#general
3141 messages · Page 1796 of 4
o hey
We want 1.8 Support back
2b2t
Should use sponge instead!!!
We need 1.8 Support
1.8 is so broken and vulnerable
no
@twin lagoon 
pls
2b is going to have a field day with this one
Can you share what versions are affected by this exploit?
what is the "We"? seems like you are quite alone
!warn @void void Annoying about outdated versions
:raised_hands: Warned ! strich#5805 (Annoying about outdated versions) [1 total infraction] -- aurora#4484.
hello are you high
not another 1.8 debate...
Don't ping
yeah lol
General going bonkers
sorry
practically all of them
Basically everything just update
no it's not, i enjoyed when natural selection would take its course by giving gamer kids carpol tunnel before 15
well i mean, the patch has only been released less than an hour ago so i bet no relevant servers have been even updated
Develop on spigot, test on paper 
It would be so appreciated if you give some details in a few weeks for learning purpose
hi dad
Idk about that. I like to just mindlessly click then use strategy and timing
We need more slow mode lol
Based on the severity of the exploit, doesn't it seem like it would be a good idea to backport to all versions?
Develop on paper, test on paper.
I applied the patch and am showing the version on the mc console. though looks like some things did not like the patch with some chunk issues.
evan my beloved
I would learn to read the commit on PaperMC's GitHub if I were you
where have you been
I did
Sadly, until we get hangar
Ah i see. Thanks for clarifying lol. My eyes just hurt from reading it LOL
3 words: great description
Why are we battling over worse pvp
chill out
You good bro?
working and trying to solve my relationship issues 
3 words: read the code
chill dog
Does it describe the issue? Kinda interested for educational purposes
Lol
That was 4
No, that's the point
java will make me blind its so bad
3 words and 1 number :P
so what is a bad faith actor capable of doing using that exploit?
ok
Of they would do that and actually good 1.8 could finally rest
yet you code with javascript 💀
is this a good time to share more kitty pictures
datk themes ftw
no java code will make me blind (java bad)
We will not describe how to do an exploit wtf?
no, that wasnt the question
what is a backport
I use Javascript more than java :( my teacher sucked at teaching java
i have github in dark easier to read
Something you won't be told about
- go to paper server terminal
- alt+f4
- right click paper discord icon
- leave server
Easiest way to crash your server: type 'stop' in the console
yeah that is hard
the only based opinion.
1.8 pvp is underdeveloped. 1.9 introduced great mechanics like the shield, attack speed, sweeping edge, and effect arrows.
best language ```bf
+[>+.<]
but... but i want to crash my own server i certainly wouldnt use it on other servers 🙄 i am trustworthy i would never do that
ok
Well yeah makes sense but I could somewhat get the idea from the changes
why dont we have a 1.8pvp debate channel, isolate all the fighting to there
That aint a crash
As a novice Java developer fluent in several other languages, I can confirm Java bad (side effects may include blindness and rapid brain cell decay)
Watch some kid think they can crash hypixel with it Lmao
seems sus.....
my question was what harm could have been done... i have no interest in executing anything
god damn
Its satire guys
Just wait till you see PHP
welcome back dap
lol
PHP isn't that bad
php is like spaghetti
blindness if it was a language
Try Python, horrible to read and write
Read papers github and the releaseD CVE
i'm fluent in english, good language
second worst language to ever exist
apparently has to do with LDAP according to the commit; also long time no see
Can someone explain what was the exploit?
Yeah same, like could they crash the server? Could they just access all files? Could they.. like.. what possibilities were there and what are we now safe for by updating accordingly :)
I still code websites in PHP
See the pins in #paper-help
no released CVE as of yet though but you can also read Log4J's commits
that's a lot
Pythons kinda easy but ir wouldn't be something i'd use outside data science
A language relying on WHitespace can't be good
Mhm. I assume they'll release it in 2-3 days
server owners ip
what about writing in Ruby
top 2 worst languages
- c#
- python
because its been going on for years in literally any minecraft related server and 1.8 pvpers are stubborn
So... an exploit that crashes server?
#4 VBscript
You are now safe from an attacker possibly running code in your server. That could allow them to do whatever you described. As to "how they do it", I have no idea nor the PaperMC team is interested in revealing in this instant.
What's so bad about see sharp? Glasses are very useful for eyesight
c# doesnt deserve to be called c# because it isnt c
sorry but java is worse than c#
This is actually a fucking disaster
forced oop + microsoft + slow
yeah really bad exploit
c sharp is a pain in the ass to learn
I love how you think about the server owners ip only and not everyone elses lmao
Anyone know what this exploit does?
dont learn it
Ah I see, thanks. Well obviously they don't share the details of the exploit. I really was just interested in the consequences. Sheeesh
Check paper help pins
i do but its like of the most important ips
Exploit is potential RCE. Update.
Thanks for your explanation!
too late, already lost half of my brain doing it
It isnt.
I heard someone say the exploit resembles an RCE... In Iaymans terms, very, very, very bad if true
Remote code execution. As to "how they do it", no one will disclose until a few weeks later when everyone has updated.
bad things
youtubers
What about un updated plugins?
chunk wiping exploit, server-crashing with simple text: i sleep
log4j exploit: real shit
Cause geyser updated that
uh-oh
Plugins shouldn't be shipping their own log4j
Plugins shouldnt be doing alot of things xd
hi! i just want to be sure, 1.8.8 are affected by the exploit or just 1.12+ ?
yet they do
bruh minecraft java was made on
1.8.8 game over
it sounds dull, but it is wayy more severe
im a cool kid btw
1.8.8 is affected
so you prefer bedrock?
An RCE exploit is 10 times worse than a chunk wiping one, in my opinion. Someone could literally do whatever they want in your machine since they can run code in it. But go off I guess.
no i get it, it sounds fucking criitcal
okay thank you!
thus you should update
idc if you prefer bedrock but paper is for java
wait, so hold on
Who told you it wasn't already public? If one random person can find it anyone else can too
is there a CVE for the new RCE?
weird how I can't find anything about this exploit
Not that we know of
according to /google
Here are the best Cross Platform App Development Languages:
Java.
JavaScript.
Kotlin.
Dart.
Objective-C.
Swift.
C#
what versions have this exploit?
Why does my discord freeze for like 3 seconds when I click a name?
specific versions?
if this affects servers including vanilla because of log4j, don't clients also include log4j?
Java actually has a much lower chance of things like buffer overflows (there are sanity checks in the JVM), which is what things like remote code execution exploits use to work. The thing is when these Java libraries use native code... Code written in C(++). Not very cool kid of you 
Every IPs you collect is information you shouldn't be leaking and something you should do your best to safeguard. I wouldn't consider the Owners/YouTubers ip more valuable then an average user. I recall tubbo leaking multiple ips when he streamed himself making servers which was disgusting
yeah the app has started to do that recently
minecraft versions
Because it helps to identify how servers can fix it?
I keep accidentally calling people
by updating
The fix is updating...
Perks of being on mobile
the fix is to update
And what happens when you don't write code correctly? 🤔
Remember we are humans
fix 1.3.2 Version
right
i haven't pinged him don't worry
Should also consider user stupidity too :)
that is why whenever i post a screenshot of my terminal I censor out ip addresses that are visible in the screenshot before posting to discord.
apparently you do. Dont be a dick

also holy shit why not just crank up the slow mode to 6 hours if you're going to keep doing it
I just want to reply to people
Yikes + ratio
lmao
Same. I hate it when others send logs but dont censor their players ip. You're just carelessly doxxing someone :/
theres nothing rude about that
Hm, what exploit the announcement is talking about? Where can I learn the details?
inconspicuous
See the pins in #paper-help
on the other hand, it's not like the people who would be able to abuse this can't literally just understand what's happening? I fully support not releasing dangerous exploit info but yeah lmao
imagine giving player ips to spigot servers at all kekw
!kick @final granite Troll
:raised_hands: Kicked UberSuperBoss#1184 (Troll) [1 total infraction] -- aurora#4484.
why do you have your real life name connected to your discord account through facebook
stfu nobody cares
theres nothing rude about that
all the trolls are out today
Drop it.
ips barely tell anything nowadays in most countries though
don't tell me what to do
Why not? What are you gonna do? Fly over here?
Curious, why doesn't paper have have an auto-updater? Could be handy for people not being in this Discord and don't update this often
Try using your own IP and maxmind.com but yeah. Most you get is country and city
i would just like to know what versions this exploit is in
auto updaters break shit
Because there can always be broken builds
the answer is: yes
All
ah okay
yes, it tells my contry. the city is wrong though
The way the internet is built unfortunately does not account for IPs being sensitive information. It just gets sent around as sort of an identifier when you're connecting to a remote service. It's how it is. I wouldn't make such a big deal about it, most of the time when you try to geolocate it you'll just get the location of an ISP tower and not the actual home of the user
hmmm
not epic exploit
why did you get kicked, james?
So if I get it correctly, the problem is in every past paper version basically, but because these later versions use a higher version of Java chances are it still wouldn't work there.
However, obviously, it is still better to just update your paper (which I already did ofc)
Mhm not the case for everyone. My friends ip gives his city. Combine it with knowing his other details you can do worse. You can also ddos too
so any versions starting from today fix it? including paper versions for 1.16 and below?
who uses vpn for gaming?
I would assume it's in all versions until someone can say what log4j2 versions are vulnerable and you can cross-reference that with MC versions
cya
!ban 348418909029924874 Cheap troll, move on
:raised_hands: Banned UberSuperBoss#1184 (Cheap troll, move on) [2 total infractions] -- NotMyFault#3732.
Only down to 1.16 not bellow

Michael you looking cute today
so its not an exploit below 1.16 or theres no patch below 1.16?
its an exploit on every version ever
geez
most likely 1.8 -> current
they haven't used even close to pure Spigot code for a long time (legend says they forked Spigot 1.7 and just built their thing which does not resemble Bukkit at all anymore at this point). They are capable of fixing their state-of-the-art software by themselves, I'd say ¯_(ツ)_/¯
Just stop using legacy software
It is an exploit over all versions but there is no fix below 1.16 l. If you use verison bellow no one can help you
if i remember correctly versions below 1.16 can use a java flag to patch this right? might be worth announcing for the people below?
they use forked bungee, nothing too special
This is not up for debate
what isnt?
that is easier said than done
Bro, stop being such a troll
Which has been deleted by now 
rory would be very disappointed in most of yall
The next one discussing about pronouns gets instantly banned, easy
Yeah. I do acknowledge its like that but sadly 70% of the time your ISP may be based in the same city you are in. I dont see it as a big deal but something that you should actually consider as data to protect as an owner/server manager
oh, that
bungee is just a proxy, not the actual Minecraft server. but yeah, I'd figure they also use a fork of bungee
Update your plugins and move on
is rory disappointed in me? i updated everything already 🥺
a lot of them are not updated
I guess if you're in a big city then that can be the case
Yes, see #announcements
Then find ones that are updated, for everything you try to do there are about 10 alternatives out there
weebs 

surprisingly not. theres very few or no alternatives anymore
weebs in, sorry
so close

Peoples priorities are just weird lmao
I'd rather have weebs than homophobes
I'm pro nouns, but verbs are cool too
I like adjectives
Nothing wrong with weebs. They're people
if you want you can send me a DM about it, I may be able to help you
nouns ❌
i prefer yesuns
adverbs?
But fuck adjectives
hot
I think all words are cool, you can't single out nouns 😶 🧐
I mean you could always just Modify your 1.8 jar 
You say verbs are cool cuz they're easy as shit in English, try learning french 
had 5 years of it, didn't help much
Whenever an exploit fix announcement happens the chat is so much more active.
!ban @clever mantle Creep elsewhere
:raised_hands: Banned NicoNeko#6018 (Creep elsewhere) [1 total infraction] -- electronicboy#8869.
oof
another brother lost
Rip
Y'all choose the worst time possibly to troll.
👌 😶 👍
They really do
creeper alert!
Awww man
oh man exciting day huh
Yup i think the chats more calm now
Where can I learn more about the exploit that was found recently
they heard it's a remote code execution exploit, they decided to remotely execute their trolling abilities 
hey nomana
Fucks sake nvm
I was a fool to think it was calming down thanos turning to dust
Wait a week, the nature of the exploit isn't being discussed at this time. Just update
and as usual, there's no eta >:)
Okay 👍
The CVE will pop up eventually on log4j's security page
Слава Украине!
how many bans are we up to today since this exploit was patched damn man
dependabot finna work overtime
Please stick to english in here
The majority cuz people are cheap trolls smh
Is that ur cat as ur pfp chew
rory?
I suggest less complaining, more updating
If people are gonna troll at least be a good one smh
Ikr
troll how
so we can ban them quicker yea
like the troll doll above?
waiting for the paper team to update faster 
Kekw
I used to get trolls when I worked support and they'd always be so obvious I could ban them instantly
a good troll is something that people will laugh at, being annoying is not one of them
Why do you have an emoji of yourself?
if one of them is innocent and was just new
I'ma just ban everyone slightly annoying, should cover 90%
90% of the server?
hi aurora
95%*
I vote DED yeetus first
thanos snapp in overcharge
briefly what is this about an exploit dupe, force op, kickall, dump?
I had someone come in with the name "Cock N Balls" and ask for me to send them some porn
Already updated all my Dockerfiles and pushed them into CI
guys, just fuck this exploit, remember when Need for Speed was a relevant racing game franchise? https://youtu.be/aA1FfmnC5zk
you love me cat 
LOL.
now the cool kids play Forza or some shit like that
Had someone ask me to recommend them a server plan that could hold 300 million players
the cool kids play gmod for the ultimate car simulation
I had someone claiming to be confused of their gender and wanted me to inspect their pants once. I just said that wasn't the support i gave-
gmod what is this 2016
fucking PLEASE
i can help them for 99$/h
GTA IV
driving almost literal bars of soap
The only relevant Racing Game Franchise is Mario Cart
Gmod is still being played on :)
Sandndbox? 
Great game :) i remember in watching yters play TTT, murder mystery or some other games. Sandbox is just chill
yeah tho it looks awesome
look don't question it 
Flashbanged ow
Hello, where can I read more about this exploit, is there a article or thread thing anyone can refer me to
sans
it's fun if you get people to play, otherwise it's just dev tooling rn
since Source 2 actually supports infinite worlds they added that into s&box + procedurally generated terrain, which is fuckin cool, they could effectively remake Minecraft in Source 2
Source 1 was quite limited in that regard
my 3000 gmod hours in darkrp got me into s&box early access in 2 hours 
Source 1 is also like 20 years old
it worked fine for Half-Life 2 all the way up to CS:GO but, yeah
ya I want to see what your workshop token is
did you release any content for gmod workshop mja
I released a few things iirc
tbf though, the fact that it still holds up even for a game as old as Half-Life 2 is amazing
of course that the CS:GO branch of the engine has much more patches over it, but Half-Life 2 still holds up imo
you might get a good token then
source 1 just casually loading up the entire world because thats all it knows to do
Apparently not 

Dang a new exploit?
damn Owen you late to the party
Just found the exploit, holy shit, thats a big one
no, its an april fools joke
the maps are relatively small enough that one could do that i think, you are not actually rendering everything outside of what you see anyways
thanks apache
I was at school!! 😠
Yeah I have gmod content 
https://steamcommunity.com/sharedfiles/filedetails/?id=322560486
the best
i miss gmod
i love balls underwater
Studying for French…. 🥴
218 hours in plague inc 😳
All my workshop content was for other games 
Hi, sorry, just read about the new exploit. I'm a server owner and I'm currently at work, so I can't exactly look up what it is. Can someone provide some info for me?
See the pins in #paper-help
I have no idea how, the game was closed, but clocked in a week of gameplay anyway, it's more like 3 hours
Just make sure to update asap
based
that avatar for aurora looks familiar
All you need to do is update to the latest build!
😄
it's anime, very well known in japan
It allows an attacker to run code in your machine (they can do whatever they want at that point). As to how it's done, no one will disclose for the following weeks. See the pins in #paper-help for more, and update
All the custom stuff I made for gmod was mostly for private servers
1588 hours on record 
from log4j...
I'm currently at work. I am trying to weigh having someone pull the plug for me and crash multiple servers or hope I'm fine for a few hours
I don't think it's remote code execution
if Log4J uses native libraries then it can potentially be a thing
run unsafe code and risk a buffer overflow
Thank you, that probably means I should pull the plug
Is the exploit on legacy versions?
yes
2676 hours, sheesh wasted 115 days in total playing gmod lmao
good I just created my own logger
1.8 and 1.12?
fuck log4j
Ugh now I'm gonna have to restart an entire ark cluster as well
what part of yes do you misunderstand?
I wish you could see how many hours you've logged on minecraft
Just surprised it isn't a picrew
is it just a paper exploit?
Oh well, thanks for the help!
I think I figured it out but 🤫
don't bait people
I don't it'd be like easily over 25k
It's an exploit in the logging library, software that uses this library is affected
lol
Wait what is the exploit?
yeah just use java.util.logging 
it's not a reason to just say fuck Log4J imo, things like this happen, you just have make sure you're running up-to-date software
which is like most of the java ecosystem
See the pins in #paper-help
weren't you supposed to not say the exploit yet
we are not saying how it's performed, are we? 🤔
bunch of script kiddies here it would of been spilled sooner or later
Paper is open source, you can find out what it was based on the changes in the source. The difficult part is taking that knowledge of what it was and making it into a proof of concept
But why, why would you do that
Can plugins also expose a server to this issue, or should it be sufficient to update Paper?
Theoretically yes
plugins that ship their own Log4J for whatever reason must also be updated
depends if they package their own log4j for some ungodly reason instead of using the server's logger
alright, thanks
I like my plugins to be 100mb+
can't wait for the first Electron-based Minecraft server 
lord please no
wtf
2022 just can get better
paper 1.16.5 760 is the patch right?
Isn’t there a nodejs Minecraft server already
Mineos is based on NodeJS
I had so much fun using it why patch ):
its not a minecraft server in of it self but a server management and webui system
Shouldn’t be too hard to add a UI to it 
From what I can see, that fix isn't backported yet

looks like chat has calmed down now
indeed
ey whats the exploit called 👀
just gave the word for my remote hands to pull the plug on my home server while I'm not at home 🙃
deez nuts
sugma
sigma
Dont do it also give ip
sugma balls
but fr im just curious 👉 👈 or is it a security by obscurity type deal
Is this exploit not like... one of the biggest ever for minecraft
rce in a shit tone of 1.12+ servers
yes
Take a look at Responsible Disclosure
waterfall itself is vulnerable I believe, not 100% on that
look in #announcements
ah yes, lemme give my home IP out to a random person
How it's done is not disclosed, what it is is a possible remote code execution exploit.
can send you a link in dm's 👀
may I take a look too, then? 👀
lol
0.5btc
lmfao
nice bait
table creation declarations
nft paper exploit
yes send me your rickroll 🙄
in other news Microsoft tempts software pirates with 50% discount on office.
Wait what is the exploit
So basically to do the exploit first you
exploit involves S.U.G.M.A system in java
home depot sucks
lmao he actually delivered okay
Anyways I predicted this but no one believed me #general message tomorrow’s winning 4 numbers are 7 4 5 1
One problem with auto-correct is that you always end up posting some thong you didn't Nintendo
you are so old
Yeah, sometimes i Nintendon't to type something
I feel like you could put that over a random scenic background like over a beach and post it on Facebook
that's probably where u got it from
dont forget the 3d joy emoji
its a text fomr a friend of mine
and red text
"funny teen quotes"
put it in a logger
Tell that 2b2t Minecraft keemstar guy to put me in a video
maybe you shouldn't be infecting your computer with that crap.
alright this is totally not a pokipog moment I'm coming back in a few hours
||I WAS JOKING||
papermc is normie now and thsts cringe
oh, the bald guy with a beard, and a crave for some raycons and gfuel?
yeah now papermc is not fun
that guy, yes i know him
He seems like he needs to touch grass but there obviously seems to be a market for no lifeing 2b2t so get that money ig
why do you hate me?
> in Minecraft-tangent community
> mad that it's full of normies
Because your rtp plugin didn’t find me the god spawn

me when RTP plugins without fluid checks or with gigantic loops
Minecraft YTers here rn recording chat for a quick-scroll montage later
"Meat Toboggan." Try gettin' THAT image out of your head. Gripping his entrails like the reins of Santa's sleigh, streaking through the fresh morning snow on a trail of bile and gore, as his eyes beg the same question as the horrified children in his wake: "Why...?" -- Kirito
me when the new RTP plugin teleports me outside of the world border 😐
you been using the wrong plugin then 
Nyways I saw the ping and thought kyori and paper finally announced their merge. Wake me up when something happens
this will never not be fun
https://youtu.be/9PIcQ7VLGoA
lol
"I have others. How about... you look like Benjamin Button fucked an old catcher's mitt. Like four inches of face stretched over twelve inches of skull. Like a moldy jack-o-lantern that some frat guy barfed in and then crushed against his forehead because he was super drunk and thought it was a beer can and immediately regretted every single life choice he ever made!"
Whenever I see the sirens I think of Patrick wee wooing.
that is absolutely the sound
does it
- use NMS heightmaps to approximate Y value
- use optimized loop when that fails
- perform fluid checks
- have zone based on world border
- use same Random many times
- No
- No
- If ur lucky
- Yes
- If u leave ur server on long enough

wait uhh
5 questions, 6 answers
not a video of all the dms and @s?
thats how good it is
Take my money
Sounds overcomplicated, close eyes and type random numbers into /tppos
my most favourite quote from SAO abridged is...
"You know something? I really hate people! They're selfish, ignorant, loud obnoxious pricks, with basically no redeeming qualities whatsoever. I mean really, look at all they've achieved! Genocide, global warming, reality TV, and just a never ending parade of failures and fuck ups! They are, without question, a complete write-off of a species, and how dare you make me care about them!"
--Kirito
you know, math is hard
ill take your entire stock
thats better than 99.9% of RTP plugins

I used to have a screenshot of a server I used to run where I did like 5 announcements and each one the people filled up all the reaction slots
It was like 95% reactions 
that dude with the Minecraft pfp is making me cringe really hard
those without a profile pic are the real deal
Do you just ban everyone who dms you or do you ignore them

pobably depends on the dm content and if the dm is nessicary
I'm sure if someone DM'd aurora with some creepy shit they'd get banned 
“hey my server is lagging can you tell me why”
90% of those dms are probably something like “what’s the exploit”
Oh I meant after the announcement
help my beta 1.3 server is lagging can you guys fix it?
think ive done that about 3000 time already ... jk
"is there exploit fix for 1.14.4"
no fix for log4j for mc 1.6??? i wanna refund! 
“is there exploit fix for bukkit 1.7.2?”
eewww 1.6 is so fare gone and old
why you no fix hmod?????
Looks like a commit was pushed a few minutes ago for 1.16.5
probably been answered 100 times but what exactly is the issue can someone pin it
the exploit affects 1.12+
#paper-help pins
it's pinned there
Are you oskar 👀
I would hate to be someone like sponge because you are sort of expected to backport fixes to those versions because of forge lts cycles

o ma god
today i remembered allan holdsworth existed

sponge is a lot less version dependent tho
naomi graces us with her presence
man I remember when CanaryMod was a thing for Minecraft
is oskar still banned here
probably
no im the dev of autoplug
ofc
ooh look aurora is back again
who are we plugging?
hmm
and your eyes
depends
Sounds fair naomi
you cannot really plug eyes
irc virgin 
When are we doing it
tf is autoplug
now, i'll grab the caulk
sounds like a sex toy
Where is the Minecraft Bug tracker report for the exploit?
who was oskar
yep
its plug but automatic
IT DOES HOLY SHIT
thats why its soo good
So I can vote for the issue
Private
So you can't vote
direct to pinging denwav lmao
Mojang was made aware as soon as we reproduced
yeah soon
if they ever unban you that is
I miss real naomi
won't be able to call her a webhook anymore
This AI just doesn’t feel real
😔
awe man it's been so peaceful and quiet since naomi was banned
what is the true naomi?
thinking about just giving my sister €10 cuz i can't think of anything she'd want
so much less naiom
1v1 me phantom forces dap.
wow such nice gift
we're not having anyone over for christmas, so no presents to buy
10 fake dollars
euro is more real than dollars
sorry that's too much politics
more like new account
no?
im still convinced mikel reported her
i was banned a year ago. for posting a picture of sayori.
Roblox?
nop i only report through in app reporting
i don't have that feature in paper without mod permissions
Do I look like I fucking play Roblox
michael going to get naomi re-banned
yes
so it was a mod confirmed
cat did it
probably cat ye
Michael is a required discord snitch
Michael got inside knowledge on how to snitch
i reported michael for never responding to me :(
nami do you talk politics? if so its probably jroy 
Airplane svelte man :o
i do not talk politics because politics suck
no u
what's gonna be ur next project paul
Oh yea I heard yatopia bought you guys out
lol, wtf
SugarcaneMC*
frank 
gaze into the abyss
abyss gazes back into you
doing some more open source stuff on funner projects, mostly just work lately though
no
didnt you have a rank here Paul?
those quotes are funny AF
i can post in the kitties channel, it's all i need

who is naomi and why were they banned
whats the command to load it?
This guy has been talking about sao for the past hour and I subconsciously tuned his messages out until I saw that big ass embed
sao quotes
use something like chunky
no i mean to render the map
whats the dynmap command
idk bruh
Asuna: I'm sorry, did I freaking stutter? (glares at Sugou) I said, if you hurt him, you will experience pain and torment beyond anything you could possibly imagine. Your body will be torn apart piece by piece as you beg for a mercy that will never come. I will add your screams to MY GOSH-DARN SPOTIFY, AND I WILL SEE YOUR HEAD MOUNTED ON A FUDGING PIKE!
google it
See this is why you DON'T suppress @ everyone #announcements
Probably something guessable like /dynmap render
i just have at everyone enabled cuz i know it'll be carnage when it happens
Thats what i live for
yes
you live for the nuking and reannexation of belgium to restore the duchy of brabant
Boss won't get off your back? Girlfriend won't stop nagging you? Did that fuckstick Tiffany sell you a bullshit dagger that broke almost immediately despite the fact that you spent half your goddamn Col on it? Have you considered... murder?
I only suppress everyone pings when servers start getting annoying
Do /dynmap help 😐
reading hard, yes
Yeah same but do not do it to import stuff like paper lol
i just leave
who?
marco
polo
polo
nailed it
anyway dap 1v1 me phantom forces when
I leave if it’s an emoji server but sometimes servers like tph have little quirky everyone pings
We try to only ping for important stuff
Well I left tph too
i'm still in there lol
Exactly and thank you otherwise you have people suppressing and they miss important things
needed to nicely ask aurora to forward me the announcement lol
thats what you get for being an irc pleb
Why does it say you are a bot? Are you on a bot client?
i am an advanced AI
"advanced"
imagine not being able to read the announcements
here, paper-dev|help, and I think waterfall stuff
Yeah it's got waterfall-help/dev too
this is why you befriend the mods and spam their telegram dms full with random jazzfunk albums and anime art
what
Ok are you a webhook because bots have profiles
Naomi is an AI
Yes tottaly 100% I believe you
good :)
that's pretty poggers art
Fruit
yes
i got a tournament in WARZONE at 7pm
most of my pixiv stuff is touhou though
oo that’s cool
touhou is good
stan koish
There's a link on the API to a build of 791 for 1.16.5
yes, and?
whats the exploit thats so quickly needed patching?
#paper-help pins
something with log4j or something i though
ye
Correct
bad apple is cool with the 8088 domination
hello friends, anyone has an idea if this exploit impacts logback as well
man i forgot how good this song was https://youtu.be/dMoszzW5YRc
Album - 在 Zoi (2016)
Video capture of my @party 2014 winning compo entry "8088 Domination", an official sequel to 8088 Corruption (https://www.youtube.com/watch?v=H1p1im_2uf4) that I made 10 years earlier. Like the former, 8088 Domination displays full-motion color video with audio on a 1981 IBM PC with CGA, a Sound Blaster, and any hard drive -- but, unlike the fo...
what was the major exploit?
check pins in #paper-help
https://naomi.s-ul.eu/7W2wF3QW what the actual fuck is this kinda scam
like yeah the album is good but worth almost 900 usd?
thats scammy
Killer Poke in modern PC's
MSi Laptops UEFI
Systemd mounts variables used by Unified Extensible Firmware Interface on Linux system's sysfs as writable by the root user of a system. As a result, it is possible for the root user of a system to completely brick a system with a non-conforming UEFI implementation (specifically some MSi laptops) by using the rm command to delete the /sys/firmware/efi/efivars/ directory, or recursively delete the root directory
Prevents the exploit, @dusty flint
Talking too much about how it works and what it does isn't a great idea
I mean, that's literally an old af big
POKE 59458,62
big
he means bug
Iris Shader mod discord released an announcement on the exploit with full details.
cat goin crazy
after work imma go to my otaku cave.
People need to update to the new paper and fabric apparently.
Well yea, it effects clients too.
how?
Full???
The same way it effects servers
It's a logging issue.
Wonder how long it will take Mojang to update vanilla to patch it then
1.18.1 will probably patch it
1.18.1 was supposed to release tomorrow so...
I can dm you it, but it's in chineese.
Yea below their post they linked to a site detailing everything. Need a translate tho.
today*
why would they
This server is on fire lmao
its safe here dejay
DeJay late to the party
dont go to the help chats
For real x)
full of even more people who cant read
If that's the one I'm thinking of the PoC is only the vulnerable application, not the remote side that exploits it
Although it will teach you how to do at least part of the exploit so don't share it here
Iris shader mod discord now has a channel to discuss it lol
OOF electroniccat
Using arch in a VM.
Bad Bad Bad NO NO NO NO.
i hate that this is supposed to be like a
"hey lets fix it silently and ask everyone to update"
now everyones like "no :)"
Iris and the Fabric Discords literally saying word for word what the exploit is
Noone can fix anything responsibly 🙄
¯_(ツ)_/¯
Well just be smart and update ur stuff x)
fabric being responsible?
i still dont know how its done lol
just know what it does
the idiots that refuse to update will be in a world of hurt.
just update it for them with the exploit 
how do i exploit
not
😄
already fixed
First
- Wipe drive
i mean the fix is posted publicly in a github commit... i'd imagine someone who wants to exploit it could figure out how to do it
@author: jeff
Nothing can be kept secret in this age, everything is out on the web to be found. Eventually it would have been learned, they just skipped the searching part.
Well here is the thing
99% of the people who want to exploit it dont know how to use github
good
and that's a fact
If you fix it quietly someone may notice
And abuse it
So the best way is to publicly announce it
older versions?
no u
People won't know, won't update.
Sadly it creates alot of chaos,
(having to publicly announce it)
literally an @ everyone
This exploit does nothing compared to /mv delete /
people wont update even if the version they're using is deleting a random chunk every 5 minutes
new minigame
leave them to the wolves
yeet a region file every 5min
should've added that to valk if offline mode was on
The exploit won't work unless you use older than java8u191
Totally exaggerated exploit
Ehhh
Not entirely
It's still important because some people are very stubborn about updating
didnt they use j8u152 or something in older versions
i used it like 30 minutes ago in java 17 lol
The exploit just can't do RCE on newer java versions, 100% can still spam your logs tho 
😩 i love yuragi
fun times
pog
jk
rce deez nuts
i need to not look in here again, very distracting
welcome back thonk
chat's too entertaining
This sounds like a great idea
see you again in 50 minutes

Might code it
we'll see
other news Netflix imposes harsher restrictions on VPNs, Residential IP addresses
you just need to install FAWE, it does that for you already 
0.5btc for links to the exploit
(for legal purposes this is a joke so jroy dun ban me)
🤑
to be fair though I've never actually had any issues with FAWE so I just said that for the sake of memes
I like FAWE
it solves a problem people have
this sounds like #politics
.fawe

cannot believe i've never seen .fawe before today
ur welcome
the original was an svg i made lol
City leaves with the seasons
i don't want to say anything, since other dude got banned here for simply saying they arr'ed Visual Studio... but... the industry could just not impose geographical restrictions 🙄
I really wonder why they hide the explanation of the exploit that doesn't work ... just to stimulate people's curiosity
This might actually be the reason air is more premium now, and not Naomi leaving
Bad people lurk this Discord for the smallest inkling of Paper fucking up purely to cause chaos
👍
no need for VPN if the show i want is available to me
^^^^
yeah like ded
So it's definitely better to just shut the hell up, even the people who know exactly how to do it
hes a terrible person
And everyone KNOWS somethings wrong but only the actually smart people will figure it out.
arr'ed?
Because most of those bad people are skids.
► Lazy Town - New Videos!: http://bit.ly/2pomR9p
Sing along to the Songs of Lazy Town!
Subscribe to the Lazy Town YouTube channel: https://www.youtube.com/channel/UCNuLcjVa3vCeHFyUeTKtBlA?sub_confirmation=1
Click to watch more Lazy Town Videos 🎬 🎤🎼
🎬 🎤🎼 All New Lazy Town - Karaoke/Sing-a-long HD : https://www.youtube.com/playlist?list=PLZs...
im not smart and i figured it out 
Sad Minecraft community reality
^^^^
why do you care so much
what all does this exploit do? it seems real bad
wait somone got banned because they pirated visual studio
of course what i meant is that they sang the Lazy Town song while they legally purchased a Visual Studio license
I run purpur so I have to wait for the update but
#paper-help read pins
quick someone hax him
Does this exploit apply to versions below 1.16?
yes
1.12+
I'd say be careful with anything newer than 1.6/7
I mean I think they didn't have to ping everyone if almost all the exploit does is console spam...
wAIT
It can do worse on older stuff.
bro
code injection if i understand correctly
But java 8u191-
bruh
chunky worth using? on an smp on weak hardware
the exploit stabs your kids
Yes
basically
yikes.
no
and some other
lol no way
injection shit
the task keeps taking longer and longer lol
bro
how many chunks should I load
oh I just realized I did way too many
bro!
if I cancel will it take what I've loaded now
bro aliens injecting ur java into paper with code rats bro!
1.16.5, 1.17.1 and 1.18 have gotten the patch
They are talking gibberish
nah bro
the arch linux users injecting code into paper
:trole:
rce
what
🐀
Ok ..word is out amongst the boys https://www.reddit.com/r/minecraftclients/comments/rcriky/how_to_exploit_log4j/
Oh nice Alr thanks for letting me know
Totally overrode Naomi
yo larry
oy mana
let me say this, it makes sense that Fabric discord is discussing the exploit since it's a server for modders, but this is on reddit now? 
Reddit?? Who dares
someone just send a rickroll to them
I didn't post that ..I just found it btw and thats a post in a 'hackers' sub
damn that's a fat rat
i know
thats a fat rat
skids will use anything they can get their hands on
even tho it wouldnt be useful for 99% of them cuz they cant even write code to inject 
@static badge
how many chunks should I preload
Do you know how to inject code into java
5

