Hackers exploit BleedingPipe RCE to target Minecraft servers, players

https://www.bleepingcomputer.com/news/security/hackers-exploit-bleedingpipe-rce-to-target-minecraft-servers-players/

Hackers are actively exploiting a 'BleedingPipe' remote code execution vulnerability in Minecraft mods to run malicious commands on servers and clients, allowing them to take control of the devices.

73 points · 3 comments · view on lemmy.world

3 Comments

2xsaiko@discuss.tchncs.de · 11 pts · 3y

I wish newer Java versions would disable object streams by default. They're such a horrible feature and should never be used. Especially over the network.

zurvan2@lemmy.world · 4 pts · 3y (1 reply)

Bear in mind these are very old versions of minecraft. Mods on these versions are still somewhat popular in a dedicated group, but these won't be a problem for a typical minecraft player.

style99@kbin.social · 5 pts · 3y

That said, EnderIO in 1.12 is probably still fairly popular. It would be a good idea for server admins and players who use that mod in particular to look into this.