Is this CB version Exploitable?

King Nasty

Full Member
Feb 12, 2011
34
0
I have a Zephyr with the CB version 4578, and I´ve managed dump the NAND successfully. This dump was done a year ago, and I was told that this version could not be hacked running a version of freeboot.

Thx
 

King Nasty

Full Member
Feb 12, 2011
34
0
I have to read a little about this I see :)

But two more question.

Will I be able to read out my CPU key, and can I use my dumped NAND to do this?
 
I have to read a little about this I see :)

But two more question.

Will I be able to read out my CPU key, and can I use my dumped NAND to do this?
Simple Answer: Yes!
 
Could you point me in the right direction to which program to use?

I have my original NAND Dump, but can´t find any topics related to "extract cpu key from nand" in here or Google :)

Thx for quick answers
Wow...Can't believe this...

Have a look here: http://team-xecuter.com/forums/showthread.php?t=54423

And here: http://team-xecuter.com/forums/showthread.php?t=54178

And here: http://team-xecuter.com/forums/showthread.php?t=55189http://team-xecuter.com/forums/showthread.php?t=54423
 

GAM3x0V3R

VIP Member
Jan 15, 2007
157
0
England
Coolshrimps jtag tool gotta flash xell to the xbox the read lines 3+5i think read a tut to find witch lines to read thats ur cpu key. make sure ur xbox is connected by av not hdmi.
 

King Nasty

Full Member
Feb 12, 2011
34
0
Sorry for asking these silly questions, but every guide I read leads me back to the following statements.

"These CB versions are patched so the JTAG/SMC Hack is no longer working: (CD = 8453 for all of them)

Xenon: 1922, 1923, 1940
Zephyr: 4571, 4572, 4578, 4579
Falcon/Opus: 5771
Jasper: 6750"

That is why I´m asking again.......will I still be able to read out the CPU key, even if I have a Zephyr 4578, which is in the list above?
 

King Nasty

Full Member
Feb 12, 2011
34
0
disregard what I said....according to M AzeeM K it can be jtagged?
Hehe, by jtagged, do you mean it would be possible to get the CPU-key, or possible to dump.

The dump has already been done, and therefore I want to be sure before soldering my box once again to install the Xell.

First time I broke my DB1F1 solder point, but found an alternative point on the back-side. This point was never desoldered :)
 
Sorry for asking these silly questions, but every guide I read leads me back to the following statements.

"These CB versions are patched so the JTAG/SMC Hack is no longer working: (CD = 8453 for all of them)

Xenon: 1922, 1923, 1940
Zephyr: 4571, 4572, 4578, 4579
Falcon/Opus: 5771
Jasper: 6750"

That is why I´m asking again.......will I still be able to read out the CPU key, even if I have a Zephyr 4578, which is in the list above?
Let me rephrase(noob-friendly): Yes, Zephyr with CB 4578 can be Jtagged, but by using all the Jtagging files present for Falcon consoles. Using files made for Jtagging Zephyr won't work on this CB.
 

King Nasty

Full Member
Feb 12, 2011
34
0
Let me rephrase(noob-friendly): Yes, Zephyr with CB 4578 can be Jtagged, but by using all the Jtagging files present for Falcon consoles. Using files made for Jtagging Zephyr won't work on this CB.
Thx alot for this answer. It was actually this answer I was looking for.

Thx again for being noob friendly :)

And thx to everybody else who participated in this post :)
 

King Nasty

Full Member
Feb 12, 2011
34
0
After the dump and flashing is done, is it ok to have the jtag still connected, or is it preferable to de-solder it?
 

King Nasty

Full Member
Feb 12, 2011
34
0
Well, I have now successfully managed to run FreeBoot on my Xenon box, but the big question is.

@M AzeM K
Why won't Xell run on my Zephyr box when I flash it with the Falcon boot?

I know my soldering is 100% as when I got a RRoD when flashing Falcon and Zephyr Xell, I re-flashed the box with my dumped file and the box was up and running again.

Can anyone explain what could be wrong.......could it be that M$ have blown some fuses, so that this hack is possible?
 
CB 4578 can be hacked with Falcon files. Now, if you say that your soldering worked when you wrote back the original NAND image, that's right, your soldering did work, but for the NAND part. It may have happened that there was some problem with the soldering of the Jtag part and that's why you were getting RROD.
 

King Nasty

Full Member
Feb 12, 2011
34
0
I have a switch on my jtag board from team-xecuter, will it help to use that switch i.e 300 or 470 when flashing and booting xell?

So the jtag part has to be enabled to get xell to boot right?

Thx for quick response!
 
Yes. The Jtag part has to be enabled in order to boot XeLL or freeBOOT etc. And yes, sometimes, when other settings don't work, you can use 330/470 switch.
 

King Nasty

Full Member
Feb 12, 2011
34
0
It is okey to use JTAG Tool from Tech-Modz, as long as I choose Falcon when installing Xell?

Will check my JTAG solderpoints again.