Hijacking the PS5's RTMP Stream via DNS Spoofing
Original: Hijacking the PS5's RTMP stream
Why This Matters
Shows how DNS-layer interception can bypass walled-garden streaming restrictions on consumer hardware.
Developer Yash Garg rerouted a PS5's live stream to his Mac using DNS spoofing, bypassing Sony's locked broadcast options. By intercepting the RTMP stream meant for Twitch, he achieved screen sharing to Discord without a capture card — saving $100+ in hardware costs.
Sony limits PS5 broadcasting to YouTube and Twitch, leaving platforms like Discord unsupported. Garg wanted to share his gameplay with friends on Discord without buying a capture card (which run $100+) or dealing with Remote Play's input lag and inflexible setup.
The PS5 uses RTMP (Real-Time Messaging Protocol) for live streaming. Garg's insight: the console doesn't hardcode Twitch's IP — it resolves the destination via DNS every time. Control the DNS response, and you control where the stream goes.
His first attempt targeted ingest.twitch.tv, but that's only a discovery endpoint. The PS5 queries it to find a regional ingest server, then streams to that server using RTMPS (RTMP over TLS on port 443). With TLS in play, a self-signed cert won't work and the PS5 has no mechanism for installing custom CAs.
YouTube looked more promising — it uses plain RTMP on port 1935, no TLS involved. The stream arrived at his Mac successfully, but PS5 pings YouTube's API every ~60 seconds to confirm the stream is live. Since YouTube never received it officially, broadcasting was cut off after a minute.
The fix came from watching DNS logs during a real broadcast session. The PS5 resolves ingest.global-contribute.live-video.net, which chains to a subdomain like aps30.contribute.live-video.net — and that server uses plain RTMP. By spoofing contribute.live-video.net to cover all subdomains, Garg directed the stream to a local RTMP server on his Mac, which he then fed into OBS and Discord.