[FIXED] Falcon only boots Xell
Console Type: Falcon
NAND size: 16
Dashboard version: 2.0.16537
CB version: 5774
update
updflash.bin log (if applicable):
Screenshot of NAND details from J-Runner:

J-Runner log:
POST output from J-Runner (either POST_OUT monitor or RATER output):
dont have JRP v2 (NAND-X & JRP v1)
Image of R-JTAG board:

Images of close-up soldering to motherboard:



(thanks to chase I found out there was a small crack in the QSB on the top left corner, see red circle)
Description of problem:
I fixed the QSB problem by cutting off the top half and solderered wires directly to the POST points

I finally managed to extract the CPU key and wrote a patched nand to the console. DIP switch 3 did the trick..
Then I ran into another problem.
The console only booted to Xell (using the eject button) in 1-2 cycles everytime so the glitching went fine.
The problem was that my console didn't boot to dash. Everytime I used the power button to boot the console, it stopped glitching after 1-3 cycles and then just sat there doing nothing while leaving a black screen.
After some searching and reading on the forum I changed values of the generated xebuild image with the SMC editor in J-Runner (thanks Martin C):
problem solved, dropped the power/VCS values to 8080 / 8655 in SMC Editor. (Martin C stated 8665, but I used 8655 by accident and it works fine)
http://team-xecuter.com/forums/showthread.php?t=139915&p=957199&viewfull=1#post957199
Final setup:
-DIP Switch 4
-1.2 Volt bridged
SMC Editor:
-Power value 8080
-VCS value 8655
Was the console working before you started: Yes
Console Type: Falcon
NAND size: 16
Dashboard version: 2.0.16537
CB version: 5774
update
updflash.bin log (if applicable):
Code:
base path changed to C:\Users\xx\XBOX 360\~~JTag\~J-Runner\xeBuild
---- { Image Build Mode } ----
building jtag image
<enter> key on completion suppressed
data directory overridden from command line to '16537\'
per build directory overridden from command line to 'data\'
file name overridden from command line to 'C:\Users\xx\XBOX 360\~~JTag\~J-Runner\103339282605\updflash.bin'
------ parsing user ini at 'data\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x1b0 bytes in memory
loading cpukey.txt from data\cpukey.txt
CPU Key set to: 0xXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX (weight:0x35 valid; ecd: valid)
setting 1blkey from ini: 0xXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
1BL Key set to : 0xXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX sum: 0x983 (expects: 0x983)
xex Key set to : 0xXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX sum: 0x800 (expects: 0x800)
Using patchsmc option (ini file)
------ parsing ini at '16537\_jtag.ini' ------
ini version 16537
ini: label [falconbl] found
found (1) 'cb_5770.bin' crc: 0x3279f0d5
found (2) 'cd_5770.bin' crc: 0xd04e8927
found (3) 'ce_1888.bin' crc: 0xff9b60df
found (4) 'cf_4532.bin' crc: 0xd28ef722
found (5) 'cg_4532.bin' crc: 0x2530f8ce
found (6) 'cb_5771.bin' crc: 0x859140f0
found (7) 'cd_8453.bin' crc: 0x25e0acd0
found (8) 'cf_16537.bin' crc: 0xd2f70347
found (9) 'cg_16537.bin' crc: 0xcf8a8c3c
ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x340f017f
found (2) 'bootanim.xex' crc: 0x1a64dd1c
found (3) 'createprofile.xex' crc: 0xbb5dfa34
found (4) 'dash.xex' crc: 0x40671195
found (5) 'deviceselector.xex' crc: 0xf80b066f
found (6) 'gamerprofile.xex' crc: 0xb55d0d4f
found (7) 'hud.xex' crc: 0xd1e27e82
found (8) 'huduiskin.xex' crc: 0x98c75ba1
found (9) 'mfgbootlauncher.xex' crc: 0x773ee67d
found (10) 'minimediaplayer.xex' crc: 0x0411007d
found (11) 'nomni.xexp' crc: 0x323c6e47
found (12) 'nomnifwk.xexp' crc: 0xbe5a4208
found (13) 'nomnifwm.xexp' crc: 0xc9c3f0e0
found (14) 'SegoeXbox-Light.xtt' crc: 0xe0ee6049
found (15) 'signin.xex' crc: 0x4dd243b2
found (16) 'updater.xex' crc: 0xe93cef2e
found (17) 'vk.xex' crc: 0xac383a80
found (18) 'xam.xex' crc: 0x18496d9a
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0xe2adddfb
found (23) 'ximecore.xex' crc: 0xc558548c
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0x4da51d92
found (26) '..\launch.xex' crc: 0x00000000
found (27) '..\lhelper.xex' crc: 0x00000000
found (28) '..\launch.ini' crc: 0x00000000
ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------
output name overridden to: C:\Users\xx\XBOX 360\~~JTag\~J-Runner\103339282605\updflash.bin
1BL RSA pub key file is not available, signature checks will not be performed
PIRS RSA pub key file is not available, signature checks will not be performed
MASTER RSA pub key file is not available, signature checks will not be performed
------ Checking data\nanddump.bin ------
data\nanddump.bin file size: 0x1080000
nanddump header checks passed OK!
Loading NAND dump (0x1080000 bytes)...done!
Detecting NAND controller type from dump data...
NAND dump is from a small block machine
NAND dump uses small block controller
parsing dump into user and spare...
done!
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypted OK, will use if no kv.bin is provided
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0xf7c000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x09 Pairing: 0x207fbe
setting LDV from image to 9
setting pairing data from image to 0x207fbe
pairing set to: 20 7f be
MobileB.dat found at page 0x3800, size 2048 (0x800) bytes
MobileC.dat found at page 0x68c0, size 512 (0x200) bytes
MobileD.dat found at page 0x62c0, size 2048 (0x800) bytes
MobileE.dat found at page 0x3880, size 2048 (0x800) bytes
Statistics.settings found at page 0x7bc0, size 4096 (0x1000) bytes
seeking FSRoot...fsroot found at page 0x3440 raw offset 0x6bc400
seeking security files...
crl.bin found in sector 0x200 size 0xa00...verified! Will use if external file not found.
dae.bin found in sector 0x19c size 0xde60...verified! Will use if external file not found.
extended.bin found in sector 0x34d size 0x4000...verified! Will use if external file not found.
secdata.bin found in sector 0x1a1 size 0x400...verified! Will use if external file not found.
done!
Writing initial header to flash image
------ loading system update container ------
16537\su20076000_00000000 found, loading...done!
Read 0xb34000 bytes to memory
checking integrity...
header seems valid, version 2.0.16537.0
header hash is OK, checking content hashes...
content hashes seem OK, everything looks good!
extracted SUPD\xboxupd.bin (0x7a010 bytes)
decrypting SUPD\xboxupd.bin\CF_16537.bin (0x4560 bytes)...done!
decrypting SUPD\xboxupd.bin\CG_16537.bin (0x75aa2 bytes)...done!
------ Loading bootloaders and required security files ------
could not read 16537\bin\payload.bin, using built in payload (0x200 bytes)
reading data\SMC.bin (0x3000 bytes)
reset smc load address to 0x1000 size 0x3000
reading data\kv.bin failed, using kv.bin from nand dump
reading .\common\cb_5770.bin (0x8e40 bytes)
loaded cb_5770.bin, could not check signature rsa key not present!
reading .\common\cd_5770.bin (0x56c0 bytes)
reading .\common\ce_1888.bin (0x5606a b pad 0x56070 b)
reading .\common\cf_4532.bin (0x44c0 bytes)
reading .\common\cg_4532.bin (0x2ef40 bytes)
extracted SUPD\xboxupd.bin\CF_16537.bin (0x4560 bytes)
extracted SUPD\xboxupd.bin\CG_16537.bin (0x75aa2 bytes)
could not read 16537\bin\freeboot.bin, using built in core (0xd40 bytes)
reading 16537\bin\patches_falcon.bin (0x9d4 bytes)
reading data\xell-2f.bin (0x40000 bytes)
reading .\common\cb_5771.bin (0x9340 bytes)
loaded cb_5771.bin, could not check signature rsa key not present!
reading .\common\cd_8453.bin (0x5780 bytes)
reading data\smc_config.bin failed, using smc_config.bin from nand dump
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu: 80øC Gpu: 75øC Edram: 78øC
Max temps : Cpu: 100øC Gpu: 100øC Edram: 102øC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : 00:1d:d8:5f:ee:e4
AVRegion : 0x00000300 (PAL50)
GameRegion : 0x02fe (PAL/EU)
DVDRegion : 2
resetKey : URDD
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
could not check signature of cb_5770.bin, 1BL RSA key not present!
could not check signature of cb_5771.bin, 1BL RSA key not present!
done!
------ Patching boot reasons and options into flash header ------
Patching header for xell power reason
------ Encrypting and finalizing bootloaders ------
Fuse CPU Key set to: 0xXXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Fuse CF LDV set to : 0xFFFFFFFFF00000000000000000000000
encoding payload.bin size 0x200 (JTAG)
patching payload.bin to load size 0xd40 (0x350 reps)
encoding SMC.bin size 0x3000 (JTAG)
SMC checksum: a6ee8b80
unknown SMC found, type: Jasper v4.1(2.03)
jtag hack found in smc.bin!
******* WARNING: could not patch SMC reset limit!
encoding kv.bin size 0x4000 (JTAG)
decrypted keyvault has been set for reference
Master RSA pub not available, not checking hash
encoding cb_5770.bin size 0x8e40 (JTAG)
CB 5770 seq 0x01050018 type: 0x01 cseq: 0x05 allow: 0x0018
expected fuses:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0F0FF0
fuseset 02: 0000F00000000000 (sequence)
fuseset 02: 000F000000000000 (allow cseq 4)
fuseset 02: 0000F00000000000 (allow cseq 5)
encoding cd_5770.bin size 0x56c0 (JTAG)
encoding ce_1888.bin size 0x56070 (JTAG)
encoding cf_4532.bin size 0x44c0 (JTAG)
encoding cg_4532.bin size 0x2ef40 (JTAG)
encoding cf_16537.bin size 0x4560 (JTAG)
encoding cg_16537.bin size 0x75ab0 (JTAG)
encoding freeboot.bin size 0xd40 (JTAG)
patching freeboot.bin with with kernel version string '16537'
Boot options set:
- console DVD eject button is being used to start xell
- alternate xell button disabled
encoding patches_falcon.bin size 0x9d8 (JTAG)
encoding fuses.bin size 0x60 (JTAG)
encoding xell-2f.bin size 0x40000 (JTAG)
encoding cb_5771.bin size 0x9340 (JTAG)
CB 5771 seq 0x01070058 type: 0x01 cseq: 0x07 allow: 0x0058
expected fuses:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0F0FF0
fuseset 02: 000000F000000000 (sequence)
fuseset 02: 000F000000000000 (allow cseq 4)
fuseset 02: 0000F00000000000 (allow cseq 5)
fuseset 02: 000000F000000000 (allow cseq 7)
CBENC pairing set to: 20 7f be
encoding cd_8453.bin size 0x5780 (JTAG)
Virtual Fuses set to:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0F0FF0
fuseset 02: 000000F000000000
fuseset 03: XXXXXXXXXXXXXXX
fuseset 04: XXXXXXXXXXXXXXX
fuseset 05: XXXXXXXXXXXXXXX
fuseset 06: XXXXXXXXXXXXXXX
fuseset 07: FFFFFFFFF0000000
fuseset 08: 0000000000000000
fuseset 09: 0000000000000000
fuseset 10: 0000000000000000
fuseset 11: 0000000000000000
done!
------ Adding bootloaders to flash image ------
adding payload.bin at raw offset 0x00000200 len 0x200 (end 0x400)
adding SMC.bin at raw offset 0x00001000 len 0x3000 (end 0x4000)
adding kv.bin at raw offset 0x00004000 len 0x4000 (end 0x8000)
adding cb_5770.bin at raw offset 0x00008000 len 0x8e40 (end 0x10e40)
adding cd_5770.bin at raw offset 0x00010e40 len 0x56c0 (end 0x16500)
adding ce_1888.bin at raw offset 0x00016500 len 0x56070 (end 0x6c570)
adding cf_4532.bin at raw offset 0x00070000 len 0x44c0 (end 0x744c0)
adding cg_4532.bin at raw offset 0x000744c0 len 0x2ef40 (end 0x80000, rest in fs)
adding cf_16537.bin at raw offset 0x00080000 len 0x4560 (end 0x84560)
adding cg_16537.bin at raw offset 0x00084560 len 0x75ab0 (end 0x90000, rest in fs)
adding freeboot.bin at raw offset 0x00090000 len 0xd40 (end 0x90d40)
adding patches_falcon.bin at raw offset 0x00091000 len 0x9d8 (end 0x919d8)
adding fuses.bin at raw offset 0x00095000 len 0x60 (end 0x95060)
adding xell-2f.bin at raw offset 0x00095060 len 0x40000 (end 0xd5060)
adding cb_5771.bin at raw offset 0x000d5060 len 0x9340 (end 0xde3a0)
adding cd_8453.bin at raw offset 0x000de3a0 len 0x5780 (end 0xe3b20)
Fixing up FS table...done!
Writing zeropair CG patch slot overflow data to sysupdate.xexp1
at raw offset 0xe4000 len 0x00023400 (end: 0x00107400)...done!
Writing target CG patch slot overflow data to sysupdate.xexp2
at raw offset 0xe4000 len 0x0006a010 (end: 0x0014e010)...done!
------ adding 28 firmware files ------
extracted SUPD\aac.xexp (0x14000 bytes) (crc32: 0x340f017f ini: 0x340f017f)
adding as aac.xexp2 at raw offset 0x172010 len 0x00014000 (end 0x00186010)
extracted SUPD\bootanim.xex (0x61000 bytes) (crc32: 0x1a64dd1c ini: 0x1a64dd1c)
adding as bootanim.xex at raw offset 0x188000 len 0x00061000 (end 0x001e9000)
extracted SUPD\createprofile.xex (0xc000 bytes) (crc32: 0xbb5dfa34 ini: 0xbb5dfa34)
adding as createprofile.xex at raw offset 0x1e9000 len 0x0000c000 (end 0x001f5000)
extracted SUPD\dash.xex (0x597000 bytes) (crc32: 0x40671195 ini: 0x40671195)
adding as dash.xex at raw offset 0x1f8000 len 0x00597000 (end 0x0078f000)
extracted SUPD\deviceselector.xex (0xa000 bytes) (crc32: 0xf80b066f ini: 0xf80b066f)
adding as deviceselector.xex at raw offset 0x78f000 len 0x0000a000 (end 0x00799000)
extracted SUPD\gamerprofile.xex (0x1b000 bytes) (crc32: 0xb55d0d4f ini: 0xb55d0d4f)
adding as gamerprofile.xex at raw offset 0x79a000 len 0x0001b000 (end 0x007b5000)
extracted SUPD\hud.xex (0x1d000 bytes) (crc32: 0xd1e27e82 ini: 0xd1e27e82)
adding as hud.xex at raw offset 0x7b7000 len 0x0001d000 (end 0x007d4000)
extracted SUPD\huduiskin.xex (0x14000 bytes) (crc32: 0x98c75ba1 ini: 0x98c75ba1)
adding as huduiskin.xex at raw offset 0x7d5000 len 0x00014000 (end 0x007e9000)
extracted SUPD\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0x773ee67d ini: 0x773ee67d)
adding as mfgbootlauncher.xex at raw offset 0x7ec000 len 0x00008000 (end 0x007f4000)
extracted SUPD\minimediaplayer.xex (0xc000 bytes) (crc32: 0x0411007d ini: 0x0411007d)
adding as minimediaplayer.xex at raw offset 0x7f4000 len 0x0000c000 (end 0x00800000)
extracted SUPD\nomni.xexp (0xc800 bytes) (crc32: 0x323c6e47 ini: 0x323c6e47)
adding as nomni.xexp2 at raw offset 0x800000 len 0x0000c800 (end 0x0080c800)
extracted SUPD\nomnifwk.xexp (0x2000 bytes) (crc32: 0xbe5a4208 ini: 0xbe5a4208)
adding as nomnifwk.xexp2 at raw offset 0x80c800 len 0x00002000 (end 0x0080e800)
extracted SUPD\nomnifwm.xexp (0x5000 bytes) (crc32: 0xc9c3f0e0 ini: 0xc9c3f0e0)
adding as nomnifwm.xexp2 at raw offset 0x812000 len 0x00005000 (end 0x00817000)
extracted SUPD\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0xe0ee6049 ini: 0xe0ee6049)
adding as SegoeXbox-Light.xtt at raw offset 0x819000 len 0x00006000 (end 0x0081f000)
extracted SUPD\signin.xex (0x19000 bytes) (crc32: 0x4dd243b2 ini: 0x4dd243b2)
adding as signin.xex at raw offset 0x822000 len 0x00019000 (end 0x0083b000)
extracted SUPD\updater.xex (0x7000 bytes) (crc32: 0xe93cef2e ini: 0xe93cef2e)
adding as updater.xex at raw offset 0x83d000 len 0x00007000 (end 0x00844000)
extracted SUPD\vk.xex (0xb000 bytes) (crc32: 0xac383a80 ini: 0xac383a80)
adding as vk.xex at raw offset 0x847000 len 0x0000b000 (end 0x00852000)
extracted SUPD\xam.xex (0x253000 bytes) (crc32: 0x18496d9a ini: 0x18496d9a)
adding as xam.xex at raw offset 0x853000 len 0x00253000 (end 0x00aa6000)
extracted nanddump\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
adding as xenonclatin.xtt at raw offset 0xaa7000 len 0x0011b000 (end 0x00bc2000)
extracted SUPD\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
adding as xenonclatin.xttp2 at raw offset 0xbc3000 len 0x00018000 (end 0x00bdb000)
extracted nanddump\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
adding as xenonjklatin.xtt at raw offset 0xbdc000 len 0x001a8000 (end 0x00d84000)
extracted SUPD\xenonjklatin.xttp (0x7000 bytes) (crc32: 0xe2adddfb ini: 0xe2adddfb)
adding as xenonjklatin.xttp2 at raw offset 0xd84000 len 0x00007000 (end 0x00d8b000)
extracted SUPD\ximecore.xex (0x17000 bytes) (crc32: 0xc558548c ini: 0xc558548c)
adding as ximecore.xex at raw offset 0xd8b000 len 0x00017000 (end 0x00da2000)
extracted nanddump\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
adding as ximedic.xex at raw offset 0xda3000 len 0x00090000 (end 0x00e33000)
extracted SUPD\ximedic.xexp (0x2800 bytes) (crc32: 0x4da51d92 ini: 0x4da51d92)
adding as ximedic.xexp2 at raw offset 0xe34000 len 0x00002800 (end 0x00e36800)
reading 16537\..\launch.xex (0xc800 bytes)
adding as launch.xex at raw offset 0xe36800 len 0x0000c800 (end 0x00e43000)
reading 16537\..\lhelper.xex (0x6000 bytes)
adding as lhelper.xex at raw offset 0xe44800 len 0x00006000 (end 0x00e4a800)
reading 16537\..\launch.ini (0x165 bytes)
adding as launch.ini at raw offset 0xe4e000 len 0x00000165 (end 0x00e4e165)
------ adding 4 security files ------
<- Processing crl.bin ->
reading data\crl.bin (0xa00 bytes)
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
adding as crl.bin at raw offset 0xe54000 len 0x00000a00 (end 0x00e54a00)
<- Processing dae.bin ->
reading data\dae.bin (0xad30 bytes)
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
adding as dae.bin at raw offset 0xe58000 len 0x0000ad30 (end 0x00e62d30)
<- Processing extended.bin ->
reading data\extended.bin (0x4000 bytes)
adding as extended.bin at raw offset 0xe64000 len 0x00004000 (end 0x00e68000)
<- Processing secdata.bin ->
reading data\secdata.bin (0x400 bytes)
adding as secdata.bin at raw offset 0xe68000 len 0x00000400 (end 0x00e68400)
------ checking for Mobile*.dat ------
MobileB.dat found, adding from previous parse
adding MobileB.dat as type 0x31 at raw offset 0xe6c000 len 0x800 (end 0xe6c800)
MobileC.dat found, adding from previous parse
adding MobileC.dat as type 0x32 at raw offset 0xe70000 len 0x200 (end 0xe70200)
MobileD.dat found, adding from previous parse
adding MobileD.dat as type 0x33 at raw offset 0xe74000 len 0x800 (end 0xe74800)
MobileE.dat found, adding from previous parse
adding MobileE.dat as type 0x34 at raw offset 0xe78000 len 0x800 (end 0xe78800)
Statistics.settings found, adding from previous parse
adding Statistics.settings at raw offset 0xf78000 len 0x1000 (end 0xf79000)
------ adding smc_config.bin ------
adding smc config to offset 0x00f7c000, len 0x400
------ finalizing image ------
Fixing up empty FS block entries...done!
Writing FS table to image offset 0xe7c000 len 0x4000 (end 0xe80000)...done!
calculating ECD bytes and assembling raw image...done!
done remapping!
------ writing image to disk ------
writing file 'C:\Users\xx\XBOX 360\~~JTag\~J-Runner\103339282605\updflash.bin' to disk...done!
---------------------------------------------------------------
C:\Users\xx\XBOX 360\~~JTag\~J-Runner\103339282605\updflash.bin image built, info:
---------------------------------------------------------------
Kernel : 2.0.16537.0
Console : Falcon
NAND size : 16MiB
Build : JTAG
Xell : power on console with console eject button
Serial : XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
ConsoleId : XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
MoboSerial: XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
Mfg Date : XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
CPU Key : XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
1BL Key : XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
DVD Key : XXXXXXXXXXXXXXXXXXXXXXXXXXXXXX
CF LDV : 9
KV type : type2 (hashed - unchecked, master key not available)
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------
Screenshot of NAND details from J-Runner:

J-Runner log:
Code:
===================================================
zaterdag 23 november 2013 15:46:23
J-Runner v0.3 Beta (2) Started
Anyone offering hosting servers with unlimited speeds/traffic at good prices (or free :P), pm me on #J-Runner EFnet
Checking Files
Finished Checking Files
Version: 03
Flash Config: 0x01198010
01198010
Xenon, Zephyr, Opus, Falcon
CB Version: 5774
Falcon/Opus
Reading Nand to C:\Users\xx\XBOX 360\~~JTag\~J-Runner\output\nanddump1.bin
Reading Nand
Done!
in 2:11 min:sec
Reading Nand to C:\Users\xx\XBOX 360\~~JTag\~J-Runner\output\nanddump2.bin
Initializing nanddump1.bin..
Reading Nand
Falcon/Opus
Jtag Selected
Nand Initialization Finished
Done!
in 2:12 min:sec
Comparing...
Nands are the same
R-Jtag Selected
Aud_Clamp Selected
Patching Jasper version 2.3 SMC at offset 0x12BA
XeLL file created Successfully falcon_hack_aud_clamp.bin
Version: 03
Flash Config: 0x01198010
Writing Nand
falcon_hack_aud_clamp.bin
Done!
in 0:10 min:sec
dont have JRP v2 (NAND-X & JRP v1)
Image of R-JTAG board:

Images of close-up soldering to motherboard:



(thanks to chase I found out there was a small crack in the QSB on the top left corner, see red circle)Description of problem:
UPDATE:Console doesn't boot to Xell or at all. Keeps blinking and tries to glitch, but never glitches. Sometimes I get 2 consecutive green beeps immediately after eachother. Tried all DIP switch settings (1-6 + 7) and tried voltages. Nothing seems to work.
I fixed the QSB problem by cutting off the top half and solderered wires directly to the POST points

I finally managed to extract the CPU key and wrote a patched nand to the console. DIP switch 3 did the trick..
Then I ran into another problem.
The console only booted to Xell (using the eject button) in 1-2 cycles everytime so the glitching went fine.
The problem was that my console didn't boot to dash. Everytime I used the power button to boot the console, it stopped glitching after 1-3 cycles and then just sat there doing nothing while leaving a black screen.
After some searching and reading on the forum I changed values of the generated xebuild image with the SMC editor in J-Runner (thanks Martin C):
problem solved, dropped the power/VCS values to 8080 / 8655 in SMC Editor. (Martin C stated 8665, but I used 8655 by accident and it works fine)
http://team-xecuter.com/forums/showthread.php?t=139915&p=957199&viewfull=1#post957199
Final setup:
-DIP Switch 4
-1.2 Volt bridged
SMC Editor:
-Power value 8080
-VCS value 8655
Was the console working before you started: Yes
Attachments
-
549.2 KB Views: 77
Last edited: