lists.openwall.net   lists  /  announce  owl-users  owl-dev  john-users  john-dev  passwdqc-users  yescrypt  popa3d-users  /  oss-security  kernel-hardening  musl  sabotage  tlsify  passwords  /  crypt-dev  xvendor  /  Bugtraq  Full-Disclosure  linux-kernel  linux-netdev  linux-ext4  linux-hardening  linux-cve-announce  PHC 
Open Source and information security mailing list archives
 
Hash Suite: Windows password security audit tool. GUI, reports in PDF.
[<prev] [next>] [<thread-prev] [thread-next>] [day] [month] [year] [list]
Message-ID: <20030723202151.GA15788@php.net>
From: s.esser at e-matters.de (Stefan Esser)
Subject: Re: Full-Disclosure digest, Vol 1 #970 - 38 msgs

Hello,

> Anyone Heard Any more on The XBOX Hack

currently there are 4 known exploits against XBOX software.
(order of releasedate)

1) 007: Agent under Fire - Savegame Stackoverflow Exploit
2) Mechassault           - Savegame Stackoverflow Exploit
3) Dashboard Font Loader Integer/Heap Overflow
4) Dashboard Audio CD Ripper Integer/Stack Overflow

The first 2 are overflows in games and therefore it is not
possible to use the DVDROM (box will reset when you press
eject). The Dashboard overflows on the other side give full
control over the box.

You can find actual information about all this on sites like

   http://www.xbox-scene.com


Stefan


-- 

--------------------------------------------------------------------------
 Stefan Esser                                        s.esser@...atters.de
 e-matters Security                         http://security.e-matters.de/

 GPG-Key                gpg --keyserver pgp.mit.edu --recv-key 0xCF6CAE69 
 Key fingerprint       B418 B290 ACC0 C8E5 8292  8B72 D6B0 7704 CF6C AE69
--------------------------------------------------------------------------
 Did I help you? Consider a gift:            http://wishlist.suspekt.org/
--------------------------------------------------------------------------


Powered by blists - more mailing lists

Powered by Openwall GNU/*/Linux Powered by OpenVZ