Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi all! We have been experiencing an issue on site where threads have been missing the latest postings. The platform host Vanilla are working on this issue. A workaround that has been used by some is to navigate back from 1 to 10+ pages to re-sync the thread and this will then show the latest posts. Thanks, Mike.
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Xbox 360 Reset Glitch Hack - Unsigned Code on current Kernels incl. X360 SLIM

13»

Comments

  • Registered Users, Registered Users 2 Posts: 1,582 ✭✭✭docentore


    as usual on the scene, this was released with some drama.

    There is a guy on x-h.org ho was working on its own on the way of running homebrew from hacked dashboard. Basically he wasn't given much help, most master hackers where given out to him for terms he used etc.
    On the night he released a clip on youtube showing his RGH xbox running XexMenu ggbuild is released. This shows it was ready some time ago, but certain people on the scene wouldn't allow some unknown hacker to get credit for this


  • Closed Accounts Posts: 2,828 ✭✭✭Reamer Fanny


    docentore wrote: »
    as usual on the scene, this was released with some drama.

    There is a guy on x-h.org ho was working on its own on the way of running homebrew from hacked dashboard. Basically he wasn't given much help, most master hackers where given out to him for terms he used etc.
    On the night he released a clip on youtube showing his RGH xbox running XexMenu ggbuild is released. This shows it was ready some time ago, but certain people on the scene wouldn't allow some unknown hacker to get credit for this

    Seems like there is a lot of politics and pettiness behind the scenes, people with their talents should work as a collective then the Xbox homebrew scene would really be pushed to it's limit


  • Registered Users, Registered Users 2 Posts: 8,584 ✭✭✭TouchingVirus


    I was hanging in IRC during the week and saw some animosity against the folks trying RGHloader from people involved with fbbuild/freeboot, it's nothing new really, there's always been people out for their name :)


  • Closed Accounts Posts: 2,828 ✭✭✭Reamer Fanny


    I was hanging in IRC during the week and saw some animosity against the folks trying RGHloader from people involved with fbbuild/freeboot, it's nothing new really, there's always been people out for their name :)

    Everyone wants a piece of the pie and rightly so the Reset Glitch Hack was an incredible achievement for the scene :D


  • Closed Accounts Posts: 33,733 ✭✭✭✭Myrddin


    Bye bye Reset Glitch - http://www.xboxhacker.org/index.php?topic=17143.0
    A month and a half after leaving the Reset Glitch Hack Tiros gligli and a new hack compatible with all HDMI consoles and that whatever the kernel, we still had not seen any reaction from Microsoft. We learn today with one of our technicians, stephane76700, the answer was already in your resellers ... a new revision of motherboard.

    This motherboard has been found in a pack Forza 4250 Go, these new consoles with a matte black shell. The MFR date visible in the back is 2011-08-17 and the reader a Liteon 1071.

    The biggest surpise is the absence of HANA chip (visible anyway) is the chip that allowed the management of the timing Reset Glitch Hack ...

    It seems that the game of cat and mouse continues so ...


  • Registered Users, Registered Users 2 Posts: 8,584 ✭✭✭TouchingVirus


    Nah, the date of the console was back in August, before the glitch hack was even released.

    The HANA was only used to slow down the CPU clock to manageable level, there may be other interrupts available to do the same thing on the newly combined Southbridge.HANA chip, or elsewhere on the board.


  • Closed Accounts Posts: 1,487 ✭✭✭Pov06


    Nah, the date of the console was back in August, before the glitch hack was even released.

    The HANA was only used to slow down the CPU clock to manageable level, there may be other interrupts available to do the same thing on the newly combined Southbridge.HANA chip, or elsewhere on the board.

    Or a much faster reset glitch chip could be used.


  • Closed Accounts Posts: 33,733 ✭✭✭✭Myrddin


    Nah, the date of the console was back in August, before the glitch hack was even released.

    The HANA was only used to slow down the CPU clock to manageable level, there may be other interrupts available to do the same thing on the newly combined Southbridge.HANA chip, or elsewhere on the board.

    I see, so although the exploit is still technically in tact, the source for carrying it out has been removed? Bizarre conincidence, I presume it was a cost cutting refinement or similar.

    If there's no other source for controlling the speed, maybe external equiptment could be used...but that'd likely be big dollars!


  • Registered Users, Registered Users 2 Posts: 807 ✭✭✭Jimbobjoeyman


    does anyone know if a usb to parallel port adapter can be used for programming the chip ?
    Or does it have to be a native port ?
    USB programmers are at least 3 times the price of parallel port programmers.


  • Registered Users, Registered Users 2 Posts: 8,584 ✭✭✭TouchingVirus


    EnterNow wrote: »
    I see, so although the exploit is still technically in tact, the source for carrying it out has been removed? Bizarre conincidence, I presume it was a cost cutting refinement or similar.

    If there's no other source for controlling the speed, maybe external equiptment could be used...but that'd likely be big dollars!

    New revisions take a few months of R&D, so yes it's just a bizarre coincidence :)
    does anyone know if a usb to parallel port adapter can be used for programming the chip ?
    Or does it have to be a native port ?
    USB programmers are at least 3 times the price of parallel port programmers.

    Nandpro operates on interrupt 0x378, so if the USB to Parallel Port adapter also operates on this interrupt then you should be ok, but it probably doesn't.

    You probably have a Nand-X and a CK3 Pro, so you should be looking at buying the two update cables from Xecuter - the CK3 pro to nand-x cable allows the nand-x update to the Nandpro v3 hex file, and the nand-x to coolrunner cable allows the nand-x to flash the coolrunner boards so there'd be no need for USB Xilinx JTAG cables ;)

    If you don't then there are cheaper JTAG flashing options over USB too :)


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 807 ✭✭✭Jimbobjoeyman


    New revisions take a few months of R&D, so yes it's just a bizarre coincidence :)



    Nandpro operates on interrupt 0x378, so if the USB to Parallel Port adapter also operates on this interrupt then you should be ok, but it probably doesn't.

    You probably have a Nand-X and a CK3 Pro, so you should be looking at buying the two update cables from Xecuter - the CK3 pro to nand-x cable allows the nand-x update to the Nandpro v3 hex file, and the nand-x to coolrunner cable allows the nand-x to flash the coolrunner boards so there'd be no need for USB Xilinx JTAG cables ;)

    If you don't then there are cheaper JTAG flashing options over USB too :)


    Thats where I get screwed over I have a usb spi flasher for nand flashing
    and an extractor 3 for dvd drive powering.
    Spose its what I get for being a cheap prick, I pay more in the long run :pac:
    The usb jtag cables I've been looking at run into €30-50 mark if you know of anything cheaper.. links please :)


  • Registered Users, Registered Users 2 Posts: 8,584 ✭✭✭TouchingVirus


    The usb jtag cables I've been looking at run into €30-50 mark if you know of anything cheaper.. links please :)

    Sorry, I thought I recalled the JTAG3 being USB but it's LPT - €35 is about standard all right :(


  • Registered Users, Registered Users 2 Posts: 807 ✭✭✭Jimbobjoeyman


    Sorry, I thought I recalled the JTAG3 being USB but it's LPT - €35 is about standard all right :(
    Xecuter are releasing there own one along with the coolrunner for people who dont use the nand-x,
    I'll see what they charge,or if I can get a few pre-programmed ones somewhere I'd buy them.


  • Closed Accounts Posts: 1,487 ✭✭✭Pov06


    Nandpro operates on interrupt 0x378, so if the USB to Parallel Port adapter also operates on this interrupt then you should be ok, but it probably doesn't.

    I have a USB LPT port cable which doesn't run on 0x378, but I found a program with which you can patch NandPro to use a custom one.

    You can download it here: http://www.megaupload.com/?d=3JGZJ7SQ

    You basically open up this program, then go into your Device Manager in your computer. Find out the number(s) at which your USB LPT port operate, then copy them into the program, select your Nandpro.exe file and click Patch.

    Most USB LPT cables contain 2 numbers, so you must write in both or as many the device manager shows.

    Then it should work :P


  • Registered Users, Registered Users 2 Posts: 807 ✭✭✭Jimbobjoeyman


    Pov06 wrote: »
    I have a USB LPT port cable which doesn't run on 0x378, but I found a program with which you can patch NandPro to use a custom one.

    You can download it here: http://www.megaupload.com/?d=3JGZJ7SQ

    You basically open up this program, then go into your Device Manager in your computer. Find out the number(s) at which your USB LPT port operate, then copy them into the program, select your Nandpro.exe file and click Patch.

    Most USB LPT cables contain 2 numbers, so you must write in both or as many the device manager shows.

    Then it should work :P

    .........SOUND............:D

    Have you tried this with nand pro .....Does it work ?


  • Closed Accounts Posts: 1,487 ✭✭✭Pov06


    Yes and yes. Just use Nandpro 2.0 and not 3.0 because the tool was made for 2.0 :rolleyes:

    EDIT: Here's the topic where I found the tools: http://forums.xbox-scene.com/index.php?showtopic=699212 It's more detailed and contains some screenshots to make it easier.


  • Registered Users, Registered Users 2 Posts: 8,584 ✭✭✭TouchingVirus


    Xecuter are releasing there own one along with the coolrunner for people who dont use the nand-x,
    I'll see what they charge,or if I can get a few pre-programmed ones somewhere I'd buy them.

    If the LPT method won't work, I'll flash a few CoolRunner boards for you when I take delivery of them and the other TX stuff for updating my nand-x so it can flash the CR boards :)


  • Closed Accounts Posts: 1,487 ✭✭✭Pov06


    The LPT method WILL work since it's the same chip and the same JTAG programmer connection points are available.

    Still waiting for my x360glitch to arrive... Apparently Falcons have the fastest boot times :P


  • Registered Users, Registered Users 2 Posts: 8,584 ✭✭✭TouchingVirus


    Pov06 wrote: »
    The LPT method WILL work since it's the same chip and the same JTAG programmer connection points are available.

    Still waiting for my x360glitch to arrive... Apparently Falcons have the fastest boot times :P

    There are reports on that thread you linked that the nandpro patching for alt LPT ports doesn't work in at least some cases. That is what I meant. If Jimbobjoeyman can't get nandpro to flash his coolrunners I'm offering to do it for him.


  • Advertisement
  • Closed Accounts Posts: 1,487 ✭✭✭Pov06


    There are reports on that thread you linked that the nandpro patching for alt LPT ports doesn't work in at least some cases. That is what I meant. If Jimbobjoeyman can't get nandpro to flash his coolrunners I'm offering to do it for him.

    Just use iMPACT to flash the coolrunner...


  • Registered Users, Registered Users 2 Posts: 807 ✭✭✭Jimbobjoeyman


    My programming problem is sorted :D
    I've found pre-programmed chips that boot in 4-7 seconds :D
    For anybody thats wondering its the x360glitch chip there selling them on dealextreme for €10 http://www.dealextreme.com/p/x360-glitch-xbox-360-modchip-for-fat-jasper-102116 (actually an official reseller-volume rate partner)
    Small bit harder to install because they dont include quick solder boards that the xecuter chip has which makes the point by the ana chip easier to solder to.
    But meh plenty of flux and take your time and you'll be fine :D

    There also selling the matrix nand flasher which is supposed to be just as good as the nand x at a lower price which I might buy aswell to replace my very temperamental xbox-experts usb flasher

    Thanks for the offer to flash the chip for me TV it was appreciated


  • Closed Accounts Posts: 1,487 ✭✭✭Pov06


    If anyone is looking for any Xbox 360 parts check out what I've got for sale:
    http://www.adverts.ie/search/user-442550/status_active/type_all

    It's all the bits taken from a Falcon board.


  • Registered Users, Registered Users 2 Posts: 1,849 ✭✭✭Redisle


    My programming problem is sorted :D
    I've found pre-programmed chips that boot in 4-7 seconds :D
    For anybody thats wondering its the x360glitch chip there selling them on dealextreme for €10 http://www.dealextreme.com/p/x360-glitch-xbox-360-modchip-for-fat-jasper-102116 (actually an official reseller-volume rate partner)

    I'd order elsewhere if I were you. Dealextreme seem to have gotten horrendously bad for shipping times lately. I was waiting over a month for an order to be despatched, asked for a refund and am waiting around 6 weeks so far for that with no word back.. also know someone else waiting 5+ weeks for an order. I used to love the site but think I will avoid in the future.


  • Registered Users, Registered Users 2 Posts: 1,897 ✭✭✭megaten


    Redisle wrote: »
    I'd order elsewhere if I were you. Dealextreme seem to have gotten horrendously bad for shipping times lately. I was waiting over a month for an order to be despatched, asked for a refund and am waiting around 6 weeks so far for that with no word back.. also know someone else waiting 5+ weeks for an order. I used to love the site but think I will avoid in the future.

    Really? most orders take over a month with Dealextreme and similar Hong Kong websites so I wouldn't have worried to be honest.


  • Closed Accounts Posts: 2,828 ✭✭✭Reamer Fanny


    megaten wrote: »
    Really most orders take over a month with Dealextreme and similar Hong Kong websites.

    Choose DHL where possible on HK based sites, orders take around 5 days to get here for just a few more dollars.


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 807 ✭✭✭Jimbobjoeyman


    just ordered my chip from dx :D

    And I did a mock up of the wiring on an old board today to get some practice before I did this to my jasper.
    The wiring's actually not that bad if you take your time and use lots of flux.

    A good tip though when working with the small points like beside the ana chip and under the cpu.
    Isolate the point your soldering to with kapton tape so you dont bridge anything or knock any resistors off in the process by accident.
    The solder points have empty pads beside them and its very easy to bridge


  • Closed Accounts Posts: 6,241 ✭✭✭Vic Vinegar


    So is anyone here going to be offering the reset glitch as a service anytime soon?


  • Registered Users, Registered Users 2 Posts: 807 ✭✭✭Jimbobjoeyman


    So is anyone here going to be offering the reset glitch as a service anytime soon?

    once my chips get in and I have a few of them done I will be.
    Wont be cheap to do though, the soldering is pretty difficult and takes alot of time to make sure its done right


  • Closed Accounts Posts: 33,733 ✭✭✭✭Myrddin


    Whats the hurry, & eagerness with people looking to jump onto this just yet? To my knowledge its still at a stage where rebooters are not an option yet. Aside from emu's & a few other bits, there's still a way to go before this overtakes the traditional jtagas the mod of choice for me.

    Unless I'm mistaken??


  • Registered Users, Registered Users 2 Posts: 807 ✭✭✭Jimbobjoeyman


    EnterNow wrote: »
    Whats the hurry, & eagerness with people looking to jump onto this just yet? To my knowledge its still at a stage where rebooters are not an option yet. Aside from emu's & a few other bits, there's still a way to go before this overtakes the traditional jtagas the mod of choice for me.

    Unless I'm mistaken??

    ggbuild :D
    Thats the RGH rebooter,
    released about a week ago

    edit-
    random youtube vid
    http://www.youtube.com/watch?v=Ww0oROQ-RrQ


  • Advertisement
  • Closed Accounts Posts: 33,733 ✭✭✭✭Myrddin


    ggbuild :D
    Thats the RGH rebooter,
    released about a week ago

    edit-
    random youtube vid

    Ah I see I see :cool:

    Edit - The boot time is horrific!


  • Registered Users, Registered Users 2 Posts: 807 ✭✭✭Jimbobjoeyman


    EnterNow wrote: »
    Ah I see I see :cool:

    Edit - The boot time is horrific!

    bloody cmod chips for you
    The ones made specifically for the job
    ie matrix glitcher,xecuter coolrunner and x360 glitch are much faster.
    Along with the fact if you make your wires ridiculously long boot times actually get better.

    The chip I bought boots in 4-7 seconds on a phat console and under a minute on slims.
    Slims are a bit awkward ie failed boots, e79 etc - like some zephyrs are with the jtag hack.

    A phat jasper is the best performance wise


  • Closed Accounts Posts: 33,733 ✭✭✭✭Myrddin


    I was going to mention had they worked out the success rate of the glitch? I remember at the start it only worked a percentage of the time...or is that what the actual delay is while booting (ie trying to glitch successfully?)


  • Registered Users, Registered Users 2 Posts: 807 ✭✭✭Jimbobjoeyman


    Ya to start with they took ages to glitch so they had to change the boot sequence of the console.
    A stock console will try to boot 3 times if it fails to boot before giving e79 and shutting off.

    They had to programme it to try to boot infinity times untill it eventually glitched and booted.

    The code has been tidied up since it was implemented into nandpro 3.0.
    And the specific chips it xecuter coolrunner,matrix glitcher etc are better timed and are better worked out to improve boot times.

    The chip I bought boots in 4-7 seconds on a phat :cool:
    And its pre-programmed


  • Registered Users, Registered Users 2 Posts: 8,584 ✭✭✭TouchingVirus


    EnterNow wrote: »
    I was going to mention had they worked out the success rate of the glitch? I remember at the start it only worked a percentage of the time...or is that what the actual delay is while booting (ie trying to glitch successfully?)

    The delay occurs because it's retrying the glitch X times. The reset signal is very narrow (20ns on the slim) so the timing needs to be perfect. Increasing the length of the wire helps for slims - there is some anti-JTAG protection there by MS.

    The boot times with the Coolrunner by TX are still very impressive:

    Slim


    Jasper


    Falcon


  • Registered Users, Registered Users 2 Posts: 807 ✭✭✭Jimbobjoeyman


    well my glitch chips have been sent :D
    I decided to go with volumerates a Delaextreme partner since everyone is complaining how slow dx is lately.
    And the fact that under official resellers volumerates is mentioned and dx isn't.

    I've two jaspers waiting here


  • Registered Users, Registered Users 2 Posts: 1,582 ✭✭✭docentore


    I've got Japser-Kronos motherboard with lost DVD key from one of the boardsies (thanks massy086).
    CoolrunnerII lies on the shelf already just beside the Olimex LPC2148 board. I'm going to get them working together this evening and update it over here.

    Wish me luck!


  • Registered Users, Registered Users 2 Posts: 807 ✭✭✭Jimbobjoeyman


    docentore wrote: »
    I've got Japser-Kronos motherboard with lost DVD key from one of the boardsies (thanks massy086).
    CoolrunnerII lies on the shelf already just beside the Olimex LPC2148 board. I'm going to get them working together this evening and update it over here.

    Wish me luck!

    Nice :D
    Practice the soldering on a scrap board first the points under the cpu and beside the ANA are really small and delicate.
    Isolate them with kapton tape if you have any to make it easier for yourself.


  • Registered Users, Registered Users 2 Posts: 1,582 ✭✭✭docentore


    Nice :D
    Practice the soldering on a scrap board first the points under the cpu and beside the ANA are really small and delicate.
    Isolate them with kapton tape if you have any to make it easier for yourself.

    I'll be fine, thanks for the tip with kapton tape.


  • Closed Accounts Posts: 1,487 ✭✭✭Pov06


    If anyone is looking for a glitch chip for the Xbox 360 I have one for sale.

    I have a x360glitch chip in an unopened condition, sealed in an anti-static bag(?)

    I badly need to sell it as I don't need it anymore because my Xbox is broken :D

    It is preprogrammed for a Falcon, but can be reprogrammed for other models too.

    I would like to sell it for €10, and I'd drop in the needed components for an LPT programmer too. (Resistors, LPT connector + case, etc.).

    Advantage for you is that you won't need to wait a few weeks for it to get here from China, and it already has the programmer cable components with it. If you're interested, give me a PM :)


  • Advertisement
  • Closed Accounts Posts: 33,733 ✭✭✭✭Myrddin


    Pov06 wrote: »
    If anyone is looking for a glitch chip for the Xbox 360 I have one for sale.

    I have a x360glitch chip in an unopened condition, sealed in an anti-static bag(?)

    I badly need to sell it as I don't need it anymore because my Xbox is broken :D

    It is preprogrammed for a Falcon, but can be reprogrammed for other models too.

    I would like to sell it for €10, and I'd drop in the needed components for an LPT programmer too. (Resistors, LPT connector + case, etc.).

    Advantage for you is that you won't need to wait a few weeks for it to get here from China, and it already has the programmer cable components with it. If you're interested, give me a PM :)

    This is a discussion forum, not an online shop. Use adverts/ebay please


  • Registered Users, Registered Users 2 Posts: 807 ✭✭✭Jimbobjoeyman


    my glitch chips are in The an post sorting office :D
    I have all the wiring done on one of my jaspers and the ecc image flashed to it,
    Now its just a matter of installing the chip when it arrives :D


  • Registered Users, Registered Users 2 Posts: 8,584 ✭✭✭TouchingVirus


    I hooked up a CK3 Pro Rev D to my nand-x tonight using a DIY cable, upgraded it with the ArmV3 hex file. Hooked up some wires from the expansion socket to the JTAG on a coolrunner and flashed it with the XSVF file for Jaspers. Will post up a guide on how to do it all tomorrow morning, sorta tired now.

    And maybe tomorrow I'll get the time to actually glitch a few jaspers/slims :)


Advertisement