LBP ONLINE MULTIPLAYER UNSAFE?! - All You NEED to Know About Current RCE Exploit in LittleBigPlanet!

Поделиться
HTML-код
  • Опубликовано: 26 янв 2025

Комментарии •

  • @ViviNoSmol
    @ViviNoSmol 16 дней назад +36

    so basically, this is why Sony closed all the LBP servers, they probably knew this and didn't wanted or couldn't fix it at all

    • @LiEnby
      @LiEnby 15 дней назад

      Iirc what I heard was Someone had come on found their bio and worlds changed to racial slurs, complained about it to Sony, so that kinda makes sense

    • @Spikel3t
      @Spikel3t 15 дней назад

      Reason they shut it down was in part to server hacks but also no point of an old game alive if it isn't generating them that money, though I doubt it was due to server costs, pretty much anyone can host a server now and the limit is your electricity bill and storage

  • @Yukki64_
    @Yukki64_ 16 дней назад +8

    Let's hope we can find a definitive solution in the near future...

  • @dandrerivera6261
    @dandrerivera6261 12 дней назад +4

    Man I just got started on joining the LBP custom server community

  • @greenbean299
    @greenbean299 15 дней назад +10

    Why would someone do this? Just let the community enjoy online play without worrying about getting hacked.

    • @jokingracer0895
      @jokingracer0895 5 дней назад

      fr people really have nothing better to do apparently

  • @thatonelazysack
    @thatonelazysack 16 дней назад +4

    I've been waiting for the dive in to be reopenned but now im glad i haven't been able to dive in

  • @toysplayonthexbox
    @toysplayonthexbox 16 дней назад +3

    11:16 On Beacon, matchmaking is disabled, so wouldn't Play Online be a little safer on it? (unless I get corrected)

    • @kubacakagoomba
      @kubacakagoomba  16 дней назад

      @toysplayonthexbox No, as it only applies to people connected to Beacon. If the malicious user is using any other custom server which has Dive-in enabled, they can still join you.

    • @toysplayonthexbox
      @toysplayonthexbox 16 дней назад

      @@kubacakagoomba I didn't day the chances were none

    • @TorutheRedFox
      @TorutheRedFox 2 дня назад

      LBP1 does matchmaking through PSN so there's nothing that the server can do to stop people from joining other random players, even across servers

  • @GolfinhoVoador
    @GolfinhoVoador 15 дней назад +2

    8:31 I was going to suggest the same thing, but wouldn't this require a CDN to avoid extremely high pings for people far away from the main server? (something which is not very cheap to set up)

    • @kubacakagoomba
      @kubacakagoomba  15 дней назад

      CDNs would be good, but that's more of a long term solution.

  • @boy-who-likes-bats
    @boy-who-likes-bats 15 дней назад

    i think i actually remember this being a thing before lbp servers were originally shut down

  • @vacuumstories
    @vacuumstories 16 дней назад +6

    Further proof that this game is dead in the water. I respect the community for keeping it on life support. There are some strange people in those LBP discords anyway, so I rather play the game locally. And many of the wonderful OG community levels are forever gone. Surely, its better than nothing. But I just really hope we get a 4th installment of the series. Hackers and attackers are lame and ruin the fun for everyone. Same reason Sony didn't bother fixing this game. Hardly worth it these days.

    • @kubacakagoomba
      @kubacakagoomba  16 дней назад +3

      @@vacuumstories I wouldn't say it's dead. Sure the exploit is severe, however compared to how many security holes the official servers had, custom servers like Beacon or Refresh have much better security than official servers ever had.
      And trust me, the devs are determined to fix that exploit, no matter what it takes. Unfortunately it's a very daunting task as it will most likely require more extensive reverse engineering of the game. This is where the original devs of the game would have an upper hand as they would have access to the source code of the game.
      Here's hoping that the exploit gets patched though 👍

    • @Spikel3t
      @Spikel3t 16 дней назад

      Also most levels before February 2023 were archived on the internet archive in a leak, made navigateable through zaprit fish and lbp find so you can find and download the file and convertable through the craftworld toolkit so you can import to moon and play again, this method works offline too so its a matter of just using a tutorial video or asking for assistance, refresh also has playhash which is like that but automatic so you can just input the hash on their website and play the level in game! Cannot keep to moon through this method through. Not all hope is lost

  • @pir_hana
    @pir_hana 14 дней назад

    There will likely never be any chance we will ever be able to play this game online ever again, at least for the foreseeable future unless someone has the knowledge of how the game works

    • @Spikel3t
      @Spikel3t 14 дней назад

      The custom servers in question:

    • @pir_hana
      @pir_hana 14 дней назад

      There will likely never be any chance we will ever be able to play this game online SAFELY without the risk of our PCs being compromised ever again

    • @Spikel3t
      @Spikel3t 14 дней назад

      @@pir_hana True, we have experts in Union and refresh but they have their own lives and stuff to get on with, they can only dedicate so much at a time and they have no obligation, its a miracle we have some of the tools we do have but in the end, its going to take a heck of a lot of work to get around this

  • @Htycto4u7gcvkuy
    @Htycto4u7gcvkuy 15 дней назад +1

    What are the names of the levels that played in the background of this video?

    • @kubacakagoomba
      @kubacakagoomba  14 дней назад +1

      Check out this blog post from LBP Union about the levels that we picked and played for the Advent Calendar on Beacon :)
      www.lbpunion.com/post/beacon-advent-calendar-happy-holidays-from-lbp-union/

  • @PorkchopGMX
    @PorkchopGMX 16 дней назад +3

    finally, another addition to my cameos playlist

    • @Spikel3t
      @Spikel3t 16 дней назад +2

      The pork is chopping

  • @toasterthebrot
    @toasterthebrot 15 дней назад +1

    Congrats, this is a surprisingly informative and no-nonsense video, seemingly also well researched, which appears to be uncommon in lbp videos today. At first i was a little worried this would be yet another video on this topic with too much fearmongering or just simply a lack of understanding by the creator leading to them talking nonsense (or both), but youve proven me wrong. Well done! One thing you got slightly wrong tho is the danger with dive-in. Only lbp1 allows people from other custom servers to join you via dive in, on lbp2 and the other games tho matchmaking through dive in is done by the custom server itself (where it offers the game rooms to join, with hopefully the most promising looking one first), which is beneficial for us. But most other methods of joining and playing with others are still done solely by psn/rpcn and/or the game itself.

    • @Spikel3t
      @Spikel3t 15 дней назад +2

      Of course its an informative and not fear mongering video, its Goomba :3 (also some of us fact checked this early to try and reduce any mistakes before release)

    • @LittleZoey
      @LittleZoey 15 дней назад

      ​@Spikel3tit's a bot

    • @toasterthebrot
      @toasterthebrot 15 дней назад

      @@LittleZoey proof?

    • @kubacakagoomba
      @kubacakagoomba  14 дней назад

      @@toasterthebrot They're wrong 😂 Usually AI replies are very easy to spot but it is also very easy to spot when a real human wrote a comment.

    • @PorkchopGMX
      @PorkchopGMX 14 дней назад +1

      @@kubacakagoombaI know this person from beacon private beta lmao

  • @LiEnby
    @LiEnby 15 дней назад +1

    Wait how does this let you take control over your real PC ..? Also isn’t the ps3 kinda sandboxed I doubt they can do the vulnerability you said suggests they can access your pod menu which is still limited to what the game lets you do, am I missing something!?
    In that case is the answer not mostly just to keep backups of your save ??

    • @timmyaucoin
      @timmyaucoin 15 дней назад

      I'm the surface yes, but when they join u they can see your IP and other sensitive info

    • @timmyaucoin
      @timmyaucoin 15 дней назад

      In*

    • @Htycto4u7gcvkuy
      @Htycto4u7gcvkuy 15 дней назад +1

      Using bugs in RCPS3 like buffer overflow. If RCPS3 has a bug like that, then super elite hacker can make your computer execute any program they wish it to in a scenario where they gain privilege escalation.

    • @kubacakagoomba
      @kubacakagoomba  14 дней назад +1

      As@@Htycto4u7gcvkuy says. It's easy to misjudge what the true capabilities of the scripting system vulnerability actually are. I do agree that the exploit isn't as dangerous as it seems, especially since it is also very easy to avoid the exploit altogether.
      Better be safe than sorry though.

    • @kubacakagoomba
      @kubacakagoomba  14 дней назад

      @@timmyaucoin That's the downside of peer-to-peer sessions in general. Not really the scope of the video but I do touch upon that a bit.

  • @boy-who-likes-bats
    @boy-who-likes-bats 15 дней назад +1

    wait lbp has online still???

    • @kubacakagoomba
      @kubacakagoomba  15 дней назад +2

      Official servers are fully shutdown, but you can play on a custom servers on PS3, Vita or RPCS3 which is a PS3 emulator on PC.

    • @boy-who-likes-bats
      @boy-who-likes-bats 15 дней назад

      @kubacakagoomba regarding rpcs3 safety, there's no xmb or ps signin, so is there still any real risk from an rce attack?

    • @atomicskies_
      @atomicskies_ 15 дней назад

      @@kubacakagoombaHow?

    • @pupi_zz
      @pupi_zz 15 дней назад

      @@atomicskies_ you have to jailbreak ur ps3 or use a ps3 emulator he has a tutorial on his channel

    • @kubacakagoomba
      @kubacakagoomba  14 дней назад

      @@atomicskies_ I've got tutorials on my channels if you're interested :)

  • @Spikel3t
    @Spikel3t 16 дней назад +5

    Hai Goomba!

  • @atomicskies_
    @atomicskies_ 15 дней назад +1

    I thought this game shut down?

    • @kubacakagoomba
      @kubacakagoomba  15 дней назад

      @@atomicskies_ The official servers were shut down. The custom servers for PS3, Vita and RPCS3 are still working 👍

  • @ac1dirty362
    @ac1dirty362 15 дней назад

    Why play it then.

    • @kubacakagoomba
      @kubacakagoomba  14 дней назад

      Same reason as if I asked 'Why not?'
      Seriously. For 16 year old game series the size of the community is still surprisingly strong. And the existence of custom servers with the developers that are eager to develop them to become more and more secure prove that.

  • @rognefis
    @rognefis 15 дней назад

    Refresh is the BEST server
    Beacon = poop

    • @salamnishellhole2160
      @salamnishellhole2160 15 дней назад +1

      refresh happened because of beacon :3

    • @Spikel3t
      @Spikel3t 15 дней назад

      In my opinion, both are good

    • @Deadmare
      @Deadmare 7 дней назад +1

      I switch between both regular some levels only exist on one or the other