Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

Xbox One Retail SKUS + Other contributions #53

Merged
merged 16 commits into from
Oct 2, 2023
Merged
1 change: 1 addition & 0 deletions .gitignore
Original file line number Diff line number Diff line change
Expand Up @@ -6,6 +6,7 @@
Thumbs.db

# mkdocs build dir
.cache/
site/

# Python venv
Expand Down
1 change: 1 addition & 0 deletions docs/NAVIGATION.md
Original file line number Diff line number Diff line change
@@ -1,5 +1,6 @@
- [Home](index.md)
- Hardware
- [SKU List](retail-xone-skus.md)
- [Codenames](codenames.md)
- [Console revisions](console-revisions.md)
- [CPU](cpu.md)
Expand Down
10 changes: 10 additions & 0 deletions docs/codenames.md
Original file line number Diff line number Diff line change
Expand Up @@ -4,10 +4,20 @@ This page contains a list of known internal codenames for hardware, software, ac

| Codename | Product / App Name | Category | Description or Comments |
|----------|-------------|------|------|
| Arden/Sparkman | Codename(s)? for the Xbox Series S/X secure AMD enclave | Hardware | N/A |
| Keystone | Unreleased Xbox Streaming platform / hardware device | Hardware | N/A |
| Cordova | Codename for one of the Xbox One ODD hardware revisions | Hardware | N/A |
| Lancaster | Codename for one of the Xbox One ODD hardware revisions | Hardware | N/A |
| Monterey | Codename for one of the Xbox One ODD hardware revisions | Hardware | N/A |
| Argos | Codename for the [Zebra prototype controller](https://x.com/TorusHyperV/status/1690416005564993536?s=20) hardware | Hardware | N/A |
| Geneva | Presumably, codename for some uncertain controller prototype hardware | Hardware | N/A |
| Nui / nuisensor | Kinect | Hardware | Internal name for Kinect, still used in official APIs and drivers |
| Petra | Presumably, a codename of an earlier Kinect prototype hardware version | Hardware | N/A |
| Nazca | Presumably, a codename of an earlier Kinect prototype hardware version | Hardware | N/A |
| Ameri | Presumably, a codename of an earlier Kinect prototype hardware version | Hardware | N/A |
| Graybull | Codename for the retail Xbox One PHAT day One mainboard revision | Hardware | N/A |
| Silverton | Codename for a retail Xbox One PHAT mainboard revision | Hardware | N/A |
| Zurich | [Xbox One Digital Tv Tuner Adapter](https://www.amazon.de/Xbox-One-Digital-TV-Tuner/dp/B00E97HVJI) | Hardware | N/A |
| Brittlebush | [XDK Transfer Device](xdk_transfer.md) | Hardware | N/A |
| Xiphos | Codename for the GIP (Gamepad Input Provider) service in SystemOS | Software | N/A |

1 change: 1 addition & 0 deletions docs/exploits.md
Original file line number Diff line number Diff line change
Expand Up @@ -11,6 +11,7 @@
- [Browser access while offline](exploits/browser-access-while-offline.md)

### Development mode
- [SystemOS Elevation of privileges via Artifice (automation tool) using vulnerability in OpenSSH service](exploits/artifice-devmode-elevation.md) (10.09.2023)
- [SystemOS Read/Write overlay for System.xvd](exploits/devmode-systemxvd-read-write.md) (31.07.2019)
- [SystemOS Elevation of privileges via UnattendedUtilities](exploits/devmode-unattended-utilities.md) (11.06.2019)
- [SystemOS Elevation of privileges via VSProfiling account](exploits/devmode-priv-escalation-vsprofiling.md) (09.09.2018)
Expand Down
24 changes: 24 additions & 0 deletions docs/exploits/artifice-devmode-elevation.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,24 @@
# Name / description of vulnerability

## Metadata
| | |
|-----------------------------|-----------------------------------------------------|
|Release date | 10.09.2023 |
|Author | Kudayasu |
|Classification | Devmode SystemOS privilege escalation |
|Patched | No (as of October 1st 2023) |
|Patch date | - |
|First patched system version | - |
|Source | https://kudayasu.github.io/an-autopsy-of-artifice/ |
|Download | https://github.com/Kudayasu/Artifice/releases/tag/v.1.1.0 |

## Info
A completely privilege escalation exploit for Devmode, granting an admin account in SystemOS.

## Prerequisites
- Windows host computer
- Console in devmode (UWP devkit or superior)

## Instructions
Download the artifice release, make sure your console is reachable from the host computer, run the program and type the console IP. Then launch the exploit.
If it succeeds, an account called `admin` with password `admin` will be created in SystemOS. You can ssh to this account.
Binary file added docs/hardware/X887998-010/back.jpeg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added docs/hardware/X887998-010/front.jpeg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added docs/hardware/X902472-006/back.jpeg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
Binary file added docs/hardware/X902472-006/front.jpeg
Loading
Sorry, something went wrong. Reload?
Sorry, we cannot display this file.
Sorry, this file is invalid so it cannot be displayed.
92 changes: 92 additions & 0 deletions docs/retail-xone-skus.md
Original file line number Diff line number Diff line change
@@ -0,0 +1,92 @@
# Retail Xbox One Motherboard SKU listing

This page aims to become an exhaustive list of every different motherboard models / SKUs out there. **It is currently Work In Progress.**

At the moment, the following identificators are collected, and where to find them:

For Xbox One Phat:

- PCB Label Number: This is the number, starting with X, that appears on the motherboard's label, in the front layer.

- PCB Soldermask Number: This is the number, starting with X, that appears on the bottom right corner, in the front layer.

- Hardware description / differences: relevant changes in components, etc.

- Owned by / Contributed by: who discovered the board revision.

- Pictures.

For Xbox One S/X:

- Same as above. Update this page with where to find the identificators on the boards.

## Contributing models and pictures

Upload your PCB pictures to the directory */docs/hardware/*.

Use the following guidelines:

* Create a subdirectory with the name of the soldermask SKU (The one on the front side of the motherboard, in the bottom right corner, starting with X. NOT THE ONE ON THE LABEL)

* Upload at least two pictures: front and back

* Make sure they are high resolution, such that the SKUs are visible when zooming in.

* Update the SKUs page accordingly.

## Xbox One Phat

### Durango Revisions


* **PCB Label Number**:
* **PCB Soldermask Number**:
* **Hardware description / differences**:
* **Owned by / Contributed by**: public domain
* **Pictures**:

Not available yet


### Silverton Revisions


* **PCB Label Number**: X933919 - 001 Rev. C
* **PCB Soldermask Number**: -
* **Hardware description / differences**: Reduced eMMC/Southbridge voltage regulator with unknown voltage divider.
* **Owned by / Contributed by**: Anonymous
* **Pictures**:

Not available yet


---
* **PCB Label Number**: X900499 - 001 Rev. C
* **PCB Soldermask Number**: X887998-010
* **Hardware description / differences**: Reduced eMMC/Southbridge voltage regulator with unknown voltage divider. Does not contain data lines on the bottom layer of the PCB, under the HDMI ports.
* **Owned by / Contributed by**: TorusHyperV
* **Pictures**:

![X887998-010 Front](hardware/X887998-010/front.jpeg)
![X887998-010 Back](hardware/X887998-010/back.jpeg)


---
* **PCB Label Number**: X940636 - 001 Rev. A
* **PCB Soldermask Number**: X902472-006
* **Hardware description / differences**: Reduced eMMC/Southbridge voltage regulator with known voltage divider. Dark green soldermask, instead of light green.
* **Owned by / Contributed by**: TorusHyperV
* **Pictures**:

![X902472-006 Front](hardware/X902472-006/front.jpeg)
![X902472-006 Back](hardware/X902472-006/back.jpeg)


## Xbox One S
_Your help is needed to complete this page! Fork this repo and make a Pull Request to contribute_

## Xbox One S - all digital
_Your help is needed to complete this page! Fork this repo and make a Pull Request to contribute_

## Xbox One X
_Your help is needed to complete this page! Fork this repo and make a Pull Request to contribute_
5 changes: 4 additions & 1 deletion docs/xcrdutil.md
Original file line number Diff line number Diff line change
Expand Up @@ -138,4 +138,7 @@ xcrdutil -delete_blob [XUC:]\targetPackage.xvd
|0x80070002 | File/path not found | This error appears whenever an invalid path to a file is used (either XCRD, native \\??\\ path, or SystemOS path). | ```xcrdutil -m [XUC:]\idontexist.xvd```
|0x80070570 | Possible permission error |This error appears when an operation is denied due to insufficient permissions. Examples include trying to mount host.xvd. | ```xcrdutil -m \??\F:\host.xvd``` or ```xcrdutil -QueryInfo \??\F:\host.xvd 3```
|0x8007048F | Path not found |This error appears when trying to create/access a file in a XCRD path that does not exist. | ```xcrdutil -c [XE0:]\someinvalidpath```
|0x80070032 | Unknown | Possibly meaning the passed XVD does not have region information | ```xcrdutil -Specifiers [XUC:]\someXvdYouveMounted```
|0x80070032 | Unknown | Possibly meaning the passed XVD does not have region information | ```xcrdutil -Specifiers [XUC:]\someXvdYouveMounted```
|0x80070005 | Unknown | Unknown | ```xcrdutil -read_blob \??\F:\host.xvd D:\DevelopmentFiles\host.xvd.dmp``` (as elevated admin account)

NOTE: It is possible that error codes have changed over time with newer xcrdutil versions, and the table might not be completely accurate.
Loading