Show Posts

This section allows you to view all posts made by this member. Note that you can only see posts made in areas you currently have access to.

Topics - teakhanirons

Pages: [1]
PS 2 / Injecting ELFs via Disc Swapping
« on: February 03, 2020, 04:28:25 AM »
Silica suggested that we could use the same technique used with the 007: Agent Under Fire method of PS2 hacking with other games.

It's simple, you find a game that loads other ELFs, you swap the DVD (without the system knowing) with a copy of the game but the ELF game calls swapped (preferably with uLaunchELF or wLaunchELF due to their small sizes since you have to keep the Table Of Contents same, more on that later)

This is the earliest record of this technique being public knowledge we could find (aside from 007: Agent Under Fire):
Then we found a forum post about this used with 007: Nightfire back in 2009, they use the same engine after all:
There's also this:
There were even reports of demos like Jak 2 working!

Some things to keep in mind:
You need the disc manipulation software Apache Version 1.1 (newer versions reported not to work)
You need to swap the disc when the system is not reading anything, menus should work.
You can't mess with the Table Of Contents of the disc, more on this later.
You can't load an ELF that's larger than the ELF you want to replace, that'd mess with the TOS.
Games released after 2001 may have checks in place, this is not guaranteed to work.

Here's how it'd go:
Open Apache and load the backup you made.
Highlight the ELF you want replace.
While highlighted click "ISO TOOLS", then "Change TOC For Selected File"
Now DO NOT CHANGE THE LBA!!! Change The SIZE to the EXACT size in bytes as the ELF file you wish to inject (for example, uLE 4.21 is 877420)
Rename the ELF you want to inject to with the ELF you want to replace's name.
Highlight the ELF you want to replace, click "ISO TOOLS" and click "Update Selected File".
Close Apache and burn with either DVDDecryptor, IMGburn or any other software that's capable of raw write.
Swap the disc when the system is not loading anything and make the game load that ELF (for example, you enter a driving stage in 007 games or run the network configuration on netplay games)

Some games with multiple ELFs:
007: Agent Under Fire (duh)
007: Nightfire (second link)
007: From Russia with Love
Jak 2 demo was reported to work
Demo Disc 066 [NTSC-U] [SCUS-97241]
Metal Gear Solid 2: Substance (the one with the skate minigame)
Metal Gear Solid 3: Subsistence Disc 2 has a main.elf, depending on when it's loaded, it may be exploitable.
I think some Splinter Cell games have multiple ELFs too but not too sure.
Silica says any game that has netplay may also be exploitable since they have the network configuration ELF.

As there are some demos reported to work as well as multiple very common games, this means potential free entry points for lots of users.

If you're fast enough to swap the disc right before the system loads the ELF but right after the disc checks are complete, theoretically, any game is exploitable.

PS Vita / [Release] LolicopocalypseVita
« on: January 13, 2020, 01:38:04 AM »
A Vita Port of Lolicopocalypse, a game by quasist for Ludum Dare 24.

dots-tb did most of the work including finding the game, getting it to compile, controls and handling sound. I only did the image scaling and the live area.

Here's what the game looks like:

Join our Discord server if you're interested in our work.

PS Vita / Persona 4 Golden PS2 Opening Movie Mod
« on: December 21, 2019, 08:55:28 PM »
Can't believe no one made this mod before.
The PS2 opening movie exists in the game files under the name "P4CTOP1.MP4" and you can just decrypt that and use rePatch to direct to it when the game calls for the actual file. Of course, this will have the side effect of the P4G opening movie playing in the TV guide thingy. I've Googled it and found a /vg/ post about it though so I'm not the first person to come up with this.

Don't mind the no audio, I'm too lazy to record a new video.

If you don't have rePatch for some reason, install it.
Drop PCSE00120 for US release/PCSB00245 for EU release in your rePatch folder.

I haven't tested the EU release, I don't have this release but it'll %99 work since they didn't rename the files.
The JP counterpart is missing, since that release uses USM files instead of MP4 and I'm too lazy to download that release.
Oh, and no Mod Compendium install thingy since the movie file is not in the CPK.

Downloads mirror
MEGA mirror

« on: November 10, 2019, 02:23:32 AM »
What's this?
Being subjected to LOLIcon's glitchy and flickery menu, incompatibility crashes with Adrenaline and having to deal with profiles for over a year was getting pretty annoying, so I tried looking for a "just OC no bullshit" plugin. I couldn't find any. I can't believe no one made one before. How could people put up with it for a year? So here I present to you:
"LOLITA500", stands for "LOLIcon Offended Little Idiots - TOTAL ACCELERATION to 500".
Sets all clocks to max (including 500mhz for CPU) at all times and disables power limits like high brightness and Wi-Fi not working on intensive games!
No dealing with menus, profiles, settings, error messages anymore!
No over complicated hooks, just 5 hooks (4 to clocking, 1 to disable power limits). It's literally smaller than 3KB.
I dealt with it so you don't have to!
  • The clocks are maxed out system wide, so every application including: shell, system apps such as web browser, and of course games will have maxed clocks.
  • Not as complex as other actual overclock plugins like LOLIcon, so it works with Adrenaline.
  • It does not have a menu system, so no more messing around with menus to set a profile. Useful for PSTV users that want to use their systems at max clock at all times.
  • Power limits are disabled, this means brightness and W-Fi settings are no longer disabled on games that attempt to do so.
  • Each clock is hooked, so even if a game dynamically sets the clock, it will still stay maxed out.

Will this kill my Vita?
Overclocking should always be done with caution, however I did an hour long stress test live:

Put "lolita500.skprx" in 'tai' folder in 'ur0' or 'ux0' and add the following:
Code: [Select]

Where do I get it from?
Also join the Discord server if you're into these stuff: I-it's not like I want you in or anything, b-baka!
by teakhanirons, dots-tb, marburg, CelesteBlue, SilicaAndPina and CBPS allies.

PS Vita / [release] DerInClocKS - OSD clocks display
« on: November 08, 2019, 09:58:40 PM »
What is this?
Just a clocks OSD display for Vita. I don't think anyone made one (that uses the kernel functions at least, looking at you VitaIdent) so I made one.

Here you go mate:

Pages: [1]