Комментарии:
I set the world name to be a Log4shell payload. Then, I remove focus from the Minecraft window so that it pauses immediately. When Minecraft pauses it saves the world. Here's where the exploit comes in. When Minecraft saves the world it logs it into the console. This will run my payload as a URL, download my L.class file, and then run the code inside with full access to Minecraft's internals.
ОтветитьThis... made me realize just how utterly bananas Log4Shell is. I didn't start a proper cybersecurity education until 2022, and I hadn't known that it had a CVSS score of 10.
Ответитьthe classic CVE-2022-2325
ОтветитьHow can i set this up?
ОтветитьXD thanks for the code.
Ответитьsub .50 when?
Ответитьu can actually beat the game in time like this without glitches/exploits etc.
ОтветитьMinecraft WR TAS any%
ОтветитьSiiiiiiiick :D
ОтветитьGG on the Speedrun World Record!
Ответитьhmmmmmm its work on 1.8.9 version? or it fix also for 1.8.9?
ОтветитьGg
ОтветитьImagine having a computer so slow that after waiting for the loading terrain to finish, the dirt background starts scrolling and shows the credits lol.
Ответитьlegit speedrun
Ответитьwelp, games solved
ggs
I just finished hunter hunter and now I read neferupitou on your terminal 0_0 (she's one of my favorites when talking about character design)
Ответитьbeat that, dream
ОтветитьWhat VSCode theme and font do you use?
Ответитьez game
ОтветитьBIG CONGRATULATIONS BROTHER!!!!!!!!
ОтветитьHOLY SHIT
ABSOLUTE WORLD RECORD!!!!
I like how he managed to gather the ender perls
Ответитьpeople who just joined be like
Ответить50ms is exactly one tick
ОтветитьActually, speedruns only count as soon as you hit the first key once you load in. Since you've probably touched 0 keys on your keyboard, you beat minecraft instantly
Ответитьlog4j is actually my minecraft nick, wtf
Ответитьspeedrunning has devoled into hacking.... what an achievement bro
ОтветитьThis thing? aHR0cHM6Ly93d3cuc3BlZWRydW4uY29tL2ZpbmRzZWVkP2g9QUNFLVNldF9TZWVkX0dsaXRjaGxlc3NfU3RydWN0dXJlcyZ4PWxfZ2RyMHA4a2QtemRubG1ycTI (base64 URI
Ответитьsubmit it to speedrun
Ответитьthis is what speedrunner want
Ответитьwhat even happened?
ОтветитьTool name?
Ответитьminecraft credits warp any%
Ответитьthis adventure was awesome,
ОтветитьSlowest femboy speedrun
ОтветитьMinecraft cheat developers discovering a god tier remote code execution exploit that affects like 90% of the fortune 100 companies only to use it to dox people on 2b2t:
Ответитьshiiit i gotta bring this up in our hackspace and see which crazy one will get the best times lmao
ОтветитьWait what
ОтветитьNice!
Ответитьcool
ОтветитьXd Java issues
Ответитьdream was quiet since this dropped
Ответитьlmao
ОтветитьThis is literally the closest thing to Arbitrary code exec a "modern" video game will ever have. Best use of the exploit i could have ever imagined too 😂
ОтветитьWowww dreammm
Ответить