h-encore hack for PlayStation Vita 3.65 - 3.68 released by TheFloW

DhAu5gMX4AEX6-c.jpg

PlayStation Vita owners have been waiting with bated breath for Vita scene hacker TheFloW to release his latest exploit: h-encore. This marks the second ever major exploit for the Vita, following the 3.60 Henkaku hack. For the first time, OFW 3.65, 3.67, and 3.68 can be modified to run backups, run homebrew, and more. Adrenaline, which lets users exploit the PSP side of the Vita, has also been updated as of two days ago, to support the latest firmwares.

To use h-encore, you're going to need a PS Vita on firmware 3.65 or above, be linked (though not activated) to a PSN account, and if you're using a OLED Vita, you'll also need a memory card.

Enso can also be installed, but only for those who are on 3.65--there's no current support for Enso on higher firmware. TheFloW's instructions note that this installation is far more complex than previous Henkaku releases, and will require more work to ensure that it works correctly.

Note that the following guide is for advanced users and a bit more complicated than the previous hack that only required you to visit a website. If you don't understand the guide below or how to use these tools, you should neither file an issue here nor annoy me on twitter, but rather seek help on /r/vitahacks (check for duplicated questions first!) or wait for an easy installer.

  1. Download and install qcma, psvimgtools and pkg2zip (check the releases section).

  2. Download the vulnerable DRM-free demo of bitter smile (yes, that's the user entry point).

  3. Download h-encore and extract it on your computer.

  4. Extract the demo using:

    pkg2zip -x PATH_OF_PKG

    This will output the files to app/PCSG90096.

  5. Copy the contents of the output app/PCSG90096 to the folder h-encore/app/ux0_temp_game_PCSG90096_app_PCSG90096(such that the files eboot.bin and VITA_PATH.TXT are within the same folder).

  6. Copy the license file app/PCSG90096/sce_sys/package/temp.bin to the folder
    h-encore/license/ux0_temp_game_PCSG90096_license_app_PCSG90096 and rename the just pasted file temp.bin to 6488b73b912a753a492e2714e9b38bc7.rif. Again, this file should be in the same folder as VITA_PATH.TXT.

  7. Start qcma and within the qcma settings set the option Use this version for updates to FW 0.00 (Always up-to-date).

  8. Launch Content Manager on your PS Vita and connect it to your computer, where you then need to select PC -> PS Vita System, and after that you select Applications. If you see an error message about System Software, you should simply reboot your device to solve it. This should create a folder at PS Vita/APP/xxxxxxxxxxxxxxxx on your computer (see qcma settings where this folder is), where the folder xxxxxxxxxxxxxxxx represents the AID (account ID) that you need to insert here. If the AID is valid, it will yield a key that you can now use to encrypt the demo.

  9. Change directory to the h-encore folder in terminal and use the key to encrypt all folders that are listed below using:

    psvimg-create -n X -K YOUR_KEY X PCSG90096/X

    Where X is (yes, repeat it 4 times or write a script for that):
    • app
    • appmeta
    • license
    • savedata
    The folder h-encore/PCSG90096 should then contain sce_sys and all 4 folders from above, and within these folders you should find files called X.psvimg and X.psvmd, where X has the same name as the folder. Backup this folder, since if everything has been done correctly, you don't need to redo all the steps to install it onto another device with the same PSN account.

  10. Copy the folder h-encore/PCSG90096 to PS Vita/APP/xxxxxxxxxxxxxxxx/PCSG90096 and refresh the database under qcma settings.

  11. The h-encore bubble with a size of around 243 MB should now appear in the Content Manager and that's what you finally need to transfer to your PS Vita.

  12. Launch h-encore to exploit your device (if a message about trophies appears, simply click yes). The screen should first flash white, then purple, and finally open a menu called h-encore bootstrap menu where you can download VitaShell and install HENkaku.

  13. Enjoy. Note that you have to relaunch the exploit everytime you reboot or shutdown your device. Of course if you only put your device into standby mode, you don't need to relaunch.

:download: GitHub
:arrow: TheFloW's Twitter
:!: For those on 3.60
 

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
    K3Nv2 @ K3Nv2: Lmao that sold out fast