The Scariest Week in Minecraft History

Sdílet
Vložit
  • čas přidán 17. 12. 2021
  • Today we'll discuss The Scariest Week in Minecraft's History and how the log4j vulnerability (log4shell) was weaponized on 2b2t and other Minecraft servers, as well as the entire internet.
    This java hack is not going away anytime soon.
    My Twitter: FitMC
    My Instagram: fitmcsippycup
    HOW TO STAY SAFE:
    1. Update Java to the most recent version
    2. Update Minecraft to the most recent version
    3. Re-install 3rd party versions of Minecraft ONLY if you know they are safe.
    4. Servers can still be affected, so only join servers you can trust.
    More info: www.minecraft.net/en-us/artic...
    Music: FFXV
    Additional 2b2t Footage/Information/Renders:
    Rebane (Footage/Information) - • This chat message hack...
    Redstoner (Footage/Information) - • The 2b2t Log4J trollin...
    0x22 (Information)
    leijurv (Information)
    xcc2 (Thumbnail Render)
    If you enjoyed learning about The Scariest Week in Minecraft History, I would appreciate if you would consider hitting that like and subscribe button!
    Hopefully the damage from the log4j vulnerability (log4shell) will not be too extreme.
    2b2t is currently awaiting the 1.18/1.19 Caves & Cliffs Minecraft update. Very exciting times!
  • Hry

Komentáře • 7K

  • @cubicinfinity2
    @cubicinfinity2 Před 2 lety +15108

    Hacking someone's computer to patch their game from the vulnerability that gave you access to their computer is on another level.

    • @tisjstme5315
      @tisjstme5315 Před 2 lety +1019

      ...but also a good thing in the MC community to know there are good hackers out there.

    • @MattBasicG
      @MattBasicG Před 2 lety +666

      @@tisjstme5315 thank god there are people who use their coding for good

    • @Alex-tx2dh
      @Alex-tx2dh Před 2 lety +209

      Some Jim Browning type moves

    • @madcroc111
      @madcroc111 Před 2 lety +385

      It's called white hats. Similar thing happened on Ethereum crypto in 2017. They hacked 180million dollars worth of coins since so many wallets were vulnerable and then returned it all later. Malicious hackers did steal 30million worth though...

    • @Internazionale2010
      @Internazionale2010 Před 2 lety +84

      He deserves a virtual knighthood

  • @alikreed1154
    @alikreed1154 Před 2 lety +6689

    Those people who tried to keep others safe are heros

    • @Zycrian
      @Zycrian Před 2 lety +90

      Im worried about my hypixel skyblock now. since im always playing in version 1.8.9

    • @TheAmazingRaptor
      @TheAmazingRaptor Před 2 lety +40

      @@Zycrian update

    • @campbat5712
      @campbat5712 Před 2 lety +7

      yeah realy

    • @AshPikachu9
      @AshPikachu9 Před 2 lety +113

      @@TheAmazingRaptor one does not simply update versions while playing hypixel

    • @Jonah16835
      @Jonah16835 Před 2 lety

      Ikr

  • @UndeadPlayer1
    @UndeadPlayer1 Před 2 lety +2618

    Imagine just getting hacked and your like "oh frick, I'm probably installing a virus now", and then the hacker installs virus protection instead. 0x22 is truly a legend.

  • @WanderingGarden
    @WanderingGarden Před 2 lety +425

    Every time we get these videos I'm just like "How is Redstoner involved this time?"

    • @theexchipmunk
      @theexchipmunk Před 2 lety +54

      But this time he committed an actual crime that can get you into prison in a lot of countries.

    • @madkills10
      @madkills10 Před 2 lety +10

      it was funny how he thought taking their accounts was ok yet anything more is "too far"

    • @joshuawright4198
      @joshuawright4198 Před 2 lety +36

      @@madkills10 I mean It's all wrong but I do see the difference between stealing someone's minecraft account qnd stealing their credit card information

    • @marcovillela7438
      @marcovillela7438 Před 2 lety +4

      Bro that guy is the Don Quixote Doflamingo of minecraft

    • @Aresie271
      @Aresie271 Před 2 lety +18

      @@theexchipmunk hey man at least all he did was destroy Minecraft shops, still fucked up that he hacked at all but if he really wanted to he could’ve hacked all of our banks and shit

  • @AntVenom
    @AntVenom Před 2 lety +6252

    0x22 is a real one.

    • @stevebrine9657
      @stevebrine9657 Před 2 lety +25

      Hi first reply

    • @sulphurous2656
      @sulphurous2656 Před 2 lety +164

      I didn't expect such deeds coming out of a cheat client programmer, that's for sure. Pretty good.

    • @starkbeatle4516
      @starkbeatle4516 Před 2 lety +34

      yeh man is out saving so good on him

    • @jwcfive7999
      @jwcfive7999 Před 2 lety +61

      For real, dude could’ve done tons of damage but decided to do good. You can never be too careful though, he might be boosting his reputation for the future…

    • @AndreUrzua1
      @AndreUrzua1 Před 2 lety +28

      The definition of a white hat hacker

  • @drcraby356
    @drcraby356 Před 2 lety +4752

    0x22 may be a Nerds Inc. member and a known hacker, but what he did is legendary. Litterally hacking peoples PC just to install a patch before actually malicious hackers got to them

    • @pyro2500
      @pyro2500 Před 2 lety +92

      Damn that’s crazy

    • @tisjstme5315
      @tisjstme5315 Před 2 lety +84

      That's being a true hero.

    • @daniilfilms
      @daniilfilms Před 2 lety +236

      He fixed the exploit with the exploit

    • @youtubevideoswatching3866
      @youtubevideoswatching3866 Před 2 lety +91

      He deserves a award. He is a literal hero, like, we need more people like him

    • @Gianski150
      @Gianski150 Před 2 lety +51

      We never know his true motives but whatever he did is heroic.

  • @svijj_
    @svijj_ Před 2 lety +1317

    As a person that's loner who only plays singleplayer, this went over my radar completely. At least I wasn't hacked I guess

    • @LolliFN
      @LolliFN Před 2 lety +37

      Its not just minecraft though but also steam, spotify and other huge corperations

    • @Villager6883
      @Villager6883 Před 2 lety +16

      @@LolliFN lol bedrock Edition not involved

    • @Villager6883
      @Villager6883 Před 2 lety +23

      @@LolliFN because bedrock is not programmed as Java it’s programmed to be C++

    • @meticakolli1237
      @meticakolli1237 Před 2 lety +43

      @@Villager6883 the bedrock players are laughing rn

    • @Villager6883
      @Villager6883 Před 2 lety +4

      @@meticakolli1237 yeah

  • @alipali
    @alipali Před 2 lety +52

    0x22 is the literal definition of "chaotic good" - doing greater good in a totally unorthodox way. Props to them.

  • @ItzOwo
    @ItzOwo Před 2 lety +8850

    Imagine getting hacked, to realise the hacker is helping you. What a legend man!

    • @cmdpro4187
      @cmdpro4187 Před 2 lety +59

      AAAA- Oh ok

    • @Nahuelwg
      @Nahuelwg Před 2 lety +128

      True gigachad

    • @redermac5667
      @redermac5667 Před 2 lety +148

      If I became a hacker, I would be a good hacker that would help people

    • @cumjesus
      @cumjesus Před 2 lety +19

      @@redermac5667 yes

    • @MrSeedkey
      @MrSeedkey Před 2 lety +44

      And then the hacker getting arrested for hacking anyway

  • @videogamplayer5846
    @videogamplayer5846 Před 2 lety +3224

    Everyone always talks about how much fit says "the oldest anarchy server in Minecraft" but nobody talks about how much he says "lets get started"

  • @PBStriker101
    @PBStriker101 Před 2 lety +289

    0x22 is really an interesting character. Kind of like an anti-hero.
    He is someone that takes part on very interesting hacking elements and actively works for whoever he wishes. But actually has some kind of work ethic and pulls power move to even protect people from genuinely evil people.
    To be honest? I think he is the most gifted programmer i ever heard of. He is so passionate of his work and talent that he has developed a new appreciation for the digital world. To the point of having restraint to not do an actual harm to other people.

  • @saiarjunk4371
    @saiarjunk4371 Před 2 lety +281

    As a cybersecurity guy this was devastating and a little fun to try and discover workarounds before the bad guys so as to patch them.

    • @SStupendous
      @SStupendous Před 2 lety +1

      First Roblox now this, feels sus

    • @mxstee
      @mxstee Před 2 lety

      Is fortnite safe and I haven’t played Minecraft In 2 months u think I’ll be fine

    • @SStupendous
      @SStupendous Před 2 lety +2

      @@mxstee Why would Fortnite not be safe, only a true failure in life would dream of hacking that

    • @mxstee
      @mxstee Před 2 lety

      @@SStupendous true i just didnt know if it had java code in it

    • @TempestaDominus
      @TempestaDominus Před 2 lety

      @@mxstee I think Fortnite should be safe tbh. Though despite everything, I think the company probably already patched regardless.

  • @haxalicious
    @haxalicious Před 2 lety +2467

    The other reason 2b2t was shut down was because the exploit ALSO worked server-side. Meaning anyone could backdoor the server with it. Not just the Minecraft server instance, but the actual dedicated box it runs on. They could crash it, delete the world data, and who knows what else. If the backups are on the same server, they could even take it down permanently.

    • @AxxLAfriku
      @AxxLAfriku Před 2 lety +29

      HELP MY!!! My muscles are too big! I am a big tall man and my muscles are even BIGGER! I use them to get views but they HURT so much!!! Because they are heavy. Do you have any advice, dear hay

    • @Eroil
      @Eroil Před 2 lety +91

      I wonder if people did that while the workarounds still worked and now there are backdoors we just don't know about... If I understand what you're saying correctly, redstoner could've just as easily broken into the server itself if he tried

    • @WinterSWW
      @WinterSWW Před 2 lety +90

      @@AxxLAfriku thats the wierdest comment and if it hurts then stop getting ripped get fat a bit or something

    • @WinterSWW
      @WinterSWW Před 2 lety +7

      For a second i thought i made a comment minutes ago and i forgot it somehow

    • @kyuzyu4702
      @kyuzyu4702 Před 2 lety +2

      Yup they can get access to whole thing but i dont think anyone tried to

  • @iamthesenate6246
    @iamthesenate6246 Před 2 lety +9918

    Fun fact, this was also in some Nasa rovers so technically you could have hacked into a space rover if you got there before nasa did

  • @Chyaman11
    @Chyaman11 Před 2 lety +56

    I thought this title was gonna be clickbait but it’s damn near an understatement

  • @Cheesecake770
    @Cheesecake770 Před 2 lety +23

    Massive Respect for ox22 and Rebane for being such a good homie 👌

  • @justasleepysnowflake
    @justasleepysnowflake Před 2 lety +5843

    That man who "hacked" people to save them is a fricking legend, mad respect for that guy

    • @ronaldwoodworker1192
      @ronaldwoodworker1192 Před 2 lety +172

      he did all that just to be referred to as "that man" 💀

    • @Spookamss
      @Spookamss Před 2 lety +65

      ah yes, hacking people to save them from hackers is tight

    • @heathjake25
      @heathjake25 Před 2 lety +52

      @@Spookamss hacking to unhack.

    • @bluedoge9205
      @bluedoge9205 Před 2 lety +46

      He used the hacks to destroy the hacks

    • @kevinzhao9134
      @kevinzhao9134 Před 2 lety +7

      So... if hack = H, H = -H?

  • @ed-uh9sh
    @ed-uh9sh Před 2 lety +3798

    i still can’t get over how easy it was to use this exploit

    • @arcaneTempest1
      @arcaneTempest1 Před 2 lety +195

      you're phrasing that like you've used it

    • @coconutman7797
      @coconutman7797 Před 2 lety +30

      @@arcaneTempest1 lmao

    • @ghostymytoasty7007
      @ghostymytoasty7007 Před 2 lety +198

      @@arcaneTempest1 it's really not that hard, I wrote a simple script to eject your disk tray. Getting past all the various 'patching' people have done is much harder. But the initial exploit really is as easy as "hi :) how about you run this code I am hosting". That is what an RCE is. The fact it can be so easily done is astounding.

    • @ElectricKitten
      @ElectricKitten Před 2 lety +9

      @@arcaneTempest1 You dont say.

    • @Saturnius
      @Saturnius Před 2 lety +8

      @@arcaneTempest1 I mean, he's not denying it...

  • @Apparently_I_am_everywhere
    @Apparently_I_am_everywhere Před 2 lety +13

    0x22 and Rebane are both legends. Without them, who knows how many more victims there could have been to this hack. They need some sort of recognition or something, because they're noble as hell.

  • @last9up
    @last9up Před 2 lety +1

    Dude I started watching your videos since 2b2t started blowing up and saw your channel grow. I'm so freaking glad you are doing so well. Haven't had time to watch now, but happy to see you succeed.

  • @CeruleanDerpo
    @CeruleanDerpo Před 2 lety +1392

    When Herobrine becomes less scary than some 2b2t players

    • @MrCommentGod
      @MrCommentGod Před 2 lety +23

      -Intense moment-

    • @tisjstme5315
      @tisjstme5315 Před 2 lety +26

      Now THAT is really scary.

    • @optimx314
      @optimx314 Před 2 lety +4

      this account has been ratted by popbob

    • @agoogleuser2507
      @agoogleuser2507 Před 2 lety +12

      Bedrock players go brrr

    • @Mr.D..
      @Mr.D.. Před 2 lety +5

      That’s terrifying I am gonna go back to fortnight

  • @GripGhoul
    @GripGhoul Před 2 lety +1406

    The scariest part is *this exploit was here for like 10 years*

    • @CairoFaustine
      @CairoFaustine Před 2 lety +263

      Anybody could of been using this in secret the whole time before it was discovered, its scary

    • @liamholcroft7212
      @liamholcroft7212 Před 2 lety +78

      @@CairoFaustine perhaps some glowies?

    • @theairaccumulator7144
      @theairaccumulator7144 Před 2 lety +128

      This is really scary. A hacker could have found this long ago just by reading the documentation carefully.

    • @galacticknight55544
      @galacticknight55544 Před 2 lety +73

      @@CairoFaustine Not just that, but who knows how many other exploits there are that hackers might still be using secretly?

    • @petman515
      @petman515 Před 2 lety +45

      @@liamholcroft7212 I know my local police have a habit of illegaly spying on people and from some of the things I've seen I'm pretty sure at least some of it is based on java exploits.

  • @cleverlesstv7724
    @cleverlesstv7724 Před 2 lety +11

    Fit, we need a video about Hausemaster and their history on 2b2t. Who is this mythical figure? Has the identify changed throughout the years? I feel it could be an interesting video.

  • @CocoaPimper
    @CocoaPimper Před 2 lety

    I am binge watching all of your videos. Redstoner comes up so frequenlty. Unbelievable this guy. :D

  • @angelicalgaming9297
    @angelicalgaming9297 Před 2 lety +3132

    I say we all salute 0x22 for his noble intentions. It just goes to show that not everyone is heartless, even hackers. o7

    • @wyndmill
      @wyndmill Před 2 lety +112

      Imagine 0x22 accidently starts a trend where people hack everyone who play minecraft, but then optimizes their computer so everything runs like nasa computers xD

    • @EndingSession
      @EndingSession Před 2 lety +52

      0x22 will go down in history as a minecraft hero

    • @krac_tac117waite7
      @krac_tac117waite7 Před 2 lety +10

      o7

    • @mistqr
      @mistqr Před 2 lety +14

      @@wyndmill tbf I kinda want that to happen

    • @AviaForce
      @AviaForce Před 2 lety +5

      o7.

  • @Qunia
    @Qunia Před 2 lety +855

    This entire exploit is like a level 10 containment breach.
    The fact that script kiddies can just straight up control your PC is horrible.

    • @WeatherWX
      @WeatherWX Před 2 lety +26

      If level 10 is world ending (the one below reality ending) your correct, anything Log4J touches is exploitable IIRC.

    • @rubixtheslime
      @rubixtheslime Před 2 lety +47

      Well you're not wrong, NIST (the organization that assigned it the name CVE-2021-44228) gave it a score of 10.0/10.

    • @TreyG425
      @TreyG425 Před 2 lety

      POV: you don’t play on pc 😶

    • @ADMICKEY
      @ADMICKEY Před 2 lety

      @@TreyG425 yes

    • @amahlaka
      @amahlaka Před 2 lety +4

      Coming from someone who has not slept properly for the past 2 weeks due to this exact vulnerability, it absolutely is.

  • @jamesscalzo3033
    @jamesscalzo3033 Před rokem +1

    Loved the video @FitMC! Can't wait for the next video man! Mad Respect to Ox22 for at least trying to ensure his fellow Minecrafter's Internet Safety. This might really explain all the Changes Minecraft was making with all of the "Security Issues" with things like Switching from Windows Accounts to Java ones. I hope Redstoner was told to "Pay for Damages" to his competitors, but that's just wishful thinking as its an Anarchy Server we're talking about here.

  • @serwalkerofthekeynes8761
    @serwalkerofthekeynes8761 Před 2 lety +2

    This reminds of a story from a while back,not MC related but this dude was a pro hacker.
    He knew he was breaking the law, but he used to hack into people's personal devices and scan for any malicious or fraudulent programmes, patch them out, and then contact the victim and let them know what he'd done and how to prevent it in the future.
    We need more people like that 😅

  • @ShortHax
    @ShortHax Před 2 lety +5038

    The problem: Apache Log4j
    The solution: A patchy Log4j

  • @chester000017
    @chester000017 Před 2 lety +953

    As someone working in CyberSec, this has become so alarming to us that we had a rough week dealing with this problem and had to wait for fix patch from actual developers of log4j. And I had to uninstall my minecraft and scan for vulnerabilities using the available tools that we had. This is a real deal people, don't take this lightly

    • @Laff700
      @Laff700 Před 2 lety +40

      Don't forget the fact that the first patch still had other vulnerabilities!

    • @sonetagu1337
      @sonetagu1337 Před 2 lety +8

      I coudnt play minecraft java even with my laptop because i have no money i have an incosistent internet so im thankfull
      (Sorry for the cringe)

    • @kailo9008
      @kailo9008 Před 2 lety +2

      I'm confused... didn't log4j patch this back in march with v2.15.0? This affected people with outdated java and log4j libraries, the majority of the corporate fixes for this exploit involved updating software and enforcing firewall policy.

    • @doubledoot
      @doubledoot Před 2 lety +2

      Why the hell did the exploit go public in the first place though?

    • @deepbromusic
      @deepbromusic Před 2 lety

      I wish happy New year to you...Can 🙂I get 10k subscribers at the end of this year ... love ❤

  • @SpeedyCheetahCub
    @SpeedyCheetahCub Před 4 měsíci +1

    The person who was hacking people in order to protect them from other hackers reminded me of something I saw a while back where someone was going around hacking printers in order to protect them from other hackers.

  • @christiansilk1455
    @christiansilk1455 Před 2 lety +2

    Never in history of man will you ever see FitMC without his legendary stone slab fireplace

  • @peegion4742
    @peegion4742 Před 2 lety +654

    My dad was actually notified and had a emergency meeting when this happened (he works in cyber risk), he told me it was about minecraft, I though that it was pretty weird then, but forgot about it in an instant. Now that I see how dangerous this actually was I feel really dumb.

    • @CrypticRite
      @CrypticRite Před 2 lety +100

      It was way more widespread then minecraft. The last week, nearly all big cyber based companies had an absolute crazy week scrambling to make sure all abilities to utilize this was patched. Amazon, Google, hell, even nasa and nsa had to take part in their own security checks.

    • @peegion4742
      @peegion4742 Před 2 lety +36

      @@CrypticRite Gosh
      damn now I feel even more stupid for not caring. I need to be more careful...

    • @Crystalelements182
      @Crystalelements182 Před 2 lety +2

      @@CrypticRite seriously!? Wow! 🤯

    • @LazyLoonz
      @LazyLoonz Před 2 lety +19

      @@CrypticRite his dad might've said don't play minecraft as theres a risk that you may get hacked

    • @ineedgoodname
      @ineedgoodname Před 2 lety +8

      My dad works at IT in oracle, who own Java.

  • @MC2738
    @MC2738 Před 2 lety +1578

    As a sysadmin, this week has been rough. I immediately took all servers offline and forced them to check updates, and of course, attempt to patch the exploit. Also, good on Mojang for pulling an all-nighter to fix this exploit.

    • @N0D0hNuts
      @N0D0hNuts Před 2 lety +60

      My main focus was also to get an offline backup of all my servers.
      We updated everything but I don't think we were affected since our servers are basically a share, an sql server and a AD server. I know that the part on top (vmware) is affected but this is up to the cloud server company to update

    • @AndrewBrownK
      @AndrewBrownK Před 2 lety +61

      profile pic checks out

    • @staydying
      @staydying Před 2 lety +5

      what is your pfp dawg

    • @MC2738
      @MC2738 Před 2 lety +20

      @@staydying lmao it's my waifu
      Amaha miu

    • @gogofuntime_yt
      @gogofuntime_yt Před 2 lety +1

      Hey fancy seeing you here

  • @dragongamer4610
    @dragongamer4610 Před rokem +1

    0x22, what a fricking legend. The hero we didn't know we needed

  • @Nicklander
    @Nicklander Před 2 lety +2081

    Imagine you find an exploit to gain full control over everyone’s computer and all you do with it is cancel the ItemShops of your biggest Minecraft enemies.

    • @SBcarsAndOthers
      @SBcarsAndOthers Před 2 lety +20

      ikr

    • @pooperdooper3576
      @pooperdooper3576 Před 2 lety +64

      @Nerdy Cuber he shouldn't be selling minecraft items for irl money though, it's kinda weird, and doesn't it go against tos?

    • @generalgeorge9464
      @generalgeorge9464 Před 2 lety +141

      capitalism

    • @ur_dedmy
      @ur_dedmy Před 2 lety +22

      @@generalgeorge9464 yes

    • @superplushyvids
      @superplushyvids Před 2 lety +67

      @@pooperdooper3576 its an infamous anarchy server, people there dont care about tos lol

  • @oposdeo
    @oposdeo Před 2 lety +398

    I work at a large tech company and every single developer at the company was working late into the night the day this was disclosed, and some over the weekend, to get all of our services and hosts patched. Quite the stressful event.

  • @paganplays8431
    @paganplays8431 Před 2 lety

    When i find FitMC makes a post, i i have to open the page pause video, and make a cup of coffee, cause its always that good!

  • @Lizabitch_
    @Lizabitch_ Před 2 lety

    I’ve seen this community do some crazy stuff. But this is on another level

  • @L30GH05TDUD3
    @L30GH05TDUD3 Před 2 lety +2417

    0x22 and Rebane should be recognized by Mojang and rewarded by their actions. Because their attempts to warn the community and also 0x22 trying patch the exploit itself is a pretty legendary and bold thing to do. My greatest respect to both and hopefully you’ll get rewarded for this someday

  • @MichaelMoore99
    @MichaelMoore99 Před 2 lety +1007

    I really love 0x22's whole ethos. It's definitely a 2b2t thing to do to use the exploit to patch the exploit.
    Very much like Thanos using the stones to destroy the stones.

    • @kinko4786
      @kinko4786 Před 2 lety +8

      Yeah, great comparison.

    • @berkhero3006
      @berkhero3006 Před 2 lety +21

      I cant belive disney copied 0x22

    • @descai10
      @descai10 Před 2 lety +4

      spoilers smh

    • @MichaelMoore99
      @MichaelMoore99 Před 2 lety +1

      @@descai10 How am I supposed to know it's spoilers? I haven't seen the movie. ;-)

    • @Alexander-sr3ng
      @Alexander-sr3ng Před 2 lety +1

      He is the chosen one

  • @lastnamefirstname5289
    @lastnamefirstname5289 Před 2 lety +5

    3:55 It appears that according to this page, server admins could patch their servers without updating.

  • @lonecub101gaming3
    @lonecub101gaming3 Před 2 lety

    I thank you for helping people stay informed and safe.

  • @PRDGL_WindyBW
    @PRDGL_WindyBW Před 2 lety +3337

    Not so fun fact: This is the most dangerous exploit/attack in internet history. It's the first one that's ever been rated 10 out of 10.

    • @rover9300
      @rover9300 Před 2 lety +217

      Damn, and to think it was on Minecraft
      Edit: and to think it started on Minecraft I know it got to other things, I watched the video

    • @velocitygames524
      @velocitygames524 Před 2 lety +348

      @@rover9300 it included Minecraft but also other massive corporations that used the log4 whatever program to make them run smoother Minecraft is just the most used example in this as it’s a Minecraft channel

    • @Lyajka
      @Lyajka Před 2 lety +49

      but you can play doom in minecraft with this exploit

    • @jdmaine51084
      @jdmaine51084 Před 2 lety +82

      @Rover anything that runs Java, there's a high possibility it's logging with log4j. Bro this wasn't just minecraft. I work at SiriusXM - worked 5 hours overnight to patch my stacks. EVERYONE felt this one. What's worse is that the vulnerability had been in the log4j library for quite some time.

    • @rover9300
      @rover9300 Před 2 lety +3

      @@velocitygames524 yup

  • @specificguy3747
    @specificguy3747 Před 2 lety +1543

    Redstoner is certainly going to have a few targets on his head after this

    • @Turbulation1
      @Turbulation1 Před 2 lety +152

      Indeed, but it doesn't matter much to him, since he knocked out major competition to his business. People could however attempt to tarnish Redstoner's reputation, and turn people away from buying stuff from Redstroner.

    • @PeterJavi
      @PeterJavi Před 2 lety +81

      @@Turbulation1 That's assuming all he did was pwn some Minecraft accounts. Doing this, doesn't really make him come across as a guy who'd stop at this. He may very well have stole more than just this.

    • @pync1
      @pync1 Před 2 lety +31

      hopefully he didnt do anything illegal with the hack because then hed have more to worry about than his minecraft market

    • @ugapeyton
      @ugapeyton Před 2 lety +115

      @@pync1 what he did was already illegal.

    • @Brody-gk1yz
      @Brody-gk1yz Před 2 lety +47

      @@ugapeyton Exactly. That makes me think he more then likely did more. I can't imagine some loser doing Just illegal crap for Minecraft.

  • @MrPablosek
    @MrPablosek Před 2 lety +5

    I never thought I would actually be scared to play minecraft until now.

  • @fl0G2
    @fl0G2 Před 2 lety

    its nice to see someone from my country fixing something that important

  • @aerohydreigon1101
    @aerohydreigon1101 Před 2 lety +731

    Let's just take a moment to respect 0x22 and Rebane
    They could've easily stolen Discord messages, Minecraft user data, etc
    But they didn't, and they even went a step further

    • @fefek1
      @fefek1 Před 2 lety +14

      True but, who the hell would want to read a random guy's discord messages?

    • @kenshinkoman2710
      @kenshinkoman2710 Před 2 lety +1

      @@fefek1 Truuuu

    • @ghostlydude6478
      @ghostlydude6478 Před 2 lety +9

      @@fefek1 probably to see if they did anything, ‘questionable,’ like discord mods and kids sort of stuff or just ammunition to blackmail/canceling.

    • @magicalkillerz9130
      @magicalkillerz9130 Před 2 lety +1

      @@fefek1 blackmail

    • @CloudiStuff
      @CloudiStuff Před 2 lety

      If the random person shared private info via dms, they could use that data maliciously

  • @TheRealGuywithoutaMustache
    @TheRealGuywithoutaMustache Před 2 lety +1906

    Lesson learned. Hackers are genuinely really scary people.

    • @MattBasicG
      @MattBasicG Před 2 lety +17

      Yes indeed

    • @Gianski150
      @Gianski150 Před 2 lety +71

      Its never a joke to take lightly on hackers. They're crafty and once they see a vulnerability, expect hell let lose.

    • @Dr4g0Npc
      @Dr4g0Npc Před 2 lety +4

      we are not

    • @xc1951
      @xc1951 Před 2 lety +72

      Untill you find them in person

    • @cccbowers914
      @cccbowers914 Před 2 lety +16

      agreed, but not as scary as you being litterly everywhere

  • @geldmoney
    @geldmoney Před 2 lety

    Man you're a really interesting youtuber.. subscribed!

  • @isaacuchiha4948
    @isaacuchiha4948 Před 2 lety +4

    Respect to Rebane who played a crucial role in protecting the server and other people

  • @housesports000
    @housesports000 Před 2 lety +482

    Only Fit can say “smiley face” and make it sound so ominous

  • @CatThatFollowsChrist
    @CatThatFollowsChrist Před 2 lety +213

    That is the most terrifying exploit I've seen in a while. And for the first time, I know people irl who were affected.

  • @cosmonaut9999
    @cosmonaut9999 Před 2 lety

    I recognize that music! Nice video, man.

  • @jere1124
    @jere1124 Před měsícem +1

    I was aware of this at the time but when this happened i was only playing bedrock and didnt have java so i wasnt affected but after hearing what was going on i got a little scared

  • @NaughtyKlaus
    @NaughtyKlaus Před 2 lety +650

    The only way to be 100% sure that it’s patched is to remove log4j entirely, but too many systems rely on it so that’s unlikely.

    • @noobster6587
      @noobster6587 Před 2 lety

      That's true

    • @humorousfool215
      @humorousfool215 Před 2 lety +38

      The latest version of log4j has the entire feature disabled so it is safe

    • @Alnarra
      @Alnarra Před 2 lety +9

      Unless you're running either tomcat or a beanfactory module or a VERY specific config, simply updating it to 2.15 should be suffecient. If you're running tomcat take it to 2.16

    • @mesayhello840
      @mesayhello840 Před 2 lety

      It is not patched. Me and my friend tried to do this multiple times like a hour ago. And it worked so... :D I have more stuff to abuse :)

    • @aetimes2
      @aetimes2 Před 2 lety

      @@mesayhello840 have you updated?

  • @unfairbullet
    @unfairbullet Před 2 lety +390

    I don’t understand how over the last few months I’ve become so emotionally invested in a random Minecraft server that I’ve never played on

    • @eduard5567
      @eduard5567 Před 2 lety +16

      yeah well there are millions more like you. literally. theres only like maximum a thousand people who log in to play 2b2t. everyday.

    • @POPCORN-ru5nl
      @POPCORN-ru5nl Před 2 lety +1

      same

    • @golonkowiczpl
      @golonkowiczpl Před 2 lety +3

      This server has the most advanced history in this game

    • @suomusintti
      @suomusintti Před 2 lety +7

      You should try it. I'm currently in queue as 367 and it's my first time

    • @THECRINGERAILWAY
      @THECRINGERAILWAY Před 2 lety +2

      You aren’t the only one…

  • @hybrid5568
    @hybrid5568 Před rokem

    I feel very fortunate to have started my minecraft journey last year about this time. I dodged a few bullets that affected other minecrafters and 2b2t. That's insane things like that can happen

  • @pentagoo4586
    @pentagoo4586 Před 2 lety +7

    Bruh I played in those days and knew nothing about this lmao

  • @iv4n380
    @iv4n380 Před 2 lety +406

    the scary part is that this exploit has been here all these years....and someone has probably been using it...imagine how much data has been collected..

    • @WolfrostWasTaken
      @WolfrostWasTaken Před 2 lety +79

      Cloudflare (which proxies like 80% of the entire internet requests) reported that absolutely no one tried to pass that malicious payload since 2011 (they keep logs of every single request since 2011!!!!)

    • @starkbeatle4516
      @starkbeatle4516 Před 2 lety +8

      possibly but nah cus it was only truly found recently so i doubt it

    • @tomsterbg8130
      @tomsterbg8130 Před 2 lety +5

      Usually vulnerabilities occur when unsuccessful update attempts happen which makes me lean towards it's not that long since it was even possible not to mention it's announcement of founding

    • @HNSYV107
      @HNSYV107 Před 2 lety +3

      i still dont think those amount of data could beat big guys like zuckerberg

    • @NightUndead
      @NightUndead Před 2 lety +18

      @@WolfrostWasTaken That is actually quite eye opening... To think they have data on EVERY SINGLE request they've had through their servers for the last 10 years.... wow

  • @Lettuce1
    @Lettuce1 Před 2 lety +594

    The log4shell exploit is so devastating to the internet. You’d think that something like this would be spotted and fixed very quickly.

    • @ChristopherGray00
      @ChristopherGray00 Před 2 lety +18

      The apache team working on log4j are morons simply put, best to not use log4j at all. They were given ample warning.

    • @Alnarra
      @Alnarra Před 2 lety +21

      Most of the libraries that make up the backbone of the internet's infrastructure are maintained by single individuals and never get real security reviews.

    • @Lettuce1
      @Lettuce1 Před 2 lety +28

      @@Alnarra the problem with this argument is that log4j is not run by an induvidual

    • @thaliacrafts407
      @thaliacrafts407 Před 2 lety +18

      Makes me wonder how many gaping holes are in software we use everyday. Everybody gangsta until someone hacks our water treatment plants.

    • @doubledoot
      @doubledoot Před 2 lety

      Yeah. Why the hell did the exploit go public in the first place?

  • @rolo8950
    @rolo8950 Před 2 lety

    I've never played Minecraft in my life yet I love your videos lol

  • @trey3530
    @trey3530 Před 2 lety

    the ffxv ost in the backround is a nice touch

  • @Eugene-pq3gg
    @Eugene-pq3gg Před 2 lety +511

    This is like the fourth time Fit has saved me from some kind of exploit.
    It's mostly by warning me not to pick Minecraft back up for now, but still.

    • @Eugene-pq3gg
      @Eugene-pq3gg Před 2 lety +4

      @@TheBinklemNetwork Thanks for mentioning.
      I'll probably end up doing it, but the fact stands that without finding this I might had been in trouble.

    • @cd-rom9226
      @cd-rom9226 Před 2 lety +3

      Stay safe mate

    • @TheBinklemNetwork
      @TheBinklemNetwork Před 2 lety +3

      @@Eugene-pq3gg definitely good that it is a known factor now! Its is always good to show restraint if you yourself aren't fully convinced on somethings safety!

    • @intelxio
      @intelxio Před 2 lety +2

      ONG BRO LMAOOOO

    • @gethinevans_
      @gethinevans_ Před 2 lety +1

      @@TheBinklemNetwork is realm’s with friends safe?

  • @funkyskunk1
    @funkyskunk1 Před 2 lety +493

    Future FitMC video:
    "Minecraft is assumed to be a harmless children's game for all ages. But this can't be said on the Oldest Anarchy Server in Minecraft. Here's the story of how a certain 2b2t player was linked to child exploitation and human trafficking."

    • @davidarvingumazon5024
      @davidarvingumazon5024 Před 2 lety +2

      Duuuuuude...
      Scawwwy fr!!!!¡!!¡¡!¡¡!!!!

    • @jwalster9412
      @jwalster9412 Před 2 lety +36

      Wouldn't be surprised lol.

    • @toddaustin449
      @toddaustin449 Před 2 lety +10

      If it does happen, 2b2t would just get shut down by whatever gov't the server rack it is or where hausemaster is

    • @TheRenegade...
      @TheRenegade... Před 2 lety +20

      @@toddaustin449 Bold to assume it hasn't already happened and we don't know yet

    • @MrcreeperDXD777
      @MrcreeperDXD777 Před 2 lety +23

      I wont be surprised if it was real. Actual criminals did play on 2b2t

  • @KaiTweak
    @KaiTweak Před 2 lety

    Thanks you for explaining this so good :)

  • @lemystwq
    @lemystwq Před 2 lety

    First real quarantined to our houses now were quarantined out of minecraft. What a crazy few years

  • @-Clueless-
    @-Clueless- Před 2 lety +278

    Imagine how much issues we could solve and fix if people put the same amount of time and effort they use to break and destroy things.

    • @noahjordan6761
      @noahjordan6761 Před 2 lety +15

      But breaking things is fun

    • @LazyBuddyBan
      @LazyBuddyBan Před 2 lety +3

      cope & seethe

    • @kendriccolamaricco2050
      @kendriccolamaricco2050 Před 2 lety +4

      @@LazyBuddyBan ur mom

    • @tisjstme5315
      @tisjstme5315 Před 2 lety +8

      @@noahjordan6761 Sorry but helping others and saving people is WAY MORE FUN.

    • @WorlWyrm
      @WorlWyrm Před 2 lety +3

      @@tisjstme5315 now imagine this, what is more fun?
      Destroying a Minecraft house or building one?

  • @ThistleBlue
    @ThistleBlue Před 2 lety +380

    Ah yes, Log4J, the Java logging framework. Funny thing is I just got a job in Java and they have an intro to logging. Better not be an unpatched log4j haha

    • @daizdamien1409
      @daizdamien1409 Před 2 lety

      Mmmm you got a job in java? Lol

    • @SkyRecruit18
      @SkyRecruit18 Před 2 lety +29

      @@liamd969 his job is probably based around making programs with java or java level security at an office job

    • @ThistleBlue
      @ThistleBlue Před 2 lety +10

      @@SkyRecruit18 Partially. Software Dev and Testing. No office though haha

    • @herrforehead3745
      @herrforehead3745 Před 2 lety +9

      @@daizdamien1409 as in a job that requires knowledge in java, he said in not at 😐

    • @ineedgoodname
      @ineedgoodname Před 2 lety +1

      @@liamd969 maybe he works at Oracle?

  • @3sum4sum
    @3sum4sum Před 2 lety

    Found FitMC on Facebook Watch! Really grabbed my attention and interest. Keep it up! You gained a Sub today!

  • @saffa3306
    @saffa3306 Před 2 lety +10

    As long as they haven't used Intel's backdoor vulnerabilities you are safe after resetting your PC. If they did use this vulnerability, i recommend getting a new motherboard.

  • @tedmcbur
    @tedmcbur Před 2 lety

    I like it how popular 2b2t players render your thumbnails

  • @byrobuff8485
    @byrobuff8485 Před 2 lety +68

    I tried to warn a server about the exploit. They banned me for spreading false panic. Later the server was shut down because of it lmao

  • @algonz5652
    @algonz5652 Před 2 lety +77

    "We built this city"
    Log4Shell: Allow me to introduce myself

    • @carolesheen3940
      @carolesheen3940 Před 2 lety

      he should really be in the trillion views and counting song

  • @Candied_Shrimp
    @Candied_Shrimp Před 2 lety +3

    Fit, you should make a vid on 2b2t's admin Hausemaster. I think it will be an interesting story :)

  • @MinecraftProLord
    @MinecraftProLord Před 2 lety

    I am very glad my siblings and I were inactive around the time this happened.

  • @raiiban
    @raiiban Před 2 lety +80

    Can confirm. Lead Network Engineer at my company, this exploit nuked my week, I busted ass to get about 95% of my customers patched and additional staff trained on what to do if anything happened, I have vacation starting today thru to the end of the year and I wasn't about to let this crap ruin it.

    • @makimaistrash
      @makimaistrash Před 2 lety +9

      great work I hope you have an excellent vacation

    • @exultant4921
      @exultant4921 Před 2 lety +6

      Awesome man hope you have a great time

    • @lucasharvey8990
      @lucasharvey8990 Před 2 lety +1

      Humanity doesn't deserve you, but we sure do need you.

  • @MerlinDeLyon
    @MerlinDeLyon Před 2 lety +161

    The Minecraft community has just gone through one of the scariest weeks in its history... And i was completely unaware :p

    • @nvapisces7011
      @nvapisces7011 Před 2 lety +30

      Meanwhile, Minecraft is celebrating 1 trillion views on CZcams

    • @robertblunt1852
      @robertblunt1852 Před 2 lety +13

      same I play on Bedrock tho but still

    • @lamarr51
      @lamarr51 Před 2 lety

      Same lmao, I've just been trucking in Snowrunner and since I'm subbed to FitMC I decided to check this vid

    • @neru1584
      @neru1584 Před 2 lety +1

      Minecraft: players hacked, scariest week in history
      CZcams: one trillion views :DDD

    • @ItsRedPanda
      @ItsRedPanda Před 2 lety

      same

  • @myomama8815
    @myomama8815 Před 2 lety +2

    huge respect for 0x22 and rebane

  • @michelleenderink3664
    @michelleenderink3664 Před rokem

    This actually happened on my birthday. What could i've imagined that day that things like this would happend. But for myself I don't play Java, I have it but I play bedrock so i'm save.
    But this is scary. Respect to the man who saved it!

  • @rjwilliams1986
    @rjwilliams1986 Před 2 lety +874

    Redstoner really is becoming a legend on the server. Seems every couple of months he is involved with something that gets fitmc video-worthy.

    • @cosmiceyness
      @cosmiceyness Před 2 lety +81

      he is a demon bro

    • @twosadcows4549
      @twosadcows4549 Před 2 lety +105

      Sounds to me like Redstoner is a trashcan that does t deserve to breath the same air as the rest of us. If he is doing this on a video game what do you think he is doing to people's personal lives...

    • @lauta8638
      @lauta8638 Před 2 lety +123

      @@twosadcows4549 redstoner killed my mother and dog

    • @augere9620
      @augere9620 Před 2 lety +96

      Sounds like he wants to be arrested. He committed some major felonies.

    • @fencingf3003
      @fencingf3003 Před 2 lety +23

      He’s just the only one that fit listens to. A bunch of other people do cool shit but no one ever hears abt it cause redstoner gets all the attention.

  • @brambleblaster
    @brambleblaster Před 2 lety +594

    Further proof that 2b2t is a lawless land. Even if it was restricted to griefing attempts, the fact people like Redstoner just don't think twice about abusing a dangerous hack like this really puts into perspective how degenerate and scary anarchy servers really are.

    • @UltraAryan10
      @UltraAryan10 Před 2 lety +35

      This could happen in any big server which end up with some malicious people. So just play minecraft with your friends if you wanna have a really good chance to stay safe.

    • @chicotada7078
      @chicotada7078 Před 2 lety +29

      redstoner is just working, selling items must be he's income

    • @epicgizmo5565
      @epicgizmo5565 Před 2 lety +26

      @@chicotada7078 destroying peoples shops that illegal even in the real world he isn't working

    • @noahjordan6761
      @noahjordan6761 Před 2 lety +20

      @@epicgizmo5565 it's not really appropriate to say "even in the real world". The point of an anarchy server is to be lawless, more so than the real world(if you consider it reality ofc)

    • @mintonpizza
      @mintonpizza Před 2 lety +1

      I agree *Mr. Jellyfart*

  • @twinny643
    @twinny643 Před rokem

    i just watched your video with a special guest, but now i know the thing about the calculator thx :)

  • @Dovwah
    @Dovwah Před 2 lety

    The song in the beginning is - veiled aggression from ffxv

  • @norsethenomad5978
    @norsethenomad5978 Před 2 lety +166

    I recall getting a message on my Minecraft server talking about this exploit, and they put forth the effort to stop it almost immediately

    • @uncletoby7456
      @uncletoby7456 Před 2 lety

      Same I play on a server called simply vanilla and it go shut down for two days and is not safe, hopefully.

    • @Jedssski
      @Jedssski Před 2 lety

      Whoever those people are. They are heroes.

  • @noskalborg723
    @noskalborg723 Před 2 lety +183

    i can only begin to imagine the damage this did to business programs run on java. it begs the question: why did that code exist in the first place?

    • @CanadianBaconPwnage
      @CanadianBaconPwnage Před 2 lety +54

      Human error. Sometimes, things fall through the cracks.

    • @marioisawesome8218
      @marioisawesome8218 Před 2 lety +21

      @@CanadianBaconPwnage today i shall make the worst error ever by adding a few lines of code to enable unimaginable RCE exploits because i am completely stupid.

    • @ravenwraith1017
      @ravenwraith1017 Před 2 lety +19

      @@CanadianBaconPwnage sounds like it is due to pure human laziness, actually.

    • @TorutheRedFox
      @TorutheRedFox Před 2 lety +10

      @@ravenwraith1017 well it's moreso a series of assumptions that something won't happen eventually leading to an ACE exploit

    • @AJMansfield1
      @AJMansfield1 Před 2 lety +6

      You know how sometimes in a card game like MTG you can end up with absolutely broken combos when different effects interact in just the right way before they release an errata or add one of the cards to the ban lists? Log4shell is kinda like that, where different developers added more and better features to different parts of the code until suddenly someone figured out some way to get it to all interact in a way that would give them RCE.

  • @Exderius
    @Exderius Před rokem

    Keep up the great work

  • @tsgmer
    @tsgmer Před 2 lety

    Hey nice vid! Also, is that final fantasy 15 music in the back round?

  •  Před 2 lety +1613

    I remember the day this came out. The past week has been absolutely insane

    • @troncis2940
      @troncis2940 Před 2 lety +1

      ok

    • @ThePrimeYeeter
      @ThePrimeYeeter Před 2 lety +55

      "Oh WoW vERY OrigINAl coMMenT"

    • @curaphix
      @curaphix Před 2 lety +40

      Hey I watched a video on you earlier it was about verified commenters and how they *buy* their way to success

    • @dingbaaat5569
      @dingbaaat5569 Před 2 lety

      Wait that’s crazy me too

    • @mehpainter
      @mehpainter Před 2 lety

      Same, amazing to think that it wasn't very major to me when I first learned about it

  • @lX_DDl
    @lX_DDl Před 2 lety +654

    The disappointing thing is that anyone could do it with the right tools (those tools won’t hard to find or get).

    • @ultimateburrito534
      @ultimateburrito534 Před 2 lety +52

      the scariest part is that the tools required is just a normal game client

    • @oooioioi9437
      @oooioioi9437 Před 2 lety +1

      Indeed

    • @braindamage1
      @braindamage1 Před 2 lety +1

      Oh s#£t

    • @SECONDQUEST
      @SECONDQUEST Před 2 lety

      Is it really? Or do you just think it should be harder? It's literally something we do our hardest to avoid.

  • @tut-4126
    @tut-4126 Před 11 měsíci

    6:30 MY GOD the dungeon music from FFXV... My favourite!!

  • @rw8628
    @rw8628 Před rokem

    fit:"In the midst of chaos, there is opportunity."
    sounds like sun tzu

  • @thehighgroundhimself736
    @thehighgroundhimself736 Před 2 lety +35

    Pretty big bruh moment for anyone working IT including myself. You just come to work one day and someone says:
    "Our software has a critical security flaw."
    "Oh shit, which one?"
    "Idk, maybe all of them, also Minecraft, Google, Microsoft and the NSA have the same problem with their software."

    • @amahlaka
      @amahlaka Před 2 lety +3

      Even better:
      “We need a list of all of our servers and applications that use log4j, but we dont have proper software/server inventory”

  • @somethingcoolgoeshere
    @somethingcoolgoeshere Před 2 lety +85

    Makes me happy knowing some people used the exploit for good and patched others computers

  • @squiddyseut6103
    @squiddyseut6103 Před 2 lety +1

    Just imagine this paired with the copenheimer bot, allowing people to access millions of computers from servers people think are personal or computer, even accessing Jebs computer

  • @JimFourOneTwoThree
    @JimFourOneTwoThree Před 2 lety +4

    Minecraft speedrunners, playing single player this whole time:
    *this is fine*

  • @nieluse7847
    @nieluse7847 Před 2 lety +266

    0x22 and Rebane was a real one, trying to protect innocent players against the exploit. Mean wile redstoner was just being a disgusting human being.

    • @Hirpeeda
      @Hirpeeda Před 2 lety +48

      I wouldn't be surprised if Redstoner got into legal trouble over this

    • @rosea1505
      @rosea1505 Před 2 lety +56

      I know it’s an anarchy server but they should ban the f*ck permanently. He’s a literal security risk. He’s willing to break the law, putting users private info at risk just to earn him money IRL. If the anarchy is outside of the sever than punishments have to be given imo

    • @Caio99BR
      @Caio99BR Před 2 lety +21

      Redstoner: business is booming

    • @plygem6927
      @plygem6927 Před 2 lety

      @@rosea1505 isnt that actually against TOS?

    • @starkbeatle4516
      @starkbeatle4516 Před 2 lety

      @@Caio99BR fax another day another dollar

  • @tytanium4701
    @tytanium4701 Před 2 lety +106

    As an owner of a small survival server, when i received a discord ping from a moderator it shook me to my core that my friends could be at risk. I have a fairly active playerbase so i couldnt just shut down the server for days but i found disabling chat worked well.

    • @sypheur27
      @sypheur27 Před 2 lety +8

      But, and this is just a theory, but do you think that one could manage to run the exploit on something else that text can be written on, such as a sign

    • @quantumz4625
      @quantumz4625 Před 2 lety +3

      @@sypheur27 well the sign would probably have to be chunk loaded, but then it could be MUCH more harmful if like that

    • @Johncw87
      @Johncw87 Před 2 lety +15

      @@sypheur27 It probably wouldn't work, unless you had a plugin or something that logs all sign messages. The text actually has to be passed to the logging library for the exploit to work. Chat is by default, signs are not.

    • @YplanAnimator
      @YplanAnimator Před 2 lety +2

      they can also backdoor the server.

    • @quantumz4625
      @quantumz4625 Před 2 lety +1

      @@Johncw87 oh that makes more sense

  • @milenatomanic951
    @milenatomanic951 Před rokem +3

    Redstoner should go to jail for life and have everything taken away from him

  • @BassArt8600
    @BassArt8600 Před 2 lety

    the funny thing is i had no internet for all this, so I just learned about this now.