#general

3141 messages · Page 1796 of 4

lavish compass
#

You do, you have the commit

cursive whale
void void
#

We want 1.8 Support back

harsh oasis
#

2b2t

viscid remnant
#

Should use sponge instead!!!

void void
#

We need 1.8 Support

vapid sapphire
#

1.8 is so broken and vulnerable

twin lagoon
#

no

mighty storm
#

But 1.9+ pvp is so much better

#

In every way

lavish compass
#

@twin lagoon happeepoheart

robust walrus
#

pls

cursive whale
reef rapids
#

Can you share what versions are affected by this exploit?

vagrant marlin
mental meadow
#

!warn @void void Annoying about outdated versions

thorny flickerBOT
#

:raised_hands: Warned ! strich#5805 (Annoying about outdated versions) [1 total infraction] -- aurora#4484.

slate wasp
robust walrus
#

not another 1.8 debate...

vernal moth
#

Don't ping

worn ember
#

General going bonkers

reef rapids
#

sorry

vagrant marlin
vernal moth
#

Basically everything just update

harsh oasis
tropic flame
#

well i mean, the patch has only been released less than an hour ago so i bet no relevant servers have been even updated

mighty storm
#

Develop on spigot, test on paper think_smart

humble stirrup
#

It would be so appreciated if you give some details in a few weeks for learning purpose

umbral parrot
viscid remnant
crimson haven
#

We need more slow mode lol

vivid basin
#

Based on the severity of the exploit, doesn't it seem like it would be a good idea to backport to all versions?

meager tusk
ashen nacelle
#

I applied the patch and am showing the version on the mc console. though looks like some things did not like the patch with some chunk issues.

twin lagoon
tropic flame
twin lagoon
#

where have you been

mighty storm
#

Sadly, until we get hangar

viscid remnant
slate wasp
mighty storm
#

Why are we battling over worse pvp

vagrant marlin
#

chill out

meager tusk
#

You good bro?

umbral parrot
tropic flame
cursive whale
#

chill dog

sleek ivy
sterile wadi
#

Lol

mighty storm
meager tusk
slate wasp
hot hamlet
robust walrus
#

so what is a bad faith actor capable of doing using that exploit?

slate wasp
crimson haven
#

Of they would do that and actually good 1.8 could finally rest

vagrant marlin
fossil patio
#

is this a good time to share more kitty pictures

ashen nacelle
#

datk themes ftw

slate wasp
#

no java code will make me blind (java bad)

mighty storm
#

We will not describe how to do an exploit wtf?

robust walrus
#

no, that wasnt the question

slate wasp
#

what is a backport

viscid remnant
ashen nacelle
#

i have github in dark easier to read

meager tusk
fossil patio
mighty storm
#

Easiest way to crash your server: type 'stop' in the console

cursive whale
#

yeah that is hard

ashen nacelle
tropic flame
slate wasp
#

best language ```bf
+[>+.<]

vagrant marlin
whole prawn
sleek ivy
cursive whale
#

why dont we have a 1.8pvp debate channel, isolate all the fighting to there

smoky python
marble musk
viscid remnant
robust walrus
#

my question was what harm could have been done... i have no interest in executing anything

plucky sparrow
#

god damn

viscid remnant
#

Its satire guys

mild rune
#

welcome back dap

marble musk
mighty storm
#

PHP isn't that bad

ashen nacelle
#

php is like spaghetti

slate wasp
#

blindness if it was a language

mighty storm
#

Try Python, horrible to read and write

viscid remnant
full rune
slate wasp
vapid sapphire
void void
#

Can someone explain what was the exploit?

old bridge
ashen nacelle
#

I still code websites in PHP

mental meadow
tropic flame
potent panther
#

that's a lot

viscid remnant
cloud moat
viscid remnant
potent panther
#

server owners ip

ashen nacelle
#

what about writing in Ruby

slate wasp
#

top 2 worst languages

  1. c#
  2. python
whole prawn
void void
ashen nacelle
#

#4 VBscript

tropic flame
mighty storm
#

What's so bad about see sharp? Glasses are very useful for eyesight

slate wasp
#

c# doesnt deserve to be called c# because it isnt c

glass crag
#

sorry but java is worse than c#

lavish compass
#

This is actually a fucking disaster

slate wasp
potent panther
#

yeah really bad exploit

cursive whale
#

c sharp is a pain in the ass to learn

viscid remnant
formal tundra
#

Anyone know what this exploit does?

slate wasp
old bridge
mighty storm
#

Check paper help pins

potent panther
ripe sphinx
#

Exploit is potential RCE. Update.

old bridge
#

Thanks for your explanation!

cursive whale
viscid remnant
marble musk
#

I heard someone say the exploit resembles an RCE... In Iaymans terms, very, very, very bad if true

tropic flame
full rune
potent panther
hot hamlet
#

What about un updated plugins?

vapid sapphire
#

chunk wiping exploit, server-crashing with simple text: i sleep
log4j exploit: real shit

hot hamlet
#

Cause geyser updated that

vagrant marlin
magic river
#

Plugins shouldn't be shipping their own log4j

hot hamlet
rugged cosmos
#

hi! i just want to be sure, 1.8.8 are affected by the exploit or just 1.12+ ?

vagrant marlin
#

yet they do

potent panther
#

bruh minecraft java was made on

void void
#

1.8.8 game over

simple tundra
slate wasp
#

im a cool kid btw

potent panther
#

so you prefer bedrock?

tropic flame
vapid sapphire
rugged cosmos
vagrant marlin
potent panther
#

idc if you prefer bedrock but paper is for java

vapid sapphire
#

wait, so hold on

marble musk
#

Who told you it wasn't already public? If one random person can find it anyone else can too

sinful iron
#

is there a CVE for the new RCE?

sleek ivy
#

weird how I can't find anything about this exploit

mighty storm
#

Not that we know of

ashen nacelle
#

according to /google
Here are the best Cross Platform App Development Languages:
Java.
JavaScript.
Kotlin.
Dart.
Objective-C.
Swift.
C#

fickle warren
#

what versions have this exploit?

mighty storm
#

Why does my discord freeze for like 3 seconds when I click a name?

barren fractal
#

specific versions?

vapid sapphire
#

if this affects servers including vanilla because of log4j, don't clients also include log4j?

tropic flame
#

Java actually has a much lower chance of things like buffer overflows (there are sanity checks in the JVM), which is what things like remote code execution exploits use to work. The thing is when these Java libraries use native code... Code written in C(++). Not very cool kid of you kekw

viscid remnant
# potent panther i do but its like of the most important ips

Every IPs you collect is information you shouldn't be leaking and something you should do your best to safeguard. I wouldn't consider the Owners/YouTubers ip more valuable then an average user. I recall tubbo leaking multiple ips when he streamed himself making servers which was disgusting

mighty storm
#

Why would we describe it? Just update

#

Or check paper help pins

whole prawn
fickle warren
barren fractal
mighty storm
#

I keep accidentally calling people

mighty storm
viscid remnant
vagrant marlin
tropic flame
#

And what happens when you don't write code correctly? 🤔

Remember we are humans

void void
#

fix 1.3.2 Version

fickle warren
#

right

mighty storm
#

i haven't pinged him don't worry

viscid remnant
ashen nacelle
mental meadow
#

apparently you do. Dont be a dick

fossil patio
tropic flame
#

also holy shit why not just crank up the slow mode to 6 hours if you're going to keep doing it kekwhyper I just want to reply to people

mighty storm
#

Yikes + ratio

viscid remnant
fickle warren
heady marlin
#

Hm, what exploit the announcement is talking about? Where can I learn the details?

hexed coral
#

inconspicuous

livid plume
#

on the other hand, it's not like the people who would be able to abuse this can't literally just understand what's happening? I fully support not releasing dangerous exploit info but yeah lmao

barren fractal
mental meadow
#

!kick @final granite Troll

thorny flickerBOT
#

:raised_hands: Kicked UberSuperBoss#1184 (Troll) [1 total infraction] -- aurora#4484.

whole prawn
#

why do you have your real life name connected to your discord account through facebook

fossil patio
viscid remnant
vagrant marlin
fickle warren
fickle rain
smoky python
#

Curious, why doesn't paper have have an auto-updater? Could be handy for people not being in this Discord and don't update this often

viscid remnant
fickle warren
#

i would just like to know what versions this exploit is in

limber knotBOT
#

auto updaters break shit

mental meadow
mental meadow
fickle warren
#

ah okay

vagrant marlin
tropic flame
charred sleet
#

hmmm

somber leaf
#

not epic exploit

vagrant marlin
#

why did you get kicked, james?

old bridge
#

So if I get it correctly, the problem is in every past paper version basically, but because these later versions use a higher version of Java chances are it still wouldn't work there.
However, obviously, it is still better to just update your paper (which I already did ofc)

viscid remnant
#

Mhm not the case for everyone. My friends ip gives his city. Combine it with knowing his other details you can do worse. You can also ddos too

fickle warren
#

so any versions starting from today fix it? including paper versions for 1.16 and below?

magic river
#

I would assume it's in all versions until someone can say what log4j2 versions are vulnerable and you can cross-reference that with MC versions

twin lagoon
#

cya

mossy vessel
#

!ban 348418909029924874 Cheap troll, move on

thorny flickerBOT
#

:raised_hands: Banned UberSuperBoss#1184 (Cheap troll, move on) [2 total infractions] -- NotMyFault#3732.

twin lagoon
mild rune
#

Michael you looking cute today

fickle warren
vagrant marlin
fickle warren
#

geez

formal turret
#

most likely 1.8 -> current

tropic flame
#

they haven't used even close to pure Spigot code for a long time (legend says they forked Spigot 1.7 and just built their thing which does not resemble Bukkit at all anymore at this point). They are capable of fixing their state-of-the-art software by themselves, I'd say ¯_(ツ)_/¯

crimson haven
livid plume
#

if i remember correctly versions below 1.16 can use a java flag to patch this right? might be worth announcing for the people below?

barren fractal
mossy vessel
#

This is not up for debate

simple tundra
ashen nacelle
fickle warren
fast arrow
#

Bro, stop being such a troll

mossy vessel
#

Which has been deleted by now PepeLaugh

mighty storm
#

rory would be very disappointed in most of yall

mental meadow
#

The next one discussing about pronouns gets instantly banned, easy

viscid remnant
simple tundra
#

oh, that

tropic flame
cloud moat
vagrant marlin
fickle warren
fossil patio
tropic flame
mental meadow
cloud moat
mild rune
#

weebs NOPERS

simple tundra
fickle warren
tropic flame
#

weebs in, sorry

mental meadow
#

so close

simple tundra
viscid remnant
#

Peoples priorities are just weird lmao

tropic flame
#

I'd rather have weebs than homophobes

mossy vessel
#

I'm pro nouns, but verbs are cool too

mild rune
#

I like adjectives

viscid remnant
#

Nothing wrong with weebs. They're people

cloud moat
mighty storm
#

nouns ❌
i prefer yesuns

potent panther
#

adverbs?

cloud moat
main hound
fast arrow
viscid remnant
#

I mean you could always just Modify your 1.8 jar kekw

tropic flame
hexed dragon
#

Whenever an exploit fix announcement happens the chat is so much more active.

golden gust
#

!ban @clever mantle Creep elsewhere

thorny flickerBOT
#

:raised_hands: Banned NicoNeko#6018 (Creep elsewhere) [1 total infraction] -- electronicboy#8869.

ashen nacelle
#

oof

main hound
#

another brother lost

viscid remnant
#

Rip

mental meadow
#

Y'all choose the worst time possibly to troll.

fast arrow
viscid remnant
#

They really do

ashen nacelle
#

creeper alert!

viscid remnant
#

Awww man

left swift
#

oh man exciting day huh

viscid remnant
#

Yup i think the chats more calm now

acoustic basin
#

Where can I learn more about the exploit that was found recently

tropic flame
#

they heard it's a remote code execution exploit, they decided to remotely execute their trolling abilities kekw

mild rune
#

hey nomana

viscid remnant
#

Fucks sake nvm

viscid remnant
#

I was a fool to think it was calming down thanos turning to dust

ripe sphinx
mighty storm
#

and as usual, there's no eta >:)

mild rune
#

The CVE will pop up eventually on log4j's security page

gleaming steeple
#

Слава Украине!

ashen nacelle
#

how many bans are we up to today since this exploit was patched damn man

mighty storm
#

dependabot finna work overtime

mental meadow
#

Please stick to english in here

mossy vessel
viscid remnant
#

Is that ur cat as ur pfp chew

mighty storm
#

rory?

mossy vessel
#

I suggest less complaining, more updating

mild rune
#

If people are gonna troll at least be a good one smh

viscid remnant
#

Ikr

fickle warren
#

troll how

mighty storm
#

so we can ban them quicker yea

ashen nacelle
#

like the troll doll above?

worn ember
mild rune
#

I used to get trolls when I worked support and they'd always be so obvious I could ban them instantly

vagrant marlin
#

a good troll is something that people will laugh at, being annoying is not one of them

mossy vessel
viscid remnant
mental meadow
#

I'ma just ban everyone slightly annoying, should cover 90%

worn ember
#

90% of the server?

left swift
#

hi aurora

viscid remnant
golden gust
#

I vote DED yeetus first

ashen nacelle
#

thanos snapp in overcharge

void void
#

briefly what is this about an exploit dupe, force op, kickall, dump?

mild rune
cloud moat
tropic flame
worn ember
#

you love me cat sad_pepe

tropic flame
#

now the cool kids play Forza or some shit like that

mild rune
#

Had someone ask me to recommend them a server plan that could hold 300 million players

vagrant marlin
viscid remnant
left swift
#

gmod what is this 2016

viscid wedge
tropic flame
cloud moat
viscid remnant
mild rune
#

gmod is very much still kicking

#

S&ndbox looks cool tho

tropic flame
#

Sandndbox? kekw

viscid remnant
#

Great game :) i remember in watching yters play TTT, murder mystery or some other games. Sandbox is just chill

tropic flame
#

yeah tho it looks awesome

mild rune
snow iron
#

Hello, where can I read more about this exploit, is there a article or thread thing anyone can refer me to

mighty storm
#

sans

left swift
#

it's fun if you get people to play, otherwise it's just dev tooling rn

mighty storm
#

no

tropic flame
#

since Source 2 actually supports infinite worlds they added that into s&box + procedurally generated terrain, which is fuckin cool, they could effectively remake Minecraft in Source 2

#

Source 1 was quite limited in that regard

left swift
#

my 3000 gmod hours in darkrp got me into s&box early access in 2 hours kekwhyper

worn ember
#

Source 1 is also like 20 years old

tropic flame
#

it worked fine for Half-Life 2 all the way up to CS:GO but, yeah

mild rune
#

I should request access

#

I've got a decent chunk of time in gmod

left swift
#

ya I want to see what your workshop token is

#

did you release any content for gmod workshop mja

mild rune
#

I released a few things iirc

tropic flame
# worn ember Source 1 is also like 20 years old

tbf though, the fact that it still holds up even for a game as old as Half-Life 2 is amazing

of course that the CS:GO branch of the engine has much more patches over it, but Half-Life 2 still holds up imo

left swift
#

you might get a good token then

vagrant marlin
mild rune
#

Apparently not KEKLEO

left swift
foggy silo
#

Dang a new exploit?

ashen nacelle
#

damn Owen you late to the party

cloud moat
#

Just found the exploit, holy shit, thats a big one

worn ember
#

no, its an april fools joke

tropic flame
formal turret
#

thanks apache

foggy silo
#

I was at school!! 😠

mighty storm
spare venture
#

i miss gmod

worn ember
#

i love balls underwater

foggy silo
#

Studying for French…. 🥴

vagrant marlin
mild rune
#

All my workshop content was for other games sadgeHD

flat shale
#

Hi, sorry, just read about the new exploit. I'm a server owner and I'm currently at work, so I can't exactly look up what it is. Can someone provide some info for me?

mental meadow
mighty storm
#

I have no idea how, the game was closed, but clocked in a week of gameplay anyway, it's more like 3 hours

foggy silo
#

Just make sure to update asap

mild rune
#

based

ashen nacelle
#

that avatar for aurora looks familiar

mighty storm
#

it's anime, very well known in japan

tropic flame
mild rune
#

All the custom stuff I made for gmod was mostly for private servers

#

1588 hours on record ez

flat shale
vivid basin
tropic flame
# main hound from log4j...

if Log4J uses native libraries then it can potentially be a thing

run unsafe code and risk a buffer overflow

flat shale
robust oxide
#

Is the exploit on legacy versions?

mild rune
#

yes

left swift
#

2676 hours, sheesh wasted 115 days in total playing gmod lmao

main hound
#

good I just created my own logger

robust oxide
main hound
#

fuck log4j

flat shale
#

Ugh now I'm gonna have to restart an entire ark cluster as well

mild rune
#

what part of yes do you misunderstand?

left swift
#

I wish you could see how many hours you've logged on minecraft

cloud moat
robust oxide
#

is it just a paper exploit?

flat shale
#

Oh well, thanks for the help!

sleek ivy
#

I think I figured it out but 🤫

mighty storm
#

don't bait people

mild rune
wide chasm
left swift
#

lol

acoustic fractal
#

Wait what is the exploit?

tropic flame
# main hound fuck log4j

yeah just use java.util.logging kekwhyper

it's not a reason to just say fuck Log4J imo, things like this happen, you just have make sure you're running up-to-date software

sleek ivy
mental meadow
left swift
#

weren't you supposed to not say the exploit yet

tropic flame
ashen nacelle
#

bunch of script kiddies here it would of been spilled sooner or later

vivid basin
mighty storm
#

But why, why would you do that

hollow igloo
#

Can plugins also expose a server to this issue, or should it be sufficient to update Paper?

tropic flame
mighty storm
#

depends if they package their own log4j for some ungodly reason instead of using the server's logger

hollow igloo
#

alright, thanks

left swift
#

I like my plugins to be 100mb+

tropic flame
#

lord please no

main hound
#

2022 just can get better

fickle warren
#

paper 1.16.5 760 is the patch right?

plucky sparrow
ashen nacelle
#

Mineos is based on NodeJS

void void
#

I had so much fun using it why patch ):

ashen nacelle
#

its not a minecraft server in of it self but a server management and webui system

plucky sparrow
cloud moat
ashen nacelle
left swift
ashen nacelle
#

looks like chat has calmed down now

tropic flame
#

indeed

rare tiger
#

ey whats the exploit called 👀

ripe sphinx
#

just gave the word for my remote hands to pull the plug on my home server while I'm not at home 🙃

tropic flame
left swift
worn ember
left swift
rare tiger
#

but fr im just curious 👉 👈 or is it a security by obscurity type deal

void void
#

Is this exploit not like... one of the biggest ever for minecraft

left swift
#

cant wait to watch the Fitz video

void void
#

rce in a shit tone of 1.12+ servers

ashen nacelle
#

yes

cloud moat
ripe sphinx
#

waterfall itself is vulnerable I believe, not 100% on that

ashen nacelle
ripe sphinx
tropic flame
worn ember
tropic flame
formal turret
#

lol

worn ember
meager tusk
#

lmfao

tropic flame
meager tusk
#

table creation declarations

left swift
#

nft paper exploit

rare tiger
ashen nacelle
#

in other news Microsoft tempts software pirates with 50% discount on office.

keen sable
#

Wait what is the exploit

foggy veldt
#

So basically to do the exploit first you

left swift
#

exploit involves S.U.G.M.A system in java

spare venture
#

home depot sucks

rare tiger
foggy veldt
#

Anyways I predicted this but no one believed me #general message tomorrow’s winning 4 numbers are 7 4 5 1

vagrant marlin
#

you were behind this exploit, i know it

#

you invented it

ashen nacelle
#

One problem with auto-correct is that you always end up posting some thong you didn't Nintendo

left swift
#

you are so old

vagrant marlin
left swift
#

that's probably where u got it from

vagrant marlin
#

dont forget the 3d joy emoji

ashen nacelle
#

its a text fomr a friend of mine

vagrant marlin
#

and red text

left swift
#

"funny teen quotes"

worn ember
#

put it in a logger

foggy veldt
left swift
#

fitz videos make me mad

#

or fit

#

whatever the fuck that guys name is

ashen nacelle
#

maybe you shouldn't be infecting your computer with that crap.

left swift
#

alright this is totally not a pokipog moment I'm coming back in a few hours

left swift
#

papermc is normie now and thsts cringe

vagrant marlin
meager tusk
vagrant marlin
#

that guy, yes i know him

foggy veldt
worn ember
rare tiger
foggy veldt
worn ember
rare tiger
#

me when RTP plugins without fluid checks or with gigantic loops

quick halo
#

Minecraft YTers here rn recording chat for a quick-scroll montage later

ashen nacelle
#

"Meat Toboggan." Try gettin' THAT image out of your head. Gripping his entrails like the reins of Santa's sleigh, streaking through the fresh morning snow on a trail of bile and gore, as his eyes beg the same question as the horrified children in his wake: "Why...?" -- Kirito

rare tiger
#

me when the new RTP plugin teleports me outside of the world border 😐

worn ember
#

you been using the wrong plugin then zoop

foggy veldt
#

Nyways I saw the ping and thought kyori and paper finally announced their merge. Wake me up when something happens

mental meadow
foggy silo
#

lol

ashen nacelle
#

"I have others. How about... you look like Benjamin Button fucked an old catcher's mitt. Like four inches of face stretched over twelve inches of skull. Like a moldy jack-o-lantern that some frat guy barfed in and then crushed against his forehead because he was super drunk and thought it was a beer can and immediately regretted every single life choice he ever made!"

quick halo
#

Whenever I see the sirens I think of Patrick wee wooing.

mental meadow
#

that is absolutely the sound

rare tiger
worn ember
rare tiger
#

wait uhh

wide chasm
#

5 questions, 6 answers

fossil patio
worn ember
#

thats how good it is

wide chasm
#

Take my money

foggy veldt
#

Sounds overcomplicated, close eyes and type random numbers into /tppos

ashen nacelle
#

my most favourite quote from SAO abridged is...

"You know something? I really hate people! They're selfish, ignorant, loud obnoxious pricks, with basically no redeeming qualities whatsoever. I mean really, look at all they've achieved! Genocide, global warming, reality TV, and just a never ending parade of failures and fuck ups! They are, without question, a complete write-off of a species, and how dare you make me care about them!"
--Kirito

worn ember
mental meadow
rare tiger
#

thats better than 99.9% of RTP plugins

mental meadow
#

too many

#

is the answer

#

too many

fossil patio
mild rune
#

I used to have a screenshot of a server I used to run where I did like 5 announcements and each one the people filled up all the reaction slots

#

It was like 95% reactions kekw

plucky sparrow
# mental meadow

that dude with the Minecraft pfp is making me cringe really hard

main hound
#

those without a profile pic are the real deal

plucky sparrow
#

Indeed

#

@marble lark can confirm

foggy veldt
#

Do you just ban everyone who dms you or do you ignore them

quick pasture
ashen nacelle
#

pobably depends on the dm content and if the dm is nessicary

mild rune
#

I'm sure if someone DM'd aurora with some creepy shit they'd get banned kekw

plucky sparrow
#

“hey my server is lagging can you tell me why”

foggy veldt
#

90% of those dms are probably something like “what’s the exploit”

#

Oh I meant after the announcement

mild rune
#

help my beta 1.3 server is lagging can you guys fix it?

ashen nacelle
left swift
#

"is there exploit fix for 1.14.4"

worn crest
plucky sparrow
#

“is there exploit fix for bukkit 1.7.2?”

ashen nacelle
#

eewww 1.6 is so fare gone and old

mild rune
#

why you no fix hmod?????

vapid sapphire
#

Looks like a commit was pushed a few minutes ago for 1.16.5

rocky flame
#

probably been answered 100 times but what exactly is the issue can someone pin it

ashen nacelle
#

the exploit affects 1.12+

mild rune
ripe sphinx
mild rune
#

it's pinned there

worn ember
foggy veldt
#

I would hate to be someone like sponge because you are sort of expected to backport fixes to those versions because of forge lts cycles

worn ember
left swift
#

o ma god

limber knotBOT
#

today i remembered allan holdsworth existed

left swift
worn ember
ashen nacelle
#

naomi graces us with her presence

mild rune
#

man I remember when CanaryMod was a thing for Minecraft

left swift
#

is oskar still banned here

worn ember
#

probably

main hound
#

no im the dev of autoplug

limber knotBOT
#

ofc

ashen nacelle
#

ooh look aurora is back again

worn ember
#

who are we plugging?

limber knotBOT
#

your mouth

#

and our ears

plucky sparrow
#

hmm

ashen nacelle
#

and your eyes

main hound
plucky sparrow
#

Sounds fair naomi

limber knotBOT
#

you cannot really plug eyes

worn ember
#

irc virgin ree

plucky sparrow
#

When are we doing it

left swift
#

tf is autoplug

limber knotBOT
#

now, i'll grab the caulk

left swift
#

sounds like a sex toy

bleak ridge
#

Where is the Minecraft Bug tracker report for the exploit?

frank otter
#

who was oskar

main hound
#

yep

worn ember
limber knotBOT
#

IT DOES HOLY SHIT

main hound
#

thats why its soo good

bleak ridge
#

So I can vote for the issue

vernal moth
#

So you can't vote

worn ember
#

direct to pinging denwav lmao

vernal moth
#

Mojang was made aware as soon as we reproduced

mild rune
#

man naomi is almost unbanned

#

gonna be sad

limber knotBOT
#

yeah soon

worn ember
#

if they ever unban you that is

plucky sparrow
#

I miss real naomi

mild rune
#

won't be able to call her a webhook anymore

plucky sparrow
#

This AI just doesn’t feel real

mild rune
#

😔

left swift
#

awe man it's been so peaceful and quiet since naomi was banned

ashen nacelle
#

what is the true naomi?

plucky sparrow
#

yea only this annoying bot

#

but other than that it’s been so peaceful

limber knotBOT
#

thinking about just giving my sister €10 cuz i can't think of anything she'd want

plucky sparrow
#

so much less naiom

limber knotBOT
#

1v1 me phantom forces dap.

left swift
#

wow such nice gift

worn ember
#

we're not having anyone over for christmas, so no presents to buy

left swift
#

10 fake dollars

limber knotBOT
#

euro is more real than dollars

left swift
#

sorry that's too much politics

twin lagoon
limber knotBOT
#

no?

mild rune
#

Discord gonna take forever to unban you

worn ember
#

im still convinced mikel reported her

ashen nacelle
#

i was banned a year ago. for posting a picture of sayori.

plucky sparrow
twin lagoon
#

i don't have that feature in paper without mod permissions

plucky sparrow
#

Do I look like I fucking play Roblox

left swift
#

michael going to get naomi re-banned

limber knotBOT
#

yes

worn ember
#

so it was a mod confirmed

mild rune
#

cat did it

limber knotBOT
#

probably cat ye

left swift
#

Michael is a required discord snitch

mild rune
#

Michael got inside knowledge on how to snitch

fossil patio
#

i reported michael for never responding to me :(

worn ember
#

nami do you talk politics? if so its probably jroy kek

foggy veldt
#

Airplane svelte man :o

ashen nacelle
#

DONT YOU DARE SUMMON JROY

#

ive already sent him to the abyss

limber knotBOT
#

i do not talk politics because politics suck

worn ember
#

no u

fossil patio
#

airplane is a movie

limber knotBOT
#

what's gonna be ur next project paul

foggy veldt
#

Oh yea I heard yatopia bought you guys out

fossil patio
#

lol, wtf

limber knotBOT
#

SugarcaneMC*

quick pasture
#

lol

#

framing that

fossil patio
#

frank KEKWHYPER

plucky sparrow
limber knotBOT
#

abyss gazes back into you

fossil patio
plucky sparrow
ashen nacelle
worn ember
#

didnt you have a rank here Paul?

ashen nacelle
#

those quotes are funny AF

fossil patio
#

i can post in the kitties channel, it's all i need

worn ember
spare venture
#

who is naomi and why were they banned

void void
#

whats the command to load it?

foggy veldt
#

This guy has been talking about sao for the past hour and I subconsciously tuned his messages out until I saw that big ass embed

limber knotBOT
#

sao quotes

plucky sparrow
#

I’m feeling quite seris right now

#

Must be the abyss

limber knotBOT
#

funny

#

no

worn ember
void void
#

whats the dynmap command

worn ember
#

idk bruh

ashen nacelle
#

Asuna: I'm sorry, did I freaking stutter? (glares at Sugou) I said, if you hurt him, you will experience pain and torment beyond anything you could possibly imagine. Your body will be torn apart piece by piece as you beg for a mercy that will never come. I will add your screams to MY GOSH-DARN SPOTIFY, AND I WILL SEE YOUR HEAD MOUNTED ON A FUDGING PIKE!

worn ember
#

google it

mossy knoll
foggy veldt
#

Probably something guessable like /dynmap render

worn ember
#

i just have at everyone enabled cuz i know it'll be carnage when it happens

#

Thats what i live for

limber knotBOT
#

yes

#

you live for the nuking and reannexation of belgium to restore the duchy of brabant

ashen nacelle
#

Boss won't get off your back? Girlfriend won't stop nagging you? Did that fuckstick Tiffany sell you a bullshit dagger that broke almost immediately despite the fact that you spent half your goddamn Col on it? Have you considered... murder?

foggy veldt
#

I only suppress everyone pings when servers start getting annoying

mossy knoll
limber knotBOT
#

reading hard, yes

mossy knoll
limber knotBOT
#

marco

worn ember
#

polo

ashen nacelle
#

polo

worn ember
#

nailed it

limber knotBOT
#

anyway dap 1v1 me phantom forces when

foggy veldt
#

I leave if it’s an emoji server but sometimes servers like tph have little quirky everyone pings

mental meadow
mossy knoll
#

poblo

#

wait

foggy veldt
#

Well I left tph too

worn ember
#

i'm still in there lol

mossy knoll
limber knotBOT
#

needed to nicely ask aurora to forward me the announcement lol

worn ember
#

thats what you get for being an irc pleb

limber knotBOT
#

shut up ded

#

you're a belgian hoe

mossy knoll
limber knotBOT
#

i am an advanced AI

foggy veldt
#

How does irc bridge work is it only #general

wide chasm
#

"advanced"

mild rune
#

imagine not being able to read the announcements

mild rune
#

The bridge has general and paper-help iirc

ripe sphinx
mild rune
#

Yeah it's got waterfall-help/dev too

limber knotBOT
#

this is why you befriend the mods and spam their telegram dms full with random jazzfunk albums and anime art

mild rune
#

what

mossy knoll
mild rune
#

Naomi is an AI

mossy knoll
#

Yes tottaly 100% I believe you

mild rune
#

good :)

limber knotBOT
mild rune
#

that's pretty poggers art

mossy knoll
#

Fruit

limber knotBOT
#

twitter artists on a different level

#

deviantart artists... too...

mild rune
#

facts

#

pixiv artist tho pepeLa

limber knotBOT
#

yes

ashen nacelle
#

i got a tournament in WARZONE at 7pm

limber knotBOT
#

most of my pixiv stuff is touhou though

spare venture
#

oo that’s cool

ashen nacelle
#

touhou is good

limber knotBOT
#

stan koish

limber knotBOT
#

bad apple overrated

#

i prefer FELT - Goldrop

#

Halozy tho

vapid sapphire
#

There's a link on the API to a build of 791 for 1.16.5

limber knotBOT
#

yes, and?

void void
#

whats the exploit thats so quickly needed patching?

ripe sphinx
charred sleet
#

something with log4j or something i though

limber knotBOT
#

ye

ripe sphinx
#

Correct

ashen nacelle
#

bad apple is cool with the 8088 domination

hollow spoke
#

hello friends, anyone has an idea if this exploit impacts logback as well

limber knotBOT
ashen nacelle
limber knotBOT
#

tfvsjs >

#

i need to find more math rock albums

solid night
#

what was the major exploit?

limber knotBOT
ashen nacelle
limber knotBOT
#

like yeah the album is good but worth almost 900 usd?

ashen nacelle
#

thats scammy

dusty flint
#

what does the fix do?

#

dont understand the code of the hotfix lol

ashen nacelle
#

Killer Poke in modern PC's

MSi Laptops UEFI
Systemd mounts variables used by Unified Extensible Firmware Interface on Linux system's sysfs as writable by the root user of a system. As a result, it is possible for the root user of a system to completely brick a system with a non-conforming UEFI implementation (specifically some MSi laptops) by using the rm command to delete the /sys/firmware/efi/efivars/ directory, or recursively delete the root directory

swift root
#

Prevents the exploit, @dusty flint

dusty flint
#

is it remote code execution?

#

the exploit

swift root
#

Talking too much about how it works and what it does isn't a great idea

golden gust
#

I mean, that's literally an old af big

ashen nacelle
#

POKE 59458,62

left swift
#

big

ashen nacelle
#

he means bug

golden gust
#

up

#

ur mandem

obsidian rose
#

Iris Shader mod discord released an announcement on the exploit with full details.

left swift
#

cat goin crazy

ashen nacelle
#

after work imma go to my otaku cave.

obsidian rose
#

People need to update to the new paper and fabric apparently.

left swift
#

wow really

#

crazy

foggy silo
#

Well yea, it effects clients too.

void void
mild rune
#

The same way it effects servers

foggy silo
#

It's a logging issue.

pliant yoke
#

Wonder how long it will take Mojang to update vanilla to patch it then

mild rune
#

1.18.1 will probably patch it

foggy silo
#

They posted the source

magic river
#

1.18.1 was supposed to release tomorrow so...

foggy silo
#

I can dm you it, but it's in chineese.

swift root
#

Mind dming me ?

#

Appreciate it

obsidian rose
# swift root Full???

Yea below their post they linked to a site detailing everything. Need a translate tho.

quasi valley
left swift
#

why would they

peak ginkgo
#

This server is on fire lmao

left swift
#

its safe here dejay

ashen nacelle
#

DeJay late to the party

left swift
#

dont go to the help chats

foggy silo
#

For real x)

left swift
#

full of even more people who cant read

magic river
#

If that's the one I'm thinking of the PoC is only the vulnerable application, not the remote side that exploits it

#

Although it will teach you how to do at least part of the exploit so don't share it here

obsidian rose
#

Iris shader mod discord now has a channel to discuss it lol

ashen nacelle
#

OOF electroniccat
Using arch in a VM.
Bad Bad Bad NO NO NO NO.

peak ginkgo
#

i hate that this is supposed to be like a

#

"hey lets fix it silently and ask everyone to update"

#

now everyones like "no :)"

#

Iris and the Fabric Discords literally saying word for word what the exploit is

#

Noone can fix anything responsibly 🙄

formal turret
#

¯_(ツ)_/¯

foggy silo
#

Well just be smart and update ur stuff x)

left swift
#

fabric being responsible?

void void
#

just know what it does

ashen nacelle
#

the idiots that refuse to update will be in a world of hurt.

mild rune
#

just update it for them with the exploit pepeLa

foggy silo
#

Well of course they don't wanna say how

#

But, you can pretty easily find out.

charred sleet
#

how do i exploit

limber knotBOT
#

not

foggy silo
#

😄

limber knotBOT
#

already fixed

foggy silo
#

First

  1. Wipe drive
formal turret
#

i mean the fix is posted publicly in a github commit... i'd imagine someone who wants to exploit it could figure out how to do it

foggy silo
#

@author: jeff

obsidian rose
foggy silo
#

Well here is the thing

left swift
worn ember
#

good

left swift
#

and that's a fact

foggy silo
#

If you fix it quietly someone may notice

#

And abuse it

#

So the best way is to publicly announce it

worn ember
#

how can they abuse it if its fixed

foggy silo
worn ember
#

no u

foggy silo
#

People won't know, won't update.

#

Sadly it creates alot of chaos,

#

(having to publicly announce it)

limber knotBOT
#

literally an @ everyone

void void
#

This exploit does nothing compared to /mv delete /

left swift
#

people wont update even if the version they're using is deleting a random chunk every 5 minutes

worn ember
#

new minigame

left swift
#

leave them to the wolves

worn ember
#

yeet a region file every 5min

limber knotBOT
#

should've added that to valk if offline mode was on

void void
#

Totally exaggerated exploit

foggy silo
#

Ehhh

#

Not entirely

#

It's still important because some people are very stubborn about updating

worn ember
#

didnt they use j8u152 or something in older versions

formal turret
#

i used it like 30 minutes ago in java 17 lol

mild rune
#

The exploit just can't do RCE on newer java versions, 100% can still spam your logs tho kekw

limber knotBOT
#

😩 i love yuragi

formal turret
#

fun times

left swift
#

rce deez nuts

formal turret
#

i need to not look in here again, very distracting

left swift
#

welcome back thonk

formal turret
#

chat's too entertaining

plucky sparrow
left swift
#

see you again in 50 minutes

worn ember
plucky sparrow
#

Might code it

formal turret
#

we'll see

ashen nacelle
#

other news Netflix imposes harsher restrictions on VPNs, Residential IP addresses

tropic flame
worn ember
#

0.5btc for links to the exploit blaze (for legal purposes this is a joke so jroy dun ban me)

foggy silo
#

🤑

tropic flame
#

to be fair though I've never actually had any issues with FAWE so I just said that for the sake of memes

#

I like FAWE

#

it solves a problem people have

worn ember
#

.fawe

peak ginkgo
#

cannot believe i've never seen .fawe before today

worn ember
#

ur welcome

left swift
#

city left the discord again right

#

we can make fun of them for a few weeks

worn ember
#

the original was an svg i made lol

swift root
#

City leaves with the seasons

tropic flame
void void
#

I really wonder why they hide the explanation of the exploit that doesn't work ... just to stimulate people's curiosity

plucky sparrow
peak ginkgo
#

👍

tropic flame
#

no need for VPN if the show i want is available to me

foggy silo
#

^^^^

left swift
#

yeah like ded

peak ginkgo
#

So it's definitely better to just shut the hell up, even the people who know exactly how to do it

left swift
#

hes a terrible person

peak ginkgo
#

And everyone KNOWS somethings wrong but only the actually smart people will figure it out.

peak ginkgo
#

Because most of those bad people are skids.

tropic flame
worn ember
#

im not smart and i figured it out kek

void void
#

Sad Minecraft community reality

worn ember
#

why do you care so much

lapis marlin
#

what all does this exploit do? it seems real bad

ashen nacelle
#

wait somone got banned because they pirated visual studio

tropic flame
#

of course what i meant is that they sang the Lazy Town song while they legally purchased a Visual Studio license

lapis marlin
#

I run purpur so I have to wait for the update but

foggy silo
worn ember
#

quick someone hax him

zealous cradle
#

Does this exploit apply to versions below 1.16?

left swift
#

yes

ashen nacelle
#

1.12+

swift root
#

I'd say be careful with anything newer than 1.6/7

void void
#

I mean I think they didn't have to ping everyone if almost all the exploit does is console spam...

spice crane
#

wAIT

swift root
#

It can do worse on older stuff.

spice crane
#

bro

worn ember
void void
#

But java 8u191-

spice crane
#

bruh

potent magnet
#

chunky worth using? on an smp on weak hardware

left swift
#

the exploit stabs your kids

spice crane
#

log4j has a Rat

#

ez

worn ember
#

basically

lapis marlin
spice crane
#

the exploit allows people to remote access ur fucking computer

#

lmao

limber knotBOT
#

no

spice crane
#

and some other

spice crane
#

injection shit

potent magnet
#

the task keeps taking longer and longer lol

spice crane
#

bro

potent magnet
#

how many chunks should I load

spice crane
#

its been patched on paper

#

i h o p e

potent magnet
#

oh I just realized I did way too many

left swift
#

bro!

worn ember
#

yeah

#

bro

potent magnet
#

if I cancel will it take what I've loaded now

void void
#

Or 1.8 and up?

spice crane
#

i think

#

idfk

left swift
#

bro aliens injecting ur java into paper with code rats bro!

spice crane
#

ur java into paper

#

what

limber knotBOT
#

1.16.5, 1.17.1 and 1.18 have gotten the patch

foggy silo
#

They are talking gibberish

worn ember
spice crane
#

the arch linux users injecting code into paper

#

:trole:

limber knotBOT
#

there's no RAT

#

it's an RCE

spice crane
#

rat

#

log4j rat!!!

#

imagine ratting

left swift
#

ayo mods

spice crane
#

rce

void void
#

No

#

Not really

tropic flame
#

what

ashen cliff
#

🐀

shrewd fjord
swift root
#

Oops didn't load chat

void void
swift root
#

Totally overrode Naomi

left swift
#

yo larry

swift root
#

oy mana

left swift
#

that guy posted reddit

#

can u permban him

tropic flame
swift root
#

Reddit?? Who dares

tropic flame
#

someone just send a rickroll to them

ashen cliff
#

They should get it. kekwhyper

shrewd fjord
#

I didn't post that ..I just found it btw and thats a post in a 'hackers' sub

left swift
#

damn that's a fat rat

tropic flame
#

i know

ashen nacelle
#

thats a fat rat

tropic flame
#

thicc rat

worn ember
#

skids will use anything they can get their hands on

worn ember
#

even tho it wouldnt be useful for 99% of them cuz they cant even write code to inject kek

quasi valley
left swift
#

kenny

#

shut up

potent magnet
void void
worn ember