First psp "signed" homebrew..
Source:Well ok, here it comes.
tested on fat PSP with OFW 6.35
Simple, notice it contains ~PSP header from demo game (UCES00206), it is exactly same header.
It is easy to craft last 16 bytes of encrypted data block to match header CMAC - yes, that's the trick
There are some strange things, it can't run homebrews with bigger executable block (data block does not matter), and because of ~PSP header, it has to match exact size of original game.
This trick might be possible on firmware kernel modules to get permanent HEN on non-pandrorable PSPs, i was not able to do it but i was not trying that much.
PS: i am not only one who found this trick
wololo.net/talk • View topic - PS3 packages and how it leads to PSP signing