Modders hint at potential kernel exploit hack for Xbox One consoles

xbawks.png

It's been a while since Microsoft released the Xbox One, and despite its age, there haven't been any reliable softmod methods to hack the console. Until now. A post started making the rounds, saying that a method for executing kernel level code on the Xbox One had been found. A list of instructions for preparing Xbox One systems to be hacked was also provided, with the process being as follows:

  1. Ensure your Xbox Live account Login-Type is configured as “No barriers” aka. auto-login with no password prompt
  2. Set your console as “Home Console” for this account
  3. Download the App Game Script
  4. Start the app (to ensure license is downloaded/cached)
  5. Take your console offline! To make extra sure it cannot reach the internet, set a manual primary DNS address of 127.0.0.1
  6. Get a device/microcontroller that can simulate a Keyboard (rubber ducky or similar) - otherwise you have to type a lot manually :D

This method appears to use a UWP app called Game Script on the Xbox One to execute the code, and was discovered by a user named carrot_c4k3. It seems as though the hack will require a lot of manual typing, unless you have a device that can simulate a keyboard, according to the preparation instructions. Reportedly, the latest firmware update for the Xbox One has already patched the exploit out, with the last exploitable firmware being 10.0.25398.4478.

:arrow: Source
:arrow: Video guide on how to prepare your system
:arrow: Proof of concept code
 
Fair, but also just a minor inconvenience. There's tons of YouTube videos with teardown instructions.
Not everyone wants to go out and spend extra money on older consoles or comfortable enough tearing them down. Running a software base script that allows open access to og and 360 would be huge. Look at the amount of hacked PS3s and what we got out of that over software. It feels like as soon as we get stable cfw way better options for apps like hshop comes out. You wouldn't recommend someone goes out and buys a modchips for 3ds.
 
You know, this hacking method will stop working in a short while (next update), and it requires that you be on the latest firmware to do it. That means unlike PS4 people who haven’t updated their systems but didn’t know about this hack in time can’t do it, nor can anyone buy an Xbox One on an old firmware that is unhacked and hack it. That means the total number of the users of the hack will be really really really small, so I doubt there would be enough people to create an active scene to begin with. Also, unlike PS4 you don’t even get achievements without online on Xbox One. And unlike PS4 you get free save backup without paying anything on Xbox. Both important things that you lose.

So yeah, I don’t see this one creating a scene. And that is without taking into consideration this quote:



"this is NOT a “jailbreak”. systemos is the virtual machine where apps run, its the environment you get control over when you enable dev mode on your console. this exploit will allow full control over this vm homebrew on retail consoles without dev mode. it will NOT allow piracy."

If it just unlocks devmode and doesn't do much else, in addition to all the aforementioned limitations, then it is worthless pretty much.

There is a hardware hack that has been hinted at though:

That is the one that sounds promising. a JTAG/RGH for the Xbox One would be fantastic.
Post automatically merged:

Fair, but also just a minor inconvenience. There's tons of YouTube videos with teardown instructions.
It is more than just opening it up. All of the current methods AFAIK require both tools and soldering, and lots of people can't solder well and don't have the tools. So having an option would be nice. Mine is already RGHed though.
 
Last edited by FFTW,
Already been patched, and if you didn't update to that FW few days ago, and install the Game Script app, then take it offline, then you're out of luck now.
-edit- Atleast here in the USA it seems.
 
Last edited by BigOnYa,
Wololo.net said:
There are specific steps you need to follow in order to run the upcoming hack: in particular, you need to download and install the Game Script App, but then need to make sure you don’t update your console beyond the vulnerable firmware (which is apparently 10.0.25398.4478). It appears anyone who updated in the past 24h is already out of luck, but don’t quote me on this.
Source

Already been patched, and if you didn't update to that FW few days ago, and install the Game Script app then you're out of luck now.
Funny thing, I just updated my 2nd XB1-S seconds ago to 10.0.25398.4478 (Europe)
Maybe you are talking about X-Series?

Wololo.net Comments said:
If you are on a 4908 firmware, you may want to enroll into the Xbox Insider Program using the Xbox Insider Hub, then leave the program and close the account using the settings of the Hub app. Now you should be able to update the console, which results in a 5gig download. It also factory resets the console, so you’ll have to sign back into your account afterwards.

Then you should be on the correct firmware and able to follow the rest of the tutorial. However, I obviously cannot say for how long this will work.
Source
 
  • Like
Reactions: BigOnYa
Funny thing, I just updated my 2nd XB1-S seconds ago to 10.0.25398.4478 (Europe)
Maybe you are talking about X-Series?
Maybe they have not pushed the new FW update to Europe yet, but they have here on my xbone USA. Luckily I updated one of my xbone couple days ago, tried to update my other xbone this morning and its a different/newer FW now. (Btw I'm not in the insider program so that's not the issue, its a new FW)
 
  • Like
Reactions: Marvin_the_Martian
Sadly I can't buy a used xbone an factory reset it so its clean because it requires internet to install the script. At that point it will auto update :(

Hopefully leads to complete offline hack.
 
Well, if Microsoft flags accounts tied to this exploit, I'm going to have to make sure to disconnect it from the MS accounts I don't want banned.

I want to see if people get banned for using their MS accounts first.
 
  • Like
Reactions: BigOnYa
Well, if Microsoft flags accounts tied to this exploit, I'm going to have to make sure to disconnect it from the MS accounts I don't want banned.

I want to see if people get banned for using their MS accounts first.
I unlinked my MS account and created a new one, before I installed the Game Script app, cause I was thinking the same thing.
 
If the states have rolled out a newer patch, I suggest using a VPN and GPS spoofer for good measure. Connect your console to VPN network, and restart console. You can cancel download of update to get update error to check target OS : 25398.4478 and restart download.

EDIT : Use a geolocation that hasn't rolled out new OS patch. In the states, and I just did my XB1X, Series S & X. Pull the plug on the wifi router to stop update download process and wait for process error. Goodluck 🤙🏽
 
Last edited by Deleted member 681324,
Fair, but also just a minor inconvenience. There's tons of YouTube videos with teardown instructions.
Not going to risk it. I am not into hardware modding, Plus, I also heard that RGH chips can sometimes kill the system.
 

Site & Scene News

Popular threads in this forum