What's new

Edge Browser Code Exec

  • Thread starter unknown v2
  • Start date
  • Views 2,801
U

unknown v2

VIP
VIP
Messages
3,217
Reaction score
1,294
Points
450
Sin$
0
If anyone wants to play around with it, it will be patched in the latest update (Creators update)

 
S

Sketch

Enthusiast
Messages
531
Reaction score
278
Points
170
Sin$
7
I am surprised you would publicise this. Few of us was picking at this. Although, we found other ways. Thanks for sharing, I guess.
 
U

unknown v2

VIP
VIP
Messages
3,217
Reaction score
1,294
Points
450
Sin$
0
I am surprised you would publicise this. Few of us was picking at this. Although, we found other ways. Thanks for sharing, I guess.

Wanted to give people a chance to mess around with it since it's being patched anyways.
 
S

Sketch

Enthusiast
Messages
531
Reaction score
278
Points
170
Sin$
7
Wanted to give people a chance to mess around with it since it's being patched anyways.
I guess. Did you manage to achieve anything at all with this? SRA access would be nice, although it is limited.
 
GraFfiX

GraFfiX

Enthusiast
Messages
30
Reaction score
5
Points
65
Sin$
0
unknown V2, thanks for releasing this exploit. I'm trying to test the exploit on my Xbox One, but I have a problem. I have confirmed that I have the proper version, however, since the xb1 is now insisting that I update, I cannot even take the xb1 online on my local network. Is there any way anyone knows of to get the xb1 at least online far enough to access my local network?
 
HexDecimal

HexDecimal

Getting There
Messages
438
Reaction score
112
Points
200
Sin$
0
unknown V2, thanks for releasing this exploit. I'm trying to test the exploit on my Xbox One, but I have a problem. I have confirmed that I have the proper version, however, since the xb1 is now insisting that I update, I cannot even take the xb1 online on my local network. Is there any way anyone knows of to get the xb1 at least online far enough to access my local network?

No, you can not connect to the internet at all with updating your console.
 
GraFfiX

GraFfiX

Enthusiast
Messages
30
Reaction score
5
Points
65
Sin$
0
No, you can not connect to the internet at all with updating your console.

I don't need to connect to the internet, I'm hosting the exploit on my local network. I assume that there's no way whatsoever to get it to connect to the network in any way without updating? If so, that sucks, makes it kind of useless to not update the console(as I have), as it seems there will be no way to exploit it in the future using this userland exploit, unless someone comes up with to get the xb1 to at least have access to the local network through the edge browser.

There is an a small amount of time after you choose to enable the network from the settings menu, where the network is in fact enabled. I verified that after you press connect from the settings menu, even if you are not updated, for a very brief period of time the xb1 grabs an IP from DHCP. This small amount of time allows for the press of one button before showing you the update/exit/turn off console menu, when you see this menu, the network is turned off. I tried pressing the big X button on the controller then selecting edge etc.., but, as I stated, it only allows for the press of a single button, so when I pressed the big X button I only got the home menu then the update/exit/turn off screen.

I'm not sure if anyone could get creative and find a way to get edge to launch on a single key press? Something like that may work.
 
HexDecimal

HexDecimal

Getting There
Messages
438
Reaction score
112
Points
200
Sin$
0
I don't need to connect to the internet, I'm hosting the exploit on my local network. I assume that there's no way whatsoever to get it to connect to the network in any way without updating? If so, that sucks, makes it kind of useless to not update the console(as I have), as it seems there will be no way to exploit it in the future using this userland exploit, unless someone comes up with to get the xb1 to at least have access to the local network through the edge browser.

There is an a small amount of time after you choose to enable the network from the settings menu, where the network is in fact enabled. I verified that after you press connect from the settings menu, even if you are not updated, for a very brief period of time the xb1 grabs an IP from DHCP. This small amount of time allows for the press of one button before showing you the update/exit/turn off console menu, when you see this menu, the network is turned off. I tried pressing the big X button on the controller then selecting edge etc.., but, as I stated, it only allows for the press of a single button, so when I pressed the big X button I only got the home menu then the update/exit/turn off screen.

I'm not sure if anyone could get creative and find a way to get edge to launch on a single key press? Something like that may work.

Removed.
 
Last edited:
GraFfiX

GraFfiX

Enthusiast
Messages
30
Reaction score
5
Points
65
Sin$
0
As soon as you connect to your network, the console tests the connection to Live, then immediately checks for updates. If the update is marked as mandatory, the console will not allow you to remain online without updating. You are not going to have time to launch edge between the time it connects and the time it finds an update.

So basically this exploit is useless in it's current state even though I haven't updated? I'm wondering if I should just go ahead and update...
 
GraFfiX

GraFfiX

Enthusiast
Messages
30
Reaction score
5
Points
65
Sin$
0
Yes it is useless. That is why it was released publicly now, I, and few others have been aware of it for a while.

Wow, that sucks. This is my luck though, I will update my Xbox One and next week there will be a full hack for people on the dash version I just updated from, stuff like that always happens to me. I think I'm going to go ahead and update though. Do you think there's any chance of this exploit ever being used as a portion of a full hack? Like do you ever see this userland exploit being combined with a kernel exploit to produce a full hack?
 
S

Sketch

Enthusiast
Messages
531
Reaction score
278
Points
170
Sin$
7
Wow, that sucks. This is my luck though, I will update my Xbox One and next week there will be a full hack for people on the dash version I just updated from, stuff like that always happens to me. I think I'm going to go ahead and update though. Do you think there's any chance of this exploit ever being used as a portion of a full hack? Like do you ever see this userland exploit being combined with a kernel exploit to produce a full hack?
No, it's unlikely from Edge.
 
M

Melviin

Newbie
Messages
3
Reaction score
2
Points
30
Sin$
0
Wow, that sucks. This is my luck though, I will update my Xbox One and next week there will be a full hack for people on the dash version I just updated from, stuff like that always happens to me. I think I'm going to go ahead and update though. Do you think there's any chance of this exploit ever being used as a portion of a full hack? Like do you ever see this userland exploit being combined with a kernel exploit to produce a full hack?
Kind of like the Jtag exploit on the 360 is what you're referring to. It seems there's more security "stuff" in the Xbox One than the 360 so maybe not. I have a feeling though there's going to be one giant hole someone's going to find and then Jtag here we come!
 
S

Sketch

Enthusiast
Messages
531
Reaction score
278
Points
170
Sin$
7
Kind of like the Jtag exploit on the 360 is what you're referring to. It seems there's more security "stuff" in the Xbox One than the 360 so maybe not. I have a feeling though there's going to be one giant hole someone's going to find and then Jtag here we come!
There is no "giant hole". It's not going to be easy. Nothing has actually been found in terms of hardware.
 
Top Bottom
Login
Register