Board logo

标题: [主要是蛋疼翻译帖]XO续破解液内强技术分析贴和新闻贴以及厚道建议贴 [打印本页]

作者: akirasai    时间: 2007-5-22 16:13     标题: [主要是蛋疼翻译帖]XO续破解液内强技术分析贴和新闻贴以及厚道建议贴

引用:
Xbox360 LIVE Bans Info and iXtreme Online FW WIP
Posted by XanTium | May 21 23:43 EST | News Category: Xbox360

  
Here are some details about the Xbox360 LIVE bans I got directly and indirectly from GaryOPA, Commodore4eva (C4E), Iriez and others. Of course don't take any of this info as 100% confirmed, noone knows exactly based on what data MS is banning ... it's just an analysis of what they think is happening and what MS might/can be checking.

C4E thinks MS is probably detecting and banning consoles from LIVE by tracking usage of backups via timing of the challenge response (c/r) on the drive over the last few weeks or months. A modified FW will reply much faster to the the Challenges requests (stored in a table) than an original firmware (seek on drive). They probably do this test more than once and can ban you if you're above a certain average.
FuzzyLogic also found that microsoft is sometimes doing additional checks on discs: PFI/DMI (so images without these sectors (or if using an old FWs without support for PFI/DMI) can probably be detected easily), drive inquiry (reads ascii string from drive), and capacity (reports capacity of disc) are requested. Strange thing here is MS requests 0x8000 bytes for PFI and DMI, while it should normally be 0x0800 bytes. TheSpecialist pointed out that the remaining 0x7800 bytes contains the relocated SS and PFI on burned discs ... which would make it very easy to detect backups for MS. C4E however told us this would not work on TS drives as its cut off to 0800 even if more data is asked, it's unconfirmed how modified HLG FWs drives respond to this atm.
The "read capacity check" will also work as detection on HLG because, unlike the newest TS FWs, it doesn't have true 'stealth media' yet, these drives are reporting back the burned disc based size of PFI instead of the correct PFI.
Apparently there's also an issue with SS (Security Sector) extracted from Hitachi-LG, some necessary data is screwed ... which means that probably only the Toshiba-Samsung / kreon setup has been extracting correct SS.

Another thing they are probably detecting (but probably not using yet to decide to ban or not) and log/flag is if you ever booted your Xbox360 with DVD SATA cable not connected to your Xbox360 (E64). Many people did this to power their drive when they wanted to flash it (power connected to 360, SATA to PC). So it's highly suggested to use an external power to flash next time.
It's also possible MS also bans based on stuff like bad credit card info for your country, running a NTSC machine with euro-address/credit card (or inverse), having out-of-region (arcade) games and demos on your HDD, unofficial 360 HDD, internet downloaded gamesaves etc. There's no clear view on all this yet.
For now, C4E believes Microsoft is not detecting modified FWs or detecting FW changes/updates. Using a special FW they did not detect any debug commands sent to the drive by MS (they went through the dash/kernel updates with the special FW as well and did not detect any debug commands there either). So they think either:
A/ MS is not doing any FW detection right now, and only previously (maybe on request of MS servers while playing on LIVE?), or
B/ MS is banning based only on the timings of the drive, ss/pfi/dmi checks, capacity, drive inquiry and c/r verification.

We also got information C4E is working on an "iXtreme Online" FW for Toshiba-Samsung drives, a Hitachi-LG version and maybe even BenQ version might follow later.
The new FW will have less features than the current Xtreme FWs: no single-layer (DVD5) support, no ripping of games (0800 mode), but more features to safely play from burned discs (emulate the exact speed and timings of the original games) and prevent booting from un-safe discs (without PFI and DMI or bad SS - so discs not passing the 'Stealth Check' (using Xbox Backup Creator(info)(info) for example) are not going to boot on the new firmware), or images that aren't exact dumps of the original.
There's no official ETA (maybe this weekend though for TS drives), and of course no guarantee MS will never ban you based on new checks (that's the risk it takes if you want to be part of the modding community ) The HLG FW will take a bit longer as it'll require true 'Stealth media' etc added.

This new FW will of course be made mostly for new consoles being modded, because even if you're not banned from LIVE yet there's no way to know if MS already has info/logs on your console ID regarding timings or other stuff so even changing to this new firmware in the near future may not stop that console ID from being banned in the next wave of MS bans.
If your console is not banned yet, it's highly suggested you don't boot any burned discs, originals should be ok, even when offline (MS might be storing results of some checks in flash), until the release of the new FW.
If your console is already banned this will of course not help you ... just enjoy the offline playing on that console for now (with some games you could try using 3rd party networks like XLink Kai(info)) and maybe some day a new exploit will allow you to do more with that console.

To end with ... X-Scene's obvious tip of the month: don't buy 2nd hand Xbox360 consoles
本文是从GaryOPA, Commodore4eva (C4E), Iriez那里了解到的有关ban机时间的一些细节,当然不保证这些细节信息百分之百准确,目前没有人能肯定MS究竟是根据什么来ban主机的,只是他们认为MS目前可能采用的手段而已。
C4E认为MS可能是通过驱动器里的“查询/应答计时器”来检测备份光盘的使用情况,而且可能已经持续检验数周到数月了。修改过的固件在响应查询请求的速度比原始固件要快很多,MS可能多次进行这种测试,如果你的平均响应值超过标准,你就死了。
FuzzyLogic也发现有时MS会对光盘进行额外的PFI(物理格式信息)和DMI(光碟制造信息)检测,驱动器查询(从光驱查询ascii字符串),以及光盘容量查询。奇怪的是MS会针对PFI、DMI请求0x8000字节的数据,而正常应该是请求0x0800字节的数据,有砖家指出,多请求的0x7800字节数据内包括备份光盘中位置已经变动的SS和PFI信息,这样来辨别备份光盘会更加容易。
但是C4E指出,这样的做法在三星光驱上是行不通的,因为三星光驱只响应0x0800字节的数据,超过部分就抛弃掉。目前还不清楚修改后HL光驱固件如何响应这个请求。
“读取容量检测”也可以被MS用来检测HL光驱,因为目前HL光驱和三星光驱相比,还没有做到真正的保密功能。HL光驱在响应请求的时候会返回备份光盘的PFI而不是原始的PFI。
而且,从HL光驱的导出的SS也有问题,有一些必要的信息丢失了,所以目前也许从三星光驱才能导出的正确SS信息。
MS也可能还在检测别的一些信息(未必会用来作为ban机的决定性信息)并且记录你是否曾经在未将光驱的SATA线连接至主机的情况下启动主机(这是刷机的必经步骤,除非你买了额外的电源模块),所以建议你下次刷机的时候使用电源模块给光驱供电,不要启动主机来供电。
另外MS可能的ban机根据还有:信用卡的信用等级、运行MTSC主机但是用的是其他国家的信用卡、下载了跨区的arcade游戏或者demo,自己改装的硬盘、下载的游戏存档等等,目前这些没有确实的根据。
目前C4E认为MS并没有检测光驱固件的修改和变动,通过使用特殊的固件进行测试,他们发现MS并没有发送任何debug命令给光驱(使用该固件的情况下进行了春季更新,依然没有发现任何异常)。所以他们认为或者
A:MS目前没有检测固件版本,或者在玩live游戏的时候游戏服务器会检测也未可知。
B:MS根据光驱内的计时器,ss/pfi/dmi的检测,容量检测,驱动器查询等上述的方式来决定是否ban你的主机
我们还得知目前C4E正在为三星光驱制作iXtreme Online固件,HL光驱的固件甚至BENQ的固件会在之后稍晚放出。
新的固件比之前的固件会少一些特性:
不能玩D5的游戏了
不能对游戏进行rip操作
但是会有更多的安全特性,如模拟Z版游戏的导出速度和计时,阻止运行不安全的光盘(没有PFI、DMI、SS信息等或者和原始镜像相比数据有缺失)。
目前还没有官方的发布时间(三星光驱的固件可能在这个周末发布),而且不会保证刷了以后MS就永远不会ban掉你的主机,HL的固件因为需要添加数据保密功能,所以需时较长。
新的固件主要是为新的主机准备的,因为即使你现在还没有被ban,你没有办法确认MS是不是之前已经记录了你的主机信息,如果是,那么即使你刷了新的固件,那么MS下一波就可能要了你的命。
如果你还没被ban,那么强烈建议你目前不要玩任何备份光盘,即便是离线状态也尽量不要,因为主机可能会记录你的游戏信息,然后耐心等待新固件的到来
当然玩正版应该没事。
如果你已经被ban,那么你死翘了,好好享受你美妙的单机人生吧,或者部分游戏试试KAI也不错,也可能在将来会发现新的漏洞....总之一切都还有希望

最后,强烈建议你:以后就不要买二手的XO了!

[ 本帖最后由 akirasai 于 2007-5-22 17:18 编辑 ]
作者: akirasai    时间: 2007-5-22 16:28

麻痹,没看到,居然有人先发了,真是白蛋疼了
作者: 比卡丘    时间: 2007-5-22 16:36

辛苦了~偶继续单机。。要不咋整啊
作者: west2046    时间: 2007-5-22 16:38

大深奥!!!
作者: zafm0861    时间: 2007-5-22 16:42

……支持下楼主……

我的机器从买来就没连过1次live,也没更新过……买了有4个月了,应该不会被记录游戏信息什么的吧...

本来想等放假回去爽live...看来没戏了...希望新固件快出来吧~~~
作者: 狂涂    时间: 2007-5-22 17:00

建议把另一段也翻译了...
作者: 比卡丘    时间: 2007-5-22 17:10

引用:
原帖由 zafm0861 于 2007-5-22 16:42 发表
……支持下楼主……

我的机器从买来就没连过1次live,也没更新过……买了有4个月了,应该不会被记录游戏信息什么的吧...

本来想等放假回去爽live...看来没戏了...希望新固件快出来吧~~~
即使你现在还没有被ban,你没有办法确认MS是不是之前已经记录了你的主机信息,如果是,那么即使你刷了新的固件,那么MS下一波就可能要了你的命。
作者: akirasai    时间: 2007-5-22 17:15

引用:
原帖由 狂涂 于 2007-5-22 17:00 发表
建议把另一段也翻译了...
哪一段?
作者: singlung    时间: 2007-5-22 17:18

嚴重期待新光驅固件
作者: 美版游戏饭丝    时间: 2007-5-22 17:51

俺是HL光驱……继续ES4吧!
作者: moonworm    时间: 2007-5-22 18:02

牛叉翻译家把这段也译了吧。
引用:
Do you already know which is the real reason of the bans?
The bans is a manual process, logs and logs are watched. It takes time.

Manual? What is what they verify exactly?
Many things. Timming and startings without reader, like when you flasheas the reader with the power supply of the console, and some more.

So when we flash the XBOX360 with Xtreme Online we will not be able to do it with the power source of the console?
Correct. Or to do it with a console already banned.

On the other hand, will Xtreme Online will be completely secure?
YES

Does Xtreme Online will be available for Hitachi readers?
YES

Will also be available for the readers with firmware v79?
All the Hitachi, including the 79, but still would be necessary to flash it via hardware.

What happens with BenQ readers?
The version for BenQ will be available after the others, almost all the work was finished before the bans began.

Will be safe for the users to flash with Xtreme Online if they previously flash with others versions of Xtreme and they have not been banned?
We do not know that, it could happen or it couldnt happen. It could be too late if the user is already in the logs. But when the drive is flashed with Xtreme Online, it would be possible to called Microsoft complaining that the ban was not justified so they dont banned you console and there is no need to buy a new one.

So thanks to Xtreme Online we have a little hope for the ban to be removed?
Aparently yes they reescan the console if you complain to the SAT.

Briefly, how does the Xtreme Online works?
Xtreme Online will emulate the exact speed and timings of the original games, and will protect the users to execute backups stealth not avoiding its execution.

We must have some precaution with Xtreme Online?
The users must have well-taken care of not to flash the drive using the power supply of the unbann console. They should not play games before they leave the region.

Thank you very much by your time.

Something that to add?
YES look for release this weekend.

作者: akirasai    时间: 2007-5-22 18:07

这段?
小学生都看得懂,翻毛啊
作者: silverhoof    时间: 2007-5-22 18:18

那岂不是在新的固件出现之前不能玩游戏了?
新的固件什么时候才能出来啊。
作者: vany    时间: 2007-5-22 18:44

以后买新主机必须增加一个步骤,就是能否登录上LIVE……
否则肯定是翻新机
作者: RestlessDream    时间: 2007-5-22 18:53

http://www.tgfcer.com/club/thread-5869809-1-1.html

新的刷机固件没用

官方的封杀手段说法已经来了
作者: RestlessDream    时间: 2007-5-22 18:54

引用:
  问题一:前些天很多国内改机用户均反应无法登录LIVE,但还有一部份改机用户仍然可以登录,请问这是什么原因?微软是依据主机什么信息来封杀的呢?

  解答:关于防盗板的问题是这样的。不会封掉用户ID,只会封掉主机。改过的机器会产生HASH值,连线的时候会上传给LIVE,那微软就知道了……就把你机器封掉了。然后就是部分改机还可以上LIVE的问题应该是属于漏洞,微软并没有进行分批次或者区域性封杀。这套辨别算法相当严密,很复杂,因为HASH值是属于唯一码,所以不光是刷光驱,所以其它任何对主机所进行的改动都是不允许的

  注: Hash值是与基本文本数值有关的一种密码保护安全方式。一个安全的hash算法可以使得在无意或有意情况下都不能构建同样的hash值。

  问题二:如果那些改机用户将固件重新刷回原始文件(这样做肯定就只能玩正版了),是否还能够重新享受LIVE?

  解答:基本上,重新购买一台未改机的XBOX360是最稳妥的。并不保证非官方手段能实现恢复原厂设置。所以同样不能保证刷回的XBOX 360主机可以重新登陆XBOX LIVE。

作者: sweden    时间: 2007-5-22 20:57


作者: yellowbigbird    时间: 2007-5-22 21:13

我只求xomc
其他就.......

我出来了
作者: akirasai    时间: 2007-5-22 21:14

引用:
原帖由 RestlessDream 于 2007-5-22 18:54 发表


这个问题偶已经在老外的论坛问了
不知道是不是胡说
等待验证ing
作者: westlost    时间: 2007-5-22 22:17

为啥不要买二手的?啥都可以买,xb不能live那么多年不也照样过来了?关键是价格只要合适不就行了
500块的xo我不信就是被ban也会没人要?
作者: 隐的游戏    时间: 2007-5-22 22:32

老子不管了
作者: nimer    时间: 2007-5-22 22:53

引用:
原帖由 RestlessDream 于 2007-5-22 18:54 发表


这套信息收集机制是什么时候开始的呢?

看口吻是说,只要是改机后上live的,通不过这个交验立刻ban,那为什么会分批地ban?
作者: gwdcoo.gold    时间: 2007-5-23 00:00

唉! 很多人原以为买回家的黄金圣衣,用着用着就变成青铜圣衣了!

作者: wpxgod    时间: 2007-5-23 01:01

引用:
原帖由 gwdcoo.gold 于 2007-5-23 00:00 发表
唉! 很多人原以为买回家的黄金圣衣,用着用着就变成青铜圣衣了!
那看看能不能搞点雅典娜的血弄成神圣衣吧
作者: 比卡丘    时间: 2007-5-23 02:02

看来只能做芯片了,在芯片中记录原哈希码,校验时总发送这个就OK了..谁来做啊

加芯片好烦啊
作者: RestlessDream    时间: 2007-5-23 06:01

引用:
原帖由 akirasai 于 2007-5-22 21:14 发表

这个问题偶已经在老外的论坛问了
不知道是不是胡说
等待验证ing
这个不是胡说

360如果大陆推行货,代理商就是中视网元

他们这个消息应该是中国微软来的
作者: 狂涂    时间: 2007-5-23 07:57

偶准备华丽的投PS3了

WE和NBA2K,就用PS3来上...

D版LIVE不报希望了.实例可以参照XBOX.再买一台玩Z是必然


作者: panda21st    时间: 2007-5-23 09:14

其实不上LIVE,对我唯一的影响就是主机的时间不准了。其他都没什么关系的。

微软封LIVE,某种程度上,还是为了进一步提高主机的销量啊。

[ 本帖最后由 panda21st 于 2007-5-23 09:19 编辑 ]
作者: silverhoof    时间: 2007-5-23 10:22

现在有点提心吊胆的,比较不爽。
等新的固件不知道有没有用,如果要等最近就不能开机玩游戏了。
如果不等,那么如果被Ban意味着必须花钱买第二台玩正版。
犹豫啊




欢迎光临 TGFC Lifestyle (http://bbs.tgfcer.com/) Powered by Discuz! 6.0.0