***** AutoGG _ gia aggiornato all'ultima versione 0.9.3 Rev 83f *****
* Per iniziare la procedura _ necessario il vostro NAND Dump:
- Se lo avete gi_ caricate il dump dal pulsante a forma di cartella.
- Se avete gi_ Fsd v3 collegate la console alla rete LAN e premete IP Xbox > Leggi.
- Se non avete FSD ma Xell provare a utilizzare il pulsante con l'icona Usb e seguire la procedura.
- Sel la console _ Retail ( Dash Originale ) installa e seleziona il tuo Nand reader e
premi Flasher > Leggi
* Se avete gi_ FSD v3 e si desidera aggiornarla selezionare la modalit_ LAN o USB e provare AutoUpdate-Dash
* Connecting
* Launching : "read" (ID: 3)
* Reading, Wait
* Waiting FSD..........................* Xbox is back
* Downloading NandDump from console Device (Usb0), please Wait
* DONE, Loading Dump.
CERCO LA NAND: "nand\nanddump.bin"
-------------------------------------------------------------------------------------------------------------
NandPro v3.0a by Tiros
Using Virtual Nand Device File: nand\nanddump.bin
Flash Config: 0x00023010
Block Size: 16KB Block Limits: 0x000000..0x000000
File: common\temp\flash.bin
Reading
0000
0000
-------------------------------------------------------------------------------------------------------------
Small Block trovato
Flashconfig:0023010 Size=16
Caricamento Nand ...OK
Controllando i Bad Blocks ...
Nessun Bad Block trovato
Checking ECC-CheckSum... Wait
-------------------------------------------------------------------------------------------------------------
Ecc Check: OK
-------------------------------------------------------------------------------------------------------------
Done
VERIFICA SMC_CONFIG
Smc Config trovato: 0x00FEB800
Lettura temperature...:
Reset Parental Code: YXAX
VERIFICA NAND DATA
ID: 257c97fd
ECC - unECC
Trovato SMC (version 3.1) : 00001000 - 00004000
SMC Patch found at offset 0x13b8
Nand NO RETAIL (Exploited)
Trovato Keyvault : 00004000 - 00008000
Looking for Cpukey in Local Database. Not Found
Alla ricerca della Cpukey in cpukey.txt. Not Found
Looking for Cpukey on Nand.Not Found
Trovato CB_A (build 9188) : 00008000 - 00009ac0
Trovato CB_B (build 9188) : 00009ac0 - 000112c0
Trovato CD (build 9452) : 000112c0 - 00016550
Trovato CE (build 1888) : 00016550 - 0006c5c0
Trovato CF (build 16547) : 000b0000- 000b4560
Trovato CF1 build : None
Trovato CG (build 16547) : 000b4560- 0012a00c
Trovato CG1 build : None
Nand valida
VERIFICA MODELLO CONSOLE
Verificando se _ modificabile...
Modello : Trinity CB_A_9188 GLITCHEABLE
CD_9452 Non JtaggABILE
Size: 16
Reloaded_Glitch.bin
-------------------------------------------------------------------------------------------------------------
1 file copiati.
-------------------------------------------------------------------------------------------------------------
FileSystems:
FileSystem Active:3 offset:0xEDF800
FileSystem Last:3 offset:0xEE0040
Block Size File
0x00001000 0x00003000 SMC_3.1.bin
0x00004000 0x00004000 Keyvault.bin
0x00008000 0x00001AC0 CB_A_9188.bin
0x00009AC0 0x00007800 CB_B_9188.bin
0x000112C0 0x00005290 CD_9452.bin
0x00016550 0x00056070 CE_1888.bin
0x000B0000 0x00004560 CF_16547.bin
0x000B4560 0x00075AAC CG_16547.bin
0x000D0000 0x0006A010 sysupdate.xexp1
0x0013C000 0x00014000 aac.xexp1
0x00150000 0x00061000 bootanim.xex
0x001B4000 0x0000C000 createprofile.xex
0x001C0000 0x00598000 dash.xex
0x00758000 0x0000A000 deviceselector.xex
0x00764000 0x0001B000 gamerprofile.xex
0x00780000 0x0001D000 hud.xex
0x007A0000 0x00014000 huduiskin.xex
0x007B4000 0x00008000 mfgbootlauncher.xex
0x007BC000 0x0000C000 minimediaplayer.xex
0x007C8000 0x0000C800 nomni.xexp1
0x007D8000 0x00002000 nomnifwk.xexp1
0x007DC000 0x00005000 nomnifwm.xexp1
0x007EC000 0x00019000 signin.xex
0x00808000 0x00007000 updater.xex
0x00810000 0x0000B000 vk.xex
0x0081C000 0x00253000 xam.xex
0x00A70000 0x0011B000 xenonclatin.xtt
0x00B8C000 0x00018000 xenonclatin.xttp1
0x00BA4000 0x001A8000 xenonjklatin.xtt
0x00D4C000 0x00007000 xenonjklatin.xttp1
0x00D54000 0x00017000 ximecore.xex
0x00D6C000 0x00090000 ximedic.xex
0x00DFC000 0x00002800 ximedic.xexp1
0x00E00000 0x0000D000 launch.xex
0x00E10000 0x00006000 lhelper.xex
0x00E18000 0x0000D000 launch.xex
0x00E28000 0x00006000 lhelper.xex
0x00E30000 0x00000A00 crl.bin
0x00E34000 0x0000AD30 dae.bin
0x00E68000 0x00004000 extended.bin
0x00E44000 0x00004000 fcrt.bin
0x00E48000 0x00000400 secdata.bin
-------------------------------------------------------------------------------------------------------------
* CpuKey sconosciuta. Se la sai inseriscila nel campo "Cpukey" o usa altri
metodi per recuperarla.
* Qualora non l'abbiate ottenuta scegliere ancora XeLL>Tipo e premere NandXell>Crea
-------------------------------------------------------------------------------------------------------------
Copia salvata come:
nands\backups\257c97fd\nanddump_381.bin
Sto scaricando l'update.Attendere,prego
common/16747_.exe Bytes: 11464781 ...
Extracting, Wait...
Sto scaricando l'update.Attendere,prego
common/Systemupdates/16747.exe Bytes: 114846937 ...
Extracting, Wait...
Done
Iniettando... Verifica file.
Keyvault Not Set, Donor will be used
Generating Random Cpukey
CpuKey non valida per la Nand selezionata
Cpukey: 6D7F11120E87776C3F0CD02D2E120ADD
Questa opzione verr_ usata per creare l'immagine:
-o patchsmc -noenter -t Glitch2m -o cfldv=3 -c Trinity -d ..\nand -f 16747 -b DD88AD0C9ED669E7B56794FB68563EFA -p 6D7F11120E87776C3F0CD02D2E120ADD ..\output\nandflash.bin -v
-------------------------------------------------------------------------------------------------------------
---------------------------------------------------------------
xeBuild v1.12.659
---------------------------------------------------------------
---- { Image Build Mode } ----
building glitch2 mfg image
verbose set to level 1
------ parsing user ini at '..\nand\options.ini' ------
******* WARNING: could not open user ini at '..\nand\options.ini', skipping
default console DVD eject button is being used to start xell
------ parsing ini at '16747\_glitch2m.ini' ------
ini version 16747mfg
ini: label [trinitybl] found
found (1) 'cba_9188_mfg.bin' crc: 0xe7ff60d0
found (2) 'cbb_9188.bin' crc: 0xfebb1074
found (3) 'cd_9452.bin' crc: 0x455fa02c
found (4) 'ce_1888.bin' crc: 0xff9b60df
found (5) 'cf_16747.bin' crc: 0x94a4ef68
found (6) 'cg_16747.bin' crc: 0x88e1e9b9
ini dictates dual CB for this model
ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x12d353e9
found (2) 'bootanim.xex' crc: 0x151b0618
found (3) 'createprofile.xex' crc: 0x32ceed5a
found (4) 'dash.xex' crc: 0x4103a319
found (5) 'deviceselector.xex' crc: 0xfe497738
found (6) 'gamerprofile.xex' crc: 0xef9022d5
found (7) 'hud.xex' crc: 0xc0e76e31
found (8) 'huduiskin.xex' crc: 0x155495d3
found (9) 'mfgbootlauncher.xex' crc: 0xdecbab8e
found (10) 'minimediaplayer.xex' crc: 0x2892b8d5
found (11) 'nomni.xexp' crc: 0xdcef767a
found (12) 'nomnifwk.xexp' crc: 0x0d14c998
found (13) 'nomnifwm.xexp' crc: 0xdc46bb6e
found (14) 'SegoeXbox-Light.xtt' crc: 0xe0ee6049
found (15) 'signin.xex' crc: 0xcbfce61f
found (16) 'updater.xex' crc: 0xafef5cf0
found (17) 'vk.xex' crc: 0xf2caff49
found (18) 'xam.xex' crc: 0x79f6eabf
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0xe2adddfb
found (23) 'ximecore.xex' crc: 0x4c2f6bd1
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0x34c9b084
found (26) '..\launch.xex' crc: 0x00000000
found (27) '..\lhelper.xex' crc: 0x00000000
found (28) '..\launch.ini' crc: 0x00000000
ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'fcrt.bin' crc: 0x00000000
found (5) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------
output name overridden to: ..\output\nandflash.bin
1BL RSA pub key file is not available, signature checks will not be performed
PIRS RSA pub key file is not available, signature checks will not be performed
MASTER RSA pub key file is not available, signature checks will not be performed
------ Checking ..\nand\nanddump.bin ------
..\nand\nanddump.bin file size: 0x1080000
nanddump header checks passed OK!
Loading NAND dump (0x1080000 bytes)...done!
Detecting NAND controller type from dump data...
NAND dump is from a small block machine
NAND dump uses big block controller
parsing dump into user and spare...
done!
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypt failed, discarding
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0xf7c000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x03 Pairing: 0x907ea0
setting pairing data from image to 0x907ea0
pairing set to: 90 7e a0
LDV was already set to 3
MobileB.dat found at block 0x3b3, page 0x4 (page 0x7664), size 2048 (0x800) bytes
MobileC.dat found at block 0x394, page 0x0 (page 0x7280), size 512 (0x200) bytes
MobileD.dat found at block 0x395, page 0x0 (page 0x72a0), size 2048 (0x800) bytes
MobileE.dat found at block 0x396, page 0xc (page 0x72cc), size 2048 (0x800) bytes
Statistics.settings found at page 0x7bc0, size 4096 (0x1000) bytes
seeking FSRoot...fsroot found at block 0x39b, page 0x0 (page 0x7360) raw offset 0x7360
seeking security files...
crl.bin found in sector 0x38c size 0xa00...verify failed! Discarding data.
dae.bin found in sector 0x38d size 0xad30...
******* ERROR: dae hash incorrect, could not decrypt!
verify failed! Discarding data.
extended.bin found in sector 0x39a size 0x4000...verify failed! Discarding data.
fcrt.bin found in sector 0x391 size 0x4000...pub key to verify signature is not available, skipping!
******* ERROR: FCRT hash check failed, could not decrypt!
verify failed! Discarding data.
secdata.bin found in sector 0x392 size 0x400...verify failed! Discarding data.
done!
Writing initial header to flash image
------ loading system update container ------
16747\su20076000_00000000 found, loading...done!
Read 0xb35000 bytes to memory
checking integrity...
header seems valid, version 2.0.16747.0
header hash is OK, checking content hashes...
content hashes seem OK, everything looks good!
extracted SUPD\xboxupd.bin (0x7a010 bytes)
decrypting SUPD\xboxupd.bin\CF_16747.bin (0x4560 bytes)...done!
decrypting SUPD\xboxupd.bin\CG_16747.bin (0x75aaa bytes)...done!
------ Loading bootloaders and required security files ------
reading ..\nand\smc.bin (0x3000 bytes)
reset smc load address to 0x1000 size 0x3000
reading ..\nand\kv.bin (0x4000 bytes)
reading .\common\cba_9188_mfg.bin (0x1ac0 bytes)
loaded cba_9188_mfg.bin, could not check signature rsa key not present!
reading .\common\cbb_9188.bin (0x7800 bytes)
reading .\common\cd_9452.bin (0x4f20 bytes)
reading .\common\ce_1888.bin (0x5606a b pad 0x56070 b)
reading ..\nand\xell-gggggg.bin (0x40000 bytes)
extracted SUPD\xboxupd.bin\CF_16747.bin (0x4560 bytes)
extracted SUPD\xboxupd.bin\CG_16747.bin (0x75aaa bytes)
reading 16747\bin\patches_g2mtrinity.bin (0xa34 bytes)
reading ..\nand\smc_config.bin (0x10000 bytes)
-------------------
checking smc_config
-------------------
extracting config
valid SMC config data found at offset 0xc000
------------------
SMC config info:
------------------
Target temps: Cpu: 82_C Gpu: 78_C Edram: 76_C
Max temps : Cpu: 89_C Gpu: 82_C Edram: 82_C
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : 7c:ed:8d:5f:44:c2
AVRegion : 0x00000300 (PAL50)
GameRegion : 0x02fe (PAL/EU)
DVDRegion : 2
resetKey : YXAX
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
could not check signature of cba_9188_mfg.bin, 1BL RSA key not present!
done!
patch slot offset reset to: 0xb0000
------ Patching BLs and modifying patches ------
Patching BLs...Done!
------ Patching boot reasons and options into flash header ------
Patching header for xell power reason
------ Encrypting and finalizing bootloaders ------
Fuse CPU Key set to: 0x6D7F11120E87776C3F0CD02D2E120ADD
Fuse CF LDV set to : 0xFFF00000000000000000000000000000
encoding smc.bin size 0x3000
SMC checksum: 87e726b7
unknown SMC found, type: Trinity v5.1(3.01)
glitch hack found in SMC binary!
encoding kv.bin size 0x4000
kv.bin appears to be decrypted already, but the hash does not match the CPU key...
******* WARNING: could not verify pre-decrypted keyvault, please be sure your provided a valid kv.bin!
decrypted keyvault has been set for reference
encoding cba_9188_mfg.bin size 0x1ac0
encoding cbb_9188.bin size 0x7800
CB 9188 seq 0x03010001 type: 0x03 cseq: 0x01 allow: 0x0001
expected fuses:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0FF0F0
fuseset 02: F000000000000000 (sequence)
fuseset 02: F000000000000000 (allow cseq 1)
**dual CB flag detected!**
** CBB crypto method set to work with mfg CBA!**
encoding cd_9452.bin size 0x5290
encoding ce_1888.bin size 0x56070
encoding xell-gggggg.bin size 0x40000
encoding cf_16747.bin size 0x4560
encoding cg_16747.bin size 0x75ab0
encoding fuses.bin size 0x60
encoding patches_g2mtrinity.bin size 0x5dc
Virtual Fuses set to:
fuseset 00: C0FFFFFFFFFFFFFF
fuseset 01: 0F0F0F0F0F0FF0F0
fuseset 02: F000000000000000
fuseset 03: 6D7F11120E87776C
fuseset 04: 6D7F11120E87776C
fuseset 05: 3F0CD02D2E120ADD
fuseset 06: 3F0CD02D2E120ADD
fuseset 07: FFF0000000000000
fuseset 08: 0000000000000000
fuseset 09: 0000000000000000
fuseset 10: 0000000000000000
fuseset 11: 0000000000000000
done!
------ Adding bootloaders to flash image ------
adding smc.bin at raw offset 0x00001000 len 0x3000 (end 0x4000)
adding kv.bin at raw offset 0x00004000 len 0x4000 (end 0x8000)
adding cba_9188_mfg.bin at raw offset 0x00008000 len 0x1ac0 (end 0x9ac0)
adding cbb_9188.bin at raw offset 0x00009ac0 len 0x7800 (end 0x112c0)
adding cd_9452.bin at raw offset 0x000112c0 len 0x5290 (end 0x16550)
adding ce_1888.bin at raw offset 0x00016550 len 0x56070 (end 0x6c5c0)
adding xell-gggggg.bin at raw offset 0x00070000 len 0x40000 (end 0xb0000)
adding cf_16747.bin at raw offset 0x000b0000 len 0x4560 (end 0xb4560)
adding cg_16747.bin at raw offset 0x000b4560 len 0x75ab0 (end 0xc0000, rest in fs)
adding fuses.bin at raw offset 0x000c0000 len 0x60 (end 0xc0060)
adding patches_g2mtrinity.bin at raw offset 0x000c0060 len 0x5dc (end 0xc063c)
Fixing up FS table...done!
Writing zeropair CG patch slot overflow data to sysupdate.xexp1
at raw offset 0xd0000 len 0x0006a010 (end: 0x0013a010)...done!
------ adding 28 firmware files ------
extracted SUPD\aac.xexp (0x14000 bytes) (crc32: 0x12d353e9 ini: 0x12d353e9)
adding as aac.xexp1 at raw offset 0x13a010 len 0x00014000 (end 0x0014e010)
extracted SUPD\bootanim.xex (0x61000 bytes) (crc32: 0x151b0618 ini: 0x151b0618)
adding as bootanim.xex at raw offset 0x150000 len 0x00061000 (end 0x001b1000)
extracted SUPD\createprofile.xex (0xc000 bytes) (crc32: 0x32ceed5a ini: 0x32ceed5a)
adding as createprofile.xex at raw offset 0x1b1000 len 0x0000c000 (end 0x001bd000)
extracted SUPD\dash.xex (0x598000 bytes) (crc32: 0x4103a319 ini: 0x4103a319)
adding as dash.xex at raw offset 0x1c0000 len 0x00598000 (end 0x00758000)
extracted SUPD\deviceselector.xex (0xa000 bytes) (crc32: 0xfe497738 ini: 0xfe497738)
adding as deviceselector.xex at raw offset 0x758000 len 0x0000a000 (end 0x00762000)
extracted SUPD\gamerprofile.xex (0x1b000 bytes) (crc32: 0xef9022d5 ini: 0xef9022d5)
adding as gamerprofile.xex at raw offset 0x762000 len 0x0001b000 (end 0x0077d000)
extracted SUPD\hud.xex (0x1d000 bytes) (crc32: 0xc0e76e31 ini: 0xc0e76e31)
adding as hud.xex at raw offset 0x77f000 len 0x0001d000 (end 0x0079c000)
extracted SUPD\huduiskin.xex (0x14000 bytes) (crc32: 0x155495d3 ini: 0x155495d3)
adding as huduiskin.xex at raw offset 0x79d000 len 0x00014000 (end 0x007b1000)
extracted SUPD\mfgbootlauncher.xex (0x8000 bytes) (crc32: 0xdecbab8e ini: 0xdecbab8e)
adding as mfgbootlauncher.xex at raw offset 0x7b4000 len 0x00008000 (end 0x007bc000)
extracted SUPD\minimediaplayer.xex (0xc000 bytes) (crc32: 0x2892b8d5 ini: 0x2892b8d5)
adding as minimediaplayer.xex at raw offset 0x7bc000 len 0x0000c000 (end 0x007c8000)
extracted SUPD\nomni.xexp (0xc800 bytes) (crc32: 0xdcef767a ini: 0xdcef767a)
adding as nomni.xexp1 at raw offset 0x7c8000 len 0x0000c800 (end 0x007d4800)
extracted SUPD\nomnifwk.xexp (0x2000 bytes) (crc32: 0x0d14c998 ini: 0x0d14c998)
adding as nomnifwk.xexp1 at raw offset 0x7d4800 len 0x00002000 (end 0x007d6800)
extracted SUPD\nomnifwm.xexp (0x5000 bytes) (crc32: 0xdc46bb6e ini: 0xdc46bb6e)
adding as nomnifwm.xexp1 at raw offset 0x7da000 len 0x00005000 (end 0x007df000)
extracted SUPD\SegoeXbox-Light.xtt (0x6000 bytes) (crc32: 0xe0ee6049 ini: 0xe0ee6049)
adding as SegoeXbox-Light.xtt at raw offset 0x7e1000 len 0x00006000 (end 0x007e7000)
extracted SUPD\signin.xex (0x19000 bytes) (crc32: 0xcbfce61f ini: 0xcbfce61f)
adding as signin.xex at raw offset 0x7ea000 len 0x00019000 (end 0x00803000)
extracted SUPD\updater.xex (0x7000 bytes) (crc32: 0xafef5cf0 ini: 0xafef5cf0)
adding as updater.xex at raw offset 0x805000 len 0x00007000 (end 0x0080c000)
extracted SUPD\vk.xex (0xb000 bytes) (crc32: 0xf2caff49 ini: 0xf2caff49)
adding as vk.xex at raw offset 0x80f000 len 0x0000b000 (end 0x0081a000)
extracted SUPD\xam.xex (0x253000 bytes) (crc32: 0x79f6eabf ini: 0x79f6eabf)
adding as xam.xex at raw offset 0x81b000 len 0x00253000 (end 0x00a6e000)
extracted nanddump\xenonclatin.xtt (0x11b000 bytes) (crc32: 0xd5d17ff5 ini: 0xd5d17ff5)
adding as xenonclatin.xtt at raw offset 0xa6f000 len 0x0011b000 (end 0x00b8a000)
extracted SUPD\xenonclatin.xttp (0x18000 bytes) (crc32: 0x7a507ad1 ini: 0x7a507ad1)
adding as xenonclatin.xttp1 at raw offset 0xb8b000 len 0x00018000 (end 0x00ba3000)
extracted nanddump\xenonjklatin.xtt (0x1a8000 bytes) (crc32: 0xdde4a14c ini: 0xdde4a14c)
adding as xenonjklatin.xtt at raw offset 0xba4000 len 0x001a8000 (end 0x00d4c000)
extracted SUPD\xenonjklatin.xttp (0x7000 bytes) (crc32: 0xe2adddfb ini: 0xe2adddfb)
adding as xenonjklatin.xttp1 at raw offset 0xd4c000 len 0x00007000 (end 0x00d53000)
extracted SUPD\ximecore.xex (0x17000 bytes) (crc32: 0x4c2f6bd1 ini: 0x4c2f6bd1)
adding as ximecore.xex at raw offset 0xd53000 len 0x00017000 (end 0x00d6a000)
extracted nanddump\ximedic.xex (0x90000 bytes) (crc32: 0x1d992bfb ini: 0x1d992bfb)
adding as ximedic.xex at raw offset 0xd6b000 len 0x00090000 (end 0x00dfb000)
extracted SUPD\ximedic.xexp (0x2800 bytes) (crc32: 0x34c9b084 ini: 0x34c9b084)
adding as ximedic.xexp1 at raw offset 0xdfc000 len 0x00002800 (end 0x00dfe800)
reading 16747\..\launch.xex (0xd000 bytes)
adding as launch.xex at raw offset 0xdfe800 len 0x0000d000 (end 0x00e0b800)
reading 16747\..\lhelper.xex (0x6000 bytes)
adding as lhelper.xex at raw offset 0xe0d000 len 0x00006000 (end 0x00e13000)
reading 16747\..\launch.ini (0x2e5 bytes)
adding as launch.ini at raw offset 0xe16000 len 0x000002e5 (end 0x00e162e5)
------ adding 5 security files ------
<- Processing crl.bin ->
reading ..\nand\crl.bin (0xa00 bytes)
crl appears crypted, attempting to decrypt with CPU key...failed! Trying alternate key...success!
adding as crl.bin at raw offset 0xe1c000 len 0x00000a00 (end 0x00e1ca00)
<- Processing dae.bin ->
reading ..\nand\dae.bin (0xad30 bytes)
dae appears encrypted, attempting to decrypt with CPU key...failed! Attempting to decrypt with alternate key...
success!
adding as dae.bin at raw offset 0xe20000 len 0x0000ad30 (end 0x00e2ad30)
<- Processing extended.bin ->
reading ..\nand\extended.bin (0x4000 bytes)
adding as extended.bin at raw offset 0xe2c000 len 0x00004000 (end 0x00e30000)
<- Processing fcrt.bin ->
reading ..\nand\fcrt.bin (0x4000 bytes)
pub key to verify signature is not available, skipping!
******* ERROR: FCRT hash check failed, could not decrypt!
****** WARNING: FCRT data appears to be crypted or damaged!! Skipping encryption.
adding as fcrt.bin at raw offset 0xe30000 len 0x00004000 (end 0x00e34000)
<- Processing secdata.bin ->
reading ..\nand\secdata.bin (0x400 bytes)
adding as secdata.bin at raw offset 0xe34000 len 0x00000400 (end 0x00e34400)
------ checking for Mobile*.dat ------
MobileB.dat found, adding from previous parse
adding MobileB.dat as type 0x31 at raw offset 0xe38000 len 0x800 (end 0xe38800)
MobileC.dat found, adding from previous parse
adding MobileC.dat as type 0x32 at raw offset 0xe3c000 len 0x200 (end 0xe3c200)
MobileD.dat found, adding from previous parse
adding MobileD.dat as type 0x33 at raw offset 0xe40000 len 0x800 (end 0xe40800)
MobileE.dat found, adding from previous parse
adding MobileE.dat as type 0x34 at raw offset 0xe44000 len 0x800 (end 0xe44800)
Statistics.settings found, adding from previous parse
adding Statistics.settings at raw offset 0xf78000 len 0x1000 (end 0xf79000)
------ adding smc_config.bin ------
adding smc config to offset 0x00f7c000, len 0x400
------ finalizing image ------
Fixing up empty FS block entries...done!
Writing FS table to image offset 0xe48000 len 0x4000 (end 0xe4c000)...done!
fixing up big block controller on small block NAND LBA numbers...done!
calculating ECD bytes and assembling raw image...done!
done remapping!
------ writing image to disk ------
writing file '..\output\nandflash.bin' to disk...done!
---------------------------------------------------------------
..\output\nandflash.bin image built, info:
---------------------------------------------------------------
Kernel : 2.0.16747.0
Console : Trinity
NAND size : 16MiB
Build : Glitch (v2 mfg)
Xell : power on console with console eject button
Serial : 111111111111
ConsoleId : 016896097961
MoboSerial: 7029729100079265
Mfg Date : 06/23/2009
CPU Key : 6D7F11120E87776C3F0CD02D2E120ADD
1BL Key : DD88AD0C9ED669E7B56794FB68563EFA
DVD Key : 11111111111111111111111111111111
CF LDV : 3
KV type : type1 (no hash)
---------------------------------------------------------------
xeBuild Finished. Have a nice day.
---------------------------------------------------------------
-------------------------------------------------------------------------------------------------------------
Nand generata
output\nandflash.bin
Usb Selected for Auto-Mode
Lan Selected for Auto-Mode
CpuKey non valida per la Nand selezionata
Iniettando... Verifica file.
Keyvault Not Set, Donor will be used
Questa opzione verr_ usata per creare l'immagine:
-o patchsmc -noenter -t Glitch -o cfldv=3 -c Trinity -d ..\nand -f 16747 -b DD88AD0C9ED669E7B56794FB68563EFA -p 6D7F11120E87776C3F0CD02D2E120ADD ..\output\nandflash.bin -v
-------------------------------------------------------------------------------------------------------------
---------------------------------------------------------------
xeBuild v1.12.659
---------------------------------------------------------------
---- { Image Build Mode } ----
building glitch image
verbose set to level 1
------ parsing user ini at '..\nand\options.ini' ------
******* WARNING: could not open user ini at '..\nand\options.ini', skipping
default console DVD eject button is being used to start xell
------ parsing ini at '16747\_glitch.ini' ------
ini version 16747
ini: label [trinitybl] found
found (1) 'cba_9188.bin' crc: 0x5a76752d
found (2) 'cbb_9188.bin' crc: 0xfebb1074
found (3) 'cd_9452.bin' crc: 0x455fa02c
found (4) 'ce_1888.bin' crc: 0xff9b60df
found (5) 'cf_16747.bin' crc: 0x94a4ef68
found (6) 'cg_16747.bin' crc: 0x88e1e9b9
ini dictates dual CB for this model
ini: label [flashfs] found
found (1) 'aac.xexp' crc: 0x12d353e9
found (2) 'bootanim.xex' crc: 0x151b0618
found (3) 'createprofile.xex' crc: 0x32ceed5a
found (4) 'dash.xex' crc: 0x4103a319
found (5) 'deviceselector.xex' crc: 0xfe497738
found (6) 'gamerprofile.xex' crc: 0xef9022d5
found (7) 'hud.xex' crc: 0xc0e76e31
found (8) 'huduiskin.xex' crc: 0x155495d3
found (9) 'mfgbootlauncher.xex' crc: 0xdecbab8e
found (10) 'minimediaplayer.xex' crc: 0x2892b8d5
found (11) 'nomni.xexp' crc: 0xdcef767a
found (12) 'nomnifwk.xexp' crc: 0x0d14c998
found (13) 'nomnifwm.xexp' crc: 0xdc46bb6e
found (14) 'SegoeXbox-Light.xtt' crc: 0xe0ee6049
found (15) 'signin.xex' crc: 0xcbfce61f
found (16) 'updater.xex' crc: 0xafef5cf0
found (17) 'vk.xex' crc: 0xf2caff49
found (18) 'xam.xex' crc: 0x79f6eabf
found (19) 'xenonclatin.xtt' crc: 0xd5d17ff5
found (20) 'xenonclatin.xttp' crc: 0x7a507ad1
found (21) 'xenonjklatin.xtt' crc: 0xdde4a14c
found (22) 'xenonjklatin.xttp' crc: 0xe2adddfb
found (23) 'ximecore.xex' crc: 0x4c2f6bd1
found (24) 'ximedic.xex' crc: 0x1d992bfb
found (25) 'ximedic.xexp' crc: 0x34c9b084
found (26) '..\launch.xex' crc: 0x00000000
found (27) '..\lhelper.xex' crc: 0x00000000
found (28) '..\launch.ini' crc: 0x00000000
ini: label [security] found
found (1) 'crl.bin' crc: 0x00000000
found (2) 'dae.bin' crc: 0x00000000
found (3) 'extended.bin' crc: 0x00000000
found (4) 'fcrt.bin' crc: 0x00000000
found (5) 'secdata.bin' crc: 0x00000000
------ ini parsing completed ------
output name overridden to: ..\output\nandflash.bin
1BL RSA pub key file is not available, signature checks will not be performed
PIRS RSA pub key file is not available, signature checks will not be performed
MASTER RSA pub key file is not available, signature checks will not be performed
------ Checking ..\nand\nanddump.bin ------
..\nand\nanddump.bin file size: 0x1080000
nanddump header checks passed OK!
Loading NAND dump (0x1080000 bytes)...done!
Detecting NAND controller type from dump data...
NAND dump is from a small block machine
NAND dump uses big block controller
parsing dump into user and spare...
done!
decrypting KeyVault at address 0x4000 of size 0x4000
keyvault decrypt failed, discarding
decrypting SMC at address 0x1000 of size 0x3000
SMC decrypted OK, will use if no external smc.bin is provided
seeking smc config in dump...found at offset 0xf7c000! Using if no smc config is provided.
CF slot 0 decrypted ok LDV 0x03 Pairing: 0x907ea0
setting pairing data from image to 0x907ea0
pairing set to: 90 7e a0
LDV was already set to 3
MobileB.dat found at block 0x3b3, page 0x4 (page 0x7664), size 2048 (0x800) bytes
MobileC.dat found at block 0x394, page 0x0 (page 0x7280), size 512 (0x200) bytes
MobileD.dat found at block 0x395, page 0x0 (page 0x72a0), size 2048 (0x800) bytes
MobileE.dat found at block 0x396, page 0xc (page 0x72cc), size 2048 (0x800) bytes
Statistics.settings found at page 0x7bc0, size 4096 (0x1000) bytes
seeking FSRoot...fsroot found at block 0x39b, page 0x0 (page 0x7360) raw offset 0x7360
seeking security files...
crl.bin found in sector 0x38c size 0xa00...verify failed! Discarding data.
dae.bin found in sector 0x38d size 0xad30...
******* ERROR: dae hash incorrect, could not decrypt!
verify failed! Discarding data.
extended.bin found in sector 0x39a size 0x4000...verify failed! Discarding data.
fcrt.bin found in sector 0x391 size 0x4000...pub key to verify signature is not available, skipping!
******* ERROR: FCRT hash check failed, could not decrypt!
verify failed! Discarding data.
secdata.bin found in sector 0x392 size 0x400...verify failed! Discarding data.
done!
Writing initial header to flash image
------ loading system update container ------
16747\su20076000_00000000 found, loading...done!
Read 0xb35000 bytes to memory
checking integrity...
header seems valid, version 2.0.16747.0
header hash is OK, checking content hashes...
content hashes seem OK, everything looks good!
extracted SUPD\xboxupd.bin (0x7a010 bytes)
decrypting SUPD\xboxupd.bin\CF_16747.bin (0x4560 bytes)...done!
decrypting SUPD\xboxupd.bin\CG_16747.bin (0x75aaa bytes)...done!
------ Loading bootloaders and required security files ------
reading ..\nand\smc.bin (0x3000 bytes)
reset smc load address to 0x1000 size 0x3000
reading ..\nand\kv.bin (0x4000 bytes)
reading .\common\cba_9188.bin (0x1ac0 bytes)
loaded cba_9188.bin, could not check signature rsa key not present!
reading .\common\cbb_9188.bin (0x7800 bytes)
reading .\common\cd_9452.bin (0x4f20 bytes)
reading .\common\ce_1888.bin (0x5606a b pad 0x56070 b)
reading ..\nand\xell-gggggg.bin (0x40000 bytes)
extracted SUPD\xboxupd.bin\CF_16747.bin (0x4560 bytes)
extracted SUPD\xboxupd.bin\CG_16747.bin (0x75aaa bytes)
reading 16747\bin\patches_trinity.bin (0x884 bytes)
reading ..\nand\smc_config.bin (0x10000 bytes)
-------------------
checking smc_config
-------------------
extracting config
valid SMC config data found at offset 0xc000
------------------
SMC config info:
------------------
Target temps: Cpu: 82_C Gpu: 78_C Edram: 76_C
Max temps : Cpu: 89_C Gpu: 82_C Edram: 82_C
Cpu Fan : (auto)
Gpu Fan : (auto)
MAC Address : 7c:ed:8d:5f:44:c2
AVRegion : 0x00000300 (PAL50)
GameRegion : 0x02fe (PAL/EU)
DVDRegion : 2
resetKey : YXAX
---------------------
Checking for smc config data patches
smc config was not patched
---------------------
could not check signature of cba_9188.bin, 1BL RSA key not present!
done!
patch slot offset reset to: 0xb0000
------ Patching BLs and modif
-------------------------------------------------------------------------------------------------------------
Nand generata
output\nandflash.bin
* Connecting
* Sending updflash.bin: Crc32 (Image) : 70835654
* Launching : "write" (ID: 3)
* Waiting FSD............................................... .................................................. ..................................Fsd not found aborting
Wait, closing Autogg
Segnalibri