xboxscene.org forums

Author Topic: How To Mod Liteon/benq Console To Boot Ap 2.5 And Work On Live Indefin  (Read 66 times)

danthaman673

  • Archived User
  • Sr. Member
  • *
  • Posts: 441

I have devised a method for making a BENQ/LITEON Box SAFE FOR ONLINE (AND PASS AP2.5 BACKUP GAMES!!)

One small Catch: It has to be a JTAG-able console or existing JTAG (with virgin KeyVault) ie; NEVER BEEN ONLINE AFTER 8955 Dash) You will also need a SAMSUNG

drive (You can buy these online very cheaply)

*** DISCLAIMER***: This has not been tested yet, but if anyone can give me a GOOD reason why this wouldn't work then I'd like to hear

it! - And the usual 'I wont except any responsibility for your poor soldering efforts because you wouldn't shell-out the 80$ to get a pro to do it but now you

want them to fix it etc.. etc .. (IMG:style_emoticons/default/rolleyes.gif)

OK:

READ ALL STEPS BEFORE BEGINNING!!

STEP ONE: on virgin console (If ur using an existing JTAG then read the other steps below) - STEP ONE is: add NAND dumping/programing method. There are

several tuts/devices to do this but remember:
 You don't need to at any time remove R6T3 (If you have then you will need to replace it - If u lost it <very easy 2do> then you will need to replace it with

<I think is> a 10k resistor - You may want to check that value but I'm pretty sure it will work. If you leave it off then you wont be able to update later)
You can use a more noob-proof (and slightly faster) solution like nand-x,cygnos revf, and there's another one (which name) escapes me. These are all basically

SPI flashers (you can make ur own from scratch - but you have to have the time and expertise) At any-rate if you choose the non-LPT route then you can re-cycle

the kit afterwards (on another JTAG) Some of these kits have a solder-less JTAG component, some don't. At any rate if you don't feel confident just approach a

pro and ask them to do it (either just the JTAG or the whole thing) After the JTAGing is done then the rest is relatively easy) After you have obtained the

CPU-key (see below) then you will need to remove the JTAG wiring so be prepared for that (The removal should be relatively easy)

Once thats done -
STEP TWO:
 Dump your NAND then: Flash Xell or Xellous or build/flash XBR(There are many tuts on this<and some apps that do it all 4u - just be careful as some of these

sometimes have bugs/viruses etc..> - I will paste some links at the bottom later
 JUST MAKE SURE YOU HAVE A GOOD DUMP FIRST.
 Get Your CPU-key by booting with the eject-button. Take a photo of the 'Fuse set Key' There are dozens of tutorials on doing this also but basically you will

need the two lines that have the CPU key as most/all flashing tut's have all this info I won't bother going into more detail here (but if u have trouble with

this step and already searched how to fix it then I will support issues/queries with this here)

STEP THREE:
Ok so you have your CPU key and at least one good nand dump then you can open your NAND in 360 Flash Tool (MODFREAKZ tool make sure you use the latest version

- currently 0.97) There are plenty of tuts on this also (If you need one ) But it's pretty easy. Just make sure you have entered you CPU key or it won't open

properly. Now: Note down the DVD-ROM key from your BenQ or Liteon (copy/paste it) There's a button for saving this to a txt/info file (from memory I thinks

'save KV info' does it) NOW:Press patch, check the box for patch KV -  Change the OSIG to your model of SAMSUNG. Check 'Rebuild' Add Cpu-Key from the info you

saved previously,You will then be prompted to Save a new copy of the NAND, give it a new name, load the new file you made and check that the new nand has

Samsung Ms28/Ms25 in the OSIG window.

STEP FOUR: Flash the SAMSUNG with the key from your BENQ/LITEON (use Jungle Flasher - 7 billion tuts on this) When you do: Make sure the key matches

what's in ur KVinfo.txt (U made in previous step) I would recommend using the latest version of samsung LT. Other than the key, no spoofing need be involved so

just basically flash it as would normally as if the key you had extracted from ur original FW was the one you pasted. BTW You might want to backup the original

FW before you write LT (Just a reminder) When you've done this confirm the key is correct (before and after flashing if u can) then install the sammy in ur

box.

STEP FIVE: Boot and make sure it runs a backup ( use an old one ) Then: Remove the JTAG wiring - U can leave the NAND wiring if u like. JTAG wiring is anything connected to J2D2

FINALLY:  Go online and update to the new dash.
Note: Ideally do the update using original(Samsung) FW (obviously with ur original LITEON/BenQ key) first and then flash LT post update (There is no definitive reason

to do this so far, but I would recommend it is there are things to indicate that there is a slim-possibility that there may be a reason to do this - Pls dont

ask me to elaborate on this) If you don't and just update with LT then more than likely it won't matter, but I've had some conflicting info about this so you

may want to play on the ultra safe side. Just make sure you're confident with changing drive key without changing FW -as most tuts don't go into or describe

this.

You should now have a box that will run ALL backups (including AP 2.5) Online for the rest of time!!! (We hope, or at least untill they come-up with something else ..)

Let me know how it goes!

A JTAG tut (U can prolly find better by googling but this looks OK <at a glance>) http://forums.xbox-scene.com/index.php?showtopic=690493
Another JTAG Tut HERE (keep in mind I haven't checked these out but they should be OK)

Brgds/Dan

This post has been edited by danthaman673: Nov 10 2010, 10:28 AM
Logged

syntaxerror329

  • Archived User
  • Hero Member
  • *
  • Posts: 1138
How To Mod Liteon/benq Console To Boot Ap 2.5 And Work On Live Indefin
« Reply #1 on: November 10, 2010, 02:49:00 AM »

QUOTE(danthaman673 @ Nov 10 2010, 04:09 AM) *

*** DISCLAIMER***: This has not been tested yet, but if anyone can give me a GOOD reason why this wouldn't work then I'd like to hear


KV hashing.

But please try and let us know how it works.  (IMG:style_emoticons/default/biggrin.gif)
Logged

danthaman673

  • Archived User
  • Sr. Member
  • *
  • Posts: 441
How To Mod Liteon/benq Console To Boot Ap 2.5 And Work On Live Indefin
« Reply #2 on: November 10, 2010, 03:23:00 AM »

QUOTE(syntaxerror329 @ Nov 10 2010, 07:19 PM) *

KV hashing.

But please try and let us know how it works.  (IMG:style_emoticons/default/biggrin.gif)



Yeah that is/was one point I was a bit unsure of, But I'm pretty sure 0.97 should cover that ...

I reckon that it would be apparent before blowing the efuses if there was any trouble allthough it may pay to check the xval after re-flashing the modded nand...

M$ Must do it somehow (very similar) when they repair/upgrade drives

I will be trying it myself, when I get a suitable console (If anyone out there wants it done free - as long as I can do a proof-of-concept vid with it)

Brgds and thanx 4 the feedback, Dan

This post has been edited by danthaman673: Nov 10 2010, 11:26 AM
Logged

syntaxerror329

  • Archived User
  • Hero Member
  • *
  • Posts: 1138
How To Mod Liteon/benq Console To Boot Ap 2.5 And Work On Live Indefin
« Reply #3 on: November 10, 2010, 04:06:00 AM »

QUOTE(danthaman673 @ Nov 10 2010, 05:23 AM) *

Yeah that is/was one point I was a bit unsure of, But I'm pretty sure 0.97 should cover that ...

I reckon that it would be apparent before blowing the efuses if there was any trouble allthough it may pay to check the xval after re-flashing the modded nand...

M$ Must do it somehow (very similar) when they repair/upgrade drives

I will be trying it myself, when I get a suitable console (If anyone out there wants it done free - as long as I can do a proof-of-concept vid with it)

Brgds and thanx 4 the feedback, Dan


Nope .97 wont help.
I wish i understood how KV Hashing worked. You would think there would be something simple that can be done to correct the hash and make your idea work but i am almost certain if you do what you are suggesting you will kill a xbox. (and a jtag one at that)

Reading this thread might give you some insight http://www.se7ensins.com/forums/topic/3163...ved/page__st__0

Still i don't get how KV Hashing works.
Logged

shawnmos

  • Archived User
  • Newbie
  • *
  • Posts: 9
How To Mod Liteon/benq Console To Boot Ap 2.5 And Work On Live Indefin
« Reply #4 on: November 10, 2010, 10:35:00 PM »

Actually if you find an xbox with an old enough version of the dashboard then the drive type isn't stored yet, only the key. Of course if the console is that old, it probably already came with a samsung drive.

I know this to be the case though since I used the jtag method to recover the key from an xbox i got off ebay. I put the key into a benq drive i had laying around and updated the dash board with no spoofing necessary. I'm assuming when i updated the benq became the "original drive".

This post has been edited by shawnmos: Nov 11 2010, 06:36 AM
Logged

Buzzcut

  • Archived User
  • Full Member
  • *
  • Posts: 220
How To Mod Liteon/benq Console To Boot Ap 2.5 And Work On Live Indefin
« Reply #5 on: November 11, 2010, 02:14:00 AM »

OSIG check was removed in dash 8955 and higher i.e. spoofing no longer required to boot console.
Logged