‹ BackHN Continuity

Thread

Hijacking the PS5's RTMP stream

295 points · 92 comments · ibobev

  1. londons_explore · · focus · HN ↗
    Kinda sad that it's 2026 and this data still goes over the internet unencrypted...

    RTMP and all the video and audio protocols behind it aren't trivial either - I bet there are hundreds of exploits waiting to be found that any three letter agency sitting on the internet can use to take over your PS5 and all credentials stored within too...

    1. rezonant · · focus · HN ↗
      Well, the server just responds with acknowledgement information, the client is doing most of the work and most of the complex parts of RTMP are hand waved and faked by both the client and the server because no one cares about how Flash used to work.

      So somewhat unlikely to be able to exploit it but have at it hass.

      I'd imagine it'd be easier to exploit the server side, actually.

      1. londons_explore · · focus · HN ↗
        Yeah, but the server is most likely running the whole thing in a docker container with no permissions to do anything. Big companies security teams tend to require that when opening non-trivial third party code up to the internet.

        The client on the other hand I would guess is running it's code as root, or at least something with full GPU access.

        1. rezonant · · focus · HN ↗
          I guarantee the RTMP process on a Playstation 5 is not running as root.
    2. [deleted] · · focus · HN ↗

      [deleted]

    3. opello · · focus · HN ↗
      Wouldn't this require a man-in-the-middle since the PS5 is transmitting data to a specific server, YouTube or Twitch in the article?

      There are extensions to RTMP to use encryption or even just TLS. But do you mean that the risk of fragments of audio and video bitstreams going out unprotected presents a remote code execution risk? That seems less a problem of vulnerability and more one of privacy.

    4. someonebaggy · · focus · HN ↗
      I think everyone is just hardcoding a template RTMP conversation and not implementing it beyond looking for certain markers.
    5. dylanger · · focus · HN ↗
      It is pretty wild that RTMP without any TLS is a thing, anyone in the chain, ISPs etc could just sit there and log all RTMP traffic and tap the stream at any time.
      1. londons_explore · · focus · HN ↗
        Would be pretty funny for an ISP to MITM all streams and put a "internet provided by Verizon" watermark in the corner of all video...
      2. hjkloinxbdj · · focus · HN ↗
        This is not correct, twitch (AWS IVS) supports rtmps.

        The OP didn’t intercept rtmp url, they intercepted the discovery endpoint.

    6. happyweasel · · focus · HN ↗
      Tunnel it
Open on Hacker News to reply ↗

Unofficial Hacker News client; not affiliated with Y Combinator.