How to JTAG your Xbox 360 and run homebrew

 by CowGuy
Featured
I will be going over how to install XBR and Xell onto your Xbox 360.  Installing XBR allows you to do many things such run unsigned code(homebrew), install any sized hard drive(even 3.5in desktop hdds!), ftp into your box, and custom dashboards.  There are endless possibilities with being able to run any code you want.  You are able to modify Xbox 360 games to run custom maps and cheats.  You can also launch games off the hard drive without a disc.  It should cost you around $5 in parts, maybe even free if you have the parts already.
 
Remove these adsRemove these ads by Signing Up

Step 1: Finding out if your Xbox is exploitable

Your kernel must be kernel 2.0.7371.0 or lower for this to work.  You can do this by opening up the system info tab.  After there is one more step to check if it still is exploitable, but you have to build your cable to dump your nand first.

1-40 of 230Next »
lars2458 says: Mar 29, 2013. 4:10 PM
I am selling my NAND-X Xecuter (used once) for best offer. Contact me if you're looking to JTag your Xbox.
alexkillpro says: Dec 21, 2012. 2:47 PM
I NNNEEEDD help cause when i putted black ops 2 in my jtag it broke it and i dont know what to do ...
scoobyrobert says: Dec 8, 2012. 4:20 AM
Thanks for the tutorial, although jtag'ing is outdated now. Reset glitch hack can work on any console although it is more expensive to pull off. At jtag xbox 360 there pritty cheap but still...
blondieboy69 says: Sep 26, 2012. 9:40 PM
does this work for 2.0.15574.0
blondieboy69 says: Sep 26, 2012. 2:36 PM
my computer won't let me use port95 i have 64 bit but i don't know which compatibility to change it to
blondieboy69 says: Sep 24, 2012. 5:45 PM
so um nvrmind figured out the compatibility doesn't work still though
blondieboy69 says: Sep 19, 2012. 8:02 PM
hey how do i change its compatibility
skibbadee says: Feb 7, 2012. 10:42 PM
(removed by author or community request)
trailleadr in reply to skibbadeeMar 13, 2012. 5:16 PM
Looks kind of shady to me. An entire domain devoted to only this supposed exploit. Not to mention is claims it requires a full xbox live connection. Why???
Lastly skibbadee just joined to apparently post that comment.
Remember folks, if it seems too good to be true, it probably is.
Thepiroboy119 in reply to trailleadrSep 13, 2012. 3:16 PM
dude, ita jtagging, look up thetechgame and se7ensins, entire communities dedicated to doing this
trailleadr in reply to Thepiroboy119Sep 13, 2012. 3:55 PM
"dude", my comment was a reply to skibbadee, which is the reason my comment is indented below his. :) His comment suggested a highly questionable method of soft-modding your xbox, and made all kinds crazy promises about what it could do.
budhaztm in reply to skibbadeeFeb 16, 2012. 9:26 PM
have you personally tried this method
poolopa99 says: Sep 5, 2012. 1:04 PM
is this undetectable???
Thepiroboy119 in reply to poolopa99Sep 13, 2012. 3:15 PM
no, if you go online with it you will get banned within the first hour, its for offline use and system link only. its worth it if u host cod lobbies
Badmandan48 says: Sep 3, 2012. 8:14 AM
anyone mind telling me how i find out whether my xbox is a zephyr, falcon, jasper etc.
cmitchell15 says: Aug 28, 2012. 12:02 PM
Will this work for K 2.0.15574.0 (BK 2.0.1888.0)?
sachila says: Jul 29, 2012. 1:02 PM
can any one help to jtag for me please tell your Skype id or email address please help me
bprince3 says: Jul 19, 2012. 10:28 PM
2 rrod = overheating
3 rrod = hardware issue (if you hold sync button and press eject button 4 times the lights will give you the 4 digit error code.. one digit every time you press eject.)

error codes
4 lights = 0
1 light = 1
2 lights =2
3 lights =3
bhossed says: Apr 19, 2012. 7:44 AM
is jtag ok for 2.0.8955.0?
what does
D:2.0.8955.0 - K:2.0.8955.0 (BK:2.0.1888.0) (E:0) X:D0E1-F705-B7B6-08FC
mean?
Hay1tsme says: Apr 9, 2012. 11:37 AM
does this work for 2.0.14719.0
tfleming1 in reply to Hay1tsmeApr 11, 2012. 2:37 PM
No man sorry.
Hay1tsme says: Apr 5, 2012. 4:06 AM
i can't install porn95nt.exe, it says incompatability with x64 bit verson of windows 7 (i did change the compatability to Windows xp service pack 2)
indijones2008 says: Dec 10, 2011. 6:30 PM
I have an XBOX 360 Slim with Liteon 16D4s DVD (F/W 9504) since October 2011 when it was purchased anew. I have never connected it to internet, so the dashboard hasn't been updated ever though I haven't checked what the current version is. Will I be able to JTAG it to be able to play copied games? I'm not interested in XBOX Live at all. Thanks!
Superben51 in reply to indijones2008Dec 19, 2011. 5:18 PM
sorry but you can't jtag any slim however you can flash the dvd drive or Reset glitch hack it.
anque in reply to Superben51Feb 1, 2012. 4:00 PM
wondering if u can help me out dont know if i have jtagable xbox my system info is as fallows d:2.0.7363.0 - k:2.0.7363.0 (bk:2.0.1888.0) x:4b5e-03a5-c6fc-d3ed its a non hdmi mnf date is 2006-03-02 thanks ahead of time
Superben51 in reply to anqueFeb 5, 2012. 10:21 AM
you should be able to just dont update the dash yet
stephin99 says: Dec 14, 2011. 3:45 PM
This goes out to all having trouble dumping nand through lpt
1. make shure 360 is plugged in both wall and motherboard
2.make shure plugged up to lpt good and snug

no results then go into to system bios and check if lpt is
1. enabled
2. set to EPP+ECP mode or into normal if in EPP+ECP

still no results
1.check soldering
2.check soldering
3.check soldering

nothing again?
1.check direction of diodes
2.add/remove the 100 ohm resisters on pins 1,2,14,16,17

nothing again bad lpt port/xbox
Mc T says: Dec 3, 2011. 3:32 PM
Some things I've found which I hope will be useful:
While trying to read your nand, you get the flashconfig of 0x12000 and/or error: 0 reading block recheck all your points to the m/board. I spent a couple of hours trying to figure out what is wrong. In the end I removed and resoldered all my points again and it worked.

Reading your nand, a message of "error: 0 reading block xyz" doen't mean you have zero errors, it means it can't read the nand.  (Probable resolder time)

.....
Testing LPT device address:03BC
Could not detect a flash controller!

Means your soldering is bad or you haven't attached the power lead to your xbox (Don't switch your xbox on, just give it power.  This powers the eeprom so you can read and write to it). Word of Warning. It can't be in a RROD mode at this point as it still won't read even if your soldering is perfect.

Get several nand backups and compare them with a hex compare tool like wxHexEditor.  There should be no differences

As it takes an age to backup the nand, you might want to consider writing yourself a batch file to collect 4 copies of your nand or copy the 4 lines below and paste onto a dos window (they will run in turn)

nandpro lpt: -r16 nand2.bin > logfile.txt 2>&1
nandpro lpt: -r16 nand3.bin >> logfile.txt 2>&1
nandpro lpt: -r16 nand4.bin >> logfile.txt 2>&1
nandpro lpt: -r16 nand.bin >> logfile.txt 2>&1

You could set this off before you go to bed and when your up the next morning, you should have 4 nand.bin files waiting for you.

If your running Degraded to initially check the flash file and it keeps crashing on you, Open it up again and click "settings".  Set the following 2 settings
1BL key an enter DD88AD0C9ED669E7B56794FB68563EFA and tick the box.
File system start to 39.
If you've already done this, open a .bin file in a hex editor and look for the string near the top of the file:
2004 - 2007
Change it to:
2004 - 2005
and write back/save the file.  Downgraded should open the file now.... or use 360 flash tool at the top of this guide if you give up

If you don't like soldering, erm well tough really - neither do I, but you could buy a NandD-X (google it).  Currently £27 or $40US.  These are pins that are soldered onto your m/board, but you can't go too far wrong with them.  They connect back to a box of tricks which sends the data via usb back toy your PC.  This solution looks very neat, but if your tight like me and would like to reuse your item, you could look into getting just the "NAND-X Pin Header Cable" (google with quotes) £3 or $4.50, chop the ends off and attach to your LPT port cable *WITH RESISTORS AND DIODE" or buy some pin headers from ebay and make your own pin headers up ("8PIN GOLD DIP IC SOCKET PANEL ADAPTER SWAPPING").  Solder one to your m/board and cables to another.  They can act like plug and socket then, so you can flash again at a later date without resoldering again.  Note: Untested.  Just bought from ebay 30 mins ago (£1.30 for 10.)

Persevere.  It will take a while, but you will get there.  From 1 week ago when I had no idea about the 360 to now, running FreeStyle Dash and putting it back in its case for good.
usman_segi says: Nov 27, 2011. 2:17 AM
I have xbox 360 pro with Kernel 2.0.13604 is it exploitable?
Furtchet says: Nov 17, 2011. 9:00 AM
This is beautiful. It is always hard first getting into homebrewing a new system. Every system has its own lingo and this is AWESOME. Thanks!
Mumztheword says: Nov 9, 2011. 7:23 PM
THERE are an awful lot of failures here. Either the info is wrong or a lot of people are just into screwing up a lot of consoles for nothing . What is happening?
I think a "Hands-on" instructional video, actually showing this info would help tremendously and curb the massive amount of failure questions.
RegularChampion in reply to MumzthewordNov 12, 2011. 7:48 PM
Well, about 2 weeks ago Microsoft released a new patch that addresses almost all exploits to date. Not sure if this still works, but I doubt it. Sorry.
stephin99 says: Nov 8, 2011. 3:56 PM
hey i am a arduino fan and i have a arduino uno and a sd shield is there a way to jtag with that ?
just curious. please someone reply soon.
jb35007 says: Oct 21, 2011. 11:35 AM
i was wondering i have a old 360 with dash 6683 but somewhere along the way the dvd drive was taken out and LOST.. my question is can i j-tag the 360 and still be able to use it and play games via a external hard drive? haveing NO way to get any codes off the old dvd drive because it is long gone.
02kingdam says: Sep 19, 2011. 12:09 PM
I had tried reading the nand and got the error about flash cannot be found i resoldered everything and then after around an hour... i then read that the power plug had to be inserted into the xbox 360 and it plugged into the wall after i done this it read first time on port 0378 so this is just a tip for those who also receives this error
Modscientist says: May 9, 2011. 12:55 PM
getting an error trying to dump:

Testing LPT device address:0378
Testing LPT device address:0278
Testing LPT device address:03BC
Could not detect a flash controller!
Can not continue

help !!?????
02kingdam in reply to ModscientistSep 19, 2011. 12:06 PM
Like a previous statement ensure that your XBOX POWER PLUG is inserted into the xbox when using nandpro but DO NOT TURN XBOX ON!!
brandon-scott says: Jun 29, 2010. 6:02 PM
I have checked my soldering very many times and added the diodes and restarted my computer but nandpro still doesnt detect it, What do i do?
02kingdam in reply to brandon-scottSep 19, 2011. 12:05 PM
Like a previous statement ensure that your XBOX POWER PLUG is inserted into the xbox when using nandpro but DO NOT TURN XBOX ON!!
ben ehrlich in reply to brandon-scottJul 13, 2010. 3:26 PM
did you make sure the diodes are facing the correct direction, thats what my problem was, it took me hours to discover it, i was about to give up too.
1-40 of 230Next »
Pro

Get More Out of Instructables

Already have an Account?

close

PDF Downloads
As a Pro member, you will gain access to download any Instructable in the PDF format. You also have the ability to customize your PDF download.

Upgrade to Pro today!