How to hack your xbox 360 completely

So you want to hack your 360.
Have no idea where to start?

This thread should give you a general idea on what you can do with your 360.


Lets get started.
First of all you'll need to determine the age of your console.
This will give you a general idea of what hack you can apply.

On the back of the 360 there is a sticker near the AV port (Phat*&Slim*)
On that you'll find the MFR date as well as the Console Serial and Product ID.

Determining the age of the 360




[​IMG]






You'll need to write down your MFR date.
This will roughly tell you what board you have in your 360.

Xenon: 2005 - 2007 203w power supply, can be JTAGged and RGH'd (14699 only) & R-JTAGged.
Zephyr: 2007 - 2008 203w power supply, can be JTAGged and RGH'd (Hard to achieve) & R-JTAGged.
Opus: Only from RRoD Repairs from MS (rare revisions) 203/175w power supply, can be JTAGged and RGH'd & R-JTAGged.
Falcon: 2007 - 2009 175w power supply, can be JTAGged and RGH'd & R-JTAGged.
Jasper: 2008 - 2010 150w power supply, can be JTAGged and RGH'd & R-JTAGged .
Trinity: 2010 - 2011 135w power supply, can be RGH'd
Corona: 2011 - on going 115w power supply, can be RGH'd

Currently there are 6 versions of the Corona.
The following guide will tell you what type of Corona you have (you will need to disassemble your 360 for this)
If you have a Redesigned Slim then you have a Corona v5 (250GB) or v6 (4GB)
Corona: 2013 - on going 115w power supply, can be RGH'd.
Next up, Determining your Kernel + Dashboard.



[​IMG]






Blades dash 1888 - 6717 
[​IMG]
[​IMG]
[​IMG]
[​IMG]

Dashboard 1888 is the first dashboard ever released, it's very unlikely you'll have this dash installed (unless you have a launchday console still in it's plastic wrapper)
Dashboard 2241 was directly available on the 360's launchday so as soon as you've connected it to XBLive you would have received an update notice.
Dashboard 4532 and 4548 are vulnerable to the KingKong Exploit, chances of you having a 360 with such a low dashboard are astronomically low.
Dashboard 7371 and lower are vulnerable to the JTAG hack, if you wish to JTAG it then DO NOT UPDATE IT!
Dashboard 14699 and lower are vulnerable to the RGH* hack
Dashboard 14717, 14719 are vulnerable to the RGH2, this method uses the Slim style hack.
Dashboard 15572 and above are hackable with the newly released ECC files.
They use the same method as the RGH2 or the R-JTAG chip (for Phatties)
The CR4 XL is the preffered chip for these dashboards.
I STILL ADVISE YOU TO NOT UPDATE TO ANY DASH AFTER 14717 IF YOU WANT TO GLITCH YOUR 360, it's cheaper and RGH1 (for dashes below 14717) has far better boot times.


And finally, Visually determining your DVD drive.



[​IMG]






[​IMG]

[​IMG]

After the visual inspection you'll roughly know what you're up against.
Xenon/Zephyr boards usually have a Sammy/Hitachi
Some have a Benq (mine did)
Falcons usually have either a Benq or Liteon.
Jaspers pretty much only have a Liteon in it.
Slims are mostly Liteon ones, Hitachi drives are pretty rare.
Early slims have a Liteon for sure, late slims can have both (Liteon 1214,1532 are both quite rare as of the time of writing)


Hitachi FW*: 32, 36, 40, 46, 47, 58, 59. 78 and 79
Samsung FW: MS24, MS25
BenQ FW: 62430C, 64930C
Liteon FW: 74850C, 83850Cv1, 83850Cv2, 93450C

Liteon FW: 9504/0272, 0225, 0401, 1071, 1175, 1214 and 1532 (1532 are always in the redesigned Slim)
Hitachi FW: 0500, 0502


DVD flashing.





[​IMG]






This type of hack is most conventional for most people.
In short:
You flash your DVD drive with a custom firmware.
This will allow you to play back upped games from a DVD.

Currently all Phat 360's are hackable.
Most of the older ones can be dumped without a PMT (Probe 3)
Liteons need a Probe 3 to retrieve the DVD key from.
Slim 360's are hackable but require either a replacement PCB (expensive), a small hardware hack or a risky hack that involves drilling into the controller chip.
All Slim 360 drives can be "flashed"
LTU 1.2 has been released which is a firmware designed for all Slim drives (for use with a replacement PCB only)

If you do flash your DVD drive, you'll want to burn your XGD3 games (8.5 GB backups) with an Liteon iHAS drive.
This eBay seller has those drives for a cheap price.



I'm keeping it rather simple and short since Jungleflasher comes with a complete manual.
I'm using a Liteon 9x from a Phat as an example.

First things first you'll need to get a X360USBPro and a CK3i or a X360 USBPro v2 + a Probe 3 for connecting the drive to the Powersource.
(VIA SATA cards also work as well as some SATA chipsets but for the sake of simplicity I'll go with the above)

Once you have the hardware you'll have to disassemble your 360.
Connect your DVD drive to the X360 USBPro and CK3i and start Jungleflasher.
Grab your DVD key by going to the DVDKey 32 tab, make sure you've set the correct IO port and hit PhatKey.
[​IMG]
Press the switch on the probe and then probe MPX01 on your DVD PCB and release the switch to extract your DVD key.
[​IMG]
Then if everything went alright, Jungleflasher should pop up a message which lets you save your DVD drive firmware.

This small firmware file contains your DVD keys and is pretty much the second holy grail of your 360 (first being the CPU key) SO SAVE IT TWICE!
Use this small FW file to build a CFW for your drive on the Firmwaretool 32 tab.
Load your firmware as Source and LT+ 3.0 as the Target.
Click on Spoof source to target and ensure both DVD keys correspond with each other.
[​IMG]

To flash it, head to MTKFlash 32.
Click on Liteon Erase to send the Erase command to your drive.
Then powercycle your drive by switching the CK3i on and off quickly.
Then if all went well your drive should return with Status 0x72.
Now proceed to click on the Write button.
Once this has completed click on Outro/ATA reset.
[​IMG]
If everything goes well your drive should now contain LT+ 3.0 and you can reassemble your 360 and enjoy your backups.

AGAIN!
I advise you to read the Jungleflasher manual for further help.
I can't possibly shorten everything in there and post it here.



ODDE*.





[​IMG]






This is pretty much the same as DVD flashing but it has a few advantages.
Mainly:
You can use an external HDD to store your game ISO's on.
It also allows you to play mulleted xbox 1 games*.

However this requires you to purchase some hardware.
Currently all Phat 360's are emulated.
Pretty much every Slim 360 is emulated for it but some drives require extra steps.
Liteon 1175 and Hitachi 0500/0502 both need you to RGH your 360 to obtain your CPU key + FCRT.bin in order to emulate the drive.



Installing an ODDE is pretty straight forward.
You'll have to dump your DVD key so refer to the flashing section to dump your key.
Some DVD drives can't be dumped and need the CPU key + FCRT.bin from the NAND so those will need to refer to the RGH section.

Phat DVD dumps:
DVD dumps from Phat needs to be "converted" to firmware.bin.
Load your DVD dump as source in Jungleflasher and load a stock firmware as the target.
Spoof the keys and save your target firmware.
Name it "firmware.bin" and save it to your microSD.

Slim DVD dumps:
DVD dumps from the slim don't need conversion of any kind.
Just dump the DVD FW and save it as dummy.bin on your microSD.


Installing the ODDE itself (I will take an Xkey as an example)
You'll need to disassemble your 360 completely.
Disconnect your DVD drive from the Mobo and connect the Xkey PCB to the Mobo.
Now connect the cables from the Xkey to the DVD drive.
They should connect like this
[​IMG]
Once that is all done then feed the flatcable through the chassis near the Ethernet port.
Connect it to the small USB adapter thingy with the blue tab to the outside of the console.

Once it's all seated together, reassemble your 360 and boot it.
Wait for the Xkey firmware to be updated and shut it down.
Then connect your HDD with your backups to the Xkey.
It can take a while for the HDD to be fully recognized (depening on the amount of games you have on it)
Games should be in a folder called GAMES on the root of the HDD.
Along with the xkey.cfg, which holds your Xkey settings.

ISOmenu:
ISOMenu is a small feature that exploits the picture viewer/MP3 player in the 360's dash.
You can select a game by pressing the Guide button and going to picture viewer.
Go to the game you want and select the map.
Once a white image appears and says: Press Eject to play (something silimar) then continue pressing B until you're back on the main dash.
Press Eject on the DVD drive tab and wait for the game to be loaded.


JTAG.





[​IMG]






This one is sweet for people with REALLY old 360's or people that just recovered a old one from RRoD.
You can basically play every game you want.
Xbox 360, Xbox 1, XBLArcade and XBLindie (as of Dashlaunch 3.0) as well as run Linux distro's and homebrew.
However you cannot connect to XBLive ever!
If you want to JTAG your 360 then you'll have to make sure it's on Dashboard 2.0.7371.0 OR LOWER.
Any dashboard above will not work and you'll need to refer to the RGH.

Added to a JTAG you'll probably want to prevent it from dieing quickly so setting the fans to a minimum of 75-80% in FSD*


RGH.





[​IMG]






This is pretty much the same as the JTAG.
However it has some differences.

First of all this hack is achieved with a special modchip that glitches the 360's boot process.
Then once it's "glitched" you can do everything a JTAG can do.
You can optionally also install a couple of switches and set up a so called Dual NAND.
This will allow you to retain your Live enabled state of the 360.

If you want to RGH your 360 then you'll have to know your dashboard first.
If you're on 14699 and below on Phats then you can use RGH1 (RGH1 is much more stable and quicker on boot then RGH2)
If you're on 14717 or above then you'll have to resort to RGH2.
Dashes 15xxx and above use a new set of timing files but they still use the wiring of RGH2.

Xboxes that are great to glitch: Opus, Falcon, Jasper/Kronos, Trinity, Corona/Corona V2.
Xboxes that also work are Xenons (14699 only) and Zephyrs, but their a pain to glitch and some don't glitch at all.
Corona V2 needs a special method of dumping the 4GB NAND.
You can dump it partially (48 MB iirc) or the full 3.8 GB.
The full 3.8 GB is rather slow but if you want to do it right the first time then dump the full 4GB.

Currently the same rules apply to both JTAG and RGH machines regarding XBLive and the fans.



RGHing your 360 comes with a few extra steps.
First of all, determine what RGH type you'll need to use by your Dash version.

RGH1:
RGH1 is used for Phats with a dashboard equal or lower then 14699.
RGH1 uses only a few wires and is faster then RGH2.

RGH2:
This hack is designed for the Slim, but is also used on 14717/14719 and 15572+ Phatty 360's.

DGX:
This method is only used to retrieve CPU keys from Slim consoles that have been updated to 15572 or higher.
If you want to glitch your box with this other then rescuing DVD keys then I advice you to convert it into a RGX.
*This one is outdated, I will write some info over it but pay no attention to this*

RGX:
This a newly released hack.
Users which have a DGX can convert their DGX to the RGX with a couple of caps/wires.
More info is coming soon on this.
*this one is outdated, I will write some info over it but pay no attention to this*
After that you'll need to dump your NAND.
You can do that with a NAND-X/JRunner programmer or an SD based NAND dumper for Corona's
[​IMG][​IMG]


R-JTAG *coming soon*
R-JTAG is a new hack developed by TX that's similar to the RGH, however with boottimes comparable to the JTAG/Falcon RGH (instaboot)​
It's basically the same as the RGH but this is only for Phatties.​
This one is especially sweet for people that have a hard to boot Falcon/Zephyr or are experiencing extremely long boottimes on their RGH2 consoles and people with Xenons.​

New chip for slims & phats?
Team Xecuter has announced that they are replacing the CR3 and R-JTAG all together in favor for a newer chip.​
I'll add more info about it when it's released.​
By the time it's released I'll also completely rewrite this entire guide.​
KingKong exploit *This is purely for legacy purposes*






So, you have a 360 with Kernel 4548 or lower and wish to do this in order to boot Linux.

Requirements:
Kernel 4548 or update to 4548 found here (link will be added soon)
Peter Jacksons King Kong the video game.
Flashed DVD drive.

The KingKong exploit can technically been seen as a "softmod" type of exploit.
But it needs a flashed DVD drive which is in itself isn't really achieved with software.





So in short:
There is no real softmod and there will much likely never be one for the 360, so you're out of luck for that.
It's pretty much all hardware based (flashing can with luck be achieved with software only, provided you have the correct SATA chipset)
You can hack both Phat, Slim and redesigned Slim 360's with all of the above regardless of your Dash version.

If you ONLY want to play games and have XBLive access, then I'd suggest you get an ODDE or flash your drive.
A RGH can be used for Live but you'll need to invest in some expensive hardware.
Besides it's extremely risky if you accidentally boot homebrew/FSD/XeXMenu, your console+profile will get banned from live if they detect you!
You cannot play XBLA/XBLIndie/DLC or use Avatar items downloaded from the web on a retail 360, if it's not released on disc then you're only able to boot that stuff on hardware hacked consoles!



Explanation of some of the words.
Mulleted xbox 1 games - This is a special method to convert normal Xbox 1 games to 7.4 GB ISO images playable on flashed/ODDE consoles.
ODDE - Optical Disc Drive Emulator, This is a small piece of hardware that emulates the 360's DVD drive.
KV - This is your KeyVault, it holds all the data of the 360 such as your DVD Key, CPU Key and various other data regarding your consoles region and settings.
RGH - Reset Glitch hack
FSD - This is FreeStyle Dash, a neat little replacement dash that resembles the old NXE* from Microsoft.
It has a lot to offer.
NXE - This is the second dashboard from MS, (dashboards 7357 to 9199)
MS - Microsoft.
Phat - Original Xbox 360.
Slim - Second 360 version.
E slim- Third 360 version.
#hack #xbox 360 #gaming #microsoft #gesture controlling #motion sensing #microsoft #infizeal

Comments

  1. For viewers living outside Australia or anywhere can unblock Fox Sports with PureVPN and watch US Open online https://www.purevpn.com/blog/watch-us-open-live-online/

    ReplyDelete


  2. if you require services of a certified and experienced ethical hacker for your general ethical and specialized Hacks with proof ?
    + Access various social networks (facebook, twitter,
    Instagram, Google+, etc)
    + Specialized and experienced hacking into Educational
    Institutions, Change of Grades, Clearing of Criminal Records,
    Blog Hack, Clear Credit Card Debts, Drop Money Into Credit
    Cards, Smartphone Hacks, Bank Account Hacks in various parts
    of the world etc,
    + Hack into email accounts (gmail, yahoo, aol, etc)
    CONTACT : GREENFR1007@GMAIL.COM or SKYPE : SATISH.ANCHAN4


    521365

    ReplyDelete
  3. My console is the Halo 4 edition 360 Slim with the latest firmware. Can I still hack it?

    ReplyDelete

Post a Comment

Popular posts from this blog

Defusing Fork Bomb

Wii Remote IR Camera Hack with Arduino Interface