mirror of
https://github.com/BX-Team/DivineMC.git
synced 2025-12-19 23:09:26 +00:00
Upstream has released updates that appear to apply and compile correctly Purpur Changes: PurpurMC/Purpur@6f5bbae5 [ci/skip] move some code around PurpurMC/Purpur@5c1a9835 fix issue with `shift-right-click-repairs-mending-points` PurpurMC/Purpur@3156e446 check damage value of tool correctly PurpurMC/Purpur@a9fe4f25 Updated Upstream (Paper)
35 lines
1.9 KiB
Diff
35 lines
1.9 KiB
Diff
From 0000000000000000000000000000000000000000 Mon Sep 17 00:00:00 2001
|
|
From: NONPLAYT <76615486+NONPLAYT@users.noreply.github.com>
|
|
Date: Sat, 1 Feb 2025 19:28:34 +0300
|
|
Subject: [PATCH] Block Log4Shell exploit
|
|
|
|
|
|
diff --git a/net/minecraft/server/network/ServerGamePacketListenerImpl.java b/net/minecraft/server/network/ServerGamePacketListenerImpl.java
|
|
index 376ae7bde8fdf0efed5a7d33f67a1a5ae3b5e6e7..ce8255db82335255313e16b9811bdfc39d33e5ee 100644
|
|
--- a/net/minecraft/server/network/ServerGamePacketListenerImpl.java
|
|
+++ b/net/minecraft/server/network/ServerGamePacketListenerImpl.java
|
|
@@ -2482,6 +2482,7 @@ public class ServerGamePacketListenerImpl
|
|
}
|
|
|
|
private void tryHandleChat(String message, Runnable handler, boolean sync) { // CraftBukkit
|
|
+ if (ServerGamePacketListenerImpl.isLog4ShellExploit(message)) return; // DivineMC - Block Log4Shell exploit
|
|
if (isChatMessageIllegal(message)) {
|
|
this.disconnectAsync(Component.translatable("multiplayer.disconnect.illegal_characters"), org.bukkit.event.player.PlayerKickEvent.Cause.ILLEGAL_CHARACTERS); // Paper - add proper async disconnect
|
|
} else if (this.player.isRemoved() || this.player.getChatVisibility() == ChatVisiblity.HIDDEN) { // CraftBukkit - dead men tell no tales
|
|
@@ -2514,6 +2515,15 @@ public class ServerGamePacketListenerImpl
|
|
}
|
|
}
|
|
|
|
+ // DivineMC start - Block Log4Shell exploit
|
|
+ public static boolean isLog4ShellExploit(String message) {
|
|
+ java.util.regex.Pattern pattern = java.util.regex.Pattern.compile(".*\\$\\{[^}]*}.*");
|
|
+ java.util.regex.Matcher matcher = pattern.matcher(message);
|
|
+
|
|
+ return matcher.find();
|
|
+ }
|
|
+ // DivineMC end - Block Log4Shell exploit
|
|
+
|
|
public static boolean isChatMessageIllegal(String message) {
|
|
for (int i = 0; i < message.length(); i++) {
|
|
if (!StringUtil.isAllowedChatCharacter(message.charAt(i))) {
|