LBP ONLINE MULTIPLAYER UNSAFE?! - All You NEED to Know About Current RCE Exploit in LittleBigPlanet!

แชร์
ฝัง
  • เผยแพร่เมื่อ 12 ม.ค. 2025

ความคิดเห็น • 47

  • @ViviNoSmol
    @ViviNoSmol 2 วันที่ผ่านมา +30

    so basically, this is why Sony closed all the LBP servers, they probably knew this and didn't wanted or couldn't fix it at all

    • @LiEnby
      @LiEnby 21 ชั่วโมงที่ผ่านมา

      Iirc what I heard was Someone had come on found their bio and worlds changed to racial slurs, complained about it to Sony, so that kinda makes sense

    • @Spikel3t
      @Spikel3t 16 ชั่วโมงที่ผ่านมา

      Reason they shut it down was in part to server hacks but also no point of an old game alive if it isn't generating them that money, though I doubt it was due to server costs, pretty much anyone can host a server now and the limit is your electricity bill and storage

  • @Yukki64_
    @Yukki64_ วันที่ผ่านมา +8

    Let's hope we can find a definitive solution in the near future...

  • @greenbean299
    @greenbean299 วันที่ผ่านมา +6

    Why would someone do this? Just let the community enjoy online play without worrying about getting hacked.

  • @GolfinhoVoador
    @GolfinhoVoador 11 ชั่วโมงที่ผ่านมา +2

    8:31 I was going to suggest the same thing, but wouldn't this require a CDN to avoid extremely high pings for people far away from the main server? (something which is not very cheap to set up)

    • @kubacakagoomba
      @kubacakagoomba  11 ชั่วโมงที่ผ่านมา

      CDNs would be good, but that's more of a long term solution.

  • @pir_hana
    @pir_hana 23 นาทีที่ผ่านมา

    There will likely never be any chance we will ever be able to play this game online ever again, at least for the foreseeable future unless someone has the knowledge of how the game works

  • @toysplayonthexbox
    @toysplayonthexbox วันที่ผ่านมา +3

    11:16 On Beacon, matchmaking is disabled, so wouldn't Play Online be a little safer on it? (unless I get corrected)

    • @kubacakagoomba
      @kubacakagoomba  วันที่ผ่านมา

      @toysplayonthexbox No, as it only applies to people connected to Beacon. If the malicious user is using any other custom server which has Dive-in enabled, they can still join you.

    • @toysplayonthexbox
      @toysplayonthexbox วันที่ผ่านมา

      @@kubacakagoomba I didn't day the chances were none

  • @boy-who-likes-bats
    @boy-who-likes-bats 16 ชั่วโมงที่ผ่านมา

    i think i actually remember this being a thing before lbp servers were originally shut down

  • @thatonelazysack
    @thatonelazysack 2 วันที่ผ่านมา +3

    I've been waiting for the dive in to be reopenned but now im glad i haven't been able to dive in

  • @vacuumstories
    @vacuumstories 2 วันที่ผ่านมา +4

    Further proof that this game is dead in the water. I respect the community for keeping it on life support. There are some strange people in those LBP discords anyway, so I rather play the game locally. And many of the wonderful OG community levels are forever gone. Surely, its better than nothing. But I just really hope we get a 4th installment of the series. Hackers and attackers are lame and ruin the fun for everyone. Same reason Sony didn't bother fixing this game. Hardly worth it these days.

    • @kubacakagoomba
      @kubacakagoomba  2 วันที่ผ่านมา +2

      @@vacuumstories I wouldn't say it's dead. Sure the exploit is severe, however compared to how many security holes the official servers had, custom servers like Beacon or Refresh have much better security than official servers ever had.
      And trust me, the devs are determined to fix that exploit, no matter what it takes. Unfortunately it's a very daunting task as it will most likely require more extensive reverse engineering of the game. This is where the original devs of the game would have an upper hand as they would have access to the source code of the game.
      Here's hoping that the exploit gets patched though 👍

    • @Spikel3t
      @Spikel3t วันที่ผ่านมา

      Also most levels before February 2023 were archived on the internet archive in a leak, made navigateable through zaprit fish and lbp find so you can find and download the file and convertable through the craftworld toolkit so you can import to moon and play again, this method works offline too so its a matter of just using a tutorial video or asking for assistance, refresh also has playhash which is like that but automatic so you can just input the hash on their website and play the level in game! Cannot keep to moon through this method through. Not all hope is lost

  • @Htycto4u7gcvkuy
    @Htycto4u7gcvkuy 12 ชั่วโมงที่ผ่านมา +1

    What are the names of the levels that played in the background of this video?

    • @kubacakagoomba
      @kubacakagoomba  8 ชั่วโมงที่ผ่านมา

      Check out this blog post from LBP Union about the levels that we picked and played for the Advent Calendar on Beacon :)
      www.lbpunion.com/post/beacon-advent-calendar-happy-holidays-from-lbp-union/

  • @PorkchopGMX
    @PorkchopGMX 2 วันที่ผ่านมา +3

    finally, another addition to my cameos playlist

    • @Spikel3t
      @Spikel3t 2 วันที่ผ่านมา +2

      The pork is chopping

  • @toasterthebrot
    @toasterthebrot 17 ชั่วโมงที่ผ่านมา +1

    Congrats, this is a surprisingly informative and no-nonsense video, seemingly also well researched, which appears to be uncommon in lbp videos today. At first i was a little worried this would be yet another video on this topic with too much fearmongering or just simply a lack of understanding by the creator leading to them talking nonsense (or both), but youve proven me wrong. Well done! One thing you got slightly wrong tho is the danger with dive-in. Only lbp1 allows people from other custom servers to join you via dive in, on lbp2 and the other games tho matchmaking through dive in is done by the custom server itself (where it offers the game rooms to join, with hopefully the most promising looking one first), which is beneficial for us. But most other methods of joining and playing with others are still done solely by psn/rpcn and/or the game itself.

    • @Spikel3t
      @Spikel3t 16 ชั่วโมงที่ผ่านมา +2

      Of course its an informative and not fear mongering video, its Goomba :3 (also some of us fact checked this early to try and reduce any mistakes before release)

    • @LittleZoey
      @LittleZoey 15 ชั่วโมงที่ผ่านมา

      ​@Spikel3tit's a bot

    • @toasterthebrot
      @toasterthebrot 13 ชั่วโมงที่ผ่านมา

      @@LittleZoey proof?

    • @kubacakagoomba
      @kubacakagoomba  8 ชั่วโมงที่ผ่านมา

      @@toasterthebrot They're wrong 😂 Usually AI replies are very easy to spot but it is also very easy to spot when a real human wrote a comment.

    • @PorkchopGMX
      @PorkchopGMX 7 ชั่วโมงที่ผ่านมา

      @@kubacakagoombaI know this person from beacon private beta lmao

  • @LiEnby
    @LiEnby 21 ชั่วโมงที่ผ่านมา +1

    Wait how does this let you take control over your real PC ..? Also isn’t the ps3 kinda sandboxed I doubt they can do the vulnerability you said suggests they can access your pod menu which is still limited to what the game lets you do, am I missing something!?
    In that case is the answer not mostly just to keep backups of your save ??

    • @timmyaucoin
      @timmyaucoin 18 ชั่วโมงที่ผ่านมา

      I'm the surface yes, but when they join u they can see your IP and other sensitive info

    • @timmyaucoin
      @timmyaucoin 18 ชั่วโมงที่ผ่านมา

      In*

    • @Htycto4u7gcvkuy
      @Htycto4u7gcvkuy 12 ชั่วโมงที่ผ่านมา +1

      Using bugs in RCPS3 like buffer overflow. If RCPS3 has a bug like that, then super elite hacker can make your computer execute any program they wish it to in a scenario where they gain privilege escalation.

    • @kubacakagoomba
      @kubacakagoomba  8 ชั่วโมงที่ผ่านมา +1

      As@@Htycto4u7gcvkuy says. It's easy to misjudge what the true capabilities of the scripting system vulnerability actually are. I do agree that the exploit isn't as dangerous as it seems, especially since it is also very easy to avoid the exploit altogether.
      Better be safe than sorry though.

    • @kubacakagoomba
      @kubacakagoomba  8 ชั่วโมงที่ผ่านมา

      @@timmyaucoin That's the downside of peer-to-peer sessions in general. Not really the scope of the video but I do touch upon that a bit.

  • @boy-who-likes-bats
    @boy-who-likes-bats 16 ชั่วโมงที่ผ่านมา +1

    wait lbp has online still???

    • @kubacakagoomba
      @kubacakagoomba  15 ชั่วโมงที่ผ่านมา +2

      Official servers are fully shutdown, but you can play on a custom servers on PS3, Vita or RPCS3 which is a PS3 emulator on PC.

    • @boy-who-likes-bats
      @boy-who-likes-bats 15 ชั่วโมงที่ผ่านมา

      @kubacakagoomba regarding rpcs3 safety, there's no xmb or ps signin, so is there still any real risk from an rce attack?

    • @atomicskies_
      @atomicskies_ 15 ชั่วโมงที่ผ่านมา

      @@kubacakagoombaHow?

    • @pupi_zz
      @pupi_zz 15 ชั่วโมงที่ผ่านมา

      @@atomicskies_ you have to jailbreak ur ps3 or use a ps3 emulator he has a tutorial on his channel

    • @kubacakagoomba
      @kubacakagoomba  8 ชั่วโมงที่ผ่านมา

      @@atomicskies_ I've got tutorials on my channels if you're interested :)

  • @Spikel3t
    @Spikel3t 2 วันที่ผ่านมา +5

    Hai Goomba!

  • @atomicskies_
    @atomicskies_ 15 ชั่วโมงที่ผ่านมา +1

    I thought this game shut down?

    • @kubacakagoomba
      @kubacakagoomba  14 ชั่วโมงที่ผ่านมา

      @@atomicskies_ The official servers were shut down. The custom servers for PS3, Vita and RPCS3 are still working 👍

  • @ac1dirty362
    @ac1dirty362 19 ชั่วโมงที่ผ่านมา

    Why play it then.

    • @kubacakagoomba
      @kubacakagoomba  8 ชั่วโมงที่ผ่านมา

      Same reason as if I asked 'Why not?'
      Seriously. For 16 year old game series the size of the community is still surprisingly strong. And the existence of custom servers with the developers that are eager to develop them to become more and more secure prove that.

  • @rognefis
    @rognefis 19 ชั่วโมงที่ผ่านมา

    Refresh is the BEST server
    Beacon = poop

    • @salamnishellhole2160
      @salamnishellhole2160 18 ชั่วโมงที่ผ่านมา +1

      refresh happened because of beacon :3

    • @Spikel3t
      @Spikel3t 16 ชั่วโมงที่ผ่านมา

      In my opinion, both are good