3

Can anyone explain to me, in simple terms, what is going on with the Java exploit?

Ironbanner12342's Avatar Ironbanner1234212/10/21 1:59 am
3 emeralds 146 4
12/13/2021 6:32 pm
anonpmc3530281's Avatar anonpmc3530281
Since I am not a programmer, I don't understand the language. Can anyone please explain in simple terms what is going on?
Posted by Ironbanner12342's Avatar
Ironbanner12342
Level 1 : New Explorer
3

Create an account or sign in to comment.

4

anonpmc3530281
12/13/2021 6:32 pm
Level 3 : Apprentice Miner
anonpmc3530281's Avatar
[deleted]
1
HoboMaggot
12/10/2021 6:39 am
Level 52 : Grandmaster Blob
history
HoboMaggot's Avatar
As Coffee stated, it allows hackers to remotely execute code (e.g. get your IP addresses and download stuff) by sending a string with a certain pattern into chat which gets logged internally (which is what minecraft always does with chat and commands), but also remotely executes that malcious code to grab your details/install ransomware.

Procedure of the hack:
  • Data from the hacker gets sent to the server via chat message to the server
  • The server logs the message sent by the hacker, containing the malicious payload
  • The (log4j) vulnerability is triggered by this payload and the server makes a request to the main server/Java files of the server via the internally imported software responsible for receiving and displaying chat messages and commands
  • The text pattern contains a path to a remote server/java file which is injected and allows an attacker to execute their code remotely.
Hopefully this is ELI5 enough. Might be 10% wrong as im not a full fledged programmer

Btw, this affects all applications who use that logging software, not just minecraft. A whole bunch of enterprise programs were vulnerable to this too, such as Steam and the Apple iCloud.
https://www.lunasec.io/docs/blog/log4j-zero-day/
4
Coffee Gamer 360
12/10/2021 4:21 am
Level 70 : Legendary Enderdragon
Coffee Gamer 360's Avatar
Basically you can execute whatever pieces of code (malicious or whatever code) just by typing in chat and without permiission of the user!
4
Comradeee
12/12/2021 1:37 am
Level 37 : Artisan Engineer
history
Comradeee's Avatar
omg
1
Planet Minecraft

Website

© 2010 - 2024
www.planetminecraft.com

Welcome