Archive for February, 2007

Feb 28

Alternative OS on Xbox 360 is now possible

According to a SecurityFocus advisory Xbox 360 using kernel version 4532 an 4548 are vulnerable to a privilege escalation. This vulnerabilty allows to run abitrary code on the Xbox 360. In other word it means that it is technically possible to install an alternative OS on the Xbox 360 that can access 360 hardware.
From the user perspectivre this mean that there might be possible to have a XMBC (Xbox Media Center) installed on vulnerable version.
It is probable that in few weeks (Days ?) an POC will be release. However we can’t say that Xbox360 is breaked t as only kernel 4532 and 4548 are vulnerable. Moreover people using live have already patch their Xbox.

Here is a partial copy of the advisory
We have discovered a vulnerability in the Xbox 360 hypervisor that allows
privilege escalation into hypervisor mode. Together with a method to
inject data into non-privileged memory areas, this vulnerability allows
an attacker with physical access to an Xbox 360 to run arbitrary code
such as alternative operating systems with full privileges and full
hardware access.

Feb 27

Microsoft MBSA presentation

MBSA stand for Microsoft Baseline Security Analyzer. This is a free tool by microsoft that check for common vulnerabilities such as weak password and provide a list of missing patch. I made a flash presentation to allow you to see it in action. I do not include the command line tool only the GUI one. I found this tool very simple to use. On the other hand a missing feature is the ability to download every update in one time.

See the interactive presentation
Note that this is my first flash presentation.