How a Mini drill tool defeated security on the Xbox 360 | MVG

Поделиться
HTML-код
  • Опубликовано: 24 ноя 2024
  • ИгрыИгры

Комментарии • 1,7 тыс.

  • @Sheevlord
    @Sheevlord 3 года назад +3080

    How to make your Xbox 360 read illegitimate discs:
    1. Perform lobotomy on the optical drive controller

    • @bur1t0
      @bur1t0 3 года назад +111

      Lobotomy is a bit of a harsh word here... I'd go with Trepanate.

    • @lis6502
      @lis6502 3 года назад +51

      @@bur1t0 lolbottomy ;d

    • @Nightenstaff
      @Nightenstaff 3 года назад +15

      Superman has entered the modding scene.

    • @perpetualcollapse
      @perpetualcollapse 3 года назад +6

      @@lis6502
      This made me laugh 🏅

    • @samzeyel8220
      @samzeyel8220 3 года назад +27

      @@bur1t0 indeed thats Trepanation, and if it goes wrong, then you have lobotomised your DVD drive....like definitely

  • @dylanrush184
    @dylanrush184 3 года назад +34

    Crazy how chaotic the inside of the chip looks like, and yet the drill spot is always in the same place. The components seem to be thrown in their haphazardly.

  • @ZaPpaul
    @ZaPpaul 3 года назад +2872

    I was living in Thailand back in the late 2000's and there Xbox piracy was all you had, there were no legal supply chains from Microsoft for the consoles and games, so it was pretty big business. so big I was in a console store there and they had a drill press with a jig on it that took seconds to perform this hack. You basically put the board in the jig, pulled down on the press and it dropped to a set height. The guy there was doing these in bulk and charging like $5 a time. They must have made loads of money.

    • @Julio-yy4ll
      @Julio-yy4ll 3 года назад +320

      Same thing here on Brazil, there were actually official supplies but they were so expensive nobody bothered

    • @hanakomisa
      @hanakomisa 3 года назад +68

      I used to live in Thailand as well, and the department store in my city were filled with stores selling pre-modded consoles tailored for piracy stuff, this was back in like 2008-2011, PS3 hadn't catched on at all since there were really no way to pirate games on it back then. PS2s are definitely the most popular by far though seeing how easy it is to do the drive mod for them.

    • @renakunisaki
      @renakunisaki 3 года назад +52

      Always surprised me that professional pirates can spend so much on equipment like that, but can't press "legit" discs to bypass the need for mods.

    • @alerighi
      @alerighi 3 года назад +177

      @@renakunisaki That would be illegal, while modding a console is not (at least in most countries, it maybe illegal in the US but not all countries are governed by lobbies that forbid you to modify hardware you bought and you own).
      Also the point of modding a console is just to play games burned on a DVD, having to buy pirated games defeat the purpose, they will cost some money to make, surely more than a new DVD-R that you can burn with your PC. Back in the days people in my country used to go to electronic fairs just to buy packs of 50 DVD, that where the cheaper option before online shopping, since there you didn't pay VAT.

    • @Matanumi
      @Matanumi 3 года назад +24

      @@Julio-yy4ll Brazils Modding and video game scene in a nutshell

  • @evilmonkeywithissues
    @evilmonkeywithissues 3 года назад +458

    I really think that anti-piracy 'locks' essentially adhere to the turn of phrase applied to physical locks; they only keep out people who don't really want to get in that bad.

    • @kuraiwolf4047
      @kuraiwolf4047 3 года назад +27

      They probably would never have thought to drill a hole in an IC though. It's something that sounds too crazy to work.

    • @HappyBeezerStudios
      @HappyBeezerStudios 3 года назад +23

      It's the same with a bike lock. It's there to keep people away, but is never fully secure. Those who really want to get the bike, will get it, but most people will take a look and back off and a few will try for a few seconds and then leave. If it takes longer than opening with a key or requires obvious tools, nobody would try it in public.

    • @Rafael_Fuchs
      @Rafael_Fuchs 3 года назад +7

      @@HappyBeezerStudios People have done tests in public. The chances of someone stopping you even when using power tools to steal a bike is very low. Only thing that stops people from doing it is the sense they'll get caught. When in reality, the chances of them getting caught is slim. If I'm remembering correctly, the tests were done in the USA/Canada. No idea what the rates would be like in countries that favor their bike transportation like the Netherlands or Finland.

    • @the_hamrat
      @the_hamrat 3 года назад +22

      This is the Console Picking Lawyer

    • @katanah3195
      @katanah3195 2 года назад +4

      @@the_hamrat "Very few locks are actual security devices. Treat your locks as latches, and don't trust a lock alone to protect your valuables or for any high security application."

  • @markusTegelane
    @markusTegelane 3 года назад +1574

    tweezers, paperclips, mini-drills...
    the most mundane common household items that defeated console security
    a.k.a. the kind of stuff you come up with if you're a hacker

    • @Pixdoet
      @Pixdoet 3 года назад +77

      yep, cant wait for someone to hack the xbox series x with a hammer

    • @TheGlitchyMario
      @TheGlitchyMario 3 года назад +50

      @@Pixdoet Someone's gonna do it with a Lego.

    • @chriswright8074
      @chriswright8074 3 года назад +4

      @@Pixdoet what about Xbox one

    • @Pixdoet
      @Pixdoet 3 года назад +7

      @@TheGlitchyMario i thought someone already made an NES with lego

    • @DimIsHigh
      @DimIsHigh 3 года назад +6

      MacGyver was the OG hacker

  • @FR4M3Sharma
    @FR4M3Sharma 3 года назад +507

    This is literally the peak of "Hardware Modder literally too angry to back off" in Console Modding. XD

    • @utewbd
      @utewbd 2 года назад +4

      Literally

  • @knghtbrd
    @knghtbrd 3 года назад +1258

    When people start drilling holes in their PCBs is about the point the hardware security people flip the tables and rage quit. Physical access always means the device belongs to YOU, not to whomever thinks it belongs to THEM. As it should be.

    • @USSMariner
      @USSMariner 3 года назад +181

      This is actually a known law in Tech Security. Everyone knows that no method will hold out if an attacker has physical access to a given system.

    • @lis6502
      @lis6502 3 года назад +152

      tell this to these "you'll own nothing and you'll be happy" jerks ;)

    • @vylbird8014
      @vylbird8014 3 года назад +82

      Drilling holes in PCBs is easy. You can see what you're doing. This is drilling a hole in a chip package - going in blind, no way to see what you're drilling, and trusting in the advice of a dodgy internet site.

    • @TheBackyardChemist
      @TheBackyardChemist 3 года назад +5

      nah, smartcard/cryptowallet/TPM chips are specially hardened against such

    • @Nordic_Mechanic
      @Nordic_Mechanic 3 года назад +7

      @@lis6502 paul swabb ?

  • @pacotesan
    @pacotesan 3 года назад +108

    Here in Brazil at that time I was one of the main modders in Sao Paulo City and I remember when the method was released on the forums and I went in the middle of the night to grab a Dremel bit that was proper for this and doing my own Xbox for testing. Next weekend after that I did at least 40, good times good times. Later a template would be release but at first I would just measure with ruler and mark with a pencil the correct spot. A software was kept running and when a loud beep started you knew the spot was hit correctly :)

    • @NTDARK13
      @NTDARK13 3 года назад +1

      Did you offer compensation if you didn't hit the spot right? Or you explained beforehand it was a do or die move?

    • @NTDARK13
      @NTDARK13 3 года назад

      @Francisco António Bianchi haha true true

    • @pacotesan
      @pacotesan 3 года назад

      @@NTDARK13 Since you did not need the mod to read the key, you could write in other models of drives (unprotected ones) and it would work fine. So I had a few spares in case anything would go wrong but being quite honest, I think I had to resort to that only once and I modded hundreds of drives back in the day. (One company thet resold console even hired me for a day to mod almost 100 units, it was crazy but they had people to open and close the x360 , so I would only deal with the barebone drive.)

    • @pacotesan
      @pacotesan 3 года назад +1

      @Francisco António Bianchi As I replied, of course the client would be assured to get a fully working modded x360. Even getting new drives was very cheap at the time.

    • @integillentguy7735
      @integillentguy7735 3 года назад +1

      quanto você cobrava pelo serviço?

  • @andresbravo2003
    @andresbravo2003 3 года назад +449

    I do like “Mistakes were made”. Quite the history!

    • @mrj4264
      @mrj4264 3 года назад +8

      You should hear the story from my mom!

    • @Ubebread1
      @Ubebread1 3 года назад

      Mistakes are always made

    • @mariotaz
      @mariotaz 3 года назад

      My mum said I should be featured on MWM.

    • @kjellrni
      @kjellrni 3 года назад

      Maids were mistaken

  • @Sir_Uncle_Ned
    @Sir_Uncle_Ned 3 года назад +19

    Physically disconnecting the wires INSIDE the chip package! Holy hell! No wonder physical security is such a big thing nowadays!

  • @enricorov
    @enricorov 3 года назад +190

    One of my favourite hacking stories, this one - I remember it also being named the "Geremia method". Bonus trivia: sometimes the wires you shorted by dilling the hole would come apart again after a bit. To repeat the unlock, you needed to either stick the bit back in the hole and wiggle, or click an electronic lighter a couple times near the chip. Apparently the EM noise produced by the piezo was enough to trigger the circuit.
    Wild times for sure.

  • @deansundquist9601
    @deansundquist9601 3 года назад +94

    Any title from MVG that has “defeated security” in the title is a much watch in my book! As always thanks for the wonderful content.

  • @KarlRock
    @KarlRock 3 года назад +2401

    Gotta be one of the funniest hacks ever 🤣 Damn clever. You could tell even that Microsoft dude was impressed. I never had to do it, but I would've loved to take the risk ☺️

    • @royalkumar795
      @royalkumar795 3 года назад +27

      Nahi Chahiye ji

    • @Einar730
      @Einar730 3 года назад +4

      No

    • @marko6804
      @marko6804 3 года назад +13

      Hi Pewds

    • @ThatOneWeeb420
      @ThatOneWeeb420 3 года назад +64

      A pair of tweezers defeated the Nintendo Wii security, too
      What's next? "How a piece of tin foil defeated security of the Sony PS5 "

    • @Xnand
      @Xnand 3 года назад +4

      @@itzjosheyy8514 Why not, he did a whole video on buying modded consoles lol

  • @conflict-tv
    @conflict-tv Год назад +21

    I was in this scene heavily back in the day. I never had one drive fail or go wrong. I developed some of the CFW for reset glitch hacked phat consoles, painstakingly using non-complier-based languages (as compiled code was hard to debug even when you had privileged access), and it taught me the high-level foundations of key/vault hardware security. Thanks to the X360, I’m now in a dream career due to the weird obsession I had with reversing the original 2005-11 hardware. 🎉

  • @aswa121235
    @aswa121235 3 года назад +405

    I easily did hundreds of these back in the day when I worked for a console shop in eastern europe and only managed to completely brick two boards at the very beginning. After doing a few of these we just eyeballed the bottom of the K letter on the MEDIATEK logo and never marked it. Worked nearly every time and when something went wrong we just put and pressed a solder ball in the hole after flashing and the drive worked again.

    • @gordordf1091
      @gordordf1091 3 года назад +4

      Nice!

    • @tezcanaslan2877
      @tezcanaslan2877 3 года назад +5

      How did you brick those two

    • @jothain
      @jothain 3 года назад +43

      @@tezcanaslan2877 well it would be quite easy to drill wrong sized hole, have drill slip etc. Then I suppose there's miniscule probability that chip insides could be slightly misaligned in manufacturing, but so little that chip would still work without issues, but resulting in dead system trying this hack. It would have to be really bad luck, but I think it could be plausible to happen.

    • @lelsewherelelsewhere9435
      @lelsewherelelsewhere9435 3 года назад +11

      @@tezcanaslan2877 I guess he went too deep, and grinded out several metal traces instead of shorting them.
      The soldier blob after, on his other later mistakes, to "remake" these traces seems to agree.
      Remove too many, and now any soldier blob would short too many.

    • @MDLuffy1234YT
      @MDLuffy1234YT 2 года назад +8

      Damn. If you could do hundreds of those fuckers with only two failures, I'm honestly surprised that it's still called the Kamikaze Method. Plus, with all of the tools in the market to make the process easier and easier, why hasn't anyone invented a device where you put the board, lower a "tonearm" of sorts with a drill bit on it, and then push a button to make it automatically drill at the perfect position, stopping when it reaches the exact depth necessary to sever the connections.

  • @franciscolozada1059
    @franciscolozada1059 3 года назад +46

    When you showed the example of a mod gone wrong lol, that dude picked out the biggest drill bit he could find lol

  • @iamdarkyoshi
    @iamdarkyoshi 3 года назад +827

    I adore stuff like this. It's really a case of "If there's a will, there's a way"
    Knocking out the bond wires to the die is a pretty clever means of gaining access to signals they wanted you to stay away from. Reminds me of dremmling open those stupid dallas clock chips on my older computers to revive the RTC

  • @Generalkidd
    @Generalkidd 3 года назад +148

    These videos are so interesting! Never would've guessed this is what it used to take to break the 360's security. Would love to see an analysis or explanation on the Xbox One's security. I would imagine Microsoft went to even greater lengths to lock it down this time around to the point where they managed to go a whole console generation without any major hardware exploits.

    • @shoopdahoop2221
      @shoopdahoop2221 3 года назад +2

      an exploit for the Xbox One will never happen
      the security is completely airtight, and there's just no reason to hack an xbox one considering everything it has to offer

    • @Psyantic1196
      @Psyantic1196 3 года назад

      Love your channel bro

    • @MaleficWeegee
      @MaleficWeegee 3 года назад +2

      @@TehChozen1 You can actually get a Retail mode version of Retroarch so you don't have to swap between the two modes. Pretty fun stuff.

    • @andrewhamop6665
      @andrewhamop6665 3 года назад +3

      @@shoopdahoop2221 famous last words...lol

    • @nigo1787
      @nigo1787 3 года назад +4

      @@shoopdahoop2221 "there's just no reason to hack an xbox one considering everything it has to offer"
      I don't get that statement. Anyway, XBox One has not been defeated to my knowledge. Congrats to Microsoft, I suppose, they succeeded THAT much

  • @James-gj8rn
    @James-gj8rn 3 года назад +387

    The “Mistakess Were Made” series is the best videos on the channel, i love them 😊

  • @syko670
    @syko670 3 года назад +10

    I worked in a modding/repair shop for consoles around this time. We had a decent method of using a dremel with the 360 lizard kit, mostly saw successes with this modding method. There were of course a few boards that we didn't line up correctly or maybe the hand wasn't steady enough. Luckily we had spare unlocked board that we could flash to in case the board was cooked after the attempt. Just had to make sure to read the drive key before attempting the kamikaze method.

  • @l4ndst4nder
    @l4ndst4nder 3 года назад +54

    Another definition for Kamikaze is Divine Wind, which is the literal translation. It’s a reference to the typhoons that destroyed both mongol invasion attempts in 1274 and 1281. Because these events have hold significant importance in Japanese culture, during WWII the pilots were called to be the “divine wind” to destroy the invaders once again.
    It was first and foremost an act of nationalism. However for cultural reasons it was interpreted as meaning a self sacrificial attack by the west.

    • @dr.velious5411
      @dr.velious5411 3 года назад +5

      That somehow never crossed my mind, but yeah it's literally Kami Kaze, as in God/Divinity + Wind

  • @RyTrapp0
    @RyTrapp0 3 года назад +5

    If anyone hasn't seen the Tony Chen presentation, it's a great watch for the tech head, really fascinating how they engineered the security and their goals in doing so.
    Gotta say though, I don't think this is a legit "mistakes were made", but rather, if you have to go to THIS length, then the security is certainly doing an effective job of being a deterrent. And that's all you can ask for from any security system, there is no such thing as "perfect" or "unhackable" security or any of the sort, that's essentially impossible, it's the degree of deterrence that matters. Doesn't have to be "unhackable" if hacking is either too risky, just a massive amount of work, or necessitating some meaningful degree of technical skill(which then essentially puts a price tag on it as a lot of people will then have to pay a skilled person to perform this service).

  • @DarthSmirnoff
    @DarthSmirnoff 3 года назад +195

    Gotta be at least one person out there with a story like "Yeah, I tried the Kamikaze hack, and now they call me Johnny 7 Fingers."

    • @23Scadu
      @23Scadu 3 года назад +5

      Imagine four balls on the edge of a cliff. Say a direct copy of the ball nearest the cliff is sent to the back of the line of balls and takes the place of the first ball. The formerly first ball becomes the second, the second becomes the third, and the fourth falls off the cliff.
      Xbox modding works the same way.

  • @AskYwalker973
    @AskYwalker973 3 года назад +3

    I did TONS of these back in 2012-2013......I should have definitely charged more. The soldering iron was way safer than the drill bit. I used the drill bit to mark the point then I used the soldering iron.......those were the days...awesome video!!!

  • @Pwnsweet
    @Pwnsweet 3 года назад +99

    This is insane. INSANE. I got out of the Xbox 360 modding scene after JTAG, and I thought that was pretty hardcore. But this. This is just insane.

    • @nothingnew765
      @nothingnew765 Год назад +2

      Same! I had a Xenon with a flashed drive for online, and a later a JTAG Jasper. Most people wanted the slims because of the RRODs.

    • @youcantstopme5136
      @youcantstopme5136 Год назад

      Lmfao people don't do that to the Xbox 360 you just buy a mod chip and put it in the 360

  • @DkryptX3
    @DkryptX3 3 года назад +3

    One thing worth mentioning. This hack, and the others related to reading the drive key and reflashing it onto a new drive were necessary to replace a failed 360 drive; not just enable burned copies.

  • @chasesmay7237
    @chasesmay7237 3 года назад +112

    That’s brilliant. They had so many consoles in the wild by then that the risk was pretty low because you could pick up a 360 for dirt cheap even in 2012. I never knew about this one though, I love it!

  • @Martin-d
    @Martin-d 3 года назад +4

    Thanks for the nostalgia hit. I remember the days patiently awaiting a method for flashing the slims, had such great times back then. I'd say I flashed well over 50 xbox 360's during this era, and the small fee I charged most people was very welcome as a young 15/16 year old at the peak. Miss those days!

  • @thatred
    @thatred 3 года назад +149

    This reminds me of an old April Fool’s joke from the german DOS magazine back in 1993, where they showed a method of drilling your 486SX CPU to convert it into a full 486DX with co-processor. They promised the drilling template for May. ;)

    • @Zerbey
      @Zerbey 3 года назад +8

      @@aDistantLight There was another one that turned your 486SX into a DX by just tricking the OS into thinking you had a coprocessor. In that era very few games used a coprocessor but some software would refuse to run without one. Surprisingly enough, all of them worked but nowhere close to the performance of a true DX.

    • @Zerbey
      @Zerbey 3 года назад +7

      The SX was a DX that failed some tests so the FPU part was disabled, in much the same way CPUs are given a lower clock speed if they don't past the quality controls for a higher speed (hence why overclocking exists). Not sure if there was a way to re-enable it without specialist equipment. I heard rumours that people did so but never saw it in person.

    • @jeffyp2483
      @jeffyp2483 3 года назад +3

      @@aDistantLight i cant recall the name, but i used a coprocessor 'emulator' tsr for my old 386sx (sx stands for 'sucks' ;) to get some game to run with belss and whistles reserved for x87 equipped machines. cant remember the game either. it worked, but i remember the performace being even worse. makes sense, no fpu, worse fp performance.

    • @5roundsrapid263
      @5roundsrapid263 3 года назад +4

      The Celeron 300A, if the right pin was drilled out, could easily run at 450 MHz, as fast as the fastest Pentium II at the time! I knew a guy who did it.

    • @jeffyp2483
      @jeffyp2483 3 года назад +1

      @@5roundsrapid263 that seems kind of familiar to me but didn't you just break the pen off?

  • @DrunkenMonk1
    @DrunkenMonk1 3 года назад +6

    Interesting thing about kamikaze is that technically there was a brief second rendition that involved dremelling the PCB substrate on a corona V3/4/5/6 prior to the release of the "postfix" adapter. Microsoft definitely learned several harsh lessons with the 360 that all essentially boil down to "don't trust the end-user with their own hardware"

  • @ShawFujikawa
    @ShawFujikawa 3 года назад +100

    Ever since LTT mentioned this offhandedly in his coverage on Retroarch with Dev Mode on the Series S, I’ve wanted to hear more about the Kamikaze mod. Nice! c:

  • @MissingNumber
    @MissingNumber 3 года назад +4

    I love these stories. The ingenuity and will of the gaming community never ceases to amaze me. I mean literally using a drill to hack a console... And even the name "kamikaze hack" just sounds awesome. Where there's a will, there's a way.

  • @Kousaburo
    @Kousaburo 3 года назад +319

    Next video: How the PS5 was defeated with a squirrel and 2 Q-Tips.

    • @KiraSlith
      @KiraSlith 3 года назад +7

      I can see lightly charring traces with burning Q-tips to increase their resistance, but what's the squirrel's job?

    • @igotnothingbettertodo472
      @igotnothingbettertodo472 3 года назад +3

      I wonder when they gonna hack it

    • @arnone1862
      @arnone1862 3 года назад +5

      I bet Stack Overflow is already working on installing Linux and Steam on a PS5 😆

    • @volvo09
      @volvo09 3 года назад +21

      @@KiraSlith you don't need the whole squirrel, just a dab of it's urine on the q tip, with the other one to wipe it off a key area of the motherboard exactly when programing is done.
      You can also create a precisely conductive solution, but that won't be available till kits are made, thus the squirrel.

    • @Eighty_Eight88
      @Eighty_Eight88 3 года назад +4

      Mistakes Were Made

  • @shawnunder7
    @shawnunder7 3 года назад +13

    The drilling is scariest when Jungle Flasher freezes and you're like "damn, I'm about to go too far". Thank lord that never happened to me and we made it to the other side.

  • @TheSa2cha
    @TheSa2cha 3 года назад +28

    I do remember trying this. I also remember how my heart skipped a beat when I bricked the drive :D

  • @sofronio.
    @sofronio. 3 года назад +3

    These stories are so fascinating. They're better than most tv shows and movies.

  • @Syntax.error.
    @Syntax.error. 3 года назад +19

    C4eva is a absolute legend. Thanks to him I was able to play so many games it was amazing. I had updated my xbox dvd firmware so often that all the plastic clips on my 360 where gone. Really miss those days.

  • @AiOinc1
    @AiOinc1 3 года назад +3

    An absolutely incredible feat of Homebrew engineering used to defeat the protection here, it's nothing short of amazing.

  • @diligaf1000
    @diligaf1000 3 года назад +131

    Love this hack it's hilarious, even MS must have had a laugh when they found out about it.

    • @matthewpepperl
      @matthewpepperl 3 года назад +30

      i can imagine the people behind xbox saying "they did WHAT!!!" and laughing their assess off

    • @knghtbrd
      @knghtbrd 3 года назад +20

      @@matthewpepperl At some level, when you're doing security stuff, you just stop and say, "Damn, if they did that, they DESERVE to get in." Doesn't mean you stop trying to identify who's gotten in, mind you.

    • @SuperDavidEF
      @SuperDavidEF 3 года назад +3

      @@knghtbrd The problem is Microsoft treating their users like criminals. Yeah, this hack probably helped a lot of copyright infringement, but that's not the point. Microsoft should have made better deals with the developer community to allow for the existence of "backup" copies. Microsoft thinks they're Neo and there is no spoon. Reality continues to hit them in the balls and they never learn, because they're making enough money being aggressive toward their customers.

    • @knghtbrd
      @knghtbrd 3 года назад +5

      @@SuperDavidEF That's a major reason why I didn't bother to buy one of the consoles. That and that most of the games I prefer to play tend to be a little older anyway.

  • @bramvandenbroeck5060
    @bramvandenbroeck5060 3 года назад +3

    Reminds me of the dallas rtc chip, you could get a drop in replacement with a fresh battery, or, you could "hack" the chip and drill holes in it to attach a coin cell to the internal legs of the chip, amazing stuff and like you said, where is a will, there is a way!

  • @negritorican
    @negritorican 3 года назад +26

    The real genius is the first person who figured this out. How? Would love to see a interview with the person who came up with this hack.

    • @Zerbey
      @Zerbey 3 года назад +12

      If you decap a microcontroller and have knowledge of how they work it's not that hard to reverse engineer it. Watch CuriousMarc, he and his team do so in several episodes.

    • @MrStronglime
      @MrStronglime 3 года назад +2

      @@Zerbey Thanks for the suggestion mate! Now watching how soviet soyuz clocks were built.

    • @davidmcgill1000
      @davidmcgill1000 3 года назад +1

      @@Zerbey Having knowledge is one thing, but deciding to shove a drill bit into it? That can't have been the first choice for a solution.

    • @VeyronBD
      @VeyronBD 3 года назад +1

      @@davidmcgill1000 I guess its really the easiest one. Decapping is a real risk especially with the epoxy junk, really only way to get to the wires is by drilling.

  • @ucitymetalhead
    @ucitymetalhead 3 года назад +13

    Sticking it to the big corporations no matter what really warms my heart.

  • @thesillyhatday
    @thesillyhatday 3 года назад +14

    This was a lot of fun back then. Couldn't believe it worked when I did it. Seems so simple but so clever too. I did it with the measuring and pencil lines. No guide for me

  • @CYPH3RsD0M41N
    @CYPH3RsD0M41N 3 года назад +93

    Microsoft: Haha! We have beaten the modders.
    Modders: Heh. Drill go brrrrrr.

  • @Kazzman90
    @Kazzman90 3 года назад +42

    I remember reading about this back then. So crazy the lengths people are willing to go.

  • @DeemienX
    @DeemienX 3 года назад +8

    Now THAT'S what you call "brute force" ... love it!

  • @TheSleepyCraftsman
    @TheSleepyCraftsman 3 года назад +78

    I would have expected MS and other companies to have formed dedicated red teams with the purpose of defeating their own security. Only my opinion, but I have always thought the best way to improve anti-tamper design is to literally defeat the anti-tamper in-house. The purpose of dedicated teams that could hack each others group's products.

    • @KiraSlith
      @KiraSlith 3 года назад +8

      From what I've heard, Microsoft's internal social corporate hierarchy is pretty easily toppled with even mild competition, so they just avoid it when they can. That's partly why huge chunks of the NT Kernel itself in Windows 10 is STILL based on code that predates Windows 2000.

    • @darrencurry4429
      @darrencurry4429 3 года назад +4

      @@KiraSlith Why does it matter if the code predates Windows 2000?

    • @TheBackyardChemist
      @TheBackyardChemist 3 года назад +9

      @@darrencurry4429 hardware changes, user requirements change, tools/compilers improve, etc.

    • @DogginsFroggins
      @DogginsFroggins 3 года назад +10

      They just made dev mode and gamepass, now its kinda pointless to hack unless you are trying to prove a point, they used the only proven model to beat piracy, create good affordable content and services.

    • @BrianKPepin
      @BrianKPepin 3 года назад +2

      Microsoft does have such a team. I don’t know if they were used for the Xbox 360 but I know they dedicated a few months trying to crack the Xbox One.

  • @froid_san
    @froid_san 3 года назад +5

    Ah the Fun times of hardware modding, never knew there was a tool to get the coordinates. I just count the pins and used a 18w soldering Iron to drill a hole and works every time, that it becomes second nature on my old job.

  • @BeastOfSoda
    @BeastOfSoda 3 года назад +27

    If that ain't a textbook MacGyver, then I don't know what is.

  • @joshualynn5250
    @joshualynn5250 3 года назад +2

    I was always more interested in JTAG and RGH mods on the 360 because of homebrew and unsigned code so I never knew about this hack. super interesting for sure. great video

  • @adamjensen1145
    @adamjensen1145 3 года назад +12

    Brings a whole new meaning to the term "brute force attack" doesn't it?

    • @BuzzBazzJ
      @BuzzBazzJ 3 года назад +1

      With a knife? Yes. Yes it does😂

    • @QuickishFM
      @QuickishFM 3 года назад

      I never asked for this

    • @adamjensen1145
      @adamjensen1145 3 года назад +1

      @@QuickishFM I didn't and the chip certainly didn't. You wouldn't catch me putting a drill through my augs, what is this, Pi? 😉😊👍

  • @anthonycondon5833
    @anthonycondon5833 3 года назад +1

    I'm a historian. I think what you're doing here, as someone who knows what they're talking about, giving a 'first pass' at the history, is going to be super useful for future historians. I know it's for the clicks today, but stuff like this could wind up being genuinely important pieces of source material to future historians. Great stuff :)

  • @matthewzepess5721
    @matthewzepess5721 3 года назад +7

    Love these videos, I remember reading all about this. Didn’t get into modded Xbox’s till rgh was a thing so it wasn’t that necessary for kamikaze anymore.

  • @andregon4366
    @andregon4366 3 года назад +120

    If I was with Microsoft I'd be like: "If you went through such lengths to defeat our security you deserve to play a few games for free"
    That was really impressive and creative.

    • @yuriwolfvt
      @yuriwolfvt 3 года назад +10

      I'm not even mad, I'm impressed.

    • @HappyBeezerStudios
      @HappyBeezerStudios 3 года назад +20

      As Valve would say: piracy is a thing of convenience. If it's easier to install and use something via a pirated copy, the dev has done something wrong. And no software DRM is unbeatable, it's only a matter of time until someone breaks it.

    • @andregon4366
      @andregon4366 3 года назад +6

      @@HappyBeezerStudios This was not a software DRM, it was hardware DRM. Which is even more impressive.

    • @ryhanzfx1641
      @ryhanzfx1641 3 года назад +4

      this is the reason the devs mod exist on future xbox right? so i can play retroarch

  • @Z0MBUSTER
    @Z0MBUSTER 3 года назад +27

    Microsoft : this is not a drill, I repeat this is not a drill !
    Kamikaze : Actually it is...

  • @XenHat
    @XenHat 3 года назад +1

    Great video! -- At 3:40, you meant "read-only".
    Also, I got banned from Xbox live/semi-bricked my own console doing one of these firmware mods back then. No drill though. fun stuff.

  • @MaximNightFury
    @MaximNightFury 3 года назад +131

    I still can't wait for "toaster strudel defeated security on the PS5"

  • @hotderp
    @hotderp 3 года назад +4

    Man I still remember hanging out on EFnet waiting for c4eva to drop firmware with every new release. Good times!!

    • @BuzzBazzJ
      @BuzzBazzJ 3 года назад

      Tried to look it up now incase I’d need the software, and it’s dead…

  • @richardweidlin9539
    @richardweidlin9539 3 года назад +76

    Well, software can't exist without hardware.
    By the way, i'm curious about how good or bad was windows ce to programming games for the dreamcast. I hope you talk about dreamcast again in your future videos.

    • @zomfragger
      @zomfragger 3 года назад +2

      Not hard as long as you know how to program in windows ce.
      Now before you make a game for the dreamcast with ce in mind you must know that the dreamcast does not have ce installed on the system. Instead it runs ce from the game disk then launches the game.

    • @ILoveWomen
      @ILoveWomen 3 года назад +9

      Windows CE had a big performance hit apparently

  • @Littlefighter1911
    @Littlefighter1911 3 года назад +1

    5:25 OMFG
    That's like blowing up a banks vault by firing an orbit canon from space.

  • @sontapaa11jokulainen94
    @sontapaa11jokulainen94 3 года назад +39

    Write protection: exists
    Hackers: *SO THAT IS WHEN I STARTED DRILLING*

  • @madcat4563
    @madcat4563 3 года назад +1

    Man I love these videos. They are very interesting.
    Many of the technical terms I don't quite understand, but I still like watching them.

  • @StormBurnX
    @StormBurnX 3 года назад +28

    It's wild to see how Team Xecuter's run has gone for over a decade but now they're behind bars thanks to nintendo :( RIP

    • @fake12396
      @fake12396 3 года назад +4

      The "Team Xecuter" that got arrested wasn't the real TX, their name was bought by the assholes behind Gateway 3DS. The actual TX guys are probably sitting on a beach right now, earning 20%.

    • @bitelaserkhalif
      @bitelaserkhalif 3 года назад +3

      The current era TX is basically gateway3ds team, which is scummy due to drama that gateway3ds team created.

    • @StormBurnX
      @StormBurnX 3 года назад +3

      @@bitelaserkhalif Oh dang. I hated the 3DS so I skipped out on that whole mess but I loved their work on the Switch, they did a remarkable job taking half-baked open source projects and turning them into actual polished professional products that didn't feel like 'hacks' but felt more like genuine accessories. Was looking forward to their releases for the newer switch models but I guess that's died out now :(

    • @MacGuffin1
      @MacGuffin1 3 года назад +4

      TX stole all their ideas and designs from the community and manufactured them poorly, they deserve no credit for anything other than ruining the scene

    • @StormBurnX
      @StormBurnX 3 года назад

      @@MacGuffin1 A popular uninformed opinion, yes. Thank you for your lack of contribution to the discourse

  • @chrislong7590
    @chrislong7590 3 года назад +1

    I can't count how many of these I did. And I didn't even use a drill or guide. The location was always the lower point of the K and you could use a small exact blade and just use it to drill down with a much finer point.
    Those days of console modding were fun and exciting. Waiting on IRC to see what drives were good for burning the non truncate discs flashing custom firmware to DVD burners, firmware update patches, and watching C4Eva break it in a week.

  • @pastiesandagstring
    @pastiesandagstring 3 года назад +5

    Lol I remember my friend doing this. So funny how they manage these hacks sometimes. I still have my o.g. Fat models so I never had to go the kamakazi route personally.

  • @Elkatook666
    @Elkatook666 3 года назад

    the instructions stated "drill gently, rinse and repeat"
    cut to picture of someone who drilled straight through the chip AND PCB !! 07:53 lolol
    great video as always

  • @mjdxp5688
    @mjdxp5688 3 года назад +8

    Next episode: How a screwdriver defeated security on the Sega Dreamcast

    • @HonkeyKong54
      @HonkeyKong54 Год назад

      How dreamcast died by not putting security

    • @HonkeyKong54
      @HonkeyKong54 Год назад

      Lmao you could burn game's day 1

  • @ControlAllDa1337
    @ControlAllDa1337 3 года назад +1

    One of my all time favourite hardware hacks. The epitome of, as the video mentions, where there's a will, there's a way.

  • @tbk2010
    @tbk2010 3 года назад +23

    I would count this as a win for Microsoft. The amount of effort and risk involved means there are much fewer Xbox owners willing to do the mod, reducing piracy compared to many other hacks. As always, security is mostly about putting up enough of a fight that it's making yourself unattractive as a target.

  • @koozmusic
    @koozmusic 3 года назад +1

    I remember dremeling down the edge of my Wii's DVD drive controller chip to expose three legs that were purposefully cut off. Scary stuff. Good thing I had a steady hand!

  • @ureeb5829
    @ureeb5829 3 года назад +3

    Its simply insane, just goes to show what people can do if they really wanna do it.

  • @woogaloo
    @woogaloo 3 года назад

    I've seen this video in a lot of articles recently. Very cool to see it outside of RUclips!

  • @Natei
    @Natei 3 года назад +3

    I did exactly this back in the day, didnt have any of the tools just some diagrams from online, Got it eventually but it was scary to say the least. I enjoyed the burned games after though

  • @Jan93Banan
    @Jan93Banan 3 года назад +2

    There was something similair with the Yamaha DT 50cc bike. There was a rev limiter in the ignition box under the seat. If you drilled a hole in a specific place you could disable the rev limiter.

  • @geofrancis2001
    @geofrancis2001 3 года назад +2

    i bet it never even crossed their minds that someone could open the package as easy as they did, it must have blown their minds that after all their work it was beaten by a drill.

  • @WildcardZwei
    @WildcardZwei 3 года назад +1

    Another wonderful episode of 'Mistakes Were Made'. (You really should use that as branding for these) I'm always surprised at the length people will go to hack their systems. But as far as I can tell, 360 is still one of the hardest systems to mod without an internal change of some kind. Still a little bit of a bummer if I'm honest.

  • @silentjose
    @silentjose 3 года назад +3

    Oh man. I remember doing an insane amount of research for this. So damn poor I could only afford one Xbox and if I messed it up it was over. Got it on the first try. I remember hearing that beep in jungle flasher and jumping.

  • @DarkGambitX
    @DarkGambitX 3 года назад

    You are one of the best creators on RUclips hands down. Every video is so thorough. My hats off to you sir.

  • @foxinrot
    @foxinrot 3 года назад +35

    Next time: how a breaker defeated security on the PS5

    • @johnnyhun1
      @johnnyhun1 3 года назад +3

      you mean hammer?

    • @HonkeyKong54
      @HonkeyKong54 Год назад

      A breaker?

    • @foxinrot
      @foxinrot Год назад

      @@HonkeyKong54 the thing that switches power to your house?

  • @romein138
    @romein138 3 года назад +1

    The peak of console modding when online gaming on consoles was just starting to boom in popularity. Now PC gaming is on the rise and hotter than ever, I don't ever see the console modding scene will ever be as fun and hot as it was back then.

    • @BuzzBazzJ
      @BuzzBazzJ 3 года назад

      Just wait till someone cracks the PS5 or SeriesX and get internal server access that cannot be revoked so both companies have to completely dump every pice of hardware and start from scratch😂😂

  • @X150t
    @X150t 3 года назад +4

    I was amazed at how easy it was to mod my 360. Even those who really don't know much about computers could follow the commands for flashing the drive.

  • @LMF5000
    @LMF5000 8 месяцев назад +1

    Former semiconductor engineer here. Since the drill is just going through the wire bonds (not the die itself) the depth of the drill hole sn't too critical. As long as you sever the wires it will work - if you go a little too far you'll only be drilling into the plastic beneath the wires, no harm done.

  • @NineOneOneFx
    @NineOneOneFx 3 года назад +5

    Do you think that drilling a hole to hack a drive sounds insane? Well, let's not forget that the first X360 hack was done using a floppy. OUTRAGEOUS!!! LOL

  • @kikihun9726
    @kikihun9726 3 года назад

    I loved how he talked about this mod in the presentation. I watched the whole video.
    I think even he wants to see when someone find a way to unlock the Xone.

  • @jovangrbic97
    @jovangrbic97 Год назад +3

    Wait, why isn't it easier to pull up the 2 pins externally? He says the chip is '4 layers' which makes it impossible, but a '4 layer chip' has no meaning, wtf? The pins are right there under the epoxy, much safer to disconnect the externally...

    • @Mr_Lambda
      @Mr_Lambda 5 месяцев назад

      That's what i was thinking. Cut the track on the pcb with a scalpel or if it's not in sight. Use a small soldering iron, heat the pin up and raise it using a scalpel tip. You need to be an expert at SMD soldering but it can be done and it's less risky

  • @badboybruno547
    @badboybruno547 3 года назад +2

    Love these security videos. Always great stuff. Much love from down under.

  • @FozzieOzbourne
    @FozzieOzbourne 3 года назад +4

    This was a pleasant notification to wake up to! 🤘🤘🤘

  • @TheAdwian
    @TheAdwian Год назад +1

    While i never had any experience with the kamikazi hack, i do remember doing the RGH hack on a few consoles back in the day when i was a teenager. RGH was the "new way" to turn consoles in to devkits that couldnt be JTAGged. I remember getting this thing from team Xecuter. it was called a nand-X, there was this chip that you had to solder onto specific points on the console, pull the nand from said console, and flash it to enable Devkit accessibility. You couldnt go online with it though unless you wanted to get instabanned. i remember people selling nand flashes that were hidden/ unbannable, but never wanted to pay for the service because i didnt trust it at the time.

  • @voxelfusion9894
    @voxelfusion9894 3 года назад +6

    And now look at the steam deck, a console that is totally unlocked. We've come a long way.

    • @LucasCunhaRocha
      @LucasCunhaRocha 3 года назад +1

      Steam deck is NOT a console, it is a normal x86 computer. Why is it so hard to people to understand it?

    • @HonkeyKong54
      @HonkeyKong54 Год назад

      Steam deck is just a pc with a front end

  • @Sieghartz93
    @Sieghartz93 3 года назад +1

    Oh boy I love coming across such well done videos and all the more when sources are properly credited! Makes me instantly subscribe!
    Thumbs up good sir and keep up the good work !

  • @MixedMucus
    @MixedMucus 3 года назад +4

    Yay, another MVG video!

  • @ashcoronawestmuckett8889
    @ashcoronawestmuckett8889 3 года назад +2

    This is really interesting, love this kind of stuff, it would be interesting to hear about more of the physical mods

  • @darrencurry4429
    @darrencurry4429 3 года назад +8

    6:10 Would be interested in a better explanation of this. I'm confused on why the pins were not an available attack? How is cutting the wire internally different from lifting the pin? What does the chip being 4 layers have to do with this? What mitigations did microsoft put in place, other than epoxy? Seems like drill the epoxy to the pins would have the same effect.

    • @renakunisaki
      @renakunisaki 3 года назад

      I assume there were other wires connected to those pins as well. It's really not clear though.

  • @forgottendreamteam
    @forgottendreamteam Год назад

    On the old star trek scotty cut a section of the wall near a locked door to cut away all the proper connections so it would open, with a lazer cutter, while the electricity was running through the ciructs...
    He did it super slow and even got yelled at for how slow it was taking.
    They even had to draw up an exact schematic to cut only the necessary parts. Exactly like pcb trimming but while its powered up.
    They were spot on when they made that part of the show and really knew how to go about the cutting.

  • @Spinningininfinity
    @Spinningininfinity 3 года назад +4

    Miss Takes is a very naughty girl but in this case she knows the drill🥳😄
    This is a truly awesome series and is in my save list.
    Live long and prosper🖖

  • @nagi.desuuu
    @nagi.desuuu 3 месяца назад

    I love how in 6:28 you repeat what you said in 5:25 because this entire hack just sounds SO DAMN RISKY

  • @joesalgadSF415
    @joesalgadSF415 3 года назад +7

    I remembered doing my 360 with that little drill kit from Xecuter that I found someone selling locally. But I remembered putting a drop of isopropyl alcohol as you drill right?

  • @Tarodenaro
    @Tarodenaro 3 года назад +1

    that two IC Bonding wire could be as thin as 10 micro meter (yes, micro; not mili) so that's a really precise drill right there.

  • @user-yz4xo7ih6m
    @user-yz4xo7ih6m 3 года назад +4

    I just bought an unlocked board and flashed my dvd key job done it was too easy in the 360 days i loved modifying them even the leds

  • @HappyBeezerStudios
    @HappyBeezerStudios 3 года назад +1

    The fact that in hindsight it's so simple is amazing.