Wasn’t log4j originally found by 2b2t players, then used maliciously and reported later on, then going onto get fixed by every major server framework like bukkit, paper, fabric, and more?
Comment on Minecraft is removing code obfuscation in Java Edition
slazer2au@lemmy.world 10 months ago
I look forward to several critical CVE being discovered like log4j
DanWolfstone@leminal.space 10 months ago
sus@programming.dev 10 months ago
No, it was found in november 24 2021, publicly disclosed in december 9 2021, and only used by 2b2t players on december 10 2021.
PlexSheep@infosec.pub 10 months ago
That would be good though. Better the communities finds them and they can be patched than when only some black hats know them.
rbos@lemmy.ca 10 months ago
Unironically, me too. They’re there now, waiting to be discovered. We can find them now on our terms or be surprised by them later.