Can't get Xell to work on Falcon

mohsinkhan47

Junior Member
Apr 12, 2012
17
0
So the issue is you can't follow installation instructions.

You have 4 pads on that top QSB - B (which isn't used), E (green), F (brown) and 3v3 (which isn't used).

For some bizarre reason you have green going to B and brown going to E.

Read the installation guide AGAIN.
Now its working. I wrote the nand on to the xbox. I tried to power the xbox on but it just gives a black screen after 2-3 cycles. What should I do?
i have the cpu key and it is nand flashed.
 
Last edited:

mohsinkhan47

Junior Member
Apr 12, 2012
17
0
So the issue is you can't follow installation instructions.

You have 4 pads on that top QSB - B (which isn't used), E (green), F (brown) and 3v3 (which isn't used).

For some bizarre reason you have green going to B and brown going to E.

Read the installation guide AGAIN.
I have the xexmenu on my flash drive and when I boot my xbox it just has a black screen
 

mohsinkhan47

Junior Member
Apr 12, 2012
17
0
You'll need to provide RATER output as well as updflash.bin.log files.
how do i get the updflash.bin.log?

Log (?):

Code:
[/COLOR]---------------------------------------------------------------     xeBuild v1.07.561
---------------------------------------------------------------
building jtag image
<enter> key on completion suppressed
data directory overridden from command line to '.\xeBuild\16202\'
per build directory overridden from command line to 'xeBuild\data'
file name overridden from command line to 'C:\Users\Mohsin\Desktop\J-Runner v02 Beta (288) Core Pack\329527783305\updflash.bin'


------ parsing user ini at '.\xeBuild\data\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x1b0 bytes in memory
loading cpukey.txt from .\xeBuild\data\cpukey.txt
CPU Key set to: 0x6D754B38DFF43282228A9D2F32F526FB
setting 1blkey from ini: 0xDD88AD0C9ED669E7B56794FB68563EFA
1BL Key set to: 0xDD88AD0C9ED669E7B56794FB68563EFA sum: 0x983 (expects: 0x983)
xex Key set to: 0x20B185A59D28FDC340583FBB0896BF91 sum: 0x800 (expects: 0x800)
Using patchsmc option (ini file)


------ parsing ini at '.\xeBuild\16202\_jtag.ini' ------
ini version 16202


ini: label [falconbl] found
found (1) 'cb_5770.bin' crc: 0x3279f0d5
found (2) 'cd_5770.bin' crc: 0xd04e8927
found (3) 'ce_1888.bin' crc: 0xff9b60df
found (4) 'cf_4532.bin' crc: 0xd28ef722
found (5) 'cg_4532.bin' crc: 0x2530f8ce
found (6) 'cb_5771.bin' crc: 0x859140f0
found (7) 'cd_8453.bin' crc: 0x25e0acd0
found (8) 'cf_16202.bin' crc: 0x752bdf18
found (9) 'cg_16202.bin' crc: 0xd8bfe2ff


ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x280c416a
found (2) 'bootanim.xex' crc: 0x0817ebbe
found (3) 'createprofile.xex' crc: 0x29823ae3
found (4) 'dash.xex' crc: 0x40bbd9ab
found (5) 'deviceselector.xex' crc: 0xb982a6d4
found (6) 'gamerprofile.xex' crc: 0xd02321c0
found (7) 'hud.xex' crc: 0xa5493707
found (8) 'huduiskin.xex' crc: 0x77318862
found (9) 'mfgbootlauncher.xex' crc: 0x5ffbc69b
found (10) 'minimediaplayer.xex' crc: 0x38b0f35e
found (11) 'nomni.xexp' crc: 0xe71f0d4c
found (12) 'nomnifwk.xexp' crc: 0x1839b40e
found (13) 'nomnifwm.xexp' crc: 0x761e6e55
found (14) 'SegoeXbox-Light.xtt' crc: 0xe0ee6049
found (15) 'signin.xex' crc: 0x6ab06853
found (16) 'updater.xex' crc: 0x836a0696
found (17) 'vk.xex' crc: 0xbc79c266
found (18) 'xam.xex' crc: 0x2bbd918a
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0xe2adddfb
found (23) 'ximecore.xex' crc: 0x52eee832
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0xeb032195


ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------


output name overridden to: C:\Users\Mohsin\Desktop\J-Runner v02 Beta (288) Core Pack\329527783305\updflash.bin




------ Checking .\xeBuild\data\nanddump.bin ------
.\xeBuild\data\nanddump.bin file size: 0x1080000
nanddump header checks passed OK!
Loading NAND dump (0x1080000 bytes)...done!
Detecting NAND controller type from dump data...
	NAND dump is from a small block machine
	NAND dump uses small block controller
parsing dump into user and spare...
done!
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypted OK, will use if no kv.bin is provided
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0xf7c000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x0d Pairing: 0xd58ba7
CF slot 1 decrypted ok LDV 0x0c Pairing: 0xd58ba7
setting LDV from image to 13
setting pairing data from image to 0xd58ba7
MobileB.dat found at page 0x26a0, size 2048 (0x800) bytes
MobileC.dat found at page 0x3400, size 512 (0x200) bytes
MobileD.dat found at page 0x26c0, size 2048 (0x800) bytes
MobileE.dat found at page 0x22c0, size 2048 (0x800) bytes
Statistics.settings found at page 0x7bc0, size 4096 (0x1000) bytes
seeking FSRoot...fsroot found at page 0x4000 raw offset 0x840000
seeking security files...
crl.bin found in sector 0x24c size 0xa00...verified! Will use if external file not found.
dae.bin found in sector 0x23f size 0x7090...verified! Will use if external file not found.
extended.bin found in sector 0x1a8 size 0x4000...verified! Will use if external file not found.
secdata.bin found in sector 0x23d size 0x400...verified! Will use if external file not found.
done!
Writing initial header to flash image


------ loading system update container ------
.\xeBuild\16202\su20076000_00000000 found, loading...done!
	Read 0xb2f000 bytes to memory
checking container integrity...
header seems valid, version 2.0.16202.00
header hash is OK, checking content hashes...
content hashes seem OK, everything looks good!
extracted SUPD\xboxupd.bin (0x79a50 bytes)
decrypting SUPD\xboxupd.bin\CF_16202.bin (0x4560 bytes)...done!
decrypting SUPD\xboxupd.bin\CG_16202.bin (0x754f0 bytes)...done!


------ Loading bootloaders and required security files ------
could not read .\xeBuild\16202\bin\payload.bin, using built in payload (0x200 bytes)
reading .\xeBuild\data\SMC.bin (0x3000 bytes)
reset smc load address to 0x1000 size 0x3000
reading .\xeBuild\data\kv.bin failed, using kv.bin from nand dump
reading .\common\cb_5770.bin (0x8e40 bytes)
reading .\common\cd_5770.bin (0x56c0 bytes)
reading .\common\ce_1888.bin (0x5606a b pad 0x56070 b)
reading .\common\cf_4532.bin (0x44c0 bytes)
reading .\common\cg_4532.bin (0x2ef40 bytes)
extracted SUPD\xboxupd.bin\CF_16202.bin (0x4560 bytes)
extracted SUPD\xboxupd.bin\CG_16202.bin (0x754f0 bytes)
could not read .\xeBuild\16202\bin\freeboot.bin, using built in core (0xd80 bytes)
reading .\xeBuild\16202\bin\patches_falcon.bin (0x9a4 bytes)
reading .\xeBuild\data\xell-2f.bin (0x40000 bytes)
reading .\common\cb_5771.bin (0x9340 bytes)
reading .\common\cd_8453.bin (0x5780 bytes)
reading .\xeBuild\data\smc_config.bin failed, using smc_config.bin from nand dump
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu:  80øC Gpu:  75øC Edram:  78øC
Max temps   : Cpu: 100øC Gpu: 100øC Edram: 102øC
Cpu Fan     : (auto)
Gpu Fan     : (auto)
MAC Address : 00:1d:d8:7d:93:68
AVRegion    : 0x00000100 (NTSC-M)
GameRegion  : 0x00ff (NTSC/US)
DVDRegion   : 1
resetKey    : UYDA
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
done!


------ Encrypting and finalizing bootloaders ------
initializing random nonces
Fuse CPU Key set to: 0x6D754B38DFF43282228A9D2F32F526FB
Fuse CF LDV set to : 0xFFFFFFFFFFFFF0000000000000000000
encoding payload.bin size 0x200 (JTAG)
patching payload.bin to load size 0xd80 (0x360 reps)
encoding SMC.bin size 0x3000 (JTAG)
SMC checksum: a6ee8b80
unknown SMC found, type: Jasper v4.1(2.03)
jtag hack found in smc.bin!


******* WARNING: could not patch SMC reset limit!


encoding kv.bin size 0x4000 (JTAG)
decrypted keyvault has been set for reference
encoding cb_5770.bin size 0x8e40 (JTAG)
CB 5770 seq 0x01050018 type: 0x01 cseq: 0x05 allow: 0x0018
	expected fuses:
	fuseset 00: C0FFFFFFFFFFFFFF
	fuseset 01: 0F0F0F0F0F0F0FF0
	fuseset 02: 0000F00000000000 (sequence)
	fuseset 02: 000F000000000000 (allow cseq 4)
	fuseset 02: 0000F00000000000 (allow cseq 5)
encoding cd_5770.bin size 0x56c0 (JTAG)
encoding ce_1888.bin size 0x56070 (JTAG)
encoding cf_4532.bin size 0x44c0 (JTAG)
encoding cg_4532.bin size 0x2ef40 (JTAG)
encoding cf_16202.bin size 0x4560 (JTAG)
encoding cg_16202.bin size 0x754f0 (JTAG)
encoding freeboot.bin size 0xd80 (JTAG)
patching freeboot.bin with option mask 0x4 and kernel version string '16202'
Options set:
    - console DVD eject button is being used to start xell 
    - alternate xell button disabled
encoding patches_falcon.bin size 0x9a8 (JTAG)
encoding fuses.bin size 0x60 (JTAG)
encoding xell-2f.bin size 0x40000 (JTAG)
encoding cb_5771.bin size 0x9340 (JTAG)
CB 5771 seq 0x01070058 type: 0x01 cseq: 0x07 allow: 0x0058
	expected fuses:
	fuseset 00: C0FFFFFFFFFFFFFF
	fuseset 01: 0F0F0F0F0F0F0FF0
	fuseset 02: 000000F000000000 (sequence)
	fuseset 02: 000F000000000000 (allow cseq 4)
	fuseset 02: 0000F00000000000 (allow cseq 5)
	fuseset 02: 000000F000000000 (allow cseq 7)
encoding cd_8453.bin size 0x5780 (JTAG)


Virtual Fuses set to:
	fuseset 00: C0FFFFFFFFFFFFFF
	fuseset 01: 0F0F0F0F0F0F0FF0
	fuseset 02: 000000F000000000
	fuseset 03: 6D754B38DFF43282
	fuseset 04: 6D754B38DFF43282
	fuseset 05: 228A9D2F32F526FB
	fuseset 06: 228A9D2F32F526FB
	fuseset 07: FFFFFFFFFFFFF000
	fuseset 08: 0000000000000000
	fuseset 09: 0000000000000000
	fuseset 10: 0000000000000000
	fuseset 11: 0000000000000000
done!


------ Adding bootloaders to flash image ------
adding payload.bin at raw offset 0x00000200 len 0x200 (end 0x400)
adding SMC.bin at raw offset 0x00001000 len 0x3000 (end 0x4000)
adding kv.bin at raw offset 0x00004000 len 0x4000 (end 0x8000)
adding cb_5770.bin at raw offset 0x00008000 len 0x8e40 (end 0x10e40)
adding cd_5770.bin at raw offset 0x00010e40 len 0x56c0 (end 0x16500)
adding ce_1888.bin at raw offset 0x00016500 len 0x56070 (end 0x6c570)
adding cf_4532.bin at raw offset 0x00070000 len 0x44c0 (end 0x744c0)
adding cg_4532.bin at raw offset 0x000744c0 len 0x2ef40 (end 0x80000, rest in fs)
adding cf_16202.bin at raw offset 0x00080000 len 0x4560 (end 0x84560)
adding cg_16202.bin at raw offset 0x00084560 len 0x754f0 (end 0x90000, rest in fs)
adding freeboot.bin at raw offset 0x00090000 len 0xd80 (end 0x90d80)
adding patches_falcon.bin at raw offset 0x00091000 len 0x9a8 (end 0x919a8)
adding fuses.bin at raw offset 0x00095000 len 0x60 (end 0x95060)
adding xell-2f.bin at raw offset 0x00095060 len 0x40000 (end 0xd5060)
adding cb_5771.bin at raw offset 0x000d5060 len 0x9340 (end 0xde3a0)
adding cd_8453.bin at raw offset 0x000de3a0 len 0x5780 (end 0xe3b20)
Fixing up FS table...done!
Writing zeropair CG patch slot overflow data to sysupdate.xexp1
	at raw offset 0xe4000 len 0x00023400 (end: 0x00107400)...done!
Writing target CG patch slot overflow data to sysupdate.xexp2
	at raw offset 0xe4000 len 0x00069a50 (end: 0x0014da50)...done!


------ adding 25 firmware files ------
extracted SUPD\aac.xexp (0x14000 bytes) (crc32: 0x280c416a ini: 0x280c416a)
	adding as aac.xexp2 at raw offset 0x171a50 len 0x00014000 (end 0x00185a50)
extracted SUPD\bootanim.xex (0x61000 bytes) (crc32: 0x0817ebbe ini: 0x0817ebbe)
	adding as bootanim.xex at raw offset 0x188000 len 0x00061000 (end 0x001e9000)
extracted SUPD\createprofile.xex (0xc000 bytes) (crc32: 0x29823ae3 ini: 0x29823ae3)
	adding as createprofile.xex at raw offset 0x1e9000 len 0x0000c000 (end 0x001f5000)
extracted SUPD\dash.xex (0x59b000 bytes) (crc32: 0x40bbd9ab ini: 0x40bbd9ab)
	adding as dash.xex at raw offset 0x1f8000 len 0x0059b000 (end 0x00793000)
extracted SUPD\deviceselector.xex (0xa000 bytes) (crc32: 0xb982a6d4 ini: 0xb982a6d4)
	adding as deviceselector.xex at raw offset 0x793000 len 0x0000a000 (end 0x0079d000)
extracted SUPD\gamerprofile.xex (0x1b000 bytes) (crc32: 0xd02321c0 ini: 0xd02321c0)
	adding as gamerprofile.xex at raw offset 0x79e000 len 0x0001b000 (end 0x007b9000)
extracted SUPD\hud.xex (0x1d000 bytes) (crc32: 0xa5493707 ini: 0xa5493707)
	adding as hud.xex at raw offset 0x7bb000 len 0x0001d000 (end 0x007d8000)
extracted SUPD\huduiskin.xex (0x14000 bytes) (crc32: 0x77318862 ini: 0x77318862)
	adding as huduiskin.xex at raw offset 0x7d9000 len 0x00014000 (end 0x007ed000)
extracted SUPD\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0x5ffbc69b ini: 0x5ffbc69b)
	adding as mfgbootlauncher.xex at raw offset 0x7f0000 len 0x00008000 (end 0x007f8000)
extracted SUPD\minimediaplayer.xex (0xb000 bytes) (crc32: 0x38b0f35e ini: 0x38b0f35e)
	adding as minimediaplayer.xex at raw offset 0x7f8000 len 0x0000b000 (end 0x00803000)
extracted SUPD\nomni.xexp (0xe000 bytes) (crc32: 0xe71f0d4c ini: 0xe71f0d4c)
	adding as nomni.xexp2 at raw offset 0x803000 len 0x0000e000 (end 0x00811000)
extracted SUPD\nomnifwk.xexp (0x2000 bytes) (crc32: 0x1839b40e ini: 0x1839b40e)
	adding as nomnifwk.xexp2 at raw offset 0x812000 len 0x00002000 (end 0x00814000)
extracted SUPD\nomnifwm.xexp (0x5000 bytes) (crc32: 0x761e6e55 ini: 0x761e6e55)
	adding as nomnifwm.xexp2 at raw offset 0x816000 len 0x00005000 (end 0x0081b000)
extracted SUPD\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0xe0ee6049 ini: 0xe0ee6049)
	adding as SegoeXbox-Light.xtt at raw offset 0x81d000 len 0x00006000 (end 0x00823000)
extracted SUPD\signin.xex (0x16000 bytes) (crc32: 0x6ab06853 ini: 0x6ab06853)
	adding as signin.xex at raw offset 0x826000 len 0x00016000 (end 0x0083c000)
extracted SUPD\updater.xex (0x7000 bytes) (crc32: 0x836a0696 ini: 0x836a0696)
	adding as updater.xex at raw offset 0x83e000 len 0x00007000 (end 0x00845000)
extracted SUPD\vk.xex (0xb000 bytes) (crc32: 0xbc79c266 ini: 0xbc79c266)
	adding as vk.xex at raw offset 0x847000 len 0x0000b000 (end 0x00852000)
extracted SUPD\xam.xex (0x24e000 bytes) (crc32: 0x2bbd918a ini: 0x2bbd918a)
	adding as xam.xex at raw offset 0x853000 len 0x0024e000 (end 0x00aa1000)
reading .\xeBuild\16202\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
	adding as xenonclatin.xtt at raw offset 0xaa2000 len 0x0011b000 (end 0x00bbd000)
extracted SUPD\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
	adding as xenonclatin.xttp2 at raw offset 0xbbf000 len 0x00018000 (end 0x00bd7000)
reading .\xeBuild\16202\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
	adding as xenonjklatin.xtt at raw offset 0xbd8000 len 0x001a8000 (end 0x00d80000)
extracted SUPD\xenonjklatin.xttp (0x7000 bytes) (crc32: 0xe2adddfb ini: 0xe2adddfb)
	adding as xenonjklatin.xttp2 at raw offset 0xd80000 len 0x00007000 (end 0x00d87000)
extracted SUPD\ximecore.xex (0x17000 bytes) (crc32: 0x52eee832 ini: 0x52eee832)
	adding as ximecore.xex at raw offset 0xd87000 len 0x00017000 (end 0x00d9e000)
reading .\xeBuild\16202\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
	adding as ximedic.xex at raw offset 0xd9f000 len 0x00090000 (end 0x00e2f000)
extracted SUPD\ximedic.xexp (0x2800 bytes) (crc32: 0xeb032195 ini: 0xeb032195)
	adding as ximedic.xexp2 at raw offset 0xe30000 len 0x00002800 (end 0x00e32800)


------ adding 4 security files ------
<- Processing crl.bin ->
reading .\xeBuild\data\crl.bin (0xa00 bytes)
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
	adding as crl.bin at raw offset 0xe34000 len 0x00000a00 (end 0x00e34a00)


<- Processing dae.bin ->
reading .\xeBuild\data\dae.bin (0xad30 bytes)
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
	adding as dae.bin at raw offset 0xe38000 len 0x0000ad30 (end 0x00e42d30)


<- Processing extended.bin ->
reading .\xeBuild\data\extended.bin (0x4000 bytes)
	adding as extended.bin at raw offset 0xe44000 len 0x00004000 (end 0x00e48000)


<- Processing secdata.bin ->
reading .\xeBuild\data\secdata.bin (0x400 bytes)
	adding as secdata.bin at raw offset 0xe48000 len 0x00000400 (end 0x00e48400)


------ checking for Mobile*.dat ------
MobileB.dat found, adding from nanddump.bin
	adding MobileB.dat as type 0x31 at raw offset 0xe4c000 len 0x800 (end 0xe4c800)
MobileC.dat found, adding from nanddump.bin
	adding MobileC.dat as type 0x32 at raw offset 0xe50000 len 0x200 (end 0xe50200)
MobileD.dat found, adding from nanddump.bin
	adding MobileD.dat as type 0x33 at raw offset 0xe54000 len 0x800 (end 0xe54800)
MobileE.dat found, adding from nanddump.bin
	adding MobileE.dat as type 0x34 at raw offset 0xe58000 len 0x800 (end 0xe58800)
Statistics.settings found, adding from nanddump.bin
	adding Statistics.settings at raw offset 0xf78000 len 0x1000 (end 0xf79000)


------ adding smc_config.bin ------
adding smc config to offset 0x00f7c000, len 0x400


------ finalizing image ------
Fixing up empty FS block entries...done!
Writing FS table to image offset 0xe5c000 len 0x4000 (end 0xe60000)...done!
calculating ECD bytes and assembling raw image...done!
writing file 'C:\Users\Mohsin\Desktop\J-Runner v02 Beta (288) Core Pack\329527783305\updflash.bin' to disk...done!
C:\Users\Mohsin\Desktop\J-Runner v02 Beta (288) Core Pack\329527783305\updflash.bin written OK


---------------------------------------------------------------
C:\Users\Mohsin\Desktop\J-Runner v02 Beta (288) Core Pack\329527783305\updflash.bin image built, info:
---------------------------------------------------------------
Console   : Falcon
NAND size : 16MiB
Build     : JTAG
Xell      : power on console with console eject button
Serial    : 329527783305
ConsoleId : 022060450324
MoboSerial: 7394962113638335
Mfg Date  : 08/15/2008
CPU Key   : 6D754B38DFF43282228A9D2F32F526FB
1BL Key   : DD88AD0C9ED669E7B56794FB68563EFA
DVD Key   : 22C0B307948A5C1CF9FD923CF1F3AD41
CF LDV    : 13
KV type   : type2 (hashed)
---------------------------------------------------------------
    xeBuild Finished. Have a nice day.
---------------------------------------------------------------


[COLOR=#333333]
Rater:

Code:
Phat SelectedVersion: 10
Power Up
Waiting for POST to change
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 1B - RC4_DECRYPT 
Post 1C - SHA_COMPUTE 
Post 1D - SIG_VERIFY 
Post 1E - BRANCH 
Post 20 - CB entry point reached 
Post 21 - INIT_SECOTP 
Post 22 - INIT_SECENG 
Post 20 - CB entry point reached 
Post 20 - CB entry point reached 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 70 - INIT_VIDEO_DRIVER 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 70 - INIT_VIDEO_DRIVER 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 70 - INIT_VIDEO_DRIVER 
Post 10 - Payload/1BL started 
Post 11 - FSB_CONFIG_PHY_CONTROL 
Post 12 - FSB_CONFIG_RX_STATE 
Post 15 - FETCH_OFFSET 
Post 16 - FETCH_HEADER 
Post 18 - FETCH_CONTENTS 
Post 1B - RC4_DECRYPT 
Post 1C - SHA_COMPUTE 
Post 1D - SIG_VERIFY 
Post 1E - BRANCH 
Post 20 - CB entry point reached 
Post 21 - INIT_SECOTP 
Post 22 - INIT_SECENG 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 20 - CB entry point reached 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 70 - INIT_VIDEO_DRIVER 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 70 - INIT_VIDEO_DRIVER 
Post 30 - VERIFY_OFFSET_4BL_CD 
Post 10 - Payload/1BL started 
Post 11 - FSB_CONFIG_PHY_CONTROL 
Post 12 - FSB_CONFIG_RX_STATE 
Post 13 - FSB_CONFIG_TX_STATE 
Post 14 - FSB_CONFIG_TX_CREDITS 
Post 18 - FETCH_CONTENTS 
Post 19 - HMACSHA_COMPUTE 
Post 1B - RC4_DECRYPT 
Post 1C - SHA_COMPUTE 
Post 1D - SIG_VERIFY 
Post 1E - BRANCH 
Post 20 - CB entry point reached 
Post 21 - INIT_SECOTP 
Post 22 - INIT_SECENG 
Post 2F - RELOCATE 
Post 2E - HWINIT 
Post 33 - FETCH_CONTENTS_4BL_CD 
Post 34 - HMACSHA_COMPUTE_4BL_CD 
Post 35 - RC4_INITIALIZE_4BL_CD 
Post 36 - RC4_DECRYPT_4BL_CD 
Post 37 - SHA_COMPUTE_4BL_CD 
Post 3A - BRANCH 
Post 40 - Entrypoint of CD reached 
Post 41 - VERIFY_OFFSET 
Post 44 - FETCH_CONTENTS 
Post 45 - HMACSHA_COMPUTE 
Post 46 - RC4_INITIALIZE 
Post 47 - RC4_DECRYPT 
Post 48 - SHA_COMPUTE 
Post 4B - LZX_EXPAND 
Post 4E - FETCH_OFFSET_6BL_CF 
Post 4F - VERIFY_OFFSET_6BL_CF 
Post 51 - LOAD_UPDATE_2 
Post 50 - LOAD_UPDATE_1 
Post 52 - BRANCH 
Post 58 - INIT_HYPERVISOR 
Post 5A - INIT_XEX_TRAINING 
Post 60 - INIT_KERNEL 
Post 61 - INIT_HAL_PHASE_0 
Post 63 - INIT_KERNEL_DEBUGGER 
Post 64 - INIT_MEMORY_MANAGER 
Post 65 - INIT_STACKS 
Post 66 - INIT_OBJECT_SYSTEM 
Post 67 - INIT_PHASE1_THREAD 
Post 68 - Started phase 1 Initialization + INIT_PROCESSORS 
Post 69 - INIT_KEY_VAULT 
Post 6A - INIT_HAL_PHASE_1 
Post 6B - INIT_SFC_DRIVER 
Post 10 - Payload/1BL started 
Post 11 - FSB_CONFIG_PHY_CONTROL 
Post 10 - Payload/1BL started 
Post 11 - FSB_CONFIG_PHY_CONTROL 
Post 12 - FSB_CONFIG_RX_STATE 
Post 13 - FSB_CONFIG_TX_STATE 
Post 15 - FETCH_OFFSET 
Post 16 - FETCH_HEADER 
Post 17 - VERIFY_HEADER 
Post 18 - FETCH_CONTENTS 
Post 19 - HMACSHA_COMPUTE 
Post 1A - RC4_INITIALIZE 
Post 1B - RC4_DECRYPT 
Post 1C - SHA_COMPUTE 
Post 1D - SIG_VERIFY 
Post 1E - BRANCH 
Post 20 - CB entry point reached 
Post 21 - INIT_SECOTP 
Post 22 - INIT_SECENG 
Post 2F - RELOCATE 
Post 23 - INIT_SYSRAM 
Post 31 - FETCH_HEADER_4BL_CD 
Post 33 - FETCH_CONTENTS_4BL_CD 
Post 34 - HMACSHA_COMPUTE_4BL_CD 
Post 35 - RC4_INITIALIZE_4BL_CD 
Post 36 - RC4_DECRYPT_4BL_CD 
Post 37 - SHA_COMPUTE_4BL_CD 
Post 3B - PCI_INIT 
Post 44 - FETCH_CONTENTS 
Post 45 - HMACSHA_COMPUTE 
Post 46 - RC4_INITIALIZE 
Post 47 - RC4_DECRYPT 
Post 48 - SHA_COMPUTE 
Post 4B - LZX_EXPAND 
Post 4D - DECODE_FUSES 
Post 4E - FETCH_OFFSET_6BL_CF 
Post 4F - VERIFY_OFFSET_6BL_CF 
Post 51 - LOAD_UPDATE_2 
Post 52 - BRANCH 
Post 59 - INIT_SOC_MMIO 
Post 5A - INIT_XEX_TRAINING 
Post 5B - INIT_KEYRING 
Post 5C - INIT_KEYS 
Post 5F 
Post 60 - INIT_KERNEL 
Post 61 - INIT_HAL_PHASE_0 
Post 62 - INIT_PROCESS_OBJECTS 
Post 63 - INIT_KERNEL_DEBUGGER 
Post 64 - INIT_MEMORY_MANAGER 
Post 65 - INIT_STACKS 
Post 66 - INIT_OBJECT_SYSTEM 
Post 67 - INIT_PHASE1_THREAD 
Post 68 - Started phase 1 Initialization + INIT_PROCESSORS 
Post 69 - INIT_KEY_VAULT 
Post 6A - INIT_HAL_PHASE_1 
Post 6B - INIT_SFC_DRIVER 
Post 6C - INIT_SECURITY 
Post 6D - INIT_KEY_EX_VAULT 
Post 6E - INIT_SETTINGS 
Post 6F - INIT_POWER_MODE 
Post 70 - INIT_VIDEO_DRIVER 
Post 71 - INIT_AUDIO_DRIVER 
Post 72 - INIT_BOOT_ANIMATION + XMADecoder & XAudioRender Init 
Shutdown

 
Last edited:

nofeloniesyet

VIP Member
Jan 16, 2011
4,830
128
Nowhere
You need to edit the power mode in your SMC to 8080.
havent ran into one of these falcons yet that has this issue,good to know thiers a solution though,seems to have worked a charm for mannnnny.
 

Martin C

VIP Member
Jan 10, 2004
35,981
0
Scotland, UK
www.team-xecuter.com
It creates a new .bin file called nanddump1_ edited. Should I use that as the source and additional file?
You only needed to load as source and click 'write NAND', but glad you got it sorted.