Firmware 5.50 and 5.51 owners – don’t give up hope just yet, as a working exploit has been found in Medal of Honor: Heroes. (Just watch the youtube video above) This surfaced on the dcemu forums a few days ago. But like the other exploits this wasn’t thought to be of any use to us all. But unlike the others this one does work.
Thanks to kgsws˜™ for getting this far with a working exploit for 5.50 & 5.51 users.
Notes:
More info: Do not change room name to “lb” manually, use nitePR cheat to do it.
tested on: (and works)
- PSP-1000 (M33)
- PSP-3000 (CFW enabler)EDIT:
It was tested on PSP-1000 with official firmware 5.51, it works.
It should work on PSP-3000 too.
*Sit back and watch the Medal of Honor: Heroes price soar on Ebay and Amazon….
Source: Dcemu
MOHH (1) exploit by kgsws
What you need:
- CFW PSP (can be far away, this exploit works over net)
- NON-CFW PSP
- WiFi net (both PSP)
for CFW-PSP:
- nitePR plugin
for NON-CFW PSP:
- MOHH (1) UMDHow to do it (CFW PSP):
- install nitePR
- copy ULUS-10141.txt to nitePR folder
- enable nitePR plugin
- run game, join infrastructure
- switch to “create server” section
- activate cheat “Room name run:ms0:/hx”
- start server
- before joining as player activate cheat “Player name run:ms0:/hx”
- wait for second player
- endHow to do it (NON-CFW PSP):
- copy file “hx” to memory stick root (you can copy entire ms0 folder)
- run MOHH (1)
- join infrastructure
- wait until CFW PSP create server
- join game called “lb”
- find first player
- aim at first player
- that should be allFor now it is untested on NON-CFW PSP, try it if you can …
Some info:
Player name is vulerable to format-string exploit.
You can’t have player name too long, format-string exploit is only way.
If you put exactly 880 characters in name (by format-string), next 4 characters will overwrite $ra register.
OK, 880 characters only for on-aim exploit.
Exploit code is stored in room name, new $ra points here.
Exploit code just load ms0:/hx.
Room name is also limited in size, you can put there only 35 characters (no ‘\0′).
I used old game registers to get loader working.
This trick is limited, it loads only 62064b to address 0×08E3227C, but it executes it from 0×08E3228C, that means first 4 instructions won’t be executed.
File ms0:/hx must be big, becouse of PSP’s cache, so when you compile your own, append some chars at end.
Same bug might be in MOHH 2, but not tested.Room name code (addresses on execution):
#addr 0×08E32270
addi $a0, $a0, 0×626C # *path
#addr 0×08E32274
jal 0×08C92BE4
#addr 0×08E32278
li $a1, 0×0801 # flags (PSP_O_RDONLY | PSP_O_EXCL)
#addr 0×08E3227C
ori $a1, $ra, 0×227C
#addr 0×08E32280
andi $a2, $sp, 0xFFFF
#addr 0×08E32284
jal 0×08C92B94
#addr 0×08E32288
andi $a0, $v0, 0xFFFF
#addr 0×08E3228C
# ms0:
#addr 0×08E32290
# /hxRegisters on crash (new $ra):
zr:0×00000000 at:0×08C3BB58 v0:0×12000000 v1:0×08D10000
a0:0×08E2C020 a1:0×00000000 a2:0×08EC5BB0 a3:0×00003670
t0:0xD6000000 t1:0×47000000 t2:0×0046FFFE t3:0×08EC2540
t4:0×493F4000 t5:0×4A000000 t6:0×4B000000 t7:0×08D10000
s0:0×20202020 s1:0×20202020 s2:0×20202020 s3:0×46464646
s4:0×30464646 s5:0×08D923C0 s6:0×08D906A0 s7:0×00000002
t8:0×08D0BB80 t9:0×08D0BB80 k0:0×09FFFB00 k1:0×00000000
gp:0×08D4B440 sp:0×09FFF270 fp:0×00010000 ra:0×08E32270
Similar Posts
- Savegame Exploit found in PSP Firmware 5.50?
- PSP Go Hack isn’t fake. MaGiXieN tests FreePlay save game exploit
- LCS Cheat Device for Custom Firmware 5.50 GEN-B
- PSP Firmware 5.55 Vulnerable to MOHH Exploit
- PSP CheatUp v0.20 – Automatically download cheat codes
- PSP CheatUp v0.26 – Automatically download cheat codes




Digg it
Stumble
Del.ico.us
Reddit
Newsvine
July 20, 2009 at 12:16 am
what does this exploit exactly do..?
July 27, 2009 at 3:20 pm
nothing…………………………………………yet
we need a hen before this is of any use
July 20, 2009 at 4:10 pm
is it possible to mod a psp game? i think it would be awsome to have a portable nazi-zombie mod for free play for this game is that even possible?
July 26, 2009 at 12:17 am
is there a european save file for this?!?
July 26, 2009 at 4:38 am
Does anybody know if there’s any work on progress to have any expectation date?
July 28, 2009 at 8:53 am
I already have cfw on my psp 3000v5.50 , its called mv05.50
July 28, 2009 at 9:18 am
how???
do you know how to program and made your own cfw?
if nnot show me the download please
July 28, 2009 at 6:22 pm
Yeah, right. He’s the only one that has a CFW for 3000 series among all the scene… I don’t take it.
August 12, 2009 at 10:55 am
i do that procedure nothing,im still on ver. ofw 5.51,anyone who help me to make my ver. to custom fermware,thanks to pspslimhacks
August 12, 2009 at 5:22 pm
mohh exploit run to my psp3006 ofw 5.51,but nothing,i put 5.03 update to bin file and i run it nothing ur psp will turn to off mode,pls.. help me how to modified my psp.
August 15, 2009 at 5:07 pm
you cant flash a 3000 ok. nothing is gonna happen until someone makes a hen, so dont try anything that you think “might” work… its dangerous as it can brick.
im tired of waiting though almost a month since this was released. EXPLOIT READY NOW HEN NOWWW
ive been checking this site every 5 hours in case there is a hen
im sick of waiting
August 17, 2009 at 5:08 pm
I thougth I was the only one…what else we can do?…..keep waiting.
August 19, 2009 at 10:59 am
[...] (US) because the exploit is discovered and the eLoader will be released very soon.. Check this out: 5.51 working exploit found in Medal of Honor: Heroes! | 5.50 Exploit found, PSP Hacks – PSP Slim Hac… Article Detail – PlayStation Portable News – PSP Updates Article Detail – PlayStation Portable News [...]
August 20, 2009 at 8:10 am
CHECK THIS OUT.
eLoader in the works.
http://pspupdates.qj.net/eLoader-now-in-the-works-for-Medal-of-Honor-Heroes-exploit/pg/49/aid/133784
it’ll work up to firmware 5.55- so that means we’ll be able to play all the great new games IF you have Medal of Honor Heroes
August 21, 2009 at 4:39 pm
Great, great news!!! …only problem is…..I don’t have MHHE UMD ;-( !!!!!
August 26, 2009 at 4:08 pm
i know the moh exploit works but have they realesed something so we can get cfw..?
August 26, 2009 at 4:15 pm
like i have the game but there is only the exploit hey havent made a hen or something to get cfw.
August 26, 2009 at 4:43 pm
By the way, what’s an eLoader? How it would work? Is a must to have the game? m0skit0 says to wait to buy it until the eLoader is released.
August 30, 2009 at 8:24 pm
so any new about mohh exploit
August 30, 2009 at 8:25 pm
any news about mohh exploit
August 31, 2009 at 2:21 am
come on lets go
August 31, 2009 at 2:22 am
any one
August 31, 2009 at 2:23 am
were are you guys you dont care for eboot wich are sort of like iso but different come on no one wants free games fine
August 31, 2009 at 2:24 am
come on anyone its been 4 days whats the deal were is everyone
August 31, 2009 at 3:33 am
dude shut the hell up.
when someone makes something outta the exploit, then you’ll know.
for now, just stop asking.
August 31, 2009 at 7:29 pm
sorry man
September 3, 2009 at 12:03 am
anything realy come on
September 3, 2009 at 12:03 am
are you almost done?
September 4, 2009 at 7:48 am
i cant wait i want CFW on my psp 3000 i had chickHen R2 but it stopped working so i updated my firmware to 5.51 come on release HEN NOW PLZ
October 4, 2009 at 7:43 am
IS THERE ANY HACK FOR 5.50 OR 5.51 VERSION…..IF YESS THEN WHERE DO I GET IT……..WE CAN SAVE AND PLAT MEDAL OF HONOUR WITHOUT 5.50OR 5.51 HACK……PLEASE HELP ME………
October 4, 2009 at 7:44 am
AND HOW TO DOWN GRADE PSP 3000 FROM 5.50TO 5.03 VERSION
October 5, 2009 at 7:03 pm
I THINK I JUST CREATED A HACK FOR THE PSP 3000. WHAT IT IS SUPPOSED TO DO IS BOOT YOUR PSP INTO CHICKEN R2. I THINK THIS HACK WILL WORK ON FIRMWARES UP TO 5.51. BUT YOU MUST MEDAL OF HONOR: HEROES FOR THIS TO WORK. ALL YOU HAVE TO DO IS DOWNLOAD THIS FILE
HERE IS THE LINK:http://rapidshare.com/files/289176885/h.bin.html
AND WHAT UR SUPPOSED TO DO IS GO TO ADHOC MODE ON MEDAL OF HONOR:HEROES AND START A GAME AND KILL YOUR SELF.
THIS HACK WAS MADE FROM KGSWS MOHH EXPLOIT. COMMENT BACK HERE AND TELL ME IF THE HACK WORKS.
I RECOMMEND USING THIS ON A PSP 2000 CAUSE IF IT BRICKS UR PSP U CAN JUST U A PANDORA BATTERY AND MMS TO FIX IT.