LBP ONLINE MULTIPLAYER UNSAFE?! - All You NEED to Know About Current RCE Exploit in LittleBigPlanet!

Поділитися
Вставка
  • Опубліковано 12 січ 2025

КОМЕНТАРІ • 46

  • @ViviNoSmol
    @ViviNoSmol 2 дні тому +27

    so basically, this is why Sony closed all the LBP servers, they probably knew this and didn't wanted or couldn't fix it at all

    • @LiEnby
      @LiEnby 19 годин тому

      Iirc what I heard was Someone had come on found their bio and worlds changed to racial slurs, complained about it to Sony, so that kinda makes sense

    • @Spikel3t
      @Spikel3t 14 годин тому

      Reason they shut it down was in part to server hacks but also no point of an old game alive if it isn't generating them that money, though I doubt it was due to server costs, pretty much anyone can host a server now and the limit is your electricity bill and storage

  • @Yukki64_
    @Yukki64_ День тому +8

    Let's hope we can find a definitive solution in the near future...

  • @greenbean299
    @greenbean299 День тому +6

    Why would someone do this? Just let the community enjoy online play without worrying about getting hacked.

  • @GolfinhoVoador
    @GolfinhoVoador 9 годин тому +2

    8:31 I was going to suggest the same thing, but wouldn't this require a CDN to avoid extremely high pings for people far away from the main server? (something which is not very cheap to set up)

    • @kubacakagoomba
      @kubacakagoomba  8 годин тому

      CDNs would be good, but that's more of a long term solution.

  • @boy-who-likes-bats
    @boy-who-likes-bats 14 годин тому

    i think i actually remember this being a thing before lbp servers were originally shut down

  • @toysplayonthexbox
    @toysplayonthexbox День тому +3

    11:16 On Beacon, matchmaking is disabled, so wouldn't Play Online be a little safer on it? (unless I get corrected)

    • @kubacakagoomba
      @kubacakagoomba  День тому

      @toysplayonthexbox No, as it only applies to people connected to Beacon. If the malicious user is using any other custom server which has Dive-in enabled, they can still join you.

    • @toysplayonthexbox
      @toysplayonthexbox День тому

      @@kubacakagoomba I didn't day the chances were none

  • @thatonelazysack
    @thatonelazysack 2 дні тому +3

    I've been waiting for the dive in to be reopenned but now im glad i haven't been able to dive in

  • @Htycto4u7gcvkuy
    @Htycto4u7gcvkuy 10 годин тому +1

    What are the names of the levels that played in the background of this video?

    • @kubacakagoomba
      @kubacakagoomba  6 годин тому

      Check out this blog post from LBP Union about the levels that we picked and played for the Advent Calendar on Beacon :)
      www.lbpunion.com/post/beacon-advent-calendar-happy-holidays-from-lbp-union/

  • @PorkchopGMX
    @PorkchopGMX 2 дні тому +3

    finally, another addition to my cameos playlist

    • @Spikel3t
      @Spikel3t 2 дні тому +2

      The pork is chopping

  • @toasterthebrot
    @toasterthebrot 15 годин тому +1

    Congrats, this is a surprisingly informative and no-nonsense video, seemingly also well researched, which appears to be uncommon in lbp videos today. At first i was a little worried this would be yet another video on this topic with too much fearmongering or just simply a lack of understanding by the creator leading to them talking nonsense (or both), but youve proven me wrong. Well done! One thing you got slightly wrong tho is the danger with dive-in. Only lbp1 allows people from other custom servers to join you via dive in, on lbp2 and the other games tho matchmaking through dive in is done by the custom server itself (where it offers the game rooms to join, with hopefully the most promising looking one first), which is beneficial for us. But most other methods of joining and playing with others are still done solely by psn/rpcn and/or the game itself.

    • @Spikel3t
      @Spikel3t 14 годин тому +2

      Of course its an informative and not fear mongering video, its Goomba :3 (also some of us fact checked this early to try and reduce any mistakes before release)

    • @LittleZoey
      @LittleZoey 12 годин тому

      ​@Spikel3tit's a bot

    • @toasterthebrot
      @toasterthebrot 11 годин тому

      @@LittleZoey proof?

    • @kubacakagoomba
      @kubacakagoomba  5 годин тому

      @@toasterthebrot They're wrong 😂 Usually AI replies are very easy to spot but it is also very easy to spot when a real human wrote a comment.

    • @PorkchopGMX
      @PorkchopGMX 5 годин тому

      @@kubacakagoombaI know this person from beacon private beta lmao

  • @vacuumstories
    @vacuumstories День тому +3

    Further proof that this game is dead in the water. I respect the community for keeping it on life support. There are some strange people in those LBP discords anyway, so I rather play the game locally. And many of the wonderful OG community levels are forever gone. Surely, its better than nothing. But I just really hope we get a 4th installment of the series. Hackers and attackers are lame and ruin the fun for everyone. Same reason Sony didn't bother fixing this game. Hardly worth it these days.

    • @kubacakagoomba
      @kubacakagoomba  День тому +2

      @@vacuumstories I wouldn't say it's dead. Sure the exploit is severe, however compared to how many security holes the official servers had, custom servers like Beacon or Refresh have much better security than official servers ever had.
      And trust me, the devs are determined to fix that exploit, no matter what it takes. Unfortunately it's a very daunting task as it will most likely require more extensive reverse engineering of the game. This is where the original devs of the game would have an upper hand as they would have access to the source code of the game.
      Here's hoping that the exploit gets patched though 👍

    • @Spikel3t
      @Spikel3t День тому

      Also most levels before February 2023 were archived on the internet archive in a leak, made navigateable through zaprit fish and lbp find so you can find and download the file and convertable through the craftworld toolkit so you can import to moon and play again, this method works offline too so its a matter of just using a tutorial video or asking for assistance, refresh also has playhash which is like that but automatic so you can just input the hash on their website and play the level in game! Cannot keep to moon through this method through. Not all hope is lost

  • @LiEnby
    @LiEnby 19 годин тому +1

    Wait how does this let you take control over your real PC ..? Also isn’t the ps3 kinda sandboxed I doubt they can do the vulnerability you said suggests they can access your pod menu which is still limited to what the game lets you do, am I missing something!?
    In that case is the answer not mostly just to keep backups of your save ??

    • @timmyaucoin
      @timmyaucoin 16 годин тому

      I'm the surface yes, but when they join u they can see your IP and other sensitive info

    • @timmyaucoin
      @timmyaucoin 16 годин тому

      In*

    • @Htycto4u7gcvkuy
      @Htycto4u7gcvkuy 10 годин тому +1

      Using bugs in RCPS3 like buffer overflow. If RCPS3 has a bug like that, then super elite hacker can make your computer execute any program they wish it to in a scenario where they gain privilege escalation.

    • @kubacakagoomba
      @kubacakagoomba  6 годин тому +1

      As@@Htycto4u7gcvkuy says. It's easy to misjudge what the true capabilities of the scripting system vulnerability actually are. I do agree that the exploit isn't as dangerous as it seems, especially since it is also very easy to avoid the exploit altogether.
      Better be safe than sorry though.

    • @kubacakagoomba
      @kubacakagoomba  5 годин тому

      @@timmyaucoin That's the downside of peer-to-peer sessions in general. Not really the scope of the video but I do touch upon that a bit.

  • @boy-who-likes-bats
    @boy-who-likes-bats 14 годин тому +1

    wait lbp has online still???

    • @kubacakagoomba
      @kubacakagoomba  13 годин тому +2

      Official servers are fully shutdown, but you can play on a custom servers on PS3, Vita or RPCS3 which is a PS3 emulator on PC.

    • @boy-who-likes-bats
      @boy-who-likes-bats 13 годин тому

      @kubacakagoomba regarding rpcs3 safety, there's no xmb or ps signin, so is there still any real risk from an rce attack?

    • @atomicskies_
      @atomicskies_ 13 годин тому

      @@kubacakagoombaHow?

    • @pupi_zz
      @pupi_zz 12 годин тому

      @@atomicskies_ you have to jailbreak ur ps3 or use a ps3 emulator he has a tutorial on his channel

    • @kubacakagoomba
      @kubacakagoomba  6 годин тому

      @@atomicskies_ I've got tutorials on my channels if you're interested :)

  • @Spikel3t
    @Spikel3t 2 дні тому +5

    Hai Goomba!

  • @atomicskies_
    @atomicskies_ 13 годин тому +1

    I thought this game shut down?

    • @kubacakagoomba
      @kubacakagoomba  12 годин тому

      @@atomicskies_ The official servers were shut down. The custom servers for PS3, Vita and RPCS3 are still working 👍

  • @ac1dirty362
    @ac1dirty362 17 годин тому

    Why play it then.

    • @kubacakagoomba
      @kubacakagoomba  6 годин тому

      Same reason as if I asked 'Why not?'
      Seriously. For 16 year old game series the size of the community is still surprisingly strong. And the existence of custom servers with the developers that are eager to develop them to become more and more secure prove that.

  • @rognefis
    @rognefis 16 годин тому

    Refresh is the BEST server
    Beacon = poop