RGH Need donor Falcon 5773 nand!

jayfig

VIP Member
Oct 29, 2010
314
0
North Carolina
I took a official Microsoft update and erased my nand by accident :facepalm: all my old nand backups are falcon 5771. I need a donor Falcon 5773 nand from that 14717 dash update! I already have my cpu/dvd key already.
 
Last edited:
Oct 4, 2011
21
0
Netherlands
That will not help you.. there are more checks now in cb_a so it needs new timings Xecuter guys are working on it.

---------- Post added at 16:41 ---------- Previous post was at 16:34 ----------

I forgot to tell its a dual cb now so it definately needs new timings. when they are released you need to repogram coolrunner chip.
 

jayfig

VIP Member
Oct 29, 2010
314
0
North Carolina
not possible fat has dual cb now like slim so new timing is required.
timing on the coolrunner right? So what about my situation with my cb being 5773 and only having 5771 old nand backups. Even if new timings are released how would I build a nand without stock 5773 nand?
 

WestCoastConsoles

VIP Member
Dec 29, 2010
1,339
0
Portland, OR
I'll give you a rough outline

1. Acquire a 5773 donor NAND
2. Extract kv and config from your 5771 image
3. Inject kv and config into the 5773 image

Might be more to it since the update but that's how it was before.

Since you are using it on your own console you may not have to re-encrypt with your CPU key. Might be able to just inject the data to the new image.
 

jayfig

VIP Member
Oct 29, 2010
314
0
North Carolina
I'll give you a rough outline

1. Acquire a 5773 donor NAND
2. Extract kv and config from your 5771 image
3. Inject kv and config into the 5773 image

Might be more to it since the update but that's how it was before.

Since you are using it on your own console you may not have to re-encrypt with your CPU key. Might be able to just inject the data to the new image.
Yeah someone in another post put up a falcon 5773 4shared link but it doesnt work im still asking around for a copy. Do you what software should I use for the extraction and injection? Im kinda ready to revive my dead 360.
 

axelll

VIP Member
Mar 1, 2011
469
17
Everywhere
It seems that 4shared is down for the moment, try again a little later. Is the only copy I have.
 
Oct 4, 2011
21
0
Netherlands
but you updated your console with the latest dash update right?so that nand dump will not help you at all you will have to wait anyway for TX to release new timings
 

jayfig

VIP Member
Oct 29, 2010
314
0
North Carolina
but you updated your console with the latest dash update right?so that nand dump will not help you at all you will have to wait anyway for TX to release new timings

Yes I did update it with the latest dash update and yes I will need the new timings but how am I going to build a nand image without the stock dash 14717 nand. Multibuilder will not let me use 14699 to build a retail 14717 image
 

jayfig

VIP Member
Oct 29, 2010
314
0
North Carolina
do not worry I can dump one from a falcon console when they have fixed fat consoles glitch I update and can release a 14717 falcon nand. :)
Sure thing and ill try to inject my KV and conf into it to build my image I mainly need it for the updated 5773 cb. Itll be a good try and even if it doesnt work I just got a email from Xbox Guru where I personally asked him about this issue and what it boils down to is that im gonna have to wait till TX releases the decrypted CB_5773 and CB_B5773.

BUT STILL PLEASE DO POST YOUR FALCON 5773 NANDDUMPS! And maybe I can calm down :eek2:
 
Last edited:

axelll

VIP Member
Mar 1, 2011
469
17
Everywhere
4shared is back online, you can download the fw from there, but I guess you already did :)
 
Last edited:

jayfig

VIP Member
Oct 29, 2010
314
0
North Carolina
Yeah its a no go until mutibuilder updates to the new version with the cb 5773.bin files in the 14717 folder. Multibuilder just keep building nands with old cb 5771 even if your added nandump in the my360 folder was already 5773 itll just downgrade the cb during the build with the new dash in it.

---------------------------------------------------------------
xeBuild v1.01.421
---------------------------------------------------------------
building glitch image
per build directory overridden from command line to 'my360'
data directory overridden from command line to '14717'
Using PATCHSMC option
file name overridden from command line to 'updflash.bin'

------ parsing user ini at '.\my360\options.ini' ------
loading file...done!
pre-parsing and sanitizing
done!
User options.ini loaded, 0x152 bytes in memory
loading cpukey.txt from .\my360\cpukey.txt
CPU Key set to: 0x**************************************
setting 1blkey from ini: 0xDD88AD0C9ED669E7B56794FB68563EFA
1BL Key set to: 0xDD88AD0C9ED669E7B56794FB68563EFA sum: 0x983 (expects: 0x983)
xex Key set to: 0x20B185A59D28FDC340583FBB0896BF91 sum: 0x800 (expects: 0x800)

------ parsing ini at '.\14717\_glitch.ini' ------
ini version 14717

ini: label [falconbl] found
found (1) 'cb_5771.bin' crc: 0x859140f0
found (2) 'none' crc: 0x00000000
found (3) 'cd_8453.bin' crc: 0x25e0acd0
found (4) 'ce_1888.bin' crc: 0xff9b60df
found (5) 'cf_14717.bin' crc: 0x2d73039a
found (6) 'cg_14717.bin' crc: 0xcf74e2b4

ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x79a3e481
found (2) 'bootanim.xex' crc: 0x38ed239e
found (3) 'createprofile.xex' crc: 0xa542df5f
found (4) 'dash.xex' crc: 0x8cfc4627
found (5) 'deviceselector.xex' crc: 0x4087247f
found (6) 'gamerprofile.xex' crc: 0x7fc12233
found (7) 'hud.xex' crc: 0x7dcafc44
found (8) 'huduiskin.xex' crc: 0xd91a3e56
found (9) 'mfgbootlauncher.xex' crc: 0x8fafd72d
found (10) 'minimediaplayer.xex' crc: 0x7d3a7acc
found (11) 'nomni.xexp' crc: 0x351db74c
found (12) 'nomnifwk.xexp' crc: 0xc9ccf242
found (13) 'nomnifwm.xexp' crc: 0xd03a4fc4
found (14) 'SegoeXbox-Light.xtt' crc: 0x086eb344
found (15) 'signin.xex' crc: 0xf1b7e073
found (16) 'updater.xex' crc: 0x7142efc0
found (17) 'vk.xex' crc: 0x1c99c116
found (18) 'xam.xex' crc: 0xeaf3030e
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0x945b7092
found (23) 'ximecore.xex' crc: 0x47f658c5
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0xa765f612
found (26) 'launch.xex' crc: 0xc6acec91
found (27) 'lhelper.xex' crc: 0xeb581eb5
found (28) 'launch.ini' crc: 0x00000000

ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------

output name overridden to: updflash.bin


------ Checking .\my360\nanddump.bin ------
Loading NAND dump (0x28ee70 bytes)...done!
Detecting NAND controller type from dump data...
NAND dump is from a small block machine
NAND dump uses small block controller
parsing dump into user and spare...
done!
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypted OK, will use if no kv.bin is provided
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0xf7c000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x09 Pairing: 0x73e04e
CF slot 1 decrypted ok LDV 0x08 Pairing: 0x73e04e
setting pairing data from image to 0x73e04e
LDV was already set to 17
MobileB.dat found at page 0x3bc0, size 2048 (0x800) bytes
MobileC.dat found at page 0x24c0, size 512 (0x200) bytes
MobileD.dat found at page 0x24a0, size 2048 (0x800) bytes
MobileE.dat found at page 0x17e0, size 2048 (0x800) bytes
seeking security files...fsroot found at page 0x1860 raw offset 0x324600
crl.bin found in sector 0x103 size 0xa00...verify failed! Discarding data.
dae.bin found in sector 0x100 size 0x7090...
******* ERROR: dae hash incorrect, could not decrypt!
verify failed! Discarding data.
extended.bin found in sector 0x34c size 0x4000...verify failed! Discarding data.
secdata.bin found in sector 0xc2 size 0x400...verify failed! Discarding data.
Writing initial header to flash image

------ Loading bootloaders and required security files ------
reading .\my360\smc.bin failed, using smc.bin from nand dump
reset smc load address to 0x1000 size 0x3000
reading .\my360\kv.bin failed, using kv.bin from nand dump
reading .\14717\cb_5771.bin (0x9340 bytes)
reading .\14717\cd_8453.bin (0x5780 bytes)
reading .\14717\ce_1888.bin (0x5606a b pad 0x56070 b)
reading .\my360\xell-gggggg.bin (0x40000 bytes)
reading .\14717\cf_14717.bin (0x4560 bytes)
reading .\14717\cg_14717.bin (0x664ac b pad 0x664b0 b)
reading .\14717\bin\patches_fat.bin (0x700 bytes)
reading .\my360\smc_config.bin failed, using smc_config.bin from nand dump
-------------------
checking smc_config
-------------------
extracting config
------------------
SMC config info:
------------------
Target temps: Cpu: 80øC Gpu: 75øC Edram: 78øC
Max temps : Cpu: 100øC Gpu: 100øC Edram: 102øC
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : 00:17:fa:f2:10:04
AVRegion : 0x00000100 (NTSC-M)
GameRegion : 0x00ff (NTSC/US)
DVDRegion : 1
resetKey : YLXR
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
done!
patch slot offset reset to: 0xb0000

------ Patching BLs and modifying patches ------
Patching patches...
Default patch offset 0x000c0010 not changed
Patching patches for alt power reason
Patches patched!
Patching BLs...Done!

------ Encrypting and finalizing bootloaders ------
encoding smc.bin size 0x3000
SMC checksum: 1d0c613e
known clean SMC found, type: Falcon v3.1(1.06)
patching smc at offset: 0x12a3
SMC hacked successfully
encoding kv.bin size 0x4000
decrypted keyvault has been set for reference
encoding cb_5771.bin size 0x9340
CB 5771 seq 0x01070058 type: 0x01 cseq: 0x07 allow: 0x0058
expected fuses:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0F0FF0
fuseset 02: 000000F000000000 (sequence)
fuseset 02: 000F000000000000 (allow cseq 4)
fuseset 02: 0000F00000000000 (allow cseq 5)
fuseset 02: 000000F000000000 (allow cseq 7)
encoding cd_8453.bin size 0x5a60
encoding ce_1888.bin size 0x56070
encoding xell-gggggg.bin size 0x40000
encoding cf_14717.bin size 0x4560
encoding cg_14717.bin size 0x664b0
encoding patches_fat.bin size 0x3f0
done!

------ Adding bootloaders to flash image ------
adding smc.bin at raw offset 0x00001000 len 0x3000 (end 0x4000)
adding kv.bin at raw offset 0x00004000 len 0x4000 (end 0x8000)
adding cb_5771.bin at raw offset 0x00008000 len 0x9340 (end 0x11340)
adding cd_8453.bin at raw offset 0x00011340 len 0x5a60 (end 0x16da0)
adding ce_1888.bin at raw offset 0x00016da0 len 0x56070 (end 0x6ce10)
adding xell-gggggg.bin at raw offset 0x00070000 len 0x40000 (end 0xb0000)
adding cf_14717.bin at raw offset 0x000b0000 len 0x4560 (end 0xb4560)
adding cg_14717.bin at raw offset 0x000b4560 len 0x664b0 (end 0xc0000, rest in fs)
adding patches_fat.bin at raw offset 0x000c0010 len 0x3f0 (end 0xc0400)
Fixing up FS table...done!
Writing CG patch slot overflow data to sysupdate.xexp1 at raw offset 0xd0000...done!

------ adding 28 firmware files ------
reading .\14717\aac.xexp (0x14000 bytes) (crc32: 0x79a3e481 ini: 0x79a3e481)
adding as aac.xexp1 at raw offset 0x12aa10 len 0x00014000 (end 0x0013ea10)
reading .\14717\bootanim.xex (0x61000 bytes) (crc32: 0x38ed239e ini: 0x38ed239e)
adding as bootanim.xex at raw offset 0x140000 len 0x00061000 (end 0x001a1000)
reading .\14717\createprofile.xex (0xc000 bytes) (crc32: 0xa542df5f ini: 0xa542df5f)
adding as createprofile.xex at raw offset 0x1a1000 len 0x0000c000 (end 0x001ad000)
reading .\14717\dash.xex (0x63b000 bytes) (crc32: 0x8cfc4627 ini: 0x8cfc4627)
adding as dash.xex at raw offset 0x1b0000 len 0x0063b000 (end 0x007eb000)
reading .\14717\deviceselector.xex (0x9000 bytes) (crc32: 0x4087247f ini: 0x4087247f)
adding as deviceselector.xex at raw offset 0x7eb000 len 0x00009000 (end 0x007f4000)
reading .\14717\gamerprofile.xex (0x1b000 bytes) (crc32: 0x7fc12233 ini: 0x7fc12233)
adding as gamerprofile.xex at raw offset 0x7f5000 len 0x0001b000 (end 0x00810000)
reading .\14717\hud.xex (0x1e000 bytes) (crc32: 0x7dcafc44 ini: 0x7dcafc44)
adding as hud.xex at raw offset 0x813000 len 0x0001e000 (end 0x00831000)
reading .\14717\huduiskin.xex (0x13000 bytes) (crc32: 0xd91a3e56 ini: 0xd91a3e56)
adding as huduiskin.xex at raw offset 0x832000 len 0x00013000 (end 0x00845000)
reading .\14717\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0x8fafd72d ini: 0x8fafd72d)
adding as mfgbootlauncher.xex at raw offset 0x847000 len 0x00008000 (end 0x0084f000)
reading .\14717\minimediaplayer.xex (0xc000 bytes) (crc32: 0x7d3a7acc ini: 0x7d3a7acc)
adding as minimediaplayer.xex at raw offset 0x850000 len 0x0000c000 (end 0x0085c000)
reading .\14717\nomni.xexp (0xc800 bytes) (crc32: 0x351db74c ini: 0x351db74c)
adding as nomni.xexp1 at raw offset 0x85c000 len 0x0000c800 (end 0x00868800)
reading .\14717\nomnifwk.xexp (0x2000 bytes) (crc32: 0xc9ccf242 ini: 0xc9ccf242)
adding as nomnifwk.xexp1 at raw offset 0x868800 len 0x00002000 (end 0x0086a800)
reading .\14717\nomnifwm.xexp (0x5000 bytes) (crc32: 0xd03a4fc4 ini: 0xd03a4fc4)
adding as nomnifwm.xexp1 at raw offset 0x86e000 len 0x00005000 (end 0x00873000)
reading .\14717\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0x086eb344 ini: 0x086eb344)
adding as SegoeXbox-Light.xtt at raw offset 0x875000 len 0x00006000 (end 0x0087b000)
reading .\14717\signin.xex (0x16000 bytes) (crc32: 0xf1b7e073 ini: 0xf1b7e073)
adding as signin.xex at raw offset 0x87e000 len 0x00016000 (end 0x00894000)
reading .\14717\updater.xex (0x7000 bytes) (crc32: 0x7142efc0 ini: 0x7142efc0)
adding as updater.xex at raw offset 0x896000 len 0x00007000 (end 0x0089d000)
reading .\14717\vk.xex (0x9000 bytes) (crc32: 0x1c99c116 ini: 0x1c99c116)
adding as vk.xex at raw offset 0x89f000 len 0x00009000 (end 0x008a8000)
reading .\14717\xam.xex (0x237000 bytes) (crc32: 0xeaf3030e ini: 0xeaf3030e)
adding as xam.xex at raw offset 0x8a9000 len 0x00237000 (end 0x00ae0000)
reading .\14717\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
adding as xenonclatin.xtt at raw offset 0xae3000 len 0x0011b000 (end 0x00bfe000)
reading .\14717\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
adding as xenonclatin.xttp1 at raw offset 0xbff000 len 0x00018000 (end 0x00c17000)
reading .\14717\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
adding as xenonjklatin.xtt at raw offset 0xc18000 len 0x001a8000 (end 0x00dc0000)
reading .\14717\xenonjklatin.xttp (0x7000 bytes) (crc32: 0x945b7092 ini: 0x945b7092)
adding as xenonjklatin.xttp1 at raw offset 0xdc0000 len 0x00007000 (end 0x00dc7000)
reading .\14717\ximecore.xex (0x15000 bytes) (crc32: 0x47f658c5 ini: 0x47f658c5)
adding as ximecore.xex at raw offset 0xdc7000 len 0x00015000 (end 0x00ddc000)
reading .\14717\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
adding as ximedic.xex at raw offset 0xddd000 len 0x00090000 (end 0x00e6d000)
reading .\14717\ximedic.xexp (0x2800 bytes) (crc32: 0xa765f612 ini: 0xa765f612)
adding as ximedic.xexp1 at raw offset 0xe70000 len 0x00002800 (end 0x00e72800)
reading .\14717\launch.xex (0x9000 bytes) (crc32: 0xc6acec91 ini: 0xc6acec91)
adding as launch.xex at raw offset 0xe72800 len 0x00009000 (end 0x00e7b800)
reading .\14717\lhelper.xex (0x6000 bytes) (crc32: 0xeb581eb5 ini: 0xeb581eb5)
adding as lhelper.xex at raw offset 0xe7d000 len 0x00006000 (end 0x00e83000)
reading .\14717\launch.ini (0x292 bytes)
adding as launch.ini at raw offset 0xe86000 len 0x00000292 (end 0x00e86292)

------ adding 4 security files ------
<- Processing crl.bin ->
reading .\my360\crl.bin (0xa00 bytes)
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
adding as crl.bin at raw offset 0xe8c000 len 0x00000a00 (end 0x00e8ca00)

<- Processing dae.bin ->
reading .\my360\dae.bin (0xad30 bytes)
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
adding as dae.bin at raw offset 0xe90000 len 0x0000ad30 (end 0x00e9ad30)

<- Processing extended.bin ->
reading .\my360\extended.bin (0x4000 bytes)
adding as extended.bin at raw offset 0xe9c000 len 0x00004000 (end 0x00ea0000)

<- Processing secdata.bin ->
reading .\my360\secdata.bin (0x400 bytes)
adding as secdata.bin at raw offset 0xea0000 len 0x00000400 (end 0x00ea0400)

------ checking for Mobile*.dat ------
MobileB.dat found, adding from nanddump.bin
adding MobileB.dat as type 0x31 at raw offset 0xea4000 len 0x800 (end 0xea4800)
MobileC.dat found, adding from nanddump.bin
adding MobileC.dat as type 0x32 at raw offset 0xea8000 len 0x200 (end 0xea8200)
MobileD.dat found, adding from nanddump.bin
adding MobileD.dat as type 0x33 at raw offset 0xeac000 len 0x800 (end 0xeac800)
MobileE.dat found, adding from nanddump.bin
adding MobileE.dat as type 0x34 at raw offset 0xeb0000 len 0x800 (end 0xeb0800)

------ adding smc_config.bin ------
adding smc config to offset 0x00f7c000, len 0x400

------ finalizing image ------
Fixing up empty FS block entries...done!
Writing FS table to image...done!
calculating ECD bytes and assembling raw image...done!
writing file 'updflash.bin' to disk...done!
updflash.bin written OK

---------------------------------------------------------------
updflash.bin image built, info:
---------------------------------------------------------------
Console : Falcon
NAND size: 16MiB
Build : Glitch
Xell : power on console with console eject button
CPU Key : ********************************
1BL Key : DD88AD0C9ED669E7B56794FB68563EFA
DVD Key : ********************************
CF LDV : 17
KV type : type2 (hashed)
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------
 
Last edited:

jayfig

VIP Member
Oct 29, 2010
314
0
North Carolina
I'll give you a rough outline

1. Acquire a 5773 donor NAND
2. Extract kv and config from your 5771 image
3. Inject kv and config into the 5773 image

Might be more to it since the update but that's how it was before.

Since you are using it on your own console you may not have to re-encrypt with your CPU key. Might be able to just inject the data to the new image.
What about the smc code or any other files? Are you sure Im just gonna need kv and config?