Advertisement



Go Back   Zune Boards > Zune Discussions > Zune Hacks & Mods > In Progress

New Member?



 
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

In Progress Want to know what hacks & mods we are working on?

Closed Thread
 
LinkBack Thread Tools
Old 08-30-2007, 04:10 PM   #1 (permalink)
zB Programmer
Jr. Member
 
Join Date: Jan 2007
Posts: 282
Reputation: 13
Default Zune HD on the PC


hey guys...got the zif connector and my zune...trying to take out the hd now
i'll fill in as i go






uaktags is offline  
Old 08-30-2007, 04:12 PM   #2 (permalink)
**** you
Administrator
Ultimate Zuner
 
Nurta's Avatar
 
Join Date: Jan 2007
Posts: 6,650
Reputation: 528
Send a message via AIM to Nurta Send a message via MSN to Nurta Send a message via Yahoo to Nurta Send a message via Skype™ to Nurta
Awards Showcase
Most Flamboyant Personality putis' Pet 
Total Awards: 2
Default

cool, are you able to jump onto the IRC
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.



Nurta is offline  
Old 08-30-2007, 04:17 PM   #3 (permalink)
zB Programmer
Jr. Member
 
Join Date: Jan 2007
Posts: 282
Reputation: 13
Default

idk...give me the link and we'll see



uaktags is offline  
Old 08-30-2007, 04:17 PM   #4 (permalink)
**** you
Administrator
Ultimate Zuner
 
Nurta's Avatar
 
Join Date: Jan 2007
Posts: 6,650
Reputation: 528
Send a message via AIM to Nurta Send a message via MSN to Nurta Send a message via Yahoo to Nurta Send a message via Skype™ to Nurta
Awards Showcase
Most Flamboyant Personality putis' Pet 
Total Awards: 2
Default

__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.



Nurta is offline  
Old 08-30-2007, 04:19 PM   #5 (permalink)
zB Programmer
Jr. Member
 
Join Date: Jan 2007
Posts: 282
Reputation: 13
Default

downloading an irc client...but so far it only recognizes the diskdrive, but its not accessible yet



uaktags is offline  
Old 08-30-2007, 04:24 PM   #6 (permalink)
**** you
Administrator
Ultimate Zuner
 
Nurta's Avatar
 
Join Date: Jan 2007
Posts: 6,650
Reputation: 528
Send a message via AIM to Nurta Send a message via MSN to Nurta Send a message via Yahoo to Nurta Send a message via Skype™ to Nurta
Awards Showcase
Most Flamboyant Personality putis' Pet 
Total Awards: 2
Default

You have got it connected to the PC and it isn't plug and play?
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.



Nurta is offline  
Old 08-30-2007, 07:31 PM   #7 (permalink)
**** you
Administrator
Ultimate Zuner
 
Nurta's Avatar
 
Join Date: Jan 2007
Posts: 6,650
Reputation: 528
Send a message via AIM to Nurta Send a message via MSN to Nurta Send a message via Yahoo to Nurta Send a message via Skype™ to Nurta
Awards Showcase
Most Flamboyant Personality putis' Pet 
Total Awards: 2
Default

w007, we have successfully downgraded the firmware using this method.

Which means we (should) have a hard mod that allows us to load a custom firmware to some degree
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.



Nurta is offline  
Old 08-30-2007, 09:35 PM   #8 (permalink)
zB Programmer
Jr. Member
 
Join Date: Jan 2007
Posts: 282
Reputation: 13
Default

well heres what we got thus far (the whole irc log should come tomorrow?).
As nurta said, we've been able to switch out the firmwares with our method utilizing the Zif connector. What we suspect now is that we should be able to, at some point, use our own custom firmware. Only thing is we get stopped by what seems to be a 3 step process. Step one shows a picture of a Zune and a loading graphic, with a message box stating "Please Wait". Then theres step 2 (we'll get into in a moment), and step 3 which again says "Please wait" but with a larger picture of a zune and a loading graphic. Now heres the theory i've come up with. Step 1 checks to see that there IS a firmware to load on the zune, if that basic step is accomplished, on comes step2. Step 2 checks to see if it's a legit firmware, if so it goes to step 3 and you'll never see step 2 appear, if not then step 2 has a picture of a zune and a computer with the message "Please connect your zune and restore device firmware". Then step 3 has 1 of 2 outcomes...If you manage to make it here with an illegitmate firmware, the Please wait is getting ready to reboot the zune and delete the firmware. If you pass step 2 legitimately, then Please wait will then load up the main menu screen

so
Step1 checks for A firmware
Step2 checks if firmware is legit
Step3 loads firmware/crashes if bad

least thats what i think thus far, until we find out more, this is all we can guess.



uaktags is offline  
Old 08-31-2007, 02:03 PM   #9 (permalink)
Pending
Support Team
zB Programmer
Super Zuner
 
Marshillboy's Avatar
 
Join Date: Nov 2006
Posts: 1,918
Reputation: 287
Default

Interesting...Good work! Care to upload some of the contents/screenshots/file list/anything you found via the zif connector?
__________________
Quote:
Originally Posted by Adam Frucci
And you know what? Macs are too hip. Oh, look at me! I do graphic design! I wear women's jeans and hang out in coffee shops! I'm a DJ! Well good for you. My computer is not a fashion statement. It's a computer.

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.



Marshillboy is offline  
Old 08-31-2007, 02:22 PM   #10 (permalink)
Administrator
Ultimate Zuner
 
Join Date: Jul 2006
Location: Fullerton, CA
Posts: 5,837
Reputation: 259
Default

Did you try the font thing yet? xD
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.




lpxxfaintxx is offline  
Old 08-31-2007, 02:58 PM   #11 (permalink)
**** you
Administrator
Ultimate Zuner
 
Nurta's Avatar
 
Join Date: Jan 2007
Posts: 6,650
Reputation: 528
Send a message via AIM to Nurta Send a message via MSN to Nurta Send a message via Yahoo to Nurta Send a message via Skype™ to Nurta
Awards Showcase
Most Flamboyant Personality putis' Pet 
Total Awards: 2
Default

ledzepp should have come in with the log...

uak did upload a couple of files, but they were in the log, I don't remember the URLs, uak might maybe

OK, the problem we have so far is that it still needs MS' sig or something. zepp made up a modified version of nk.bin with a different font, but it rejects it.

So the only thing currently we can try is modifying the files on there. Especially the edb files on there, that probably correspond to databases.


This still has potential, since we can return once again to buffer overflows and try modify the "databases" but to do that we need the software to do it Ana, you seem to have some experience with this, even though I haven't seen you post in here yet...

Also, could someone else try and make up a modified nk.bin file (and maybe mess with eboot somehow?) since zepp was coming up with some problems, maybe collingall or berdon? Keep it as similar as possible.
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.



Nurta is offline  
Old 08-31-2007, 03:15 PM   #12 (permalink)
Administrator
Ultimate Zuner
 
Join Date: Jul 2006
Location: Fullerton, CA
Posts: 5,837
Reputation: 259
Default

Hrm, I thought the font would be already in the device, and not in the firmware... I was thinking just "drag and drop" the font into the font directory. LOL, guess not.
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.




lpxxfaintxx is offline  
Old 08-31-2007, 03:21 PM   #13 (permalink)
**** you
Administrator
Ultimate Zuner
 
Nurta's Avatar
 
Join Date: Jan 2007
Posts: 6,650
Reputation: 528
Send a message via AIM to Nurta Send a message via MSN to Nurta Send a message via Yahoo to Nurta Send a message via Skype™ to Nurta
Awards Showcase
Most Flamboyant Personality putis' Pet 
Total Awards: 2
Default

Quote:
Originally Posted by lpxxfaintxx View Post
Hrm, I thought the font would be already in the device,
it is in the device, but it is packaged in nk.bin

ZunePet's postings on it we acaccurate after all, in that it is not decompiled by the Zune, it simply leaves everything wrapped up other than media and the bg and stuff.


A couple ideas:
get a 3x3 song from the HD and see if it has any actual drm to it or if that is managed by the device
overflow in the db
continue modifying the nk and trying to get it to boot
really **** with things and see if it recovers
delete the bg image/replace it with other image types/replace it with overflow images
mess with that xml document that zepp said shouldn't do anything
randomly put porn throughout the drive and see what happens
get the White Screen of Death back
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.



Nurta is offline  
Old 08-31-2007, 04:12 PM   #14 (permalink)
Administrator
Ultimate Zuner
 
Join Date: Jul 2006
Location: Fullerton, CA
Posts: 5,837
Reputation: 259
Default

What would happen if we loaded the Toshiba Gigabeat S firmware on it? Maybe it has the same signature as Microsoft's...
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.




lpxxfaintxx is offline  
Old 08-31-2007, 04:20 PM   #15 (permalink)
**** you
Administrator
Ultimate Zuner
 
Nurta's Avatar
 
Join Date: Jan 2007
Posts: 6,650
Reputation: 528
Send a message via AIM to Nurta Send a message via MSN to Nurta Send a message via Yahoo to Nurta Send a message via Skype™ to Nurta
Awards Showcase
Most Flamboyant Personality putis' Pet 
Total Awards: 2
Default

Quote:
Originally Posted by lpxxfaintxx View Post
What would happen if we loaded the Toshiba Gigabeat S firmware on it? Maybe it has the same signature as Microsoft's...
don't work
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.



Nurta is offline  
Old 08-31-2007, 05:05 PM   #16 (permalink)
zB Programmer
Experienced Member
 
LedZepp's Avatar
 
Join Date: Mar 2007
Posts: 975
Reputation: 119
Default

Im really sorry guys, there was a power outage in my neighborhood in the middle of the night. Lost everything i had on my computer that wasnt saved, including the log.

http://uaktechnology.com/localdiskzune.zip
http://uaktechnology.com/tfat.zip


those are the files that uak had given us, we had tried to put gigabeat fw on but it rejected it. Same with my modified nk.bin. Like nurta said we need more time to screw around with it. I should be getting my usb enclosure pretty soon(tomorrow or monday) so i will be able to do it too.




LedZepp is offline  
Old 08-31-2007, 07:24 PM   #17 (permalink)
zB Programmer
Jr. Member
 
Join Date: Jan 2007
Posts: 282
Reputation: 13
Default

"white screen of death" that nurta is refering to is something that i came across but may actually be done by others. What happened was while i was hooking my zune back up the battery wire was Fed and then when i finally got it to hook correctly and the zune logo to not keep flashing, what popped up for only a mere second was a White screen that resembled the old Blue Screen of Death, but had like jibberish all written in it. then it flashed away, i've been trying to recreate my mistake (all i kno is it came after having put the HD cord in the wrong way then the right way, then realized that the battery wasn't connected correctly becuz the logo was flashing..then when i fixed that, the popup came up) and since i havne't been able to recreate it, i haven't been able to get a pic/vid of it for nurta.

The TFAT file holds the firmware and the Local Disk holds the content folder (with all my music and stuff in it) and a few little files

Now my question is, anyone got any bricked Zunes. Broken ones, fed up ones, anything? i want to cross reference these hds..and see how different the data is on them thats stored (if i load up 3 completely wiped out hds) and start then from scratch with a 1.4 fw...then go in and look at the data it stores, whats different. maybe find our secret



uaktags is offline  
Old 08-31-2007, 07:27 PM   #18 (permalink)
**** you
Administrator
Ultimate Zuner
 
Nurta's Avatar
 
Join Date: Jan 2007
Posts: 6,650
Reputation: 528
Send a message via AIM to Nurta Send a message via MSN to Nurta Send a message via Yahoo to Nurta Send a message via Skype™ to Nurta
Awards Showcase
Most Flamboyant Personality putis' Pet 
Total Awards: 2
Default

Yeah, one other thing I think we should try for is the 1.0 firmware, which might give us something useful.

For this we need a brand new Zune though.
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.



Nurta is offline  
Old 08-31-2007, 07:42 PM   #19 (permalink)
Administrator
Ultimate Zuner
 
Join Date: Jul 2006
Location: Fullerton, CA
Posts: 5,837
Reputation: 259
Default

What about the ones that you guys won (by cheating ) on Club Live?
__________________

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.

To view links or images in signatures your post count must be 0 or greater. You currently have 0 posts.




lpxxfaintxx is offline  
Old 08-31-2007, 07:42 PM   #20 (permalink)
zB Programmer
Jr. Member
 
Join Date: Jan 2007
Posts: 282
Reputation: 13
Default

ok..so we need brokens and brandnews...lol...we sure that we cant find the fw on a ms site?



uaktags is offline  
Closed Thread


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On