All the latest UK technology news, reviews and analysis

Hackers crack Xbox 360 security

by Tom Sanders in California

02 Mar 2007

Be the first to comment

  • Tweet this
Microsoft Xbox 360
A flaw could allow an attacker to take control of the system

An anonymous hacker claims to have uncovered a critical security flaw in the software that runs Microsoft's Xbox 360 that could allow an attacker to take control of the system. 

Microsoft has acknowledged the vulnerability and issued a patch on 9 January. The hacker demonstrated the vulnerability in December, but has only now provided details on how to exploit the flaw on the Full Disclosure security email list.

"Microsoft has completed the investigation into the public claims of a vulnerability in Xbox 360. The issue in question can only allow a user with physical access to the console to modify the Xbox configuration," a Microsoft spokesperson told vnunet.com.

The vulnerability affected the hypervisor component that effectively acts as a gatekeeper to the system by encrypting all code and making it read-only.

This approach limits access to system resources for games and any code that users or attackers could inject.

Because the flaw lets users override the Xbox security system, it could allow them to install a custom operating system.

This includes systems that are stripped from copyright protection technologies that prevent users from running illegally copied games.

Microsoft introduced the flaw through the 4532 kernel update on 31 October that was automatically distributed to all Xbox 360 systems with an internet connection through the Xbox Live service.

It took six days for the company to develop a patch after it was contacted.

Microsoft's previous generation gaming console was an easy target for so-called modders. The practice has been a constant irritation to Microsoft and the hypervisor technology was designed to block the practice.

Users can manually download the patch by connecting to Xbox Live. Users of systems without an internet connection can obtain the update by manually downloading a patch to a PC, burning it to a CD and inserting it into the console.

Do you agree?

 

Add your comment

We won't publish your address
By submitting a comment you agree to abide by our Terms & Conditions. Your comment will be moderated before publication.

Poll

IT priorities for 2012

What is the most important IT priority for your company this year?

99%

0%

1%

0%

0%

Connect with V3.co.uk

Sign up to our daily or weekly newsletters

Accurev

Top 5 software development challenges

This paper focuses on a series of best practices and techniques for development teams looking to improve their software development processes

Talend

Rubbish in, rubbish enterprise

Why good data management at all levels is essential in the modern business (video, 6mins)

Data Delivery Support Analyst

We have been given the privilege of recruiting for a...

Quant Trader - Equities - Leading Prop shop

My client is a proprietary, electronic trading firm and...

Senior Project Manager (Telecoms - 9 month FTC)

Our client is looking for a Senior Project Manager (Telecoms...

Business Analyst - Surrey

Business Analysts are being sought by my leading financial...

To send to more than one email address, simply separate each address with a comma.