<?xml version="1.0" encoding="UTF-8"?><rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
		>
<channel>
	<title>Comments on: Hacking Apple TV without a patchstick?</title>
	<atom:link href="http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/feed/" rel="self" type="application/rss+xml" />
	<link>http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/</link>
	<description>Get more from your shiny box of joy</description>
	<lastBuildDate>Wed, 28 Jul 2010 11:45:46 +0000</lastBuildDate>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.0</generator>
	<item>
		<title>By: Andrew</title>
		<link>http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/comment-page-1/#comment-73438</link>
		<dc:creator>Andrew</dc:creator>
		<pubDate>Sun, 20 Jul 2008 08:02:14 +0000</pubDate>
		<guid isPermaLink="false">http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/#comment-73438</guid>
		<description>Actually the whole problem is not getting the AppleTV to talk to your fake update server, it is making it accept an unsigned file. Forget cracking the signature, it is not viable.

Also, if you do crack the signature, you might as well get involved with iPhone hacking, which also uses signed firmware. The dev team&#039;s Pwnage &quot;fixes&quot; this, but by making the device ignore the mismatching signature, rather than getting the signature right. It would require previous modification of the AppleTV for this technique to work though, so it kind of beats the purpose of this.

The only way to do it without previously modifying the AppleTV would have to be via some sort of vulnerability exploit, but then it would work only for a short while (until the next software update), so I believe this idea does not have a lot of potential, unless we can get the AppleTV to ignore the signature checking (quite hard to do, if you ask me).</description>
		<content:encoded><![CDATA[<p>Actually the whole problem is not getting the AppleTV to talk to your fake update server, it is making it accept an unsigned file. Forget cracking the signature, it is not viable.</p>
<p>Also, if you do crack the signature, you might as well get involved with iPhone hacking, which also uses signed firmware. The dev team&#8217;s Pwnage &#8220;fixes&#8221; this, but by making the device ignore the mismatching signature, rather than getting the signature right. It would require previous modification of the AppleTV for this technique to work though, so it kind of beats the purpose of this.</p>
<p>The only way to do it without previously modifying the AppleTV would have to be via some sort of vulnerability exploit, but then it would work only for a short while (until the next software update), so I believe this idea does not have a lot of potential, unless we can get the AppleTV to ignore the signature checking (quite hard to do, if you ask me).</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: GZ</title>
		<link>http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/comment-page-1/#comment-73366</link>
		<dc:creator>GZ</dc:creator>
		<pubDate>Sat, 19 Jul 2008 23:46:16 +0000</pubDate>
		<guid isPermaLink="false">http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/#comment-73366</guid>
		<description>A Man in the middle could work.  Inject once the signature is retrieved.  Setup a proxy, haven&#039;t checked if the appleTV can use a proxy, might have to do a double NAT to filter all traffic through the proxy.</description>
		<content:encoded><![CDATA[<p>A Man in the middle could work.  Inject once the signature is retrieved.  Setup a proxy, haven&#8217;t checked if the appleTV can use a proxy, might have to do a double NAT to filter all traffic through the proxy.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mark</title>
		<link>http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/comment-page-1/#comment-71636</link>
		<dc:creator>Mark</dc:creator>
		<pubDate>Tue, 15 Jul 2008 02:25:51 +0000</pubDate>
		<guid isPermaLink="false">http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/#comment-71636</guid>
		<description>HMM, what if you guys modify the real updates by apple and add the hacks to be installed along with updates, I kow it sounds simple but it may be very hard but then again, there wont be no need to find the &quot;signature&quot;.
if there was a way you could open the update package and add your hack or replace them with its original files, there would be no need for anything else, right??
I have done this for other stuff, and it works most of the time.</description>
		<content:encoded><![CDATA[<p>HMM, what if you guys modify the real updates by apple and add the hacks to be installed along with updates, I kow it sounds simple but it may be very hard but then again, there wont be no need to find the &#8220;signature&#8221;.<br />
if there was a way you could open the update package and add your hack or replace them with its original files, there would be no need for anything else, right??<br />
I have done this for other stuff, and it works most of the time.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Nutz</title>
		<link>http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/comment-page-1/#comment-70421</link>
		<dc:creator>Nutz</dc:creator>
		<pubDate>Fri, 11 Jul 2008 13:18:42 +0000</pubDate>
		<guid isPermaLink="false">http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/#comment-70421</guid>
		<description>I&#039;d like to get dmg&#039;s and .signature files for past updates to compare.  Anyone have 2.0 and 2.0.1?</description>
		<content:encoded><![CDATA[<p>I&#8217;d like to get dmg&#8217;s and .signature files for past updates to compare.  Anyone have 2.0 and 2.0.1?</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mojo</title>
		<link>http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/comment-page-1/#comment-67440</link>
		<dc:creator>Mojo</dc:creator>
		<pubDate>Tue, 01 Jul 2008 11:18:30 +0000</pubDate>
		<guid isPermaLink="false">http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/#comment-67440</guid>
		<description>You absolutely need a patchstick to install the hosts file and disable the update integrity check. Then though it will be possible to install any provided update. This, of cource, is not the solution. But it&#039;s a more comfortable way than to install ssh then copy some files, run some updates, install some files again ...

The other way mentioned is to hack the private key so it is possible to sign selfmade updates .... not very likely</description>
		<content:encoded><![CDATA[<p>You absolutely need a patchstick to install the hosts file and disable the update integrity check. Then though it will be possible to install any provided update. This, of cource, is not the solution. But it&#8217;s a more comfortable way than to install ssh then copy some files, run some updates, install some files again &#8230;</p>
<p>The other way mentioned is to hack the private key so it is possible to sign selfmade updates &#8230;. not very likely</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anonymous coward</title>
		<link>http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/comment-page-1/#comment-67032</link>
		<dc:creator>anonymous coward</dc:creator>
		<pubDate>Sun, 29 Jun 2008 22:32:10 +0000</pubDate>
		<guid isPermaLink="false">http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/#comment-67032</guid>
		<description>How would you set up a new IP address in /etc/hosts before you&#039;ve hacked your ATV? You&#039;ve got a chicken/egg situation there.</description>
		<content:encoded><![CDATA[<p>How would you set up a new IP address in /etc/hosts before you&#8217;ve hacked your ATV? You&#8217;ve got a chicken/egg situation there.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mojo</title>
		<link>http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/comment-page-1/#comment-66115</link>
		<dc:creator>Mojo</dc:creator>
		<pubDate>Thu, 26 Jun 2008 08:13:57 +0000</pubDate>
		<guid isPermaLink="false">http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/#comment-66115</guid>
		<description>Wouldn&#039;t it be sufficient to just set the new ip adress in the /etc/hosts? This way it is possible to block update ...</description>
		<content:encoded><![CDATA[<p>Wouldn&#8217;t it be sufficient to just set the new ip adress in the /etc/hosts? This way it is possible to block update &#8230;</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: anonymous coward</title>
		<link>http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/comment-page-1/#comment-65982</link>
		<dc:creator>anonymous coward</dc:creator>
		<pubDate>Wed, 25 Jun 2008 21:40:39 +0000</pubDate>
		<guid isPermaLink="false">http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/#comment-65982</guid>
		<description>You don&#039;t need to use internet sharing. Just set up the DNS server on your local LAN to point mesu.apple.com to a local address.</description>
		<content:encoded><![CDATA[<p>You don&#8217;t need to use internet sharing. Just set up the DNS server on your local LAN to point mesu.apple.com to a local address.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: Mojo</title>
		<link>http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/comment-page-1/#comment-64955</link>
		<dc:creator>Mojo</dc:creator>
		<pubDate>Sun, 22 Jun 2008 08:33:23 +0000</pubDate>
		<guid isPermaLink="false">http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/#comment-64955</guid>
		<description>But it would be easier to upgrade to future versions of atv without losing all plugins and hacks.
Of course, first you&#039;ll need to hack your atv. But that could happen with a linux patchstick as well. This patchstick just installs/hacks the update app. Then just select update and it connects to an update.awktwardtv.org and downloads the last atv os + all available hacks.</description>
		<content:encoded><![CDATA[<p>But it would be easier to upgrade to future versions of atv without losing all plugins and hacks.<br />
Of course, first you&#8217;ll need to hack your atv. But that could happen with a linux patchstick as well. This patchstick just installs/hacks the update app. Then just select update and it connects to an update.awktwardtv.org and downloads the last atv os + all available hacks.</p>
]]></content:encoded>
	</item>
	<item>
		<title>By: pman</title>
		<link>http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/comment-page-1/#comment-64435</link>
		<dc:creator>pman</dc:creator>
		<pubDate>Fri, 20 Jun 2008 20:16:12 +0000</pubDate>
		<guid isPermaLink="false">http://www.appletvhacks.net/2008/06/20/hacking-apple-tv-without-a-patchstick/#comment-64435</guid>
		<description>This won&#039;t work.  As stated above all Apple software updates are cryptographically signed by Apple.  Without Apple&#039;s private key it would be impossible to spoof the updates.  You would need to modify the public key that is already on the Apple TV, which isn&#039;t possible until the device is hacked.

I think a better route would be to look for buffer overflows that can be exploited via media playback, but that&#039;s a tough one.</description>
		<content:encoded><![CDATA[<p>This won&#8217;t work.  As stated above all Apple software updates are cryptographically signed by Apple.  Without Apple&#8217;s private key it would be impossible to spoof the updates.  You would need to modify the public key that is already on the Apple TV, which isn&#8217;t possible until the device is hacked.</p>
<p>I think a better route would be to look for buffer overflows that can be exploited via media playback, but that&#8217;s a tough one.</p>
]]></content:encoded>
	</item>
</channel>
</rss>
