5.51 working exploit found in Medal of Honor: Heroes

Share


Firmware 5.50 and 5.51 owners – don’t give up hope just yet, as a working exploit has been found in Medal of Honor: Heroes. (Just watch the youtube video above) This surfaced on the dcemu forums a few days ago. But like the other exploits this wasn’t thought to be of any use to us all. But unlike the others this one does work.

Thanks to kgsws˜™ for getting this far with a working exploit for 5.50 & 5.51 users.

Notes:

More info: Do not change room name to “lb” manually, use nitePR cheat to do it.

tested on: (and works)
- PSP-1000 (M33)
- PSP-3000 (CFW enabler)

EDIT:
It was tested on PSP-1000 with official firmware 5.51, it works.
It should work on PSP-3000 too.

*Sit back and watch the Medal of Honor: Heroes price soar on Ebay and Amazon….

Source: Dcemu


Download: Medal of Honor: Heroes Exploit for 5.50+ & 5.51 firmware
( for 5.50+ & 5.51 firmware - 19.5 KiB - 11,419 Hits)

MOHH (1) exploit by kgsws

What you need:
- CFW PSP (can be far away, this exploit works over net)
- NON-CFW PSP
- WiFi net (both PSP)
for CFW-PSP:
- nitePR plugin
for NON-CFW PSP:
- MOHH (1) UMD

How to do it (CFW PSP):
- install nitePR
- copy ULUS-10141.txt to nitePR folder
- enable nitePR plugin
- run game, join infrastructure
- switch to “create server” section
- activate cheat “Room name run:ms0:/hx”
- start server
- before joining as player activate cheat “Player name run:ms0:/hx”
- wait for second player
- end

How to do it (NON-CFW PSP):
- copy file “hx” to memory stick root (you can copy entire ms0 folder)
- run MOHH (1)
- join infrastructure
- wait until CFW PSP create server
- join game called “lb”
- find first player
- aim at first player
- that should be all

For now it is untested on NON-CFW PSP, try it if you can …

Some info:

Player name is vulerable to format-string exploit.
You can’t have player name too long, format-string exploit is only way.
If you put exactly 880 characters in name (by format-string), next 4 characters will overwrite $ra register.
OK, 880 characters only for on-aim exploit.
Exploit code is stored in room name, new $ra points here.
Exploit code just load ms0:/hx.
Room name is also limited in size, you can put there only 35 characters (no ‘\0′).
I used old game registers to get loader working.
This trick is limited, it loads only 62064b to address 0x08E3227C, but it executes it from 0x08E3228C, that means first 4 instructions won’t be executed.
File ms0:/hx must be big, becouse of PSP’s cache, so when you compile your own, append some chars at end.
Same bug might be in MOHH 2, but not tested.

Room name code (addresses on execution):
#addr 0x08E32270
addi $a0, $a0, 0x626C # *path
#addr 0x08E32274
jal 0x08C92BE4
#addr 0x08E32278
li $a1, 0×0801 # flags (PSP_O_RDONLY | PSP_O_EXCL)
#addr 0x08E3227C
ori $a1, $ra, 0x227C
#addr 0x08E32280
andi $a2, $sp, 0xFFFF
#addr 0x08E32284
jal 0x08C92B94
#addr 0x08E32288
andi $a0, $v0, 0xFFFF
#addr 0x08E3228C
# ms0:
#addr 0x08E32290
# /hx

Registers on crash (new $ra):
zr:0×00000000 at:0x08C3BB58 v0:0×12000000 v1:0x08D10000
a0:0x08E2C020 a1:0×00000000 a2:0x08EC5BB0 a3:0×00003670
t0:0xD6000000 t1:0×47000000 t2:0x0046FFFE t3:0x08EC2540
t4:0x493F4000 t5:0x4A000000 t6:0x4B000000 t7:0x08D10000
s0:0×20202020 s1:0×20202020 s2:0×20202020 s3:0×46464646
s4:0×30464646 s5:0x08D923C0 s6:0x08D906A0 s7:0×00000002
t8:0x08D0BB80 t9:0x08D0BB80 k0:0x09FFFB00 k1:0×00000000
gp:0x08D4B440 sp:0x09FFF270 fp:0×00010000 ra:0x08E32270

Similar Posts:

  • psp3001user

    what does this exploit exactly do..?

    • vin

      nothing…………………………………………yet
      we need a hen before this is of any use

  • theconkshell

    is it possible to mod a psp game? i think it would be awsome to have a portable nazi-zombie mod for free play for this game is that even possible?

  • lpm888

    is there a european save file for this?!?

  • emesma

    Does anybody know if there’s any work on progress to have any expectation date?

  • mv0539

    I already have cfw on my psp 3000v5.50 , its called mv05.50

    • vin

      how???
      do you know how to program and made your own cfw?
      if nnot show me the download please

      • emesma

        Yeah, right. He’s the only one that has a CFW for 3000 series among all the scene… I don’t take it.

  • ryan3000

    i do that procedure nothing,im still on ver. ofw 5.51,anyone who help me to make my ver. to custom fermware,thanks to pspslimhacks

  • ryan3000

    mohh exploit run to my psp3006 ofw 5.51,but nothing,i put 5.03 update to bin file and i run it nothing ur psp will turn to off mode,pls.. help me how to modified my psp.

    • vin

      you cant flash a 3000 ok. nothing is gonna happen until someone makes a hen, so dont try anything that you think “might” work… its dangerous as it can brick.
      im tired of waiting though almost a month since this was released. EXPLOIT READY NOW HEN NOWWW
      ive been checking this site every 5 hours in case there is a hen
      im sick of waiting

      • emesma

        I thougth I was the only one…what else we can do?…..keep waiting.

  • Pingback: Just want to know if i can get a cfw running. - PSP Slim Hacks - PSP Forums

  • vin

    CHECK THIS OUT.
    eLoader in the works.
    http://pspupdates.qj.net/eLoader-now-in-the-works-for-Medal-of-Honor-Heroes-exploit/pg/49/aid/133784
    it’ll work up to firmware 5.55- so that means we’ll be able to play all the great new games IF you have Medal of Honor Heroes

  • emesma

    Great, great news!!! …only problem is…..I don’t have MHHE UMD ;-( !!!!!

  • jony1

    i know the moh exploit works but have they realesed something so we can get cfw..?

  • jony1

    like i have the game but there is only the exploit hey havent made a hen or something to get cfw.

  • emesma

    By the way, what’s an eLoader? How it would work? Is a must to have the game? m0skit0 says to wait to buy it until the eLoader is released.

  • seadump

    so any new about mohh exploit

  • seadump

    any news about mohh exploit

  • seadump

    come on lets go

  • seadump

    any one

  • seadump

    were are you guys you dont care for eboot wich are sort of like iso but different come on no one wants free games fine

  • seadump

    come on anyone its been 4 days whats the deal were is everyone

    • KaminariiDenkou

      dude shut the hell up.
      when someone makes something outta the exploit, then you’ll know.
      for now, just stop asking.

  • seadump

    sorry man

  • seadump

    anything realy come on

  • seadump

    are you almost done?

  • sicsicsic

    i cant wait i want CFW on my psp 3000 i had chickHen R2 but it stopped working so i updated my firmware to 5.51 come on release HEN NOW PLZ

  • kewalshah27

    IS THERE ANY HACK FOR 5.50 OR 5.51 VERSION…..IF YESS THEN WHERE DO I GET IT……..WE CAN SAVE AND PLAT MEDAL OF HONOUR WITHOUT 5.50OR 5.51 HACK……PLEASE HELP ME………

  • kewalshah27

    AND HOW TO DOWN GRADE PSP 3000 FROM 5.50TO 5.03 VERSION

  • blazer13

    I THINK I JUST CREATED A HACK FOR THE PSP 3000. WHAT IT IS SUPPOSED TO DO IS BOOT YOUR PSP INTO CHICKEN R2. I THINK THIS HACK WILL WORK ON FIRMWARES UP TO 5.51. BUT YOU MUST MEDAL OF HONOR: HEROES FOR THIS TO WORK. ALL YOU HAVE TO DO IS DOWNLOAD THIS FILE
    HERE IS THE LINK:http://rapidshare.com/files/289176885/h.bin.html
    AND WHAT UR SUPPOSED TO DO IS GO TO ADHOC MODE ON MEDAL OF HONOR:HEROES AND START A GAME AND KILL YOUR SELF.

    THIS HACK WAS MADE FROM KGSWS MOHH EXPLOIT. COMMENT BACK HERE AND TELL ME IF THE HACK WORKS.

    I RECOMMEND USING THIS ON A PSP 2000 CAUSE IF IT BRICKS UR PSP U CAN JUST U A PANDORA BATTERY AND MMS TO FIX IT.

  • hardhead61

    any one got any idea as to when the 5.51 hen will be made?

  • erdemd