PhatHack
May 30, 2012, 11:04:20 am *
Welcome, Guest. Please login or register.

Login with username, password and session length
News: Registration only by approval.  You probably want to send one of the admins an email asking them to approve you if you just created an account.
 
   Home   Help Search Login Register  
Pages: [1]   Go Down
  Print  
Author Topic: Conclusions #1  (Read 971 times)
0 Members and 2 Guests are viewing this topic.
para
Senior Member
Veteran.
*****
Offline Offline

Posts: 181



WWW
« on: March 27, 2005, 12:35:53 am »

Ok, from my point of view it's time to sum up some of our findings here and discuss them on a general (not too technical) level.

1) All interesting files on the DMS are signed
2) The DMS disk (its unique data like serial, etc.) seems to be signed
3) The firmware is checked by a non-accessible bootloader
4) Signed files are (compared to encryption) validated by public-keys only

These four basic findings lead me to the impression that it's going to be very hard to hack the DMS as these guys @Phatnoise (yes, I do mean you) knew what they'd done - no wonder, they're (were?) people like us! As long as we don't devise a way of using some still undiscovered bugs I can only imagine some hardware solution. We either might recode their initial bootloader (assuming it's an EEPROM) and/or try to manipulate the harddisk's firmware. Both of which I havn't done yet :-/

Time to discuss, and please keep it on a general level as the detailed technical means should be discussed in their respective threads...

Para
« Last Edit: March 27, 2005, 12:37:31 am by para » Logged

AndyMan
Getting the hang of things.
**
Offline Offline

Posts: 75



« Reply #1 on: March 27, 2005, 03:16:03 am »

I'm not holding out much hope of getting the rc.sh signed by Brendan (more's the pity) because I think it may just have worked... the hardware to accomplish this still has not arived BUT they tell me it'll be available later this week.

basically, I wanted to load hdb rather than hda in the drive map (Vince, if you're looking) would this be futile??

Brendan, any chance of getting the script signed?
« Last Edit: March 27, 2005, 03:16:18 am by AndyMan » Logged
para
Senior Member
Veteran.
*****
Offline Offline

Posts: 181



WWW
« Reply #2 on: March 27, 2005, 12:35:44 pm »

What I wanted to say is: changing files (or patching code) is not an option at the moment so let's discuss other possibilities. Of course this doesn't mean to give up any research in these areas...
Logged

Pages: [1]   Go Up
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.14 | SMF © 2006-2011, Simple Machines LLC Valid XHTML 1.0! Valid CSS!
Page created in 0.022 seconds with 17 queries.