
Xbox Hackers Have Managed To Dump NAND of Xbox One

It's closing in on to being nearly a week since the Xbox One was officially launched by Microsoft. Facing a lot of hiccups and bumpy roads leading to the launch, Microsoft still managed to sell one million units to the customers within 24hours but keep in mind that it is a total of selling units in 13 key countries.

Hackers confirm that they have successfully managed to dump Xbox One's NAND.

dedicatedtogamers3840d ago (Edited 3840d ago )

PSP: The Console.

I remember reading an article a bit ago which postulated that the security for Xbox One was going to be weak. After all, the original form of security was always-on DRM and registering your game discs with a mandatory install.

And in less than a year, the XBox team has had to gut that system, start all over, and develop a new method of copyright protection, online security, account verification, anti-hacking methods, etc. And now that you don't HAVE to be online, there is no way to prevent it. Anyone who works with computers or network security knows that you can't create an infrastructure that is

1) Stable
2) Fast
3) Widespread, and
4) Secure

in less than a year. If you have less than a year, pick one from that list. If you're lucky, pick two.

What is more worrying is that if hackers have been able to do that ALREADY, what will they unlock in 6 months? A year? Is your account information safe? How about your credit-card info? Will there be hackers and cheaters in online multiplayer games?

pete0073840d ago

Not long ago i prophetized that this generation of consoles will be the EASIEST of all to reverse engeneer. why? you ask! X86 architecture for 30 years on the hands of modders, pirates and university guys that hack sometimes just for fun or to prove their skills.
dont tell me the semi custom bullshit and all those specific chips. a good ivy bridge, not to go haswell+ a capable Gpu with some good ram to keep bandwidt sky high ( guess what... ddr4 is coming soon!!)
and thats all. a flahed firmware and fire your guns.
the only good thing is that the most hacked one is the best seller.... aka ps2......

ginsunuva3840d ago

This has nothing to do with credit card info.

But everything else is true

Omegasyde3840d ago (Edited 3840d ago )

I work in Network security and your statement of "Anyone who works with computers or network security knows that you can't create an infrastructure that is ...less than a year is" is far away from the truth.

Network security is all about resource management. Microsoft could of improved security and could of changed the system security protocols in a month if they wanted too.

The reason the Xbox is getting modded, is because of piss poor management and or policies. Let alone the fact Xbox1 OS also uses a windows kernel + x86, which modders have been playing with for years.

I will agree with your statement that the this was a horrible insight since the system's proprietary features originally relied on always-on DRM.

dedicatedtogamers3840d ago (Edited 3840d ago )

@ Omegasyde

So you're saying that Microsoft could've made a network from the ground up (after scrapping the original X1 DRM) in less than a year that was fast, widespread, reliable, and secure?

I don't think so. Like I said, pick one. Pick two if you're lucky. I agree that, yes, you COULD scrape together working protocols for a nation-wide network - heck, maybe even a worldwide network - in a month or two. But it will have serious flaws, security being one of them.

Let's hope PS4 doesn't also have these sort of security problems.

EDIT @ inveni0

Okay, let's not waste time arguing about semantics. The point is that Microsoft didn't have enough time to add enough proper layers of security to the Xbox One. Simple. Any questions?

mark134uk3840d ago

i think ms will allow it to be hacked as it will boost sales like it did with the 360

nveenio3840d ago


"Secure" doesn't exist in reality. THAT'S what every network security professional knows. There is always a hole. Rushed networks are less secure than established networks, but that doesn't mean they fall within the scope of the broad generalization the term "secure" provides.

3840d ago
4Sh0w3840d ago

I heard this all before with the 360 launch and how it was doomed, 360 did fine, Xbox most stable, console and games sales did quite well. In other words who cares= I buy games and enjoy my console like most good citizens.

KiLLeRCLaM3840d ago

They are gonna hack our accounts and steal our passwords/credit card info and all that good stuff..

Eonjay3840d ago

I used to hack my PS3 but I gave in and decided to support the developers. I didn't do it for Sony, I did it because I wanted to show my appreciation to the developers that put their time and effort into playing the games I loved. After I updated, I went out and bought the same games I used to pirate. The only way to keep the good games coming is to support the people who create them.

Oner3840d ago

@ mark134uk "i think ms will allow it to be hacked as it will boost sales like it did with the 360"

Not always true, look at what happened to the Dreamcast. Having a hacked system may increase sales of said console but at the cost of the system being sold at a loss to the manufacturer i.e. no profit, as well as no profit for the games that are available.

In a situation like that you may think it's good as you are getting "free" games but what happens when devs dont make money? They don't make games. Then what? You can't download games that aren't being made.

Now CFW and Homebrew that is a different story and is completely fine. But we all know that is not the main intent/use by the vast majority of users do so.

indysurfn3840d ago

Okay I'm calling total Bull. booo hoo, woe is us now we will get hacked without DRM. If being connected would save systems from being hacked then why is there currently hacked xbox360 machines that sign on, and get updates ALL THE TIME! Every single day, and they do not get banned!

This sounds like a article that is paid for by Microsoft. They are hiding behind you giving up your freedom, so they can police you!

Remember 85% of all news articles are paid for by a sponsor!

TOTAL BS I for one am not falling for it.
First ban the xbox360's that sign in to get updates so they can run there games. Then make that stupid claim!

GribbleGrunger3840d ago (Edited 3840d ago )

Can they access your Kinect camera?

DatNJDom813840d ago (Edited 3840d ago )

False Flag Ops. DRM will return.

badz1493840d ago

all I can say is...This is why we can't have nice things!

on the other hand, x86 architecture and Windows on top of it? it's no longer a "come at me, bro" situation with the hackers, it's more like "please be gentle" kinda thing!

iChii3839d ago

Wow, the comments on that article are just horrible... o.e

Kushan3839d ago

It's amusing how many of you don't know what you're talking about.

Xbone NAND was dumped using methods similar to the current 360 dumping methods, that's why it was so easy - they've had years of practice.

NAND is encrypted, key is unknown.

Contents of NAND are digitally signed, key will almost certainly never be known.

NAND dumps are incredibly common as a first step, they're not a vector for attack by themselves though as the digital signatures prevent any kind of modification to them (unless a system HAS no Digital signature enforcement, but rest assured this will).

In other words, this doesn't mean anything, they still need other exploits to do anything with the console. The 360's NAND was dumped and even decrypted years before they could do something with it (The JTAG hack) and even that was patched, another attack had to be used (the glitch attacks).

user55757083839d ago

explains why they originally wanted to implement DRM

gear3839d ago

"Will there be hackers and cheaters in online multiplayer games?"
YES! and I will be the first one to cheat

SilentNegotiator3839d ago (Edited 3839d ago )

That reminds me; I need to dust off the ol' PSP and hack it. PSP doesn't even support the latest wifi standards, so I can't even play my PS+ games on it anymore.

On topic, even with the 24-hour DRM, they should have been prepared with more basic security.

abzdine3839d ago

i could really feel the DRM u-turn would have had consequences cause it was thought from the beginning to counter the piracy.

making a u-turn 3months before release is impossible to do without bad consequences, especially when we know how terrible are MS in protecting their products from being hacked.

it's their own fault and i really hope this isn't true this early in the process because on top of the not so overwhelming sales they could lose the third party support as well.

The_Con-Sept3839d ago

Wait until they find out how to change the serial numbers for the units. You will never be able to get rid of the cheaters and random consoles will get banned if the numbers match.

PSX043840d ago

just now I can say ... welcome to xbone

cleft53840d ago

Not surprising considering they are using Windows 8 operating system with the console. Nothing against Microsoft but Windows 8 is hardly the most secure platform. Just be glad they got rid of the DRM otherwise there would be whole teams of hackers working everyday to figure out how to take apart the system. This is just typical stuff right here.

r1sh123840d ago (Edited 3840d ago )

this isnt really a hack.. Hes dumped the nand, the only time its 'hacked' is when the nand can be modified and put back into the console.

Removing the DRM would have made no difference to this, the DRM was related to games and this is related to the OS/ xbox itself.

These are two separate items that are being put together.
DRM would have needed to be authenticated by something, most likely a hashcheck md5- checksum (i reckon).That would be authenticated via the network so this is not related to the nand dump.

This does mean homewbrew - modded nands might find a way into the Xbone, which could lead to Jtag style mods. For the time being we have to wait and see what happens and how the nand is analysed.

the most worrying thing - why are xbox 360 nand dumping tools working on the Xbone?

I wonder how the PS4 compares?

Edit: Just to add remember when the ps3 finally got hacked Sony left the Pseudo Random Number Generator? (PRNG)in the code (LOL).
I wonder if MS have been stupid enough to do that?
or Hopefully SOny learned.

Without being able to break those keys theres not much to that can be modded. Running unsigned games etc..

wheresmymonkey3839d ago

I agree by itself this is nothing. Problem is that now people can go through it with a fine tooth comb looking for loopholes and exploits and figures out what realtes to what.

THe biggesst problem is that between this and the discs that got dumped the other week hackers have all they need to figure out how to reverse engineer pretty much everything.

Coupled with the fact that the 360 piracy scene has some pretty dedicated and tenacious people in it and you have the potential for all kinds of trouble.

Blaze9293840d ago

this thing runs parts of windows...are we really surprised that it was this quick and easy?

Darrius Cole3840d ago

I don't speak advanced-computer-nerd'ese . Could someone translate the article? And could someone tell me what a "NAND" is?

UnholyLight3840d ago (Edited 3840d ago )

Yeah, just like I was before, I'd be perfectly fine with Microsoft implementing their DRM policies again.

I really don't like what I'm hearing here with how easy it's going to be for hackers to get into the system. Is our account information safe? What about my PS4? How long before the same happens with that console as well?

Like I said, I'd much rather have those security checks than have to be worried about this for the next ~5 years before the next gen arrives. Thanks for ruining what could have saved us from this, all you who got upset at Microsoft!

T23840d ago

whos worried use playstation cards or don't save your c.c online....

thisismyaccount3840d ago (Edited 3840d ago )

And piracy will make it a "successful" console....again.

Sometimes i wonder if the companies behind, do this on purpose, knowing that their console is not selling well (lets leave a "door" open in our system)....

Seriously... not even 1 month old and we have seen:

XB1 BluRay Disc .iso of Ghost or copied (what ever the term is, dont rem.)
And now the Console or parts of it too.

How much longer until the console is fully "hacked" ?

sweendog3840d ago

First I have heard that DRM on xbox was to stop pyracy. It hasnt worked on PC only controlled the innocent. I think that is why DRM was put forward

Finch3839d ago

All due respect to both companies, but I would of thought the ps4 would be cracked first. Now this is still early on both sides Xbox may get nodded first the way it's going now. Yet I still would not be surprised if the ps4 is still fully cracked first. I know they both will be cracked, just wondering what one first.

Shnazzyone3839d ago

Only 1 week. Surprised this hasn't happened to ps4, it's just an x86 system too. The second both the consoles announced basic pc arcitecture at their core I knew this was going to happen. How long until people find a way to play the exclusives on their pc's?

illizit3839d ago

LOL.. You can really tell this site is made up of little script kiddies that have no idea what is going on.

The dumping of the NAND means nothing. Is it a first step? Sure.. but there is so much more that needs to occur. It has nothing to do with x86 architecture nor having a windows kernel.

Carry on..

+ Show (9) more repliesLast reply 3839d ago
inf3cted13840d ago

Same security probably, not impressed.

Moz3840d ago

It's what happens when you have to put the copy protection in with less then 6 months to work on it. They just didn't have the time to implement anything different. They were probably expecting this but when the choice was between weak copy protection and no one buying your console they didn't have much choice.

iamnsuperman3840d ago

The only other choice would be to delay the launch. That could have been disastrous for Microsoft but at the same time it might have eliminated this issue

svoulis3840d ago (Edited 3840d ago )

If you're wondering what that means.

Hacked Lobbies, Homebrew, Piracy, and the possibility of Microsoft putting the ON switch for DRM. (cause they can)


Not exactly, but upon signing into your Xbox One you agree on the EULA to not sue them for anything including changing in service and their policy. If they feel this is a real threat the only retaliation would be to re-enable always online. Which would suck for everyone.

MasterCornholio3840d ago (Edited 3840d ago )

"possibility of Microsoft putting the ON switch for DRM. (cause they can)"

Thats what they found out?

Well i hope it doesnt happen because we dont need that DRM crap back.


"Which would suck for everyone."

This would be bad for Xbox One owners but not PS4 owners. So im not worried about DRM at all.

Blackdeath_6633840d ago

knowing what microsoft are like they will probably end making a knee-jerk reaction that will harm its regular consumers in some way the best way for them to deal with it is via updates the same way apple does on IOS

OrangePowerz3840d ago (Edited 3840d ago )

Would be interesting to see what the Anonymous guys would do if DRM comes back given how pissed hackers got when Sony removed the little option to install Linux.

user95970823840d ago

People who use online functions with stolen game isos always got banned/consolebanned. It's no different than it's always been.

famoussasjohn3840d ago

Shinymasonite - I've known multiple people with modded xbox's and they haven't been banned in years.

KiLLeRCLaM3840d ago

Microsoft knew all along that this was going to happen and a good reason to re-enable always online again..That is what they wanted from the beginning..

+ Show (4) more repliesLast reply 3840d ago
falviousuk3840d ago

@blackdeath A knee jerk reaction, you mean like removing the other OS option from their console .... oh wait that wasnt on the xbox was it.

svoulis3840d ago

Yes, thats right. Lets talk about Other OS. Which I am sure all of 3% of PS3 owners used. It was a vulnerability and it was taken away. How exactly is that Sonys fault that someone decides to ruin it for everyone? Just like in this case if Microsoft enables DRM again, it wouldn't be our fault or theirs it would be forcing their hand because of hackers.

so yes harp on the Other OS drama, cause that proves how insanely intelligent you are.

Drekken3840d ago

A feature no one used on a console you never owned.

T23840d ago (Edited 3840d ago )

wow you built a time machine, welcome to 2010 sir!

ziggurcat3840d ago

1. Less that 1% of the user base even used otherOS

2. It would still be there if idiots had left well enough alone.

Pope_Kaz_Hirai_II3840d ago

falviousuk + 9h ago
@blackdeath A knee jerk reaction, you mean like removing the other OS option from their console .... oh wait that wasnt on the xbox was it.


+ Show (2) more repliesLast reply 3840d ago
calis3840d ago

What exactly is the NAND and what does it do?

Blackdeath_6633840d ago

its a type of flash memory that doesn't require power. the info stored on there is what makes and xbox an xbox and not just a piece of hardware that you can manipulate if i am not mistaken by dumping NAND you can modify the OS and have custom firmware this will basically allow the hackers to do as they please pirate games, homebrew software and pretty much anything they want. from the limited experience i have hacking the PSP.

i wonder if said hacker can use the kinect for his own evil desires that would be creepy

RDF3840d ago

The thought that hackers could rewrite Kinect into their personal Webcam and spy on ppls is quite scary.

sloth4urluv3840d ago

As already stated NAND is a non volatile memory (same stuff in a USB stick/SSD).
Dumping the memory is not difficult, all it requires is un-soldering the memory and connecting it to a test board that can interface to it.

(I don't know anything about the xbox one architecture, but the same would be true for the PS4 if it uses NAND as well.)
If the controller for the flash (a device that remaps the addresses for the data and performs wear leveling to prevent certain frequently used addresses from being worn out) is a discrete external part, it can easily be lifted and moved as well. This would provide a perfect copy of the OS since all the addresses would be mapped in the correct order. If the memory controller is embedded, then dumping the NAND flash would dump all the data but you would have no idea what order it is in.


esemce3840d ago (Edited 3840d ago )

By having access the the 360's nand and hacking/modding it this was acheived.


It does not mean the Xbone is hacked but is just 1 step closer to it.

+ Show (1) more replyLast reply 3840d ago
They’re not working on Call of Duty? Give it time.