Flashed Falcon now no power

djob1981

Full Member
Dec 5, 2011
39
0
Ok i got the xell dash then used the usb pen with the new glitched nand file from multibuilder 0.7, xell flashed it turned the xbox off as per the guide biot now i get no power when i try to turn it on the CR has a red light so i know the board is getting power but wont turn on at all
 

djob1981

Full Member
Dec 5, 2011
39
0
cant get the nand to flash back at all
keep getting looking for usb device which makes me think either my wires are bad for the nand x or i have a bigger problem

---------- Post added at 08:06 ---------- Previous post was at 07:56 ----------

---------------------------------------------------------------
xeBuild v1.00.356
---------------------------------------------------------------
building glitch image
per build directory overridden from command line to 'my360'
data directory overridden from command line to '14699'
Using PATCHSMC option
file name overridden from command line to 'nandflash.bin'

------ parsing user ini at '.\my360\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x14b bytes in memory
loading cpukey.txt from .\my360\cpukey.txt
CPU Key set to: 0x934E8CB7528EBE30D34AEC4929A76A74
setting 1blkey from ini: 0xDD88AD0C9ED669E7B56794FB68563EFA
1BL Key set to: 0xDD88AD0C9ED669E7B56794FB68563EFA sum: 0x983 (expects: 0x983)
xex Key set to: 0x20B185A59D28FDC340583FBB0896BF91 sum: 0x800 (expects: 0x800)

------ parsing ini at '.\14699\_glitch.ini' ------
ini version 14699

ini: label [falconbl] found
found (1) 'cb_5771.bin' crc: 0x859140f0
found (2) 'none' crc: 0x00000000
found (3) 'cd_8453.bin' crc: 0x25e0acd0
found (4) 'ce_1888.bin' crc: 0xff9b60df
found (5) 'cf_14699.bin' crc: 0x6fb4d90e
found (6) 'cg_14699.bin' crc: 0xbccc9fe1

ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x36790e61
found (2) 'bootanim.xex' crc: 0x187ede71
found (3) 'createprofile.xex' crc: 0x81d7a946
found (4) 'dash.xex' crc: 0x3957764c
found (5) 'deviceselector.xex' crc: 0x6246b4c0
found (6) 'gamerprofile.xex' crc: 0xb7add96a
found (7) 'hud.xex' crc: 0x202eb5c8
found (8) 'huduiskin.xex' crc: 0x4c80fbe9
found (9) 'mfgbootlauncher.xex' crc: 0x254ad664
found (10) 'minimediaplayer.xex' crc: 0xd8d21cfc
found (11) 'nomni.xexp' crc: 0xbf36fdf7
found (12) 'nomnifwk.xexp' crc: 0xa837ae53
found (13) 'nomnifwm.xexp' crc: 0x93246a8a
found (14) 'SegoeXbox-Light.xtt' crc: 0x086eb344
found (15) 'signin.xex' crc: 0xecd9cab1
found (16) 'updater.xex' crc: 0x125cdb94
found (17) 'vk.xex' crc: 0x9c744d4c
found (18) 'xam.xex' crc: 0x0b764b88
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0x945b7092
found (23) 'ximecore.xex' crc: 0x8d45ea14
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0xc90a651a
found (26) 'launch.xex' crc: 0x9f94f79b
found (27) 'lhelper.xex' crc: 0xeb581eb5
found (28) 'launch.ini' crc: 0x00000000

ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------

output name overridden to: nandflash.bin


------ Checking .\my360\nanddump.bin ------
Loading NAND dump (0x22ee70 bytes)...done!
NAND dump is from a small block machine
NAND dump uses small block controller
parsing dump into user and spare...
done!
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypt failed, discarding
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0xf7c000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x0d Pairing: 0x5f2856
CF slot 1 decrypted ok LDV 0x0e Pairing: 0x5f2856
setting LDV from image to 14
setting pairing data from image to 0x5f2856
MobileB.dat found at page 0x77a0, size 2048 (0x800) bytes
MobileC.dat found at page 0x42c0, size 512 (0x200) bytes
MobileD.dat found at page 0x4e0, size 2048 (0x800) bytes
MobileE.dat found at page 0x23c0, size 2048 (0x800) bytes
seeking security files...fsroot found at page 0x71e0 raw offset 0xeade00
crl.bin found in sector 0x43 size 0xa00...verify failed! Discarding data.
dae.bin found in sector 0x120 size 0x7090...
******* ERROR: dae hash incorrect, could not decrypt!
verify failed! Discarding data.
extended.bin found in sector 0x12a size 0x4000...verify failed! Discarding data.
secdata.bin found in sector 0x3d size 0x400...verify failed! Discarding data.
Writing initial header to flash image

------ Loading bootloaders and required security files ------
reading .\my360\smc.bin failed, using smc.bin from nand dump
reading .\my360\keyvault.bin (0x4000 bytes)
reading .\14699\cb_5771.bin (0x9340 bytes)
reading .\14699\cd_8453.bin (0x5780 bytes)
reading .\14699\ce_1888.bin (0x5606a b pad 0x56070 b)
reading .\my360\xell-gggggg.bin (0x40000 bytes)
reading .\14699\cf_14699.bin (0x4450 bytes)
reading .\14699\cg_14699.bin (0x67168 b pad 0x67170 b)
reading .\14699\bin\patches_fat.bin (0x6f0 bytes)
reading .\my360\smc_config.bin failed, using smc_config.bin from nand dump
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu: 80øC Gpu: 75øC Edram: 78øC
Max temps : Cpu: 100øC Gpu: 100øC Edram: 102øC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : 00:12:5a:c7:b3:9d
AVRegion : 0x00000300 (PAL50)
GameRegion : 0x02fe (NTSC/EU)
DVDRegion : 2
resetKey : YLXR
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
done!

------ Encrypting and finalizing bootloaders ------
SMC checksum: b92ed1ba
unknown SMC found, type: Xenon v1.2(1.51)
patching smc at offset: 0x1180
SMC hacked successfully
done!

------ Adding bootloaders to flash image ------
adding smc.bin to 0x00001000 len 0x3000
adding kv.bin to 0x00004000 len 0x4000
adding cb_5771.bin to 0x00008000 len 0x9340
adding none to 0x00011340 len 0x0
adding cd_8453.bin to 0x00011340 len 0x5a60
adding ce_1888.bin to 0x00016da0 len 0x56070
adding xell-gggggg.bin to 0x00070000 len 0x40000
adding cf_14699.bin to 0x000b0000 len 0x4450
adding cg_14699.bin to 0x000b4450 len 0x67170
adding patches_fat.bin to 0x000c0010 len 0x3e0
Fixing up FS table...done!
Writing CG patch slot overflow data to sysupdate.xexp1...done!

------ adding 28 firmware files ------
reading .\14699\aac.xexp (0x14000 bytes) (crc32: 0x36790e61 ini: 0x36790e61)
adding as aac.xexp1 at raw offset 0x12b5c0
reading .\14699\bootanim.xex (0x61000 bytes) (crc32: 0x187ede71 ini: 0x187ede71)
adding as bootanim.xex at raw offset 0x140000
reading .\14699\createprofile.xex (0xc000 bytes) (crc32: 0x81d7a946 ini: 0x81d7a946)
adding as createprofile.xex at raw offset 0x1a1000
reading .\14699\dash.xex (0x63a000 bytes) (crc32: 0x3957764c ini: 0x3957764c)
adding as dash.xex at raw offset 0x1b0000
reading .\14699\deviceselector.xex (0x9000 bytes) (crc32: 0x6246b4c0 ini: 0x6246b4c0)
adding as deviceselector.xex at raw offset 0x7ea000
reading .\14699\gamerprofile.xex (0x1b000 bytes) (crc32: 0xb7add96a ini: 0xb7add96a)
adding as gamerprofile.xex at raw offset 0x7f5000
reading .\14699\hud.xex (0x1e000 bytes) (crc32: 0x202eb5c8 ini: 0x202eb5c8)
adding as hud.xex at raw offset 0x813000
reading .\14699\huduiskin.xex (0x13000 bytes) (crc32: 0x4c80fbe9 ini: 0x4c80fbe9)
adding as huduiskin.xex at raw offset 0x832000
reading .\14699\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0x254ad664 ini: 0x254ad664)
adding as mfgbootlauncher.xex at raw offset 0x847000
reading .\14699\minimediaplayer.xex (0xc000 bytes) (crc32: 0xd8d21cfc ini: 0xd8d21cfc)
adding as minimediaplayer.xex at raw offset 0x850000
reading .\14699\nomni.xexp (0xe000 bytes) (crc32: 0xbf36fdf7 ini: 0xbf36fdf7)
adding as nomni.xexp1 at raw offset 0x85c000
reading .\14699\nomnifwk.xexp (0x2000 bytes) (crc32: 0xa837ae53 ini: 0xa837ae53)
adding as nomnifwk.xexp1 at raw offset 0x86a000
reading .\14699\nomnifwm.xexp (0x5000 bytes) (crc32: 0x93246a8a ini: 0x93246a8a)
adding as nomnifwm.xexp1 at raw offset 0x86e000
reading .\14699\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0x086eb344 ini: 0x086eb344)
adding as SegoeXbox-Light.xtt at raw offset 0x875000
reading .\14699\signin.xex (0x16000 bytes) (crc32: 0xecd9cab1 ini: 0xecd9cab1)
adding as signin.xex at raw offset 0x87e000
reading .\14699\updater.xex (0x7000 bytes) (crc32: 0x125cdb94 ini: 0x125cdb94)
adding as updater.xex at raw offset 0x896000
reading .\14699\vk.xex (0x9000 bytes) (crc32: 0x9c744d4c ini: 0x9c744d4c)
adding as vk.xex at raw offset 0x89f000
reading .\14699\xam.xex (0x236000 bytes) (crc32: 0x0b764b88 ini: 0x0b764b88)
adding as xam.xex at raw offset 0x8a9000
reading .\14699\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
adding as xenonclatin.xtt at raw offset 0xae2000
reading .\14699\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
adding as xenonclatin.xttp1 at raw offset 0xbff000
reading .\14699\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
adding as xenonjklatin.xtt at raw offset 0xc18000
reading .\14699\xenonjklatin.xttp (0x7000 bytes) (crc32: 0x945b7092 ini: 0x945b7092)
adding as xenonjklatin.xttp1 at raw offset 0xdc0000
reading .\14699\ximecore.xex (0x15000 bytes) (crc32: 0x8d45ea14 ini: 0x8d45ea14)
adding as ximecore.xex at raw offset 0xdc7000
reading .\14699\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
adding as ximedic.xex at raw offset 0xddd000
reading .\14699\ximedic.xexp (0x2800 bytes) (crc32: 0xc90a651a ini: 0xc90a651a)
adding as ximedic.xexp1 at raw offset 0xe70000
reading .\14699\launch.xex (0x9000 bytes) (crc32: 0x9f94f79b ini: 0x9f94f79b)
adding as launch.xex at raw offset 0xe72800
reading .\14699\lhelper.xex (0x6000 bytes) (crc32: 0xeb581eb5 ini: 0xeb581eb5)
adding as lhelper.xex at raw offset 0xe7d000
reading .\14699\launch.ini (0x29e bytes)
adding as launch.ini at raw offset 0xe86000

------ adding 4 security files ------
reading .\my360\crl.bin (0xa00 bytes)
writing as crl.bin to flash
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
reading .\my360\dae.bin (0xad30 bytes)
writing as dae.bin to flash
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
reading .\my360\extended.bin (0x4000 bytes)
writing as extended.bin to flash
reading .\my360\secdata.bin (0x400 bytes)
writing as secdata.bin to flash

------ checking for Mobile*.dat ------
MobileB.dat was found in dump, 0x800 bytes, adding type 0x31
MobileC.dat was found in dump, 0x200 bytes, adding type 0x32
MobileD.dat was found in dump, 0x800 bytes, adding type 0x33
MobileE.dat was found in dump, 0x800 bytes, adding type 0x34

------ adding smc_config.bin ------
adding smc config to offset 0x00f7c000, len 0x400

------ finalizing image ------
Fixing up empty FS block entries...done!
Writing FS table to image...done!
calculating ECD bytes and assembling raw image...done!
writing file 'nandflash.bin' to disk...done!
nandflash.bin written OK

---------------------------------------------------------------
nandflash.bin image built, info:
---------------------------------------------------------------
Console : Falcon
NAND size: 16MiB
Build : Glitch
Xell : power on console with console eject button
CPU Key : 934E8CB7528EBE30D34AEC4929A76A74
1BL Key : DD88AD0C9ED669E7B56794FB68563EFA
CF LDV : 14
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------
 

djob1981

Full Member
Dec 5, 2011
39
0
Everything looks ok - have you touched anything inside between writing it and powering on?

Can you post a pic of your soldering from point B?

I have removed the coolrunner to see if that was the fault
i was using QSB for the coolrunner if that helps
 

Martin C

VIP Member
Jan 10, 2004
35,981
0
Scotland, UK
www.team-xecuter.com
if you've broken a trace on point B then removing the coolrunner won't help.

It's either a damaged trace/resistor on point B

or

Your NAND has a corrupt SMC.

Check out point B first.
 

Martin C

VIP Member
Jan 10, 2004
35,981
0
Scotland, UK
www.team-xecuter.com
if you're happy that nothing was messed with, then it's not point B. If you have a meter, you can put it either side of the resistor to the right of the solder point and it should read 33-40ohms. Any more and it's a blown resistor.
 

Martin C

VIP Member
Jan 10, 2004
35,981
0
Scotland, UK
www.team-xecuter.com
So you just want to make sure you have continuity now between the leftmost part of the resistor and the trace coming away from the point. I think there's an alt. point on the bottom of the board for it.
 

djob1981

Full Member
Dec 5, 2011
39
0
Fixed it, i had to short out all the wires on both the left and right hand side of the nand so i can now read and write back to the nand