Yifan Lu releases psvimgtools, a Vita Backup Decrypter

image.jpg

The Playstation Vita's Content Manager Assistant allows you to backup games, saves and settings to your PC, encrypted with an AES256 key, which means that you can't do that much with them. While the hackers xyz and proxima were reportedly busy researching the F00D processor of the Vita, they discovered a trick that lets you practically obtain this secret key. With the AES256 key in one's possession, it's it now possible to decrypt Vita CMA Backups, even those from an unhackable firmware (3.63 etc.) although a hackable 3.60 Vita is always required.
Scratch that. Team Molecule member Davee prepared an online converter at this address.

Yifan Lu posted about this process in their blog and released psvimgtools, which consists of a PC tool for Windows, Mac and Linux as well as a companion homebrew application for Henkaku-enabled PS Vita systems. Yifan Lu summarized the possibilities that this provides as follows:

Hacking backups isn’t as fun as having a hacked system. So, don’t update from 3.60 if you have it! You cannot run unsigned code with this, so you are only limited to tricks that can be done on the registry, app.db, and other places. This includes:

- Enabling almost any games to run on the PSTV
- Swap X/O buttons for out-of-region consoles
- Run PSP homebrew with custom bubbles
- and maybe more as people make new discoveries

As a bonus, Yifan Lu claimed that because how Sony implements CMA backups and this trick relying on a hardware vulnerability, it is pretty much impossible to patch in future system updates. If Sony nonetheless decides to fix this, they would break compatibility of all CMA backups created to date, which even Sony is unlikely to pull off.

For more information on how this works, head to the source for Yifan Lu's blog post.

:arrow: Get psvimgtools on Github
:arrow: Source
:arrow: Yifan Lu's Twitter
 
Last edited by WiiUBricker,

yifan_lu

@yifanlu
Member
Joined
Apr 28, 2007
Messages
663
Trophies
0
XP
1,671
Country
United States
Just letting you know I have the the exact same problem. Maybe @yifan_lu can help?
Read the readme.

https://github.com/yifanlu/psvimgtools/blob/master/README.md

"The pack input directory should follow the same format as the output of psvimg-extract. The means a separate directory for each backup set (there may only be one set, in which your input directory will contain one subdirectory) each with a VITA_PATH.TXT file specifying the Vita path and optionally a VITA_DATA.BIN file if the set is a file."
 

WiiUBricker

News Police
OP
Banned
Joined
Sep 19, 2009
Messages
7,827
Trophies
0
Location
Espresso
XP
7,485
Country
Argentina
Read the readme.

https://github.com/yifanlu/psvimgtools/blob/master/README.md

"The pack input directory should follow the same format as the output of psvimg-extract. The means a separate directory for each backup set (there may only be one set, in which your input directory will contain one subdirectory) each with a VITA_PATH.TXT file specifying the Vita path and optionally a VITA_DATA.BIN file if the set is a file."
Thanks. Maybe you can include the readme in the download archives as well.

https://twitter.com/DaveeFTW/status/833760978869374976

"You no longer need a vita to derive your AID for CMA backup decryption. Use this:"
http://cma.henkaku.xyz/

Great! XD
Thanks. I have updated the OP to reflect this change.
 
  • Like
Reactions: RealityNinja

Chary

Never sleeps
Chief Editor
Joined
Oct 2, 2012
Messages
12,340
Trophies
4
Age
27
Website
opencritic.com
XP
128,231
Country
United States
Wow, man, you and Prans are scooping up all the hot news this past week! I'll have to pick up my game and get back into things.

This is awesome to hear, I can't wait to see how the Vita hacking scene progresses onward.
 
  • Like
Reactions: RealityNinja

Sonic Angel Knight

Well-Known Member
Member
Joined
May 27, 2016
Messages
14,397
Trophies
1
Location
New York
XP
12,926
Country
United States
I have to agree with @Chary as much as i like these new tools, is just a shame that the people didn't just make stuff like backups easier from day one. :(

Now to prepare my body for USB HDD loading on psvita tv. Someone who been buying all his games on sale during playstation store discounts needs this badly. How am i suppose to play chary's beloved persona 4 golden? :creep:
 

Nirmonculus

Well-Known Member
Member
Joined
Nov 4, 2014
Messages
735
Trophies
0
XP
560
Country
This is one good news. Really happy about this. Been playing a lot on Vita lately :B so those backups can be edited on the pc side and imported back in?
 

wookiee

Member
Newcomer
Joined
May 14, 2016
Messages
12
Trophies
0
XP
83
Country
United States
Sorry noob here and just got a vita yesterday. What's a vita backup decrypted? I've got my vita on 3.6 and added henkaku.
 

aljpn91

Banned!
Banned
Joined
Dec 28, 2015
Messages
276
Trophies
0
Age
32
XP
122
Country
Sorry noob here and just got a vita yesterday. What's a vita backup decrypted? I've got my vita on 3.6 and added henkaku.

it's an encrypted backup of a psvita game/save/app made with CMA (content manager assistant) stored in your computer
 
Last edited by aljpn91,

elBenyo

Wad of meat.
Member
Joined
Jan 2, 2016
Messages
487
Trophies
0
Age
33
XP
885
Country
United States
Now the question is can we trade legit backups between systems or inject the contents of one game over another? If PSP homebrew works on 3.63 do PSP backups load this way, or PS1 games in PSP mode?
 

DavidKang

Well-Known Member
Member
Joined
Jun 23, 2012
Messages
139
Trophies
1
Location
Seoul
XP
782
Country
3.61+ games on 3.60 vita? By transporting over the games via CMA backup? Not yet right? Still waiting for 3.61+ games support for henkaku...
 
  • Like
Reactions: Meteor7

signz

Timelord
Member
Joined
Jul 16, 2008
Messages
2,120
Trophies
1
Age
36
XP
1,238
Country
Germany
What I wonder is, by using psvimage-extract, are the extracted files also decrypted or still encrypted? Tried editing my FFXHD (digital, on 3.63) save but FFXED couldn't open the created .psu file (followed this tutorial to create one out of my data0000.bin). Well, it could open it but the data was really scrambled. :/
 

WiiUBricker

News Police
OP
Banned
Joined
Sep 19, 2009
Messages
7,827
Trophies
0
Location
Espresso
XP
7,485
Country
Argentina
What I wonder is, by using psvimage-extract, are the extracted files also decrypted or still encrypted? Tried editing my FFXHD (digital, on 3.63) save but FFXED couldn't open the created .psu file (followed this tutorial to create one out of my data0000.bin). Well, it could open it but the data was really scrambled. :/
This has been discussed a few posts back in this very thread.
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    Bunjolio @ Bunjolio: a