//ketvault address 17489
#define hvKvPtrDev 0x80000102000162E0 // 0x00000102000162E0
QWORD KVAddress = (Globals::isDevkit) ? HvxPeekQWORD(hvKvPtrDev) : HvxPeekQWORD(hvKvPtrRetail);
//Pokes devkit console cert for 17489
if (Globals::isDevkit) {
Utilities::SetMemory((BYTE*)((*(DWORD*)0x81D59F68) + 0x313C), &Globals::KV.ConsoleCertificate, 0x1A8);//Devkit v17489
}
//checks weather RGH is devkit or not
Globals::isDevkit = *(DWORD*)0x8E038610 & 0x8000 ? FALSE : TRUE;
/*Patches ran 1st on boot */
if (Globals::isDevkit) {
// Kernel Version
*(PDWORD)0x81744334 = 0x38C04451;
*(PDWORD)0x81D275A4 = 0x44510000;
*(PDWORD)0x81CB8B58 = 0x38C04451;
*(PDWORD)0x8174459C = 0x2B3F4497;
*(PQWORD)0x81823310 = 0x6000000039604497;
// Kernel.exe
*(PDWORD)0x80040460 = 0x44970000;
*(PDWORD)0x80040468 = 0x07600000;
// Stops Avatar Update Loop
*(PDWORD)0x817BE360 = 0x60000000;
// MMGetPhysical
*(PDWORD)0x8172BDC8 = 0x60000000;
// CXChalResp::CheckPkSig
*(PDWORD)0x81ABD380 = 0x38600001;
// Rename XOSD to XOSC
*(PDWORD)0x8168A4EC = 0x786F7363;
*(PDWORD)0x8168A512 = 0x786F7363;
// XamUserCheckPriv
*(PDWORD)0x817A80E8 = 0x39600001;
*(PDWORD)0x817A8154 = 0x39600001;
*(PDWORD)0x817A815C = 0x39600001;
*(PDWORD)0x817A8148 = 0x39600001;
// Evaluate Content
*(PDWORD)0x81732850 = 0x38600000;
}
unsigned char DevKitPatches[0x228] = {
0x81, 0x73, 0x64, 0x34, 0x00, 0x00, 0x00, 0x01, 0x60, 0x00, 0x00, 0x00,
0x81, 0x73, 0x28, 0x50, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x00,
0x81, 0x72, 0xEE, 0xC4, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x00,
0x80, 0x0C, 0x51, 0xE8, 0x00, 0x00, 0x00, 0x01, 0x39, 0x60, 0x00, 0x00,
0x80, 0x0C, 0x52, 0x10, 0x00, 0x00, 0x00, 0x01, 0x39, 0x60, 0x00, 0x00,
0x80, 0x0A, 0x17, 0xB0, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x00,
0x80, 0x0A, 0x09, 0xE8, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x14,
0x80, 0x09, 0xEE, 0xDC, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x01,
0x80, 0x0A, 0x0D, 0xB8, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x00,
0x80, 0x09, 0xEE, 0x78, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x01,
0x80, 0x0A, 0x64, 0x94, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x14,
0x80, 0x0A, 0x5B, 0xDC, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x14,
0x80, 0x0A, 0x62, 0x8C, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x14,
0x80, 0x14, 0xA1, 0xFC, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x01,
0x80, 0x14, 0xC3, 0x5C, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x01,
0x80, 0x14, 0xC3, 0x64, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x01,
0x80, 0x14, 0xA1, 0x5C, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x01,
0x80, 0x0E, 0x22, 0xCC, 0x00, 0x00, 0x00, 0x01, 0x48, 0x00, 0x00, 0x34,
0x80, 0x0E, 0x45, 0xE0, 0x00, 0x00, 0x00, 0x01, 0x60, 0x00, 0x00, 0x00,
0x80, 0x19, 0x3B, 0xE8, 0x00, 0x00, 0x00, 0x01, 0x48, 0x00, 0x00, 0x30,
0x80, 0x19, 0x3F, 0xFC, 0x00, 0x00, 0x00, 0x01, 0x60, 0x00, 0x00, 0x00,
0x80, 0x04, 0x04, 0x60, 0x00, 0x00, 0x00, 0x01, 0x44, 0x97, 0x00, 0x00,
0x80, 0x04, 0x04, 0x68, 0x00, 0x00, 0x00, 0x01, 0x07, 0x60, 0x00, 0x00,
0x81, 0xAB, 0xD3, 0x3C, 0x00, 0x00, 0x00, 0x01, 0x60, 0x00, 0x00, 0x00,
0x81, 0xB4, 0x88, 0x5C, 0x00, 0x00, 0x00, 0x01, 0x60, 0x00, 0x00, 0x00,
0x81, 0x73, 0x3A, 0xCC, 0x00, 0x00, 0x00, 0x01, 0x4B, 0xFF, 0xFF, 0x04,
0x81, 0x73, 0x42, 0x04, 0x00, 0x00, 0x00, 0x01, 0x48, 0x00, 0x00, 0x14,
0x81, 0x68, 0xA4, 0xEC, 0x00, 0x00, 0x00, 0x01, 0x78, 0x6F, 0x73, 0x63,
0x81, 0x68, 0xA5, 0x12, 0x00, 0x00, 0x00, 0x01, 0x78, 0x6F, 0x73, 0x63,
0x81, 0x72, 0xBD, 0xC8, 0x00, 0x00, 0x00, 0x01, 0x60, 0x00, 0x00, 0x00,
0x81, 0x82, 0x0E, 0x4C, 0x00, 0x00, 0x00, 0x01, 0x60, 0x00, 0x00, 0x00,
0x81, 0x82, 0x0E, 0x78, 0x00, 0x00, 0x00, 0x01, 0x60, 0x00, 0x00, 0x00,
0x81, 0x82, 0x11, 0x20, 0x00, 0x00, 0x00, 0x01, 0x60, 0x00, 0x00, 0x00,
0x81, 0x76, 0x16, 0x98, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x00,
0x81, 0x76, 0x17, 0x58, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x00,
0x81, 0x76, 0x18, 0xD0, 0x00, 0x00, 0x00, 0x01, 0x38, 0x60, 0x00, 0x00,
0x81, 0x5F, 0x3E, 0x7C, 0x00, 0x00, 0x00, 0x01, 0x00, 0x00, 0x00, 0x00,
0x81, 0x5F, 0xD9, 0xCD, 0x00, 0x00, 0x00, 0x05, 0x6F, 0x76, 0x65, 0x72,
0x72, 0x69, 0x64, 0x65, 0x5C, 0x64, 0x61, 0x73, 0x68, 0x2E, 0x78, 0x65,
0x78, 0x00, 0x00, 0x00, 0x81, 0x88, 0x00, 0xB8, 0x00, 0x00, 0x00, 0x02,
0x38, 0x60, 0x00, 0x04, 0x48, 0x48, 0xFD, 0x71, 0x81, 0xD2, 0x75, 0xA4,
0x00, 0x00, 0x00, 0x01, 0x44, 0x97, 0x00, 0x00, 0x81, 0x7A, 0x80, 0xE8,
0x00, 0x00, 0x00, 0x01, 0x39, 0x60, 0x00, 0x01, 0x81, 0x7A, 0x81, 0x54,
0x00, 0x00, 0x00, 0x01, 0x39, 0x60, 0x00, 0x01, 0x81, 0x7A, 0x81, 0x5C,
0x00, 0x00, 0x00, 0x01, 0x39, 0x60, 0x00, 0x01, 0x81, 0x7A, 0x81, 0x48,
0x00, 0x00, 0x00, 0x01, 0x39, 0x60, 0x00, 0x01, 0xFF, 0xFF, 0xFF, 0xFF
};
static HvxCall HvxExpansionInstall(DWORD PhysicalAddress, DWORD CodeSize) {
if (Globals::isDevkit) {
__asm
{
li r0, 0x70
sc
blr
}
}
else
{
__asm
{
li r0, 0x72
sc
blr
}
}
}
static HvxCall HvxExpansionCall(DWORD ExpansionId, QWORD Param1 = 0, QWORD Param2 = 0, QWORD Param3 = 0, QWORD Param4 = 0) {
if (Globals::isDevkit) {
__asm
{
li r0, 0x71
sc
blr
}
}
else
{
__asm
{
li r0, 0x73
sc
blr
}
}
}
//Code for Liveblock & livestrong
void patch_BLOCK_LIVE(BOOL State) {
WCHAR* nullStr = L"NO.%sNO.NO\0";
memcpy((PBYTE)0x8161EB14, State ? toCHAR(nullStr) : toCHAR(L"SIFLC.%sXBOXLIVE.COM"), 0x14);
memcpy((PBYTE)0x8161EB2C, State ? toCHAR(nullStr) : toCHAR(L"PIFLC.%sXBOXLIVE.COM"), 0x14);
memcpy((PBYTE)0x8161EB44, State ? toCHAR(nullStr) : toCHAR(L"NOTICE.%sXBOX.COM"), 0x14);
memcpy((PBYTE)0x8161EB58, State ? toCHAR(nullStr) : toCHAR(L"XEXDS.%sXBOXLIVE.COM"), 0x14);
memcpy((PBYTE)0x8161EB70, State ? toCHAR(nullStr) : toCHAR(L"XETGS.%sXBOXLIVE.COM"), 0x14);
memcpy((PBYTE)0x8161EB88, State ? toCHAR(nullStr) : toCHAR(L"XEAS.%sXBOXLIVE.COM"), 0x14);
memcpy((PBYTE)0x8161EB9C, State ? toCHAR(nullStr) : toCHAR(L"XEMACS.%sXBOXLIVE.COM"), 0x14);
}
VOID SetLiveBlock(BOOL State) {
if (Globals::isDevkit) {
patch_BLOCK_LIVE(State);
}
else
{
DWORD Address = ResolveFunction(MODULE_LAUNCH, DL_ORDINALS_SETOPTVALBYNAME);
((VOID(*)(...))Address)("liveblock", (PDWORD)&State);
((VOID(*)(...))Address)("livestrong", (PDWORD)&State);
}
}