Is this diagram I found online a correct diagram for R-JTAG?

Cokeaholik

Junior Member
Mar 18, 2016
17
0
I found this diagram online after reading from forum to forum it states that it's a JTAG wiring but is it a working R-JTAG? If I use this method what setting would I select in j-runner ?
 

Attachments

Cokeaholik

Junior Member
Mar 18, 2016
17
0
What do you mean by R-JTAG board? I have a jasper 16 mb I have the rgh2+ on it but it won't glitch into the hacked dash so I can install FSD.
 

teknogod17

VIP Member
Nov 6, 2013
150
0
Yes it would work as a alternative to jtag wiring for r-jtag but deselect aud_clamp in jrunner before create xell image. Also this is not all the steps for r-jtag. You also need a glitch chip ---->(cr4) and optional but recommended QSB's and a JR-Programmer.
 

Cokeaholik

Junior Member
Mar 18, 2016
17
0
  • Console Type: Jasper
  • Programmer Used: JR-PROGRAMMER V2
  • NAND Size: 16 MB
  • Dashboard version: 2.0.17489.0
  • CB Version: 6752
  • Screenshot of NAND details from J-Runner:
NAND Pic.jpg


  • J-Runner log
  • updflash.bin log


base path changed to C:\Users\Pedro\Desktop\XBOX Mod\J-Runner v3.5 Core Pack (17349 - Dashlaunch 3.14)\xeBuild
---- { Image Build Mode } ----
building glitch2 image
<enter> key on completion suppressed
data directory overridden from command line to '17489\'
per build directory overridden from command line to 'data\'
file name overridden from command line to 'C:\Users\Pedro\Desktop\XBOX Mod\J-Runner v3.5 Core Pack (17349 - Dashlaunch 3.14)\401876295005\updflash.bin'

------ parsing user ini at 'data\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x1a0 bytes in memory
loading cpukey.txt from data\cpukey.txt
CPU Key set to: *MYCPUKEY (weight:0x35 valid; ecd: valid)
setting 1blkey from ini: 0xDD88AD0C9ED669E7B56794FB68563EFA
1BL Key set to : 0xDD88AD0C9ED669E7B56794FB68563EFA sum: 0x983 (expects: 0x983)
xex Key set to : 0x20B185A59D28FDC340583FBB0896BF91 sum: 0x800 (expects: 0x800)
Using patchsmc option (ini file)

------ parsing ini at '17489\_glitch2.ini' ------
ini version 17489

ini: label [jasperbl] found
found (1) 'cba_6752.bin' crc: 0x6aed11dc
found (2) 'cbb_6752.bin' crc: 0xc90be105
found (3) 'cd_9452.bin' crc: 0x455fa02c
found (4) 'ce_1888.bin' crc: 0xff9b60df
found (5) 'cf_17489.bin' crc: 0x26c9baed
found (6) 'cg_17489.bin' crc: 0xa9c9815e
ini dictates dual CB for this model

[rawpatch] label not found in ini

ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x40d5adce
found (2) 'bootanim.xex' crc: 0x85238a78
found (3) 'createprofile.xex' crc: 0x034acd79
found (4) 'dash.xex' crc: 0xdb4717cf
found (5) 'deviceselector.xex' crc: 0x1eb402b9
found (6) 'gamerprofile.xex' crc: 0xf4e4902e
found (7) 'hud.xex' crc: 0xb1485b31
found (8) 'huduiskin.xex' crc: 0x5fb2d289
found (9) 'mfgbootlauncher.xex' crc: 0xe9d4483a
found (10) 'minimediaplayer.xex' crc: 0x61f6c912
found (11) 'nomni.xexp' crc: 0x3ec9f846
found (12) 'nomnifwk.xexp' crc: 0x96bf4907
found (13) 'nomnifwm.xexp' crc: 0x772eb1df
found (14) 'SegoeXbox-Light.xtt' crc: 0xe0ee6049
found (15) 'signin.xex' crc: 0x68541d87
found (16) 'updater.xex' crc: 0xd63a84d9
found (17) 'vk.xex' crc: 0x81700712
found (18) 'xam.xex' crc: 0xa5741001
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0xe2adddfb
found (23) 'ximecore.xex' crc: 0x86cbabf6
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0xbee64013

ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'fcrt.bin' crc: 0x00000000
found (5) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------

output name overridden to: C:\Users\Pedro\Desktop\XBOX Mod\J-Runner v3.5 Core Pack (17349 - Dashlaunch 3.14)\401876295005\updflash.bin

1BL RSA pub key (1BL_pub.bin) not available, signature checks will not be performed
PIRS RSA pub key (PIRS_pub.bin) not available, signature checks will not be performed
MASTER RSA pub key (MAST_pub.bin) not available, signature checks will not be performed

------ Checking data\nanddump.bin ------
data\nanddump.bin file size: 0x1080000
nanddump header checks passed OK!
Loading NAND dump (0x1080000 bytes)...done!
Detecting NAND controller type from dump data...
NAND dump is from a small block machine
NAND dump uses big block controller
parsing dump into user and spare...
done!
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypted OK, will use if no kv.bin is provided
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0xf7c000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x17 Pairing: 0xd79756
setting LDV from image to 23
setting pairing data from image to 0xd79756
pairing set to: d7 97 56
Scanning for mobile data and fsroot...Mobiles found:
fsroot version 01 found at offset 0x00e44000 len 0x4000 page 0x00007220
mobileB.dat version 01 found at offset 0x00e34000 len 0x0800 page 0x000071a0
mobileC.dat version 01 found at offset 0x00e38000 len 0x0200 page 0x000071c0
mobileD.dat version 01 found at offset 0x00e3c000 len 0x0800 page 0x000071e0
mobileE.dat version 01 found at offset 0x00e40000 len 0x0800 page 0x00007200
extracting MobileB.dat from page 0x71a0 (offset 0xe34000), size 2048 (0x800) bytes
extracting MobileC.dat from page 0x71c0 (offset 0xe38000), size 512 (0x200) bytes
extracting MobileD.dat from page 0x71e0 (offset 0xe3c000), size 2048 (0x800) bytes
extracting MobileE.dat from page 0x7200 (offset 0xe40000), size 2048 (0x800) bytes
Statistics.settings found at offset 0xf78000, size 4096 (0x1000) bytes
seeking security files...
crl.bin found in sector 0x387 size 0xa00...verified! Will use if external file not found.
dae.bin found in sector 0x388 size 0xad30...verified! Will use if external file not found.
extended.bin found in sector 0x38b size 0x4000...verified! Will use if external file not found.
secdata.bin found in sector 0x38c size 0x400...verified! Will use if external file not found.
done!
Writing initial header to flash image

------ loading system update container ------
17489\su20076000_00000000 found, loading...done!
Read 0xb50000 bytes to memory
checking integrity...
header seems valid, version 2.0.17489.0
header hash is OK, checking content hashes...
content hashes seem OK, everything looks good!
extracted SUPD\xboxupd.bin (0x7ce00 bytes)
decrypting SUPD\xboxupd.bin\CF_17489.bin (0x4560 bytes)...done!
decrypting SUPD\xboxupd.bin\CG_17489.bin (0x7889c bytes)...done!

------ Loading bootloaders and required security files ------
reading data\SMC.bin (0x3000 bytes)
reset smc load address to 0x1000 size 0x3000
reading data\kv.bin failed, using kv.bin from nand dump
reading .\common\cba_6752.bin (0x1ac0 bytes)
loaded cba_6752.bin, could not check signature rsa key not present!
reading .\common\cbb_6752.bin (0x9390 bytes)
reading .\common\cd_9452.bin (0x4f20 bytes)
reading .\common\ce_1888.bin (0x5606a b pad 0x56070 b)
reading data\xell-gggggg.bin (0x40000 bytes)
extracted SUPD\xboxupd.bin\CF_17489.bin (0x4560 bytes)
extracted SUPD\xboxupd.bin\CG_17489.bin (0x7889c bytes)
reading 17489\bin\patches_g2jasper.bin (0x91c bytes)
reading data\smc_config.bin failed, using smc_config.bin from nand dump
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu: 80øC Gpu: 75øC Edram: 77øC
Max temps : Cpu: 95øC Gpu: 90øC Edram: 92øC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : 00:25:ae:2c:14:ab
AVRegion : 0x00000100 (NTSC-M)
GameRegion : 0x00ff (NTSC/US)
DVDRegion : 1
resetKey : XAUD
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
could not check signature of cba_6752.bin, 1BL RSA key not present!
done!
patch slot offset reset to: 0xb0000

------ Patching BLs and modifying patches ------
Patching BLs...Done!

------ Patching boot reasons and options into flash header ------
Patching header for xell power reason

------ Encrypting and finalizing bootloaders ------
encoding SMC.bin size 0x3000
SMC checksum: 496ebd95
unknown SMC found, type: Jasper v4.1(2.03)
glitch hack found in SMC binary!
encoding kv.bin size 0x4000
decrypted keyvault has been set for reference
Master RSA pub not available, not checking hash
encoding cba_6752.bin size 0x1ac0
encoding cbb_6752.bin size 0x9390
CB 6752 seq 0x010800d0 type: 0x01 cseq: 0x08 allow: 0x00d0
expected fuses:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0F0FF0 (retail)
fuseset 02: 0000000F00000000 (sequence)
fuseset 02: 0000F00000000000 (allow cseq 5)
fuseset 02: 000000F000000000 (allow cseq 7)
fuseset 02: 0000000F00000000 (allow cseq 8)
**dual CB flag detected!**
encoding cd_9452.bin size 0x5290
encoding ce_1888.bin size 0x56070
encoding xell-gggggg.bin size 0x40000
encoding cf_17489.bin size 0x4560
encoding cg_17489.bin size 0x788a0
encoding patches_g2jasper.bin size 0x550
done!

------ Adding bootloaders to flash image ------
adding SMC.bin at raw offset 0x00001000 len 0x3000 (end 0x4000)
adding kv.bin at raw offset 0x00004000 len 0x4000 (end 0x8000)
adding cba_6752.bin at raw offset 0x00008000 len 0x1ac0 (end 0x9ac0)
adding cbb_6752.bin at raw offset 0x00009ac0 len 0x9390 (end 0x12e50)
adding cd_9452.bin at raw offset 0x00012e50 len 0x5290 (end 0x180e0)
adding ce_1888.bin at raw offset 0x000180e0 len 0x56070 (end 0x6e150)
adding xell-gggggg.bin at raw offset 0x00070000 len 0x40000 (end 0xb0000)
adding cf_17489.bin at raw offset 0x000b0000 len 0x4560 (end 0xb4560)
adding cg_17489.bin at raw offset 0x000b4560 len 0x788a0 (end 0xc0000, rest in fs)
adding patches_g2jasper.bin at raw offset 0x000c0010 len 0x550 (end 0xc0560)
Fixing up FS table...done!
Writing zeropair CG patch slot overflow data to sysupdate.xexp1
at raw offset 0xd0000 len 0x0006ce00 (end: 0x0013ce00)...done!

------ adding 25 firmware files ------
extracted SUPD\aac.xexp (0x14000 bytes) (crc32: 0x40d5adce ini: 0x40d5adce)
adding as aac.xexp1 at raw offset 0x13ce00 len 0x00014000 (end 0x00150e00)
extracted SUPD\bootanim.xex (0x61000 bytes) (crc32: 0x85238a78 ini: 0x85238a78)
adding as bootanim.xex at raw offset 0x154000 len 0x00061000 (end 0x001b5000)
extracted SUPD\createprofile.xex (0xc000 bytes) (crc32: 0x034acd79 ini: 0x034acd79)
adding as createprofile.xex at raw offset 0x1b5000 len 0x0000c000 (end 0x001c1000)
extracted SUPD\dash.xex (0x5b0000 bytes) (crc32: 0xdb4717cf ini: 0xdb4717cf)
adding as dash.xex at raw offset 0x1c4000 len 0x005b0000 (end 0x00774000)
extracted SUPD\deviceselector.xex (0xa000 bytes) (crc32: 0x1eb402b9 ini: 0x1eb402b9)
adding as deviceselector.xex at raw offset 0x774000 len 0x0000a000 (end 0x0077e000)
extracted SUPD\gamerprofile.xex (0x1b000 bytes) (crc32: 0xf4e4902e ini: 0xf4e4902e)
adding as gamerprofile.xex at raw offset 0x77e000 len 0x0001b000 (end 0x00799000)
extracted SUPD\hud.xex (0x1d000 bytes) (crc32: 0xb1485b31 ini: 0xb1485b31)
adding as hud.xex at raw offset 0x79b000 len 0x0001d000 (end 0x007b8000)
extracted SUPD\huduiskin.xex (0x14000 bytes) (crc32: 0x5fb2d289 ini: 0x5fb2d289)
adding as huduiskin.xex at raw offset 0x7b9000 len 0x00014000 (end 0x007cd000)
extracted SUPD\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0xe9d4483a ini: 0xe9d4483a)
adding as mfgbootlauncher.xex at raw offset 0x7d0000 len 0x00008000 (end 0x007d8000)
extracted SUPD\minimediaplayer.xex (0xc000 bytes) (crc32: 0x61f6c912 ini: 0x61f6c912)
adding as minimediaplayer.xex at raw offset 0x7d8000 len 0x0000c000 (end 0x007e4000)
extracted SUPD\nomni.xexp (0xf000 bytes) (crc32: 0x3ec9f846 ini: 0x3ec9f846)
adding as nomni.xexp1 at raw offset 0x7e4000 len 0x0000f000 (end 0x007f3000)
extracted SUPD\nomnifwk.xexp (0x2000 bytes) (crc32: 0x96bf4907 ini: 0x96bf4907)
adding as nomnifwk.xexp1 at raw offset 0x7f3000 len 0x00002000 (end 0x007f5000)
extracted SUPD\nomnifwm.xexp (0x5000 bytes) (crc32: 0x772eb1df ini: 0x772eb1df)
adding as nomnifwm.xexp1 at raw offset 0x7f6000 len 0x00005000 (end 0x007fb000)
extracted SUPD\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0xe0ee6049 ini: 0xe0ee6049)
adding as SegoeXbox-Light.xtt at raw offset 0x7fd000 len 0x00006000 (end 0x00803000)
extracted SUPD\signin.xex (0x1a000 bytes) (crc32: 0x68541d87 ini: 0x68541d87)
adding as signin.xex at raw offset 0x806000 len 0x0001a000 (end 0x00820000)
extracted SUPD\updater.xex (0x7000 bytes) (crc32: 0xd63a84d9 ini: 0xd63a84d9)
adding as updater.xex at raw offset 0x822000 len 0x00007000 (end 0x00829000)
extracted SUPD\vk.xex (0xb000 bytes) (crc32: 0x81700712 ini: 0x81700712)
adding as vk.xex at raw offset 0x82b000 len 0x0000b000 (end 0x00836000)
extracted SUPD\xam.xex (0x251000 bytes) (crc32: 0xa5741001 ini: 0xa5741001)
adding as xam.xex at raw offset 0x837000 len 0x00251000 (end 0x00a88000)
extracted nanddump\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
adding as xenonclatin.xtt at raw offset 0xa89000 len 0x0011b000 (end 0x00ba4000)
extracted SUPD\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
adding as xenonclatin.xttp1 at raw offset 0xba7000 len 0x00018000 (end 0x00bbf000)
extracted nanddump\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
adding as xenonjklatin.xtt at raw offset 0xbc0000 len 0x001a8000 (end 0x00d68000)
extracted SUPD\xenonjklatin.xttp (0x7000 bytes) (crc32: 0xe2adddfb ini: 0xe2adddfb)
adding as xenonjklatin.xttp1 at raw offset 0xd68000 len 0x00007000 (end 0x00d6f000)
extracted SUPD\ximecore.xex (0x17000 bytes) (crc32: 0x86cbabf6 ini: 0x86cbabf6)
adding as ximecore.xex at raw offset 0xd6f000 len 0x00017000 (end 0x00d86000)
extracted nanddump\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
adding as ximedic.xex at raw offset 0xd87000 len 0x00090000 (end 0x00e17000)
extracted SUPD\ximedic.xexp (0x2800 bytes) (crc32: 0xbee64013 ini: 0xbee64013)
adding as ximedic.xexp1 at raw offset 0xe18000 len 0x00002800 (end 0x00e1a800)

------ adding 5 security files ------
<- Processing crl.bin ->
reading data\crl.bin (0xa00 bytes)
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
adding as crl.bin at raw offset 0xe1c000 len 0x00000a00 (end 0x00e1ca00)

<- Processing dae.bin ->
reading data\dae.bin (0xad30 bytes)
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
adding as dae.bin at raw offset 0xe20000 len 0x0000ad30 (end 0x00e2ad30)

<- Processing extended.bin ->
reading data\extended.bin (0x4000 bytes)
adding as extended.bin at raw offset 0xe2c000 len 0x00004000 (end 0x00e30000)

<- Processing fcrt.bin ->
fcrt.bin not found and not required by keyvault, skipped

<- Processing secdata.bin ->
reading data\secdata.bin (0x400 bytes)
adding as secdata.bin at raw offset 0xe30000 len 0x00000400 (end 0x00e30400)

------ checking for Mobile*.dat ------
MobileB.dat found, adding from previous parse
adding MobileB.dat as type 0x31 at raw offset 0xe34000 len 0x800 (end 0xe34800)
MobileC.dat found, adding from previous parse
adding MobileC.dat as type 0x32 at raw offset 0xe38000 len 0x200 (end 0xe38200)
MobileD.dat found, adding from previous parse
adding MobileD.dat as type 0x33 at raw offset 0xe3c000 len 0x800 (end 0xe3c800)
MobileE.dat found, adding from previous parse
adding MobileE.dat as type 0x34 at raw offset 0xe40000 len 0x800 (end 0xe40800)
Statistics.settings found, adding from previous parse
adding Statistics.settings at raw offset 0xf78000 len 0x1000 (end 0xf79000)

------ adding smc_config.bin ------
adding smc config to offset 0x00f7c000, len 0x400

------ cleaning up image ------
Fixing up empty FS block entries...done!
Writing FS table to image offset 0xe44000 len 0x4000 (end 0xe48000)...done!

------ finalizing image ------
fixing up big block controller on small block NAND LBA numbers...done!
calculating ECD bytes and assembling raw image...done!
done remapping!

------ writing image to disk ------
writing file 'C:\Users\Pedro\Desktop\XBOX Mod\J-Runner v3.5 Core Pack (17349 - Dashlaunch 3.14)\401876295005\updflash.bin' to disk...done!
---------------------------------------------------------------
C:\Users\Pedro\Desktop\XBOX Mod\J-Runner v3.5 Core Pack (17349 - Dashlaunch 3.14)\401876295005\updflash.bin image built, info:
---------------------------------------------------------------
Kernel : 2.0.17489.0
Console : Jasper
NAND size : 16MiB
Build : Glitch (v2)
Xell : power on console with console eject button
Serial : 401876295005
ConsoleId : 032912232116
MoboSerial: 705984D114639495
Mfg Date : 12/07/2009
CPU Key : *MYCPUKEY
1BL Key : DD88AD0C9ED669E7B56794FB68563EFA
DVD Key : 1DBE9E676E0DF66A353E9FA7F32F587F
CF LDV : 23
KV type : type2 (hashed - unchecked, master key not available)
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------



  • Image of the CR4 XL
  • IMG_1927.JPG

  • Images of close-up soldering to motherboard






  • IMG_1931.JPGIMG_1932.JPGIMG_1933.JPGIMG_1930.JPG
Because the diode point was burned out i used the alternate point below it.


  • IMG_1935.JPGIMG_1934.JPG

These are pics of the diode I used a 60 Watt iron on ???? big mistake


  • IMG_1937.JPGIMG_1938.JPG
  • Detailed Description of the Problem

After getting the cpu key and having the dashboard hacked i havent been able to get the hacked dashboard to launch ive tried all dip switches and jumper settings not sure what is wrong. These are the dips ive tried:



  • IMG_1675.PNG
I also installed a cap. Ive read that is supposed to make the xbox glitch with fewer tries.


  • Was the console working before you started: Yes
  • Do you get a green debug light appear on the CR4 XL chip every 4-5 seconds: Yes
  • How long is the light on for each time about a second each glitch.


Any help will be appreciated. I can still restore the xbox to normal but i want it glitched i have the RGH2+ method wiring installed and can still read all the files with jrunner and press f2 to get the information of my xbox. Can someone please show me what im overlooking or doing wrong?
 

Cokeaholik

Junior Member
Mar 18, 2016
17
0
I have the glitch chip but not sure where and what wires to install to the cr4 ive only seen installs with qsb's.

- - - Updated - - -

sorry for the late reply weekend warrior status last week can you check out my pics please.