Yifanlu explains Stage 3 of the HENkaku exploit, hints at a major upcoming update
After Developers St4rk and Hexkyz have proven they successfully reversed the HENkaku exploit, Yifanlu has (as promised) shared details on the obfuscation techniques he and the rest of Team Molecule have used to protect the HENkaku code.
I got confused for some time as to why the HENkaku code was obfuscated in the first place. Hardware mod teams such as Gateway obfuscate their code in order to protect their shady business and prevent clones from stealing their market. Team molecule had no such incentive. Yifanlu had stated a few times that the KOTH challenge of reversing the HENkaku exploit would bring hackers’ attention to the PS Vita, but I was missing one part of that logic. To me, obfuscating the code was just one additional layer on top of an already fairly difficult challenge. As we’ve seen, it’s not like stages 1 and 2 of the Henkaku exploit were easy to reverse engineer in the first place, so why add clever obfuscation on top of this?
Yifanlu was nice enough to take the time to explain this to me again: The encryption of the Henkaku exploit does not protect hackers from Sony reverse engineering the exploit (Sony have access to the source code of their firmware and to debugging tools, it was probably trivial for them to understand the exploit and how to patch it), and its goal is not directly to prevent other “teams” from reusing the exploit.
What yifanlu explained to me however, is that because of how HENkaku was protected, it required other hackers to find PS Vita kernel exploits in order to reverse engineer HENkaku. by submitting this challenge, Team molecule has ensure that a few hacking groups out there now know enough about the PS Vita that they could contribute to future hacks if needed.
Yifanlus’s explanation can be read on his article here. It’s a great read if you are even remotely interested in console hacking.
Last but not least, Yifanlu indicated in his article that a major update to HENkaku is coming soon (the source code for that will be revealed soon as well):
Molecule has gotten quite lazy since the release of HENkaku and since we underestimated the amount of time it would take for the challenge to be completed, we are only midway through polishing up the source code for release. The participants and I have agreed to not release anything until the end of the month. As a bonus for waiting, the source will not be for HENkaku as you know it today–it will be for the major update we have been working on. Stay tuned for more details!
Source: Yifanlu
Congrats to the participants, always nice to see new developments come up like this.
FIRST
U beat meh
2nd
I hope this means more pirating
“first, u beat meh, 2nd, i hope this means more pirating” – the four comments I could see as I started writing mine. Good work guys, give yourselves a pat on the back
I look forward to seeing what Team Molecule do next, to be honest – might it be that back porting of HENkaku to older firmwares, or for 3.61 forcing Sony to do yet another hasty patch job while Team Molecule laugh, standing on their hill built out of kernel exploits other hackers have gifted them plus more than a few of their own? That’s my guess.
I’ll read Yifan’s article with interest… not only an excellent coder but a great writer in the field of technology too. The Vita hacking scene would be lost without him, the rest of Team Molecule and TheFloW.
Now THAT’S a damn comment
with all the stuff thefl0w is doing with the pspemu porting to lower firmwares would be useless
Agreed. Just throwing ideas out there. All 3.60 needs to be the golden firmware is ePSP and PS1 Loader, the former is an excellent start.
Oh it’s not quite on topic for this but if anyone has recent nightlies of RetroArch with gPSP working for GBA support let me know. My old September versions run GBA games with frame skips, I want the JIT support so stuff like Super Circuit hold solid 60fps because then I don’t need to get hand cramp using my 3DS for the same job. Vita form factor is better 😉
Retroarch ps1 emulator is far breed than the one in the vita.
That surprises me actually, since 2016-10-20 nightly gPSP and VBA don’t run Super Circuit full speed – VBA is full speed everywhere but where it counts (the races) and gPSP can run full speed but randomly has huge lag and slowdown everywhere in the game.
Okay having briefly tested PCSX-ReARMed with SCPH1001 BIOS in place using THPS2 as test game I can safely say it isn’t better than the Vita’s inbuilt one as it constantly bogs down. In the hanger level as soon as you open the snowing outside bit with the tape the FPS can dip as low as 30 with assorted sound issues. My 3.51 Vita with TheFloW’s PS1 Loader exploit doesn’t do that.
not getting my hopes up for a 3.61 henkauk… that will never happen.
definitely not.
the vulnerability that enables henkaku is gone on 3.61, and there is no incentive in trying to find a new one there. 3.61 adds no features, no tools, nothing. “Stability” of course..
Major update ? Like 3.61 henkaku ver.?
more like a permanent hack to avoid the browser method, it would be nice… no need to hack it again every time it’s power off…
@Gerald the offline solution (Email app) Works really well, and is super quick
With how rare vita kernel exploits are, releasing one for 3.61 would be a huge waste. It’d be better to wait for a more substantial update. If someone updated to 3.61, that’s their own problem. Sell your vita and buy one on an older firmware.
3.61 ha nothing 3.60 doesnt have, so what use would 3.61 henkaku be?
Games that require 3.61, of course. Such as Dragon Quest Builders (full) and Darkest Dungeon
Dragon Quest Builders needs 3.60, but future games will probably need 3.61. World of Final Fantasy, for example.
Let’s hope there’s a PS4 HENkaku soon since they now have an exploit for 4.01. PS Vita and PS4 running HENkaku now that would be amazing
Will USB Hard Disk drives be a possibility for the PSTV once this kernel thing has been exploited ?
Dude………I fully agree as being able to redirect USB drive as UX0 would be the bomb. I mean I already have 64/128gb USB thumb drives (even those low profile ones). The speed of $ony memory is so slow and the price so high. You can buy a new PSTV on ebay/amazon for less than $50….open up the USB memory and goodbye overpriced $ony memory….this is my most desired feature!