I tried creating my first FreeBoot with 13599 dash following a popular tutorial for that specifies dash 12611 but using the 13599 files, however the update failed.
After creating the updflash.bin and flashing it the console just turned on and did nothing. Right now I am flashing back to 13146 with JTAG Tool but I was wondering if someone could help me? I have never used FreeBoot before and I am a bit lost.
Here is what I did. I got the original 7371 nand and put it in 360 flash tool to extract the information and files required, following the tutorial. I put the 13599 files in the directory specified, and created the freeboot. After that I updated it via Flash360 on the XBOX. After that, XBOX did not boot.
The unit is a Falcon, using DB1F1 and ROL. If someone could help me with a custom mini guide or something I would greatly appreciate it.
EDIT: I decided to redo the FB and it went OK, here is my log.
Also, I was thinking. I am using the freeboot image 13146 I made with JTAG Tool, but I see in the log "could not find Xell", so I am thinking that I need to Write Xell(ous), Write FB 13146 with JTAG Tool, then Read that Nand, then create the new FB 13599 based on the 13146 FB dump, is this the way I should do it?
LOG WITH 13146 FB Created with JTAG Tool (not 13146/xellous dump)
---------------------------------------------------------------
fbBuild v0.32
---------------------------------------------------------------
per build directory overridden from command line to 'mydata'
file name overridden from command line to 'updflash.bin'
------ parsing user ini at '.\mydata\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x13a bytes in memory
loading cpukey.txt from .\mydata\cpukey.txt
CPU Key set to: 0xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
loading 1blkey.txt from 1blkey.txt
1BL Key set to: 0xDD88AD0C9ED669E7B56794FB68563EFA sum: 0x983 (expects: 0x983)
Using nonandmu option (ini file)
------ Checking .\mydata\nanddump.bin ------
NAND dump not found at '.\mydata\nanddump.bin'
------ parsing ini at '.\data\filelist.ini' ------
ini version 13599
ini: label [falconbl] found
found (1) 'cb_5770.bin' crc: 0x3279f0d5
found (2) 'cd_5770.bin' crc: 0xd04e8927
found (3) 'ce_1888.bin' crc: 0xff9b60df
found (4) 'cf_4532.bin' crc: 0xd28ef722
found (5) 'cg_4532.bin' crc: 0x2cc9b951
found (6) 'cb_5771.bin' crc: 0x859140f0
found (7) 'cd_8453.bin' crc: 0x25e0acd0
found (8) 'cf_13599.bin' crc: 0x15a4ae66
found (9) 'cg_13599.bin' crc: 0x8d643839
ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0xa622262f
found (2) 'bootanim.xex' crc: 0x5ebaa67f
found (3) 'createprofile.xex' crc: 0xf53f0259
found (4) 'dash.xex' crc: 0x0377a5b8
found (5) 'deviceselector.xex' crc: 0xa5da5863
found (6) 'gamerprofile.xex' crc: 0x9b97b30f
found (7) 'hud.xex' crc: 0x3bd83963
found (8) 'huduiskin.xex' crc: 0xf7c69840
found (9) 'mfgbootlauncher.xex' crc: 0xf4d1be33
found (10) 'minimediaplayer.xex' crc: 0xcbd3e4a6
found (11) 'nomni.xexp' crc: 0x8099a6af
found (12) 'nomnifwk.xexp' crc: 0x43d15042
found (13) 'nomnifwm.xexp' crc: 0x6c1f328e
found (14) 'signin.xex' crc: 0x013749fb
found (15) 'updater.xex' crc: 0x0d0d3f84
found (16) 'vk.xex' crc: 0xc3707c11
found (17) 'xam.xex' crc: 0x35c77172
found (18) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (19) 'xenonclatin.xttp' crc: 0x7a507ad1
found (20) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (21) 'xenonjklatin.xttp' crc: 0x945b7092
found (22) 'ximecore.xex' crc: 0xa49f0061
found (23) 'ximedic.xex' crc: 0x1d992bfb
found (24) 'ximedic.xexp' crc: 0xf67612f5
found (25) '..\launch.xex' crc: 0x00000000
found (26) '..\lhelper.xex' crc: 0x00000000
ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------
output name overridden to: updflash.bin
Writing initial header to flash image
------ Loading bootloaders and required security files ------
could not read \bin\payload.bin, using built in payload (0x200 bytes)
reading .\mydata\smc.bin (0x3000 bytes)
reading .\mydata\kv.bin (0x4000 bytes)
reading .\data\cb_5770.bin (0x8e40 bytes) (crc32: 0x3279f0d5 ini: 0x3279f0d5)
reading .\data\cd_5770.bin (0x56c0 bytes) (crc32: 0xd04e8927 ini: 0xd04e8927)
reading .\data\ce_1888.bin (0x5606a b pad 0x56070 b) (crc32: 0xff9b60df ini: 0xff9b60df)
reading .\data\cf_4532.bin (0x44c0 bytes) (crc32: 0xd28ef722 ini: 0xd28ef722)
reading .\data\cg_4532.bin (0x2ef40 bytes) (crc32: 0x2cc9b951 ini: 0x2cc9b951)
reading .\data\cf_13599.bin (0x4450 bytes) (crc32: 0x15a4ae66 ini: 0x15a4ae66)
reading .\data\cg_13599.bin (0x6590e b pad 0x65910 b) (crc32: 0x8d643839 ini: 0x8d643839)
could not read \bin\freeboot.bin, using built in core (0xd50 bytes)
reading .\bin\patches_falcon.bin (0x938 bytes)
**** ldv line 3 set to 00 f0 type: 3
xell not found in perbuild directory, checking firmware /bin folder
xell not found in firmware /bin folder, checking base path
reading xell-2f.bin (0x38a60 bytes)
reading .\data\cb_5771.bin (0x9340 bytes) (crc32: 0x859140f0 ini: 0x859140f0)
reading .\data\cd_8453.bin (0x5780 bytes) (crc32: 0x25e0acd0 ini: 0x25e0acd0)
reading .\mydata\smc_config.bin (0x4000 bytes)
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu: 80øC Gpu: 75øC Edram: 78øC
Max temps : Cpu: 100øC Gpu: 100øC Edram: 102øC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : 00:1d:d8:1d:f9:07
AVRegion : 0x00000100 (NTSC-M)
GameRegion : 0x00ff (NTSC/US)
DVDRegion : 1
resetKey : XDLL
---------------------
Checking ini for smc config data patches
smc patched with ini values
---------------------
SMC patched info:
------------------
Target temps: Cpu: 80øC Gpu: 75øC Edram: 78øC
Max temps : Cpu: 100øC Gpu: 100øC Edram: 102øC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : 00:1d:d8:1d:f9:07
AVRegion : 0x00000100 (NTSC-M)
GameRegion : 0x00ff (NTSC/US)
DVDRegion : 0
resetKey : XDLL
---------------------
done!
------ Encrypting and finalizing bootloaders ------
patching payload.bin to load size 0xd50 (0x354 reps)
hack found in smc.bin!
done!
------ Adding bootloaders to flash image ------
Fixing up FS table...done!
Writing zeropair CG patch slot overflow data to sysupdate.xexp1...done!
Writing target CG patch slot overflow data to sysupdate.xexp2...done!
------ adding 26 firmware files ------
reading .\data\aac.xexp (0x4800 bytes) (crc32: 0xa622262f ini: 0xa622262f)
reading .\data\bootanim.xex (0x55000 bytes) (crc32: 0x5ebaa67f ini: 0x5ebaa67f)
reading .\data\createprofile.xex (0xc000 bytes) (crc32: 0xf53f0259 ini: 0xf53f0259)
reading .\data\dash.xex (0x5e9000 bytes) (crc32: 0x0377a5b8 ini: 0x0377a5b8)
reading .\data\deviceselector.xex (0x9000 bytes) (crc32: 0xa5da5863 ini: 0xa5da5863)
reading .\data\gamerprofile.xex (0x1a000 bytes) (crc32: 0x9b97b30f ini: 0x9b97b30f)
reading .\data\hud.xex (0x1f000 bytes) (crc32: 0x3bd83963 ini: 0x3bd83963)
reading .\data\huduiskin.xex (0x11000 bytes) (crc32: 0xf7c69840 ini: 0xf7c69840)
reading .\data\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0xf4d1be33 ini: 0xf4d1be33)
reading .\data\minimediaplayer.xex (0xc000 bytes) (crc32: 0xcbd3e4a6 ini: 0xcbd3e4a6)
reading .\data\nomni.xexp (0xd000 bytes) (crc32: 0x8099a6af ini: 0x8099a6af)
reading .\data\nomnifwk.xexp (0x2000 bytes) (crc32: 0x43d15042 ini: 0x43d15042)
reading .\data\nomnifwm.xexp (0x5000 bytes) (crc32: 0x6c1f328e ini: 0x6c1f328e)
reading .\data\signin.xex (0x12000 bytes) (crc32: 0x013749fb ini: 0x013749fb)
reading .\data\updater.xex (0x8000 bytes) (crc32: 0x0d0d3f84 ini: 0x0d0d3f84)
reading .\data\vk.xex (0x9000 bytes) (crc32: 0xc3707c11 ini: 0xc3707c11)
reading .\data\xam.xex (0x217000 bytes) (crc32: 0x35c77172 ini: 0x35c77172)
reading .\data\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
reading .\data\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
reading .\data\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
reading .\data\xenonjklatin.xttp (0x7000 bytes) (crc32: 0x945b7092 ini: 0x945b7092)
reading .\data\ximecore.xex (0x15000 bytes) (crc32: 0xa49f0061 ini: 0xa49f0061)
reading .\data\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
reading .\data\ximedic.xexp (0x2800 bytes) (crc32: 0xf67612f5 ini: 0xf67612f5)
***** could not read .\data\..\launch.xex, skipping *****
***** could not read .\data\..\lhelper.xex, skipping *****
------ adding 4 security files ------
reading .\mydata\crl.bin (0x9e0 bytes)
writing as crl.bin to flash
reading .\mydata\dae.bin (0xad30 bytes)
writing as dae.bin to flash
reading .\mydata\extended.bin (0x4000 bytes)
writing as extended.bin to flash
reading .\mydata\secdata.bin (0x400 bytes)
writing as secdata.bin to flash
------ checking for Mobile*.dat ------
------ adding smc_config.bin ------
------ finalizing image ------
Fixing up empty FS block entries...done!
Writing FS table to image...done!
calculating ECD bytes and assembling raw image...done!
writing file 'updflash.bin' to disk...done!
updflash.bin written OK
---------------------------------------------------------------
updflash.bin built, info:
---------------------------------------------------------------
console : falcon
NAND size: 16MiB
xell : power on console with console eject button
CPU Key : xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
1BL Key : DD88AD0C9ED669E7B56794FB68563EFA
---------------------------------------------------------------
fbBuild Finished. Have a nice day.
---------------------------------------------------------------
After creating the updflash.bin and flashing it the console just turned on and did nothing. Right now I am flashing back to 13146 with JTAG Tool but I was wondering if someone could help me? I have never used FreeBoot before and I am a bit lost.
Here is what I did. I got the original 7371 nand and put it in 360 flash tool to extract the information and files required, following the tutorial. I put the 13599 files in the directory specified, and created the freeboot. After that I updated it via Flash360 on the XBOX. After that, XBOX did not boot.
The unit is a Falcon, using DB1F1 and ROL. If someone could help me with a custom mini guide or something I would greatly appreciate it.
EDIT: I decided to redo the FB and it went OK, here is my log.
Also, I was thinking. I am using the freeboot image 13146 I made with JTAG Tool, but I see in the log "could not find Xell", so I am thinking that I need to Write Xell(ous), Write FB 13146 with JTAG Tool, then Read that Nand, then create the new FB 13599 based on the 13146 FB dump, is this the way I should do it?
LOG WITH 13146 FB Created with JTAG Tool (not 13146/xellous dump)
---------------------------------------------------------------
fbBuild v0.32
---------------------------------------------------------------
per build directory overridden from command line to 'mydata'
file name overridden from command line to 'updflash.bin'
------ parsing user ini at '.\mydata\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x13a bytes in memory
loading cpukey.txt from .\mydata\cpukey.txt
CPU Key set to: 0xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
loading 1blkey.txt from 1blkey.txt
1BL Key set to: 0xDD88AD0C9ED669E7B56794FB68563EFA sum: 0x983 (expects: 0x983)
Using nonandmu option (ini file)
------ Checking .\mydata\nanddump.bin ------
NAND dump not found at '.\mydata\nanddump.bin'
------ parsing ini at '.\data\filelist.ini' ------
ini version 13599
ini: label [falconbl] found
found (1) 'cb_5770.bin' crc: 0x3279f0d5
found (2) 'cd_5770.bin' crc: 0xd04e8927
found (3) 'ce_1888.bin' crc: 0xff9b60df
found (4) 'cf_4532.bin' crc: 0xd28ef722
found (5) 'cg_4532.bin' crc: 0x2cc9b951
found (6) 'cb_5771.bin' crc: 0x859140f0
found (7) 'cd_8453.bin' crc: 0x25e0acd0
found (8) 'cf_13599.bin' crc: 0x15a4ae66
found (9) 'cg_13599.bin' crc: 0x8d643839
ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0xa622262f
found (2) 'bootanim.xex' crc: 0x5ebaa67f
found (3) 'createprofile.xex' crc: 0xf53f0259
found (4) 'dash.xex' crc: 0x0377a5b8
found (5) 'deviceselector.xex' crc: 0xa5da5863
found (6) 'gamerprofile.xex' crc: 0x9b97b30f
found (7) 'hud.xex' crc: 0x3bd83963
found (8) 'huduiskin.xex' crc: 0xf7c69840
found (9) 'mfgbootlauncher.xex' crc: 0xf4d1be33
found (10) 'minimediaplayer.xex' crc: 0xcbd3e4a6
found (11) 'nomni.xexp' crc: 0x8099a6af
found (12) 'nomnifwk.xexp' crc: 0x43d15042
found (13) 'nomnifwm.xexp' crc: 0x6c1f328e
found (14) 'signin.xex' crc: 0x013749fb
found (15) 'updater.xex' crc: 0x0d0d3f84
found (16) 'vk.xex' crc: 0xc3707c11
found (17) 'xam.xex' crc: 0x35c77172
found (18) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (19) 'xenonclatin.xttp' crc: 0x7a507ad1
found (20) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (21) 'xenonjklatin.xttp' crc: 0x945b7092
found (22) 'ximecore.xex' crc: 0xa49f0061
found (23) 'ximedic.xex' crc: 0x1d992bfb
found (24) 'ximedic.xexp' crc: 0xf67612f5
found (25) '..\launch.xex' crc: 0x00000000
found (26) '..\lhelper.xex' crc: 0x00000000
ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------
output name overridden to: updflash.bin
Writing initial header to flash image
------ Loading bootloaders and required security files ------
could not read \bin\payload.bin, using built in payload (0x200 bytes)
reading .\mydata\smc.bin (0x3000 bytes)
reading .\mydata\kv.bin (0x4000 bytes)
reading .\data\cb_5770.bin (0x8e40 bytes) (crc32: 0x3279f0d5 ini: 0x3279f0d5)
reading .\data\cd_5770.bin (0x56c0 bytes) (crc32: 0xd04e8927 ini: 0xd04e8927)
reading .\data\ce_1888.bin (0x5606a b pad 0x56070 b) (crc32: 0xff9b60df ini: 0xff9b60df)
reading .\data\cf_4532.bin (0x44c0 bytes) (crc32: 0xd28ef722 ini: 0xd28ef722)
reading .\data\cg_4532.bin (0x2ef40 bytes) (crc32: 0x2cc9b951 ini: 0x2cc9b951)
reading .\data\cf_13599.bin (0x4450 bytes) (crc32: 0x15a4ae66 ini: 0x15a4ae66)
reading .\data\cg_13599.bin (0x6590e b pad 0x65910 b) (crc32: 0x8d643839 ini: 0x8d643839)
could not read \bin\freeboot.bin, using built in core (0xd50 bytes)
reading .\bin\patches_falcon.bin (0x938 bytes)
**** ldv line 3 set to 00 f0 type: 3
xell not found in perbuild directory, checking firmware /bin folder
xell not found in firmware /bin folder, checking base path
reading xell-2f.bin (0x38a60 bytes)
reading .\data\cb_5771.bin (0x9340 bytes) (crc32: 0x859140f0 ini: 0x859140f0)
reading .\data\cd_8453.bin (0x5780 bytes) (crc32: 0x25e0acd0 ini: 0x25e0acd0)
reading .\mydata\smc_config.bin (0x4000 bytes)
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu: 80øC Gpu: 75øC Edram: 78øC
Max temps : Cpu: 100øC Gpu: 100øC Edram: 102øC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : 00:1d:d8:1d:f9:07
AVRegion : 0x00000100 (NTSC-M)
GameRegion : 0x00ff (NTSC/US)
DVDRegion : 1
resetKey : XDLL
---------------------
Checking ini for smc config data patches
smc patched with ini values
---------------------
SMC patched info:
------------------
Target temps: Cpu: 80øC Gpu: 75øC Edram: 78øC
Max temps : Cpu: 100øC Gpu: 100øC Edram: 102øC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : 00:1d:d8:1d:f9:07
AVRegion : 0x00000100 (NTSC-M)
GameRegion : 0x00ff (NTSC/US)
DVDRegion : 0
resetKey : XDLL
---------------------
done!
------ Encrypting and finalizing bootloaders ------
patching payload.bin to load size 0xd50 (0x354 reps)
hack found in smc.bin!
done!
------ Adding bootloaders to flash image ------
Fixing up FS table...done!
Writing zeropair CG patch slot overflow data to sysupdate.xexp1...done!
Writing target CG patch slot overflow data to sysupdate.xexp2...done!
------ adding 26 firmware files ------
reading .\data\aac.xexp (0x4800 bytes) (crc32: 0xa622262f ini: 0xa622262f)
reading .\data\bootanim.xex (0x55000 bytes) (crc32: 0x5ebaa67f ini: 0x5ebaa67f)
reading .\data\createprofile.xex (0xc000 bytes) (crc32: 0xf53f0259 ini: 0xf53f0259)
reading .\data\dash.xex (0x5e9000 bytes) (crc32: 0x0377a5b8 ini: 0x0377a5b8)
reading .\data\deviceselector.xex (0x9000 bytes) (crc32: 0xa5da5863 ini: 0xa5da5863)
reading .\data\gamerprofile.xex (0x1a000 bytes) (crc32: 0x9b97b30f ini: 0x9b97b30f)
reading .\data\hud.xex (0x1f000 bytes) (crc32: 0x3bd83963 ini: 0x3bd83963)
reading .\data\huduiskin.xex (0x11000 bytes) (crc32: 0xf7c69840 ini: 0xf7c69840)
reading .\data\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0xf4d1be33 ini: 0xf4d1be33)
reading .\data\minimediaplayer.xex (0xc000 bytes) (crc32: 0xcbd3e4a6 ini: 0xcbd3e4a6)
reading .\data\nomni.xexp (0xd000 bytes) (crc32: 0x8099a6af ini: 0x8099a6af)
reading .\data\nomnifwk.xexp (0x2000 bytes) (crc32: 0x43d15042 ini: 0x43d15042)
reading .\data\nomnifwm.xexp (0x5000 bytes) (crc32: 0x6c1f328e ini: 0x6c1f328e)
reading .\data\signin.xex (0x12000 bytes) (crc32: 0x013749fb ini: 0x013749fb)
reading .\data\updater.xex (0x8000 bytes) (crc32: 0x0d0d3f84 ini: 0x0d0d3f84)
reading .\data\vk.xex (0x9000 bytes) (crc32: 0xc3707c11 ini: 0xc3707c11)
reading .\data\xam.xex (0x217000 bytes) (crc32: 0x35c77172 ini: 0x35c77172)
reading .\data\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
reading .\data\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
reading .\data\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
reading .\data\xenonjklatin.xttp (0x7000 bytes) (crc32: 0x945b7092 ini: 0x945b7092)
reading .\data\ximecore.xex (0x15000 bytes) (crc32: 0xa49f0061 ini: 0xa49f0061)
reading .\data\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
reading .\data\ximedic.xexp (0x2800 bytes) (crc32: 0xf67612f5 ini: 0xf67612f5)
***** could not read .\data\..\launch.xex, skipping *****
***** could not read .\data\..\lhelper.xex, skipping *****
------ adding 4 security files ------
reading .\mydata\crl.bin (0x9e0 bytes)
writing as crl.bin to flash
reading .\mydata\dae.bin (0xad30 bytes)
writing as dae.bin to flash
reading .\mydata\extended.bin (0x4000 bytes)
writing as extended.bin to flash
reading .\mydata\secdata.bin (0x400 bytes)
writing as secdata.bin to flash
------ checking for Mobile*.dat ------
------ adding smc_config.bin ------
------ finalizing image ------
Fixing up empty FS block entries...done!
Writing FS table to image...done!
calculating ECD bytes and assembling raw image...done!
writing file 'updflash.bin' to disk...done!
updflash.bin written OK
---------------------------------------------------------------
updflash.bin built, info:
---------------------------------------------------------------
console : falcon
NAND size: 16MiB
xell : power on console with console eject button
CPU Key : xxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxxx
1BL Key : DD88AD0C9ED669E7B56794FB68563EFA
---------------------------------------------------------------
fbBuild Finished. Have a nice day.
---------------------------------------------------------------
Last edited: