can't always be right, it isn't boring and it does sit on an interesting bus 

So it goes like that:
- We send an i2c command to the HANA to slow down the CPU at POST code D8 .
- We wait for POST DA start (POST DA is the memcmp between stored hash and image hash), and start a counter.
- When that counter has reached a precise value, we send a 20ns pulse on CPU_RESET.
- We wait some time and then we send an i2c command to the HANA to restore regular CPU clock.
- The cpu speed goes back to normal, and with a bit of luck, instead of getting POST error F2, the boot process continues and CB_A runs our custom CB_B.

When CB_B starts, DRAM isn't initialised so we chose to only apply a few patches to it so that it can run any CD, the patches are:
- Always activate zero-paired mode, so that we can use a modified SMC image.
- Don't decrypt CD, instead expect a plaintext CD in NAND.
- Don't stop the boot process if CD hash isn't good.

CB_B is RC4 crypted, the key comes from the CPU key, so how do we patch CB_B without knowing the CPU key?
RC4 is basically:
 crypted = plaintext xor pseudo-random-keystream
So if we know plaintext and crypted, we can get the keystream, and with the keystream, we can encrypt our own code. It goes like that:
 guessed-pseudo-random-keystream = crypted xor plaintext
 new-crypted = guessed-pseudo-random-keystream xor plaintext-patch
You could think there's a chicken and egg problem, how did we get plaintext in the first place?
Easy: we had plaintext CBs from fat consoles, and we thought the first few bytes of code would be the same as the new CB_B, so we could encrypt a tiny piece of code to dump the CPU key and decrypt CB_B!

The NAND contains CB_A, a patched CB_B, our payload in a custom plaintext CD, and a modified SMC image.
The SMC image is modified to have infinite reboot, and to prevent it from periodically sending I2C commands while we send ours.

Now, maybe you haven't realised yet, but CB_A contains no checks on revocation fuses, so it's an unpatchable hack !

Caveats
=======

Nothing is ever perfect, so there are a few caveats to that hack:
- Even in the glitch we found is pretty reliable (25% success rate per try on average), it can take up to a few minutes to boot to unsigned code.
- That success rate seems to depend on something like the hash of the modified bootloader we want to run (CD for fats and CB_B for slims).
- It requires precise and fast hardware to be able to send the reset pulse.

Our current implementation
==========================

We used a Xilinx CoolRunner II CPLD (xc2c64a) board, because it's fast, precise, updatable, cheap and can work with 2 different voltage levels at the same time.
We use the 48Mhz standby clock from the 360 for the glitch counter. For the slim hack, the counter even runs at 96Mhz (incremented on rising and falling edges of clock)
The cpld code is written in VHDL.
We need it to be aware of the current POST code, our first implementations used the whole 8 bits POST port for this, but we are now able to detect the changes of only 1 POST bit, making wiring easier.

Conclusion
==========

We tried not to include any MS copyrighted code in the released hack tools.
The purpose of this hack is to run Xell and other free software, I (GliGli) did NOT do it to promote piracy or anything related, I just want to be able to do whatever I want with the hardware I bought, including running my own native code on it.

Credits
=======

GliGli, Tiros: Reverse engineering and hack development.
cOz: Reverse engineering, beta testing.
Razkar, tuxuser: beta testing.
cjak, Redline99, SeventhSon, tmbinc, anyone I forgot... : Prior reverse engineering and/or hacking work on the 360.</pre><div></div><p></p>]]></description><guid isPermaLink="false">30</guid><pubDate>Sun, 28 Aug 2011 15:15:00 +0000</pubDate></item><item><title>Halo Anniversary Pre-Order Bonuses Announced</title><link>https://ibotmodz.net/gaming_news/halo-anniversary-pre-order-bonuses-announced-r29/</link><description><![CDATA[<p>343i is at it again, this time announcing the pre-order bonuses for Halo Anniversary. </p><blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="cms" data-ipsquote-contenttype="records1" data-ipsquote-contentid="29" data-ipsquote-contentclass="cms_Records1"><div>Master Chief Avatar Armorâ€“ Heroes Never Die, and to honor the 10th anniversary of John 117, you will finally be able to transform your Xbox LIVE Avatar into the iconic hero by outfitting it with Master Chiefâ€™s signature MJOLNIR Powered Assault Armor.<p> </p><p>â€œGrunt Funeralâ€ Skull â€“ An exclusive, game-modifying skull that changes the rules of the game for an explosively humorous experience, â€œGrunt Funeralâ€ sends Haloâ€™s most lowly and lovable enemy out in a blaze of glory. And plasma. And then more glory. Once the skull has been activated, every Gruntâ€™s methane tank will explode like a plasma grenade when killed. Watch out for the Grunt chain reaction!</p></div></blockquote><p>The grunts burn in their final blaze of glory Nov. 15, 2011.</p>]]></description><guid isPermaLink="false">29</guid><pubDate>Tue, 19 Jul 2011 19:25:00 +0000</pubDate></item><item><title>Epic Statement about GOW 3 Leak</title><link>https://ibotmodz.net/gaming_news/epic-statement-about-gow-3-leak-r28/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/6db8f5e3dd80bd180fb8a3a001b22104.jpg.3b1b76aa391112a5ba145145c500cd85.jpg" /></p>
<p>After videos and copies of the highly anticipated Gears of War 3 appeared on the web, Epic did not hesitate in realeasing an official statement.</p><blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="cms" data-ipsquote-contenttype="records1" data-ipsquote-contentid="28" data-ipsquote-contentclass="cms_Records1"><div><p>Dana Cowley, head of PR for Epic Games has taken the time to release an official statement regarding the Gears of War 3 leak, despite her being on vacation. Yesterday, reports of an early build of Gears 3 had been leaked onto the web. This early build contains the full campaign as well as all the gameâ€™s multiplayer modes. We were just emailed a joint statement from Microsoft and Epic via Dana Cowley:</p><p> </p><p></p><p><div style="margin-left:25px">    </div><div style="margin-left:25px"><em>We have seen the reports of Gears of War 3 content being propped on the Web and working closely with our security teams and law enforcement to address the situation. This content is not from a final build and is not representative of what fans will enjoy when the game launches worldwide on September 20, 2011.</em></div></p><p></p><p> </p><p>We hope to see this resolved. There has still been no word on whether or not anything will be added to the retail version of the game that was not included in the leaked version.</p><p> </p><p>Justin McFarland</p><p>Save &amp; Quit</p></div></blockquote>]]></description><guid isPermaLink="false">28</guid><pubDate>Sun, 03 Jul 2011 22:00:00 +0000</pubDate></item><item><title>Halo Reach Title Update Announced</title><link>https://ibotmodz.net/gaming_news/halo-reach-title-update-announced-r27/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/59cb9472be07246ae13dba15ba53e04a.png.13bdfc0f731522f0d530ea53c883f195.png" /></p>
<p>It seems that old man Bungie has been holding the community back, as many players have been demanding a title update for months. Some of the most prominent demands include a more classic halo feel in matchmaking, as well as more custom game options to be available. 343i has been listening, and has announced that they are working on a patch that will be released soon after Bungie officially hand over control of reach to them.</p><p> </p><blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="cms" data-ipsquote-contenttype="records1" data-ipsquote-contentid="27" data-ipsquote-contentclass="cms_Records1"><div>Weâ€™re pleased to confirm that weâ€™re planning a Title Update (a small download which will add some interesting functionality) for Halo: Reach in preparation for the multiplayer aspect of Halo: Anniversary.<p> </p><p>If your heart suddenly sped up, fret not, Reach fan. This is something that will not only sit side-by-side with Reachâ€™s existing gameplay and will be accessible by both Reach and Anniversary players, but will allow us to make fairly significant changes to multiplayer gameplay within the confines of Matchmaking. Weâ€™ve talked about this as a way to better recreate the classic Halo: CE feel for the new classic maps, and it will let us do some things in gameplay that simply arenâ€™t possible now. I donâ€™t want to give too much away until we get through gameplay and bug-testing, but an example scenario would be allowing you to play, say, [REDACTED] with zero fall damage. Now thatâ€™s a limited and simplistic example, but it does speak to the way weâ€™re approaching the changes philosophically. There are some bigger ticket â€œclassicâ€ Halo gameplay elements which people are clamoring for and which we intend to do our best to deliver on. More news about specific changes and the timing of the Title Update will be forthcoming. But I can say that, having tried a few of the more significant tweaks, certain â€œclassicâ€ elements are already working with beautiful and deadly efficiency. </p></div></blockquote><p>Heres hoping we get access to all the options that Bungie left out of the menu (and chooses to tease us with, making thier own gametypes that use options we cannot access.)</p>]]></description><guid isPermaLink="false">27</guid><pubDate>Thu, 30 Jun 2011 05:10:00 +0000</pubDate></item><item><title>Modern Warfare 3 Leaked</title><link>https://ibotmodz.net/gaming_news/modern-warfare-3-leaked-r26/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/859a87fcfcb8529673e6bd99d2ff2221.jpg.6ee17923bc91f0a3f1e8474b6cdc7bf8.jpg" /></p>
<p>"In one of the biggest gaming leaks ever, Modern Warfare 3 has been leaked" ~Jack from Rooster Teeth</p><p> </p><blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="cms" data-ipsquote-contenttype="records1" data-ipsquote-contentid="26" data-ipsquote-contentclass="cms_Records1"><div>Call of Duty: Modern Warfare 3 is coming Nov. 8, 2011, Kotaku has learned, delivering with it mammoth battles that engulf a dozen cities around the world including New York, Paris and London.<p> </p><p>Multiple sources have shared details of the game's story, art, sounds and game modes with Kotaku, noting that the game will reshape the landscape of the Call of Duty franchise, bringing an impressive number of eclectic settings, deep multiplayer gaming and a story that ties up nearly all loose ends from previous titles, including the final moments of key figures in the series' history.</p><p>While we haven't seen the game in action ourselves, we've gone to great lengths to nail down as much as possible the veracity of our sources. We believe that the imagery and chief details are accurate. That doesn't mean things can't change before release, but this appears to be a full run down of where Infinity Ward, Sledgehammer Games and Raven Software is on Modern Warfare 3 as they add the final polishing touches.</p></div></blockquote><p> </p><p>Game modes, characters, locations, tons of stuff has been leaked...</p><p> </p><p><a href="http://kotaku.com/5801226/the-modern-warfare-3-files-exclusive-first-details-on-the-biggest-game-of-2011" rel="external nofollow">Full article</a> &lt;-- SPOILER ALERT</p>]]></description><guid isPermaLink="false">26</guid><pubDate>Mon, 16 May 2011 23:40:00 +0000</pubDate></item><item><title>Geohot VS Sony = OVER</title><link>https://ibotmodz.net/gaming_news/geohot-vs-sony-over-r25/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/b1f1176295ef3d454ba01e9cf73a5db3.png.8eb65c7c7468161f04e0fce919c0c741.png" /></p>
<blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="cms" data-ipsquote-contenttype="records1" data-ipsquote-contentid="25" data-ipsquote-contentclass="cms_Records1"><div>The legal action between Sony and George Hotz has come to a close, with both sides seemingly happy with the results. Sony has Hotz agreeing not to do bad things to its hardware, and Hotz gets to be left alone and continue with his life. Neither side has admitted any liability in the matter, and things seemed to have worked out... for the best?</div></blockquote><p> </p><p> </p><p>Quote from geohot's <a href="http://geohotgotsued.blogspot.com/" rel="external nofollow">website</a>: </p><p> </p><blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="cms" data-ipsquote-contenttype="records1" data-ipsquote-contentid="25" data-ipsquote-contentclass="cms_Records1"><div>As promised, all left over legal defense money, plus a little to bump it to a nice number, has been sent to the EFF. Thank you all so much for your support, without it, things could have been much worse.<p> </p><p>This money goes to the EFF in hopes that America can one day again be a shining example of freedom, free of the DMCA and ACTA, and that private interest will never trump the ideas laid out in the constitution of privacy, ownership, and free speech.</p><p> </p><p>At the end of the day, something I take comfort in. The PS3 got OWNED.</p><p>"Once the code works they'll never be able to take it away from us."</p><p><strong>Will you be continuing your work on Sony products anonymously?</strong></p><p>Nah. As much as I don't respect the goons at Sony, I do respect the court.</p><p><strong>Will future research on Sony products be chilled?</strong></p><p>Nah. If you piss them off enough for them to pull out the legal team and their million dollar checkbook, worst thing that happens is you have to super swear to never do it again.</p><p> </p><p><strong>Will Sony do a better job with security next time?</strong></p><p>LOL, I think they'll do a lot worse. It wouldn't surprise me if the people who did PS3 security were fired. And I'm curious as to who Sony is hiring for NGP security. Lawyers? Get the code to sign a contract that it won't have exploits? You shouldn't piss off the community of people who are actually talented at this stuff. Hell, maybe you even pissed off your engineering employees enough to leave some nice backdoors?</p></div></blockquote>]]></description><guid isPermaLink="false">25</guid><pubDate>Sat, 16 Apr 2011 15:10:00 +0000</pubDate></item><item><title>Halo Chess Now  A Reality</title><link>https://ibotmodz.net/gaming_news/halo-chess-now-a-reality-r24/</link><description><![CDATA[
<p><img src="https://ibotmodz.net/uploads/monthly_2024_11/d500e79874d5139945cd289c0b545827.jpg.39912090026dc4caa81d7fa1e644fc83.jpg" /></p>
<p>Remember april fools last year? When bungie claimed they were making a chess game mode for reach?</p><p>Bungie does, which is why they released an official chess variant to the community.</p><blockquote data-ipsquote="" class="ipsQuote" data-ipsquote-contentapp="cms" data-ipsquote-contenttype="records1" data-ipsquote-contentid="24" data-ipsquote-contentclass="cms_Records1"><div> You can play Chess on any map that contains the necessary Forge objects. That means Tempest is in, and oddly enough Anchor 9 also makes the grade, making Space Chess a certified Space Reality. Thatâ€™s one small step for a man, one giant leap forâ€¦well, you know the rest.</div></blockquote><p>It appears that it utilizes bump possession, and does not have a checkmate thus forcing players to rely on the honor system for certain aspects of the game.</p><p>Get your fix here: <a href="http://www.bungie.net/Stats/Reach/FileDetails.aspx?fid=15992988" rel="external nofollow">http://www.bungie.net/Stats/Reach/FileDetails.aspx?fid=15992988</a></p><p>Heres a video from rooster teeth explaining how to play:</p><p><a href="http://www.youtube.com/watch?v=M2FrLwkgLZk&amp;feature=player_embedded" rel="external nofollow">http://www.youtube.com/watch?v=M2FrLwkgLZk&amp;feature=player_embedded</a></p>]]></description><guid isPermaLink="false">24</guid><pubDate>Sat, 09 Apr 2011 17:15:00 +0000</pubDate></item></channel></rss>
