11
IMPORTANT: Java Exploit (Remote Code Execution)notification_important
(Posting this for the awareness of everyone since this is a Minecraft forum community and I have noticed that no one has made a thread about this yet)
An exploit has been discovered in a library that Minecraft uses, which could be used for remote code execution. Players can type a malicious chat message that could result to the code being executed in your computer. This affects literally every server from 1.7 to 1.18, and the type of server (i.e. Bukkit-based, Sponge, Fabric, etc.) does not matter since the vanilla Minecraft server is also affected by the exploit. The Minecraft client has also been affected.
SOLUTIONS
Here are some few things you can do to prevent yourself from the exploit:
1. Update your launcher to the latest version.
2. If you, or someone you know, owns a server, ask them to update the server as well.
3. Add this Java argument to both the client and server:
For now, you are highly suggested to NOT JOIN PUBLIC SERVERS!
Sources
An exploit has been discovered in a library that Minecraft uses, which could be used for remote code execution. Players can type a malicious chat message that could result to the code being executed in your computer. This affects literally every server from 1.7 to 1.18, and the type of server (i.e. Bukkit-based, Sponge, Fabric, etc.) does not matter since the vanilla Minecraft server is also affected by the exploit. The Minecraft client has also been affected.
SOLUTIONS
Here are some few things you can do to prevent yourself from the exploit:
1. Update your launcher to the latest version.
2. If you, or someone you know, owns a server, ask them to update the server as well.
3. Add this Java argument to both the client and server:
-Dlog4j2.formatMsgNoLookups=trueFor now, you are highly suggested to NOT JOIN PUBLIC SERVERS!
Sources
- https://www.reddit.com/r/admincraft/comments/rcp138/paper_exploit_found_you_need_to_update_fast/
- https://www.reddit.com/r/Minecraft/comments/rcum79/important_javawide_exploit_that_lets_people/
- https://twitter.com/slicedlime/status/1469150993527017483
- https://www.reddit.com/r/hypixel/comments/rcv207/warning_do_not_log_onto_public_servers_new/
- https://www.reddit.com/r/programming/comments/rcxehp/rce_0day_exploit_found_in_log4j_a_popular_java/
- https://hypixel.net/threads/psa-there-is-a-fatal-remote-code-execution-exploit-in-minecraft-and-its-by-typing-in-chat.4703238/
14
It's a good thing I rarely ever play on servers lol
something new
I do not have a new official launcher (no Windows 10 edition), I play on 1.18.1. and 1.17.1 in single player. I already heard about some hole Is something threatening me?Very nice guide, most servers have either filtered / removed this error.
Although you should be careful when entering other less reputable servers due to
the fact it could be vulnerable to data breaches and so much more.
Although you should be careful when entering other less reputable servers due to
the fact it could be vulnerable to data breaches and so much more.
Remote code execution.... what type of code would this be?
That means that anyone could run shell commands (also what you could do in your command line) with your computer permission. Anything running on your computer using quasi shell commands in background. So if anyone is able to execute any shell command on your computer with your permission level and your permission level is likly administrator that one controlles you computer and could do basicly anything; including very bad stuff like reading anything you tipp, install coin miners, using your computer for illegal hacking operations or installing software like ransomware.
Unwanted Remote Code Execution is the worst thing in IT so take this Java problem serious.
Unwanted Remote Code Execution is the worst thing in IT so take this Java problem serious.
Any code the executioner wants
With version 8u121+ it "probably" won't cause RCE as there are additional flags that have to be enabled for it. I also couldn't trigger execution on openjdk version "11.0.13".
Either way it's indeed just ~60 char long string that can cause everyone to freeze for one minute at least (it's trying to connect to remote ldap server, so some connection timeout/retry).
It's both server and client and it had to been there for some time.
in short, update your shit and your safe
Either way it's indeed just ~60 char long string that can cause everyone to freeze for one minute at least (it's trying to connect to remote ldap server, so some connection timeout/retry).
It's both server and client and it had to been there for some time.
in short, update your shit and your safe
people who use the 2 month old launcher because the new launcher is "horrible, bad, and never will use because its Microsoft crap" will be upset when they update to find that its literally the exact same thing with some promised features and easier Microsoft login
Nonsense. It's not easier because the "new" launcher does not allow you to use multiple accounts side by side.
And another thing: the "old" (or current?) launcher remains fully supported by Mojang, so there are 0 negative effects from using it.
And another thing: the "old" (or current?) launcher remains fully supported by Mojang, so there are 0 negative effects from using it.
How is this related to the topic?
its a java issue not a launcher issue
