Checklist:
- Your here because you found in the flow chart that your exploit method is the RGH method (dash higher than 7371, and console is a slim or a Xenon)
- You have Orig.bin NAND dump backed up
What you need now:
- Slim Proto Chip: This is the best method to use for slim consoles. It is the easiest to get working and has the best boot times. The other instructions for slims are here if you get your hands on some old chips but otherwise there is no reason you shouldn't use a Slim Proto. There is a V1 and a V2. The V2 is a bit better and easy to find (while the V1s are rare) but a V1 will work fine if you get your hands on one.
- Coolrunner: There are basically two ways to go with the Coolrunners if you can't get a Slim Proto or have a phat that you want to RGH1. A CR3 Lite or a Coolrunner Rev C with its addons. The CR3 Lite is essentially the rev C and its addons so it is a lot easier to use but there are 2 problems with it. First, it doesn't work as well as the rev C on Trinitys, and second TX has stopped making them so they are hard to get. Basically if you can get a CR3 Lite and don't have a Trinity get it. Otherwise if you have a Trinity or cannot find a CR3 Lite then get a Coolrunner Rev C.
Slim Proto V2: http://www.modsupplier.com/catalog/xecuter-slim-proto-v2-tx-p-1093.html
CR3 Lite - http://www.xconsoles.com/products/tx-cr3-lite.html
Coolrunner Rev C - http://www.xconsoles.com/products/cr-rev-c-mega-bundle-1.html or http://www.modchipcentral.com/store/product.php?productid=17959
- IF YOU DON'T HAVE A NAND-X/J-R Programmer OR DemoN, you will need this: http://www.modchipcentral.com/store/product.php?productid=17773Or you can make one:http://www.instructables.com/id/How-to-hackRHG-your-Xbox-360/step5/coolrunner-LPT-program-cable/
- IF YOU HAVE A NAND-X but it didn't come with the NAND-X/J-R Programmer to coolrunner cable you need this: http://www.modchipcentral.com/store/product.php?productid=17776
- IF YOU HAVE A CORONA V3/V4 YOU WILL NEED THE POST_OUT FIX: http://www.xconsoles.com/products/tx-corona-postfix-adapter.html (must be signed in to see this)
- NOTE: If you are using a Slim Proto, and have a Corona V3/V4, and don't have a DemoN you will NOT need a NAND-X/J-R Programmer because its only purpose for non-DemoN V3/V4s is to program the chip but the protos come pre-programmed
NOTE: There is another Coolrunner, the CR3 Pro that is available for purchase. I will not be talking about it in this guide however because its setup is a bit different and it is intended for advance users. Plus the Proto is better anyway
Now if you are on dash 14699 exactly and you have a phat you need to check your CB version (skip if you are above or bellow this dash) to see if you can use the RGH1 method for faster boot times. In J-Runner simply look to the right under "NAND info" and check your "2BL [CB]" version. If your CB version is any of the following or higher than you unfortunately need to use the R-JTAG method:
- Zephyr CB 4577, 4575
- Falcon/Opus CB 5772, 5773
- Jasper CB 6752, 6753
In J-Runner (it should still be open with your motherboard type selected and your NAND dump selected under "Source File") in the upper right section titled "XeBuildOptions" click the drop down and select "Add Dash". In the window that appears check off "16747" and click "Add Dashes". Then in the same drop down select "16747" as it will now be in the list, and then select "Glitch" so it's bubble is filled. Then look in the drop down just bellow that where it says "RGH". If you are using the RGH1 wiring then leave it as is, but if you are using the RGH2 wiring then change it to RGH2.
Now there are four scenarios you could have at this point:
1) You have a NAND-X/J-R Programmer and used it to read your NAND
2) You don't have the NAND-X/J-R Programmer and read your NAND with LPT
3) You have a Corona V2/V4 and therefore don't own a NAND-X/J-R Programmer
4) You have a DemoN and used that to read your NAND
NOTE!: You'll know if your Coolrunner is getting power if the red and green lights come on, and the green light will turn off once it programs. Additionally, if for some reason J-Runner does not automatically select the right .xsvf files for you and brings up the selection prompt you must select the timing file manually. If you have a Falcon select "Falcon" and if you have a Trinity select "Trinity". If you have any other console you can use A, B or C (and if you want try each one to see which gives the best boot times. Also if you are using a DemoN make sure you check off "DemoN Installed" at the bottom.
NOTE2: Even if you have a Corona V2/V4 if you want to spend the extra money you can buy a NAND-X/J-R Programmer and use that to program the Coolrunner instead of the LPT cable. Just follow number one instead.
NOTE3: If you are using a Slim Proto chip follow the next steps normally but SKIP any part that talks about programming the chip/coolrunner as they come pre-programmed.
Also, if you are above dash 14719 the "Create ECC" button is probably greyed for you. If this is the case just skip that and go right to pressing "Write ECC". If that doesn't work you can always use the "Write ECC for >14719" function under the advance tab.
1)
If you have the NAND-X/J-R Programmer simply plug in the Coolrunner to it with the NAND-X to coolrunner cable, and then plug the NAND-X/J-R Programmer into your computer like so (in the picture is the coolrunner rev c. but the Coolrunner plugs in the same way):
Now once both are plugged in make sure "USB" is selected under "CoolRunner Programming" in the upper left, the Coolrunner switch is set to PRG, and unplug the NAND reading cable that is in the side of your NAND-X/J-R Programmer (don't deattach/desolder it from the board!) and then click "Flash CoolRunner". Once it is done you can detach the Coolrunner and "NAND-X/J-R Programmer to Coolrunner Cable" and set them aside.Now plug the NAND reading cable back into the NAND-X/J-R Programmer. Now, in J-Runner click "Create ECC" in the upper left, and make sure there are no errors in the log (there really shouldn't be so if you get one google it). Then click "Write ECC" in the upper left and wait for it to finish. Then you can disconnect the NAND-X/J-R Programmer from your console and computer and move onto the next step. Also, unplug the Xbox's power.
--END OF 1--
2)
If you don't have the NAND-X/J-R Programmer you need to attach the LPT cable you bought or made to your cool runner. If you bought the pre-made one it connects so that you can see the metal contacts (so they are facing up), and if you made one wire it up as shown in the schematic. Usually the pre-made cable comes with a sticker so you can make sure its facing the right way. Yours may be different. Also if you bought the pre-made one you will see that it doesn't have an external power source like the homemade one. Some computers LPT ports provide enough power on their own but if it doesn't work you have to connect the included 2 wire power cable to the Coolrunner and the cut the plug of the other end and get 3.3v from the xbox's DVD port (you can go strait from the port-but if you do don't solder or you may never get the plug back in-or use an old DVD drive power cable). You wire the black to ground and the red to the 3.3v pin. Then simply plug in the xbox's power brick (but don't turn it on) and it should power your Coolrunner while on standby.
DVD port power:
Then make sure the switch is set to NOR, and "LPT" is selected under "CoolRunner Programming".
You also need to specify your LPT port, though usually the default value is correct. If the default doesn't work you need to go to the "Device Manager" in windows, find your LPT port in it, which will look something like this:
and then right click on it and select "Properties" and then go to the resources tab. For the number you find ignore the "0x" and just put the rest in. Now click "Flash CoolRunner" and when it finishes you can unplug the coolrunner and its power and set them aside. Now, in J-Runner click "Create ECC" in the upper left and make sure there are no errors (there really shouldn't be so if you get one google it). Now open your J-Runner folder and then "output" in their copy the "image_00000000.ecc" file to the Nandpro30 folder. Then reopen a command prompt and cd to your Nandpro30 folder again (you should know how to do this now) and then type this command:
Code:
nandpro lpt: +w16 image_00000000.ecc
It will look like this:
Then press enter and it will write up to 004F so it should go fast. When done disconnect the LPT cable and move onto the next step. Also, unplug the Xbox's power.
--END OF 2--
3)
If you have a Corona V2/V4 you will be following a method similar to scenario 1:
Attach the LPT cable you bought or made to program your cool runner. If you bought the pre-made one it connects so that you cannot see the metal contacts (so they are facing down), and if you made one wire it up as shown in the schematic. Also if you bought the pre-made one you will see that it doesn't have an external power source like the homemade one. Some computers LPT ports provide enough power on their own but if it doesn't work you have to connect the included 2 wire power cable to the Coolrunner and the cut the plug of the other end and get 3.3v from the xbox's DVD port (you can go strait from the port-but if you do don't solder or you may never get the plug back in-or use an old DVD drive power cable). You wire the black to ground and the red to the 3.3v pin. Then simply plug in the xbox's power brick (but don't turn it on) and it should power your Coolrunner while on standby.
DVD port power:
Then make sure the switch is set to NOR, and "LPT" is selected under "CoolRunner Programming".
You also need to specify your LPT port, though usually the default value is correct. If the default doesn't work you need to go to the "Device Manager" in windows, find your LPT port in it, which will look something like this:
and then right click on it and select "Properties" and then go to the resources tab. For the number you find ignore the "0x" and just put the rest in. Now click "Flash CoolRunner" and when it finishes you can unplug the Coolrunner and its power and set them aside. Now, in J-Runner click "Create ECC" in the upper left, and make sure there are no errors in the log (there really shouldn't be so if you get one google it). Then click "Write ECC" in the upper left. It will pop-up with that special read/write menu, and if it didn't start writing automatically just make sure the ECC is loaded into the bar and click "Write" and wait for it to finish. Then you can disconnect the R/W Kit cable from your Xbox and computer, and move onto the next step. Also, unplug the Xbox's power.
--END OF 3--
4)
Luckily for you the DemoN can be used to program the Coolrunner as well as read the NAND.
Plug in the Coolrunner to the DemoN using the included ribbon cable. There are two cables but one is smaller than the other so it is easy to tell which one is the right one. Now once that is plugged in make sure "USB" is selected under "CoolRunner Programming" in the upper left, the Coolrunner switch is set to PRG, and the DemoN and Coolrunners power lights are on. Then click "Flash CoolRunner". Once it is done you can detach the Coolrunner from the DemoN and set it aside. Now, in J-Runner click "Create ECC" in the upper left, and make sure there are no errors in the log (there really shouldn't be so if you get one Google it). Then in the DemoN drop down menu click "Toggle NAND" and then make sure that at the bottom of J-Runner it shows that the DemoNs NAND is selected. Now click "Write ECC" in the upper left and wait for it to finish. Then you can disconnect the DemoN's USB cable from your computer, switch the device switch to "Xbox" instead of "PC", and move onto the next step
If you went with a Coolrunner Rev C follow the same steps as above, but you must modify the Coolrunner so that it can connect to the DemoN in this fashion (the board that plugs into the Coolrunner Rev C comes with the DemoN):
Plug the board in and then solder the EN connection from the board to the Coolrunner
NOTE2: There are some users who have reported that they aren't able to program the DemoN until the Coolrunner is soldered into the motherboard. If you cannot program the DemoN now continue on and once you have installed the Coolrunner into the board then try programming it.
--END OF 4--
Installing the POST_OUT fix (for Corona V3s/V4s):
*SKIP THIS IF YOU DON'T HAVE A CORONA V3/V4.
If you have a Corona V3/V4 you will need to install the POST_OUT fix on order to regain the yellow wire/C connection. You have to remove the heatsink in order to do this (see the slim opening guide you used to open the console) It goes on relatively simply like so (use the solder anchors to fix it in place):
Wiring/Jumper Settings for Coolrunner:
The wiring/jumper settings will differ depending on whether you have a phat, a trinity, or a corona v1/v2. Standard soldering rules apply, simply make all the connections in the pictures and place the Coolrunner where indicated. Also you may run into a wire being too short. If that is the case, extend it with your own wire. Additionally you will notice that for each of these diagrams the "Ground" location points to the AV port. Simply solder the ground wire in-between the top of the port and next to one of the prongs that sticks up (in the corner they create). Any arrows you see pointing to a hole means that the wires of that color are to be sent through it to the other side of the board.
NOTE: If you have a Coolrunner Rev C and its addons instead of a Coolrunner Lite you will need to wire in the addons so I will go over these now.
CPU Signal Cleaner (RGH1 and 2):*Can be used with the RGH1 or 2 wiring but isn't really needed on RGH1 setups. Highly recommended for RGH2 setups!
As you can see this is where to place the cleaner on either system type:
Just cut off a small part of your blue CPU_RST cable and use it to solder "D" on the Coolrunner to "D" on the CPU Signal Cleaner and then solder "CPU_RST" on the cleaner to the actual CPU_RST point on the motherboard with the rest of the blue cable. Switch settings will be shown under each motherboards (Phat, Trinity, Corona) sections.
Multi-Cap Addon (RGH1 ONLY):
This only applies to RGH1 setups so if you are using the RGH2 wiring leave it off.
This is how you install the addon:
Switch settings will be shown under each motherboards (Phat, Trinity, Corona) sections.
Phat:
Wiring:
Place the Coolrunner with its sticky pad here (it is on the AV port; Rev C is smaller but goes in same place):
RGH 1:
There are now two possibilities. You either have the QSB's or you don't. Whatever you have you are going to refer to the same diagrams, but for QSB owners you are going to wire the 3V3, and B wires to the points labeled on the QSB's instead (for the 3V3 wire it is the one with the large text not the small text):
RGH 2:
Since you have a Xenon you must install the wires alone to these points:
If you have trouble soldering to B (if you aren't using the QSBs and only wires), here is a good alternate point for both RGH1 and RGH2 Wiring (pictures provided by pinkfloydviste):
FT3N2
If you have trouble booting, here are different techniques for laying wires: http://team-xecuter.com/forums/showthread.php?t=82208
If you have trouble with a Zephyr: http://team-xecuter.com/forums/showthread.php?t=84048
It is important that your run CPU_RST along the bottom of the board because the top has too much interference.
Jumper Settings:
Refer to the following picture:
For non-Jaspers:
LK1 - Short the points
LK2 - Leave alone
LK3 - Leave Alone (Short if using RGH1 wiring)
LK4 - Leave alone
For Jaspers:
LK1 - Short the points
LK2 - Short the points
LK3 - Leave Alone (Short if using RGH1 wiring)
LK4 - Leave alone
For all phats:
-8 switch (S2) dip: Set one and five on (up position) and the rest off. Then later try combos of 2,3, and 4, and 6,7,8 (2 on at a time) if you want to try to improve glitch times.
-6 switch (S4) dip: Set 1 on and the rest off. Then later try different ones on (one at a time) if you want to try to improve glitch times.
-Set the operation switch to "Phat" (if you have slow times try "Slim" later)
Refer to the following picture:
Jumper 1: JP closed for RGH1, open for RGH2
Jumper 2: Try both and see what works best for you
Jumper 3: Usually needed on only Jasper, but you can try it on any phat
Rev C Addons:
CPU Signal Cleaner -
Try combos of 1 on for each dip switch (i.e. 1K and 470p, not 1K and 2K). Only one on at a time!
Multi-Cap Addon -
Try just one on at a time.
Now, put the motherboard back into the metal shell, reattach the heatsink if you removed it (remember to use thermal paste), and plug in the front ROL board, then move on to Step 3: Xell
[/Spoiler]
Trinity:
I will integrate these instructions when I get the chance but for now here is how to use the Slim Proto: http://team-xecuter.com/forums/showthread.php?t=139308
Everything else in this section is for the older methods.
Wiring:
Place the Coolrunner with its sticky pad here (it is on the AV port; Rev C is smaller but goes in same place):
There are now two possibilities. You either have the QSB's or you don't. Whatever you have you are going to refer to the same diagrams, but for QSB owners you are going to wire the 3V3, B, E, and F wires to the points labeled on the QSB's instead:
If you have trouble soldering to B (if you aren't using the QSBs and only wires), here is a good alternate point (pictures provided by pinkfloydviste):
FT2R2
If you have trouble booting, here are different techniques for laying wires, and other helpful info: http://www.team-xecuter.com/forums/showthread.php?t=86641
Jumper Settings:
CR3 Lite:Refer to the following picture:
a
For Trinity:
LK1 - Short the points
LK2 - Short the points
LK3 - Leave alone
LK4 - Short the points 1&2 (or if you have trouble/bad boot times try desoldering the points)
-8 switch (S2) dip: Set one and five on (up position) and the rest off. Then later try combos of 2,3, and 4, and 6,7,8 (2 on at a time) if you want to try to improve glitch times.
-6 switch (S4) dip: Set 1 on and the rest off. Then later try different ones on (one at a time) if you want to try to improve glitch times.
-Set the operation switch to "Phat" (if you have slow times try "Slim" later)
Refer to the following picture:
Jumper 1: Leave open since you have to be using RGH2
Jumper 2: Try both and see what works best for you
Jumper 3: Leave open since it doesn't apply to Slims
Rev C Addons:
CPU Signal Cleaner -
Try combos of 1 on for each dip switch (i.e. 1K and 470p, not 1K and 2K). Only one on at a time!
Now, put the motherboard back into the metal shell, reattach the heatsink if you removed it (remember to use thermal paste), and plug in the front ROL board, then move on to Step 3: Xell
Corona:
I will integrate these instructions when I get the chance but for now here is how to use the Slim Proto: http://team-xecuter.com/forums/showthread.php?t=139308
Everything else in this section is for the older methods.
Wiring:
Place the Coolrunner with its sticky pad here (it is on the AV port; Rev C is smaller but goes in same place):
There are now two possibilities. You either have the QSB's or you don't, or have a Corona V2/V4. Whatever you have you are going to refer to the same diagrams, but for QSB owners you are going to wire the 3V3, E, and F wires to the points labeled on the QSB's instead. Additionally, if you have a V3/V4 you are going to solder C to the "POST 1" point of the POST_OUT fix instead. Also, use the yellow wire from the "Phat Kit" because the slim one is too short, and D is a very small point so be careful. If you are too afraid to use this point or don't have a thin enough tip, you can use another point (see alt point) but it requires that you remove the X-Clamp and fan which I am not going to talk about here. Additionally wrap up the 50cm blue wire into a coil (it is supposed to be that long, do not cut it). Plus, if you have a Corona V3/V4 the wire for "C" is going to go to "POST 1" on the fix instead :
If you have trouble booting, here are different techniques for laying wires, and other helpful info: http://www.team-xecuter.com/forums/showthread.php?t=86641
Jumper Settings:
Refer to the following picture:
For Corona:
LK1 - Leave Alone
LK2 - Short the points
LK3 - Leave alone
LK4 - Short the points 1&2 (or if you have trouble/bad boot times try shorting 2&3, or un-shorting all of them)
-6 switch (S4) dip: Set 1 on and the rest off. Then later try different ones on (one at a time) if you want to try to improve glitch times.
-8 switch (S2) dip: Set one and five on (up position) and the rest off. Then later try combos of 2,3, and 4, and 6,7,8 (2 on at a time) if you want to try to improve glitch times.
-Set the operation switch to "Slim" (if you have slow times try "Phat" later)
Refer to the following picture:
Jumper 1: Leave open since you have to be using RGH2
Jumper 2: Try both and see what works best for you
Jumper 3: Leave open since it doesn't apply to Slims
Rev C Addons:
CPU Signal Cleaner -
Try combos of 1 on for each dip switch (i.e. 1K and 470p, not 1K and 2K). Only one on at a time!
Now, put the motherboard back into the metal shell, reattach the heatsink if you removed it (remember to use thermal paste), and plug in the front ROL board, then move on to Step 3: Xell
Step 2c: R-JTAG
Checklist:
- Your here because you found in the flow chart that your exploit method is the R-JTAG method (dash higher than 7371 but less than 15572 if you have a phat, and console is a phat or slim)
- You have Orig.bin NAND dump backed up
What you need now:
- R-JTAG Starter Kit if you didn't opt for the Ultimate Kit : http://www.xconsoles.com/products/tx-rjtag-starter-kit.html
The R-JTAG hack only works if your console is on dash 15574 or higher, so if you are not on that dash you need to update to it: [Click here to view this link]
The are two ways to setup the R-JTAG hack: The regular way, and the AUD_CLAMP way. Because the AUD_CLAMP method proved to be so reliable on the original JTAG hack that will be the method I am showing you how to do.
In J-Runner (it should still be open with your motherboard type selected and your NAND dump selected under "Source File") in the upper right section titled "XeBuildOptions" click the drop down and select "Add Dash". In the window that appears check off "16747" and click "Add Dashes". Then in the same drop down select "16747" as it will now be in the list, and then select "Jtag" so it's bubble is filled. Also, tick off "R-JTAG" and tick off "Aud_Clamp?"
Now there are three scenarios you could have at this point:
1) You have a NAND-X/J-R Programmer and used it to read your NAND
2) You don't have the NAND-X/J-R Programmer and read your NAND with LPT
4) You have a DemoN and used that to read your NAND
(3 is not applicable for this hack since Coronas are slims)
1)
If you have the NAND-X/J-R Programmer Now, in J-Runner click "Create Xell-Reloaded" in the upper left, and make sure there are no errors in the log (there really shouldn't be so if you get one google it). Then click "Write Xell-Reloaded" in the upper left and wait for it to finish. Then you can disconnect the NAND-X/J-R Programmer from your console and computer and move onto the next step. Also, unplug the Xbox's power.
--END OF 1--
2)
If you don't have the NAND-X/J-R Programmer Now, in J-Runner click "Create Xell-
Reloaded" in the upper left and make sure there are no errors (there really shouldn't be so if you get one google it). Now open your J-Runner folder and then "output" in their copy the "[Your Console Mobo].bin" file to the Nandpro30 folder. Then reopen a command prompt and cd to your Nandpro30 folder again (you should know how to do this now) and then type this command:
Code:
nandpro lpt: -w16 [Your Console Mobo]_hack_aud_clamp.bin
It will look like this:
Then press enter and it will write up to 004F so it should go fast. When done disconnect the LPT cable and move onto the next step. Also, unplug the Xbox's power.
--END OF 2--
4)
In J-Runner click "Create Xell-Reloaded" in the upper left, and make sure there are no errors in the log (there really shouldn't be so if you get one Google it). Then in the DemoN drop down menu click "Toggle NAND" and then make sure that at the bottom of J-Runner it shows that the DemoNs NAND is selected. Now click "Write ECC" in the upper left and wait for it to finish. Then you can disconnect the DemoN's USB cable from your computer, switch the device switch to "Xbox" instead of "PC", and move onto the next step. MAKE SURE THAT IF AT ANYTIME YOU NEED TO WRITE/READ SOMETHING TO/FROM YOUR DEMON AFTER THIS THAT YOU MOVE THE SWITCH BACK TO "PC", UNLESS YOU ARE WRITING/READING THE NAND USING THE DAUGHTER-BOARD THAT IS INSTALLED TO THE BACK OF THE CONSOLE
--END OF 4--
Wiring/Jumper Settings for the R-JTAG Chip:
The wiring/jumper settings will be the same for all consoles since they are all phats. Standard soldering rules apply, simply make all the connections in the pictures. Also you may run into a wire being too short. If that is the case, extend it with your own wire. Additionally you will notice that for each of these diagrams the "Ground" location points to the AV port. Simply solder the ground wire in-between the top of the port and next to one of the prongs that sticks up (in the corner they create). Any arrows you see pointing to a hole means that the wires of that color are to be sent through it to the other side of the board.
Wiring:
Temporarily sit the R-JTAG chip were it is on this picture but down onto the board as if the DVD drive isn't there and wire it up in that position:
When you are done wiring it this is where it will go, so at the end of the task when you are putting the DVD drive back it pull of the sticky pad protector and place the device down onto the DVD drive.
Refer to the following diagrams to install the wiring:
Jumper/Dip Settings:
First, refer to the following picture and dip switch:
Make sure that all of the dips are off at first, and then do the following based on mobo:
Jasper:
7 - On
8 - On
4/5 - Try one of these on at a time and see which one gives better boot times
Rest - Keep off
7 - On
3/4/5 - Try one of these on at a time and see which one gives better boot times
Rest - Keep off
8 - On
3 - On
Then, refer to this picture:
Short 1 and 3 (ignore picture)
2:Switch to the ON position
3:Switch to the middle position (470 ohms) and then later try the left position (330 ohms) if you have bad boot times
Now, connect the R-JTAG chip to the Post_QSB using the provided cable:
Finally, put the motherboard back into the metal shell, reattach the heatsink if you removed it (remember to use thermal paste), and plug in the front ROL board, then move on to Step 3: Xell
Step 3: Xell
Blue Screen (for what it looks like):
Now that your Xbox is somewhat back together, it is time to get what is called your "CPU key". Your CPU key and a NAND dump (which you already have) is what you ultimately need to exploit your console.
If you are using the RGH method move the "SLIM/PHAT" switch to whichever console you have, and move the "PRG/NOR" switch to "NOR"
Now plug in your consoles power supply and video cable (preferably not HDMI as there can be problems with it). If you have a DemoN your console will default to the DemoN NAND so don't worry about changing it. Now change your TV to the proper input and turn on your console with either the button or a controller.
(NOTE RGH Xenons, will take a VERY long time to boot) If you are using the RGH/R-JTAG method you should see the green light on the Coolrunner/R-TAG chip flash every few seconds and eventually stop and a blue screen should show, and you should not see the Red Light of Death. If you are using the JTAG method blue screen should show relatively quickly and you should not see the RROD. Once the screen is up, it will start going through some things and scrolling down. Eventually you will see: "your cpu key:" and then a long alphanumeric code. Write this code down this is your CPU key. If you want your DVD key it is right bellow that. Now turn your console off and in J-Runner input your CPU key into the "CPU Key" box on the left. J-Runner should output "CPU Key is correct".
If you know the console booted because the Coolrunner Lite stopped flashing or the optical out port is red, but you didn't get any image on screen, turn off the console and check this:
Plug in an Ethernet cable to your console and make sure it is connected to your router properly, then turn the console on. You should see the green light on the Coolrunner/R-JTAG chip flash every few seconds and eventually stop, and when it does you should not hear the fan clicking, the optical port will turn red, and you should not see the Red Light of Death; however, you will not see anything on the screen. This is because the Corona motherboards AV output crashes due to the Coolrunner sometimes, which is normal OR your console just doesn't like the exact setup you used (which is also normal). In order to get your CPU key, you will need to return to J-Runner, which should still be open. Though first you need to find out what your IP address subnet is by opening a CMD prompt (start->search/run "cmd") and typing in "ipconfig" then pressing enter. You may see multiple adapters, but what you are looking for is the section called something like "Ethernet adapter Local Area Connection" if you have a wired internet connection to your computer, or Wireless adapter Local Area Connection" if you have a wireless internet connection to your computer. Now under that section you should see an entry called "IPv4 Address" that is something like "192.168.x.y" and X is most likely 1,2, or 0. Write down what that X value is. Now in J-Runner at the top click "Settings" and look at the right where it says "IP settings". For "IP Default" enter "192.168.x.2" (were x is the value you wrote down), for "IP Range Start" enter "192.168.x.2", and for "IP Range Finish" enter "192.168.x.199". Now click OK at the bottom middle. Now in the bottom right of J-Runner click "Scan IP Range", it should find your Xbox and grab your CPU key, which will appear in the log and the box on the left, and you can be sure of this by clicking the "KV Info" tab to the right. You should see all the info filled in. If you want your DVD key it will also be listed under that tab.Turn your console off.
STOP! If your console didn't turn on, boot, RROD'ed, RLOD'ed, the green light didn't flash (if you are RGH'ing/R-JTAGing), or something unexpected happened, check your wiring, wire placement, retrace your steps, etc (usually the green light not flashing is wire placement). There are too many things to check so I can't list all the scenarios, so simply retrace your steps. If you have a RGH/R-JTAG and you got slow boot times (more than 10-30sec, 1min on stubborn console, for seconds on a non-Xenon RGH, and more than 10-20sec for an R-JTAG) then go back to your section and try different Jumper settings/CPU_RST wire/wire positioning. If you did all of this but you are still stuck try posting your problem here in the Xbox 360 support forum, or over at Team Xecuter's Forums.
If this all worked, continue on.
Now in J-Runner click "Create Image" in the upper left and it should succeed, and the source box bellow should change to a new file. Find that file in the J-Runner "output" folder and rename it to updflash.bin if it isn't already named that and reload it into your source box.
Consoles that used the TV to get their key, and don't have a DemoN:
Now place that file on a FAT32 formatted flash drive, OR burn it to a blank CD/DVD. Insert which ever you used into your console and boot it up again. The blue screen will appear again and have a message about flashing your NAND. Let it finish and when done it should power off or at least say it completed the flash. You are now officially exploited
. Move on to part 6.
Consoles that used IP Scanning to get their key, and don't have a DemoN:
Reattach whatever device you used to read your NAND and in J-Runner click "Write NAND" (if you have a Corona v2 that box will come up) or if you used LPT flash the updflash.bin with Nandpro (you can do this on your own by now I believe in you
, just check the command example above if you can't remember and just use "updflash.bin" this time). When it is done you are officially exploited
. Move on to part 6.
Consoles that have a DemoN period:
Move the DemoN's device switch back to "PC" and reattach the DemoN's USB cable. Then in J-Runner click "Write NAND" in J-Runner and wait till it is done. Now just move the device switch on the DemoN back to "Xbox". You are now officially exploited
. Move on to part 6 .
Part 6: While you're in there...
While your console is open, you may want to consider a few other mods such as:
- Protecting yourself from accidental updates (prevents e-fuses from blowing). Phat: http://team-xecuter.com/forums/showthread.php?t=53292 Slim: Remove R6T3 (can't find picture).
- 12V fan mod: http://www.llamma.com/xbox360/mods/360-12V-fan-Mod.htm
- Change LEDs on the ROL (Slim): http://xbox-experts.com/tutorial/xbox-360-slim-rf-module-led-mod/
- Change LEDs on the ROL (Phat): http://www.hacksden.com/showthread.php/4654-Phat-ROL-RF-Board-LED-Mod
- Internalizing your HDD: http://www.llamma.com/xbox360/mods/internalize-360-hard-drive.htm
- Using a PC power supply: http://www.llamma.com/xbox360/mods/pc_power_supply_xbox_360.htm
- Getting quieter Talismoon fans: http://www.talismoon.com/cgi-bin/version2/engine.pl?page=overview-xbox360
Now whether you do any of these or not, reassemble your entire console. DemoN owners here is how you connect it to everything:
Phat:
*Here it shows the Coolrunner Rev 3 with an addon board. The CR3 Lite has its own port already which you will be using. Also if you are using the R-JTAG hack the wire plugs into this:
^Ignore if not using R-JTAG method
*Here you have to remove the cover of the one MU. You obviously don't have to use TX's tool. A flat head screwdriver or something similar will suffice.
*Use the adhesive pad to keep it in place
Also if you want to use your laptop drive as your hard drive refer to this tutorial on how to open the phat's drive shell:http://www.afterdawn.com/guides/archive/disassemble_xbox_360_console_hdd_adapter.cfm OR if you have a slim you can just slide the hard drive in (it is hard to line up with the port) and hold it in place with a packing peanut or something (OR you can buy a custom slim HDD case that opens OR crack one you own open). Once you get to where you turn your Xbox on, it will show up as a normal MS hard drive would so just format it normally through the "Memory" section in settings.
Part 7: Software Setup
You may be done all of the hardware changes, but not the software. This part will get you started with using your Xbox's new capabilities. When you turn it on you'll have to go through the setup crap.
Step 1: XEXmenu
First you are going to get XEXmenu. It is a replacement dash and the way you must first run custom code/programs until you setup everything else. Download XEXmenu 1.2 here: http://www.mediafire.com/?37qni84y3m4w7r1 OR if you don't have a flash drive download the ISO version here (you will need a CD) http://www63.zippyshare.com/v/35199471/file.html.
If you got the USB drive version, plug a flash drive into your Xbox, turn the Xbox on, and format the flash drive as a memory card. Then plug the flash drive into your computer. Download USBXTAFv44: [Click here to view this link] Now open it, and click "File" in the top left, and then "Open First USB Drive". In the column on the left, right click on the "Data Partition" folder and click "New Folder" and name it "Content". Then right click on the "Content" folder and click "New Folder" and name it "0000000000000000" (that's 16 zeros). Now click on the 0s folder you just created so it is highlighted. Extract the XEXMenu1.2 archieve so that the "CODE9999" folder is on your desktop. Now drag the "CODE9999" folder into the right plane in USBXTAF. Once it is inserted remove the flash drive and plug it back into your console.
If you got the ISO version simply extract the ISO and burn it to a CD, and then insert it into your console.
Now back on your console you are going to go to the demos if you got the USB version and you should see XEXmenu so launch it. If you got the ISO version it will show up as a game so just launch the DVD drive on the dashboard.
You should now be in XEXmenu, so press the back button to familiarize your self with the controls, and refer back to them if you forget.
If you have an internal hard drive you can now copy XEX menu to it by going to your USB drive/ the CD drive, pressing Y on the "CODE9999" folder and hitting copy. Then paste it in the "Content" folder on your hard drive. If you are just going to use an external USB you will have to keep it on the USB drive or make a 16GB partition on your external USB drive, format it as a MU, and move XEXmenu there.
Now in the next few sections you can launch .XEX files by pressing A on them in XEXmenu. Also when you need to move files around you can either use XEXmenu by placing the files on a flash drive formatted as FAT32 (if Xell is on your flash drive because you didn't move it you can use CD's, another flash drive, or an external USB drive) OR FTP. FTP is a way to copy files from your computer to your Xbox over your local network. You must download a FTP client (such as FlashFXP) and have your Xbox connected to your router. Then you find out your Xbox's IP address by going to Network settings on the main dashboard, and then on your FTP client you connect to your Xbox (it is the lightening bolt on FlashFXP) by going to the connect menu and inserting your Xbox's IP and "xbox" for the username and password.You browse through your Xbox, which will be on the right, like files on a computer, yours will be on the left and you simply drag files to and from your Xbox and computer. HDD1:\ is the internal hard drive, USB0:\ is a flash drive, USBMU:\ is a MU formatted flash drive. NOTE, in order to use FTP you must have XEXmenu (or Freestyle dash which we will setup later) open on your Xbox.
I will assume from now on you know how to move files around.
Also you will want to create the following folders on your hard drive: Games, Xbox1, Emulators, and Apps (placing any files of these sorts into their appropriate folder, with "Games" being Xbox 360 Games)
Step 2: Freestlye dash
Freestyle dash is the latest and greatest replacement dash that is fully customizable, looks nice, and has tons of features. If you want to you can stick with just XEXmenu but I highly recommend FSD You can download it here: http://www.realmodscene.com/index.php?/topic/2090-f3-rev-775/, and see a video of it here:
My head hurts enough from writing this so I won't fully explain how to use it, but you can figure it out easily by looking around it in. Just extract it into a folder called FSD3 on your HDD or USBHDD in the root (Hdd1:\FSD3 or USB0:\FSD3) and run the default.xex to get into it. Once your in it you setup everything in the "Settings" option where you can change the theme colors etc., and in order to add games to your library you must FTP/copy them into the folder of their type (Games/Xbox1/Emulators/Apps) and then add those folders to the scan list (you do this in settings). It also has a file browser you can use to move files and launch .XEXs with. Also you can FTP while FSD is running. If you need help with it ask in the Support forum or search Google.
Step 3: Dashlaunch
Dashlaunch comes with a bunch of nice features such as auto-patching your arcade games that you downloaded, but its main feature is changing where your "Xbox Home" button in the Xbox guide points to. This way you can have Freestyle dash/XEXmenu as your default dashboard. Even if you don't want that it is good to have Dashlaunch anyway as you don't have to set a default dash.
Download it here: http://www.realmodscene.com/index.php?/topic/3228-dashlaunch-312/
Get the installer default.xex onto your Xbox and run it. You use LB and RB to change sections, and the left thumb-stick to navigate a section. If you need to know the controls for something just idle over it and the controls help will slide out.
Get to this section:
Then press A on "Paths" to expand it and it will look like this (minus the French):
Press A on "Default" and you will enter a file browser. Navigate to either your Freestyle Dash .xex (should be in something like HDD1:\FSD or Freestyledash or Freestyle) or your XEXmenu.xex (should be in [device]:\content\0000000000000000\CODE9999...) and press A on it. Also do this for the "Guide" entry. If you want to you can set stuff for the BUT_A/B/X/Y buttons which means that if you hold that button when you are turning your console on or pressing "Xbox Home" in the guide you will launch that .xex instead of the default one.
NOTE!: Any time you want to go to the normal dashboard just hold RB while booting/hitting "Xbox Home" in the guide.
Now go to this section of Dashlaunch:
Move down so "Flash" is highlighted, then press X. This will save your settings. Now turn your console off and back on. It should go to the dash you assigned to default. You can return to the Installer.xex anytime to change settings.
Step 4 : XBOX1 Emulator
This will get original Xbox games working as the are broken by default, and will get you the hacked emulator files so that you can play any original Xbox game (some may run poorly).
Download HDD CPF: www.download.digiex.net/Consoles/Xbox360/Jtag/harddrive.zip
Extract it and get the .xex file onto your Xbox and run it. Go through the on screen instructions (just pressing A a few times, don't mind the warnings) and when it is done return to FSD/XEXmenu by simply dashboarding with the "Xbox Home" button in the guide.
Download the 2007 hacked emulator files: [Click here to view this link]
Now extract the folder and copy the "Compatibility" folder to the HDDX:\ folder on your Xbox overwriting anything that is already there.
You can now play any original Xbox game or homebrew.
Part 8: Afterwards
Now that you have an exploited console these are some things you might want to try:
- Xbins, a library of files such as emulators: [Click here to view this link]
- LibXenon (runs in xell) based apps/emulators: http://libxenon.org/index.php?PHPSESSID=ja3u7k1skvj561qjg9t2ifsst5&board=8.0
- Halo Reach RTE: http://www.mediafire.com/?tqy3xb6w8v3badq
- Halo 3 RTE: http://www.se7ensins.com/forums/thr...ation-to-mod-halo-3-on-real-time-halo.282834/
- Check out the Xbox 360 Modding Tutorials section (which this is in) OR the sections for a game you want to mod for more
Also any time you need to update your exploited Xbox to a newer dash, simply download the latest version of J-Runner (it should auto-update), input your CPU key and browse for you Orig.bin NAND dump, add the dash your are updating to in the drop down in the upper left, and click"Create Image" in the upper left. Then simply place the updflash.bin on a FAT32 flash drive and update with Xell again (by turning the console on with eject with the flash drive in). Corona V2 users you will have to manually flash the NAND with the QSB SD Card reader adapter (it sucks).
You are now off to experiment with your new console on your own. I hope this was of use to you ![]()
P.S. In case you are interested, here is the link to just the picture album. Just to see the number of pictures (lol) and for easier distribution: http://s1139.photobucket.com/albums/n554/oblivioncth/Se7ensins/Ultimate Exploit Tutorial/#!cpZZ1QQtppZZ20
What I think I will be adding next: Future R-JTAG addons/revisions
Change Log:
10/25/12 - Original Post
10/27/12 - Updated to support 16197
11/10/12 - Added instructions for using J-R programmer (I was being lazy not including it
)
11/25/12 - Clarified information about dashboard versions
12/9/12 - Added information on upcoming DGX Addon
12/10/12 - Updated to support 16202, fixed typos
12/17/12 - Added information on Corona V3/4, Fixed flow chart type, prepared tut for DGX and POST_OUT Fix release
12/27/12 - Added info on how to use the DGX, will add Corona V3/V4 soon
12/29/12 - Changed LPT resistors from 100K ohms to 100 ohms (typo - thanks deathmind)
12/30/12 - Updated the link for dashlaunch from 3.05 to 3.06
1/5/13 - Added info for Corona V3s/V4s
1/13/13 - Changed FSD3 link to the latest version, and added video directly to thread.
1/21/13 - Finished adding DemoN install instructions, corrected typos
1/28/13 - Corrected incorrect value for RGH selection for Corona boards in J-Runner (thanks Komano)
2/4/13 - Added pictures for motherboard identification double check, fixed typo about NAND-X
2/19/13 -Added info for the RGH1 wiring method for those eligible (since the boot times are faster), and added info about the Demon BB Conversion Kit.
2/20/13 - Updated to support 16203
2/24/13 - Updated the link for dashlaunch from 3.06 to 3.07
2/25/13 - Changed 100K ohms for LPT to 100ohms... again. Somehow didn't stick last time.
2/28/13 - Changed pictures source to Dropbox. Hopefully they stay. EDIT: Didn't work :|
2/28/13 - Images have actually been fixed now. Should stay since Imgur doesn't have bandwidth limits
3/4/13 - Updated guide to include the new ECCs. Also added new "Guide Status" at the top.
3/9/13 - Updated FSD link to the latest version (Rev735 and LiNK Beta 3)
3/10/13 - Changed the "Creating ECC" step so that it only needed J-Runner and no manually addition of the ECCs since J-Runner was updated and now has then included
4/22/13 - Added point "B" alternate for those having trouble with it (thanks pinkfloydviste for the pictures!)
4/30/13 - Remove "B" alternate under Corona (accidental addition). Thanks Tormios
5/11/13 - Added tip about the possibility of having to install the CR3 Lite before you can program it with the DemoN, and simplified some of the steps with the DemoN
5/17/13 - Added the R-JTAG method for phats, removed RGH method for phats except for Xenons
6/7/13 - Changed the way the user connects the DemoN to their PC to a more foolproof method.
6/8/13 - Added option for Coolrunner Rev C since it tends to get better glitch times on Trinitys
7/6/13 - Fixed incorrect statement that the R-JTAG starter kit did not come with the QSBs (Thanks Lamb Chops!)
7/25/13 - Added more info about the Coolrunner Rev C since TX stopped making the CR3 Lites
8/10/13 - Corrected some info on programming Coolrunner with an LPT cable.
12/2/13 - Fixed some typos and broken links
*This post was removed for spacing so I put it back here:
Brilliant tutorial!
Thank you! I have always wanted to write one of these massive ones ![]()