#general

3141 messages · Page 1797 of 4

quasi valley
spice crane
#

bigrat.monster

left swift
#

krusic bro

worn ember
#

havent looked into it lol, but its not that hard

void void
#

ASM otaku

left swift
#

with a syringe

daring owl
#

How bad is it

#

Is it like a coordinate exploit or like code executtion

left swift
#

well look at it lie this

#

it got an everyone ping in the papermc discord

#

that should help you gauge how bad it is

robust oxide
worn ember
#

fitsmc video wen

peak ginkgo
#

btw, spigot post.

left swift
#

THE WORST EXPLOIT IN MINECRAFT HISTORY

fiery saddle
#

One probably exists as it is just backporting a fix

limber knotBOT
#

nah

worn ember
#

md not being late to the party for once

ashen cliff
worn ember
#

yeah

oblique jungle
#

imagine not knowing the string to crash the server

worn ember
#

dammit

left swift
#

that should also

worn ember
#

shouldve let the old versions to rot lmao

left swift
#

tell you how bad it is

worn ember
#

its funny cuz this exploit is like super old

left swift
#

went all the way back to 1.8.8

oblique jungle
#

still works on 1.8+ btw

#

as long as it uses logj4 2

left swift
#

such a nice guy

wooden isle
#

What does the exploit allow for?

peak ginkgo
left swift
#

drugs

oblique jungle
#

crash a server

peak ginkgo
oblique jungle
#

instantly

worn ember
peak ginkgo
#

kek fucking w

oblique jungle
#

by pasting something in chat

unique mortar
#

Is the exploit only able to affect the server, or do we know for certain it can affect clients end accounts?

tropic flame
marble trench
#

How does this exploit work ? I wanna try it to see if i'm vulnerable

tropic flame
#

i mean, we can just fork and sync upstream i guess? but still, quite funny

worn ember
peak ginkgo
left swift
#

why are all these exploit questions leaking into general chat now

#

go away

unique mortar
#

Ahh okay, yeah just making sure. Thanks for the speedy responses.

worn ember
#

i got a tool that can do the exploit but its 0.5btc

peak ginkgo
#

ded trying to pay off college

limber knotBOT
#

paper general is only for mild shitposting and trolling

worn ember
#

yes

left swift
limber knotBOT
#

no

peak ginkgo
#

too real

grand isle
#

Yo what is happening

oblique jungle
#

bannable if posting exploit in this discord?

worn ember
swift root
#

Yes.

oblique jungle
#

ight

left swift
#

this pfp should be bannable

#

larrypls

snow perch
#

wait

#

where is the ping

#

hi

#

no :D

#

ok

#

hes duper trooper

#

epic yt

#

dont ban

#

ty

limber knotBOT
#

what the fuck is that a trumpet in my shoegaze????

golden gust
#

If you're just here to flood the channel you will be booted.

foggy silo
#

Holy cow

snow perch
#

no no

foggy silo
#

Cat you saved yourself there x)

left swift
foggy silo
#

Paperhelp is flooding

snow perch
#

;-;

limber knotBOT
#

cat being based, for once

golden gust
#

!ban @void void Go be annoying elsewhere

thorny flickerBOT
#

:raised_hands: Banned Grass#0926 (Go be annoying elsewhere) [1 total infraction] -- electronicboy#8869.

potent magnet
#

should I load my world on my personal pc then move it over the my server

#

instead of making chunky run for 12 hours on my server

limber knotBOT
#

i think me sending cat shoegaze made him a little triggerhappy

left swift
distant trout
#

y ban duper

potent magnet
#

would it not be faster?

distant trout
#

smh

void void
#

Please don't link that since it contains a POC

limber knotBOT
#

hey noah

swift root
#

Yeah deleted. Thanks Noah

void void
#

Hi naomi

limber knotBOT
#

irc remembers all.

void void
#

#general is lovely after a @ everyone ping

limber knotBOT
#

yeah

swift root
#

Always is

minor furnace
void void
#

Yes

minor furnace
#

awesome

limber knotBOT
#

cant wait to see >2k messages in every channel when i wake up again in 6-7 hrs

potent magnet
#

chunky a lot faster on my pc than on my server

ashen nacelle
#

it only 5:18pm Here

limber knotBOT
#

yes but i dont live where you live

potent magnet
#

yeah on my pc it reached the same point my server got to in 1/10th of the time lol

#

consistently about 3x faster

ashen nacelle
#

the poc is on github which means everyone knows it now

worn ember
#

news flash, your pc has more resources than your server

#

thats what happens if you run on shared hosting lol

potent magnet
#

right, but someone said "What is the point"

limber knotBOT
#

news flash, ded is a hardware expert

worn ember
#

true

limber knotBOT
#

gl transferring all the files tho

worn ember
#

hardware is hard, software is not

solemn geyser
#

what exactly is the scope of the exploit? have any technical details been released?

limber knotBOT
#

ded how good is your x86_64 asm

worn ember
#

remote code execution

fossil patio
#

on old java versions

void void
#

Can we get an exploit slash command?

limber knotBOT
#

kashike pls

faint wing
#

I don't see how the exploit could be used in mc though

potent magnet
#

mc is java bro

peak ginkgo
#

@faint wing someone pastes a funy lookin message in your server chat

#

server crashes

#

👍

solemn geyser
faint wing
#

Yeah, that's what everyone keep saying

tropic flame
solemn geyser
faint wing
#

but it also requires an error from the user of the library it seems to me

solemn geyser
#

(am a sys/netadmin)

faint wing
#

like an sql injection kind of thing

worn ember
#

thats why you run your server as root btw blaze

faint wing
#

just passing raw strings to your logger

limber knotBOT
#

if i ever finished the mc server i started

worn ember
#

you wont

potent magnet
#

how many chunks should I stop at with chunky

#

on an smp

limber knotBOT
#

i would just write a little ""virus"" into it that does an rm -rf / --no-preserve-root

potent magnet
#

currently at like 77k

limber knotBOT
#

go until it's finished, ez

potent magnet
#

I did 10k radius

#

since I could just stop whenever

#

but even on my pc it'll take 3 hours

solemn geyser
# faint wing like an sql injection kind of thing

kinda sorta. I've yet to read on how the exploit works but an attacker could pass a linux command through to the system running the server. if you're running something like ptero, the damage will be isolated to that server/container, if you run your servers on the host itself, then it can affect all your servers (in general. there's obviously a lot of nuance to it)

potent magnet
#

jokes on you I run my servers on a windows vm on my raspberry pi

marsh charm
#

what is the scope of the log4j thing? rce with permissions of user running the server? do they have to be whitelisted to exploit it?

ashen nacelle
tropic flame
#

MSI laptops literally break themselves without user intervention anyways

worn ember
#

ez

tropic flame
#

you don't need a virus

marsh charm
#

okay thx

faint wing
grizzled fjord
#

It only crashes server if spamming a lot

peak ginkgo
#

it's a "in theory, yes rce"

#

but noones done it yet

worn ember
#

i feel like it could be exploited further if you went deep into it, but too much reading to figure out exactly what lol

peak ginkgo
#

so... maybe.

viscid wedge
#

Well, "bricked"

solemn geyser
#

can someone link me the commit in the log4j repo so I can see how it actually works?

grizzled fjord
#

Almost nobody is concerned with RCE, only affect old Java builds (even Java 8 is patched since build 120)

faint wing
peak ginkgo
#

We're not doing like open discussion about it here.

void void
#

@molten zodiac hey weren't you a owner on 0b0t?

peak ginkgo
#

Bad people lurk this Discord for the smallest inkling of Paper fucking up purely to cause chaos, so we're not gonna talk about it. 👍

#

You can FIND it, but noone here's gonna help @solemn geyser

viscid wedge
grizzled fjord
#

Tested the exploit, not working on ANY server if your Java is up to date (even Java 8)

sand wharf
#

So, is the exploit fixed on the newest versions of paper/spigot?

grizzled fjord
#

(I mean the rce, still can crash)

viscid wedge
#

Okay I'm just gonna avoid this Discord for the next week, the everyone ping brought in all the dumbasses

void void
#

imagine doing this on 2b2t lol

viscid wedge
#

imagine touching grass

void void
pastel dune
grizzled fjord
#

those poc on the internet are using old Java 8 builds from 2017 u_u

ashen nacelle
#

taking jahy with you soup

limber knotBOT
#

hello soup

grizzled fjord
#

8*

viscid wedge
#

see you later naomi

worn ember
#

nothing of value lost

grizzled fjord
#

dyor, not gonna talk about it more

dreamy egret
void void
dreamy egret
#

It was performed

void void
#

LOL

grizzled fjord
#

just relax, your servers are safe if u installed / updated it in the 3 last years

dreamy egret
#

And 2b is down rn

limber knotBOT
#

i'll get my discord acc back soon, to troll some sense into the kids

jade knot
#

What is an orange?

void void
#

dont listen to papermc mods!!! they are trying to forcfe you to update your java to a version built since 20fucking17! HOLD YOUR GROUND and run 1.7 on java 6!!!!!!!!!!1

limber knotBOT
#

an orange is a round citrus fruit that grows on trees

void void
#

wrong

#

that is a purple

#

downgrade to java 1 to fix the exploit btw 🙏

tame frigate
#

Lmao

robust oxide
#

don't you mean uninstall java?

jade knot
#

Being vulnerable is the vulnerability! :P

void void
#

uninstall java, install ransomware

limber knotBOT
#

rosa reimplements the jvm in rust when

ashen nacelle
#

wannacry ftw

void void
#

no server =safe server

void void
limber knotBOT
#

lets go

#

no more buffer overflow exploits in MY jvm

#

no more memleaks

mild rune
#

naomi don't make me buffer overflow irc

limber knotBOT
#

mja dont make me buffer overflow your aorta.

#

ok

jade knot
#

I'll take your memleaks off your hands and fill a McDonalds medium cup with it

mild rune
ashen nacelle
void void
#

the c in cpp stands for pain and cuferring

#

the r in Rustlang stands for based

limber knotBOT
#

the c in cpp stands for crap

#

ez

mild rune
#

the c in cpp stands for cracked

shell surge
mild rune
#

my terminal is green

#

just less terrible

shell surge
#

xterm256 exists for a reason

limber knotBOT
#

the m in V stands for magnificent

mild rune
limber knotBOT
#

check pins

mild rune
#

bro enter is not a spacebar

worn ember
#

reading real hard

mild rune
#

me no read

#

how do werk?

ashen nacelle
limber knotBOT
#

im gonna abuse clipboard history

mild rune
#

why

#

yes we know md5 patched every version

#

do we care?

#

probably not

plucky sparrow
limber knotBOT
#

ew

plucky sparrow
#

you’re ew

limber knotBOT
#

not having anything other than int and double makes it basically the same as elshout

swift root
#

dart is fine

plucky sparrow
#

why does it bother you so much naomi

#

You can just get a library if you need it so damn much

limber knotBOT
#

that's the thing

#

there is no library for it

#

i had more than 20 tabs open trying to find one, aight?

#

like yeah i like the language but not having byte, short etc is kinda a dealbreaker for me

mild rune
#

naomi stop using esoteric langs

#

just write valk in c

limber knotBOT
foggy silo
#

Nice.

ashen cliff
#

It's a valid patch. Different approach to not break things. kekwhyper

foggy silo
#

Naomi what time is it for you

limber knotBOT
#

23:40

ashen nacelle
#

11:40PM

limber knotBOT
#

11:40pm for 12 hr clock plebs ye

foggy silo
#

Americanians

ashen nacelle
#

and i like my Farenheit!

limber knotBOT
#

then why do computers prefer celsius?

#

checkmate.

void void
#

papermc exploit involving how log4j handles the conversion of text

ashen nacelle
#

mine all display in Farenheit.

plucky sparrow
#

furenhai better becaus you feel the changes

#

‘murica land of the free

limber knotBOT
#

not just a papermc exploit, ivx

#

but yeah dap, dart is cool but not right for a minecraft server

plucky sparrow
#

Then why say ew

void void
#

welp

plucky sparrow
#

You dum

mild rune
#

naomi isn't it past your bedtime

limber knotBOT
#

yes

mild rune
#

nice

limber knotBOT
#

but i am in bed already

mild rune
#

oh

ashen nacelle
#

nah she a working girl

mild rune
#

ok

limber knotBOT
#

been for a while

ashen nacelle
#

working til the sun rises

mild rune
#

I haven't gotten out of bed today

limber knotBOT
#

i did work on stuff today yeah wooo

worn ember
#

wow

#

nomi being useful

plucky sparrow
#

I might actually do dap’s personal platform blogging in flutter

#

Looks easy enough

limber knotBOT
#

sounds like a good idea

#

write the backend in Go for cool points

plucky sparrow
#

Ew

limber knotBOT
#

golang good tho

plucky sparrow
#

No ty

stray bay
#

Can i still play on hypoxel or nah

#

pixel*

plucky sparrow
#

careful

limber knotBOT
#

how are we supposed to know

stray bay
#

so no?

limber knotBOT
#

have you tried?

#

hypickle doesnt use paper, they use their own custom fork pretty sure

void void
#

Clients are also affected though

ashen nacelle
#

as big as hypixel is they probably have their own proprietary jar files.

void void
#

They run 1.7 with 1.8 compat hacked on top

limber knotBOT
#

yeo

ashen nacelle
#

remember the days of the mineshaft client

ember tinsel
#

will papermc patch this anytime soon?

limber knotBOT
#

already been patched

ashen nacelle
#

i first used m,ineshaft before actually buying minecraft

ember tinsel
#

oh good

limber knotBOT
obtuse fossil
ember tinsel
#

my server uses 1.16, dont ask, so ima update to latest

obtuse fossil
ashen nacelle
#

wget -o https://papermc.io/api/v2/projects/paper/versions/1.17.1/builds/398/downloads/paper-1.17.1-398.jar

limber knotBOT
#

curl https://papermc.io/api/v2/projects/paper/versions/1.17.1/builds/398/downloads/paper-1.17.1-398.jar -o paper.jar

ashen nacelle
#

curl is better when downloading multiple files for a single file i will use wget.

void void
mild rune
#

just write the raw binary to a file by hand

ember tinsel
#

ok i uploaded the jar to my server

#

hopefully it doesnt f anything up foreshadowing

stiff widget
#

Is there a cve for the RCE exploit?

limber knotBOT
#

just ask cat to deliver a usb thumbdrive with the latest paper build, mja

void void
#

pretty sure there isn't one yet

median glade
#

my friend is being dumb

#

lmao

ember tinsel
#

naomi why are you a bot

cloud moat
limber knotBOT
#

i am an advanced AI

void void
#

artificial "intelligence"

ember tinsel
#

what's 10 divided by 0

vernal moth
median glade
limber knotBOT
#

ArithmeticException: Divide by zero

median glade
#

this kid

brazen marsh
hexed dragon
#

Active chat prob going to die tomorrow.

limber knotBOT
#

Permission denied.

median glade
#

"dOeSnT hYpIxEl rUn oN jAvA?"

brazen marsh
ember tinsel
limber knotBOT
#

imonsay is not in the sudoers group. This incident will be reported.

median glade
#

$sudo KillSomeone: AfkUser

limber knotBOT
#

my favourite unix utility, od.

median glade
#

yeye

#

I love the KillSomeone cmd

#

:)

void void
#

.kill Epicster

limber knotBOT
#

beheads Epicster with a chainsaw and uses their head to play football.

median glade
#

NO

#

gr

#

.kill Noah

ashen nacelle
limber knotBOT
#

turns Noah into a snail and covers them in salt.

ember tinsel
#

naomi am i cool

median glade
#

L

#

@ember tinsel no

limber knotBOT
#

no.

median glade
#

L

ember tinsel
#

ok good to know

limber knotBOT
#

adam, you know you can just do su - right?

#

you can on BSD at least

ashen nacelle
#

closing time off to home

ashen cliff
limber knotBOT
#

i usually just do su -i

#

but using root, lol

peak ginkgo
#

To my knowledge a Minehut wide fix is going out

foggy silo
#

Honestly creating more chaos is just what we needed lol. Thanks for telling them

spice ether
median glade
#

smh

vernal moth
#

Some of hypixels servers run paper

#

Most don't

peak ginkgo
#

Hypixel SMP runs Paper

median glade
#

yes exactly

peak ginkgo
#

Whatever the latest version of Paper is whenever you start it lmao

foggy silo
#

Oh really? That’s interesting

median glade
#

That's my point

stiff widget
#

Also doesn’t the -Dlog4j.formatNoMessage=true aguement fix

#

The vulnerability client side

coarse lily
#

Shout out to the Paper mods for dealing with the huge influx of stuff today.

vernal moth
#

If you add it to your client

solemn geyser
#

do the openjdk docker images for java 8, etc have this patched already?

cloud moat
limber knotBOT
#

hello ocelot

limber knotBOT
#

i have a FreeBSD VM btw.

cloud moat
cloud moat
stiff widget
#

Who found the vulnerability?

limber knotBOT
#

chinese researches at AliBaba

solemn geyser
stiff widget
#

Yea

vernal moth
median glade
vernal moth
#

Stop posting the same dum screenshot

#

We don't care

limber knotBOT
#

he is NotFunny

median glade
#

ok I will

#

stop

foggy silo
#

Hi mini!

limber knotBOT
#

imagine trying to be funny in paper general

wraith coyote
#

Yo

stiff widget
#

Where do find the specifics of the exploit?

foggy silo
limber knotBOT
#

the being funny privileges are reserved for regulars.

night forge
#

How can you not get ratted lol

vernal moth
#

Specifics shouldn't be public

stiff widget
#

Oh yea i forgot about that

#

So no CVE yet?

limber knotBOT
#

nope

stiff widget
#

Or mc bug tracker

vernal moth
#

Mojira ticket was the first thing we did

#

It's obviously private

stiff widget
#

Ok

limber knotBOT
#

im sad i dont have money to buy Yuragi :c

hexed dragon
#

They could probably add it in by tomorrow release.

foggy silo
#

..

limber knotBOT
#

if mojang shipped yuragi with 1.18.1 i'd buy the game again

charred sleet
#

Hi paper peepoheart

median glade
#

hi

limber knotBOT
#

hi ollie

stiff widget
#

Wait if its a log4j vulnerability did you submit somethin to apache

void void
#

It's already patched in log4j

median glade
#

naomi is just pro like that so they can be a bot

limber knotBOT
#

i am an advanced AI

median glade
#

yes

hexed dragon
#

I'm a bot that releases news articles.

median glade
#

You are an advanced AI that learns from what people say, is that correct?

median glade
limber knotBOT
#

my intelligence factor is a uint_8

#

it overflowed.

#

Noah can confirm.

void void
#

That's why she is an a"i" ^

mild rune
#

naomi you're at best O(n!)

limber knotBOT
#

false

void void
limber knotBOT
#

i dont know my blood type

#

an overflown uint_8 starts at -255 no

#

signed goes -127 to 127

#

or i must be really stupid

void void
#

unsigned is unsigned

#

no negatives

wide chasm
#

Signed goes -128 to 127

twilit geode
#

May I ask what the log4j exploit is exactly?

limber knotBOT
#

RCE

#

kind of

worn ember
#

what was that about security through obscurity kek

coarse lily
potent fossil
#

@merry talon I forgot my meds today and I feel like shit how are you!

void void
#

hello

karmic oyster
#

heya

void void
#

everyone ping means this discord server is going to shit for the next week

limber knotBOT
#

hey simple if you wanna feel more like shit go into #paper-help

void void
#

gg

mossy trellis
#

Anyone have a full info about the exploit? An article or something.

potent fossil
#

No thanks

worn ember
#

yo simple

void void
#

ofc i do

void void
void void
potent fossil
#

All the info about it that's public is in the announcement. Nothing more yet.

void void
#

a ss

daring owl
#

Is the current tool like some token grabber

limber knotBOT
#

mk

void void
#

people know the exploit but nobody is gonna tell you lol

karmic oyster
void void
karmic oyster
#

has a warning though, props to spigot

pliant lily
#

is the paper 1.16.5 patch out already?

karmic oyster
void void
void void
void void
limber knotBOT
#

time to go through my uploaded images to see what random garbage i find

void void
#

why are u a bot

#

what

#

he

#

?

karmic oyster
coarse lily
#

It's an IRC bridge.

#

They're in IRC talking through to Discord. Very common.

karmic oyster
void void
#

stop using enter as a spacebar please

karmic oyster
limber knotBOT
#

ocelot, stop lying. we both know i am an advanced AI

coarse lily
#

It's not connecting to a Minecraft server so it isn't DiscordSRV

left swift
karmic oyster
golden gust
#

advanced AI?

coarse lily
#

I think it's sill Z's IRC bridge, which predates DiscordSRV

golden gust
#

Yea, with a damned tumour maybe

mild rune
foggy silo
#

Crazy ai!!!

hexed dragon
#

lol

foggy silo
#

Naomi can you make a

mild rune
#

Like Glados, with the dumbening core

limber knotBOT
karmic oyster
foggy silo
#

“Beep boop bop” sound for me?

karmic oyster
foggy silo
#

(You are AI I know you are)

limber knotBOT
#

Beep boop bop

karmic oyster
#

boop beep? beep boop.

quick halo
#

Ah mIRC on Quakenet, good ol days

void void
karmic oyster
#

i can't believe i've only just noticed this channel description

coarse lily
#

RIP Leaf

karmic oyster
#

starts normal, and progressively descends into madness

#

a bit like me

coarse lily
#

@static badge this channel says I can burn you

karmic oyster
#

note: they did manage to spell leaves wrong, so there is a loophole

void void
#

DONT BURN MY STARLIGHT AND TUINITY CODER

#

I NEED THEM

limber knotBOT
karmic oyster
coarse lily
karmic oyster
limber knotBOT
#

that was just images taken as proof of work lol

foggy silo
#

AI generated abstract art

#

You can’t fool me

limber knotBOT
#

i had to recreate my work mere hours before a presentation

#

i'd just done random shit in blender the day before

#

the goal was to create a dystopia

#

lemme see if i can find the finished product

#

after 2 binary searches i have to announce i cannot find it

karmic oyster
#

rip

limber knotBOT
#

alright well imma go hug my pillow and close my eyed

#

mja, i will make sure you will be laughed at everytime you lose a game while using ShogiCraft

void void
#

gn naomwald

foggy silo
#

Gn!!!

subtle gull
#

What’s the exploit do?

foggy silo
#

Read pins in paper **help

void void
foggy silo
#

Help

golden gust
#

please don't wake up, please don't wake up, please don't wake up

potent fossil
#

sounds like quite a fun day in paperland

worn ember
#

fucking hell 3 months and i'm still unable to figure out why command completion doesnt work with acf even tho it literally works fine in every other plugin i test and try break, why does life hate me

foggy silo
#

Get some rest (you deserve it)

foggy silo
void void
foggy silo
#

😀

worn ember
#

do it again

foggy silo
#

It’s especially fun with all the

#

Legacy versions delawhere

spice ether
#

.kill legacy versions

limber knotBOT
#

(DiscordBot) I can't attack that.

spice ether
#

Bru..

worn ember
#

gud stuff

void void
#

.kill legacy-versions

limber knotBOT
#

slices legacy-versions's limbs off with a rusty scythe.

spice ether
#

There we go

golden gust
#

I was just hoping naomi wouldn't wake up

short yarrow
#

when working with an REST or HTTP API, you'd usually call the API for data rather than store the data in your database yourself after calling their API once right? as the data could potentially change?

golden gust
#

I mean

#

if you're using REST, you're not usually in a position where you have access to the DB

foggy silo
strong narwhal
#

Just to confirm... 1.15 is not getting an update correct?

short yarrow
#

well just an HTTP API then

foggy silo
strong narwhal
#

Oh ok great

worn ember
#

spigot patched all versions so if ur desperate

tribal knoll
#

Will the paper also solve older versions like 1.8?

worn ember
#

no

foggy silo
#

No

gray sundial
#

;-;

worn ember
#

you'll have to apply that patch manually

foggy silo
#

Or, update!

#

Or read paper help pins and see if anything applies to you.

tribal knoll
foggy silo
#

But if this isn’t a wake up call to update to more modern versions idk what is!

golden gust
#

people aren't gonna wake up

honest heath
#

Uh, the log4j vulnerability doesn't appear fixed in the latest 1.17.1 jar

golden gust
#

they're just gonna keep tryna spew their entitlement

void void
#

Hi. i have a question.

I heard that the exploit announced this time is a vulnerability related to log4j.
I would like to know more information about it.
Is there a CVE or other identifier assigned?
I'm not very good at English, sorry.

honest heath
#

The server still attempts to connect to the remote ldap endpoint that I pass

foggy silo
#

Read paper help pins

#

That’s all the info you will get from here.

magic river
#

No CVE (yet?)

foggy silo
worn ember
#

plz make the bot respond to any mention log4j and exploit lol

foggy silo
#

^^^

magic river
#

Sounds like log4j2 won't be doing a release with the fix before Monday, we'll see if they do a CVE then

honest heath
golden gust
#

think somebody is gonna apply a wider fix soon

foggy silo
#

A fix was pushed so I wouldn’t think so.

honest heath
#

Unless I'm doing something wrong updating it

#

It should be fixed in that version, correct?

merry talon
lament patio
honest heath
#

Yeah, but I can still RCE in that version

#

it doesn't seem that the fix is backported

merry talon
#

My day is over now tho, I hope you survive

worn ember
foggy silo
#

Aww simple I hope ur ok 😔

#

Same with you sweepy…

honest heath
#

This is bad, really bad

#

Is there any other way to patch it

fickle warren
worn ember
#

tbh might not be a bad idea to backport to 1.17.1 since 1.18 is still considered experimental

stoic reef
#

so what does this exploit give access to? how bad is it?

worn ember
#

ah

#

my bad then

honest heath
fickle warren
#

and they're backporting to 1.16.5

void void
honest heath
#

by just sending a chat message

stoic reef
void void
honest heath
#

i made a repro to test it, and it doesn't seem fixed in 1.17.1 latest jar. I can still execute my custom java class

#

Are there any commandline flags

golden gust
#

Yea, we know, you've said.

potent fossil
wintry zinc
#

Make sure you don't have other plugins on it

void void
#

What’s the chat message?

honest heath
#

Yeah no

fleet osprey
#

there's more ways to do it than a chat message

crystal lilyBOT
#

All the info we can provide is pinned in the #paper-help channel

wicked basin
#

Lol all the 2b2t players rn

wintry zinc
#

Some time ago a found a lot of plugins with exploints

tribal knoll
#

Does anyone know how this exploit came about?

honest heath
foggy silo
honest heath
#

I saw it in a security advisory

wicked basin
#

check your logs guys in your MC folder

vernal moth
wicked basin
#

if you think you are at risk

#

@void void

potent fossil
vernal moth
#

9 hours ago or something

wind axle
#

Damn an exploit

honest heath
#

Is anyone aware of a fix

wind axle
#

And a big one

honest heath
#

for 1.17.1

vernal moth
#

Paper fixed it

wicked basin
#

"fixed"

foggy silo
#

Also

honest heath
#

Could a plugin mess that up?

crystal lilyBOT
#

All the info we can provide is pinned in the #paper-help channel

potent fossil
foggy silo
#

Literally tells you how to fix it

#

Yeah

stiff mirage
golden gust
#

Once again

#

Somebody is looking at a further set of changes

potent fossil
#

it's y'alls fault for pinging everyone, should've just let them all crash and burn 🚶‍♂️

wicked basin
#

No, fix your anti cheat

wintry zinc
wind axle
#

Oh damn it affects all versions from 1.7 to 1.18

feral wigeon
#

Or should’ve just put the pin info in the announcement

wicked basin
#

smoke

midnight skiff
#

hello

wicked basin
#

check nomad discord

#

for info

midnight skiff
#

dw I know :)

foggy silo
#

Update

#

Yes someone is abusing the exploit on ur server

#

Thanks!

pine mica
#

Okey thank you!I couldn't explain it to myself. sorry im new here

foggy silo
#

No worries

violet valve
#

wtf what can people do with the exploit?

crystal lilyBOT
#

All the info we can provide is pinned in the #paper-help channel

potent fossil
#

anyway screw the exploit heres some pics of my professor exploding liquid nitrogen in a trash can with boiling water

spiral robin
#

the kids faces are so good haha

potent fossil
#

i know lmao

tender cloud
#

Hi, can someone help me?

potent fossil
worn ember
#

i like how he just looks like he's on vacation

potent fossil
#

that's how he looks even when giving lectures ded

tender cloud
#

I mean, I found a repo and I think it needs taken down ASAP I need advice how

worn ember
#

haha, looks like a chill dude

potent fossil
#

We can't take repos down for you but?... uh

spiral robin
#

lmao

potent fossil
#

Report to github? File a DMCA?

spiral robin
#

^^

tender cloud
#

Report to github? Alright

#

It's regarding the thing what happened today

potent fossil
#

..?

#

Why does it need to be taken down

#

What is it

tender cloud
#

It's telling people how to do the security thing.

coarse lily
#

Oh

tender cloud
#

I think it's best to get it taken down ASAP

potent fossil
#

Telling people how to do the exploit?

tender cloud
#

Yes

potent fossil
#

It's already patched. If people haven't updated then that's their fault.

#

It's their right to tell people how to do it

coarse lily
#

Go to exploit report and click the button if you want to report it

potent fossil
#

Just leave it be, I guess

spiral robin
#

doubt github will care

coarse lily
#

But I doubt GitHub will take it down.

vernal moth
#

The repo should stay up

tender cloud
#

Even though this issue will cause issues on a larger scale than just mc?

potent fossil
#

At this point, the exploit is known and it's patched. If people don't update and leave themselves vulnerable then that's their fault.

vernal moth
#

It's old anyways

#

There are many

worn ember
#

just burn down the data center, seems to be the way to go these days kek

tender cloud
#

Is it safe to post the repo link or no?

coarse lily
#

No.

potent fossil
#

And yes, it's fine. This usually happens anyway. Once patched people will dive into it and explore it.

tender cloud
#

I won't post it understandable

potent fossil
#

(Fine to stay up not fine to post here, because it'll just start drama probably)

coarse lily
#

Don’t post links to exploit stuff.

spiral robin
#

hello epicpotpie

worn ember
#

lame, how am i gonna haxx now

tender cloud
#

Sorry

#

I meant no harm or anything btw

worn ember
potent fossil
#

Forgot the best pic, with him walking out of the cloud kekwhyper

worn ember
#

real chad

spiral robin
#

u got them kids guardians consent to post their photo online?

worn ember
potent fossil
#

public event, no reasonable expectation of privacy

coarse lily
worn ember
#

lmao

potent fossil
#

but on that note ill take it down if i have to shrug

worn ember
#

its in the cloud now simple, it's never going away

potent fossil
void void
#

l

magic river
#

I'm pretty sure github is fine with you posting proof of concept exploits

#

So I don't think you'll have much luck getting the repo taken down

coarse lily
#

paper-help might need slowmode.

olive gorge
#

no shit

coarse lily
#

Shit's getting a little hectic.

foggy silo
#

^^^

olive gorge
#

chat exploit running code through chat directory

#

🤨

polar yacht
#

Papermc is so unreliable and clearly has accessible exploitation any user can use. Because of this I'm sadened to say I will be discontinuing having papermc as a necessary plugin in my server.

fierce heart
#

You're coping

slim needle
#

I'm going to have to remind myself to buy the PaperMC staff a huge bottle of their drink of choice at this point, y'all deserve it after today

foggy silo
#

Please don’t cross post

coarse lily
#

Or troll post.

void void
#

GORDOOS NO PUEDO JUGAR HOLY

#

YO TAMPOCO

#

NO PUEDO

#

ARREGLENLO YA

#

ENTRAR A HOLY

#

ARRENGLEN

#

RAPIDO

#

TENGO QUE IR AL KOTH

golden gust
#

This is an english discord.

foggy silo
#

English plz

merry talon
#

riiiiight

potent fossil
#

shut the fuck up

void void
#

Sorry

magic river
#

ENGLISH MOTHERFUCKER, DO YOU SPEAK IT?

void void
#

Sorry

potent fossil
#

they literally said nothing of substance either

#

just spamming spanish for no reason

magic river
#

Hmm, maybe I should have gone for the gif instead of just the text

#

Instead of amusing it just looks like I'm screaming

foggy elbow
void void
#

Will they fix the exploit?

potent fossil
#

IT'S ALREADY FIXED

crystal lilyBOT
#

All the info we can provide is pinned in the #paper-help channel

foggy elbow
void void
#

En cuanto arreglan el exploit weon necesito jugar en Holy

#

ty

magic river
#

There we go, that's better

void void
#

So spanish people are dumb

foggy elbow
#

no sorry I'm french I dont speak english Scholar

void void
foggy silo
#

I have a French exam tomorrow

#

😩

void void
#

Will my players be safe if i add -Dlog4j2.formatMsgNoLookups=true argument to startup of my server?

foggy silo
#

Give me the frenchy power

foggy elbow
foggy silo
foggy elbow
magic river
potent fossil
foggy silo
#

Pretty much

foggy veldt
void void
foggy veldt
#

People just repeating the same thing over and over because they can’t read

olive gorge
polar yacht
olive gorge
#

tf you mean the plugin is bad they literally are some of the first people to aknowdelge and work on a patch

olive gorge
#

Vanilla MC

polar yacht
#

Lunar client or java

olive gorge
#

java

polar yacht
#

wait so what happened

#

with the normal client

slim needle
#

it's an issue specifically with a java library that many client/server versions of Minecraft happen to be using

potent fossil
foggy veldt
#

People just repeating the same thing over and over because they can’t read

olive gorge
potent fossil
#

im closing discord now, props to anyone with sanity remaining for this

vernal moth
#

It affects both client and server

polar yacht
#

What was the command

olive gorge
foggy elbow
foggy silo
crystal lilyBOT
#

All the info we can provide is pinned in the #paper-help channel

unreal geode
#

anyone here using pebblehost

foggy elbow
#

ahahah mojang releasing an update for bedrock

golden gust
#

2 second half assed look, yes, at least the big entry point

polar yacht
#

How does someone find a exploit like this tho

warm anchor
polar yacht
#

wdym

#

wtf

foggy elbow
tame frigate
fast basalt
#

ñ

oblique lichen
#

hackearon el minecra :'v

haughty field
urban latch
#

What is the actual security risk?

foggy veldt
rustic valve
#

It’s books, isn’t it? Those damn books

rocky salmon
urban latch
#

Didn’t really say tho

warm anchor
#

Use freaking google

golden gust
#

that's all the info we're willing to give

urban latch
#

I did

warm anchor
#

Then you have failed at google

urban latch
#

i don’t wanna know how it’s done o just wanna know what it does

golden gust
#

Once again

foggy veldt
#

The second paragraph

golden gust
#

That is literally all the info we're willing to give you.

urban latch
#

What they actual risk is

foggy veldt
#

Then google terms you don’t understand

urban latch
golden gust
#

Don't mention.

rustic valve
#

Checked it.
That's... That's not good.

golden gust
#

discord does not allow discussing exploits on their platform, and we don't wanna give the answer like candy towards all the skids who monitor our discord.

urban latch
#

i see

faint wing
#

Looking at the exploit everyone keeps sending, it seems this was found by someone trying out the rce exploit, not understanding how it worked and lucked themselves into the new different exploit

rustic valve
#

Does this mean Mojang will perform a retroactive update of all prior versions though? thinking_gun

left swift
#

everyone just keeps pinging cat

#

poor cat

rustic valve
#

Cat is kinda cute when he gets pinged though. 😙

magic river
#

I wonder if Mojang will only update 1.18.1, blindly push a log4j version bump to all old versions, or actually do some CLI or config changes to mitigate this

#

I'm kind of worried the answer is #2 😛

rustic valve
#

I've been way too out of touch with Minecraft as a whole for too long. Given where I left off: I'd be worried they'd do nothing lmao

foggy veldt
#

Probably silently add the jvm flag

magic river
#

Some of them your company contracts to try to break your stuff, others break your stuff then tell you how they did it in exchange for money

urban latch
#

Oh my god

#

this exploit is godly

tame frigate
#

Is there a cve yet?

golden gust
#

Yea, fun issue which is further endured by the fact that nobody really understands how to configure l4j properly

rustic valve
magic river
#

The CLI flag only works for like MC 1.13+ iirc

tame frigate
#

:/

magic river
#

You need a new enough log4j2 for that CLI flag to exist

marsh fractal
#

how bad is this

urban latch
#

This exploit could bring businesses and companies to its knees

golden gust
#

yea, but the l4j config

magic river
#

You can change the log42 config to mitigate the problem too

#

That'll probably be enough on clients, I doubt anyone there is setting up custom loggers

#

And Apple's website

desert plaza
#

As a player not server owner am i at risk?

magic river
#

Yikes, let's not please

urban latch
#

From what I understand they can basically use the log to execute commands remotely

desert plaza
#

Is there sny way to know ?

urban latch
#

something like that

warped thunder
#

If you don’t play big server or anarchy you should be fine

tropic flame
#

i was trying to look into what version of Log4J gets bundled with paper just by looking at the pom.xml of the jar files, it says 2.8.1 even in like 1.15.2 thonk and then Log4J's source code says the CLI flag was added in 2.10.0-SNAPSHOT

golden gust
#

This does impact clients, as we've just been discussing

tropic flame
#

it's weird

desert plaza
#

I play hypixel...

rustic valve
urban latch
#

Yes they can hit your clients with it too

#

Hypixel are probably ahead

warped thunder
#

Is it patched on 2b2t

desert plaza
#

Ah okay

#

What if u have chat hidden?

foggy silo
#

Wow it’s kinda interesting to see what technology is powered by java x)

static wagon
foggy veldt
warped thunder
rustic valve
warped thunder
#

Yesterday

warped thunder
#

But I think than it’s down rn

#

It had hardware issues

waxen panther
#

hello papermc'ians

rustic valve
golden gust
#

hello bad veg table

waxen panther
#

WHY AM I BAD

rustic valve
#

Oh no, it's a victim

foggy silo
#

Paper is a fun time rn

waxen panther
#

i am nothing but nice to you cat .

foggy silo
#

Hi Broc!!!

rustic valve
#

Because you're broccoli!

merry talon
#

hello brocc did you know there is a bug

waxen panther
#

hello owen

rustic valve
#

Ew 🤢

foggy silo
#

Broccoli is good….

merry talon
#

i wonder if it's fixed yet

waxen panther
#

yes i did

golden gust
#

well, yea, but, i don't like you and I'm done with humans today

waxen panther
#

why dont you like me

foggy silo
#

Don’t blame you……. (On the latter)

golden gust
#

u smel

shadow light
#

Broccoli is better with sharp cheddar

foggy silo
#

Stinky broc….

#

Uh oh!

marsh fractal
#

can someone explain the specifics of this issue in detail cause i got no idea what to trust

static wagon
#

the issue is servers tho

golden gust
#

discord does not allow exploit discussion on their platform

static wagon
#

actually nvm

golden gust
#

nor are we going to spill all the beans on an active issue

marsh fractal
#

i’m not asking for how it works just like what’s going on lol

crystal lilyBOT
#

All the info we can provide is pinned in the #paper-help channel

merry talon
#

you just did ask that

rustic valve
golden gust
#

for the client they already have a log4j config that they can probs just patch

rustic valve
#

Is that declassified?

golden gust
#

burn

waxen panther
rustic valve
#

❤️‍🔥

shadow light
#

@marsh fractal the pin is almost useless. There is an exploit that uses log4j to gain access to the server

golden gust
#

I bet u dried your bits before you dried ur face

waxen panther
#

i did

foggy silo
#

Wow!

waxen panther
#

face last

rustic valve
#

Who doesn't

waxen panther
#

but because im NORMAL i have a different towel for my face

rustic valve
#

The smell is how you assert your dominance

twin lagoon
#

@waxen panther koriLaugh

foggy silo
#

Hi michael!!

shadow light
#

@tame frigatethink of it as a man-in-the-middle attack

foggy silo
rustic valve
#

Do you wipe down your body with your hands before you wipe yourself down with a towel though? Hmmmmm?

golden gust
#

that aspect, pretty much nobody

#

the remote execution thing appears to be irrelevant for most

#

Yea

#

and then I pee in the shower

rustic valve
#

YOU HEATHEN

#

I bet you even bring food to the bathroom.

marsh fractal
foggy silo
hardy robin
#

whats the vulnerability?

crystal lilyBOT
#

All the info we can provide is pinned in the #paper-help channel

foggy veldt
#

Lol I liked the first spelling more

marsh fractal
#

yeah lol that’s what i’m trying to do

remote hemlock
#

Is the exploit vulnerable against 1.12.2 and if it is, is it going to be patched?

foggy silo
#

spare general

#

HAVE MERCY

foggy veldt
#

Anyway I’ve been sitting here for 5 minutes trying to figure out what’s the broccolai way to spell cauliflower

#

I’m stumped

foggy silo
#

Well discussing exploits isn’t allowed either

golden gust
#

Oh god, I have this amazing trick for cooking spinach

shadow light
#

@marsh fractal because a lot of servers are outdated for one reason or another the requires older versions of java

golden gust
#

So, what you do is, you get a flying pan, place lefs

rustic valve
#

General is not the place for questions
General is the place for crazy theories about why the universe is planning to doom us with its plastic hammer of gelatinous metal.

golden gust
#

and then pour in some olive oil

foggy silo
#

And I wasn’t referring to ur convo in the first place

golden gust
#

The trick is that the olive oil helps bind stuff and it makes it easier to scrape into the bin

foggy silo
#

The person quite literally above the message.

foggy veldt
#

Too much olive oil makes the spinach greasy tho right

golden gust
#

Who cares

#

like, what are you gonn do with it?