#general

3141 messages · Page 1799 of 4

ashen cliff
#

¯_(ツ)_/¯

mental meadow
#

Please don't post false and potentially dangerous "advice"like this

magic river
#

Wait when did @coarse lily turn red?

coarse lily
#

Your eyes are failing, old man.

mental meadow
#

He was too flustered from you

ashen cliff
outer patio
void void
#

i put 5+ hours of research into this i know what im talking about

coarse lily
#

It's extremely easy to trigger the exploit.

#

If you know what you're doing.

autumn glen
#

I spent 15 minutes to find what I was looking for.. maybe you are in the wrong path 😂

coarse lily
#

Everyone should update their servers and restart their clients for the fix ASAP.

static badge
#

i put 5+ hours into my shitposting daily

ashen cliff
#

Same.

#

And I already dumped the server specs.

#

🛌

limber knotBOT
#

krusic bro!

ashen cliff
#

Bro.

#

Daily reminder that you can't msg yourself!

limber knotBOT
#

it is friday morning bro!

ashen cliff
#

Fact.

mental meadow
coarse lily
mental meadow
#

Earlier versions of the article called it a Minecraft bug

void geyser
#

really enjoyed reading the issue in apache's github repository for log4j

mental meadow
#

We do love some responsible disclosure

ashen cliff
#

It's interesting that we wouldn't have this issue, if we knew that this option existed and was enabled by default. Since, most people don't have a use for it anyway.

ashen cliff
#

Bro.

meager tusk
#

Wanted to patch KGBPaper.

#

Found nothing to patch.

ashen cliff
#

Daily reminder.

meager tusk
#

We patched this years ago.

void void
#

rce no

meager tusk
#

lol

ashen cliff
#

Idriz bro.

#

Don't tell them.

meager tusk
#

Ok bro.

limber knotBOT
#

Idriz what version is KGBPaper on currently?

#

Asking for a friend.

ashen cliff
#

1.18.1 (2).

muted stratus
#

penis :)

potent fossil
#

ok

limber knotBOT
#

i thought KGBPaper was on 1.20 already

potent fossil
#

ur mom is on 1.20 already

ashen cliff
#

That's the KGBPaper Red members exclusive build.

muted stratus
potent fossil
#

Ok you can stop being a shit-tier troll now

#

Turn up the heat or go away

muted stratus
#

:c

limber knotBOT
#

memes go in #gifs-and-memes

#

shit memes stay in your gallery

muted stratus
#

I'm not a troll just wanted to post memes

muted stratus
magic river
limber knotBOT
#

reading hard

#

and ye i just saw this

crimson harness
#

Hi

limber knotBOT
#

oh shit i totally forgot im on the 727 bus rn

ashen cliff
#

That was fun.

swift root
#

bro, it's internal

#

you need to take it to a psychologist

ashen cliff
#

Yeah.

limber knotBOT
#

or a&e

#

depending on what it is

ashen cliff
#

Looks like Forge 1.6.4 doesn't like that. kekwhyper

#

Bruh. It legit runs regex, if you do that. kekwhyper

limber knotBOT
#

nice

peak ginkgo
#

which one for 1.18 and how much ram is overkill

#

money means nothing just help me pick lmao

#

(this is bloom.host)

swift root
#

money means nothing?

#

go with the best

peak ginkgo
swift root
#

all the time hands down

limber knotBOT
#

buy hw yourself ez

swift root
#

if money is no object just pay exorbitant amounts and be sure you've got nothing to worry about

peak ginkgo
#

the hypixel solution

clear mulch
#

the log4j bug allowed hackers to gain access to players' computers?

swift root
#

if this was syscraft I'd be !whichhost-ing you rn though. MORE DETAILS

crystal lilyBOT
#

All the info we can provide is pinned in the #paper-help channel

peak ginkgo
swift root
#

that's the lineup

crystal lilyBOT
#

All the info we can provide is pinned in the #paper-help channel

peak ginkgo
#
  1. idk a lot? maybe max 25 after the hype downs down
  2. vanilla
  3. Los Angeles, or anywhere US West really
  4. Hopefully no more than like $50/mo
  5. 1.18
swift root
#

pure vanilla or paper 👀

limber knotBOT
#

Paper

#

I also just joined on irc to join #syscraft

swift root
#

you'll want syscraft-mc

limber knotBOT
#

thanks left the other one

swift root
#

or mayhaps syscraft-hosting, i think that's the one for the hosting discussion channel

#

I haven't IRC'd for a while

limber knotBOT
#

hey another irc friend

swift root
#

have something against like... discord?

limber knotBOT
#

yes, they suspended my ass

peak ginkgo
#

was easier to just pop open thelounge and join #syscraft

limber knotBOT
#

true

swift root
#

:DDDDDDDDDDDD

limber knotBOT
#

effort

#

i can join syscraft from the invite in the topic

hexed dragon
#

The dates for version above snapshot 17w15a have been updated.

limber knotBOT
#

i peek into the computer science classroom just to see someone in photoshop with a kekw

ashen cliff
chilly hearth
#

How is it possible Microsoft wasn't aware of this? 😵

ashen cliff
#

Well. They aren't omnipotent.

hexed dragon
#

For the launcher versions the snapshot 13w37b switched with 1.6.3 in the order.

mental meadow
chilly hearth
#

Ahh, I see. Well I must admit you guys have fixed it really quick.

magic river
#

ShellShock existed for 25 years before being discovered

#

Sometimes things just get overlooked

#

Vulnerability was added in Bash 1.03 in 1989, not discovered (or not disclosed anyway) until 2014

warm gulch
#

how long has this been used for?

magic river
#

It was reported about a month ago to the log4j folks, they fixed it 5 days ago, everyone else just found out in the last day or two

#

It's known there are bots sweeping the internet looking for things to exploit now but not when/if they were before it was public

warm gulch
#

mhm, i thought maybe i was safe since i hadn't played mc for 2 weeks but i'll look trought my files to see if i got it, thanks for your anwser!

void void
radiant oriole
#

you will not see the message in the logs unless you patched

mental meadow
#

oh poggers I got retweeted by sliced

#

I'm fame now

void void
#

so the message will be there

radiant oriole
#

No, it will not.

void void
#

at least on the client

radiant oriole
swift root
#

also read the pin there

void void
#

i have read the pin there

swift root
#

we won't tolerate authoritative sharing of fake news about this exploit

warm gulch
#

they told me you can not see the message if the person knows what they are doing

radiant oriole
#

the pin has been updated several times in the past 2 hours alone

warm gulch
#

so i believe them

void void
radiant oriole
#

it is.

void void
#

never knew how toxic this community is

swift root
#

I don't get why people who haven't been testing and working alongside the entire community of Paper developers for a full day about this issue want to override those who have

#

We know that logging can be prevented

radiant oriole
#

You're spreading the misinformation. I've been working on this exploit for literally 17 hours. I know how this thing works and I know exactly how it can be exploited to the worst. It's absolutely possible, and VERY EASY to remove it from the logs.

swift root
#

Anyways, we try and be kind to people but we've also been dealing with this sorta stuff since it started, and our patience wears thin. We strive to give you the most accurate and useful information possible, take us at our word that we've ensured we aren't lying.

mental meadow
#

With things like that, dismissing it or not being cautious enough can quickly backfire. Just a few hours ago we were pretty sure RCE is only an issue on really old Java versions, now we know that is not the case. It is always best to be more careful while these things are still developing

limber knotBOT
#

is the CVE out there yet?

swift root
#

doubt

radiant oriole
#

CVE is not yet published

mental meadow
#

The number is reserved, but the details are not public yet

limber knotBOT
#

yeah just found it on github

mental meadow
#

a nice number to remember

#

44228

limber knotBOT
#

yep

#

we blame 44228 for my lack of sleep tonight

ashen cliff
#

Based.

viscid wedge
#

Is who disclosed it public information?

mental meadow
#

I think Alibaba?

ashen cliff
#

Wouldn't surprise me.

mental meadow
#

"in November the Alibaba Cloud security team disclosed a vulnerability in Log4j2"
from the ars technica article

viscid wedge
#

I'm reading that now too

#

The scale on this is rather unfortunate

mental meadow
#

It's a severe security exploit in a widely used library

#

Not really surprising that it affects a lot of things

ashen cliff
#

Just hope everyone updates in time. Shellshock also had a huge scale and we mostly survived that without incidents.

mental meadow
#

Yeah, I'd say this is maybe a level below Shellshock and the likes, because this is not in a "standard" library that everyone uses, only in a library that a lot of people use

pulsar sinew
#

There a dedicated channel for discussing PRs to papermc.io itself?

mental meadow
#

No, but I saw your PR

pulsar sinew
#

oki

mental meadow
#

Did Github really remove that? :/

#

annoying

limber knotBOT
pulsar sinew
#

yep

#

which is a shame, because legacy support is nice

#

and having one link to auto resolve mentioning issues or PR numbers was nice

#

darn

#

@ person on IRC (?) I assumed #paper-dev was just for the server itself

limber knotBOT
#

i'd say they're closely related enough to fit in the same channel

pulsar sinew
#

I guess?

#

PR already got seen anyway, dont have to ask about it

#

and its not like its a breaking issue anyways

#

you can still download builds

limber knotBOT
#

sitting in cafeteria

#

hear SUPER IDOL DE XIAO RONG behind me

#

resisting the urge to sing along

tropic flame
#

absolutely based place you live in, naomi

#

in fact we should use the new Log4J exploit to play super idol de xiao rong in everyone's clients kekwhyper

limber knotBOT
#

SUPER IDOL DE XIAO RONG DOU MEI NI DE TIAN BA YU ZHENG WU DU YANG GUANG DOU MEI NI YAO YEN

#

YAN*

#

do i need to go on

mild rune
#

Naomi it’s past your bedtime

#

Also where did your pfp go

limber knotBOT
#

oh no

#

did my discord account get yeeted?

mild rune
limber knotBOT
#

that'd be shit

mild rune
#

It doesn’t show in the mentionable people

ashen cliff
#

What did you even do?

limber knotBOT
#

literally existing

ashen cliff
#

There you go.

mild rune
#

She existed too late

peak ginkgo
#

@swift root

#

no

swift root
#

wat

#

oh

peak ginkgo
#

no

mild rune
#

Looks like you’re not deleted naomi

limber knotBOT
#

yeah my account still exists

mental meadow
#

@wispy blade is still hhere

limber knotBOT
#

just checked

peak ginkgo
#

takes 30 days

#

after 30, give it a role or something

#

it'll leave the server

mental meadow
#

let's hope we don't get to that point lol

limber knotBOT
#

yeah im gonna change my discord username to xxnaomibhop2021xx

#

nah i reach the age of digital consent in my country in 3 days so all good

ashen cliff
#

So you can consent to the deletion of your account?

mild rune
#

Still can’t believe someone reported you lmfao

limber knotBOT
#

having a role in papermc would be pretty cool

#

how about "The GPT-3 Instance"

#

might have to bribe mini in exchange for a beer

mild rune
#

Lmao

#

Just donate money for a heart

limber knotBOT
#

Kacper did it

#

why can't

#

i

#

i pressed enter too early why am i this bad at typig

mild rune
#

Enter is not a substitute for a space bar smh

limber knotBOT
#

i know, enter does not make you jump

swift root
#

man i love all the cybersec experts crawling out of the woodwork to tell us all we're incorrect about everything

mild rune
#

Everyone an expert on the internet

limber knotBOT
#

if i wanted to talk cybersec i'd call ZOLDER BV

mild rune
#

I find it funny people are confidently incorrect

limber knotBOT
#

Zolder is cool

radiant oriole
limber knotBOT
#

get em kevin

#

show them your intellect

bleak anvil
#

How many time do people threaten to leave Paper every day in #paper-help? Can we get some stats on this? I've seen it three times today

mental meadow
#

Too many

limber knotBOT
#

~2/week

#

on average

mental meadow
#

You should see how many instantly leave after I ping everyone

swift root
limber knotBOT
#

what was their name again

#

this one kid that pinged literally every staff member

mental meadow
#

sad that Discord only updates the metrics once a week or so

limber knotBOT
#

it's discord

#

they are suffering from scale

olive marlin
#

Naomi when?

limber knotBOT
#

when what

olive marlin
#

I believe waterdrunkgirl or whatever it was, when they got banned.

limber knotBOT
#

no they also pinged a now banned user

mild rune
#

I’m off to sleep. Night everyone. ❤️

hexed dragon
#

The discord snowgiving server getting 4K boosts

bleak anvil
mental meadow
#

Today 381 users left this discord, and 1541 joined (o.O)

tropic flame
#

is the fix for 1.12+ clients by Mojang also apply to modded clients, or is it only for vanilla?

mental meadow
#

Naomibot lol

bleak anvil
#

Wow that's nice

limber knotBOT
#

i am NOT a bot

#

i am a self-contained advanced AI to have conversations with

stray oyster
#

Are you sure about that

limber knotBOT
#

pretty darn sure

ashen cliff
#

Yes.

mental meadow
#

damn I wanted to make a joke but I forgot Naomi is like 5

bleak anvil
#

You know it checks out.

nAomI = nom AI

stray oyster
limber knotBOT
#

wtf aurora

stray oyster
limber knotBOT
#

i will not send you anime art i find on twitter and pixiv at all today.

#

just because of that

stray oyster
#

Naomi what’s your Line ID

limber knotBOT
#

dont have line

mental meadow
#

Line ID

#

spot the weeb

stray oyster
limber knotBOT
#

do have telegram

#

and signal

mental meadow
#

i don't think anyone ever messaged me on line 😦

stray oyster
viscid wedge
#

Sorry to drill the topic into the ground, but would remote class loading being off in the JVM neutralize this as well?

limber knotBOT
#

five, you're forgetting starcraft 2 ingame chat

stray oyster
#

Oh I’m not into starcraft

viscid wedge
#

I'm not a good Java dev, I'm just going off commits

radiant oriole
#

You'd think it would, but it doesn't at all.

limber knotBOT
#

is korean

#

not into starcraft

#

LITERALLY HOW

stray oyster
#

Who is Korean

viscid wedge
#

What else is needed to mitigate Kevin?

limber knotBOT
#

explain yourself xernium

radiant oriole
#

Not going to say.

viscid wedge
#

Oh, right. My bad.

stray oyster
#

I’m Austrian like aurora you pleb

viscid wedge
#

Yeah that was stupid in hindsight. I've been getting irritated with people asking that all day.

mental meadow
#

technically I'm german I just live in Austria

radiant oriole
#

I kinda want to do a writeup because of how cool this bug actually is but I gotta wait a while.

viscid wedge
#

I'd read it

mental meadow
limber knotBOT
#

no

viscid wedge
#

I don't have the energy

limber knotBOT
#

they can suck my

#

i gotta wait 3 days to make that joke

mental meadow
#

bad naomi

limber knotBOT
#

ther would not be much to suck so it's fine

stray oyster
mental meadow
viscid wedge
#

Damn

mental meadow
#

don't let me go through all bonks I have

viscid wedge
bleak anvil
#

My family is German does that count?

limber knotBOT
#

my great-great grandfather is belgian does that count

mental meadow
#

damn I don't have okayu bonk

#

sad

stray oyster
limber knotBOT
#

i'd whip out the monkegame sauce emotes but i'm lazy

#

338171

stray oyster
#

No you did not

limber knotBOT
#

yes i did

#

monkegame has sauce emotes, all from the same shitty venom x konosuba sauce

#

it's a thing that me and smertie do sometimes

#

we go to That One Website and click random a bunch of times and "rate"

tropic flame
#

konosuba
based

#

you read they're working on the third season, Naomi?

limber knotBOT
#

i dont care

#

komi.

void void
#

is 1.16.5 patched in server side and client side?

#

Naomi?

limber knotBOT
#

pretty sure they are

#

if you're on the latest verson

void void
quiet dragon
#

1.12.2 exploit fix updated?

tropic flame
viscid wedge
#

They're working on a third?

#

That's cool. I remember enjoying the first two a lot.

elfin steppe
tropic flame
# viscid wedge They're working on a third?
chilly hearth
#

?

mossy vessel
#

Let's not share these kinds kthx

chilly hearth
#

It was literally telling what it was and how to prevent it?

#

It wasn't anything wrong......

magic river
#

"what it is" is the problem

chilly hearth
#

Bruh?

magic river
#

iirc that video makes it clear what you do to exploit it

#

Unless that was a different one

chilly hearth
#

Well most definitely if you would have read the description....

magic river
#

Yeah that video is no good here

chilly hearth
#

Okay...

elfin steppe
#

i see some terminal stuff behind

magic river
#

Trying to avoid sharing how to do the exploit

elfin steppe
#

perhaps it demonstrates how to do it?

magic river
#

It does

chilly hearth
elfin steppe
#

yeah thats a no no

chilly hearth
#

But it wasn't showing it in a bad way.

magic river
#

Discord ToS potentially banned such things and it's just not a good idea anyway

elfin steppe
#

people can use things that are meant to be used for good to be used for bad

magic river
#

Maybe in a few days once things have settled and we have established fixes for everything and people have had time to learn about them

#

Then you can talk about "wow how dumb was this, you can just do X and trigger it"

chilly hearth
#

It's just funny to test it with friends on private servers, because you can learn from it.

magic river
#

But right now that's telling people how to use an attack that people are actively exploiting (and not just against Minecraft even)

limber knotBOT
#

shut up smertie

ancient zodiac
#

shut up bot naomi

elfin steppe
#

would mojang bother to backport the 1.18.1 fix to older versions tho (servers)

magic river
#

Probably not

chilly hearth
magic river
#

There are plenty of teenagers in this discord 😛

elfin steppe
#

yeah 1.8 and 1.12 servers are gonna get hurt from now on

chilly hearth
#

Most definitely. 😂

chilly hearth
#

It's already fixed, if you just use lunar client, or add a simple java startup flag.

magic river
#

Those would be the people who would enjoy using that to crash servers but don't know how to figure it out on their own

radiant oriole
magic river
#

Maybe they found it somewhere else but whatever, not going to share that here

elfin steppe
chilly hearth
radiant oriole
#

it DOES work

chilly hearth
radiant oriole
#

I'm not telling why or how but it DOES.

magic river
#

Oh yeah, and you can definitely RCE on all versions of Java

#

So... yeah

radiant oriole
#

It's a slightly different exploit but I've personally RCE'd all versions of java right up to java 17.

elfin steppe
#

the flag works...??

elfin steppe
#

oh nevermind

radiant oriole
#

The flag works, the "oh you're on a recent java version" is total bunk.

elfin steppe
#

yeah spigot folks say the same thing too

chilly hearth
marble wren
#

<@&748618676189528155>

quiet dragon
#

paperspigot exploit fix released???

marble wren
#

Getting spooky messages from this fella here

elfin steppe
#

this might be a dumb question but can OpenJDK or any OpenJDK distribution (Adoptium, Corretto, Zulu etc) do anything about this or no?

radiant oriole
#

no

mental meadow
#

also songoda discord lol

radiant oriole
#

all jdk distributions and versions and literally nothing, NOTHING you do regarding java version will fix this.

mental meadow
#

!ban @sand estuary Steam Phishing

thorny flickerBOT
#

:raised_hands: Banned DTM Panda#4159 (Steam Phishing) [1 total infraction] -- aurora#4484.

elfin steppe
radiant oriole
#

I'm not sure if it's possible or not.

#

I think it's probably not possible, but don't quote me on that.

bleak anvil
#

Conspiracy theory: this whole thing is a plot by Mojang to force people to update to the new launcher

radiant oriole
#

no, this whole thing is ACTUALLY invented by the paper mods to increase the popularity of the paper discord server and to drive more traffic to the paper website.

ashen cliff
#

MultiMC. 🛌

bleak anvil
#

Brilliant moves

tropic flame
vernal moth
#

Many people still don't realize how bad this really is

#

We will grow to hate this CVE

hexed dragon
vernal moth
#

It's so much more than just MC

#

Look at this shit

radiant oriole
#

shit ghidra cracked sadge

tropic flame
#

Ghidra cracked?? enable online mode!! 😠

viscid wedge
#

I had a rather grave realization that I'm not going to share publicly

#

This isn't good.

mental meadow
#

I'm surprised at how little media attention this has so far

magic river
#

All I can say is get fucked everyone who use elasticsearch

#

Wait I think I have one at work for gitlab

elfin steppe
mental meadow
viscid wedge
sharp sentinel
#

It’s received a lot of attention but just for Minecraft stuff

#

It’s odd

#

Realistically it’s a bigger issue outside of MC

elfin steppe
#

because when you ask the average person what comes to their mind of the word "Java", half of the time they'll say Minecraft kekw

viscid wedge
#

Spring

magic river
#

average person doesn't know what that is

#

They might know Java has something to do with Android

viscid wedge
#

No, sorry. Just another casualty I thought of.

magic river
#

Doesn't spring default to using logback?

viscid wedge
#

Yeah, but many deployments still use log4j2

#

I just had to switch a machine off it

foggy veldt
#

Oh wew I take a nap and the issue got worse

#

I actually have to care now ;-;

thorny totem
#

1.18.1 is released^^ edit: already said here, woopsies

sharp sentinel
#

Practically every big MC mod / plugin is gonna have a notification that tells us when updates release tbh 😛

#

So it’s hard to beat people who are gonna receive an alert

thorny totem
#

😆 yeah

limber knotBOT
#

someone nick my dc account again thx

mental meadow
#

it's still called naomi

limber knotBOT
#

interesting

#

probably cuz i havent talked in x amount of time

mental meadow
#

likely

limber knotBOT
#

ohno

void void
#

Oh hey

#

Naomi has a pfp now

limber knotBOT
#

wow

magic river
#

MultiMC also did an update

limber knotBOT
#

i have a pfp?

radiant oriole
#

no, multimc's patch screwed up some instances

magic river
#

So perhaps either they broke it or the two updates clashed

radiant oriole
#

mojang's update had nothing to do with multimc

elfin steppe
clear mulch
#

when paper 1.18.1

limber knotBOT
#

what the fuck is that

magic river
clear mulch
#

ty

magic river
radiant oriole
#

Yeah I saw that earlier

mental meadow
#

we do love a good score

magic river
#

Oh the CVE is public now

ashen cliff
#

Is it actually a 10? kekwhyper

mental meadow
#

According to Apache

spiral pivot
#

Didn't the post originally say that build 398 of 1.17 fixed the exploit? Now it's 399?

mental meadow
mental meadow
ashen cliff
#

Nice.

mental meadow
#

A solid 10

spiral pivot
#

Gotcha, thanks. May be worth another @ everyone because we thought we had fixed it. Really appreciate the work though

ashen cliff
#

Even redhat gave it a 9.8. kekwhyper

magic river
#

But the DoS seems to not work on Paper anyway, at least not on newer versions?

#

I guess maybe it would if you spammed it enough? Dunno if anyone tried

#

On vanilla it was a single attempt killed the server, on paper your console was just useless for 30 seconds or so

#

Still though, update

soft warren
#

Quick question, does build #66 1.18 paper have the fix for the security issue?

mental meadow
soft warren
#

I read that but I dont quite understand im sorry. So it does include the fix?

mental meadow
#

Paper 1.18 #66 or higher

soft warren
#

Thank you so much!

magic river
#

Versions Affected: all versions from 2.0-beta9 to 2.14.1

#

So hey, 1.7 might be ok 😄

rich atlas
#

sup

spiral pivot
#

Does this fix protect clients from the exploit as well?

magic river
#

No

#

You need to update clients too

#

For 1.12+ vanilla that just means restart the game and launcher

#

If you're using forge, fabric, or any other launchers the fix might be more involved, check with them

spiral pivot
#

Fabric looks like they're saying it will automatically install.

elfin steppe
#

If you update to the latest version of Fabric Loader yes its fixed

#

forge just tells you to use the flag though

void void
#

hi/hola

mental meadow
#

no shit

static moat
#

I mean there's a reason that the head of tech at Mojang was tweeting about it SCpolite

#

And they patched the vanilla client

#

asap

mental meadow
#

give it a few hours, news sites are already starting

limber knotBOT
#

might dm this to the CEO of Zolder BV

static moat
#

To be fair, this isn't exactly Mojangs fault

limber knotBOT
#

see if they continue zoldersessions finally

mental meadow
#

I'm gonna punch the next news page to call this a minecraft exploit

hexed dragon
#

lol

static moat
#

It's an exploit by a 3rd party library (won't go further into detail on how it works)

limber knotBOT
#

no because it's already fixed

ashen cliff
#

Not on a 1.12.2 server running outdated software. 🛌

#

And outdated utility clients.

hexed dragon
mental meadow
#

yes

#

I just send them an angry message already

#

like

#

they even acknowledge that it affects a lot of software at the end of the article

foggy silo
#

I news providers trying to “jump in” just making more chaos.

#

But this is just

#

“Minecraft exploit!!! OMG”

worn crest
foggy silo
worn crest
#

There were grass blocks, dirt blocks and ugh thonk

mental meadow
hexed dragon
void void
#

what could the security exploit do tho?

hexed dragon
vernal moth
#

Finally a worked force op!

foggy veldt
#

2021 free download

hexed dragon
#

The launcher versions above 13w39a which is a 1.7 snapshot have their date updated which suggests they have been updated with the fix.

foggy veldt
#

Rip people playing tekkit on 1.6.4

void void
#

lol, every channel is talking about this

ashen cliff
foggy veldt
#

Unrip people playing tekkit on 1.6.4

grim island
#

jokes on you I play tekkit on 1.2.5

main brook
vernal moth
#

I can tell your computer to do stuff

main brook
#

oh

vernal moth
#

Just by sending you a chat message

#

That's a remote code execution

main brook
#

imagine just restarting everyone's pc on a server

mental meadow
#

Worse

main brook
#

yea

mental meadow
#

Imaging someone using your computer to host child porn or something

main brook
#

oh

vernal moth
#

I can make your PC hack the FBI

grim island
#

installing cryptominer

main brook
#

that's very bad

vernal moth
#

So they will come knock

swift root
#

imagine enslaving an entire server community's machines and networks as part of a botnet that commits international crimes 😎

main brook
#

or just send virus links

vernal moth
#

This is basically a virus, lol

main brook
#

i mean, yea

void void
#

what if people just... didnt do that, and we played minecraft

grim island
#

where's the fun in that!

vernal moth
#

This affects so much more than just Minecraft

#

We just happened to be the first to understand the scope

#

The apache foundation sure didn't

main brook
#

was the log4j2 always there

#

or

#

did something come with it

vernal moth
#

And idk if Alibaba did

void void
#

oh, ok. This is big, lol

main brook
#

yea

void void
#

is 1.8 safe to play on at all at this point

grim island
#

why logging library even had capabilities to do such things in the first place though

mental meadow
void void
#

I decided I wanted to start a server like 2 weeks ago... Excellent timeing

main brook
#

yea

void void
foggy silo
#

Yea it was defo underestimated it seems x)

#

(By certain other parties)

vernal moth
#

Apache said the gonna release in 72 hours yesterday

main brook
#

imagine you playing chill then you start to see things in your compture

vernal moth
#

They since deleted that whole thread 😂

foggy silo
#

Yea really fun

mental meadow
#

and released it now lol

left swift
#

tekkit 1.6.4 the classic days

#

let's go back

main brook
#

ah the classic days, where cars had white tires and i was unborn

#

😔

mental meadow
#

just don't use your computer, ez fix

rare python
#

Wait, does the exploit affect game clients?

#

Or just servers?

main brook
mental meadow
#

And much more

main brook
#

imagine a exploit like this in discord

#

that would be so scaryt

rare python
#

Isn't it a log4j thing?

left swift
#

how could the simulation do this

mental meadow
#

The client also implements log4j

grim island
#

well you know minecraft logs every message from the chat, even when you spamclick the bed to go to sleep

main brook
#

next time im gonna fly bawl click on beds

void void
#

Heres how stuipidly easy and dangerous this exploit is... incase anyones wondering the severity

grim island
void void
#

Basically, type type, sned command, take over a remote computer

#

I shut my server down 😮

swift root
#

@void void Don't send details about the exploit or how it's done here - see the pinned message in #paper-help

void void
#

oop, sry. noob

main brook
#

oh so that's why some servers just crashed ig

vernal moth
#

Yes

marble trench
#

Do this bug gonna be fixed on 1.12.2 ?

crystal lilyBOT
#

All the info we can provide is pinned in the #paper-help channel

brave mountain
#

Damn a lot of enterprise software uses java.

#

Like cash registers on the supermarkets.

swift root
#

gotta get into cash register logging systems

#

yes I'll buy one ||not gonna type it but the thing|| please

void void
#

Can I buy jndi for 50 dollars plz

foggy veldt
#

Oh I didn’t read one message under

grim island
swift root
#

tosh, edit pls

void void
#

Srsly this actually might work

swift root
#

don't share anything too detailed.

#

yeah just gonna nuke it lol

vernal moth
#

It's way too late anyways

swift root
#

we still fight the spread!

#

the less 12yos trying this the better

foggy silo
#

Lmao yes

void void
foggy silo
#

Finally can get op on my FAV server

#

😻😻

foggy veldt
#

On the bright side at least in the mc community the 12 year olds won’t know how to set up the thing so hopefully it shouldn’t be too bad until someone releases super force op hacked client for $300 and hopefully by then most servers will have updated

rare tiger
#

Actual latest would be 1.18 but 1.17.1 is latest stable. Also why did you crop out useful error info?

#

Oh wait he deleted his messsage :/

#

Ok cool

worn ember
#

hangar wen

crisp sinew
#

Hello

#

Whats happening here

left swift
#

brekfast

crisp sinew
#

Like the issue?

#

Some security issue

crystal lilyBOT
#

All the info we can provide is pinned in the #paper-help channel

mental meadow
worn crest
#

german website thonk

void void
#

bad security bug, should shutdown and backup your server until you verify your host updated

#

^^

brave mountain
silk sparrow
#

what's situation with log4j?? is now things safe or nah

crystal lilyBOT
#

All the info we can provide is pinned in the #paper-help channel

untold copper
#

day #185 of trying to get abs (yesterday): no exercise
day #186 of trying to get abs (today): 50 Zone Minutes. Did 25 minutes of high intensity interval training. I am tired.

worn ember
foggy silo
#

Fr

#

Hi snoopa!!

grim island
#

endermen have 2 eyes, but with looting III you can get four of them

hexed dragon
#

1.18.1 spigot release

untold copper
grim island
void void
#

when a working 1.18 fishing plugin... Far more important IMO

elfin steppe
#

basically 1.18.1 is network compatible with 1.18 like 1.16.5 is to 1.16.4?

limber knotBOT
#

told my economics teacher to watch JoJo lmao

left swift
#

weeb

void void
#

im proud

#

tell your teacher to stop making you guys study and watching anime w you guys instead

prisma mantle
#

i ❤️ gypt

foggy silo
#

I love the grind tho…

meager tusk
hexed dragon
#

KENNY STREAM!

worn ember
left swift
#

wow really no way!

#

this is so crazy!

left swift
#

are you just an update bot soyab

limber knotBOT
#

yes

#

without the bot tag

hexed dragon
#

I send all news related to not just minecraft but discord too.

left swift
#

I didnt say it was only minecraft related

hexed dragon
#

I am a bot yes.

#

I look at twitter.

limber knotBOT
#

one of the worst things that can happen

#

prod going down on a friday

left swift
#

you mean best things

#

everyone loves working on weekends

twin lagoon
#

@untold meadow BEST kezz

untold meadow
#

@twin lagoon BEST miceaheil

main raft
foggy silo
#

Hi Michael hi kezz!!!

limber knotBOT
#

hey owen

foggy silo
#

Hi Naomi! steve_hug

limber knotBOT
#

HAHA MY BUS DRIVER IS WEARING A FEDORA

foggy silo
#

Based bus driver

limber knotBOT
foggy silo
#

👀

limber knotBOT
#

he likes stepping on the gas my god

void void
foggy silo
#

Hru noah!

remote pelican
#

is my world normal? I just encountered this on the paper 1.18 snapshot

limber knotBOT
#

that's happened to me so many times in vanilla singleplayer that i wouldnt worry about it

remote pelican
#

sure, thanks

void void
#

what are you doing here hank

#

english mode = true

#

chat = 💀

#

english mode = off

torn violet
#

For MC 1.18.1, does the client fix the fog issue or is it the server that needs to be 1.18.1?

limber knotBOT
#

wow! so funny! you must be the winner of the Hilarity Championship!

#

.try

torn violet
#

I did. The client updated but server didn't. Fog seems the same? But that doesnt make sense

#

Thought the client handled rendering

hexed dragon
#

Paper 1.18.1 build out

hoary belfry
#

is it stable?

left swift
#

thanks soyab update bot

neat oyster
#

My uwu plan failed

#

If you watched the stream you would understand

zinc wagon
#

Log4j

daring stirrup
#

What does this exploit do

vernal moth
#

Bad things

#

Update

daring stirrup
#

I need 1.8.9 one

vernal moth
#

Haha

void void
chilly hearth
zinc wagon
daring stirrup
rare forge
daring stirrup
zinc wagon
chilly hearth
#

Not vbucks

rare forge
daring stirrup
daring stirrup
zinc wagon
rare tiger
chilly hearth
#

I would link a video which shows how it works but the mods already got angry, so i wont do that xD

runic fable
zinc wagon
#

If there werent people wouldnt be telling everyone about it

zinc wagon
chilly hearth
zinc wagon
vernal moth
#

The Argument only works on newer versions

zinc wagon
#

oh

chilly hearth
#

^

vernal moth
balmy atlas
#

Is there a way to start a server with a datapack like the start the world from scratch?

vernal moth
#

And yes this exploit is as bad as it gets basically

zinc wagon
#

Anyways it shouldnt be noticeable from a player perspective afaik

balmy atlas
#

I've been trying to start with terralith

#

But the biome blending is trash

neat oyster
#

i have a doubt

zinc wagon
daring stirrup
#

Wait i have purpur

neat oyster
#

can i use petoradactyl on a existing server

balmy atlas
#

So I wanted to start it with the chunks generated within terralith's generation

daring stirrup
#

I replaced my 1.17.1 to the newest one

vernal moth
#

This affects everything that uses log4j, not just java

daring stirrup
#

Is it safe now?

vernal moth
#

My company is running around in circles

#

Yes justin

zinc wagon
daring stirrup
#

Yey

vernal moth
#

No but virtually every company has a product that uses log4j

chilly hearth
vernal moth
#

Apple is affected

#

Tesla cars are affected

chilly hearth
#

If it says 2021 you have a problem.

neat oyster
daring stirrup
zinc wagon
chilly hearth
#

If the responds is 2021

neat oyster
daring stirrup
daring stirrup
chilly hearth
#

?

#

What does yours say?

daring stirrup
#

Lemme ss

chilly hearth
#

Thats good

daring stirrup
#

wait lemme try it on my other server

chilly hearth
#

If the server respond would be 2021 it wont.

#

You give it a var as parameter, and normally it would give you back the value of that var, which it now wont.

#

For example if the server would say 2021, players could use ${jndi: for example

daring stirrup
#

oh sh*t

chilly hearth
#

Which could be very bad

daring stirrup
#

my other server says 2021

chilly hearth
void void
#

hola :v

daring stirrup
chilly hearth
#

Oww, than you have to wait for paper to update it.

daring stirrup
#

i think there is 1 for it

chilly hearth
#

There isn't.

hexed dragon
#

Degraded performance on GitHub Actions.

topaz mortar
#

there won't be

daring stirrup
foggy silo
#

Fun.

daring stirrup
#

It says in paper pins

chilly hearth
#

Or remove the class.

foggy silo
#

You can just add the log config…

daring stirrup
chilly hearth
#

I thought it was?

daring stirrup
#

Paper didnt make bungeecord

chilly hearth
#

This bugg isn't paper related at all?

unkempt drift
#

No, bungee cord doesn’t use log4j. Paper’s fork of bungee cord, Waterfall does, and so it needed an update.

daring stirrup
#

I have bungeecord jar

warm anchor
#

then you are fine.

daring stirrup
#

Can i replace it with waterfall

limber knotBOT
#

yes

chilly hearth
#

People are using the exploit to crash servers like Mineplex

#

Its massive

left swift
daring stirrup
#

Now my server crashes every min

reef orchid
daring stirrup
#

*restarts

unkempt drift
#

Starlight is a PaperMC thing now.

#

Since leaf joined

reef orchid
#

oh

left swift
potent panther
#

did 1.18.1 fix the exploit?

left swift
#

yes

reef orchid
potent panther
#

i mean vanilla 1.18.1

reef orchid
#

yeah all vanilla versions should be fixed ,it should download a new jar if u open minecraft

potent panther
#

oh so fast all versions

magic river
#

It's not a new jar but yeah

unkempt drift
#

Vanilla 1.18.1 is the only vanilla server version (>1.7) where it’s fixed without having to do anything extra tho.

marble lark
#

woah woah I'm late

reef orchid
marble lark
#

what exactly is the security issue that they found?

magic river
reef orchid
unkempt drift
foggy silo
#

Hi Sherman!

magic river
#

The client isn't just a single jar, it's a bunch of pieces and the launcher downloads them all

marble lark
#

ello Owen

magic river
#

They updated some of the pieces, not the main client jar

#

Like, for the client all of its dependencies are separate files, all of the assets are, etc

reef orchid
#

oh got it

left swift
marble lark
#

haha

magic river
#

That's how they could get it done so fast, 1.12+ they only had to update a single file since it was an asset all modern versions shared

marble lark
#

for reals though what happened

left swift
#

read pins in paper help

magic river
#

Exploit in log4j2 that can cause arbitrary code execution

#

Triggered by, among other things, messages in chat

#

Affects clients too so if you join a server and someone sends one of those messages they can hack your computer

marble lark
marble lark
#

how the hell did that happen in log4j of all things

magic river
#

Enterprise bullshit

marble lark
#

fair enough

foggy silo
#

Yea not something you’d expect, honestly

#

It’s a logger!

hexed dragon
#

It logs too much.

marble lark
#

I guess vulnerabilities are always in the most unexpected of places

chrome cosmos
#

wow what a randomgif

foggy silo
#

Logging logger logged too hard

marble lark
foggy silo
#

Well it wasn’t meant to be malicious….

magic river
#

Someone thought your logger should be able to look shit up from a server to decide how to log things

foggy silo
#

I guess just, they made a big oopsie.

marble lark
foggy silo
marble lark
#

I'm gonna assume Minecraft isn't the only victim of this lmaoo

left swift
#

its not

faint crystal
#

whole world

foggy silo
#

Steam, iCloud, but so much

magic river
#

Steam search, iCloud, anyone who uses elasticsearch, etc

limber knotBOT
#

i hope felenov gets backdoored

#

honestly

#

man deserves it

marble lark
#

elshout backdoor

limber knotBOT
#

writing the backdoor in elshout sounds like a good idea

marble lark
#

ello aurora

mental meadow
#

I'm in a xisumavoid video 😄 CalliPog

faint crystal
mental meadow
#

literally famous now

limber knotBOT
#

true

foggy silo
#

Ayo? 😳

mental meadow
#

don't talk to me anymore

limber knotBOT
#

hey aurora wanna play osu

foggy silo
#

😫😫

mental meadow
#

yes I need to test out my new osu playing headphones

foggy silo
#

Aurora I know you’re on a new level than all of us

#

But hi!!

left swift
#

felenov the dude banned for pirating?

limber knotBOT
#

yes

left swift
#

kek

mental meadow
#

Osu! headphones

#

only for osuing

limber knotBOT
left swift
#

naomi moment

chrome cosmos
left swift
#

ur mom

limber knotBOT
#

not even just pirating

#

writing a keygen for microsoft visual studio

#

all because they locked him out of azure KEKW

left swift
#

typical 15 year olds

foggy silo
#

Bruh

void void
#

hi

chrome cosmos
#

smort

limber knotBOT
#

that's the thing

void void
left swift
#

irc bridge

magic river
#

GPT-3

limber knotBOT
#

running on paper

marble lark
#

ayy aurora ye be famous now

#

also felenov got banned?

limber knotBOT
#

days ago

#

signed someone up for telemarketers

warm anchor
#

only a few more left before sharman now

foggy silo
#

How does everyone know them?

#

I don’t!

limber knotBOT
#

know who

left swift
#

theres a few around I'm surprised are squeaking by

#

like naomi

limber knotBOT
#

im just

#

"notable, notably annoying" - (broccolai)

left swift
#

@waxen panther

#

naoki quotes you youre big time now

#

big time rush

waxen panther
#

god im so funny

#

that is hilarious

potent panther
#

the log4j is also fixed on vanilla clients 1.7< and dont need to add something to the parameters?

left swift
#

yes

void void
#

does #66 fix the exploit

marble lark
left swift
#

yes

waxen panther
#

use 66 yes

limber knotBOT
#

yes

void void
#

thanks a lot guys

marble lark
#

sheesh

void void
#

appreciate it

hexed dragon
#

use the highest number.

marble lark
#

i mean I can't say I'm surprised either though

left swift
#

brocc so funny and pingable and cool and vegtabel and billie eilish stan

marble lark
hexed dragon
#

I'm a bot

potent panther
#

and for servers they also fixed it on 1.18.1

left swift
#

1.16.5+ latest builds they are fixed

potent panther
#

for vanilla

left swift
#

for older versions read paper help pins

potent panther
#

for vanilla

left swift
#

no chocolate

potent panther
#

i dont use vanilla but want to know if bukkit and spigot will be ok

left swift
#

yes 1.18.1 fixed it

potent panther
#

oh ok

limber knotBOT
#

spigot's fine

#

they backported lots of fixes

marble lark
#

md_5 doin work

#

xd

left swift
#

SHermanInTank

void void
#

-Dlog4j2.formatMsgNoLookups=true

#

do i need to add this to the launch arguments?

left swift
#

no

limber knotBOT
#

if you're using the latest build, no

void void
#

okay thank you

#

someone in another server mentioned it

limber knotBOT
#

tbh i kinda wanna write an ai that just spouts the nonsense i spout now

#

the plugin doesn't cover all the ways you can use the exploit

void void
#

i want to be a bot too

left swift
#

i

potent panther
#

webhook

left swift
#

got my poki reacts in

#

kenny got owned!

mental meadow
#

Which is why we have been saying for ages: Plugins don't work, chat is not the only attack vector

left swift
#

but Aurora it says fix in title

mental meadow
#

@quick pasture fake news!

limber knotBOT
#

^

mental meadow
#

Update your software. That is the best fix

limber knotBOT
#

how dare you lie to use frank

#

us

#

not use

left swift
#

Frank deskchan

mental meadow
#

smh not being able

#

to edit messages

#

smh

latent flint
#

💀 😂 That is hilarious. How does that sort of bug happen to begin with.

limber knotBOT
#

what did frank say