Hacking PSA: Fake GoldHEN Payload

SapphireExile

Sapphire
OP
Member
Joined
May 2, 2018
Messages
118
Trophies
0
Age
28
Location
Bartow, FL
Website
sapphirelabs.online
XP
496
Country
United States
A fake GoldHen has been found in the wild to be bricking consoles. It usually goes by name "GoldHEN v2.0.1b" and is being hosted on several hosting sites.

Always read the code you run. If you can't, make sure you're only running payloads for trusted sources such as @Leeful and @Prb. Best case is to grab the payloads from the developers themselves when possible.

News covering this:
https://wololo.net/2021/10/03/psa-p...on-some-exploit-hosts-jailbreak-users-beware/

*Edit
If anyone finds one of these hosters, let me know and I'll add it to a list here for people to avoid, or someone can start a new thread with a list of bad hosts.
 
Last edited by SapphireExile,

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,471
Trophies
3
XP
29,180
Country
United States
I can't seem to dump my sflash0. it either fails after so much time or I only get around a 512KB file when it's supposed to be 32MBs. this is on 5.05. it shows all files in dev as being 0KBs in every one of the three ways I've tried dumping it. @KiiWii @Leeful ? file xplorer also kernel paniced immediately after trying to dump the sflash0. the other two ways orbis ftp and the normal goldhen ftp didn't do that.
 

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,471
Trophies
3
XP
29,180
Country
United States
are you able to dump it? I'm using xproject and goldhen 1.1, also tried vortex ftp, and I tried file xplorer. none worked.
 

Leeful

GBAtemp Member
Developer
Joined
Sep 4, 2015
Messages
1,903
Trophies
1
XP
7,068
Country
United Kingdom
I can't seem to dump my sflash0. it either fails after so much time or I only get around a 512KB file when it's supposed to be 32MBs. this is on 5.05. it shows all files in dev as being 0KBs in every one of the three ways I've tried dumping it. @KiiWii @Leeful ? file xplorer also kernel paniced immediately after trying to dump the sflash0. the other two ways orbis ftp and the normal goldhen ftp didn't do that.
Just dumped my 505 sflash0 twice without any problems. Once using GoldHEN 1.1's FTP and as a second test using X-Project 1.5.8, Hen2.1.3 and xVortexFTP.
both dumped the full 32MB. (size showed 0 inFTP)
Not sure why you are having problems, Might be a setting in your FTP client, might be if you are using the Sandisk Connect, but I dont think that will be it if FTP usually works with it.
 

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,471
Trophies
3
XP
29,180
Country
United States
Just dumped my 505 sflash0 twice without any problems. Once using GoldHEN 1.1's FTP and as a second test using X-Project 1.5.8, Hen2.1.3 and xVortexFTP.
both dumped the full 32MB. (size showed 0 inFTP)
Not sure why you are having problems, Might be a setting in your FTP client, might be if you are using the Sandisk Connect, but I dont think that will be it if FTP usually works with it.
yep, must've been the sandisk connect. I signed online to get it. it was very quick this time. the system tried to download system software 9.00 and an update to cyberpunk (think it was 1.31), both failed, possibly due to having update blocker. I just put in the dns to block updates (do these ever change?), and I'll stay online for the time being maybe or maybe not:

1633284936816.png
 
  • Like
Reactions: Leeful

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,471
Trophies
3
XP
29,180
Country
United States
I'm not entirely sure. I think it contains the main ps4 keys for your system. I think the eap key is part of it. that's the hdd key to decrypt and encrypt it. the only way I know of to put it back is a hard mod, but transferring it via ftp makes it easier, I guess.
 

TurboLolo

Active Member
Newcomer
Joined
Mar 24, 2021
Messages
35
Trophies
0
Age
38
XP
385
Country
Poland
I'm not entirely sure. I think it contains the main ps4 keys for your system. I think the eap key is part of it. that's the hdd key to decrypt and encrypt it. the only way I know of to put it back is a hard mod, but transferring it via ftp makes it easier, I guess.
Hmmm... interesting. I thought that kind of data is stored on some kaind of flash memory not just FTP accessed file.
 

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,471
Trophies
3
XP
29,180
Country
United States
I'm not sure what all ftp has access to, but there are 14 or 15 partitions with the hdd. I think each partition listed on the root is either the hdd or flash memory. I've not counted them though, and I just assume that.
 

TurboLolo

Active Member
Newcomer
Joined
Mar 24, 2021
Messages
35
Trophies
0
Age
38
XP
385
Country
Poland
I remember when connecting my 1TB PS4 (update to 4TB) HDD to PC and sow 15 partitions, that was crazy.
 

godreborn

Welcome to the Machine
Member
Joined
Oct 10, 2009
Messages
38,471
Trophies
3
XP
29,180
Country
United States
yeah, when I formatted my ps4 hdd in disk management to get rid of my banned account, it was kinda a pita. I had to delete each partition one-at-a-time. one partition was much larger than the others. it was probably the user one.
 

TurboLolo

Active Member
Newcomer
Joined
Mar 24, 2021
Messages
35
Trophies
0
Age
38
XP
385
Country
Poland
yeah, when I formatted my ps4 hdd in disk management to get rid of my banned account, it was kinda a pita. I had to delete each partition one-at-a-time. one partition was much larger than the others. it was probably the user one.
Yep, the large one is the user one.
 
  • Like
Reactions: godreborn

Site & Scene News

Popular threads in this forum

General chit-chat
Help Users
  • BigOnYa @ BigOnYa:
    I thought I saw a puttie snatch...
  • BigOnYa @ BigOnYa:
    I'm so pumped, NCAA football video game is back after a 10 year hiatus, coming to SeriesS/X, PS5 in July.
  • BigOnYa @ BigOnYa:
    Wish they would let us play the NCAA football 14 on newer xbox, its one of the only games I love and own on disc still, that is not back compatible, bs.
  • AdenTheThird @ AdenTheThird:
    @BigOnYa My dad recently bought a spare Series X off of me, got game pass, and saw Madden '24 on Game Pass, decided to try it out.

    ...He was a bit taken aback by the 60GB download size. Poor guy's still living in the 90s!
    +1
  • SylverReZ @ SylverReZ:
    @AdenTheThird, Bro's still in the PS2 age.
  • K3Nv2 @ K3Nv2:
    Lol charging your dad's classic unless he's the type that doesn't like taking things like that
  • AdenTheThird @ AdenTheThird:
    @K3Nv2 He was looking into consoles for his house anyway (for my younger siblings and himself) and I had a spare XSX and Switch I ended up selling him at pretty steep cuts. I would just give them to him, but I did buy them with the intent to sell them... and college is super expensive.
  • BigOnYa @ BigOnYa:
    A little yeah...
  • Xdqwerty @ Xdqwerty:
    @BigOnYa, [insert wut here]
    +1
  • BigOnYa @ BigOnYa:
    I'm a little hi, but bout to fix that.
    +1
  • BigOnYa @ BigOnYa:
    Now I'm low, i was upstairs in my wifeys kitchen, now I'm downstairs in my dungeon.(My basement)
    +1
  • BakerMan @ BakerMan:
    do you mind? i snuck in with amiibo and jars, and am trying to do my thing brony style
  • BakerMan @ BakerMan:
    have you ever regretted saying something immediately after saying it?
    +1
  • BakerMan @ BakerMan:
    nah what i was doing was trying to cure my ever-so-apparent crabs
  • Xdqwerty @ Xdqwerty:
    @SylverReZ,
    my younger brother is forcing me to play with him and my cousins are here *sigh*
    +1
  • BigOnYa @ BigOnYa:
    @SylverReZ that Hack a hacked 360 vid was neat, never knew it existed.
    +1
  • SylverReZ @ SylverReZ:
    @BigOnYa, I thought it was interesting.
    +1
  • Xdqwerty @ Xdqwerty:
    nvm this video is clickbait
    Xdqwerty @ Xdqwerty: nvm this video is clickbait