Log4JExploit-Fix PUBLIC ARCHIVE icon

Log4JExploit-Fix PUBLIC ARCHIVE -----

log4j, exploit, fix, crash, rce, client side, server side




Version: 1.3.3
Can fix it?

[16:32:01] [Server thread/ERROR]: [Log4JExploitFix] Unhandled exception number 256 occurred in onPacketSending(PacketEvent) for Log4JExploitFix
java.lang.IndexOutOfBoundsException: Index 0 out of bounds for length 0
at jdk.internal.util.Preconditions.outOfBounds(Preconditions.java:64) ~[?:?]
at jdk.internal.util.Preconditions.outOfBoundsCheckIndex(Preconditions.java:70) ~[?:?]
at jdk.internal.util.Preconditions.checkIndex(Preconditions.java:266) ~[?:?]
at java.util.Objects.checkIndex(Objects.java:359) ~[?:?]
at java.util.ArrayList.get(ArrayList.java:427) ~[?:?]
at dev.luzifer.log4jexploitfix.Log4JExploitFix$1.onPacketSending(Log4JExploitFix.java:52) ~[Log4JExploitFix-1.3.3.jar:?]
at com.comphenix.protocol.injector.SortedPacketListenerList.invokeSendingListener(SortedPacketListenerList.java:195) ~[ProtocolLib (3).jar:?]
at com.comphenix.protocol.injector.SortedPacketListenerList.invokePacketSending(SortedPacketListenerList.java:149) ~[ProtocolLib (3).jar:?]
at com.comphenix.protocol.injector.PacketFilterManager.postPacketToListeners(PacketFilterManager.java:547) ~[ProtocolLib (3).jar:?]
at com.comphenix.protocol.injector.PacketFilterManager.invokePacketSending(PacketFilterManager.java:521) ~[ProtocolLib (3).jar:?]
at com.comphenix.protocol.injector.netty.manager.NetworkManagerInjector.onPacketSending(NetworkManagerInjector.java:99) ~[ProtocolLib (3).jar:?]
at com.comphenix.protocol.injector.netty.channel.NettyChannelInjector.processOutbound(NettyChannelInjector.java:570) ~[ProtocolLib (3).jar:?]
at com.comphenix.protocol.injector.netty.channel.NettyChannelInjector$2.proxyRunnable(NettyChannelInjector.java:473) ~[ProtocolLib (3).jar:?]
at com.comphenix.protocol.injector.netty.channel.NettyEventLoopProxy.execute(NettyEventLoopProxy.java:220) ~[ProtocolLib (3).jar:?]
at net.minecraft.network.Connection.sendPacket(Connection.java:433) ~[?:?]
at net.minecraft.network.Connection.send(Connection.java:380) ~[?:?]
at net.minecraft.server.network.ServerGamePacketListenerImpl.send(ServerGamePacketListenerImpl.java:2165) ~[?:?]
at net.minecraft.server.network.ServerGamePacketListenerImpl.send(ServerGamePacketListenerImpl.java:2151) ~[?:?]
at com.comphenix.protocol.reflect.accessors.DefaultMethodAccessor.invoke(DefaultMethodAccessor.java:23) ~[ProtocolLib (3).jar:?]
at com.comphenix.protocol.injector.netty.channel.NettyChannelInjector.sendServerPacket(NettyChannelInjector.java:293) ~[ProtocolLib (3).jar:?]
at com.comphenix.protocol.injector.netty.channel.NettyChannelInjector.lambda$processOutbound$5(NettyChannelInjector.java:564) ~[ProtocolLib (3).jar:?]
at org.bukkit.craftbukkit.v1_19_R1.scheduler.CraftTask.run(CraftTask.java:101) ~[paper-1.19.2.jar:git-Paper-278]
at org.bukkit.craftbukkit.v1_19_R1.scheduler.CraftScheduler.mainThreadHeartbeat(CraftScheduler.java:483) ~[paper-1.19.2.jar:git-Paper-278]
at net.minecraft.server.MinecraftServer.tickChildren(MinecraftServer.java:1473) ~[paper-1.19.2.jar:git-Paper-278]
at net.minecraft.server.dedicated.DedicatedServer.tickChildren(DedicatedServer.java:446) ~[paper-1.19.2.jar:git-Paper-278]
at net.minecraft.server.MinecraftServer.tickServer(MinecraftServer.java:1397) ~[paper-1.19.2.jar:git-Paper-278]
at net.minecraft.server.MinecraftServer.runServer(MinecraftServer.java:1173) ~[paper-1.19.2.jar:git-Paper-278]
at net.minecraft.server.MinecraftServer.lambda$spin$0(MinecraftServer.java:305) ~[paper-1.19.2.jar:git-Paper-278]
at java.lang.Thread.run(Thread.java:833) ~[?:?]

Version: 1.3.3
[ProtocolLib] [PacketFilterManager] [Log4JExploitFix] Unsupported server packet in current Minecraft version: CHAT[PLAY, SERVER, 15, classNames: [net.minecraft.network.protocol.game.PacketPlayOutChat, net.minecraft.network.protocol.game.ClientboundChatPacket, net.minecraft.network.play.server.SPacketChat] (unregistered)]

Are you sure you tested it on 1.19.2?

Version: 1.3.3
gooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooooood

Version: 1.3.3
This plugin is just perfect .

Version: 1.3.3
So People says you dont need it so for extra protection i will download it You Guys are awesom

Version: 1.3.3
Seems to be good. Thank you Cipher.

(( Your review must be at least 80 characters ))

Version: 1.3.3
The best plugin against the Log4j exploit! It reliably protects the players from malicious messages and comes with an additional "protected" logger. - This is particularly good for analyzing the bad messages. - The author is friendly and constantly updates the plugin, so you can assume that you will be well equipped against this exploit in the future, too. :)

Version: 1.3.2
This plugin is very good. The plugin does not completely patch the exploit but it blocks hackers from hacking other players. I would recommend this on your server to protect your players!

Version: 1.3.1
Yeah. I'm using it, hope it helps my server and everyone....................................

Version: 1.3.1
Not sure why people are giving it 1 star because it isn't bypassing any checks I tried.

I tried the following attacks on 1.8 to see if anything would be logged and they were all removed as message:
- Log in with a cracked account with the URL as name -> Name 24>16 and not logged. it's impossible to fit the evil URL as name while not breaking the 15 character limits.
- Simply say the message, message didn't show up, gave a warning I tried to break the server.
- Rename item to message, kill message didn't show up and wasn't logged, so worked good as well.
- Rename mob to message, when player gets killed by mob, the message also gets removed.

If there's any way to bypass it I'd change my rating but for now it doesn't seem to allow any logging to go through.

Version: 1.3.1
... Still easily exploitable, don't use this. Update your server and tell people to use Vanilla clients/updated mod loaders.

Version: 1.2
Very smart idea, this will keep players safe even if they use custom clients to play.
-
Author's response
thanks :)

Version: 1.2
This plugin does not patch the exploit fully, there are several ways to bypass the exploit, both on the server side and on the client side. DO NOT USE THIS PLUGIN.
-
Author's response
Oh hello,

as i can see you found the way from papermc-discord, where you jumped on me and stated this plugin AND its functionality as very dangerous and malicious, to my resource page where you now... do the same?

Why are you saying everywhere that people should not protect themselves sufficiently from the exploit using an additional plugin besides the updates?

Nowhere it states that it will 100% fix anything, it just blocks the execution of the exploit. The exploit is still there if you dont update.

The integrated filter system filters the logs which, would've been produced by Log4J in the next moment, for the malicious strings. If it found any, it will cancel the logging. To protect the player clients it blocks the spreading of the exploit over the chat at protocol-level which would cause getting the message logged clientside. Just for your information.

Version: 1.1
I wonder what's the command :) ?
-
Author's response
¯\_(ツ)_/¯

Version: 1.1
Very dumb, first at all SpigotMC/Paper (Incluiding the forks) fixed already it (Or still on debug), also doesn't fix really all.
-
Author's response
read the description again. server, and *client*side. the plugin blocks the message so it doesn't get logged for both sides. the fixes of spigot or paper are just serverside

Version: 2021-12-10
This does not fully fix the issue. Some examples of when this could still affect the server:
- If a user were to include the text in a command. (Including to another player like /msg)

This only prevents the player from typing into chat when it needs to prevent it in many many more scenarios.
-
Author's response
hey, have been fixed now :)

Version: 2021-12-10
Plug-in is very good, thank you for sharing, I found a few BUG, private chat players can still lead to card suits, hope repair, thank you for your selfless dedication
-
Author's response
hey, thank you. fixed! :)

Version: 2021-12-10
Başarılı eklenti. Böyle bir eklentiyi hızlı ve ücretsiz olarak sağladığın için çok teşekkürler. Gördüğüm kadarıyla emeğinin karşılığını alamıyorsun. Umarım bir gün yaptığın işin karşılığını alırsın.
Successful plugin. Thank you very much for providing such an add-on quickly and for free. As far as I can see, you're not getting paid for your work. I hope one day your work will be rewarded.
-
Author's response
thank you :)

Resource Information
Author:
----------
Total Downloads: 11,409
First Release: Dec 9, 2021
Last Update: Dec 21, 2021
Category: ---------------
All-Time Rating:
18 ratings
Version -----
Released: --------------------
Downloads: ------
Version Rating:
----------------------
-- ratings