XboxHacker BBS
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 19, 2013, 05:42:05 AM


Login with username, password and session length


Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 »
  Print  
Author Topic: TS-H943 firmware dump by software  (Read 121240 times)
k0mpresd
Xbox Hacker
*****
Posts: 608


View Profile
« Reply #40 on: April 18, 2006, 07:14:26 PM »

i have 2 sata ports on my mb and the ide > sata adapter i got @ a local computer store..not sure what brand

just tried a game..works fine..so it looks like it flashed back ok
« Last Edit: April 18, 2006, 07:25:12 PM by k0mpresd » Logged
BlueCop
Master Hacker
****
Posts: 316


"When the going gets weird, the weird turn pro."


View Profile
« Reply #41 on: April 18, 2006, 07:55:24 PM »

Woo I got a method that works with reading and writing from a ms25 drive without any ide>sata adapter or swaping with sata dvd-roms i don't have.

what you need is a sata harddrive and your Toshiba-Samsung Drive

since the via chipset i have always chokes on ms25 you have to hook up a sata harddrive to the sata controller. i used my xbox 360 harddrive but i tested with another sata harddrive and the method worked with it as well.

you start the computer to dos using bootdisk or other method(i used a usb stick to boot into dos)

you will of course need mtkflash 1.83c on the booted media

start your 360 with just the power cable connected to the dvd drive.

disconnect the sata cable from your harddrive and plug it into your dvd drive

i then ran mtkflash r backup.bin to backup a copy of the firmware
or do mtkflash w firmware.bin to write a firmware

after you backup/write the firmware you can't backup/write a firmware again untill you redo the whole process.

so if you do a backup of your firmware and then want to write a new firmware to the drive you would have to shutdown the computer and the 360 and start the process over.

I tested this multiply times and it worked fine each time.

Peace
BlueCop

Edit: i forgot to mention. i didn't need a second dvd-rom connected for a selection menu. it simply detected the ms25 drive and would do whatever operation i selected on it.
« Last Edit: April 18, 2006, 08:06:59 PM by BlueCop » Logged
k0mpresd
Xbox Hacker
*****
Posts: 608


View Profile
« Reply #42 on: April 18, 2006, 08:28:22 PM »

ha...awesome..that makes sense though i guess..youre still hotswapping in a way..
Logged
Lash444
Newbie
*
Posts: 4


View Profile
« Reply #43 on: April 19, 2006, 12:29:58 AM »

Heh, I tore apart my 360 hard drive casing in order to hook this thing up figuring it wouldnt auto detect the dvd drive. 

I can report that the Promise Sata controller on the P4C800E-Deluxe, does not properly detect the hard drive with mktflash, but does indeed detect the TS-H943  H/W:004  F/W: ms25 properly.
I have not put the thing together yet and ran it, but it did dump the bin and the process to write it back appears to have updated it correctly.  Thanks for the help guys.
Logged
ChaosBoy
Member
**
Posts: 32


View Profile
« Reply #44 on: April 19, 2006, 02:14:05 AM »

@BlueCop

i have tried your way and works fine... Wink
i have here one asus mb with sata an ide port...
i connected one excelstor 80 gb hd on port 1 and hotswap with my sammy, started mktflash and i have succesfully dumped my fw... Shocked
i shutdown and restart my pc and my xbox360 and tried to write the firmware to the sammy... it workz...

good news...

so, now we can try to hack this firmware.. Grin

Greets
ChaosBoy
« Last Edit: April 19, 2006, 02:19:21 AM by ChaosBoy » Logged

Greets
ChaosBoy

P.S: to be or not to be... a hacker!!!
nokaktsawa
Hacker
***
Posts: 60


View Profile
« Reply #45 on: April 19, 2006, 03:03:59 AM »

so, now we can try to hack this firmware.. Grin

Right. But first: one simple question. If we experiment modifying the firmware, and flash a badly modified one, can we ALWAYS reflash the original firmware, no matter what the bad firmware is?
Logged
ChaosBoy
Member
**
Posts: 32


View Profile
« Reply #46 on: April 19, 2006, 03:12:40 AM »

i think so...
Bluecop / Geremia??? what do u mean??

Greets
ChaosBoy

Logged

Greets
ChaosBoy

P.S: to be or not to be... a hacker!!!
MacDennis
Xbox Hacker
*****
Posts: 614


View Profile
« Reply #47 on: April 19, 2006, 03:21:27 AM »

Right. But first: one simple question. If we experiment modifying the firmware, and flash a badly modified one, can we ALWAYS reflash the original firmware, no matter what the bad firmware is?
This is definately NOT the case for the LG drives. I'm not sure but the TS could also have a recovery mode.

Great work guys!!  Smiley
Logged
BlueCop
Master Hacker
****
Posts: 316


"When the going gets weird, the weird turn pro."


View Profile
« Reply #48 on: April 19, 2006, 05:54:55 AM »

since i have a socketed flash on my drive i can easily recover from bad flashes.

I will try to do some testing with bad flashes with mtkflash and report back with success failures.
Logged
ChaosBoy
Member
**
Posts: 32


View Profile
« Reply #49 on: April 19, 2006, 06:04:06 AM »

thnxx BlueCop

Greets
ChaosBoy
Logged

Greets
ChaosBoy

P.S: to be or not to be... a hacker!!!
k0mpresd
Xbox Hacker
*****
Posts: 608


View Profile
« Reply #50 on: April 19, 2006, 06:19:38 AM »

yes..thanx bluecop for doing some more testing ...soo..whats next?  Smiley
Logged
ChaosBoy
Member
**
Posts: 32


View Profile
« Reply #51 on: April 19, 2006, 06:28:25 AM »

@k0mpresd

take a look at http://www.xboxhacker.net/forums/index.php?topic=359.60

Greets
ChaosBoy
Logged

Greets
ChaosBoy

P.S: to be or not to be... a hacker!!!
uberfry
Xbox Hacker
*****
Posts: 862



View Profile
« Reply #52 on: April 19, 2006, 06:52:47 AM »

hi...i know this might have nothing to do with this thread, but i couldn't think of any better thread to post in...
is it possible to hack the fw without having to put it in the xbox360? maybe an rs232 port available?
i don't wanna give up the warranty...
Logged
MacDennis
Xbox Hacker
*****
Posts: 614


View Profile
« Reply #53 on: April 19, 2006, 07:12:30 AM »

is it possible to hack the fw without having to put it in the xbox360? maybe an rs232 port available?
i don't wanna give up the warranty...
Did you spot a rs232 port on your console? If you want to dump / flash the TS-H943 or LG firmware by software or hardware then you WILL have to open the console. Basically, if you want to do any x360 hacking at all then you WILL have to give up your warranty. That's the price you will have to pay for being a hacker.  Grin
Logged
patx
Hacker
***
Posts: 68


View Profile
« Reply #54 on: April 19, 2006, 08:10:36 AM »

On another note. i have been trying the tiros method of grounding the eject pin on startup to get the drive recognized by windows.

i have tried this several times and my via sata controller always chokes on ms25 firmware no matter what i try. i was abled to get the drive recognized by my my via software in windows using this method to startup the drive and then pluging the sata cable in while windows was running. i couldn't get the drive to populate though.

I tried mtkflash win with ms07 and ms25 running on my drive and it didn't find my drive as a compatible target.
Just an idea, but did you consider my method to get the drive detected and working in Windows? I did try this method succesfully with the original LG Windows software flasher for the 8163B drive. Perhaps the same method works with mtkflash. I don't have a Samsung drive so I can't try. The nice thing is, the inquiry command to detect the drive can be faked and you can specify whatever inquiry data you like. The inquiry command seems to be the root cause for a drive not being detected by Linux / Windows ..

http://www.xboxhacker.net/index.php?option=com_smf&Itemid=33&topic=663.0

Has anyone tried this yet ?!? I have ordered the usb.brando adapter and a sammy drive... I will test it as soon as I receive those.
Logged
uberfry
Xbox Hacker
*****
Posts: 862



View Profile
« Reply #55 on: April 19, 2006, 09:07:51 AM »

is it possible to hack the fw without having to put it in the xbox360? maybe an rs232 port available?
i don't wanna give up the warranty...
Did you spot a rs232 port on your console? If you want to dump / flash the TS-H943 or LG firmware by software or hardware then you WILL have to open the console. Basically, if you want to do any x360 hacking at all then you WILL have to give up your warranty. That's the price you will have to pay for being a hacker.  Grin

heard about replacement drives? Smiley
because normally u have 2 pads marking "TX" and "RX"
think about it before making fun of me Cheesy
Logged
MacDennis
Xbox Hacker
*****
Posts: 614


View Profile
« Reply #56 on: April 19, 2006, 09:24:36 AM »

heard about replacement drives? Smiley
Yes.

because normally u have 2 pads marking "TX" and "RX"
Where are these pads located? Let's imagine you are able to flash the replacement drive with a hacked firmware. How are you going to connect it to your console?

think about it before making fun of me Cheesy
Dude, I'm not making fun out of you. I'm only stating the obvious.

To be fair, yes it's possible to hack the firmware without a console or any other hardware. A disassembler or a tool like IDA is enough. Firmware is just software. But how are you going to test a patches without the drive being connected to an actual console? Yes you can send commands to the drive by using plscsi for example but commands related to the authentication of x360 discs need to be encrypted first by using AES. I assume that you would like to test your final patches on an actual console in the end right? If people are too scared to brick the drive/console or if they don't want to void their warrenty then they should find another hobby IMHO.
« Last Edit: April 19, 2006, 09:41:35 AM by MacDennis » Logged
BlueCop
Master Hacker
****
Posts: 316


"When the going gets weird, the weird turn pro."


View Profile
« Reply #57 on: April 19, 2006, 11:04:08 AM »

Where are these pads located? Let's imagine you are able to flash the replacement drive with a hacked firmware. How are you going to connect it to your console?
there are four header holes next to the ram on the TS mainboard. underneath the 2 center ones are labled RX, TX. one of the side ones is ground. the other side i tested with a multimeter and didn't get any voltage with it was on. i didn't look ot hard at it so i am not sure what that pin is.

I did wire up a max232 chip to the rx,tx and gnd lines. I tried some code to output the security sector to the SBUF(serial output). I had some luck with it outputing information on the serial port but the main problem i am having is geting an accurate baud rate. i discussed it more in another thread. i haven't found a solution yet. i was trying to get a 9600bps baud within a + or - 2-3%.

I soldered a 4 pin header to the spot and cut a small square hole in the bottom of my drive casing. i can plug in the serial port cable easily now.

I thought it might be usefull to embeded some serial output cues that might be able to help understand the flow of how things are working in the drive but i was using the Security Sector output as a test case that would be usefull to be able to dump several of them without having the dump the flash each time to extract it.
« Last Edit: April 19, 2006, 11:09:49 AM by BlueCop » Logged
BlueCop
Master Hacker
****
Posts: 316


"When the going gets weird, the weird turn pro."


View Profile
« Reply #58 on: April 19, 2006, 11:33:26 AM »

OK i used MTKFlash to Erase my flash chip to test if a currupted flash on a drive would still be able to be flashed again.

I could not get MTKFlash to work with the drive anymore using the method with the harddrive. I don't have the tools to try the other methods of swaping with another dvd drive. That might still work. the problem i was having was that mtkflash wouldn't detect my drive after i currupted the flash.

So be carefull and don't flash anything bad to your chip because you might not be able to recover by software. There is always the option of desoldering though.
Logged
Zenofex
Member
**
Posts: 18


View Profile WWW
« Reply #59 on: April 20, 2006, 04:55:19 PM »

I can also confirm that a bad flash WILL ruin your drive, I toasted my first TS today and am having a friend of mine remove the epoxy and chip from the board so that i can wire a socket to the back of my drive.  Luckily if this fails i have already aquired my key and dumped the firmware, Ill probably order a replacement just to have 2 drives. I knew my drive was toasted when i was using mktflash and it got to "UPDATING BANK 12" (I knew it was gone after it didn't stop at bank #4 but i was trying to be hopefull). lol, well as someone on this board has said "Dont try to hack the 360 if your afraid you might ruin it".  Now i just need to wait till i either get the socket set up or my replacement in.
Logged

---------------------------------------------------------------------------
Check out my website http://www.gtvhacker.com/
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM