That's actually a nice trick, I never thought about that, I just had the idea of running a homebrew inside a "signed" npdrm iso, but if we can get passed it, it's just as finekgsws wrote:Well ok, here it comes. Try this one.
tested on fat PSP with OFW 6.35
How?
Simple, notice it contains ~PSP header from demo game (UCES00206), it is exactly same header.
It is easy to craft last 16 bytes of encrypted data block to match header CMAC - yes, that's the trick
There are some strange thigs, it can't run homebrews with bigger executable block (data block does not matter), and because of ~PSP header, it has to match exact size of original game.
This trick might be possible on firmware kernel modules to get permanent HEN on non-pandrorable PSPs, i was not able to do it but i was not trying that much.
PS: i am not only one who found this trick
Advertising