Can the BD-JB Blu-ray Disc Java Sandbox Escape by TheFlow be used on the xbox one

Kopimist

Well-Known Member
Member
Joined
Nov 6, 2019
Messages
357
Trophies
0
Age
36
XP
995
Country
United States
I saw on his presentation months ago that the xbox one is also affected by it, so any hope for a jailbreak with this?
In theory, it could work for booting backups burnt to a disc but I don't believe anyone has managed to pull it off. As far as leading to an actual jailbreak of the console for homebrew outside of dev mode, it's not likely
 

Torus

Member
Newcomer
Joined
Dec 12, 2021
Messages
23
Trophies
0
XP
243
Country
Hong Kong
how does someone start with doing this

Using this image: https://www.mediafire.com/file/6a6aexvvm36o3t3/Doom-BluPlay.iso/file (by Shykelit above, who sent me the image months ago at the time of the Tweet). This is just executing Java code contained in the bluray disc.

More info:
https://en.wikipedia.org/wiki/BD-J

A list of homebrew games you can play through this method:
https://www.blu-play.com/links

As for reversing & exploiting the interpreter: it's very easy to obtain the binaries from a dev-mode console nowadays, so it isn't a far-fetched idea to maybe look up for vulns. If anyone wants to look into it feel free to ping me btw
 

lolki

Member
Newcomer
Joined
Nov 22, 2022
Messages
6
Trophies
0
Age
36
XP
42
Country
United States
yes im pretty sure
It's cool.
Using this image: (by Shykelit above, who sent me the image months ago at the time of the Tweet). This is just executing Java code contained in the bluray disc.

More info:

A list of homebrew games you can play through this method:

As for reversing & exploiting the interpreter: it's very easy to obtain the binaries from a dev-mode console nowadays, so it isn't a far-fetched idea to maybe look up for vulns. If anyone wants to look into it feel free to ping me btw
Xbox Series X too works?
 
Last edited by lolki,

XboxModder2

Well-Known Member
OP
Newcomer
Joined
Feb 12, 2022
Messages
54
Trophies
0
Age
23
Location
a desert
XP
288
Country
Libya
Wonder if it will be possible to transfer over the contents of the Xbox One's memory to a PC via FTP with this method in mind?
We should do some testing and post the results, its dire in the xbox one scene lol
Post automatically merged:

Using this image: https://www.mediafire.com/file/6a6aexvvm36o3t3/Doom-BluPlay.iso/file (by Shykelit above, who sent me the image months ago at the time of the Tweet). This is just executing Java code contained in the bluray disc.

More info:
https://en.wikipedia.org/wiki/BD-J

A list of homebrew games you can play through this method:
https://www.blu-play.com/links

As for reversing & exploiting the interpreter: it's very easy to obtain the binaries from a dev-mode console nowadays, so it isn't a far-fetched idea to maybe look up for vulns. If anyone wants to look into it feel free to ping me btw
I am interested in finding some vulnerabilities but i have no idea how to and where to look lol, i already have dev mode and everything
 
Last edited by XboxModder2,

Tomato123

Well-Known Member
Member
Joined
Feb 8, 2020
Messages
735
Trophies
1
Location
England
XP
2,553
Country
United Kingdom
BD-J and BD-JB are not the same thing. BD-J is a standard feature on all Bluray players which follow the standard properly. It allows java code execution in a sandboxed environment. BG-JB specifically targets the PS4/5 implementation of BD-J to allow for full userland code execution. While possible that Microsoft made a similar mistake with their implementation, it's extremely unlikely to be 1:1. Though it is a possible entry point to start looking for vulnerabilities.
 
  • Like
Reactions: CompSciOrBust

XboxModder2

Well-Known Member
OP
Newcomer
Joined
Feb 12, 2022
Messages
54
Trophies
0
Age
23
Location
a desert
XP
288
Country
Libya
ah, sorry buddy totally misread the post, apologies.
no worries
Post automatically merged:

BD-J and BD-JB are not the same thing. BD-J is a standard feature on all Bluray players which follow the standard properly. It allows java code execution in a sandboxed environment. BG-JB specifically targets the PS4/5 implementation of BD-J to allow for full userland code execution. While possible that Microsoft made a similar mistake with their implementation, it's extremely unlikely to be 1:1. Though it is a possible entry point to start looking for vulnerabilities.
ah i see, thanks, so bdjb is the only way forward right?
Post automatically merged:

BD-J and BD-JB are not the same thing. BD-J is a standard feature on all Bluray players which follow the standard properly. It allows java code execution in a sandboxed environment. BG-JB specifically targets the PS4/5 implementation of BD-J to allow for full userland code execution. While possible that Microsoft made a similar mistake with their implementation, it's extremely unlikely to be 1:1. Though it is a possible entry point to start looking for vulnerabilities.

this video shows that the BD-J exploit works though
 

Tomato123

Well-Known Member
Member
Joined
Feb 8, 2020
Messages
735
Trophies
1
Location
England
XP
2,553
Country
United Kingdom

this video shows that the BD-J exploit works though

Because BD-J is not an exploit. It's a feature of the Bluray standard. Easiest way I can try explain is imagine you have BD-J which is like 10% of the system's functionality unlocked (But planned like that by Sony/Microsoft/etc). BD-JB exploits the already unlocked 10% to unlock an extra 40% of that functionality, which is the exploit part of this all. (The percentages are just arbitrary numbers with no real meaning other than to portray my point.)

The names do cause a lot of confusion, but there is a big difference between the two.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • Xdqwerty @ Xdqwerty:
    Also somebody is remaking it
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, the other game where I found newgrounds is new york shark
    +1
  • SylverReZ @ SylverReZ:
    Spoke to Tom Fulp the other day, if he can find his old Newgrounds site content like the mini Flash animations from the 2000's that played on the portal.
  • SylverReZ @ SylverReZ:
    So far no response, but he did say that he'll find them. Wayback Machine doesn't have em.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, atleast the 1999 versión of pico's school is avaliable (the difference between it, the 2006 versión and the 2016 versión is that the speed of the game depends of the speed of your computer and that it had the og soundtrack)
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Another being Pico VS Bear, the original 1999 version before Jim Henson filed a DMCA takedown.
    +1
  • Xdqwerty @ Xdqwerty:
    The 2006 versión was made when the flash portal was made
  • SylverReZ @ SylverReZ:
    Many people thought it was lost, but was discovered that he hid it on the same page.
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, although the "secrets" system where the game was has been removed. Also pico vs uberkids had a netplay versión that was shutdown, although the swf file has been found
  • SylverReZ @ SylverReZ:
    @Xdqwerty, Nope. There are two download buttons on the same page, where you can download the original under a file called "bear.exe". "bear2.exe", however, is the updated game in a Flash projector. P.s. this was on the archived Pico page from 2000.
  • SylverReZ @ SylverReZ:
    @Xdqwerty, That's been there for a long time, too. People who search for lost media don't look hard enough lmao.
    +1
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, also the pico 2 demos used to be only for the newgrounds patrons but they are on internet archive too (https://archive.org/download/picos_school_2)
    +1
  • Xdqwerty @ Xdqwerty:
    Iirc the demos were removed from newgrounds in 2022
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, or well only the demo with mindchamber's style was on newgrounds
    +1
  • Xdqwerty @ Xdqwerty:
    Fun fact @SylverReZ: iirc one of the goals on the fnf Kickstarter stated that pico 2 would be finished but the Kickstarter didnt get enough money for that goal to be fullfiled
  • SylverReZ @ SylverReZ:
    @Xdqwerty, FNF sucks, their community is toxic as hell.
  • The Real Jdbye @ The Real Jdbye:
    @SylverReZ its a single player game
  • Xdqwerty @ Xdqwerty:
    @The Real Jdbye, Yea but it has a shitton of mods with their own songs and stuff
  • Xdqwerty @ Xdqwerty:
    @The Real Jdbye, and quite a lot of people involved in those mods get cancelled
  • SylverReZ @ SylverReZ:
    Newgrounds wasn't the birth of FNF; rather, it was games where you beat up celebrities and parodies.
    +2
  • a_username_that_is_cool @ a_username_that_is_cool:
    FNF was born from Game Jams
  • a_username_that_is_cool @ a_username_that_is_cool:
    Specifically Ludum Dare 47
  • Xdqwerty @ Xdqwerty:
    @SylverReZ, and Sonic fights a la dragón ball z
    Xdqwerty @ Xdqwerty: @SylverReZ, and Sonic fights a la dragón ball z