Help - Search - Members - Calendar
Full Version: Complete Guide To Installing Xbreboot For Noobs
Scenyx Entertainment Community > Xbox360 Forums > Xbox 360 Hacking Forums > Technical Onboard Bios / Kernel / Dashboard Forum
Pages: 1, 2, 3, 4, 5, 6, 7
Roamin64
**UPDATE : XBReboot is now supported on 256 / 512 mb nands!

The very first thing you need to check, is your xbox kernel. At the time of writing, the most recent kernel is : 2.0.8955.0
  • Turn on your xbox and go to console settings.
  • Go to system info, the kernel version is on top right.
IPB Image

As of 5/12/09 (December 5th 2009) If you have kernel 2.0.8495.0 or HIGHER, YOU CANNOT INSTALL XBReboot.

If you have kernel 2.0.7371.0 or lower, there is one more check to do, which requires you to read the nand chip with a homemade lpt nand reader. USB Version

** There is no other 100% way of knowing your CB version without reading the nand.

Follow this thread to build a cable, Simple Db-25/cat5 Lpt Nand Dump/flash Cable Tut



Use this site to determine which motherboard type you have : Xbox 360 revisions OR check this picture.

Once the cable is ready and double checked, grab nandpro20b from Xbins (Make sure its version 2.0b)

Follow these steps to read your nand :
  • Make sure port95nt.exe is installed, if it's not, install it (from nandpro20b folder) you might need to reboot.
  • Plug your 360, but don't power it on.
  • Plug the lpt cable
  • Go to the nandpro20b folder and type :
  • nandpro lpt: -r16 orig.bin
  • MAKE SURE THAT THE FLASH CONFIG SAYS : FlashConfig:01198010 , if it doesn't , refer to troubleshooting at end of guide.
  • Wait patiently...
  • If there are errors, refer to trouble shooting at end of guide.
  • If there are no errors, read the nand again :
  • nandpro lpt: -r16 orig2.bin
  • Reading it a 3rd time is not a bad idea.
  • Don't power on the console in between reads , especially not without dvd drive connected , or your dumps will mostlikely not match.
Once you have a good dump , at any point you can restore it to your 360. Follow instructions at end of guide.

How to make sure you have a good dump :
  • First , compare the dumps together using a hex editor or other tool, they should match 100%
  • Grab Degraded 1.1b from Xbins. *** You can also use 360 Flash tool to verify CB.
  • Run Degraded and click settings, enter key you found using google "Degraded 1BL key" should pop right up.
  • After you set the key click Valid next to it and set the File System Start to 39. Click ok.
  • Open orig.bin
  • If you get, cannot read file , you must edit the orig.bin file. Make a copy of it, origcopy.bin and open it up in your hex editor. At offset 0x0012 , you will see 2004 - 2007 Microsoft Corporation...
  • Change it to : 2004 - 2005 Microsoft Corporation and it will open with Degraded :
IPB Image
(This picture shows an unexploitable CB version)

If Degraded shows you some bad blocks, refer to the bad blocks section at the end of the guide.

Check which version of CB you have.

Exploitable CB versions:
1888, 1902, 1903, 1920,1921: exploitable xenon
4558: exploitable Zephyr
5761, 5766, 5770: exploitable falcon
6712, 6723: exploitable jasper

These CB versions are patched so the JTAG/SMC Hack is no longer working: (CD = 8453 for all of them)

Xenon: 1922, 1923, 1940
Zephyr: 4571, 4572, 4578, 4579
Falcon/Opus: 5771
Jasper: 6750

More info here :
Xbox 360 Kernel

If you have an exploitable CB , then you are in luck , if you dont, then for now , there is nothing you can do but find another xbox 360.

So you have a 7371 or ealier kernel , and an exploitable CB you can install the JTAG HACK Refer to the picture for your motherboard under the Required Soldering topic. Once you wired your 360 this way, you install XBR to your nand.


Flashing XBR to your nand :
  • Grab the XBR_8955 matching your board from Xbins
  • Go to your nandpro20b folder
  • nandpro orig.bin: -r16 rawkv.bin 1 1
  • nandpro orig.bin: -r16 rawconfig.bin 3de 2
  • Now that you have extracted your keyvault and config blocks from your orig.bin, inject them in the xbr_8955.bin of your motherboard version :
  • Rename the xbr_8955.bin of your board to xbr.bin to simplify things.
  • nandpro xbr.bin: -w16 rawkv.bin 1 1
  • nandpro xbr.bin: -w16 rawconfig.bin 3de 2
  • Now that you've injected your keyvault and config into xbr.bin all you need to do is flash it back to your nand.
  • nandpro lpt: -w16 xbr.bin
  • Once done , unplug lpt cable from pc.
  • Users mentionned leaving the console unplugged, and powered off for 30 seconds in order to clear the SMC from memory.
  • Turn on xbox and enjoy XBR.
  • Problems? Refer to troubleshooting and end of guide.
Troubleshooting

I've gathered this from reading other people's posts, as i have not experienced any problems at all, except read errors above 0x200 while making first dump of my nand.

Nandpro / LPT notes : You should try to keep your cable as short as possible to avoid errors.

Nandpro FATAL ERROR :
  • nandpro only works with certain USB adapters, and real LPT ports, not pci to lpt cards.
  • Check wiring, check pc BIOS settings for parallel port mode SPP (Normal) but users report nandpro working fine on most lpt settings.
  • Is port95nt.exe installed? Run port95nt.exe again
  • Try a different pc
Nandpro Flashconfig: 01198010 / reading errors :
  • Are you using the diode as explained in the cable making tutorial? The diode is a hit and miss, if you receive config 01198010 then its not needed. The diode goes with the black line towards the board , and pin 11 of lpt port connected to the other leg.
  • Shorten your wires
  • Are you using the 5 resistors? Some boards require you to solder directly, without using the resistors. This will fix reading errors above 0x200 that some experience.
  • Check solder joints, make sure they are clean and they are not touching each other.
Nandpro Error 250:
  • Error 250: This , in my experience means that the block is full of 0's, and is not an error you should be concerned about if you come across it once or twice. Of course if you keep getting Error 250, there might be an error elsewhere , or maybe you've flashed 0's all over your nand.
RRoD / Blackscreen / Error 79 :
  • Do you have an exploitable CB? People seem to only look at their dash board and see it's 7371 or lower and think they can install XBR without verifying their CB to see if JTAG hack will work.
  • Did you inject the rawkv.bin into xbr.bin ? (nandpro xbr.bin: -w16 rawkv.bin 1 1)
  • Did you inject the rawconfig.bin into xbr.bin ? (nandpro xbr.bin: -w16 rawconfig.bin 3de 2)
  • Did you have Bad Blocks in your orig.bin ? Did you follow the Bad Block Installation notes?
Restoring your original nand.
  • Make sure port95nt.exe is installed, if it's not, install it (from nandpro20b folder) you might need to reboot.
  • Plug your 360, but don't power it on.
  • Plug the lpt cable
  • Go to the nandpro20b folder and type :
  • nandpro lpt: -w16 orig.bin
  • Your nand is back to its original state.
Bad Blocks in the nand

If Degraded shows you some bad blocks, you will have to move the blocks from your xbr.bin to where they are remapped.
IPB Image

You can use this tool : Bad Block Remapper

If you want to do it manually, you have to do this:
  • Take the picture above as example.
  • It says: Note : Block 0x2CE found at 0x3F8
  • This is where the bad block 0x2CE was remapped.
  • nandpro xbr.bin: -r16 block2ce.bin 2ce 1 (Reads block 0x02CE and saves as block2ce.bin)
  • nandpro xbr.bin: -w16 block2ce.bin 3f8 1 (Write block2ce.bin to 0x3f8 where block is remapped)
  • You will have to do this for each block.
  • Here is the "formula":
  • nandpro xbr.bin -r16 blockXXX.bin XXX 1 (Where XXX is the bad block number)
  • nandpro xbr.bin -w16 blockXXX.bin YYY 1 (Where YYY is the address where block is found in degraded)
Tips on finding a xbox with an exploitable CB version
  • According to this post most boards manufactured after june 2009 should come with an unexploitable CB version so seek something earlier.
  • Obviously, must be be pre summer 09' update (kernel 7371 and lower)
  • Find your serial number inside your xbox by going to console settings , system info. This is the real serial number, if you bought the 360 second hand , nothing guarantees the information on the back being accurate.
  • There is one trick to find the manufactured date with the serial number, this site shows how. The last 5 digits of your serial number determines the date YWWFF 74902 would be 2007 week 49 (december) factory code : Mexico
  • Even if it was manufactured before june 2009, if its a second hand console , maybe it was sent to microsoft at some point and it could have been update then.
Playing content from a hdd that wasn't signed to this console

I paid for a lot of microsoft xbla games, and i believe it is my right to play on both my xbox as i please, so here i will give the gross method of playing your 360 xbla games and dlc on this XBR kernel.
  • Unscrew your hard drive case until you have just the hard drive and plug it in a SATA port of your pc.
  • Grab xplorer360 from xbins and execute it.
  • Open Hard drive
  • Go to partition 3
  • Your games are in Content\0000000000000
  • Extract the content you want.
  • Most xbla should be contained in a single file
  • To see the title of the content, hex edit one of the content file the title of the xbla or the dlc is usually at 0x412
  • Grab Yaris-Swap from xbins
  • Open content file and patch it
  • Inject back into hdd using xplorer360
  • xplorer360 is drag and drop, use it
  • xplorer360 needs a modification in order to see 120gb drives properly, follow this link.
Thanks to the authors of all the tools mentioned in this post, and to all the hard work that everyone did involving them.

Feel free to let me know if anything needs to change, if anything was out of line (rules wise) or if the topic is even in the right section smile.gif
tonybologna
Thanks for this. I also posted this over at 360iso & gave you credit for it. I took no credit but just posted it because so many people are struggling with this hack. Good job! wink.gif
Ranger72
I like to think of myself as being a little more than a newb when it comes to soldering and fallowing directions to the letter. But for the life of me I cant seem to get this to work.

I have created the cable just like the tutorial suggests. Fallowed everything perfectly. Tested every connection with an ohm meter from the pins to the motherboard and everything matches just as it should. I have tried 5 different PC's and 3 different 360 revisions and not for the life of me can I get lptpro to detect anything.

All I get is testing LPT device address:0378 ect for all 3 addresses and then (could not detect a flash controller)

Same result no matter what PC or 360 I use. When creating the cable I used the 100 ohm resisters and diode on pin 11. I even tried it without the diode just for kicks. And of course I installed the Port95nt driver.

Anyone have a clue as to what I may be doing wrong here?
thwack
QUOTE(Ranger72 @ Dec 7 2009, 10:00 PM) *

I like to think of myself as being a little more than a newb when it comes to soldering and fallowing directions to the letter. But for the life of me I cant seem to get this to work.

I have created the cable just like the tutorial suggests. Fallowed everything perfectly. Tested every connection with an ohm meter from the pins to the motherboard and everything matches just as it should. I have tried 5 different PC's and 3 different 360 revisions and not for the life of me can I get lptpro to detect anything.

All I get is testing LPT device address:0378 ect for all 3 addresses and then (could not detect a flash controller)

Same result no matter what PC or 360 I use. When creating the cable I used the 100 ohm resisters and diode on pin 11. I even tried it without the diode just for kicks.

Anyone have a clue as to what I may be doing wrong here?


Have you tried it without the resistors?
dstruktiv
QUOTE(Ranger72 @ Dec 8 2009, 10:00 AM) *

I like to think of myself as being a little more than a newb when it comes to soldering and fallowing directions to the letter. But for the life of me I cant seem to get this to work.

I have created the cable just like the tutorial suggests. Fallowed everything perfectly. Tested every connection with an ohm meter from the pins to the motherboard and everything matches just as it should. I have tried 5 different PC's and 3 different 360 revisions and not for the life of me can I get lptpro to detect anything.

All I get is testing LPT device address:0378 ect for all 3 addresses and then (could not detect a flash controller)

Same result no matter what PC or 360 I use. When creating the cable I used the 100 ohm resisters and diode on pin 11. I even tried it without the diode just for kicks.

Anyone have a clue as to what I may be doing wrong here?


I've just followed the instructions to the letter on a Falcon board and am now successfully dumping my nand pop.gif (12MB done so far without errors).

I used the 100ohm resisters and the 1N4148 diode. I've read in numerous places that you may or may not need the diode, you also may get away without using the resistors. Try shortening your cable and see if that helps (Although mine is roughly 1 metre long and works fine).

My wiring is 360 -> CAT6 Solid core network cable wires -> Female DB29 plug (With 5x resistors and 1x diode) -> Male to Male LPT cable -> Intel computer with 945G chipset -> Windows XP 32bit -> Nandpro

I can't remember exactly what parallel port mode I have set in my BIOS but will check after this dump completes.
Ranger72
QUOTE(thwack @ Dec 7 2009, 05:05 PM) *

Have you tried it without the resistors?



No I have not tried it without the resisters. I am now making another cable and using a normal LPT printer cable cut about 2 feet long. I will try it once without the resisters and see what happens.

QUOTE(dstruktiv @ Dec 7 2009, 05:09 PM) *



I used the 100ohm resisters and the 1N4148 diode. I've read in numerous places that you may or may not need the diode, you also may get away without using the resistors. Try shortening your cable and see if that helps (Although mine is roughly 1 metre long and works fine).

I can't remember exactly what parallel port mode I have set in my BIOS but will check after this dump completes.


i tried it without the diode. The first cable i made was pretty short. Next cable I am making will be shorter yet.
LiGhTfasT
Ranger72: Make sure you have the power brick plugged in and switched on at mains... that got me the first time

then i have error 0 no matter what i did so i removed the cat5 socket and wired direct with diode on db25 and all resistors... so far had 3 dumps all the same biggrin.gif
vintage_guitar
Remember to make the cable as short as possible, that is a big issue. Also try without resistors or lower ohm versions.
Ranger72
QUOTE(LiGhTfasT @ Dec 7 2009, 05:39 PM) *

Ranger72: Make sure you have the power brick plugged in and switched on at mains... that got me the first time

then i have error 0 no matter what i did so i removed the cat5 socket and wired direct with diode on db25 and all resistors... so far had 3 dumps all the same biggrin.gif



I did try with the power brick connected. When the LPT cable is connected the console will not power on (pretty sure it is not supposed to be turned on anyway) but from some tutorials I read that at some point the power may come on anyway on its own and as stated with the cable connected to the PC even if I hit the power button on the console it does not power on.

I even tried to connect a direct ground wire from the console to the PC just to see if that would be an issue.

The cable I am making now will not have any resisters just so I can see if I can get some type of confirmation that it is at least detecting the flash chip.

This cable is about 2 feet long.
Ranger72
Second cable I just made without any resisters or diode does the same thing as the other cable. Still does not detect any flash chip.

Normally with the lpt cable connected to the PC if I hit the power button on the console should it power on? When I hit the power button it does nothing.

I also tried every different variation of the lpt port from within the bios as well.
vintage_guitar
The xbox should not turn on when connected through LPT to PC, this is correct. However, it may turn on and off by itself while reading/flashing, which happens to some people and not others, and is not an issue. Try making your cable shorter. Also which settings did you use in BIOS? You should first try SPP. Then try ECP, etc. Just keep fiddling with it.
Ok I see you fiddled with BIOS settings. Hmm.. cable length is all i can think of. Mine wouldn't work unless it was about 10inches-1 foot long.
Ranger72
QUOTE(vintage_guitar @ Dec 7 2009, 06:59 PM) *

The xbox should not turn on when connected through LPT to PC, this is correct. However, it may turn on and off by itself while reading/flashing, which happens to some people and not others, and is not an issue. Try making your cable shorter. Also which settings did you use in BIOS? You should first try SPP. Then try ECP, etc. Just keep fiddling with it.



I tried every bios variable option there is on each of the 5 PC's I have tried this on. My newest cable I just built is about 2 feet long. Any shorter and I will have a problem trying to find a place to sit the console any closer to the PC.

all 3 of the different 360 versions I have tried (zenon, falcon, and jasper) all have the older pre summer dashboard installed.

To be honest I am at wits end on this. I cant think of any single variable I have missed.
popaman
my first pc it read the nand but all the dumps werent the same

the second pc did the same

the third pc read the nand and all dumps were exactly the same and everythin went ok smile.gif

so im sayin that your problem probably isnt a pc, if its doin the same thing between all five of them. I would triple check your connections on the lpt connector and make absolutely sure that you have pins 1,2,11,14,16,17,and 18.

All pc's I used had the lpt port on the motherboard. I believe pci lpt cards dont work or are ify.
rage10
QUOTE(Ranger72 @ Dec 7 2009, 11:30 PM) *

No I have not tried it without the resisters. I am now making another cable and using a normal LPT printer cable cut about 2 feet long. I will try it once without the resisters and see what happens.
i tried it without the diode. The first cable i made was pretty short. Next cable I am making will be shorter yet.


Hi Ranger72.. i had the same issue. tried a few diffent pc etc.

then i found that i soldered the parallel port incorrectly. ensure your pin numbers are correct.
Ranger72
QUOTE(rage10 @ Dec 7 2009, 11:00 PM) *

Hi Ranger72.. i had the same issue. tried a few diffent pc etc.

then i found that i soldered the parallel port incorrectly. ensure your pin numbers are correct.


On both cables I verified every connection from the adapter that connects to the PC to the motherboard contacts using an ohm meter.

I will check them again tomorrow just to make sure.

Thanks for the help guys.
dstruktiv
Whilst I managed to get Nandpro to detect the flash every dump I took came out different. I tried 6 and never got 2 identical ones. I've just finished making a custom LPT cable that's about 15CM long. It's so short that I need to put the Xbox right up to the back of the PC to connect it.

It's worked though, I've just got 2 identical valid dumps in a row biggrin.gif

I'm flashing XBR to the nand now then will solder the JTAG wires and hopefully it'll work first go tongue.gif
thwack
Just to add (only just noticed this) in this section:

Flashing XBR to your nand :

* Grab the XBR_8955 matching your board from Xbins
* Go to your nandpro20b folder
* nandpro orig.bin: -r16 rawkv.bin 1 1
* nandpro orig.bin: -r 16 rawconfig.bin 3de 2
* Now that you have extracted your keyvault and config blocks from your orig.bin, inject them in the xbr_8955.bin of your motherboard version :
* Rename the xbr_8955.bin of your board to xbr.bin to simplify things.
* nandpro xbr.bin: -w16 rawkv.bin 1 1
* nandpro xbr.bin: -w16 3de 2
* Now that you've injected your keyvault and config into xbr.bin all you need to do is flash is back to your nand.
* nandpro lpt: -w16 xbr.bin
* Once done , unplug lpt cable from pc , turn on xbox and enjoy XBR.
* Problems? Refer to troubleshooting and end of guide.

The bold bit should read:

*nandpro xbr.bin: -w16 rawconfig.bin 3de 2

Corkin' tut smile.gif
XBoxgeek
There are 2 versions of XBR on Xbins for the Xenon board whereas the other boards only have one version each. How can I tell what version of the Xenon XBRs I need?

XBR_Xenon_1921_8955_1 seems to be newer (by file date) and there is also XBR_Xenon_8955_1. Is the 1921 version only for boards with a CB of 1921?

My board has a CB of 1903 and has dash 7371

Cheers
XG
dstruktiv
I've done the JTAG and dash 8955 (XBR) booted up straight away biggrin.gif

Now I'm having another issue, no matter what I do I cannot get my DVD drive to work. The middle green light constantly flashes even if I have it plugged in. Pushing the button doesn't open it and trying to open it from the dashboard does nothing. Any ideas?
Roamin64
QUOTE(thwack @ Dec 8 2009, 09:02 AM) *

Just to add (only just noticed this) in this section:

Flashing XBR to your nand :

* Grab the XBR_8955 matching your board from Xbins
* Go to your nandpro20b folder
* nandpro orig.bin: -r16 rawkv.bin 1 1
* nandpro orig.bin: -r 16 rawconfig.bin 3de 2
* Now that you have extracted your keyvault and config blocks from your orig.bin, inject them in the xbr_8955.bin of your motherboard version :
* Rename the xbr_8955.bin of your board to xbr.bin to simplify things.
* nandpro xbr.bin: -w16 rawkv.bin 1 1
* nandpro xbr.bin: -w16 3de 2
* Now that you've injected your keyvault and config into xbr.bin all you need to do is flash is back to your nand.
* nandpro lpt: -w16 xbr.bin
* Once done , unplug lpt cable from pc , turn on xbox and enjoy XBR.
* Problems? Refer to troubleshooting and end of guide.

The bold bit should read:

*nandpro xbr.bin: -w16 rawconfig.bin 3de 2

Corkin' tut smile.gif



Ouch! This is correct, i made a mistake, can someone explain me why i can'T edit my post?

Edit: Seems we can only edit our posts within 15 minutes of its creation.. If there is a workaround, please let me know so i can fix post 1.
Aksh0le
QUOTE(dstruktiv @ Dec 8 2009, 10:06 AM) *
I've done the JTAG and dash 8955 (XBR) booted up straight away biggrin.gif

Now I'm having another issue, no matter what I do I cannot get my DVD drive to work. The middle green light constantly flashes even if I have it plugged in. Pushing the button doesn't open it and trying to open it from the dashboard does nothing. Any ideas?


boot into xell with a wired controller in the back(can also use a GH Guitar wired), and get the dvd key and make sure its the right dvd key for that drive? Either that or check your connections in the back of the drive and on the mobo.
Roamin64
An invalid dvd key shouldn't prevent you from opening/closing the drive. A bad dvd firmware would. Also make sure the power/eject cable (the one with about 6 wires, white connector) is properly connected, and that no pins were bent putting it back together after your install. I have a friend that bent a pin without noticing ,and brought me his 360 to check. He felt pretty silly when thats the first thing i made sure , that all connections were correct wink.gif

Let us know.

edit: I asked a mod to allow me to fix the rawconfig.bin mistake from original tut, should be updated later on today.
thwack
QUOTE(XBoxgeek @ Dec 8 2009, 02:16 PM) *

There are 2 versions of XBR on Xbins for the Xenon board whereas the other boards only have one version each. How can I tell what version of the Xenon XBRs I need?

XBR_Xenon_1921_8955_1 seems to be newer (by file date) and there is also XBR_Xenon_8955_1. Is the 1921 version only for boards with a CB of 1921?

My board has a CB of 1903 and has dash 7371

Cheers
XG


The one's I've tested with a CB of 1903, I've used XBR_Xenon_8955_1 smile.gif

QUOTE(Roamin64 @ Dec 8 2009, 04:37 PM) *

An invalid dvd key shouldn't prevent you from opening/closing the drive. A bad dvd firmware would. Also make sure the power/eject cable (the one with about 6 wires, white connector) is properly connected, and that no pins were bent putting it back together after your install. I have a friend that bent a pin without noticing ,and brought me his 360 to check. He felt pretty silly when thats the first thing i made sure , that all connections were correct wink.gif

Let us know.

edit: I asked a mod to allow me to fix the rawconfig.bin mistake from original tut, should be updated later on today.


Just another addition to the tut - maybe highlight in bold YOU DO NOT NEED TO DOWN/UPGRADE YOUR DASH IF IT'S IN THE EXPLOITABLE LIST

Might save a lot of thse type of posts wink.gif
Sonic-NKT
Hey,
i just followed your tutorial and i got the "Error 250" for several blocks at the end of the nandpro reading progress (arround 6) they are not in one row...
can i still proceed?
thwack
QUOTE(Sonic-NKT @ Dec 8 2009, 08:51 PM) *

Hey,
i just followed your tutorial and i got the "Error 250" for several blocks at the end of the nandpro reading progress (arround 6) they are not in one row...
can i still proceed?


Test your dumps in 360FlashTool/Degraded. If they're bad, either you're using NandPro 2 and not 2b, or it's your cable.
dstruktiv
My dvd drive isn't modified. The connections are good. The flash went perfect etc.

I did spill some solder at one point though a wee blob dropped on to the corner of the "XSB" chip which I assume is the south bridge. I cleaned it up as far as I can tell but maybe there's some there shorting something sad.gif

Box seems to work perfectly apart from that though no RRoD or anything. As soon as a plug the black power cable in a get the flashing green dvd light sad.gif
Tj1zzle
QUOTE(tonybologna @ Dec 6 2009, 12:21 AM) *

Thanks for this. I also posted this over at 360iso & gave you credit for it. I took no credit but just posted it because so many people are struggling with this hack. Good job! wink.gif


fuck xbox360iso those people should not be fed this.
that community is fucking shit up all across the scene
Sonic-NKT
QUOTE(thwack @ Dec 8 2009, 10:08 PM) *

Test your dumps in 360FlashTool/Degraded. If they're bad, either you're using NandPro 2 and not 2b, or it's your cable.

The dumps open and show 6 bad blocks which are found at other positions... so can i just move those bad block and still flash this one smile.gif

PS: im using NandPro2b and tried several cables, everytime the exact same dump
kleimo
Just asking. I have not got two same dumps yet. But all the dumps of rawkv.bin i got have compared to be the same so do i need the whole good dump of the nand?
dstruktiv
If you can't get two good dumps nthen chances are you can't flash to it consistently either. Shorten yur cables. Try different combinations of resisters/diode etc.

Seems I've now bricked my box, tried to find and remove any trace of solder I may have dropped, didn't end up removing anything but now I get 3RRod sad.gif
vintage_guitar
QUOTE(dstruktiv @ Dec 8 2009, 03:53 PM) *

If you can't get two good dumps nthen chances are you can't flash to it consistently either. Shorten yur cables. Try different combinations of resisters/diode etc.

Seems I've now bricked my box, tried to find and remove any trace of solder I may have dropped, didn't end up removing anything but now I get 3RRod sad.gif

Do you have your CPU key? it is possible to rebuild your nand backup with certain information
dstruktiv
So I could see some tiny amounts of solder just out of reach underneath the edge of the south bridge chip, I figured the box was screwed so go a bit rough with a sharp knife trying to dig it out, didn't care if I ruined it or not cause I thought it was already ruined. I didn't manage to chip and out but whatever I did my Xbox now works and it recognizes the dvd drive. Just booted into XeXLoader so happy!
Tj1zzle
QUOTE(dstruktiv @ Dec 8 2009, 06:02 PM) *

So I could see some tiny amounts of solder just out of reach underneath the edge of the south bridge chip, I figured the box was screwed so go a bit rough with a sharp knife trying to dig it out, didn't care if I ruined it or not cause I thought it was already ruined. I didn't manage to chip and out but whatever I did my Xbox now works and it recognizes the dvd drive. Just booted into XeXLoader so happy!


mayb i should scan my board more carefully for a similar situation, glad to hear it worked out for u.
i know how frustratingly testy it can be
Bon Scott
QUOTE(dstruktiv @ Dec 8 2009, 09:02 PM) *

So I could see some tiny amounts of solder just out of reach underneath the edge of the south bridge chip, I figured the box was screwed so go a bit rough with a sharp knife trying to dig it out, didn't care if I ruined it or not cause I thought it was already ruined. I didn't manage to chip and out but whatever I did my Xbox now works and it recognizes the dvd drive. Just booted into XeXLoader so happy!


Hey, good news indeed! Luck you in the end. I wish I could do this hack at my console. Unfortunately I wasn't aware about this part of scene and I updated to dash to 8955. No hope by now.
Sonic-NKT
just flashed sucessfully XBR on my xenon smile.gif
but it was a bit strange, first i got reading errors (Error 250) while dumping the original always at the same blocks (very near the end).
But since the KV is at the beginning of the nand, and it is the only really needed part of it for the hack i just extracted it and injected it in XBR (XBReboot_XENON_8955_1), after that i "fixed" the bad blocks and flashed it (Got write Error 202 on the same blocks as reading).
Result: xbox turns on, no the screen, no booting.

Then just tried out of curiosity to inject only the KV in (XBReboot_Xenon_1921_8955_1, i have 1888 CB) and just flashed it without fixing the bad blocks. Ok got the same write errors but the 360 boots up fine, had to configure it again (dident inject config) but it seems to work with no problems. Im very happy smile.gif


PS: noticed something strange, maybe its normal smile.gif after copying over Xexloader of the CD (burned the iso), i left the CD in the 360 drive and everytime i poweron the console it wont boot into the NXE.
i see the xbox logo an unusually long time and then E61 appears. With no disc or a original/backup Game-Disk it works fine.
DarkSabre_X
I did this as well. first try it wasn't finding the lpt port. then i realized i had 2 wires swapped. fixed it and everything dumped and flashed for me great. this was an old box i did the hybrid xclamp mod on. only problem is that after about 10 to 30 mins of playtime it has been freezing then black screening on me. it was giving the artifact issue but now it just freezes. graphics seem ok now. is it something i did in the xbr flashing or is is freezing because the hybrid xclamp fix is only working halfway? guess i'll just keep playing around with the screws till i get something that works. prob do the 12v fan mod too.

oh and btw does anybody know if the xexloader will let you replace nand files? i know it lets you browse them. guess i should give that a try too
dufc1983
im buying a pre hacked console. but i've been asked if i wanna keep R6T3 in or have it removed,whats the best option here
thwack
QUOTE(dufc1983 @ Dec 9 2009, 11:05 AM) *

im buying a pre hacked console. but i've been asked if i wanna keep R6T3 in or have it removed,whats the best option here


Just get rid of it - you won't need it again (and it'll stop you accidently updating your 360 and borking it)
Misterturtle
http://i.imgur.com/Fdjmi.png is a picture of what says needs to be done to exploit the jtag hack.

http://forums.xbox-scene.com/index.php?showtopic=690493 is a picture of how I have it soldered at the moment.

Am i going to have to unsolder and solder to the way the first one says? Or is the way i have it fine?
Misterturtle
Oh and to Ranger if you are still following this post. Make sure plug and play for your lpt port is enabled in device manager. I had to do that. Also try just restarting your computer with everything plugged in and hooked up if the plug and play doesnt work.
Roamin64
Misterturtle

That picture you posted shouldn't be used as a reference at all, because where it shows the diode , its utterly confusing for noobs , that might think its soldered on the board exactly where it shows, instead of clearly indicating that the light blue wire should go on one end of the diode, and the black ring of the diode on the board directly.

If you are referring to the 3 resistors in that picture, from what i understand it also works , but the http://i.imgur.com/Fdjmi.png picture is how i did it, and from what i read it is the best method to use.
Cascade
So after I do this- then I can do a JTAG hack- to get my CPU key(so I at least have it incase anything)?
dstruktiv
QUOTE(Cascade @ Dec 10 2009, 09:13 AM) *

So after I do this- then I can do a JTAG hack- to get my CPU key(so I at least have it incase anything)?


Yup, after XBR has been written to the nand using this guide, you can then boot in to Xell by plugging a wire controller in to the back usb port on the 360 and powering the console on by pushing the middle X button on the controller.

You'll then see Xell load up and it will clearly say:

CD Key: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
DVD Key: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX

Take a photo on a digi cam then you can write the key out in to a text file.

IPB Image

More pics...

IPB Image

IPB Image

IPB Image

IPB Image

IPB Image

And some Linux...

IPB Image

IPB Image
Cascade
@dstruktiv:: Coo, basically then I wire the 25 pin cable flash the XBR and then boot into xell via wired controller in the rear port. Thx for the guide Roamin64.

Haha, I dusted off a console I had in the garage w/out HDMI. I know this sucker has a exploitable CB. Guess what? I plugged it in to see if was okay and 3rlod!!!! So I did what any normal person would do. I KEPT TURNING IT ON AND OFF UNTILL I WAS SATISFIED(bout 15 times all red lights) and still no worky.

Then I come home from work today and viola!! It was on!!!!! My 2 yr old was playing with it. I was like WTF!!! COOL!

Taking this sucker to work and wire the sh*t up jester.gif Sorry for the rant.
Misterturtle
I got an xenon motherboard and set it up like this:

http://img19.imageshack.us/i/wiringforxenondiagram.jpg/

I have dumped the nand 8 times now, compared all of them with HxD (a hex editor) and none of them are even close to each other.

I have resoldered 3 times.

Yes, i do have an explotiable CB and unupdated kernal.

I noticed at the end of each dump there are alot of 00's and FF's. I know this normally means empty/bad data. So which one is it for this? Are there suppose to be FF's and 00's at the end of Xenon dumps?

Should i Possibly use usb reader? I've heard about them, but ive never seen anything about them. Do you make it or just buy it or what?

I'm completely stuck and its getting very frustrating, been working non it for a couple of days now. Someone please help x.x
FalconLTD
ok i am new to this process. I wired up the 3 jtag wires for falcon already. I have to wire up LPT/SPI later. But my questions are:
Would I need to leave the wires there for the hack to run after flashing xbreboot?
If I install a linux distribution, will that be able to flash the nand?
Can I leave out the 100ohm resistors?
TorchMach1
I'm having trouble getting this to work. I dumped my NAND successfully 3 times. No errors, all 3 matched, compatible CB, etc. I follow directions in this tutorial, flash XBR, and try to boot my 360. When I hit the power button, the center green LED flashes like normal, but no display on the screen. Then the ring of light flashes the top two red, then the bottom tow red. It just sits there alternating back and forth. Any ideas??

Edit: I may have found my problem...I was using Nandpro 20 not Nandpro 20b. I am reflashing after following the tutorial with Nandpro 20b. I will report back with my results.
Misterturtle
I was having the christmas lights also, i read around and saw somewhere it was a corrupt KV/config..I tried reflashing the original nand and now it wont turn on, so i suspect my nand dumps were corrupt and im trying to get a donor nand now to rebuild my image, keep me posted on how your x-mas light's turn out.

At least its festive tongue.gif
TorchMach1
QUOTE(TorchMach1 @ Dec 10 2009, 11:14 PM) *
Edit: I may have found my problem...I was using Nandpro 20 not Nandpro 20b. I am reflashing after following the tutorial with Nandpro 20b. I will report back with my results.


That was my problem! Using Nandpro 20, you can't correctly patch the rawkv.bin and rawconfig.bin to xbr.bin. I thought something was amiss when Nandpro 20 was trying to read the flash controller when trying to patch the bins. Got it up and running now! Thanks for the tutorial!


QUOTE(Misterturtle @ Dec 11 2009, 12:00 AM) *
I was having the christmas lights also, i read around and saw somewhere it was a corrupt KV/config..I tried reflashing the original nand and now it wont turn on, so i suspect my nand dumps were corrupt and im trying to get a donor nand now to rebuild my image, keep me posted on how your x-mas light's turn out.

At least its festive tongue.gif


I guess the dump of the original Nand wasn't good? Sorry about your troubles. Let us know how it pans out.
OliSykesIsPro
i'm getting FRAG [christmas lights]...


and sometimes E79...



i do have my 330 ohm jumpers installed, flashconfig is correct, and i'm using 100ohm resistors. I flashed XELL to get cpu key and such already, so I know it's expolitable, and I checked in all tools available, no bad blocks from orig.bin, it's all good...


reflashing now after repatching my kv and config. lets see how it goes.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2013 Invision Power Services, Inc.