Hijacking the PS5's RTMP Stream

Hacker News by 6 min read 34x views
Hijacking the PS5's RTMP Stream

Share Post

The lengthy way about to display sharing.

Contents

Sony has increasingly locked downward what you can do alongside the PS5’s hardware. Streaming is a fine example: the console gives you a nice, convenient “Broadcast” button, but the instant you desire to do item exterior the fistful of services Sony supports, it gets annoying extremely fast.

Third-party Bluetooth devices are the identical story! Sony locks the wireless stack to their own peripherals, so your headphones or controllers from another brands merely won’t brace :/

#The Problem

I frequently stream games alongside allies on Discord who observe me play, but the PS5 doesn’t assistance display sharing to Discord. The apparent fix is a grasp cardstock — plug the HDMI output into a capture card, nourish it into OBS on your Mac, stream from there. But decent ones aren’t cheap, and I didn’t desire to expend upwards of $100 fair for this.

#Remote Play

Remote Play slightly worked for me. I could nexus the PS5 to my MacBook, portion the Mac’s display to Discord and perform from there.

The issue is that you need to nexus everything to the Remote Play device: controller, earphones, etc. I additionally occasionally ran into input lag, and the stream norm is entirely controlled by the PS5. You can’t really configure anything.

I didn’t desire to alter my bodily setup all period I wanted to stream.

#How PS5 Streaming Works

The PS5 supports streaming to YouTube and Twitch by default if you’re signed into those accounts. The protocol used for this is RTMP, or Real-Time Messaging Protocol, which is commonly used for live audio/video streaming.

So whenever you commencement a broadcast, the PS5 approximately does this:

What if we could create our own equipment act as Twitch and obtain that RTMP stream instead?

That’s the idea. The PS5 doesn’t hardcode Twitch’s IP, it looks it up via DNS all time. If we authority what DNS returns, we authority anywhere the stream goes.

#Finding the Right Hostname

The apparent archetypal attempt was to spoof ingest.twitch.tv directly. That’s the hostname the PS5 resolves whenever you hit broadcast, so pointing it at the Mac should work, right?

Not quite. ingest.twitch.tv:443 is really a discovery endpoint, not the RTMP server itself. The PS5 makes an HTTPS call to it asking “which local ingest server should I use?”. Twitch responds alongside item akin ap-southeast-1.prod.fi.contribute.live-video.net. Then the PS5 pushes the genuine stream there.

Spoofing that hostname ran into a distinct problem: the genuine Twitch ingest uses RTMPS (RTMP complete TLS on harbor 443), and the PS5 validates the certificate against trusted CAs. A self-signed cert doesn’t work, and there’s no way to instal tradition CAs on a PS5.

I afterward tried YouTube as a workaround. YouTube’s RTMP ingest uses plain RTMP on harbor 1935 alongside no TLS, so the stream came through fine. But the PS5 stopped the broadcast following concerning 60 seconds since it periodically checks YouTube’s API to verify the stream is really live. Since we intercepted it, YouTube never saw it, so the API returned nothing and the PS5 gave up.

The genuine fix came from observing DNS logs during broadcasting:

sudo tail -f /tmp/dnsmasq.log # Sep 22 23:20:28 dnsmasq: query[A] ingest.global-contribute.live-video.net from 192.168.8.171 # Sep 22 23:20:28 dnsmasq: answer aps30.contribute.live-video.net is 35.55.13.0

The PS5 was resolving ingest.global-contribute.live-video.net, which chains downward to aps30.contribute.live-video.net. That’s the genuine RTMP server. Spoofing contribute.live-video.net covers all subdomains and redirects the genuine stream to the Mac without any certificate issues.

#DNS Trick

The setup has two chief parts: dnsmasq and nginx-rtmp. I built a small macOS list bar app that bundles the two and manages them.

I run dnsmasq on my Mac and configure it to determine Twitch’s ingest domains to my Mac’s LAN address:

server=1.1.1.1 server=8.8.8.8  # Redirect Twitch ingest traffic to the Mac address=/contribute.live-video.net/192.168.8.175 address=/ingest.global-contribute.live-video.net/192.168.8.175 address=/live.twitch.tv/192.168.8.175 address=/live-sin.twitch.tv/192.168.8.175 address=/live-nrt.twitch.tv/192.168.8.175 address=/live-syd.twitch.tv/192.168.8.175 address=/live-fra.twitch.tv/192.168.8.175 address=/live-ams.twitch.tv/192.168.8.175 address=/live-lhr.twitch.tv/192.168.8.175 address=/live-jfk.twitch.tv/192.168.8.175 address=/live-lax.twitch.tv/192.168.8.175 address=/live-sea.twitch.tv/192.168.8.175  log-queries log-facility=/tmp/dnsmasq.log  no-hosts listen-address=0.0.0.0

192.168.8.175 is my Mac’s IP. When the PS5 asks DNS for one of these Twitch endpoints, dnsmasq returns my Mac’s IP instead. The PS5 connects to my Mac thinking it’s Twitch.

The final part is pointing the PS5 at this DNS server. I have a GL.iNet router operating OpenWRT, so I configured it to hand my Mac’s IP as the DNS server specifically for the PS5’s DHCP lease.

# SSH into the router and run: uci add_list dhcp.lan.dhcp_option="tag:PS5,6,192.168.8.175" uci commit dhcp /etc/init.d/dnsmasq restart

The tag:PS5 part plant since the PS5’s fixed lease already has that tag set in /etc/config/dhcp. Option 6 is the DHCP choice for DNS server. The PS5 picks this up on its next DHCP renewal, no manual DNS configuration is required on the console!

#Receiving the Stream

For that, I’m using nginx-rtmp:

worker_processes 1;  error_log /tmp/nginx-error.log warn; pid /tmp/nginx.pid;  events {  worker_connections 512; }  rtmp {  server {  listen 1935;  chunk_size 4096;  application ps5 {  live on;  record off;  sync 10ms;  # Notify our app whenever a stream starts  on_publish http://127.0.0.1:9988/on_publish;  }  } }  http {  server {  listen 8080;  location /stat {  rtmp_stat all;  }  } }

The on_publish recall is how the list bar app detects whenever the PS5 starts broadcasting. nginx fires a POST to localhost:9988 alongside the stream name, and the app surfaces the complete RTMP URL prepared to copy.

At this point, the PS5 is pushing its stream (1080p60, H.264, AAC stereo) immediately to my Mac alternatively of Twitch.

From current I can drag the stream into anything: OBS to re-stream it, document it locally, or fair perform it directly.

#Watching It

Instead of going through OBS, I used mpv to drag the stream and shared the opening to Discord. The low-latency overview keeps the postpone small than a second:

mpv --profile=low-latency --audio-buffer=0.3 rtmp://127.0.0.1/ps5/stream-key

This has been fairly dependable surprisingly. I’ve been using it for a few weeks now and haven’t had any issues. You can discover the complete origin code here.

Until next time! 👋

Other Article Hacker News
↑
Close Right Ads
Close Left Ads