A9VG电玩部落论坛

 找回密码
 注册
搜索
查看: 17031|回复: 50

[讨论] Xbox360 slim 9.6A 4G 主机破解重大突破!读CPU KEY、DVD KEY支援X-KEY!

[复制链接]

精华
0
帖子
7
威望
0 点
积分
-13 点
种子
0 点
注册时间
2012-8-10
最后登录
2012-8-14
 楼主| 发表于 2012-8-10 20:52  ·  广东 | 显示全部楼层 |阅读模式
Xbox360slim 9.6A 4G主机破解前提:
需要先获取DVD key能支援X-key的找我恰谈!
1、DVD key能支援X-key;
2、工作进展: 兼容建兴LiteOn 16DG5S XKEY;



淘宝ID:搏胜利电子科技
QQ ID:786727886
SZ手机:15012886687

精华
0
帖子
495
威望
0 点
积分
544 点
种子
22 点
注册时间
2008-5-4
最后登录
2024-6-2
发表于 2012-8-10 21:08  ·  加拿大 | 显示全部楼层
这NM是个啥,jsNB哄哄的为个啥,连句整话都说不好的,来发广告的是个啥,如果能获取dvd-key找你个毛。

精华
0
帖子
270
威望
0 点
积分
274 点
种子
0 点
注册时间
2012-3-5
最后登录
2015-2-24
发表于 2012-8-10 21:18  ·  上海 | 显示全部楼层
本帖最后由 rogerena 于 2012-8-10 21:19 编辑

什么乱七八糟的,不懂装懂

精华
0
帖子
8
威望
0 点
积分
8 点
种子
0 点
注册时间
2012-6-16
最后登录
2013-2-4
发表于 2012-8-10 21:19  ·  香港 | 显示全部楼层
support
该用户已被禁言

精华
0
帖子
238
威望
0 点
积分
358 点
种子
2 点
注册时间
2009-1-4
最后登录
2023-10-21
发表于 2012-8-10 21:25  ·  广东 | 显示全部楼层
没版主真可怕                  

精华
0
帖子
41
威望
0 点
积分
41 点
种子
0 点
注册时间
2009-8-3
最后登录
2015-4-23
发表于 2012-8-10 21:29  ·  广东 | 显示全部楼层
mr.n 发表于 2012-8-10 21:08
这NM是个啥,jsNB哄哄的为个啥,连句整话都说不好的,来发广告的是个啥,如果能获取dvd-key找你个毛。

看来中国大陆都是外行啊!老外的网站早放出来了,,一群井底之蛙!
LZ是说他可以读到CPU和DVD KEY了!现在就是在做读取DVD KEY服务宣传,是来帮你们了。
放料——
http://www.homebrew-connection.o ... one-xell-even-boot/

精华
0
帖子
41
威望
0 点
积分
41 点
种子
0 点
注册时间
2009-8-3
最后登录
2015-4-23
发表于 2012-8-10 21:30  ·  广东 | 显示全部楼层
rogerena 发表于 2012-8-10 21:18
什么乱七八糟的,不懂装懂

还在瞎叫唤!!井口看看真是太小了点吧!!!

精华
0
帖子
41
威望
0 点
积分
41 点
种子
0 点
注册时间
2009-8-3
最后登录
2015-4-23
发表于 2012-8-10 21:34  ·  广东 | 显示全部楼层
qwe741 发表于 2012-8-10 21:25
没版主真可怕

https://bbs.a9vg.com/thread-3239951-1-1.html


2012-8-10 10:23 上传下载附件 (9.8 KB)


CoronaV2 Nanddumping is done … XeLL even boot !


CoronaV2 Nand 提取完成 … XeLL 可以启动!



Orkid1818, dayton360mods.com‘s member, share with us today some proof of his works on corona V2. Basicly he was able to dump the nand of his Corona V2 (4Go xbox with phison’s eMMC chip linked to the nand) and was to launch XeLL to grab CPUkey.

Orkid1818, dayton360mods.com 的成员, 今天与我们一起分享和见证他在 corona V2 上的作品. 基本功能是提取 Corona V2 主板的 NAND 固件内容 (通过群联 eMMC 芯片连接到 NAND 的 4GB xbox 主机) 并实现了 XeLL 的启动运行而且提取到了重要的 CPUkey.

Here you can see as proof the nand dump :
从下面的截图您可以看到作为 nand 被提取的证据:


2012-8-10 10:23 上传下载附件 (254.68 KB)


Here is a pastbin of XeLL output, you can see that the nand isn’t properly recognize.
这是一个 pastbin 的 Xell 输出,你可以看到这个 nand 的识别并不完整。

We can say from that
但我们可以看出

- Magic bytes are OK
- Magic bytes 是正确的

- Nand dump is 66 Mo (like the data part for Jasper BB nand)
- Nand 固件容量为 66 MB (类似 Jasper BB nand 数据提取的效果)

- the CPUKey decrypt the KV properly and display console info as corona
- 提取的 CPUKey 正确的解密了 KV 部分并显示了 corona 主机的信息

- Bootloader are the one from corona
- Bootloader 来自于一台 corona 主机

So it’s definilty legit
Odd stuff, the nanddump don’t contain the spare data (info about the pages of the nand), probably because of the phison chip … maybe they are in it? Time will tell.
But every good news comes with a bad one, orkid1818 is Asian and we are meeting to trouble to exchange technical info about how he manages to do it but time will help =)
More news soon.
Thx to Juggahax0r, dayton360mods.com‘s admin for the news tips.
You can also check his Facebook page there.
Thx also to Swizzy for his clever help as usual.
这一部分在说现状和展望,不详细翻译了:

坏消息:提取的 NAND 还不完整,还有一些重要数据没有完全得到,怀疑和群联芯片有直接关系。
好消息:orkid1818 是亚洲人,时间会为我们带来更多的好消息,真诚祈祷并耐心等待吧!!!

消息来源:http://www.homebrew-connection.org/

精华
0
帖子
52
威望
0 点
积分
59 点
种子
0 点
注册时间
2012-2-27
最后登录
2018-8-30
发表于 2012-8-10 21:37  ·  广东 | 显示全部楼层
不懂的还真别乱喷,否则真让人笑话了。楼主说的读DVDKEY作用大得很。目前XKEY已经支持0500光驱了,只要有CPUKEY和DVDKEY及NAND即可,1175的近日就会支持,这么说该懂了吧??

精华
0
帖子
8
威望
0 点
积分
8 点
种子
0 点
注册时间
2012-6-16
最后登录
2013-2-4
发表于 2012-8-10 21:52  ·  香港 | 显示全部楼层
L0156: >> 14.07.2012, 08:26:12
L0157: Opened window "Access Method" (parent window "PG4UW v2.90c/07.2012 - univers ...").
L0158:
L0159: >> 14.07.2012, 08:26:28
L0160: Closed window "Access Method" (by pressing "OK").
L0161:  |>---------- Access Method ----------
L0162:  |  Invalid Block Management: "Treat All Blocks (was "Do not Use")"
L0163:  |* Spare Area Usage: "User Data"
L0164:  |  User Area - Start Block: "000000"
L0165:  |  User Area - Number of Blocks: "001998"
L0166:  |  User Area - Last Block: "002047"
L0167:  |  User Area - Max. Allowed Number of Invalid Blocks: "000050"
L0168:  |  [x] Check Required Valid Blocks Area
L0169:  |  Required Valid Blocks Area - Start Block: "000000"
L0170:  |  Required Valid Blocks Area - Number of Blocks: "000001"
L0171:  |  [ ] Check Max. Allowed Number of Invalid Blocks in Device
L0172:  |  Max. Allowed Number of Invalid Blocks in Device: "000050"
L0173:  |  [x] Quick Program
L0174:  |  ----------  Reserved Block Area Options  ----------
L0175:  |  RBA Table - Start Block: "002033"
L0176:  |  RBA Table - Number of Blocks: "000015"
L0177:  |  RBA Table should be located: "after Block Reservoir"
L0178:  |  ----------  Invalid Block Indication Options  ----------
L0179:  |  Invalid Block Indication Byte Value: "00"
L0180:  |  ----------  Tolerant Verification Options  ----------
L0181:  |  [x] Use Tolerant Verify feature
L0182:  |  ECC frame size (bytes): "000512"
L0183:  |  Acceptable number of errors: "000012"
L0184:  |  Show tolerated errors in log-window: "Disable"
L0185:  |<---------- Access Method ----------
L0186:
L0187: Changed items are marked with asterisk "*" on the left.
L0188:
L0189: >> 14.07.2012, 08:26:34
L0190: Reading device: Hynix H27UBG8T2A [TSOP48].
L0191: Programming adapter test ...
L0192: Searching for programming adapter DIL48/TSOP48 ZIF 18.4mm NAND (ord.no. 70-1105).
L0193:   Programming adapter found, identification:
L0194:   S/N: 1105-02693.
L0195: Programming adapter test - O.K.
L0196: Device insertion test ...
L0197: Checking device ID ...
L0198: Reading device ...
L0199: Verifying device with buffer ...
L0200: Some single-bit errors were accepted...
L0201: Reading device - done.
L0202: Elapsed time: 1:58:48.0
L0203: Statistics info: Success:2  Failure:0  Other failure:0  Total:2
L0204:
L0205: Saving file: C:\Users\luca\Desktop\newcorona4gb_2.BIN
L0206: File format: Binary
L0207: Save file successful!
L0208:
L0209: >> 14.07.2012, 10:33:28
L0210: Dialog View/Edit buffer was opened.
L0211:
L0212: >> 14.07.2012, 10:33:39
L0213: Dialog View/Edit buffer was closed.

***************************************************************************
L0101: Closed window "Access Method" (by pressing "OK").
L0102:  |>---------- Access Method ----------
L0103:  |* Invalid Block Management: "Treat All Blocks (was "Do not Use")"
L0104:  |* Spare Area Usage: "Do not Use"
L0105:  |  User Area - Start Block: "000000"
L0106:  |  User Area - Number of Blocks: "001998"
L0107:  |  User Area - Last Block: "002047"
L0108:  |  User Area - Max. Allowed Number of Invalid Blocks: "000050"
L0109:  |  [x] Check Required Valid Blocks Area
L0110:  |  Required Valid Blocks Area - Start Block: "000000"
L0111:  |  Required Valid Blocks Area - Number of Blocks: "000001"
L0112:  |  [ ] Check Max. Allowed Number of Invalid Blocks in Device
L0113:  |  Max. Allowed Number of Invalid Blocks in Device: "000050"
L0114:  |  [x] Quick Program
L0115:  |  ----------  Reserved Block Area Options  ----------
L0116:  |  RBA Table - Start Block: "002033"
L0117:  |  RBA Table - Number of Blocks: "000015"
L0118:  |  RBA Table should be located: "after Block Reservoir"
L0119:  |  ----------  Invalid Block Indication Options  ----------
L0120:  |  Invalid Block Indication Byte Value: "00"
L0121:  |  ----------  Tolerant Verification Options  ----------
L0122:  |  [x] Use Tolerant Verify feature
L0123:  |  ECC frame size (bytes): "000512"
L0124:  |  Acceptable number of errors: "000012"
L0125:  |  Show tolerated errors in log-window: "Disable"
L0126:  |<---------- Access Method ----------
L0127:
L0128: Changed items are marked with asterisk "*" on the left.
L0129:
L0130: >> 14.07.2012, 06:48:50
L0131: Reading device: Hynix H27UBG8T2A [TSOP48].
L0132: Programming adapter test ...
L0133: Searching for programming adapter DIL48/TSOP48 ZIF 18.4mm NAND (ord.no. 70-1105).
L0134:   Programming adapter found, identification:
L0135:   S/N: 1105-02693.
L0136: Programming adapter test - O.K.
L0137: Device insertion test ...
L0138: Checking device ID ...
L0139: Reading device ...
L0140: Verifying device with buffer ...
L0141: Some single-bit errors were accepted...
L0142: Reading device - done.
L0143: Elapsed time: 1:50:59.8
L0144: Statistics info: Success:1  Failure:0  Other failure:0  Total:1
L0145:
L0146: >> 14.07.2012, 08:23:40
L0147: Dialog View/Edit buffer was opened.
L0148:
L0149: >> 14.07.2012, 08:24:00
L0150: Dialog View/Edit buffer was closed.
L0151:
L0152: Saving file: C:\Users\luca\Desktop\newcorona4gb.BIN
L0153: File format: Binary
L0154: Save file successful!
您需要登录后才可以回帖 登录 | 注册

本版积分规则

Archiver|手机版|A9VG电玩部落 川公网安备 51019002005286号

GMT+8, 2024-11-20 04:53 , Processed in 0.194268 second(s), 16 queries , Redis On.

Powered by Discuz! X3.4

Copyright © 2001-2020, Tencent Cloud.

返回顶部