Jump to content

Recommended Posts

Posted (edited)

Hi Forge contributors and users,

I was running a public modded server using Forge 14.23.5.2860 on Minecraft 1.12.2 (Enigmatica 2 Expert 1.90e) when a malicious user gained control of the server and executed code remotely on every connected clients device. I have live video evidence of this occurring and the hacker/developer of the exploit claiming that it is an unknown zero-day exploit. I believe the developer in question is the one who created the exploit. Sadly, the remote code executed on client PCs was used to steal browser sessions and info as well as active Discord and Steam sessions.

I'm sure many of your are aware of the log4shell exploit from 2021 that Forge was protected against. I don't believe this exploit was log4shell, but it's behavior is nearly identical, and thus I believe the severity is very high. Unfortunately, I am unable to recreate or understand the exploit in any way at this point, and the developer is not being forthcoming in how it is performed either (I think he intends to sell it for a profit). I'm mostly certain that this exploit affects Forge specifically, and most likely only Minecraft version 1.12.2.

I am providing a Youtube link to the unedited VOD from the livestream when the attack occurred (chat is blurred at some points to protect private information that was leaked). In the description of the video there is also a link to a .zip archive that contains relevant client and server log files from the session. Hopefully these are of some help, but from what I've looked at I couldn't find much at all pertaining to how the exploit was performed. I'm hoping that with all of this information someone more knowledgeable than me with Forge will be able to figure out more details on the exploit.

Link to VOD (relevant timestamps are included in Youtube description on the video):

 

Edited by Yoyoyopo5
  • 2 weeks later...
Posted

The concept is a known exploit that has been around for several years. It is not something that is caused by anything in ours, or Minecraft's end. 
It is unfortunately a risk when using mods in Minecraft. They are arbitrary jars which can have any code in them. This is one of the reasons we push people to use the latest versions.
This particular case was fixed in BdLib for 1.16+ and the author has no intention of back porting.

I do Forge for free, however the servers to run it arn't free, so anything is appreciated.
Consider supporting the team on Patreon

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Unfortunately, your content contains terms that we do not allow. Please edit your content to remove the highlighted words below.
Reply to this topic...

×   Pasted as rich text.   Restore formatting

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

Announcements



  • Recently Browsing

    • No registered users viewing this page.
  • Posts

    • The game crashed whilst unexpected error Error: net.minecraftforge.fml.ModLoadingException: Advanced Mining Dimension (mining_dimension) encountered an error during the done event phase
    • Here is the end of the log. it was way too big to put in pastebin, but I started from when I was online and everything was fine. Error should be in here: https://pastebin.com/Sdhdq593
    • Update: I stand corrected as I was able to dig up a relevant log from my earlier testing which highlights the overall issue but does not explain how to solve it. See, Diagnostic Logs for pack.mcmeta not found: https://pastebin.com/LXS8Rtna
    • Which mod was this? What are all the mods that were in use? It will help if enough information to replicate the problem is available.
    • I have been attempting to create a supplementary resource pack with Patchouli in order to add back the guidebook for Better End but unfortunately in every prototype I have made pack.mcmeta and my resource pack are not recognized. I have tested both zipped and unzipped and either way curseforge does not recognize my resource pack as existing. For testing I stripped my pack down to just the pack.mcmeta file and two empty folders labelled data and assets and I know the data folder is not the problem as firstly my first attempts just had an assets folder following Patchouli instructions and data came later in my flailing attempts to make anything in my pack work. The mcmeta file is not recognized whether or not I use this:  { "pack": { "pack_format": 15, "description": "A replacement for the BetterEnd Guide Book." } "language": { "en_US": { "name": "English", "region": "United States" } } } ,or this:  { "pack": { "pack_format": 15, "description": "A replacement for the BetterEnd Guide Book." } } I have made sure to only use lowercase and the pack folder is named better-end-guide. Is this some magic nonsense from me doing this manually instead of using an IDE or similar tool? Could it be because my files are by default in UTF-8 even though ANSI gives the same results? Is there a specific community secret tool I am supposed to use for zipping or specific settings? I am pulling my hair in distress. Unfortunately as there are no errors involved I lack logs to offer, if that disqualifies this thread please do not be harsh and instead if you can then please direct me to a forum with different rules and sufficiently respectful but knowledgeable as to be of assistance. Most of my experience with the programming community has been poor and so naturally I find myself wary.
  • Topics

  • Who's Online (See full list)

    • There are no registered users currently online
×
×
  • Create New...

Important Information

By using this site, you agree to our Terms of Use.