How to Hack/RHG Your Xbox 360

419,780

87

38

Intro: How to Hack/RHG Your Xbox 360

If you want to hack your Xbox 360 and your dashboard version is over 7371 then the only way that you can hack it is with the reset glitch hack (RGH). When I started looking for a way to hack my 360 I heard about the jtag method only to find out that my dashboard was newer then 7371, but in early September a hardware exploit was developed know as the RGH. Basically what the RGH does is send a single to the processor that tells it to reset. Usually it would do exactly that however if the single is sent when it is booting up it allows us to run unsigned code.

to perform this RGH and utilize the exploit what you will need to do is read the NAND, install the modchip, write the NAND and installing your dash board of choice (i will be using xexmenu).

To do this you will need:

modchip (i will be using the coolrunner from team-xecuter)

coolrunner LPT program cable

male LPT port (printer cable) (x1)

wires (x12 this will be your LPT cable so make them long)

computer with a female LPT port

a program to read the NAND (i used nandprob 2 you can find it HERE)

soldering iron

solder

Jtag tool (software)

360gcprog (software)

flux (not needed but HIGHLY recommended)

***Disclaimer: I am not liable for any damage that may be caused to your property or self from following the instructions in this tutorial. Soldering irons can be very hot and cause burns, as well as possibly break your Xbox 360. Opening your xbox 360's shell will void its warranty. *** 
 
now then lets get started. first you need to completely take apart you 360 there are plenty of guides to do that so i wont cover it here. When the case is removed it should look like the picture. i highly suggest that you take off the metal case it sits in so that you can access the bottom of the motherboard. 

Step 1: Checking What Motherboard You Have

to check what mother board you have to turn the 360 around and look where you plug in the power cable, then use the first picture to find out witch one looks like yours and what motherboard you have.you are now ready to build a nand cable and dump your nand

note: no xenon or corona motherboards are hack-able yet and i've been told that zephyr xbox's have a very low success rate.

Step 2: Reading the NAND

To read the NAND, which is basically the Boot Sector of the Xbox 360, you will need to solder cables to the motherboard in very specific spots. To find those points use the diagram in the first pictures, make sure you find it on the xbox, and flip the motherboard upside down making sure you can see the bottom of the points that you are going to solder to. I suggest flipping the motherboard upside down because the points are small bumps of solder removing any need to add external solder. I also put the resistor leg on the motherboard because they were easier to solder in to place.    

Step 3: Reading the NAND

So if your soldering connections are strong and not overlapping anywhere then we are ready to read the NAND. open and install nandprob and restart your computer. After it has booted up again, open cmd and navigate to where the nandprob 2.0 folder is found and enter into the folder after you are inside type in (nandpro.exe lpt: -r16 nand1.bin) without the brackets. After the first one is done hit the up arrow key and change the nand1.bin part of the command to nand2.bin and dump the nand again. DUMPING MORE THEN ONCE IS VERY VERY IMPORTANT. Once you are done dumping all the times you want compare the files with total commander.you NEED to have two or more  matching dumps before moving on.

it is alright to have 1 or 2 bad blocks in the NAND just so long as all the dumps are the same.

Step 4: Checking If Your Xbox Is Exploitable

if you have a slim skip this step
to make sure that your xbox is exploitable the you need to know the CB version.
Check the number in the 2BL [CB] field. The CB needs to be one of the following to be exploitable.

Zephyr: 4578, 4579
Falcon and Opus: 5771
Jasper: 6750, 6751

If the CB is not one of the numbers above, the console is not covered in this guide. Since writing this an new exploit call RGH 2.0 has made all phat Xboxs hackable was been released, However I have not had any experience with it.

Step 5: Coolrunner LPT Program Cable

you can just go buy a cable to program your coolrunner for you or if your really going to go all out with DIY then heres how to make your own. the second image is a different one if the first one didn't work for you.

you'll need

male LPT port

4.8 kohm resistor

if the first cable didn't work then you'll need

male LPT port

220 omh resister (x1)

3.3 komh ressister (x3)

1N4148 diode (x3)

Step 6: Programing the Coolrunner

now download the correct .xsvf file for your xbox and open up the 360gcprog and follow the first image from top to bottom. the .xsvf files you flash onto the coolrunner tells it what kind of motherboard you have and then tells it the exact timing for the coolrunner to send the reset pulse to the processer.

Step 7: Install/solder the Mod Chip In

now come the fun part! you get to solder the cool-runner into the actual 360. if you can't solder small points now would be the time to get someone else to do this for you. the first picture is a complete over view and the ones after that are of my personal install.

the wires of the coolrunner are pre-tinned and cut to the perfect length for optimum glitch time (how long it takes to boot up). i would suggest just putting small amounts of flux on the wires and the motherboard, then touching the wire down and applying the soldering iron until the solder on the wire melts into place.

Step 8: Write the Nand

remember those nand dumps we made at the beginning? well now it is time to use them to make something called freeboot. to make the freeboot file you need the cpu key from your xbox so open up jtag tool and follow the images.

Step 9: Installing Xexmenu

ok so now that you have freeboot installed you can start up your xbox and if it boots then everything is good so you can unsolder the nand cable and pack up your xbox back in the case and put it where it would normally go, everything will be done with usb from now on. you need to get a usb stick and format it with the xbox. download the program i have uploaded and go HERE for the files for xex menu. open up the program you downloaded and follow the images.

note: your xbox will not boot to xexmenu you will still have to go though the MS dashboard and launch it. although it is possible to make it so it will boot to it i am not including the instructions in this 'able.

Step 10: Launching Xexmenu

plug the usb stick back into your xbox and go to demos. there should be one called xexmenu, just click play. from here you can play any homebrew apps you want or even full disk games like me. so just kick back and start enjoying your now fully hacked xbox 360

Step 11: BONUS... How to Play Iso's

okay so you have an iso that you ....ahem.... made and you want to play it. right?. it is actually very simple to do. just go here and download the program. extract that sucker with 7-zip. once you have that done open it up and hit the choose iso folder button and select the folder your game is in. choose a destination folder, make sure that your iso shows up and hit the go button. once it is done extracting take all the files and transfer it to the xbox's harddrive or usb. load up xexmenu and it should list your game right away.

Share

    Recommendations

    • Audio Contest 2018

      Audio Contest 2018
    • Electronics Tips & Tricks Challenge

      Electronics Tips & Tricks Challenge
    • Plastics Contest

      Plastics Contest

    38 Discussions

    0
    None
    bleumods

    1 year ago

    under step 6 i didnt see a download for the corona? Does this work for the corona?

    0
    None
    bleumods

    1 year ago

    at the 6th step for programming the cool runner but i dont see a download for the corona? this works for the corona right? if so which download is the corona

    0
    None
    St8kout.

    2 years ago

    Not sure why you mention "flux" at the end, unless you are using the wrong type of solder.

    There's basically two types of solder:

    -Rosin core, for electronics. Already has flux in it. Nothing else to add.

    -Acid core, for plumbing, NOT for electronics. Often the paste comes separately from the solder. This kind likes to eat circuit boards. Again, NOT for electronics.

    2 replies
    0
    None
    Project DSt8kout.

    Reply 1 year ago

    In fact, I'd go so far as to say it's very common. Rosin-core solder works fine, but applying flux works so much better than the rosin core alone.

    0
    None
    GeorgeS302St8kout.

    Reply 1 year ago

    It's not uncommon to add a bit of extra flux to the board you're trying to solder to in order to get the solder to flow properly. It helps keep things a bit tidier.

    0
    None
    camronshaw6565

    1 year ago

    Hey!! I Just got my JTaged xbox back and i need the next step i got paypal ill pay just email me at Camrondshaw@gmail.com or cal or Text at 765-508-1075

    0
    None
    The Lost Puppy

    2 years ago

    Nice guide, but what's up with the ds passme in step 5?

    0
    None
    Superben51devilsteps

    Reply 5 years ago on Step 3

    Dump again, then compare them. If there is still an error dump one more time and compare. Depending on the address the block is at it might be okay to continue but I would STRONGLY advise against it because if you don't get a good dump then if something goes wrong (which is very possible with non matching nands, if the error in the wrong sector) you don't have a stock nand to flash back and lose your xbox. If however you want to continue then look into using J-runner for making the ECC image.

    0
    None
    KRIPTICxKILLER

    3 years ago

    Can I have one shipped to me for money?

    0
    None
    CurtyK

    3 years ago

    Are you sure this works 100%

    0
    None
    sfjuocekr

    3 years ago on Step 3

    Making three dumps is the minimum required to reconstruct a dump IF you have any read errors. I suggest you work on your soldering skills as I have personally never had issues dumping, but then again I have a background in electronics.

    If your dump takes A LONG time to complete AND you get differences on different spots. A shorten the wires and redo soldering spots.

    The best tip I can give you is to heat up the spot you are going to solder for a second or to, then apply some tin and remove the tin and iron. You always want to preheat the spot to solder on to to make the tin melt and then apply just a tiny speck extra to merge it with the tin on the wire you want to solder. I never use flux on solder spots like these, the tin you use is likely to have a resin (flux) core.

    here is an easy tutorial dor xbox 360 rgh :)

    http://consolesnews.com/tutorials/tutorial-installing-xbox-360-rgh-with-coolrunner/

    0
    None
    nicksv

    4 years ago on Introduction

    When reading nand you could have wrote that the xbox needs to have power on it, but not turned on.

    I tried reading the nand on two different computers. The one computer had bad blocks each time and i think i tried all bios setups.

    The other computer was running ECP mode in bios on the lpt cable. And that gave me the best reading. It remapped a little bit of the nand but it worked great.
    (I used XNandHealer to verify the nands)

    On some computers when reading the nand the xbox may turn on by it self. Either in the beggining of the reading or the end but will most likely turn it self off again.

    And for writing the nand. You could have added text to see what pictures are from the xbox and maybe a little text that describes what you are about to do. Had to look at other guides to figure out how to get it working.

    And for the coolrunner LPT cable i used another schematic that was more simple. http://img638.imageshack.us/img638/430/lptjtagprog... <- worked perfect for my coolrunner rev C. And this on both computers

    All in all it was an ok guide and i got it working. But its not very noob friendly.

    But i have a question. I don't understand after i did the RGH i was not able to play the games that was allready installed on the harddrive without it still asking for a disc. After that i updated the dashboard like this -> http://www.xpgamesaves.com/topic/103897-tutupdate-...

    And i have also played with the settings menu in xexmenu. Pretty much all i done and now it runs all the games i had allready installed on the harddrive..?

    What changed this you think? Is it the dashboard update or the settings thing in xexmenu?

    And last thing i run all the games from the normal game menu. Xexmenu does not find any games?

    0
    None
    evelez2

    4 years ago

    I was reading xexmenu is up to 1.5, is that correct? Where can I get it?