XboxHacker BBS
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 23, 2013, 01:51:05 PM


Login with username, password and session length


Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 »
  Print  
Author Topic: xb360 jtag exploit - Discussion  (Read 86041 times)
skygames
Member
**
Posts: 12


View Profile
« Reply #320 on: August 29, 2009, 09:52:12 AM »

Hello staff where I find flash_hack for falcon, thanks for the help. Grin
Logged
parasven
Master Hacker
****
Posts: 182


View Profile
« Reply #321 on: August 29, 2009, 10:22:19 AM »

not yet released
Logged
Zakwarrior
Member
**
Posts: 27


View Profile
« Reply #322 on: August 30, 2009, 10:58:30 PM »

Hi everyone (sorry for my english I'm french)

I'm new on this forum but I wanted to share something probably intresting that I found out after messing around with my xenon and my jasper motherboard.

The actuall problem to run the hack on other motherboards then xenon (zephyr, falcon, jasper) is that we don't have the J1F1 to connect the resistors to J2D2.

So I looked for alternative points and there is many and here is where they go (sorry I don't have any better looking picture, this is from the french forum http://gueux-forum.net)



So I found out that J1F1.3 is connected to the point FT1V2 that you can find behind the motherboard and can also be found on jasper motherboard.

I also found out that J1F1.5 is connected to the point R2B19 that you can ALSO find on the jasper motherboard.

And the last point J1F1.4 is connected to the point R2B18, this one isn't on jasper motherboard but I'm sure there is another alternative point, with a little help it could be found quickly ... 

 
« Last Edit: August 30, 2009, 11:01:17 PM by Zakwarrior » Logged
slasherking823
Master Hacker
****
Posts: 222


View Profile
« Reply #323 on: August 31, 2009, 12:12:18 AM »

and we need smc for those machines
Logged

If that gamerscore or tenth prestige is so important to you that you absolutely need a pointless number - get it legit
If you are just trying to show off - throw a party(real party, not nerd party, some of you would miss that point)
If you like to be a fagot and go by "Jtags are for Mw2" - GTFO
l0w0utput
Newbie
*
Posts: 4


View Profile
« Reply #324 on: August 31, 2009, 03:07:35 PM »

Looking at how the three tracks ( J1F1 3-5 ) enter the southbridge on  a Xenon board, I noticed that this area seems to be quite identical on Jasper boards. Presuming these 3 tracks on a Jasper board really are  J1F1 3-5 (sorry but I'm not capable of providing proof that this is actually the case) this would lead to following soldering points for Jasper:

J1F1 -3-  < a solderpad close to FT2R2, backside of mainboard, close to one of the 'holes' of the southbridge >
              or  < solderpad at R2B16, frontside, but different one as for Xenon! >
J1F1 -4-  < resistor under the -V- of R4V3, backside, close to the small ADP1823 chip >
J1F1 -5-  < solderpad named FT4P4, on the backside of the HANA chip >

Maybe this helps..

Logged
l_oliveira
Xbox Hacker
*****
Posts: 1342


View Profile
« Reply #325 on: August 31, 2009, 07:56:12 PM »

We still need the SMC (System Management Controller) firmware with the patch to send the JTAG commands through the GPIO for this to work. Because Jasper SMC program is different from Xenon, flashing a Xenon image will cause serious problems.

Figuring out where the wires must go is nice, but without the hacked SMC program the hack just won't happen on Jasper or Falcon boards...
Logged


It's a Rough World
Zakwarrior
Member
**
Posts: 27


View Profile
« Reply #326 on: September 02, 2009, 11:41:56 PM »

Anyway hope this helped
« Last Edit: September 02, 2009, 11:43:29 PM by Zakwarrior » Logged
bucksie
Newbie
*
Posts: 5


View Profile
« Reply #327 on: September 03, 2009, 05:50:41 AM »

thers not enough gpio's on the smc anyways. they had to use one that controls one of the led's on the rol but this is cumbersome hence the reason why they are looking for better gpio's to steal from.
Logged
Badger101
Member
**
Posts: 36


View Profile
« Reply #328 on: September 12, 2009, 05:42:05 AM »


I tried that image on a keyless board (no dvdrom or anything) with the resistors in place and all I get is constantly flashing center light, no RROD or anything at all. if I unplug the av cable, it responds properly with 4 reds.

Hey Arakon.

How did you manage to sort this problem out?

I have the same issue with one of my boards.

CB 1921
CD 1921
CE 1888
CF(0) 7371
CF(1) 7363

Thanks.
Logged
Arakon
Administrator
Xbox Hacker
*****
Posts: 6925


View Profile
« Reply #329 on: September 12, 2009, 05:51:40 AM »

The problem was simply that I didn't have a VGA cable.. the center flashing came from the lack of dvd rom.
Logged

I do NOT give support by email, PM, ICQ or whatever. Anyone annoying me that way will have his balls removed. With a rusty butterknife. Slowly. And I'll enjoy doing it.
Badger101
Member
**
Posts: 36


View Profile
« Reply #330 on: September 12, 2009, 06:45:16 AM »

Thanks.

I had taken out the dvd rom so I had somewhere to sit my programmer.

Stil doesn't work though. The power switch is very unresponsive, and when turned on it will sit there for around 15 secs and then give a 3red rings.

Flashing back to the dash to see if everything is O.K.

Dash works fine. The unresponsive power switch was me being a girl and not pressing it hard enough  Grin.

But it still won't boot into Xell  Sad

This is my second box, the first went well after building a buffer for the programmer (and will be to play with linux etc.)
This one is my games machine which I only wanted the cpu key before updating to the new dash.

Has anyone got any ideas?
« Last Edit: September 12, 2009, 07:56:15 AM by Badger101 » Logged
Badger101
Member
**
Posts: 36


View Profile
« Reply #331 on: September 12, 2009, 09:41:37 AM »

The secondary error code is 0022.

Quote from tmbinc:

'The box switched on, so your SMC code works, but the CPU stopped booting at some point, but without signaling an errorcode (like 010x broken memory etc.)  to the SMC. This is likely a corrupted image, or an image which doesn't work on your hardware. For example, trying to use the hack on an updated box would cause this error, but just flashing half of an image, or a broken image, will do the same.'

I've flashed the image to the nand, read it back and fc'd it. O.K. (used the same image on my other box which works fine).
I've flashed the dash back, and it works fine.
Buzzed all the connections out, there all good.

Could it be the hardware revision? (it's a refurb from around a year ago with different heatsinks)

« Last Edit: September 12, 2009, 09:56:47 AM by Badger101 » Logged
gadget78
Master Hacker
****
Posts: 104


View Profile
« Reply #332 on: September 12, 2009, 09:52:21 AM »

<-- snip -->

CB 1921
CD 1921
CE 1888
CF(0) 7371
CF(1) 7363

Thanks.

flash back you original again, so thats its booting fine ...
then get the xenon_1921_hack.rar file from the 'usual places'
and write that (DO NOT erase before hand) .... see if that works Smiley

(you have to have a suitable CB version to match what the Fuses are at )

Mick ..
Logged
Badger101
Member
**
Posts: 36


View Profile
« Reply #333 on: September 12, 2009, 10:01:24 AM »

Thanks gadget78!

Just figured that out when you posted, but why no erase?

Personally I don't see a point in erasing when you are programming the whole nand anyway.

Pls tell me if I'm wrong?
Logged
l_oliveira
Xbox Hacker
*****
Posts: 1342


View Profile
« Reply #334 on: September 12, 2009, 10:33:02 AM »

He mean that the new image is only 1.3mb (80 blocks) SO DON'T ERASE YOUR FLASH.... Smiley


backup only the beginning of your flash with this command:

nandpro lpt: -r16 backup.bin 0 55  (backing up a few blocks more as safety measure)

then flash 1921 hack image:

nandpro lpt: -w16 xenon_1921hack.bin

This does the job.


To restore later on:

nandpro lpt: -w16 backup.bin   (this will overwrite the nand with the 55 blocks you saved earlier replacing  the 0x50 from hack plus refreshing 5)
Logged


It's a Rough World
duggyuk
Master Hacker
****
Posts: 271


View Profile
« Reply #335 on: September 19, 2009, 08:39:27 AM »

Thanks gadget78!

Just figured that out when you posted, but why no erase?

Personally I don't see a point in erasing when you are programming the whole nand anyway.

Pls tell me if I'm wrong?

If you erase, you lose your config area iirc. you program around 1.3MB (of a total of 17MB) available space.
Logged
Xexman
Member
**
Posts: 18


View Profile
« Reply #336 on: September 19, 2009, 07:05:14 PM »

Hi,
I am wondering if you can possibly modify an Xex file to decrypt an encrypted audio file on a game?  Or is this something that would take 1 or more clever programs to do after this hack is well distributed?
Thanks
Logged
B1N4RY
Xbox Hacker
*****
Posts: 790


View Profile
« Reply #337 on: September 20, 2009, 11:45:11 AM »

modifying a xex will break the signature, making the xbox rejecting to run
Logged
slasherking823
Master Hacker
****
Posts: 222


View Profile
« Reply #338 on: September 20, 2009, 02:54:43 PM »

Hi,
I am wondering if you can possibly modify an Xex file to decrypt an encrypted audio file on a game?  Or is this something that would take 1 or more clever programs to do after this hack is well distributed?
Thanks

if you want to make a rebooter to run a custom xex then go ahead
Logged

If that gamerscore or tenth prestige is so important to you that you absolutely need a pointless number - get it legit
If you are just trying to show off - throw a party(real party, not nerd party, some of you would miss that point)
If you like to be a fagot and go by "Jtags are for Mw2" - GTFO
CaNNa
Newbie
*
Posts: 8


View Profile
« Reply #339 on: September 22, 2009, 05:18:14 PM »

I imagine the file "$SystemUpdate_Fall08_7371" will hold relevance for some users  Wink
  Yes just dont download the fall 08 from here its actually 8498 and it fuked me up bigg
Logged
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM