- English
- português
O PicoFlasher, também conhecido como Raspberry Pi Pico, é um dispositivo que pode ser usado para ler/escrever NANDs de Xbox 360 e também como um chip de glitch em placas Trinity. Ele funciona em conjunto com o programa para Windows J-Runner with Extras e J-Runner-Pro e pode ser usado para instalações JTAG e RGH. Ele é um dos programadores de NAND mais rápidos e é consideravelmente mais barato que a maioria.
O Raspberry Pi Pico não é feito especificamente para ler e escrever NANDs, no entanto, por cortesia de Balika011, agora pode ser usado como um programador de NAND.
O Raspberry Pi Pico não pode ser usado para programar chips de glitch.
Utilização
Para usar o Pi Pico como um PicoFlasher, você precisa primeiramente programá-lo com um arquivo da versão mais recente do software PicoFlasher daqui
Solder each wire (or connect a pin header wire) to each of the labeled pads on the Raspberry Pi pictured in one of the diagrams below, and then solder the other ends of the wires to each of the corresponding pads on the motherboard.
Once you’ve finished soldering, clean up any flux with isopropyl alcohol and cotton swabs.
Hax360 Firmware
SPI Pinout for NAND/eMMC
| Pico / Pico 2 | RP2040 Zero | Xbox |
|---|---|---|
| GP16 | GP0 | SPI_MISO |
| GP17 | GP1 | SPI_SS_N |
| GP18 | GP2 | SPI_CLK |
| GP19 | GP3 | SPI_MOSI |
| GP20 | GP4 | SMC_DBG_EN |
| GP21 | GP5 | SMC_RST_XDK_N |
| GND | GND | GND |
Debug UART Pinout (hax360 firmware only)
PicoFlasher by hax360 also has built-in UART reading functionality. This is for advanced users; if you just want to do NAND reading/writing, you can just ignore this section.
Kernel
| Pico / Pico 2 | RP2040 Zero | Xbox |
|---|---|---|
| GP0 (UART0_TX) | GP12 (UART0_TX) | KER_DBG_RXD |
| GP1 (UART0_RX) | GP13 (UART0_RX) | KER_DBG_TXD |
SMC
| Pico / Pico 2 | RP2040 Zero | Xbox |
|---|---|---|
| GP4 (UART1_TX) | GP8 (UART1_TX) | SMC_DBG_RXD |
| GP5 (UART1_RX) | GP9 (UART1_RX) | SMC_DBG_TXD |
Diagrams
Note that 15432's firmware uses the GP0 though GP5 pins instead of the ones on these diagrams.
Corona/Waitsburg/Stingray SPI (J2C1 & J2C3)
These can either be used for 4 GB or 16 MB NAND types if you're using PicoFlasher V4 or newer.
15432's Firmware
| Due to 15432's firmware being not as up to date as hax360's fork, 15432's firmware is now considered not recommended. The information has only been kept here for preservation. |
Pinout
| Pico GPIO | Xbox 360 Pinout |
| GP0 | SPI_MISO |
| GP1 | SPI_SS_N |
| GP2 | SPI_CLK |
| GP3 | SPI_MOSI |
| GP4 | SMC_DBG_EN |
| GP5 | SMC_RST_XDK_N |
| GND | GND |
Diagram
When using the PicoFlasher fork by 15432, you use the console's SMC programming header regardless of if the console has 4 GB or 16 MB flash memory.
Reading the NAND
- Plug your Xbox 360 power supply in, but do not turn the console on. You can leave the RF board disconnected to prevent turning it on by accident.
- Plug the white end of the cable into the bottom port of the programmer. Plug the USB cable into the programmer and your PC.
- Launch J-Runner. Select "Read NAND" in the top left. It may prompt you for your Xbox 360’s model, make the correct selection and click OK. If everything is wired properly, it will read your NAND twice and automatically compare the dumps. If it says "Device Not Found" or anything about missing CB/CD files, see the troubleshooting steps at the bottom of this page. If you get messages about bad blocks, ignore them. When it has finished, it will tell you if the two dumps are an exact match. If they are, you can close J-Runner and proceed. If they aren’t, take more dumps until you get matching ones.
- With 4 GB NANDs, a pane will open in the lower right, listing some removable drives. If everything is wired properly, one will show up as Removable Media.
- Copy both of the dumps to a safe place such as cloud storage or send it to yourself in an email to keep them safe. They are located in the
outputfolder in the J-Runner directory.
(Phat Only) Checking your CB if it's JTAGable
This section is only if you have a phat Xbox 360 that has a dashboard/kernel version of 2.0.7371.0 or lower.
Open J-Runner and select "…" next to the Load Source field and choose the nanddump1.bin or nanddump2.bin file. On the right-hand side, note the value next to the 2BL [CB] label. If your CB is on the list below, your console is JTAGable. Any newer CB, which is not on the list, will be patched.
| Model | Exploitable CB Versions |
|---|---|
| Xenon | 1888, 1897, 1902, 1903, 1920, 1921 |
| Elpis | 8192 |
| Zephyr | 4540, 4558, 4570, 4580 |
| Falcon/Opus | 5760, 5761, 5766, 5770 |
| Jasper | 6712 & 6723 |
| Tonasket | none |
Writing XeLL to the NAND

- In J-Runner, select "…" next to the Load Source field and choose your
nanddump1.binornanddump2.bin. - Select the appropriate radio button in the top right of the window:
JTAG- For JTAG, R-JTAG, or R-JTOP.Glitch- For RGH1.Glitch2- For RGH1.2, RGH2, RGH3, EXT_CLK, Muffin/Mufas, or S-RGH.Glitch2m- Same as Glitch2 but only used if your eFuses are in a non-bootable state. Rather than using the real eFuses from the console's CPU, it uses virtual eFuses stored on the NAND instead.
- Put a check in the appropriate checkbox (if applicable) in the top right of the window:
- If you are using JTAG, select
JTAGand leave the R-JTAG checkbox disabled.- If you are using R-JTAG or R-JTOP, the
R-JTAGcheckbox would be enabled. - If you are not on a Xenon console, enable
Aud_Clampfor either of these three modifications.
- If you are using R-JTAG or R-JTOP, the
- If you are using RGH1.2 or S-RGH, enable
SMC+ - If you are on a non-Xenon console with EXT_CLK, enable
SMC+ - If you are using Project Mufas, enable
SMC+ - If you are using RGH2 with an X360ACE, enable
SMC+ - If you are using RGH2 or RGH2+ with a CR3/CR4, enable
CR4 - If you are using RGH3, select
RGH3 - If you have an Xbox 360 E Stingray motherboard, enable
WB 2K- Some Stingray motherboards use Winbond W641GG2KB-14 RAM, which is incompatible with older Corona bootloaders. This setting just installs a newer bootloader that's compatible with this new RAM type, which was already installed on Corona/Waitsburg through system updates. This means that it can also still be enabled on Xbox 360 S Corona/Waitsburg motherboards, though it won't gain any benefits. You can leave this setting disabled if you know your board has Samsung RAM, but if you forgot or are unsure, then just enable the option to be safe.
- If you have an Elpis motherboard, enable
Elpis- Many Elpis motherboards have Samsung RAM, which is incompatible with the Falcon bootloader that's used by default with Xenon Glitch2 images. This setting just installs an Elpis bootloader that's compatible with this new RAM and GPU configuration, which was already installed on refurbished/remanufactured Elpis motherboards from the factory. This means it can still be used on Elpises with Infineon/Qimonda RAM, though it won't gain any benefits. You can leave this setting disabled if you know your board has Infineon/Qimonda RAM, but if you forgot or are unsure, then just enable the option to be safe.
- If you are using JTAG, select
- Select the
Create XeLLbutton and wait for it to finish. - Select the
Write XeLLbutton, select your system, and press OK. It will write the XeLL to the first 50 blocks of the motherboard's NAND.- If it says "Device Not Found" or Flash Config 0x00000000, see the troubleshooting steps at the bottom of this page.
- Once it has successfully written to the motherboard, unplug the power cable from your Xbox 360 and unplug the USB cable from the computer and programmer.
- Go back to the page you were originally on for wiring instructions.
Troubleshooting
- "Device Not Found"
- Re-insert the USB cable
- Check that the drivers are properly installed
- "Flash Config 0x00000000"
- Check that your power brick is plugged in, with an amber colored LED, and that it is plugged into your console completely (console turned off).
- Check your soldering to your motherboard. Each point should be solidly connected and have a shiny round joint.
- Check that you’ve cleaned up any flux you had used. Depending on the type, it may be conductive and cause issues. MG 835 is strongly suggested to avoid this.
- "Wrong Version"
- Re-insert the USB cable
- What should I do if I ripped off a soldering pad?
- Look online for an alternate point to solder onto. Practice more on junk electronics before attempting to continue.
DirtyJTAG Usage
Make sure to download the latest J-Runner with Extras in order to use DirtyJtag.
- Flash the latest pico-DirtyJtag.uf2 to your Pico.
- Open Zadig and install the LibUSB-win32 driver to the device labeled
DirtyJtag - Use the following pinout for connecting your Pico to the glitch chip:
Pinout
| TDI | GPIO16 | 21 |
| TDO | GPIO17 | 22 |
| TCK | GPIO18 | 24 |
| TMS | GPIO19 | 25 |
| GND | 23 | |
| VCC | 36 |
Utilização como um Chip de Glitch
Não está claro como usá-lo como um chip de glitch mas foi demonstrado functionar como uma prova de conceito aqui.
While the RP2040 can be used to glitch a system, it has the major disadvantage of not being able to run in sync with STBY_CLK, which normal glitch chip designs can use. This means that the Pico cannot achieve the same rate of success as a normal glitch chip, and it can take more tries to successfully boot a system, especially with approaches requiring more precise timings, like EXT_CLK.




