You can create custom NAND images that can be used through Shadowbooting. GoobyCorp has created a script as part of their Xbox-360-Crypto suite, shadowboot.py, which is designed for extracting, analyzing, and building Xbox 360 shadowboot images.
Setup
As a prerequisite, Python 3 must be installed on your PC.
- Run
pip install cryptographyto install the cryptography library in python. - Download Xbox-360-Crypto and extract the contents to your PC.
- On line 23 of shadowboot.py, add
from nand_tool import *and save the file. - Add keys to
Xbox-360-Crypto-master\Keys\:- 1BL_pub.bin (key size is 272 bytes, if your key is 16 bytes it is the wrong key)
- Master_pub.bin (rename if the key you have is called MAST_pub.bin)
- SB_prv.bin (rename if the key you have is called SB_priv.bin)
- Download and extract the contents of StreamIO into
Xbox-360-Crypto-master\StreamIO.
Usage
Build Mode (build)
Creates a new shadowboot image at the specified OUTPUT_PATH. Requires a manifest file or build directory.
python3 shadowboot.py build OUTPUT_PATH [options]
| Option | Purpose |
|---|---|
| --nochecks | Skip integrity checks when parsing the shadowboot. |
| -m, --manifest MANIFEST_PATH | Use a build manifest JSON file. |
| -b, --build-dir BUILD_DIR_PATH | Use a directory containing required files. |
Example:
python3 shadowboot.py build ./output/jasper-bb-zerofuse.bin --manifest ./Build/jasper-bb-zerofuse.json
Manifest file:
./build/manifest_template.json is a template you can copy and modify. Options are explained below. Note that if a base image is provided, it will use it as a fallback so if a component is missing (e.g. "SC") it will use the component from the base image.
{
"build": {
"version": 17559 // (Required) Kernel version to use
},
"options": {
"use_smc": true, // (Optional) Whether to include SMC
"use_kv": true, // (Optional) Whether to include KeyVault
"test_kit": false, // (Optional) Build for testkit (true) or retail/devkit (false)
"base_image_checks_disabled": false // (Optional) Disable integrity checks on base image
},
"files": {
"base_directory": "Build", // (Required) Base directory containing the following input files
"base_image": "xboxrom.bin", // (Optional) Base firmware image (fallback)
"SMC": "SMC_dec.bin", // (Optional) Decrypted SMC file
"KV": "KV_dec.bin", // (Optional) KeyVault file
"SB": "sb.bin", // (Required) SB bootloader
"SC": "sc.bin", // (Required) SC bootloader
"SD": "sd.bin", // (Required) SD bootloader
"SE": "se.bin", // (Optional) SE bootloader (used if HV/kernel not provided)
"kernel": "kernel.bin", // (Optional) Kernel binary (required if SE not provided)
"HV": "hypervisor.bin", // (Optional) Hypervisor binary (required if SE not provided)
"HVK_patches": "hvk.bin" // (Optional) Patches for HV/kernel
}
}
Extract Mode (extract)
Extracts various components from a shadowboot or flash image.
python3 shadowboot.py extract INPUT_PATH OUTPUT_DIR [options]
| Option | Purpose |
|---|---|
| --flash | Parse a full flash image instead of just a shadowboot. |
| --nochecks | Skip integrity checks. |
| --all | Extract everything. |
| --smc | Extract SMC. |
| --keyvault, --kv | Extract KeyVault. |
| --sb | Extract SB bootloader. |
| --sc | Extract SC bootloader. |
| --sd | Extract SD bootloader. |
| --se | Extract SE bootloader. |
| --kernel | Extract Kernel. |
| --hypervisor, --hv | Extract Hypervisor. |
| --loader | Extract HV/kernel patch loader. |
| --patches | Extract HV/kernel patches. |
Example:
python3 shadowboot.py extract ./input/falcon-xdkbuild-nand.bin ./output/falcon-xdkbuild-nand --all
Info Mode (info)
Displays metadata about a shadowboot or flash image, including:
- Console type
- SMC version
- Bootloader versions (SB, SC, SD, SE)
- Hypervisor and Kernel versions
- Whether the image is retail, testkit, or devkit.
python3 shadowboot.py info INPUT_PATH [options]
| Option | Purpose |
|---|---|
| --flash | Parse a full flash image instead of just a shadowboot. |
| --nochecks | Skip integrity checks. |
Example:
python3 shadowboot.py info ./input/zephyr-nand.bin
Split Mode (split)
Extracts a specific firmware version from a multi-image file.
python3 shadowboot.py split INPUT_PATH OUTPUT_DIR [options]
| Option | Purpose |
|---|---|
| -k, --kernel KERNEL_VERSION | Specify the kernel version to extract. |
| -r, --revision {xenon, zephyr, falcon, jasper, trinity, corona, winchester} | Specify the console revision. |
| -t, --type {retail, testkit, devkit} | Specify the console type. |
| --nochecks | Skip integrity checks. |
Test Mode (test)
Placeholder mode, currently unused.
python3 shadowboot.py test INPUT_PATH OUTPUT_PATH [options]
| Option | Purpose |
|---|---|
| --nochecks | Skip integrity checks. |