Archive for the 'In the news' Category Page 2 of 2



Nov 09

Firmware 1.1.2 for Iphone and Itouch released and already jailbroken

With the upcoming release of the iphone in England and Germany, Apple have issue a new firmware (1.1.2) that patch the current jailbreak method based on the tiff exploit. A twin firmware for ipod touch was release also. It does not seems to appear that the new apple firmware introduce new features to the iphone. It however according to mac rumor the long time waited functionnaly to add an event in the calendar was added to the touch.

It seem’s that the 1.1.2 firmwae is already broken and the ipod touch is jaibreaked (see the screenshot ) and read this post to know more. Since the new firmware patch the tiff exploit (see endgadget screenshot below) I wonder want exploit is used. Since the jailbreak was so fast it is likely that the team had the exploit ready for many weeks and keep it secret. Thus my bet is it work even on old firemware.

Feb 28

Alternative OS on Xbox 360 is now possible

According to a SecurityFocus advisory Xbox 360 using kernel version 4532 an 4548 are vulnerable to a privilege escalation. This vulnerabilty allows to run abitrary code on the Xbox 360. In other word it means that it is technically possible to install an alternative OS on the Xbox 360 that can access 360 hardware.
From the user perspectivre this mean that there might be possible to have a XMBC (Xbox Media Center) installed on vulnerable version.
It is probable that in few weeks (Days ?) an POC will be release. However we can’t say that Xbox360 is breaked t as only kernel 4532 and 4548 are vulnerable. Moreover people using live have already patch their Xbox.

Here is a partial copy of the advisory
We have discovered a vulnerability in the Xbox 360 hypervisor that allows
privilege escalation into hypervisor mode. Together with a method to
inject data into non-privileged memory areas, this vulnerability allows
an attacker with physical access to an Xbox 360 to run arbitrary code
such as alternative operating systems with full privileges and full
hardware access.