Introduction: How to Hack/RHG Your Xbox 360

Picture of How to Hack/RHG Your Xbox 360

If you want to hack your Xbox 360 and your dashboard version is over 7371 then the only way that you can hack it is with the reset glitch hack (RGH). When I started looking for a way to hack my 360 I heard about the jtag method only to find out that my dashboard was newer then 7371, but in early September a hardware exploit was developed know as the RGH. Basically what the RGH does is send a single to the processor that tells it to reset. Usually it would do exactly that however if the single is sent when it is booting up it allows us to run unsigned code.

to perform this RGH and utilize the exploit what you will need to do is read the NAND, install the modchip, write the NAND and installing your dash board of choice (i will be using xexmenu).

To do this you will need:

modchip (i will be using the coolrunner from team-xecuter)

coolrunner LPT program cable

male LPT port (printer cable) (x1)

wires (x12 this will be your LPT cable so make them long)

computer with a female LPT port

a program to read the NAND (i used nandprob 2 you can find it HERE)

soldering iron

solder

Jtag tool (software)

360gcprog (software)

flux (not needed but HIGHLY recommended)

***Disclaimer: I am not liable for any damage that may be caused to your property or self from following the instructions in this tutorial. Soldering irons can be very hot and cause burns, as well as possibly break your Xbox 360. Opening your xbox 360's shell will void its warranty. *** 
 
now then lets get started. first you need to completely take apart you 360 there are plenty of guides to do that so i wont cover it here. When the case is removed it should look like the picture. i highly suggest that you take off the metal case it sits in so that you can access the bottom of the motherboard. 

Step 1: Checking What Motherboard You Have

Picture of Checking What Motherboard You Have

to check what mother board you have to turn the 360 around and look where you plug in the power cable, then use the first picture to find out witch one looks like yours and what motherboard you have.you are now ready to build a nand cable and dump your nand

note: no xenon or corona motherboards are hack-able yet and i've been told that zephyr xbox's have a very low success rate.

Step 2: Reading the NAND

Picture of Reading the NAND

To read the NAND, which is basically the Boot Sector of the Xbox 360, you will need to solder cables to the motherboard in very specific spots. To find those points use the diagram in the first pictures, make sure you find it on the xbox, and flip the motherboard upside down making sure you can see the bottom of the points that you are going to solder to. I suggest flipping the motherboard upside down because the points are small bumps of solder removing any need to add external solder. I also put the resistor leg on the motherboard because they were easier to solder in to place.    

Step 3: Reading the NAND

Picture of Reading the NAND

So if your soldering connections are strong and not overlapping anywhere then we are ready to read the NAND. open and install nandprob and restart your computer. After it has booted up again, open cmd and navigate to where the nandprob 2.0 folder is found and enter into the folder after you are inside type in (nandpro.exe lpt: -r16 nand1.bin) without the brackets. After the first one is done hit the up arrow key and change the nand1.bin part of the command to nand2.bin and dump the nand again. DUMPING MORE THEN ONCE IS VERY VERY IMPORTANT. Once you are done dumping all the times you want compare the files with total commander.you NEED to have two or more  matching dumps before moving on.

it is alright to have 1 or 2 bad blocks in the NAND just so long as all the dumps are the same.

Step 4: Checking If Your Xbox Is Exploitable

Picture of Checking If Your Xbox Is Exploitable

if you have a slim skip this step
to make sure that your xbox is exploitable the you need to know the CB version.
Check the number in the 2BL [CB] field. The CB needs to be one of the following to be exploitable.

Zephyr: 4578, 4579
Falcon and Opus: 5771
Jasper: 6750, 6751

If the CB is not one of the numbers above, the console is not covered in this guide. Since writing this an new exploit call RGH 2.0 has made all phat Xboxs hackable was been released, However I have not had any experience with it.

Step 5: Coolrunner LPT Program Cable

Picture of Coolrunner LPT Program Cable

you can just go buy a cable to program your coolrunner for you or if your really going to go all out with DIY then heres how to make your own. the second image is a different one if the first one didn't work for you.

you'll need

male LPT port

4.8 kohm resistor

if the first cable didn't work then you'll need

male LPT port

220 omh resister (x1)

3.3 komh ressister (x3)

1N4148 diode (x3)

Step 6: Programing the Coolrunner

Picture of Programing the Coolrunner

now download the correct .xsvf file for your xbox and open up the 360gcprog and follow the first image from top to bottom. the .xsvf files you flash onto the coolrunner tells it what kind of motherboard you have and then tells it the exact timing for the coolrunner to send the reset pulse to the processer.

Step 7: Install/solder the Mod Chip In

Picture of Install/solder the Mod Chip In

now come the fun part! you get to solder the cool-runner into the actual 360. if you can't solder small points now would be the time to get someone else to do this for you. the first picture is a complete over view and the ones after that are of my personal install.

the wires of the coolrunner are pre-tinned and cut to the perfect length for optimum glitch time (how long it takes to boot up). i would suggest just putting small amounts of flux on the wires and the motherboard, then touching the wire down and applying the soldering iron until the solder on the wire melts into place.

Step 8: Write the Nand

Picture of Write the Nand

remember those nand dumps we made at the beginning? well now it is time to use them to make something called freeboot. to make the freeboot file you need the cpu key from your xbox so open up jtag tool and follow the images.

Step 9: Installing Xexmenu

Picture of Installing Xexmenu

ok so now that you have freeboot installed you can start up your xbox and if it boots then everything is good so you can unsolder the nand cable and pack up your xbox back in the case and put it where it would normally go, everything will be done with usb from now on. you need to get a usb stick and format it with the xbox. download the program i have uploaded and go HERE for the files for xex menu. open up the program you downloaded and follow the images.

note: your xbox will not boot to xexmenu you will still have to go though the MS dashboard and launch it. although it is possible to make it so it will boot to it i am not including the instructions in this 'able.

Step 10: Launching Xexmenu

Picture of Launching Xexmenu

plug the usb stick back into your xbox and go to demos. there should be one called xexmenu, just click play. from here you can play any homebrew apps you want or even full disk games like me. so just kick back and start enjoying your now fully hacked xbox 360

Step 11: BONUS... How to Play Iso's

okay so you have an iso that you ....ahem.... made and you want to play it. right?. it is actually very simple to do. just go here and download the program. extract that sucker with 7-zip. once you have that done open it up and hit the choose iso folder button and select the folder your game is in. choose a destination folder, make sure that your iso shows up and hit the go button. once it is done extracting take all the files and transfer it to the xbox's harddrive or usb. load up xexmenu and it should list your game right away.

Comments

bleumods (author)2017-09-07

under step 6 i didnt see a download for the corona? Does this work for the corona?

bleumods (author)2017-09-07

at the 6th step for programming the cool runner but i dont see a download for the corona? this works for the corona right? if so which download is the corona

St8kout. (author)2016-08-17

Not sure why you mention "flux" at the end, unless you are using the wrong type of solder.

There's basically two types of solder:

-Rosin core, for electronics. Already has flux in it. Nothing else to add.

-Acid core, for plumbing, NOT for electronics. Often the paste comes separately from the solder. This kind likes to eat circuit boards. Again, NOT for electronics.

Project D (author)St8kout.2017-01-30

In fact, I'd go so far as to say it's very common. Rosin-core solder works fine, but applying flux works so much better than the rosin core alone.

GeorgeS302 (author)St8kout.2017-01-29

It's not uncommon to add a bit of extra flux to the board you're trying to solder to in order to get the solder to flow properly. It helps keep things a bit tidier.

camronshaw6565 (author)2016-12-05

Hey!! I Just got my JTaged xbox back and i need the next step i got paypal ill pay just email me at Camrondshaw@gmail.com or cal or Text at 765-508-1075

The Lost Puppy (author)2016-05-13

Nice guide, but what's up with the ds passme in step 5?

devilsteps (author)2012-11-27

What if I have one nonmatching block... Is that ok?

Superben51 (author)devilsteps2012-11-27

Dump again, then compare them. If there is still an error dump one more time and compare. Depending on the address the block is at it might be okay to continue but I would STRONGLY advise against it because if you don't get a good dump then if something goes wrong (which is very possible with non matching nands, if the error in the wrong sector) you don't have a stock nand to flash back and lose your xbox. If however you want to continue then look into using J-runner for making the ECC image.

AlphaFalcon (author)Superben512016-04-03

can I BYE one

AlphaFalcon (author)2016-04-03

can I BYE one

KRIPTICxKILLER (author)2015-07-23

Can I have one shipped to me for money?

CurtyK (author)2015-07-01

Are you sure this works 100%

taimurhassan6101 (author)2015-04-20

is winchester motherboard hackable?which motherboard of xbox 360 are not hackable?

sfjuocekr (author)2015-04-13

Making three dumps is the minimum required to reconstruct a dump IF you have any read errors. I suggest you work on your soldering skills as I have personally never had issues dumping, but then again I have a background in electronics.

If your dump takes A LONG time to complete AND you get differences on different spots. A shorten the wires and redo soldering spots.

The best tip I can give you is to heat up the spot you are going to solder for a second or to, then apply some tin and remove the tin and iron. You always want to preheat the spot to solder on to to make the tin melt and then apply just a tiny speck extra to merge it with the tin on the wire you want to solder. I never use flux on solder spots like these, the tin you use is likely to have a resin (flux) core.

oliver.hirvi.9 (author)2014-10-21

it says i have a 12v 9,6a what motherboard is that?

That means 12 VOLT, 9.6 AMP, that's your power/psu, not motherboard.

youssef.chelsea (author)2015-02-10

here is an easy tutorial dor xbox 360 rgh :)

http://consolesnews.com/tutorials/tutorial-installing-xbox-360-rgh-with-coolrunner/

nicksv (author)2014-05-09

When reading nand you could have wrote that the xbox needs to have power on it, but not turned on.

I tried reading the nand on two different computers. The one computer had bad blocks each time and i think i tried all bios setups.

The other computer was running ECP mode in bios on the lpt cable. And that gave me the best reading. It remapped a little bit of the nand but it worked great.
(I used XNandHealer to verify the nands)

On some computers when reading the nand the xbox may turn on by it self. Either in the beggining of the reading or the end but will most likely turn it self off again.

And for writing the nand. You could have added text to see what pictures are from the xbox and maybe a little text that describes what you are about to do. Had to look at other guides to figure out how to get it working.

And for the coolrunner LPT cable i used another schematic that was more simple. http://img638.imageshack.us/img638/430/lptjtagprog... <- worked perfect for my coolrunner rev C. And this on both computers

All in all it was an ok guide and i got it working. But its not very noob friendly.

But i have a question. I don't understand after i did the RGH i was not able to play the games that was allready installed on the harddrive without it still asking for a disc. After that i updated the dashboard like this -> http://www.xpgamesaves.com/topic/103897-tutupdate-...

And i have also played with the settings menu in xexmenu. Pretty much all i done and now it runs all the games i had allready installed on the harddrive..?

What changed this you think? Is it the dashboard update or the settings thing in xexmenu?

And last thing i run all the games from the normal game menu. Xexmenu does not find any games?

evelez2 (author)2014-03-06

I was reading xexmenu is up to 1.5, is that correct? Where can I get it?

austiboy2 (author)2013-11-15

If your computer doesn't have an LPT port, is it possible to connect it using an adapter of some sort?

devilsteps (author)2012-09-08

i deleted my nands from the nand step... should i just get 2 new one?

Superben51 (author)devilsteps2012-09-08

Yes. It's vital to have at least one good NAND dump permenatly backed up in case something goes wrong. You'll also write a modified version of your own NAND back to the xbox, so it is super important to have and keep a NAND dump handy.

devilsteps (author)2012-09-06

this step still doesnt work for me... even though i name the file with .svf at the end the program still says that it is not a correct svf file...

devilsteps (author)2012-09-04

i have a zephyr, but when i open the file for the zephyr a page comes up with a bunch of symboles... how do download this?

Superben51 (author)devilsteps2012-09-04

If you right click and press open in a new tab, a window will pop up asking what you want to do. Click the option for save file and then press okay.

devilsteps (author)Superben512012-09-05

so i got the file, but it is a firefox file... how do i make it svf file

devilsteps (author)devilsteps2012-09-05

nevermind i got it :D

angel_6571 (author)2012-06-27

Which way do we face the resistors ? Thanks

Superben51 (author)angel_65712012-06-27

The resistors are non polar, meaning that it doesn't matter which way they are.

Aaamazzara (author)2012-05-14

Are you sure this works? i have seen many people say that you need to have the diode in there on pin 11???

Superben51 (author)Aaamazzara2012-05-14

I know that it worked 100% for me. However if you are feeling worried about it (something about computer voltage-back or something) just throw it in there.

Aaamazzara (author)2012-04-22

Im having a problem with this part of it. I dont know what schematic to use. I am trying to program my coolrunner, im planning on going with the first picture but i dont understand what you mean by dont use the power. Then what do i do?

Superben51 (author)Aaamazzara2012-04-23

What I mean is don't use the batteries. The LPT port on your computer will supply the power needed if you leave out the batteries.

awesome8889 (author)2012-02-25

Can you do this with the new xbox 360 slim??

Superben51 (author)awesome88892012-02-25

yes but you need to have a trinity motherboard. and the solder points are different i'll try and update the guide soon.

Aaamazzara (author)2012-01-26

So with this method we dont need to buy a nand pro?

Superben51 (author)Aaamazzara2012-01-27

yup i only bought the cool runner the rest i had kicking around

About This Instructable

396,564views

86favorites

License:

More by Superben51:How to hack/RHG your Xbox 360knex PS3 game holderhow to mod the xbox 360 ring of light
Add instructable to: