Release: Tom & mr.Gas publish custom Bubbles trick for PS Vita!
Even thought some of us told you that there won’t be a christmas present for 2014, since the leaked september files for the firmwares 3.18/3.20 were supposed to be this years christmas presents, some others decided that it would not be okay to leave you guys hanging without a christmas present and those guys are the french developer Tomtomdu80 and his good friend mr.Gas.
Those 2 devs have decided to share one of the multiple methods we have to create and launch our own custom bubbles on the PS Vita.
But how does it work? Well…
Before we take a look at the tutorial of these guys, we have to take a look at the native side of the PS Vita and some of the starting parameters that are executed when launching content for the PSPemulator of the PS Vita.
originalpath=ux0:pspemu/PSP/GAME/NPUG80318& selfpath=ux0:pspemu/PSP/GAME/NPUG80318/EBOOT.PBP& discid=NPUG80318&parentallevel=3&gamedataid=&appver=00.00& bootable=1&category=EG
This is an example parameter of launching a PSP game on the PS Vita. We can see that the original path seems to be located in the ux0:/ part of the PS Vita, which then executed the PSPemulator alongside a file that will be launched inside of the PSPemulator, in this case it is the EBOOT.PBP file inside of the path /PSP/GAME/NPUG80318/.
The game (Game ID: NPUG80318) is Loco Roco: Midnight Carnival by the way, but that is not important – any PSN game can be used for this trick, just as a little side notice.
Additional starting parameters are added with an ampersand (the ‘and’ symbol – &). These starting parameters can be exploited with renaming a folder into NPUG80318&, while having the original folder NPUG80318 alondside it.
If you did this, and then dropped a fake_np signed EBOOT.PBP file, that uses the bought PSN game (any!) as a base, you will be able to launch your ‘fake signed’ game instead of the purchased PSN game. Oh, and the custom bubble appears after a quick database rebuild.
A little summary how to do this:
Rename a PSN games folder into (for example) ‘MyHomebrew&’.
Now create another folder inside of /PSP/GAME/ and call it ‘MyHomebrew’.
Drop a fake_np signed EBOOT.PBP into the ‘MyHomebrew’ folder.
Rebuild the database to make the bubble appear (or change its appearance).
That is basically it. Now I know that most of you will ask us ‘How to create a fake_np signed EBOOT.PBP file, that uses the PSN game as a base?’, and we have a solution for this!
Just follow KanadeEngel’s video on creating the fake signed EBOOT.PBP file, and follow my Video on doing the necessary steps on your PS Vita.
Keep in mind that the PSN games EBOOT.PBP file has to be bigger than the uncompressed content (GAME.ISO file) you want to sign! So compressing a “too big” game into .CSO, .DAX or anything else wont help you!
Keep in mind that in order to rename a folder on your memory stick, you have to have access to at least a working VHBL exploit, which enables you to run a PSP homebrew to rename a folder on your memory stick. As long as you are using an older firmware with a working exploit (e.g. FW 3.18 or 3.20), then you are easily able to recreate this.
For those of you currently running firmware 3.30+, you guys have to wait until someone releases a VHBL for those firmwares, unfortunally. But don’t be sad, we have good news!
Our forums user Crownable has found an usermode exploit in a PSP game, and he said he is going to release it, if it can be used for a VHBL.
With the custom bubbles around the corner, I bet (well, or hope…) that he is going to release this for the firmwares 3.30 – 3.35, instead of waiting for a new firmware like everyone else is currently doing.
Once again thank Tomtomdu80 and mr.Gas for this awesome christmas present, and be sure to check our blog to not miss our upcoming tutorial for creating your own fake_np signed Homebrews!
Merry christmas everybody!






Great job and btw First!
Best Christmas ever?… I very much think so.
Very nice, got the minecraft update now this? I don’t want nothing else for this year 🙂
Thank You to All of the Developers who were involved and also thank you to all the people who helped bring us the information. Happy Holidays. 🙂
just christv works and it isnt even decent freeware 🙁
uknow its been over ten years ive been searching for livetv-dlna
nice bubbles !!!!!
XDDD
I am a bit confused here , what is the point of this in basic terms?
Very simple, you can create your own bubbles if you meet the requirements.
what is the point in that?
Booting homebrew more directly without going through the exploit game, I think
It won’t work on TN-V?
Very confused on how to go about this. I know u need to change the folder names with psp filer, but before that you need a signed eboot, and before that you need an iso of the home brew you’d like to sign, and before that you need a way to convert a homebrew eboot into an iso. Is there a tutorial from beginning to end for a complete newb to take the pspFiler homebrew and go through each step to create these bubbles?
Also once a bubble is created will you need to spoof the folder name of another game to add a new bubble to the vitas home screen? In the proof of concepts people were creating multiple bubbles of the same game. Can that been done with this current method?
any help would be appreciated.
too bad im on the lower firmware but does not have any exploitable game.. hahaha.. you had me going there.. >.<
but the downside is u need a double copy of pbp so it eats a lot of memory card,,, or after u rebuild database it automatically merges the pbp files and delete one??
Nice to see a release! I take it however that this is not the method used to turn FFT0 into a bubble… Just based upon the size that is…
The FF Type 0 you saw running as a bubble was just an eCFW launched through the bubble that auto launches FF Type 0 (or any other ISO).
so incase you intall tnv bubbles u will have tnv even if you update your fw? hope there would be an upcoming tutorial for that
Nope, they’re using a private kexploit, the public can’t run any eCFW past 3.18, if you update past 3.18 the best you’ll get is a user exploit if one gets released.
So how do you sign a TN-V launcher?
On 3.18
https://twitter.com/qwikrazor87/status/548261027976970240
Thank you Qwik, it’s exactly what i was looking for.
I found annoying launching VHBL into Gladiator’s exploit…
I’ll give it a try next days 😀
This is a great Xmas present
Good stuff, this better lead to piracy, and FIRST for the win.
I think post should start like this
” even though I was a douchbagg and told you all that you won’t get any Christmas surprises…..”
xD
Because it is totally 100% my decision to release or not release this.
Inb4 FW 3.40 and people cry for another release.
How can you say its 100% your decision…are you master to Mr.gas or Tom …or is that your work?
On his you tube video he posts that hes annoyed that “his good good friends” decided to release, but here he says it was one hundred per cent his decision. This odious man, who sits in a darkened room 24/7, who has nothing but contempt for us lesser beings, truly has delusions of grandeur and clearly has no idea of his own limitations i.e. loves to say “we” alot and showcase other peoples hard work!
Folks… he was being sarcastic.
“We” when there is work done by friends …”I” when the decision is to be made
Raiden, read this page and then re-read my comment:
http://en.wikipedia.org/wiki/Sarcasm
wow!!!! So you learned your sarcasm from wikipedia ….nice
Please kill yourself. Thanks.
There is such a thing as knowing when you are a fool. Sometimes tis best to willfully acknowledge such, as it adds depth to your character, not so! says the obstinate child, balking at each imagined slight.
in his defense he probably knew about it ahead of time and wanted it to be a supprise instead of giving you what you expect
Good Xmas present. Hope I can make this trick work or I’ll need a guide for dummies 🙂
wow that good!!!thnx guy keep working 🙂
This is probably a stupid question, but just to make sure before i go through the trouble myself… This can work on a PSTV right? thank you to anyone who takes the time to answer.
Yes. Don’t update or you’ll be sobbing.
OH, thats great. Thank you mr.gas and tom for the release.
But how do I convert a psp eboot to iso?
If .iso/eboot.pbp < exploitgame then this trick is near useless for people running talkman tokyo (17MB), amiright?
It doesn’t necessarily need to be the exploit game.
Yes, assuming that it’s their biggest PSP game, and they will have to buy a bigger game in that case. I’d recommend GTA Vice City Stories (it’s pretty cheap for its >1.5GB size, at least when it’s on sale).
i figured out a way you can double the size of the game continuously to add more games to it.
so if you have a game with 1gb it can go up to 2gb but it’s pretty easy just put the same game folder as your exploit use cdma upload it into it delete game and reinstall using cdma and it should work i yet to try it you should give it a shot.
I love the fact old tools and basic observation achieve this. Please, tell me the other way is more innovative (not that this didn’t require innovation). lol Sony is an old dog that needs new tricks, y’know what they say about old dogs? Where is the keymaster, Neo? :p Guess once you build your home’s framework you can only do so much with it unless you knock it down and start again completely from scratch. The house has been cased, only a matter of time for pure genius to emerge with the lock picks. Nice work, gentlemens, and thank you!
Nice, thanks a lot for the release!
Reminds me of the trick used to launch homebrew back in the days of the PSP OFW 1.50, where you would put MyHomebrew and MyHomebrew% in ms0:/PSP/GAME
soooo, this won’t work on 3.35??
Z,qwikrazor87 can i do this to ps1 game? and if i can is it the same way to psp game?
You cant. PS1 games use PSISOIMG instead of NPUMDIMG.
There is a total noob loader to run it without exploits ?
Thank You 🙂
Thanks . 🙁
Is the PSISOIMG format (and its encryption) known well enough? Maybe theoretically, a tool like fake_np that operates with the PSISOIMG format could be made. Probably it’s just that no one cared about doing it. Though there have been a lot of questions from users all the time about this.
The ps vita never will be hacked thats the true
What exactly are you trying to say? In many ways, it’s already hacked…
Well, Z and his friends have had 3.3x exploits for a long time and are keeping them secret. So I’m glad this Crownable dude is sharing.
You got a free way to run any PSP game you want as a damn bubble on 3.35 (which is basically better than a kxploit) and you still complain.
Good job, Tom. You should’ve kept this for yourself. Some people dont deserve free exploits.
I have an idea, why dont we SELL exploits? 50$ each exploit, that might be a good idea for people to see the value in this work.
/s
That’s a terrible idea. There were bound to be ungrateful ppl there always is? That doesn’t mean you should ignore the ppl who are. The first 3 comments are thx m8t. A play on the PSP emulator and a way around ecfw for all those who were without. Once again thanks everyone!
/s indicates sarcasm. Do people not understand sarcasm anymore?
Lol no its very difficult over the computer, someone else pointed out this out in another post. Oh well blah blah thank them. And thank you. Next pro online mode on ecfw! Lol since the psn is down :p
You fail at sarcasm, and life…
I’m complaining about you. Not the people who actually do things.
help needed! im on 3.18 and i have 1 psp psn game which is patapon 2, when i run tnv on patapon 2 and use pspfiler homebrew to rename the patapon2 folder with the same game id but with an & at the end, it doesnt work, like its protected or something it just reverts back, any suggestions?
You probably shouldn’t try to do that if your only PSP game is your exploit game, you won’t be able to load back into tn-v if you replace your exploit game.
Providing you got the exploit have backed up with CMA, there’s no danger in messing around with it. Your can just restore the game backup of something goes wrong.
*exploit game backed up with CMA
I’ve been having the same issue, psp filer isn’t able to rename or delete files within the game folder for me. Could potentially be because the game is in use, since we’re running tnv using it.
I’ve had to go away for a few days and left my vita at home though, so only had 30 to play around with it before I left. Someone suggested renaming the GAME folder and trying again, but that didn’t seem to change anything either. Changes don’t seem to stick when found through ftp either.
ok so i would like a bit more clarity with this.
1. all this does is replace a bubbles boot path? meaning it does not make a new bubble on its own?
2. the game that you are wanting to use as the launching game/homebrew has to be a less memory size the bubbled game your replacing? so for those users that has Talkman Travel Tokyo (18MB) have to use a game that’s 18MB or lower?
This is correct. Keep in mind that you can use ANY(!) PSN game as a base for this trick, instead of only exploit games.
You could use Little Big planet (~1.3GB, afaik) for this trick and then boot any ISO that is smaller than the base game you have used (little big planet, ~1.3GB, in this case).
is this limited to a bought (psp and not psvita) psn game? or is there a way to make a bubble from other means? as awesome as the exploits and all are its a bit troubling to keep buying games to get some hack/exploit to work (not to mention that i spent about 100+ on my vita for just the exploited games lol)
in some videos I have seen that there is’ a chance to put homebrew ? as a direct start , how can I do this’ ?
Thank You
Wouldn’t this technically work with PS1 EBOOTs by using the same method?
nope
does this work for psn demos or must be a bought game?
It has to be a PSP PSN game.
There are no PSP PSN demos that can be downloaded onto the Vita.
PS1, PSV or PSM content does not work with this.
Locoroco midnight carnival demo can be downloaded on US PSN
Split second demo too
Can custom bubble be transferred by opencma?? If yes i’d find myself a lower firmware vita…
As ErikPshat pointed out a few years ago, this can be easily bypassed by taking out USRDIR of the ISO to the location near the signed EBOOT.PBP on the memory stick, and modifying/signing BOOT.BIN accordingly to have paths changed from disc0:/ to the new paths on ms0:/. However, I never tried this myself (haven’t got the time) and I’m not sure whether this will work for ISOs where the functionality is critically dependent on the lba positions.
(Note: the first paragraph is a blockquote, but due to a bug in the site’s current design, it doesn’t appear any different from the other text)
so is the playstation store down or whats up ?
Yes. Sony is getting DDoSed.
While I have moved on to 3.35, I’m glad to see one working bubble exploit is out there in the wild. With my limited knowledge of the subject I don’t know if this can be patched or if Sony can make only valid content run.
Thanks again for all your hard work, Devs & Merry Christmas/Happy Holidays to all!
Thanks for your hard work Z I appreciate all you’ve done and your work on the videos your site is also very helpful to the community I always go there lol
Do this bubble trick work with “Ape Quest Starter Pack PSP demo” or not please reply Im on 3.18 and have a exploit game too (Patapon 2)
How do I get fake_np to sign my homebrew? I’m trying to sign pspfiler.iso but the fake_np keeps closing half a second after launch.
Are you running the command line? To open the commandline in Vista/7/8+, go to the directory that contains fake_np, Shift+RightClick empty space inside the directory and select “Launch Command Prompt Here”. Then you need to use the command line as described here: http://wololo.net/talk/viewtopic.php?f=29&t=10197#p122980
You mean to edit this command line (fake_np [-b base_name] [-c] [iso_name] [pbp_name]) with the PSN game, ISO, and EBOOT.PBP? I tried that and it still closed on me. Nothing changed
Yes. for example:
fake_np -b my_psn_game.pbp pspfiler.iso eboot.pbp
This will take the header from my_psn_game.pbp and turn pspfiler.iso into an eboot.pbp.
If you are running this from the commandline, then it shouldn’t close immediately. It should instead show you an error and then let you try again.
I did everything you said. A new command window open and closed and then it repeated the command line. I didn’t get any errors. I’m not sure if it’s a compatibility issue with fake_np.exe on Win. 7. If it is, which compatibility mode do I switch it too?
Why uncompressed?
Just wondering after creating a custom bubble, theoretically would it be possible to use qcma to transfer the custom bubble to a 3.35 firmware?
I would say no, since QCMA would likely only copy the NPXX00000 folder (Which should contain the game, but now contains your Homebrew/ISO) and not the NPXX00000& folder, which would contain the actual PSN game.
I haven’t tried this, but If QCMA only backs up the NPXX00000 folder (I don’t see any reason for it to back up the NPXX00000& along with it, since according to the vita/CMA it shouldn’t exist) It’ll show up as corrupt data after restoring, if the NPXX00000& Folder is not there as well.
can u like do make kxploit on wagic src and use it that way ?
or is it make bubble now ?
if u ftp upload ?
Awesome! Thanks for the hard work devs! 😀
Nice Christmas Present 😀 But Sony may be able to ban you from using these Bubbles correct? And since people online can see what you are playing couldn’t you just not rename the Bubble and just keep it as it’s original PSN game? So then Sony doesn’t know whether or not its legit or fake? It’ll be more confusing if you have a lot of Bubbles to begin (don’t know which game is which) with but would this be considered safer so as to not get banned?