-
First off, You need to check that you have no Higher than kernel 7371 and for the moment only works on Xenon due to the diagrams/software not being realeasd for other types.
You need to solder up the LPT NAND reader as described in this http://forums.xbox-scene.com/index.php?showtopic=690493 thread
You also need Xenon_hack.bin (available from the usual places)
ATM it only works on VGA so you either have to go out an purchase a VGA xbox360 cable or do the VGA mod
http://forums.xbox-scene.com/index.php?showtopic=522608
After succesfully flashing the NAND, have a camera ready to take a quick capture or the screen or if you have video capturing capabilities then im sure that will do.
You need to grab lines 3 and 5 or 4 and 6, it doesnt matter) of the fuses that breifly flash up on the screen, those two parts make up your CPU key
(IMG:http://img198.imageshack.us/img198/8386/fuses2.jpg)
Right, now Grab flashtool 0.88b http://rapidshare.com/files/151147932/360_...Retail.rar.html
Load it and it should come up with a popup requesting cpukey, tick the box and paste it in. if not click keys on the app and insert them there.
Click open dump file and point it towards your 360 dump.
(IMG:http://img3.imageshack.us/img3/4097/fdtq.jpg)
There you have it, Your DVD key + drive revision (IMG:style_emoticons/default/smile.gif)
Then using the Same method you used to flash xenon_hack.bin, Flash back your 360 nand.bin to resume 360 functionality and flash the Dvd drive with the drive key you recovered (IMG:style_emoticons/default/smile.gif)
This post has been edited by RRODXbox: Aug 21 2009, 07:16 PM
-
ecellent stuff
its the first proper tut, and first real use of the new hack i feel
its great to have all the info in one place
many thanx
-
Fuck yeh, let the money roll in!
I'm attempting to decrypt nand now, will let you know how it goes.
-
Fantastic, have got a DVD key for what appears to be a Hitachi-LG. I have a spare Lite-On knocking around, is there a tut for spoofing a Lite-On as a Hitachi? This is all looking VERY promising!
-
OH YEAH, OH YEAH, OH YEAH, IT WORKS!
-
Nice tut im sure this will come in handy sometime!!
-
Yes this works, and is easy to do. But you need to take a quick pic, right? Wrong, I've found a way to make it so that the screen freezes. Want to know how to do it? Heck I'll tell ya it's very easy.
Open note pad.
type um.... FREEZE, or Pause, or anything.
Now click file-save as
and save it as XENON.ELF
very important to save it like that.
Then put it on a usb drive. Turn on your 360 with xell installed, and bam the screen will um..... pause.
Hawk
-
Thanks for the tip Mhawk!!!
I didn't have any probs grabbing a picture quickly but will help those who arent so quick.
-
Here is my question
why under OSIG does it say unknown ? Im sure i got a valid dump because when i flashed my nand image back to my 360 everything works fine (played tiger woods 10 with no problems) I got my CPU key form fusebits 3 and 5 entered it in to flash tool opened up my nand dump and it ether crashes or i get unknown OSIG
Why is this ? any help would be great
Thanks for any help
oh and yes the dvd key that flash tools shows is correct
xxpittbullxx
http://img199.images.../flashtoola.jpg
-
QUOTE(RRODXbox @ Aug 21 2009, 10:09 AM)

ATM it only works on VGA so you either have to go out an purchase a VGA xbox360 cable or do the VGA mod
Why is only VGA supported for this ?
-
Because thats all the drivers are made for at the moment.
-
QUOTE(xxpittbullxx @ Aug 22 2009, 06:10 PM)

Here is my question
why under OSIG does it say unknown ? Im sure i got a valid dump because when i flashed my nand image back to my 360 everything works fine (played tiger woods 10 with no problems) I got my CPU key form fusebits 3 and 5 entered it in to flash tool opened up my nand dump and it ether crashes or i get unknown OSIG
Why is this ? any help would be great
Thanks for any help
oh and yes the dvd key that flash tools shows is correct
xxpittbullxx
http://img199.imageshack.us/img199/300/flashtoola.jpg
From what I had accidently found on XBH, some Kevaults do not have OSIG section in them meaning you can use any drive without getting E66 and works with just the key.
Yours is working so I wouldn't worry about it too much (IMG:style_emoticons/default/smile.gif) its not like you are going to take it on live and risk a ban from bad spoofing is it (IMG:style_emoticons/default/smile.gif)
-
Thank you very much RRODxbox I thought that maybe I had some missing info in my dump but I guess not
a hundred thanks
-
I just flashed my xenon, got E79. I'm using an Infectus.
Is there anything that needs to be done with the xenon.bin file before flashing? Do you need to use the LPT flashing, or will the infectus do it ok?
-
QUOTE(X-hacker @ Aug 24 2009, 03:29 PM)

I just flashed my xenon, got E79. I'm using an Infectus.
Is there anything that needs to be done with the xenon.bin file before flashing? Do you need to use the LPT flashing, or will the infectus do it ok?
Did you run your resistors from the JTAG port to the GPU SMC port?
As shown here: http://forums.xbox-s...o...690493&st=0
(ignore all other connections listed EXCEPT the 330 Ohm resistors and their points on the motherboard, they are what you need)
-
Ya, Tmbinc said that if you flash the NAND without doing the 3 resistors, you get E79
-
Ok got it. I've got the efuses read out and the CPU key.
I've inputted the CPU key in the flash tool, then tryed to open my dump but it just crashes and comes up with error reporting...
Wrong CPU key? Do I need the 1BL key?
-
No you dont need the 1bl key, I saw on XBH that after a certain revision of Flash tool you no longer need it and some people have managed to get thir keys from my tut. maybe you are using an old version?
And did you take you key from lines 3 and 5 or 4 and 6, it doesnt matter which but maybe you put them in the wrong way round?
-
QUOTE(X-hacker @ Aug 25 2009, 01:00 AM)

Ok got it. I've got the efuses read out and the CPU key.
I've inputted the CPU key in the flash tool, then tryed to open my dump but it just crashes and comes up with error reporting...
Wrong CPU key? Do I need the 1BL key?
Try this.
Open the FlashTool
Click on Keys.
Enter the 2 lines from the fuses.
ok
Close the program completely.
Reopen
Select your NAND file - it should populate with DVD key and ORIG Data. If it crashes, it's possible your dump isn't good. I strongly recommend running it through Degraded v1.1 first to ensure there are no bad blocks (although it's probably too late for you unless you did multiple dumps).
-
I have a spare part xbox i got with no dvd-drive, so i´ve read the orig flash with no problems, and flashed xenon-flash.bin and got the dvdkey, but when i flash the orig flash back i get and error from the xbox E71
I don´t know if the xbox already had this from the start
Is there anyway i kan get another flash to try with ???
The MOBO is Xenon
-
QUOTE(duval @ Aug 26 2009, 02:07 AM)

I have a spare part xbox i got with no dvd-drive, so i´ve read the orig flash with no problems, and flashed xenon-flash.bin and got the dvdkey, but when i flash the orig flash back i get and error from the xbox E71
I don´t know if the xbox already had this from the start
Is there anyway i kan get another flash to try with ???
The MOBO is Xenon
E71 is a normal error so it may have been there before.
According to internet nerds it has somethignt o do with the ethernet port...
All it means is there is a general hardware problem or bridge in circuits.
Do the Xclamp repair, then maybe run some heat on it and some good thermal paste and you should be fine.
Man I can wait to het this hack going to revive some dvdless xboxes
-
I made the Statute to the letter, to be in two with the console turned on and connected to vga cable Munitor
pulling me this error
C:\NandPro20>NandPro.exe lpt: -r16 nand.bin
NandPro v2.0 by Tiros
Testing LPT device address:0378
Using LPT device at address:0378
FlashConfig:00012000
Starting Block:0x000000
Ending Block:0x0003FF
Press any key to begin reading nand
Error: 0 reading block 0
Error: 0 reading block 1
Error: 0 reading block 2
Error: 0 reading block 3
Error: 0 reading block 4
Error: 0 reading block 5
Error: 0 reading block 6
Error: 0 reading block 7
Error: 0 reading block 8
Error: 0 reading block 9
Error: 0 reading block A
Error: 0 reading block B
Error: 0 reading block C
Error: 0 reading block D
Error: 0 reading block E
Error: 0 reading block F
Error: 0 reading block 10
Error: 0 reading block 11
Error: 0 reading block 12
Error: 0 reading block 13
Error: 0 reading block 14
Error: 0 reading block 15
Error: 0 reading block 16
Error: 0 reading block 17
Error: 0 reading block 18
Error: 0 reading block 19
Error: 0 reading block 1A
Error: 0 reading block 1B
Error: 0 reading block 1C
Error: 0 reading block 1D
Error: 0 reading block 1E
Error: 0 reading block 1F
Error: 0 reading block 20
Error: 0 reading block 21
Error: 0 reading block 22
Error: 0 reading block 23
Error: 0 reading block 24
Error: 0 reading block 25
Error: 0 reading block 26
Error: 0 reading block 27
Error: 0 reading block 28
Error: 0 reading block 29
Error: 0 reading block 2A
Error: 0 reading block 2B
Error: 0 reading block 2C
Error: 0 reading block 2D
Error: 0 reading block 2E
Error: 0 reading block 2F
Error: 0 reading block 30
Error: 0 reading block 31
Error: 0 reading block 32
Error: 0 reading block 33
Error: 0 reading block 34
Error: 0 reading block 35
Error: 0 reading block 36
Error: 0 reading block 37
Error: 0 reading block 38
Error: 0 reading block 39
Error: 0 reading block 3A
Error: 0 reading block 3B
Error: 0 reading block 3C
Error: 0 reading block 3D
Error: 0 reading block 3E
Error: 0 reading block 3F
Error: 0 reading block 40
Error: 0 reading block 41
Error: 0 reading block 42
Error: 0 reading block 43
Error: 0 reading block 44
Error: 0 reading block 45
Error: 0 reading block 46
Error: 0 reading block 47
Error: 0 reading block 48
Error: 0 reading block 49
Error: 0 reading block 4A
Error: 0 reading block 4B
Error: 0 reading block 4C
Error: 0 reading block 4D
Error: 0 reading block 4E
Error: 0 reading block 4F
Error: 0 reading block 50
Error: 0 reading block 51
Error: 0 reading block 52
0053
I can also be failing to
be said: the xbox is still on but no video and the fans off
-
Do you have the diode installed on pin 11, also try reducing the cable length for the parallel port
-
QUOTE(reddwarf @ Aug 26 2009, 01:58 PM)

Do you have the diode installed on pin 11, also try reducing the cable length for the parallel port
I have installed the diode 11 are other pruebaa elpin, see what happens cut the cable
-
can this help me out with my problem? my pcb board on the drive is not the one for the 360? Do i need any cables and such?
-
QUOTE(suarez_suarez @ Aug 26 2009, 12:01 PM)

I have installed the diode 11 are other pruebaa elpin, see what happens cut the cable
Yep let us know!!!!
QUOTE(hazy4days @ Aug 26 2009, 07:21 PM)

can this help me out with my problem? my pcb board on the drive is not the one for the 360? Do i need any cables and such?
Yes you can recover the DVD from the motherboard once you have the nand dump and the cpu key, use 360 flash dumper to decode the dvd key, it'll even tell you what type of DVD drive is married to the system!!
-
QUOTE(reddwarf @ Aug 27 2009, 12:35 AM)

Yep let us know!!!!
Yes you can recover the DVD from the motherboard once you have the nand dump and the cpu key, use 360 flash dumper to decode the dvd key, it'll even tell you what type of DVD drive is married to the system!!
So wat cable do i need to do this?
-
Jtag hack and lpt nand dump cable. Go back to General Technical Hacking Discussion its all covered in there.
-
QUOTE(majinsoftware @ Aug 27 2009, 08:02 AM)

Jtag hack and lpt nand dump cable. Go back to General Technical Hacking Discussion its all covered in there.
Can u give me a link bcuz i cant find it anywere
-
OMG, If you cant find this then you shouldnt even be plugging a xbox into the tv/power let alone opening it and modding it. God some people can be super stupid or super lazy.
http://forums.xbox-scene.com/index.php?showtopic=690493
-
Excellent tutorial, thanks!!
I revived a 360 this weekend which had a missing DVD-key. It had been sitting around for a while and has a pre-NXE dash. I think I'll keep it around for the good things to come!
-
yeah thanks for the tutorial, it was easy and workd out well. e
-
Hey RRODxbox,
First I'd like to say thanks for all the work on this. I've had a 360 with bricked dvd drive for a while now. I understand all the physical work, no problem. However, I've never flashed a drive on anything. I've read all the pages of info on this post and the LPT diagram one, but there are too many different tools being used for the same purpose for me to follow.
All I want to do is Figure out what my original key was for my drive, get a new drive and put the OEM firmware and key on it.
My understanding is that I hook up my wires: JTAG and LPT Nand. My 360 drive stays connected to 360. I have VGA cable for 360 hooked up. I have Nandpro on my PC. Do I boot the 360 and PC at same time? then I take picture of "fuses" or the Read. How do I find the dvd key? Sorry I know it's first post and all, if you could point me in the right direction I'd be very grateful. Thanks
This post has been edited by aspiretoshred: Sep 15 2009, 09:09 PM
-
I've got Region: Unk 0201. What does that mean?
-
QUOTE(aspiretoshred @ Sep 15 2009, 08:58 PM)

Hey RRODxbox,
First I'd like to say thanks for all the work on this. I've had a 360 with bricked dvd drive for a while now. I understand all the physical work, no problem. However, I've never flashed a drive on anything. I've read all the pages of info on this post and the LPT diagram one, but there are too many different tools being used for the same purpose for me to follow.
All I want to do is Figure out what my original key was for my drive, get a new drive and put the OEM firmware and key on it.
My understanding is that I hook up my wires: JTAG and LPT Nand. My 360 drive stays connected to 360. I have VGA cable for 360 hooked up. I have Nandpro on my PC. Do I boot the 360 and PC at same time? then I take picture of "fuses" or the Read. How do I find the dvd key? Sorry I know it's first post and all, if you could point me in the right direction I'd be very grateful. Thanks
Sorry for the long reply, havent been around much..
You dont need to turn the 360 on, just powered by a PSU
You dump your NAND.bin then flash Xell to your 360 to get the CPU keys
After getting a succesful dump you load your NAND.bin in flashtool inserting your CPU key you saw in Xell. then is simply displays it as shown in my pic on the 1st page 
You then flash your NAND.bin back to the 360 and flash the key you found back to the drive and all should be well 
-
One quick question, I have a xenon board with 7371, will this work with NXE?
So far this is the only tutorial I have found that says 7371 and the rest say lower than taht?
Just want to know.
Thanks
-
Any Dasboard version up to and including 7371 is compatible with the retrieval method
-
can i also use infectus programmer
to program the nand i have already install infectus to write nand en dump
thx
-
Dude, you're my hero!
I did have to remove the resistors from my lpt cable to get it to work, though. Using "fc/b", my nand dumps seem to have a lot of differences, but I did manage to make 2 without any errors in the reading process.
My cable is about 3' (which is just long enough to sit the xbox on top of the pc and reach the lpt port), and I did use a switching diode. The box is flashed back to the orig nand, so seems to be fine, but either my dumping isn't consistent for some reason, or fc/b is an inefficient way to compare dumps.
Another box I tried hooking up to read suddenly turns my power brick red when I plug it in; no idea why, as before I started hooking it up, it didn't have a problem....
-
First off i just want to thank everyone who worked on this project. Im new to the xbox 360 scene as well as this is my first forum post. I mixed up dvd drives a while back and stole a few parts out of the wrong one and figured i was screwed for life, until i read this forum. i understand most of it what im not sure about though is once you solder everything up it says after flashing the nand. how do you flash the nand? do you hook up the serial port to the computer and run somthing? any helpful responses would be appreciated.
-
ok to update my situation, i just checked my kernal version and i have one of the 84XX versions. i have a feeling im shit out of luck for a while? so my question now would be is there anyway to downgrane from my version, or will i just have to wait until some sort of downgrade hack out. once again appreciate all the work you all have done here and i look forward to your responses....
-
RRODXbox,
Thank you so much for your tutorial. I was able to recover a lost key on an old xenon console as well.
You rock!
-
QUOTE(RRODXbox @ Aug 22 2009, 06:42 PM)

Thanks for the tip Mhawk!!! :)
I didn't have any probs grabbing a picture quickly but will help those who arent so quick.
Hey RRodbox.. i'm new to this site and i thought i'd ask u wats going wrong with my xbox. i've lost my dvd key and i wanted to recover it so i did your method. and wen i tried to flash the nand with da hack.bin to boot xell the xbox turns on and after about 20 secs gives me RROD with error code 0022. i then flashed back the backed up bin file to see if the box will boot properly but then nothing happens as in the xbox doesn't respond at all. doesnt even switch on and i flash the hack.bin it switches on but gives RROD. when i backed up the nand.bin they both were read without any errors. please help me. this is my console and i cant afford another one. please man.
-
Thanks for the tutorial, i had to remove the 100ohm resistors for mine to "try" and read anything, but when it does try and read I'm getting error after error, with no dump, any pointers?
Its left me with a 182kb file under the nand name but i didnt let it go all the way through because of all the errors, the flash id was 120000 so i guess i may possibly need the diode in there, does it go between J1D2 4 and R2D8 or am i reading the diagram wrong?
all the 330 resistors are still in there just the 100's taken out.
All the best
Stu
This post has been edited by knight2000uk: Yesterday, 02:22 AM
-
Update on my last, the diode seems to be taking it to the right flash id, will report back when i have a good dump (no not that kind of dump lol
)
Stu
-
Thanks for the tut RRODXbox, learned a lot. I have a xenon with 8507 kernel. Because of your breakthrough I am hopeful on getting my key some day!
fiveten
-
I can read you need the VGA cable for this. Isn't it possible with the RCA one? If not, would it be possible to do this without using the screen (like output the info we want on a file?)
Thanks!
-
Hi,
I have followed this tutorial for a zephyr mainboard and all went well. Xell booted up and got my key. But as I flashed back the original nand I'm getting RROD. I've tried several times, taking off power after flashing but still no luck. Thing is that I just have 1 dump so maybe that was a bad dumb. Later I tried on a new Elite with jasper which I accidentaly lost the key, with kernel 7636 (if im not mistaken). Read original nand 6 times with no errors, tried to boot up xell (jasper hacked 16mb version) and it didnt boot, probably the kernel is not exploitable. Then i reflashed the original nand and got RROD also on this one. I tried all the 6 dumps and still no luck. Took all day. Any suggestions please?
-
I am currently having the same problem. Have 4 reads, all done with no errors, all identical. Flashed Xell, got CPU key, got the DVD key. Now I flashed the NAND backup and got E79 (the console is almost unused as the owner tried to mod it himself and erased before reading the key). Do I have to erase before writing the NAND back? Do I have to write with nandpro using w or W?
bar807 did you try erasing before writing back the original NAND?
-
I just did this over the weekend! Thank you so much for this!! It's probably the coolest hack I've ever done!
-
Hi great guide I managed to get my dvd key but when I flash the original nand dump back all I get now is 2 alternating red leds jumping from bottom 2 to top 2?. Theres no video output just black screen with the leds jumping from top to bottom
I dumped the nand 3 times and compared them using infectus tools with no errors.
Anybody got any ideas ??.
Thanks again
-
Compared using infectus tools? Could you detail that method? Did you try comparing with "fc" command in DOS, or with Total Commander "Compare by content" option?
How many times did you write the flash back to the console? Did you try an erase command before writing?
I was able to solve the problem mentioned 2 posts above by erasing and writing again. Don't know if the problem was that I did not erase first, or maybe due to a bad writing. All is good, key injected in DVD and all is working fine and dandy 
Thanks everyone for the tutorials and help!
-
Is Xell the same as xenon_ha&k.bin? spent ages tryin to sort this and ive got as far as reading nand and tryin to flashj xenon bin file but it wont boot up at all 3 red lights!!!!!
-
I have a good falcon board with kernal 7371 that somebody swapped in a samsung drive and lost the key,
Will this method work on this board? I think there might have been some program updates in the past week?..
I just gave away 3 xbox's this last month that would have been great for this all worked just had lost dvd keys.
Damn.
-
QUOTE
Will this method work on this board?
Of course, it works! Recently I retrieved the lost key of Falcon MB.
-
Does this method works for 512mb jaspers (june 09) boards?
-
Is there a way to do this without VGA cable?
I have the NAND all wired to LPT and JTAG hack soldered but have NOT done anything else yet.
Anyone know i dont want to go ahead yet to screw something up.
thanks
-
Form where I can download Xenon_hack.bin
-
I found it
thank's for the tutorial.
-
QUOTE(Braaap17 @ Dec 21 2009, 12:50 PM)

Is there a way to do this without VGA cable?
I have the NAND all wired to LPT and JTAG hack soldered but have NOT done anything else yet.
Anyone know i dont want to go ahead yet to screw something up.
thanks
You don't need the VGA cable, you can use the normal cable and go composite.
But, IT'S FUCKIN' HARD TO READ!
0's look like 8's
-
Hi all,
Could someone please tell me why I would need to write back to the NAND since I only read it to get the DVD key as the same key is going to be used?
Thanks.
-
Is their like any way too check your kernel without the Xbox360 having too goto the dashboard coz this is the furthest i get look:
http://img205.images...d=image443r.jpg
Or
http://img205.images...g=image443r.jpg
-
QUOTE(Unstopible @ Jun 16 2010, 03:24 PM)

Is their like any way too check your kernel without the Xbox360 having too goto the dashboard coz this is the furthest i get look:
http://img205.images...d=image443r.jpgOr
http://img205.images...g=image443r.jpg
Yep - just dump the NAND using NandPro as normal, then check using Degraded - it'll tell you your kernel version and more importantly, if you've got an exploitable CB.
-
No - exploitable (ie pre 8XXX) only.
-
DVD drive does not matter you just need an exploitable kernal
-
I remembered I had an old broken xbox 360 from 5 years ago in storage, I have like on of old dashboards in the 600's it is exploitable and xenon motherboard. But problem is I switched out dvd drive boards to a fixed dvd-rom now I have no clue what goes where or if what I have is the original. SO i need to get my keys from my motherboard. Can someone please send me links of tutorials in steps I will need to do things. If you could that would help a brother out so much. I can't seem to get help and ive been searching hard.
-
can someone talk to me on IM because I do not know what I am doing, obviously I need to do more research to learn but I do not understand this at all. Is there links to prereq knowledge I really need to do this but i don't know where to start. please shoot me a pm with any help your willing to give.
-
is there like a modchip that would do this for me, or could i do this through sata cord, i would rather not solder but if I have to i need better instructions and pictures, these other post seem to be for people that know a lot already and leaves noobs no place to begin learning. I need to know everything you have on retreiving keys from mother board
-
The link for the download doesn't work can someone pm me the program links. Also what is the printer cable for what is getting sent through that. I really neeed an indepth tutorial if any could send me some links.