Xbox 360 Hacks

From ivc wiki
Revision as of 16:24, 14 June 2006 by Ivc (talk | contribs)
Jump to navigationJump to search

It's now possible to hack the Xbox 360 to make it read regular DVD writable discs.

Requirements

  • Screwdrivers
  • Plastic stick
  • S-ATA cable
  • Compatible S-ATA controller card or on-board chipset - Silicon Image Sil3112 does not work
  • DOS boot disk or hard drive
  • Windows XP
  • Mktflash, KDX and hacked firmwares
  • Xbox 360 console near a computer
  • ..or Xecuter power adapter


Drives and firmwares

There are currently two different DVD drives for the Xbox 360. Toshiba-Samsung and Hitachi-LG, both require their own hacked firmware.

The first proof of a hacked firmware was actually for the Hitachi-LG and creditted for the_specialist at xboxhacker.net. But the first publicly available hacked firmware was for the Toshiba-Samsung, the Hitachi-LG firmware was released under a month afterwards. These firmwares was hacked and released by commodore4eva.

You can find the DVD drive model you have by looking at the tray, if there are many holes and cracks it's a Hitachi-LG, else it's a Toshiba-Samsung.


Disassemble

It's quite hard to disassemble the 360, as Microsoft officialy said, there are no screws and it was supposedly no way to open it. But you first have to remove the faceplate, untuck a few tabs, use a plastic stick to untuck the tabs on the back and lift the top case off the console. No need to remove the black screws on the bottom of the machine if you only want to remove the DVD drive.


Firmware Upgrade

Toshiba-Samsung DVD Drive

For the TS drive there are two different firmwares available. One is used to play backup copies of Xbox 360 games and the other is to gain access to the drive in Windows to dump the security-sector and game data.

xtreme.bin - the normal hacked firmware
xtreme0800.bin - to gain access to the drive in Windows

There is also a proper release of the xtreme.bin key above called xtreme_proper.bin. The only change is the default key, 00's instead of FF's. The change was needed for KeydriveX (KDX) to function properly.

xtreme_proper.bin - key is 00's instead of FF's for KDX

Dump firmware

In order to flash the hacked firmware, you first have to dump the current firmware. Every single DVD drive has a unique key that is chained together with the rest of the console. You cannot exchange the drive from another console, it will only give you error messages if you try.

To dump the firmware, you have to boot into DOS and use a utility called mtkflash.exe to read the flash chip to a file. You can use a floppy, pendrive or harddrive to do this. That's no covered here.

  1. Make sure the SATA settings in the BIOS is set to NATIVE/ID and not SATA-Raid
  2. The Xbox 360 DVD power cable should still be connected to the Xbox 360 motherboard, or via Xecuter adapter
  3. Plug the SATA into the back of the DVD drive and connect it to the computer SATA connector
  4. Boot computer into DOS using a floppy, hard drive or pendrive
  5. Start Xbox 360 with DVD power cable still connected and video cable plugged in, not neccessary to the tv
  6. Wait 20 seconds for the Xbox 360 to initilize
  7. Execute this command: mtkflash.exe r /SATA /m orig.bin
  8. Wait a few moments while it's dumping the firmware

If your SATA controller/chipset is not recognized, read about hexediting |here.

Patch firmware

Once you have dumped the firmware, turn off the Xbox 360, boot into Windows XP and start KDX (KeydriveX) by foros. This application will load your dumped firmware and read the key. Copy this key, open the hacked firmware, and paste the key into the DVD Key field to replace the 00's or FF'. Save the firmware as patchorg.bin (8+3 characters for DOS).

Write firmware

When you've patched your DVD drive key onto the hacked firmware, boot into DOS again and use mtkflash.exe to write the new firmware to the DVD drive firmware chip.

Follow the same procedure as when you dumped the firmware, mentioned above.

  • Execute mtkflash.exe w /SATA /m patchorg.bin


Hitachi-LG drive

Requirements:

  • Slax Linux Live Boot CD

The Hitachi-LG drive is a lot easier to upgrade and it's not required to dump the the key or the entire firmware, but it's still recommended. The hacked firmware do incremential updates of the memory banks that is needed to be upgraded.

The drive does not require a seperate firmware to dump game data. All Xbox 360 DVD drives by default will not be detected by Windows. This is because the ATAPI command talk is non-standard and specific for the Xbox 360 system. That's one reason why the Toshiba-Samsung drive requires a seperate firmware.

The Hitachi-LG firmware on the other hand has a debug routine that can be trigged either by software or hardware. The easiest way is of course by software and the Slax Live CD happen to hit or trigger the debug routing while it's booting. We can take advantace of that by doing a soft-reboot with the reset button and boot back into Windows while the DVD drive is still in debug mode and accessible from Windows.

Dump firmware (optional)

Requirements:

  • Memdump_win - dump key

It's recommended that you dump the entrie firmware incase you should need to go back to the original firmware later on. There is nothing that needs to be done to this dump, it's for backup purposes only.

  1. Download and burn out the Slax Live CD
  2. Move the Xbox 360 near the computer, plug in the video cable to allow it to boot normally
  3. The DVD drive power cable should still connected to the Xbox 360 motherboard, or via Xecuter adapter
  4. Plug the SATA cable into the Xbox 360 drive and the computer
  5. Make sure the computer bios is set to boot from CD or DVD
  6. Start the Xbox 360 and wait 20 seconds for it to initialize
  7. Boot the Live CD and wait for the login prompt
  8. Press the RESET-button on the computer and remove the CD
  9. Boot into Windows and check that the drive is detected as aregular DVD drive
  10. Start a new command prompted by selecting Start and Run, type cmd.
  11. Execute this command: memdump_win e 12200 8 8000 firmware.bin (where e is the drive letter of the drive)

Dump key (optional)

Requirements:

  • Memdump_win - dump key

It's recommended that you extract the DVD drive key incase anything should happen while you flash the drive with the hacked firmware or troubleshoot. The key is used to encrypt and decrypt the commands between the drive and the Xbox 360 system, without it the drive is useless.

It's also possible to extract the key from the firmware dump mentioned above using KeydriveX (KDX).

  1. Follow the procedure above up to the last step
  2. Execute this command: memdump_win e 91004F0 1 10 key.bin (where e is the drive letter of the drive)

Write firmware

Backup games

First of all, you have to realise that you need DVD+-R Dual Layer media and a burner that is able to set the so called booktype to DVD-ROM. This is also known as bitsetting. Most NEC and BenQ drives allows you to set the bitsetting for dual layer burns.

There are two ways to create a backup:

  • Use a generic PC DVD drive
  • Use the Xbox 360 DVD drive


Generic PC DVD drive method

Pros: easier, no need to have the Xbox 360 near the computer Cons: security-sector not extracted, need to find 8 GB movie dvd

Requirements:

  • DVD drive - one you can disassemble
  • DVD disc around 8 GB - larger than Xbox 360 games
    • Know to work: Hitch, Shrek, Saving Private Ryan, Underworld Evolution. You can also burn a data or movie dvd over 8 GB.
  • wxRipper - dump game data
  • Enough hard drive space - to save 15 GB of data

You have to open/disassemble the DVD drive because you are going to swap the movie dvd with a Xbox 360 game disc without ejecting the disc. Also, you can not get the required security-sector file using this method. A matching SS file could be found online though, more below.

The reason for this is that the TOC, or table of content size, of the movie dvd will exceed size of any Xbox 360 game and we can therefore do a normal straightforward dump of the disc because this bypasses the disc security added by Microsoft. Ejecting the disc would reset the TOC and after an eject the normal accessible TOC (Video DVD part) of any Xbox 360 game is only a few megabytes.

Preparing

You need to have external access to the DVD drive. Make enough room around the computer and make sure nothing can damage the computer or the DVD drive while you're dumping the game. The drive can be USB connected as long as it works with Windows.

Remove the top case shield of the DVD drive by removing the screws that hold it together. When you have the top loose, take a look at it and notice the round plastic piece with a metalic ring in it that normally is holding the DVD disc down when it's spinning. You need to somehow, without damaging it, remove it from the top shield. You need this piece before you can proceed. Another way is to just put the top shield back on when nessecary if that's possible.

Swapping disc

With the piece in hand, connect the DVD drive externally to the computer and boot Windows.

Warning: Do not look at the laser when the the computer is powered on.

Start wxRipper, now eject the drive as normal, place the movie dvd in the tray, press the eject button and immediately when the tray has stopped retracting, put the plastic metalic ring on top of the disc where the spin-motor is popping up from beneath. The disc is now secure and ready to be spun up by the syste.

When the disc has spun up and is recognized, press the "Stop"-button or select "Stop" from the Hotswap-menu. For USB drives, you have to wait 2 minutes for it to shut down normally as the stop command does not work over USB.

Dumping game data

When the movie dvd has spun down, without touching the eject button, remove the disc and swap it with the Xbox 360 Game DVD you want to dump. Press the "Play"-button or select "Play" from the menu. Wait a few moments for it to be recognized. Then press the "Find"-button or select "Find magic number" from the menu. A list of seven "Copy", "Dummy" and "Jump" actions will appear.

The disc is now ready to be dumped. Press green-button or select the "Start dump" option fron the menu. Save the iso-file as gamename_videomode.iso, i.e halo2_pal.iso.

If you get CRC errors or bad sectors, you can try to save the layout file using the File menu, open the layout file in notepad, change the 1st and 3rd line that start with "C" (c is copy) and change the letter to "D" (d is dummy), save the file and open it again in wxRipper. This should take care of the reading errors.

Security-sector file

This iso-file is now ready but you still need the security-sector file that is needed in the combining step below. Without the ss-file the iso-file is worthless. You can either extract this using the Xbox 360 DVD drive method below or try to find the online.

You can find the number (md5sum) of the ss-file you need by opening the iso-file in Xbox360 SS Merger and select "Yes" when you're asked to calculate the md5sum. When it's finished, hopefully someone else have already submitted the game that you ripped to the online database and you're shown the md5sum of the ss-file that they successfully used. Use the recommended md5sum number to find the ss-file online.


Xbox 360 DVD drive method

Pros: able to extract security-sector Cons: toshiba-samsung drive requires reflash between playing back and dump data

Requirements:

  • TS drive only: flash drive with xtreme0800.bin firmware - to make it show in Windows
  • DVDProInfo - send commands to drive and create security-sector file
  • ISOBuster - dump game data

You going to send custom commands to the drive using DVDProInfo. The first 4 consquative commands are used to extract the security-sector and then the last command is to tell the drive to get ready to dump the game data. ISOBuster is used to dump the content of the disc.

The extracted security-sectors file will be combined with the game data and burned to the second layer of the dual layer disc. Without the correct security-sector the disc is rejected by the Xbox 360.

Toshiba-Samsung DVD drive only

The drive needs to be flashed with the game-dump-ready firmware (xtrem0800.bin) so that it appears as a normal DVD drive in Windows.

Save security-sector

To start of, open DVDProInfo and select the Xbox 360 DVD drive on the lower-left dropdown-menu. In the lower-right dropdown-menu select "Send Custom Command" under the "MMC Commands" header. Read the warning message that appears and click "I Agree". A window will slide out on the right side and show you 12 fields starting with the name CDB. In those fields fill inn two character in each field from the list below. One line at a time. Press "Send" between each line.

AD 00 FF 02 FD FF FE 00 08 00 01 C0
AD 00 FF 02 FD FF FE 00 08 00 03 C0
AD 00 FF 02 FD FF FE 00 08 00 05 C0
AD 00 FF 02 FD FF FE 00 08 00 07 C0

You will notice that only the second to last field is different (CBD 10).

When you have executed all four lines, switch to the main window with the DVDInfoPro logo and buttons with CD icons on the top. Press the right-most button marked with a document and a pencil, it's named "Saves Hexadecimal display as a binary file". Save the file as gamename_videomode_ss.bin, i.e halo2_pal_ss.bin.

Dump game data

When you've saved the security-sector, switch over to the small slide-out window again and enter this command to allow dumping of the game data.

FF 08 01 01 00 00 00 00 00 00

Now open IsoBuster and select the Xbox 360 DVD drive on the top-left dropdown-menu. Right-click on the top drive-icon named something like DVD-R DL and select "Extract From-To". In the window that opens enter 0 in the "Start Adress"-field and 3567872 in the "Length"-field. Select the first "User Data - 2048 bytes/block" option in the "Extraction Type"-setting below. Click "Start Extraction" and save the game data as gamename_videomode.iso, i.e halo2_pal.iso.

If you receive any errors during the extraction select "Fill with blank zeros" and check the "Use this for all errors".


Combining ss and game data

Before you can burn the iso-file, you need to combine the security-sectors file and the game data iso. You need Xbox360 SS Merger for this.

Start the program and under the "ISO File"-header, press the browse button on the right. Select the game data iso file you created with IsoBuster. The program should automatically detect which method you used to create the iso-file and fill in the correct security-sector offset further down. Next, under the "SS File"-header, click browse and select the correct security-sector file for the game iso you selected above.

When everything is set, click the big "Merge and create layer break file"-button and Xbox360 SS Merger will patch the iso-file you selected and create a small new text file that has an .dvd extenstion that is used to guide the dvd writer program you're going to use to make the appropriate break between the layers.


Burning game backup

Requirements:

  • DVD burner with DL bittsetting
  • DVD+-R Dual Layer media (8.5 GB)
  • CloneCD (recommended) - dvd writing
  • ..or DVD Decryptor - dvd writing
  • Nero CD-DVD Speed - to change bitsetting

If you've finally combined the security-sector file and game data iso-file, you need a rather new DVD burner and good DVD Dual Layer media before you can burn the game backup.

The reason you need a rather new DVD burner is that the way the firmware works is by masqurading the mediaflag to the Xbox 360 system. The burner has to support DVD-ROM bitsetting/mediaflag. Normally Xbox 360 games has a mediaflag of Xbox360Game and normal DVD+-R discs has a mediaflag of DVD-R or DVD+R (after bitsetting it's DVD-ROM instead). When the Xbox 360 system asks what kind of a disc is in the tray, the hacked firmware will tell the system that normal DVD+-R discs are indeed Xbox360Game discs but in reality is just dvd+-r backup discs of Xbox 360 games with the bitsetting set to DVD-ROM.

To check if your DVD burner has bitsetting support, open the latest CD-DVD Speed and the "Extra"-menu and then "Bitsetting". The first two options (DVD+R, DVD+RW) might be greyed out and disabled, but the third and important (DVD+R DL) setting should be enabled. It should be set to DVD-ROM book type, set the others to DVD-ROM if possible. Click "Refresh" to verify.

To burn the final iso-file use either CloneCD or DVD Decryptor. Many people have had success by setting the burning speed to 2.4x. When finished make sure the Xbox 360 DVD drive is flashed with the normal hacked firmware and reassemble the console to check if the new backup disc is working.

Happy gaming. :)


References