Xecuter Defeats Corona !

Status
Not open for further replies.

BL4K3Y

VIP Member
Top Poster Of Month
Jul 7, 2010
13,686
118
Colne, Lancashire (UK)
There are still some people who believe in Xenons, lol. I just cant throw mine away tbh. I wanna glitch it so bad. I may be getting something to watercool it personally.
You should know that Xenon RGH is ONLY for drive key recovery - nothing else, because it isn't stable enough to run a glitch dashboard.
 

siren215

VIP Member
Feb 22, 2012
268
33
XBOX :P
New version CoolRunner dev hardware is in production for testers. It really is going to rock your box.

Trinity & Corona has been completely re-done. Lot's of changes and new additions. No backwards compatibility RGH1 has been ditched completely.

CoolRunner V2 Example - glitch times on a test Trinity and Corona were 1 1 1 1 2 1 1 1 2 1

Coming soon ;)
Thats a great news...i was about to sell my corona..i think its worth a wait...great going guys..thx a lot!!
 

aarongdl

Senior Member
Nov 30, 2011
142
0
nitram released a rebooter for Xenons. I'm aware it takes awhile it glitch, but if boot times were adjusted how would it still be unstable?

i'm fairly interested in it lol.
 

CALZALOL

Full Member
Apr 14, 2012
48
8
new york
I've posted this here because I think it may be the new corona hack
and this guy has stole and claimed it as his own.

I'm not trying to promote this person or this mod just unsure of if this is leaked!

Okay guys two questions;
1. Is this a leak?
2. Would this actually work?

http://www.se7ensins.com/forums/threads/new-xbox-360-homebrew-method-founded-by-me.727980/

So basically, this is another way to run homebrew. Or in other words "RGH", or "Jtag" ANY console. Corona included. If you have any questions regarding this, or any other material. Shoot me a PM, .

First, you're going to have to adjust the optimal configulation of distributed database system inside of Q41 sector of the south bridge chip. The actual exploit we are looking at is on the Output controller hub (ICH).

As you can see below in the diagram, the north and south bridge chips. (Note, the picture is not a diagram of an xbox 360's motherboard. It is just a visual to make it easier to understand.)


After we run the reverse pulse out of the output controller hub, it will bypass the Out-Of-Band management controller, which is segment one of Syscall. Syscall is the how a program requests a service from an operating system's kernel. This is a vital process in the Xbox 360's security which is what we are bypassing now.

This is the point where all of this becomes important.
Code:
00000000..00100000: SMC, KV, CB, CD, CE, CF, CG, backup bootloader
00100000..00140000: main bootloader
00140000..00f7c000: empty space
00f7c000 : smc config block
00ffc000 : exploit buffer
After bypassing the OOB management controller, it will cause a buffer overflow in the smc config block which calls for payload ea00c020. You see what I did there? It bypasses the main bootloader cycle and starts it in hypervisor, which will still start most of the same functions as the main bootloader cycles, except in an escalated state. Boot times will be a tad slower, but not as slow as the RGH. Maybe a second or two slower.

Unprivileged code interacts with the hypervisor via the syscall instruction. This causes the machine to enter escalated hypervisor mode.

Preconditions (Registers set by unprivileged code)
Code:
%r0 syscall no.
%r3-%r12 syscall arguments
Priviledged code
Code:
13D8: cmplwi %r0, 0x61
13DC: bge illegal_syscall
...
13F0: rldicr %r1, %r0, 2, 61
13F4: lwz %r4, syscall_table(%r1)
13F8: mtlr %r4
...
1414: blrl
When processing the syscall, the processor is running in "hypervisor real mode", with the MMU switched off. However, when accessing memory locations with the MSB cleared, an additional offset, the Hypervisor Real Mode Offset (HRMO), will be applied to all memory addresses.

This does not take multiple attempts like the RGH does to boot. It boots like a normal xbox. It may seem a bit confusing, but I plan on making this more user-friendly looking in the near future. Until then, I will continue developing this. Stay tuned for updates every couple days.

If you repost this, please give me credit. I put a lot of time into studying this. And also some money, due to multiple xbox purchases.
Credit goes to me, *******.
 
Last edited:
  • Like
Reactions: blazek566

biggg

Full Member
Jun 2, 2012
37
0
Bucharest, RO
New version CoolRunner dev hardware is in production for testers. It really is going to rock your box.

Trinity & Corona has been completely re-done. Lot's of changes and new additions. No backwards compatibility RGH1 has been ditched completely.

CoolRunner V2 Example - glitch times on a test Trinity and Corona were 1 1 1 1 2 1 1 1 2 1

Coming soon ;)
This phrase "coming soon" it's killing me. I pray to GOD to give me days to see this in my hand, because i'm waiting for 6 months and counting. I will took a picture of this and put it on my wall. :frown:
 

playonlcd

Full Member
Nov 1, 2009
70
0
I've posted this here because I think it may be the new corona hack
and this guy has stole and claimed it as his own.

I'm not trying to promote this person or this mod just unsure of if this is leaked!
http://www.se7ensins.com/forums/threads/new-xbox-360-homebrew-method-founded-by-me.727980/
Very interesting approach.
We don't know yet how RGH is working for Corona but time will tell if this is working and who is gonna implementing it first; then we will know if it was a leak or just a fake. :)


This phrase "coming soon" it's killing me. :frown:
Hope that is not taking 6 months like on Demon, when testing was announced till production.
 
Last edited:

boby2pc

Junior Member
Feb 8, 2011
10
0
Good news.
What about phison chip support. It will be possible to read nand with NAND-x ?
 

biggg

Full Member
Jun 2, 2012
37
0
Bucharest, RO
Very interesting approach.
We don't know yet how RGH is working for Corona but time will tell if this is working and who is gonna implementing it first; then we will know if it was a leak or just a fake. :)



Hope that is not taking 6 months like on Demon, when testing was announced till production.
I hope that too, but i see that Team Xecuter and C4eva are very greedy when we are talking about details. We haven't seen something eloquent lately. they like to boil us on low heat
 

Ubergeek

Xecuter Groupie
Feb 24, 2003
6,259
0
California, USA

playonlcd

Full Member
Nov 1, 2009
70
0
Ubergeek
I agree.
But when testing begins, most of us thinks on 1 month or two...
Mostly, corona from my point of view were more urgent as there is no method for modding this version and you can easily have 2 console given the low price lately.

I hope that too, but i see that Team Xecuter and C4eva are very greedy when we are talking about details. We haven't seen something eloquent lately. they like to boil us on low heat
Given the fact that they are more private researcher....i understand their position. I think major of us were expecting how evolution is going, like were on modding 16D4S drive...but is not the case around here for technical discussions.
 

WNYConsoles

Troll Eating Dogs
I would also like to know why that isn't possible? The OP over there seems to know what he is talking about and I can't imagine someone posting all that information if it was just BS. That information is beyond my knowledgebase but I assume it would require a device to do what he said?
 

TilVl

VIP Member
May 11, 2011
1,383
0
Just got someone used tech terms doesn't mean it work. You can talk software all day long and speak about how to obtain results by software. Obviously if it was correct why isn't it released yet?

The hack is going to be roughly the same but adaption need to be made. It to me this guy simply to the current hack and explained how it might keyword, might work on cornoa. I highly doubt it would be that simple or a working hack would have been public by now.

Even if it do work that the glitch portion. The chain of trust and everything else would need to be reversed. Doubt its the same cb and what not as trinity.

Sent from my SGH-T839 using Tapatalk
 
Last edited:
Status
Not open for further replies.