Critical flaw in Minecraft's code meant anybody could crash any server
The easily triggerable exploit, which involves flooding the server with infinitely looping requests for information about a specific inventory slot, brings Minecraft to its digital knees and starves the machines of CPU and memory.
Rather alarmingly, it's claimed that the vulnerability was privately revealed to Mojang almost two years ago, and that no action was taken by the developer at the time.
The coder who discovered the flaw, Ammar Askar, said he had made repeated attempts to draw Mojang's attention to the bug, before giving up and taking the drastic measure of publicly revealing it on his blog. Ars Technica has the nitty gritty.
"The version of the game when the vulnerability was reported was 1.6.2, the game is now on version 1.8.3," wrote Askar. "That's right, two major versions and dozens of minor versions and a critical vulnerability that allows you to crash any server, and starve the actual machines of CPU and memory was allowed to exist."
The now publicly available and easily recreatable exploit has finally drawn the attention of Mojang, who have been in touch with Askar and issued a fix.
Posted:
Related Forum: PC Gaming Forum
Source: http://www.pcgamesn.com/minecraft/a-critical-flaw-in-minecrafts-code-meant-anybody-could-crash-any-server
Related Articles
Comments
JRMHPosted:
Unless it actually takes money out of their pockets, they won't do anything about it. Ridiculous.
I kinda wish I knew about this beforehand though, would love to go onto corrupt servers and do it. Lol.
I kinda wish I knew about this beforehand though, would love to go onto corrupt servers and do it. Lol.
DeluxeHazardPosted:
This is one thing that is so annoying about big companies. They learn about huge exploits or issues in their servers and do nothing about it. It will sooner or later affect their customers and they will be incredibly pissed off at the company for them not doing anything about it earlier to prevent the issue.
SkittlePosted:
This reminds me of the russian coder who found out how to delete any video from YouTube, I am surprised that Mojang did nothing to fix this!
Latest Downloads
- 01. Red Dead Redemption 2: Save Game (all bags)(0)
- 02. My Summer Car: SaveGame (Sporty white Satsuma)(0)
- 03. Cubium: SaveGame (The Game done 100%)(0)
- 04. Pure: SaveGame (The game is 100% complete) [R.G. Catalyst](1)
- 05. Cat Quest 3: SaveGame (Before the final boss, level 199)(1)
- 06. Bridge Constructor Portal: SaveGame (The game done 100%)(0)
- 07. [EU] CarX D.R.O. - Level 25 [CUSA15633](4)
- 08. [EU] CarX D.R.O. - Level 25 Trophy(2)
- 09. Gears 5: Save Game (100% Completed + Hivebusters DLC Completed)(4)
- 10. Leisure Suit Larry: Box Office Bust - SaveGame(1)
- 11. [EU] Dying Light 2 -Special Walz Edition (CUSA28617)(28)
- 12. Hellgate London - SaveGame (completed to the station Charing cross)(0)
- 13. Jade Empire: Special Edition - SaveGame (18 lvl, 100%)(1)
- 14. BB-Daman Bakugaiden V: Final Mega Tune(0)
- 15. Black Myth: Wukong - SaveGame (Saves before some bosses)(2)
Latest Tutorials
- 01. PS3 HEN - Audio via a USB headset.(811)
- 02. Stumble Guys | Social Butterfly Achievement(469)
- 03. Last Days of Lazarus Achievement Walkthrough (Xbox/PS)(1,766)
- 04. EDENGATE: The Edge of Life - 100% Trophy/Achievement Guide(2,232)
- 05. Sherlock Holmes Chapter One | Walkthrough | No Commentary(1,813)
- 06. Morbid: The Seven Acolytes | Full Game Walkthrough(2,955)
- 07. Adam Wolfe | Full Game Walkthrough | No Commentary(1,962)
- 08. ALFRED HITCHCOCK: VERTIGO - 100% Walkthrough(2,416)
- 09. SHERLOCK HOLMES THE AWAKENED | Walkthrough | No Commentary(1,677)
- 10. Space Roguelike Adventure | Guide - Cheat Code!(1,968)
- 11. DETECTIVE Stella Porta Case | Trophy & Achievement Guide(1,448)
- 12. Tunic 100% Platinum Walkthrough | Trophy & Achievement Guide(2,150)
- 13. Outbreak: The Nightmare Chronicles Achievement Walkthrough(1,757)
- 14. Full Void 100% - Trophy & Achievement Guide(1,823)
- 15. Outbreak: Lost Hope #Xbox Achievement Walkthrough(2,570)
"Critical flaw in Minecraft's code meant anybody could crash any server" :: Login/Create an Account :: 20 comments