XboxHacker BBS
November 20, 2009, 05:28:36 PM *
Welcome, Guest. Please login or register.
Did you miss your activation email?

Login with username, password and session length
News: SMF - Just Installed
 
   Home   Help Search Login Register  
Pages: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 »
  Print  
Author Topic: Cracked Samsung SDG-605B/616T/616F Firmware for Xbox 1 - V2  (Read 111560 times)
commodore4eva
Member
**
Posts: 33


View Profile
« on: April 22, 2006, 01:59:33 AM »

------------------------------------------------------
Cracked Samsung SDG-605B/616T/616F Firmware for Xbox 1
------------------------------------------------------

22 April 2006

Whats New
-----------------
Totaly re-done to read security sector from image, will now work with all games and xbox live.
Security sector moved to image
Security sector now read from  PSN $fd021e (originals) AND  PSN $f9fa00 (backups. This is the next sector after end of xbox game data.)
Patched read sector routine to work with originals and backups
Patched debug cdb command (FF 66 05 or FF 06 05) for bank 0 rom checksum check to return original bank 0 rom checksum. Possible xbox live checker
Extra debug cdb command found to unlock drive without any challenge response (FF 08 01)

Tested with unmodified xbox with copy of Halo 2 made using hot swap technique, clonecd, original dvd size was psn 30000-FCxxxxx. Added security secotr to image with hex editor at psn f9fa00

Also included security sectors from games

[edit SiliconIce: please, do not post links to this material - BIOS and Firmware images contain copyrighted code]



Dont forget to include per game security sector into image. If need be, will post firmware to easily return security sector data


This will be similar to our soon to be released xbox 360 firmware.

Steps to flash drive:
---------------------


1. Plug Samsung DVD drive into PC IDE port with power still from XBOX.

2. Use included MTK Win flash program and firmware file "SDG605b.bin" and flash the drive (I used ATAPI mode).

3. Plug back into XBOX and enjoy:)


Commodore4Eva

Commodore4Eva@hotmail.com
« Last Edit: April 22, 2006, 12:36:54 PM by SiliconIce » Logged
BlueCop
Master Hacker
****
Posts: 301


"When the going gets weird, the weird turn pro."


View Profile
« Reply #1 on: April 22, 2006, 02:05:59 AM »

Excellent work. i looked forward to analyzing your patches and trying out the firmware.
Logged
Arakon
Administrator
Xbox Hacker
*****
Posts: 5184


View Profile
« Reply #2 on: April 22, 2006, 02:23:36 AM »

let's see if this one actually does something.. for everyone wanting to test: you will need a DL blank, the security sector location is on the second layer.
Logged

I do NOT give support by email, PM, ICQ or whatever. Anyone annoying me that way will have his balls removed. With a rusty butterknife. Slowly. And I'll enjoy doing it.
Dzgx216
Master Hacker
****
Posts: 168


View Profile
« Reply #3 on: April 22, 2006, 02:34:42 AM »

Great show, Downloading the FW image tonight to Diff with the original!
Logged

- Danzig -
pash
Hacker
***
Posts: 75

Dont bite the Hand that feeds.


View Profile
« Reply #4 on: April 22, 2006, 03:25:39 AM »

I hope this one is better then your first try @: http://www.xboxhacker.net/forums/index.php?topic=562.msg5339#msg5339  Roll Eyes

Quote to first try from Speci:

Quote
Just like I expected, it's fake and a bad one too  Try to make it more real next time by including the CPR_MAI 
 
« Last Edit: March 28, 2006, 03:10:54 PM by TheSpecialist » 
 

PS: MTK Win flash IS NOT INCLUDED!
Logged

Hey Major N., where is IK+ for 360?
uberfry
Xbox Hacker
*****
Posts: 862



View Profile
« Reply #5 on: April 22, 2006, 03:31:17 AM »

anyone tried it yet???

edit:

Quote
This will be similar to our soon to be released xbox 360 firmware.

btw, weren't you the one who was saying that you decapped the x360 chips and found the security holes? (thread had been deleted within the same day it had been created i think)
« Last Edit: April 22, 2006, 03:37:54 AM by uberfry » Logged
twizter
Hacker
***
Posts: 59


View Profile
« Reply #6 on: April 22, 2006, 05:11:34 AM »

question 1: is there a possibility of placing the SS location on Single Layer discs?
question 2: is a PPF patch a possible method for adding the SS to game images?
Logged
commodore4eva
Member
**
Posts: 33


View Profile
« Reply #7 on: April 22, 2006, 06:08:30 AM »

Make sure you use dvd+r DL bit set to dvd-rom.
Security sector was put on second layer in preperation for xbox 360 disks.
Logged
Arakon
Administrator
Xbox Hacker
*****
Posts: 5184


View Profile
« Reply #8 on: April 22, 2006, 06:14:16 AM »

if you could post a firmware with the SS being on the first layer, I'd appreciate it. I'm not gonna waste an expensive DL disk just for testing, but I'm willing to try it if I can just use a normal dvd-r and could confirm wether this is valid or not.
Logged

I do NOT give support by email, PM, ICQ or whatever. Anyone annoying me that way will have his balls removed. With a rusty butterknife. Slowly. And I'll enjoy doing it.
burgemaster
Master Hacker
****
Posts: 100


View Profile
« Reply #9 on: April 22, 2006, 06:42:19 AM »

Good work

Glad people are trying hard still
Logged
pizzaman
Member
**
Posts: 13


View Profile
« Reply #10 on: April 22, 2006, 06:48:03 AM »

anyone got a diff link for it as cannot get from there
Logged
twizter
Hacker
***
Posts: 59


View Profile
« Reply #11 on: April 22, 2006, 06:50:21 AM »

i mirrored the rar file at this url.

[edit SiliconIce: please do not post links to copyrighted materials. Firmware images contain copyrighted code]
« Last Edit: April 22, 2006, 12:38:00 PM by SiliconIce » Logged
xDREAM
Master Hacker
****
Posts: 124


View Profile
« Reply #12 on: April 22, 2006, 06:56:42 AM »

if you could post a firmware with the SS being on the first layer, I'd appreciate it. I'm not gonna waste an expensive DL disk just for testing, but I'm willing to try it if I can just use a normal dvd-r and could confirm wether this is valid or not.


The SS adress is @ FDB5h in sdg605b.bin, you can change it yourself dunno if this will corrupt the crack or not.
Logged
twizter
Hacker
***
Posts: 59


View Profile
« Reply #13 on: April 22, 2006, 07:00:50 AM »

xDREAM: could you describe the method you took to open the .bin and find out the address, if its too long, could you point me in the right direction?
Logged
xDREAM
Master Hacker
****
Posts: 124


View Profile
« Reply #14 on: April 22, 2006, 07:03:30 AM »

xDREAM: could you describe the method you took to open the .bin and find out the address, if its too long, could you point me in the right direction?

Just search for bytes F9FA00 and there is only one location in the file that has those bytes. Altho im not 100% sure this is the right address to patch since i didnt look at the disasm
Logged
Arakon
Administrator
Xbox Hacker
*****
Posts: 5184


View Profile
« Reply #15 on: April 22, 2006, 07:06:18 AM »

problem is that this would likely break the checksum, and if it's the wrong adress, it could very well kill the drive for good.
Logged

I do NOT give support by email, PM, ICQ or whatever. Anyone annoying me that way will have his balls removed. With a rusty butterknife. Slowly. And I'll enjoy doing it.
xDREAM
Master Hacker
****
Posts: 124


View Profile
« Reply #16 on: April 22, 2006, 07:09:12 AM »

problem is that this would likely break the checksum, and if it's the wrong adress, it could very well kill the drive for good.

Yup your right.. does the samsung have a checksum? Which is prolly disabled in this firmware anyways
Logged
uberfry
Xbox Hacker
*****
Posts: 862



View Profile
« Reply #17 on: April 22, 2006, 07:23:13 AM »

Quote
Extra debug cdb command found to unlock drive without any challenge response (FF 08 01)
could you please release the fw with that?
Logged
TheSpecialist
Global Moderator
Xbox Hacker
*****
Posts: 782


View Profile
« Reply #18 on: April 22, 2006, 09:08:52 AM »

Took a quick look at it and I really don't see how this crack could ever work. What I do see is that the zip contains MS copyrighted stuff ...
Logged
uberfry
Xbox Hacker
*****
Posts: 862



View Profile
« Reply #19 on: April 22, 2006, 09:21:01 AM »

TS: nothing at all in it? or just the fact that it will never read sector fd021e?
im currently modding my 616, going to try this right after
Logged
Pages: 1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 »
  Print  
 
Jump to:  

Powered by MySQL Powered by PHP Powered by SMF 1.1.4 | SMF © 2006-2007, Simple Machines LLC Valid XHTML 1.0! Valid CSS!