XboxHacker BBS
 
*
Welcome, Guest. Please login or register.
Did you miss your activation email?
May 23, 2013, 09:04:14 PM


Login with username, password and session length


Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 »
  Print  
Author Topic: 360 Flash Dump Tool V0.1  (Read 143742 times)
robinsod
Global Moderator
Xbox Hacker
*****
Posts: 648


Perl packed my shorts during global destruction


View Profile
« Reply #240 on: March 05, 2008, 03:12:31 AM »


- How about support for devkit dumps?  (I can supply you with raw_dumps + cpu_key + ......)

Sure, I think the XEX keys may have changed (1BL key is all 0's iirc)

- The HK/Asia-EU bug is still there, did you fixed it?

No, this was just a quick fix to get secdata.bin support "out there", v89 should add several fixes though

- What do you think about integrating "Degraded.exe" into "360 Flash Dump Tool"

Maybe, it uses the same code....
Logged
MODFREAKz
Master Hacker
****
Posts: 440



View Profile
« Reply #241 on: March 05, 2008, 06:14:38 AM »

wonderful !!

I send you PM with related files and dumps.
Logged

Pitfall6667
Master Hacker
****
Posts: 107


LOOK AT ME MY POSTCOUNT IS 2082 AND MY DICK'S 1mm!


View Profile
« Reply #242 on: March 16, 2008, 05:06:18 AM »

Thanks Robinsod.


Team MODFREAKz (thanks you too): TF supports Dev dump 3215, 4548 but not the Dev dump 6683 (Huh), i can extract/mod the kv but i can't extract the FS ( Huh).
XEX1=A26C10F71FD935E98B99922CE9321572
XEX2=20B185A59D28FDC340583FBB0896BF91
1BL key : DD88AD0C9ED669E7B56794FB68563EFA

try xex1 & 2 = (others => 0)
Logged

For some people, I wish they were disabled from the fingers on. That way, they wouldn't be able to post.
zouzzz
Master Hacker
****
Posts: 326


View Profile
« Reply #243 on: March 16, 2008, 01:24:47 PM »

Ok thanks.

Theory :
- extract the FS of debug box
- create an image with FS of debug box and dump of retail box
- flash the retail boxe to pass retail in debug/retail

Do you think this theory is possible or not?
« Last Edit: March 16, 2008, 01:34:29 PM by zouzzz » Logged

Pitfall6667
Master Hacker
****
Posts: 107


LOOK AT ME MY POSTCOUNT IS 2082 AND MY DICK'S 1mm!


View Profile
« Reply #244 on: March 16, 2008, 03:55:09 PM »

sure, why not try? sounds like a brand new idea Tongue
Logged

For some people, I wish they were disabled from the fingers on. That way, they wouldn't be able to post.
MODFREAKz
Master Hacker
****
Posts: 440



View Profile
« Reply #245 on: October 05, 2008, 09:40:43 AM »

here is my bug fixed/patched versions of 360 Flash Dump Tool

What's new?

360 Flash Dump Tool v0.88b  -  DevKit Only          Download
- Open/Save 64MB dev dumps only
- Fixed the Region bug (HK/Asia <=> EU)
- Add Dev Region (DEV 0x7FFF)
- Redesigned (XP style)
- Some bugfixes


360 Flash Dump Tool v0.88b  -  Retail Only           Download
- Open/Save 16MB retail dumps only
- Fixed the Region bug (HK/Asia <=> EU and AUS)
- Redesigned (XP style)
- Some bugfixes


btw. I hope robinsod don't mind this!
Logged

schwatter
Member
**
Posts: 46


View Profile
« Reply #246 on: October 05, 2008, 09:50:02 AM »

thank you. The DevKitversion works great Cheesy
Also with the 16mbRetailmethodDumb from xdk
« Last Edit: October 05, 2008, 10:10:19 AM by schwatter » Logged
zouzzz
Master Hacker
****
Posts: 326


View Profile
« Reply #247 on: October 05, 2008, 10:47:10 AM »

Great. Thanks!
Logged

itsfakemon
Master Hacker
****
Posts: 265


View Profile
« Reply #248 on: October 05, 2008, 11:17:07 AM »

dankeschoen! Wink
Logged

excuse me, I'm French...
MoDInside
Hacker
***
Posts: 66


View Profile
« Reply #249 on: October 05, 2008, 04:31:08 PM »

here is my bug fixed/patched versions of 360 Flash Dump Tool

What's new?

360 Flash Dump Tool v0.88b  -  DevKit Only          Download
- Open/Save 64MB dev dumps only
- Fixed the Region bug (HK/Asia <=> EU)
- Add Dev Region (DEV 0x7FFF)
- Redesigned (XP style)
- Some bugfixes


360 Flash Dump Tool v0.88b  -  Retail Only           Download
- Open/Save 16MB retail dumps only
- Fixed the Region bug (HK/Asia <=> EU and AUS)
- Redesigned (XP style)
- Some bugfixes


btw. I hope robinsod don't mind this!

Thanks.
Logged
mushy408
Hacker
***
Posts: 69


View Profile
« Reply #250 on: October 06, 2008, 11:23:11 AM »

This is great news Cheesy Nice to see that you guys have been hard at work making the unimaginable... well... do-able to those who haven't got a clue. I've just read through all those pages and I've got a bit of a headache now Tongue Time for a cuppa and then start making notes on this shizzel!

Big thanx to all the contributors and creators of this tool. Microsoft - the time is nigh!
Logged
Ell3X
Master Hacker
****
Posts: 144



View Profile
« Reply #251 on: November 05, 2008, 12:44:01 PM »

Hi,

just found a "bug" in fdt0.88b.
i have a "jap" box and the regioncode is "unknown 0101".
but it should be a normal jap ?

 


 
Logged
joeylw
Newbie
*
Posts: 1


View Profile
« Reply #252 on: November 29, 2008, 03:09:04 AM »

ok sorry for this noob question... i have some xbox 360's but no orginal dvd drives and from what i understand you can use 360 flash dump tool v.88 to get this key off the motherboard. can anyone give me some kind of direction or a tutorial on how to get the dvd key?... how do you connect your 360 motherboard to ypur pc?

Thank You for your help!
Logged
Arakon
Administrator
Xbox Hacker
*****
Posts: 6925


View Profile
« Reply #253 on: November 29, 2008, 03:26:55 AM »

there is no way to get the key off the MB if you don't have a working drive with the key in the first place.
Logged

I do NOT give support by email, PM, ICQ or whatever. Anyone annoying me that way will have his balls removed. With a rusty butterknife. Slowly. And I'll enjoy doing it.
braza
Hacker
***
Posts: 92


View Profile
« Reply #254 on: December 23, 2008, 05:43:19 AM »

Problem..

I try to patch the region (JAPAN TO eua) on KV.BIN on NXe dashboard and  get  error.,  2 red ligths UP and 2 green lights DOWN ,!

tHE Flash Dump Tool  is not compatible com latest dash ??
Logged
cjack
Hacker
***
Posts: 88



View Profile
« Reply #255 on: January 24, 2009, 11:16:25 AM »

Hi! Just dumped the NAND of a Jasper motherboard. Seems that the data structure is changed compared to old version of flash.
Need to manage the new size of NAND too. FlashTool update required  Grin See you guys
Logged
Ell3X
Master Hacker
****
Posts: 144



View Profile
« Reply #256 on: January 24, 2009, 04:02:02 PM »

Hi! Just dumped the NAND of a Jasper motherboard. Seems that the data structure is changed compared to old version of flash.
Need to manage the new size of NAND too. FlashTool update required  Grin See you guys

useless !

jasper has no vulnerable cb, this meens no downgrading, no cpu-key and so on ...
Logged
Redline99
Global Moderator
Xbox Hacker
*****
Posts: 774


View Profile
« Reply #257 on: March 03, 2009, 03:30:07 PM »

does anyone have the sources to .88b or anything newer than .87? If you do please pm me. thanks
« Last Edit: March 03, 2009, 03:32:04 PM by Redline99 » Logged

Where's Waldo
Shaun
Xbox Hacker
*****
Posts: 505



View Profile
« Reply #258 on: March 04, 2009, 10:17:22 AM »

Im assuming via your own programmer cjack ? (guessing infectus support for new flash id is a way off lol)
Not seen any details about it as obviously is has to be in a different format 1 way or another.
Logged
arnezami
Master Hacker
****
Posts: 214


View Profile
« Reply #259 on: August 16, 2009, 07:18:08 AM »

Bugfix info regarding CD decryption. If you have a 1920+ CD version it doesn't decrypt CD properly. This was because the "DerivedKey" was only calculated in CE (which was decrypted properly) but should have been done in CD already.

Since 0.88b is already out I will post my changes: (only 0.88a source is released)

Change part of FlashFile.ccp into this (CD decrypt now gets the cpu key, not CE decrypt):
Code:
m_CDSection.Initialise(CString("CD"),Base,&m_BlockDriver,m_CBSection.GetKey(),m_CBSection.GetVersion() >= 1920 ? m_pFuse : NULL);
Base += m_CDSection.GetLength();

m_CESection.Initialise(CString("CE"),Base,&m_BlockDriver,m_CDSection.GetKey());
This means removing this line in CXSection.h:
Code:
BOOL Initialise(CString& rName, unsigned int BaseAddress, CBlockDriver * pBlockDriver, unsigned char * pKey, unsigned char * pCPUKey);
and changing CD Initialise into this line:
Code:
BOOL Initialise(CString& rName, unsigned int BaseAddress, CBlockDriver * pBlockDriver, unsigned char * pKey, unsigned char * pCPUKey);
also remove CCESection::Initialise from CXSection.cpp.

Then change CCDSection::Initialise in CXSection.cpp into this:
Code:
BOOL CCDSection::Initialise(CString& rName, unsigned int BaseAddress, CBlockDriver * pBlockDriver, unsigned char * pKey, unsigned char * pCPUKey)
{
BYTE* pData;

m_Name = rName;
m_DecryptedData = NULL;

m_StartBlock = BaseAddress/0x4000;

if(!ReadSection(m_StartBlock,BaseAddress-(m_StartBlock * 0x4000),0x20,&pData,pBlockDriver))
{
return FALSE;
}

if(pKey)
{
Decrypt(pKey,pData,pCPUKey);
}
delete pData;
return TRUE;
}
and add CCDSection::Decrypt to CXSection.cpp:
Code:
BOOL CCDSection::Decrypt(unsigned char *pK0, unsigned char * pData, unsigned char * pCPUKey)
{
unsigned char Digest[SHA_DIGEST_LENGTH];

RC4_KEY RC4Key;

if(*pK0 == 0x00)
{
return FALSE;
}

m_DecryptedData = new unsigned char[m_Length];

CalculateHMACSHA(pK0,&pData[0x10],0x10,Digest);

if (pCPUKey) {
CalculateHMACSHA(pCPUKey,Digest,0x10,Digest);
}

memcpy(m_Hdr,pData,0x10);
memcpy(m_Key,Digest,0x10);


//first 16 bytes of Digest is the key
RC4_set_key(&RC4Key, 0x10, Digest);
RC4(&RC4Key,
m_Length - 0x10,
&pData[0x20],
m_DecryptedData);

return TRUE;
}
and of course change CXSection.h accordingly:
Code:
virtual BOOL Initialise(CString& rName,unsigned int BaseAddress, CBlockDriver * pBlockDriver, unsigned char * pKey, unsigned char * pCPUKey);
virtual BOOL Decrypt(unsigned char *pK0, unsigned char * pData, unsigned char * pCPUKey);

The above was discussed here.

Regards,

arnezami
« Last Edit: August 16, 2009, 04:32:42 PM by arnezami » Logged
Pages: « 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC

Valid XHTML 1.0! Valid CSS! Dilber MC Theme by HarzeM