Hacking A question about 1BL

overlord00

A motherfucking birdplane
OP
Member
Joined
Sep 12, 2009
Messages
661
Trophies
0
XP
482
Country
So ever since the days of the KK hack, the 1BL code has been known and used, and is an important part of what the scene knows about the booting of the XBOX.
I have been doing some reading lately and pretty much stumbled onto this question;
where did tmbinc get this information from?

The 1BL is, and quoting from FREE60.org "Stored in CPU rom, decrypts and starts CB bootloader".
a better explaination was given again on FREE60.org "Buried deep inside the CPU die, this ~32kb of ROM code is responsible for reading the 2BL from NAND-flash and decrypts it into the embedded SRAM in the CPU"
How the crap did he manage to get this code? Dump something from the CPU? use assembly to read back and go through until he found something that might be useful?

I have tried to read as best i can about this, but havnt really been able to get any information whatsoever. Its as if he pulled it out of no where.
Does anyone know what sort of process was used or what this sort of thing would have you be doing?
tmbinc seems like a genius. (and in all cases probably is)
Anyone clear even a part of this up for me?

Thanks all.
 

DinohScene

Gay twink catboy
Global Moderator
Joined
Oct 11, 2011
Messages
22,552
Trophies
4
Location
Восторг
XP
22,808
Country
Antarctica
boot0 also lies inside the Wii CPU and is dumped, or at least known.

If you have full control over the hardware you can read out ANYTHING you want to.
It just takes a lot of knowledge and programming skills to achieve it.
 

overlord00

A motherfucking birdplane
OP
Member
Joined
Sep 12, 2009
Messages
661
Trophies
0
XP
482
Country
which really doesnt answer anything :P

"If you have full control over the hardware you can read out ANYTHING you want to."
yeah, but to have full control, dont you need to know things... like 1BL? :P
 

DinohScene

Gay twink catboy
Global Moderator
Joined
Oct 11, 2011
Messages
22,552
Trophies
4
Location
Восторг
XP
22,808
Country
Antarctica
KK hack loaded a Linux distro via unencrypted shaders into the memory (which wasn't checked by the HV etc etc)

From there you can read out anything you want and decrypt it with a normal computer.
Or for some stuff let the 360 decrypt it on-the-fly.

I don't know how Felix did this but this is about as accurate as I can guess.

It basically the same with dumping DS/GBA games, DVD drive FW, PS2 BIOS dumping, NAND dumping etc.
Read it out and save it, then build tools to decrypt them.
 

overlord00

A motherfucking birdplane
OP
Member
Joined
Sep 12, 2009
Messages
661
Trophies
0
XP
482
Country
actually, thats pretty informative.
Thanks again DinohScene.

I hadnt concidered the KK hack didnt need any real information about the system to perform its hack.
Well, that's one (possible) step closer to the truth...
 

DinohScene

Gay twink catboy
Global Moderator
Joined
Oct 11, 2011
Messages
22,552
Trophies
4
Location
Восторг
XP
22,808
Country
Antarctica
You're welcome ;]

The same can be applied to reading out the FW of a Slim 360 drive.
It can be read out but cannot be written to unless you preform a hardware hack.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BakerMan
    I rather enjoy a life of taking it easy. I haven't reached that life yet though.
  • BigOnYa @ BigOnYa:
    I don't trust the free ones, but ipvanish I've used for couple years now, n like
  • Psionic Roshambo @ Psionic Roshambo:
    I wonder if they could get CPUs to run that hot then use the heat to power a steam turbine to power the CPUs....
  • BigOnYa @ BigOnYa:
    Good idea, or at least power the GPU
  • Psionic Roshambo @ Psionic Roshambo:
    It's not the movies or games downloads that I would worry about, like breaking into networks, downloading encrypted things, spying on network traffic. I have seen so many "Top Secret" seals on files when I was a kid
  • Psionic Roshambo @ Psionic Roshambo:
    I was obsessed with finding UFOs, a surprising amount of US files where stashed on computers in other countries, China back in the early 90s omg sooo much
  • BigOnYa @ BigOnYa:
    Yea that crazy, I've never tried hack into anything, I just pirate, and my ISP have send me 3-4 letters, so had to VPN it
  • Psionic Roshambo @ Psionic Roshambo:
    Ship to ship communication software for the Navy although without access to the encrypting chips it was mostly useless
  • Psionic Roshambo @ Psionic Roshambo:
    I bet now a 4090 could probably crack it? Hmmm maybe not even back then I'm pretty sure they where using like 1024 bit encryption
  • Psionic Roshambo @ Psionic Roshambo:
    Yayyy the one set finished 324GBs lol
  • Psionic Roshambo @ Psionic Roshambo:
    Compressed....
  • Psionic Roshambo @ Psionic Roshambo:
    I wonder how many years that would have taken on a 56K modem lol
  • Psionic Roshambo @ Psionic Roshambo:
    18000 hours lol
  • Psionic Roshambo @ Psionic Roshambo:
    750 days lol
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    So Internet is very much faster now lol
  • BigOnYa @ BigOnYa:
    "Time Remaining- 2 years, 9 girlfriends, 6 hairstyles, please standby..."
    +1
  • Psionic Roshambo @ Psionic Roshambo:
    I remember one time I downloaded like a 500MB ISO file on 56K and that literally took like 2 days
  • Psionic Roshambo @ Psionic Roshambo:
    I had some sort of resume thing, I remember the software had chains
  • Psionic Roshambo @ Psionic Roshambo:
    Damned if I can't remember.the name though
  • Psionic Roshambo @ Psionic Roshambo:
    Some sort of download management app
  • BigOnYa @ BigOnYa:
    Ok good chatting, I'm off to the bar, to shoot some pool, nighty night.
    +1
  • BakerMan @ BakerMan:
    hey psi
  • BakerMan @ BakerMan:
    i call your girl lyndon the way she b on my johnson
    BakerMan @ BakerMan: i call your girl lyndon the way she b on my johnson