Hacking PSA: Fake GoldHEN Payload

SapphireExile

Sapphire
OP
Member
Joined
May 2, 2018
Messages
115
Trophies
0
Age
27
Location
Bartow, FL
Website
sapphirelabs.online
XP
464
Country
United States
A fake GoldHen has been found in the wild to be bricking consoles. It usually goes by name "GoldHEN v2.0.1b" and is being hosted on several hosting sites.

Always read the code you run. If you can't, make sure you're only running payloads for trusted sources such as @Leeful and @Prb. Best case is to grab the payloads from the developers themselves when possible.

News covering this:
https://wololo.net/2021/10/03/psa-p...on-some-exploit-hosts-jailbreak-users-beware/

*Edit
If anyone finds one of these hosters, let me know and I'll add it to a list here for people to avoid, or someone can start a new thread with a list of bad hosts.
 
Last edited by SapphireExile,

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
36,184
Trophies
3
XP
26,066
Country
United States
I can't seem to dump my sflash0. it either fails after so much time or I only get around a 512KB file when it's supposed to be 32MBs. this is on 5.05. it shows all files in dev as being 0KBs in every one of the three ways I've tried dumping it. @KiiWii @Leeful ? file xplorer also kernel paniced immediately after trying to dump the sflash0. the other two ways orbis ftp and the normal goldhen ftp didn't do that.
 

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
36,184
Trophies
3
XP
26,066
Country
United States
are you able to dump it? I'm using xproject and goldhen 1.1, also tried vortex ftp, and I tried file xplorer. none worked.
 

Leeful

GBAtemp Member
Developer
Joined
Sep 4, 2015
Messages
1,885
Trophies
1
XP
6,795
Country
United Kingdom
I can't seem to dump my sflash0. it either fails after so much time or I only get around a 512KB file when it's supposed to be 32MBs. this is on 5.05. it shows all files in dev as being 0KBs in every one of the three ways I've tried dumping it. @KiiWii @Leeful ? file xplorer also kernel paniced immediately after trying to dump the sflash0. the other two ways orbis ftp and the normal goldhen ftp didn't do that.
Just dumped my 505 sflash0 twice without any problems. Once using GoldHEN 1.1's FTP and as a second test using X-Project 1.5.8, Hen2.1.3 and xVortexFTP.
both dumped the full 32MB. (size showed 0 inFTP)
Not sure why you are having problems, Might be a setting in your FTP client, might be if you are using the Sandisk Connect, but I dont think that will be it if FTP usually works with it.
 

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
36,184
Trophies
3
XP
26,066
Country
United States
Just dumped my 505 sflash0 twice without any problems. Once using GoldHEN 1.1's FTP and as a second test using X-Project 1.5.8, Hen2.1.3 and xVortexFTP.
both dumped the full 32MB. (size showed 0 inFTP)
Not sure why you are having problems, Might be a setting in your FTP client, might be if you are using the Sandisk Connect, but I dont think that will be it if FTP usually works with it.
yep, must've been the sandisk connect. I signed online to get it. it was very quick this time. the system tried to download system software 9.00 and an update to cyberpunk (think it was 1.31), both failed, possibly due to having update blocker. I just put in the dns to block updates (do these ever change?), and I'll stay online for the time being maybe or maybe not:

1633284936816.png
 
  • Like
Reactions: Leeful

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
36,184
Trophies
3
XP
26,066
Country
United States
I'm not entirely sure. I think it contains the main ps4 keys for your system. I think the eap key is part of it. that's the hdd key to decrypt and encrypt it. the only way I know of to put it back is a hard mod, but transferring it via ftp makes it easier, I guess.
 

TurboLolo

Active Member
Newcomer
Joined
Mar 24, 2021
Messages
34
Trophies
0
Age
37
XP
353
Country
Poland
I'm not entirely sure. I think it contains the main ps4 keys for your system. I think the eap key is part of it. that's the hdd key to decrypt and encrypt it. the only way I know of to put it back is a hard mod, but transferring it via ftp makes it easier, I guess.
Hmmm... interesting. I thought that kind of data is stored on some kaind of flash memory not just FTP accessed file.
 

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
36,184
Trophies
3
XP
26,066
Country
United States
I'm not sure what all ftp has access to, but there are 14 or 15 partitions with the hdd. I think each partition listed on the root is either the hdd or flash memory. I've not counted them though, and I just assume that.
 

TurboLolo

Active Member
Newcomer
Joined
Mar 24, 2021
Messages
34
Trophies
0
Age
37
XP
353
Country
Poland
I remember when connecting my 1TB PS4 (update to 4TB) HDD to PC and sow 15 partitions, that was crazy.
 

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
36,184
Trophies
3
XP
26,066
Country
United States
yeah, when I formatted my ps4 hdd in disk management to get rid of my banned account, it was kinda a pita. I had to delete each partition one-at-a-time. one partition was much larger than the others. it was probably the user one.
 

TurboLolo

Active Member
Newcomer
Joined
Mar 24, 2021
Messages
34
Trophies
0
Age
37
XP
353
Country
Poland
yeah, when I formatted my ps4 hdd in disk management to get rid of my banned account, it was kinda a pita. I had to delete each partition one-at-a-time. one partition was much larger than the others. it was probably the user one.
Yep, the large one is the user one.
 
  • Like
Reactions: godreborn

You may also like...

General chit-chat
Help Users
    AncientBoi @ AncientBoi: No Thanks. I'll just use my own :evil::rofl2: