How To CRASH Minecraft Servers With 1 Block.

Поделиться
HTML-код
  • Опубликовано: 8 сен 2024
  • ИгрыИгры

Комментарии • 1,4 тыс.

  • @TheMisterEpic
    @TheMisterEpic  Год назад +509

    Bedrock players, if you want a good server not infested with cheaters, join og-network.net (Port: 19132)!
    Server Discord - discord.gg/G7zq6NPZnM

  • @ell.....
    @ell..... Год назад +4665

    It's crazy that you can still do this stuff in 2023. You'd think having the OFFICIAL Mob Vote server nuked would be enough incentive to try patching these exploits but ig not.

    • @hrmm_9
      @hrmm_9 Год назад +63

      the issue is how would they do it

    • @egirlpimp
      @egirlpimp Год назад

      @@hrmm_9 by making an actual good server backend. on java its basically impossible to run operator commands or spawn in items with packets cause inventories are verified by the server through a lengthy process. currently on bedrock the server just accepts whatever you send it without any security measures or checks, which lets you do things like this with very minimal effort
      edit: patched but still inexcusable for a lot of these

    • @Mehidden81
      @Mehidden81 Год назад +27

      There are too many to patch

    • @wildymc
      @wildymc Год назад +74

      bedrock 1.19.60 patched it

    • @JAL_EDM
      @JAL_EDM Год назад +74

      They actually DID patch it.

  • @ecko
    @ecko Год назад +1287

    What's crazy is I used to play Mineplex Bedrock daily even streaming it, until I was met with hackers who placed bedrock around their cake in cake wars and tp killing players. The thing is you can't even "accuse" players of cheating on their server. This was around 3/4 years ago and nothing has changed since, for a game worth billions of dollars and making billions at the same time it's a complete disaster. Shame nothing will ever be done about it. A+ Video as always

    • @Zerrarian
      @Zerrarian Год назад +5

      @shadrYT

    • @nonameguy3
      @nonameguy3 Год назад +6

      The crossover we need

    • @skyr3x
      @skyr3x Год назад +8

      I remember this, how it worked/works as far as i recall was that you used a combination of "notick" as well as a clientsided gamemode 1 along with some specific moving around you did in your inventory to prevent the items from becoming ghost items, then there was also .enchant commands that let you make 32k items

    • @flamedramon68
      @flamedramon68 Год назад +24

      Asking Microsoft to do something right with their IPs is a fruitless endeavor. They don't give a rat's ass unless it affects their wallets

    • @SowTag
      @SowTag Год назад +4

      Ah yes, Mineplex at its finest

  • @VintageToiletsRock
    @VintageToiletsRock Год назад +611

    Lack of anticheat is a problem, but the real problem is the fact that bedrock servers TRUST the client for inventory data! This is something that was patched in Java edition back in ALPHA! This was only a few versions after the initial server software was released. Meanwhile, bugrock has been out for years and still struggling with the same issue.

    • @qy9MC
      @qy9MC Год назад +79

      Bedrock

    • @user-dw5uy3in5j
      @user-dw5uy3in5j Год назад +60

      It's really strange to me that such a big game would trust the client at all with important data?

    • @Buddelbubi
      @Buddelbubi Год назад +2

      No. Thats wrong. The server can decide who stores the inventory data.

    • @VintageToiletsRock
      @VintageToiletsRock Год назад +63

      @@Buddelbubi Then how come a hacked client can modify nbt data server side on bedrock but cannot do the same in java?

    • @brondlini5459
      @brondlini5459 Год назад +15

      Literally what I was about to say. Even 2b2t isn't this NUTS.
      Mojang just can't/don't want to do their job right. It's not their problem as long as they make money after all 😒

  • @captaincookie72
    @captaincookie72 Год назад +1576

    bedrock is non negotiably the most broken version of minecraft. one time i was playing split screen and the left half everything was tinted blue except my character

    • @captaincookie72
      @captaincookie72 Год назад +23

      I think I have a picture of it somewhere

    • @paulhudalla9527
      @paulhudalla9527 Год назад +94

      Bedrock is a perfect game, with no Glitches at all 😅
      Really though, Switch Bedrock (what I play) is garbage. Glad I started playing Legacy Console again since I still had it. That actually runs smoothly on Switch while Bedrock can lag a ton, just with 2 people that are literally like 1-2 miles apart.

    • @cYObEL
      @cYObEL Год назад +6

      undertale

    • @SpectacularSpiderFan
      @SpectacularSpiderFan Год назад +24

      Of course. Java is the perfect version, where you can walk around in the end and not die randomly, as Ph1lza can testify to that.

    • @sfisher923
      @sfisher923 Год назад +23

      @@paulhudalla9527 As a Bedrock Player I can agree that Switch Players got it bad compared to other versions of Bedrock (Haven't played Switch but most of the things I hear/read on the Bug Tracker are from Switch Users)

  • @TJZ2022
    @TJZ2022 Год назад +2372

    This could be put to good use in destroying P2W Bedrock servers.

    • @wildymc
      @wildymc Год назад +68

      patched in most recent update

    • @SuperDominicS
      @SuperDominicS Год назад +363

      ​@@wildymcas a wise man said, if there's a will there's a way.

    • @SmitePlayz_
      @SmitePlayz_ Год назад +6

      I have never seen a single pay to win bedrock server

    • @yosh-9999
      @yosh-9999 Год назад +94

      @@SmitePlayz_ pixel paradise

    • @LawfulDmcBoo
      @LawfulDmcBoo Год назад +80

      @@SmitePlayz_ literally any of the main bedrock servers

  • @doufmech4323
    @doufmech4323 Год назад +168

    Rule #1. Never trust the client. Always validate all data sent to the client. Yes, some cheats can be hard to detect/prevent, but the client should never be able to just "get" items.

    • @holymeto9981
      @holymeto9981 Год назад +1

      What you mean?

    • @rory8182
      @rory8182 Год назад +7

      @@holymeto9981 I think he means that you need to have your game check data coming from the client to ensure it is data that should be coming from them, so that you can only execute commands if you are allowed to

    • @holymeto9981
      @holymeto9981 Год назад +1

      @@rory8182 Ok so you guys are relying on our morals to not cheat 32k items in even if we weren't operator? Is that what you meant or I misunderstood?

    • @rory8182
      @rory8182 Год назад +8

      @@holymeto9981 yes, the current system just assumes that the client is working as intended and isn't sending data that is incorrect

    • @holymeto9981
      @holymeto9981 Год назад +1

      @@rory8182 So this is a « just because We could, doesn't mean we should, as it would be cheating and immorale» situation?

  • @AzureWoof
    @AzureWoof Год назад +549

    It is utterly ridiculous that Mojang has no protections in place at all for Bedrock edition. One of the first things you do before you release a multiplayer game is to make sure the client can't manipulate how the server processes information. I wouldn't even necessarily consider such a precaution as an anti-cheat measure. It's just common sense.

    • @alecz3843
      @alecz3843 Год назад +41

      Yeah its not even an anti cheat that's meant to prevent this, its coding in a way so the client can't modify data that should only be changed by the server or check the data the client is sending to make sure its actually possible.

    • @ES-cf4ph
      @ES-cf4ph Год назад +22

      Yeah. It is the same like a bank allowing to send any arbitrary data and not validating it so you could just "transfer" yourself 1000000$ from any account or something like that.

    • @blinking_dodo
      @blinking_dodo Год назад +2

      And the weird part is, they KNEW cheats existed when they made bedrock, but ignored that problem anyway!

    • @alecz3843
      @alecz3843 Год назад +8

      @@abirdpilguy3211 but you still cant do something as big as executing any command you want on the server

    • @sabianwarner5316
      @sabianwarner5316 Год назад

      These clients only allow for client side modifications, don't affect the server at all.

  • @LightslicerGP
    @LightslicerGP Год назад +445

    I've been a victim to this! I had a small world for survival and invited someone.
    They put on an inappropriate skin and quickly switched back, so I got suspicious of them.
    Within 2 minutes later their friend joins and asks for access to place blocks. I neglecting did, and they went kinds far. They placed one of these blocks, and executed commands such as the title command, fill command for every player, and totem noises, giving me a jumpscare.
    I've since blocked them, and reported them. But I HIGHLY doubt that Microsoft cares at all, and will do anything about it.

    • @qy9MC
      @qy9MC Год назад +49

      Yep Microsoft 101, they won’t manage it for you and they won’t let u manage it for yourself.

    • @fortnitesexman
      @fortnitesexman Год назад +14

      "inappropriate skin" 💀💀💀

    • @itzadam_
      @itzadam_ Год назад

      ​@@fortnitesexman says the person called fortnite sex man

    • @buizelmeme6288
      @buizelmeme6288 Год назад +3

      I'm so sorry for your lost! Hopefully someone else can be a good friend to play in your world!

    • @fortnitesexman
      @fortnitesexman Год назад +7

      @@itzadam_ ah yes, another person who thinks calling out the fact that my name is stupid (which is the point) disproves my point
      atleast it's more creative and memorable than "itz adam" might aswell call yourself "dave" or "steve" at that point

  • @Pacca64
    @Pacca64 Год назад +106

    How does the client even have the ability to create and/or edit items??? There's clearly some bad client trusting code floating around. Can't be too surprised considering bedrocks messy development history where it was initially single player only, and gradually evolved from that to peer2peer to dedicated servers. Fascinating stuff.

    • @chrissametrinequartz9389
      @chrissametrinequartz9389 Год назад

      they spoof the packets

    • @zea_64
      @zea_64 Год назад +39

      @@chrissametrinequartz9389 You can spoof packets in Java edition too, but if it's to generate/change an item in your inventory the server just won't accept that. You can see this when you have an item desync: your client tells the server to do something with this item, and the server tells the client that item doesn't even exist, then it disappears from your client. If servers just blindly trusted clients and did not checks, the Internet would not function.

    • @LiEnby
      @LiEnby Год назад +22

      believe it or not, bedrocks inventory is actually client side.
      yes. really

    • @Pacca64
      @Pacca64 Год назад +4

      @@LiEnby *facepalm*

    • @supergamerstv2615
      @supergamerstv2615 Год назад

      ​@@LiEnbymojang actually changed it everything to do with items is server sided now.

  • @5074pokemon
    @5074pokemon Год назад +76

    As someone who's in several discord servers for a while now, I can say that Microsoft is actually doing their job! (Kind of) 1.19.60 patched the exploit that clients like Horion have been using to spawn items. But crash exploits and combat hacks remain as functional as they have been for years.

    • @iDqrken
      @iDqrken Год назад

      I was halfway through writing a comment, then I saw this.

    • @tpkowastaken
      @tpkowastaken Год назад

      Crash exploits are fixed too aren't they? Or do you know about any?

    • @5074pokemon
      @5074pokemon Год назад

      @@tpkowastaken Haven't heard of crashing being patched, I can go look and see if Zephyr's exploits work
      (Yup, teleporting out of bounds still works on the integrated server and on realms 🤦)

    • @Choroalp
      @Choroalp Год назад

      Combat hacks are not that game breaking. just annoy,ng for users

    • @5074pokemon
      @5074pokemon Год назад

      @@Choroalp fair

  • @caseslayer1157
    @caseslayer1157 Год назад +284

    I had one of these happen to a public realm I was a admin on and I managed to solve it pretty fast by just disabling command blocks and killing all command block mine carts. It was a challenge for the team to give everyone who was online back their gear

    • @haminice
      @haminice Год назад +35

      Best way is to just have a command block that instantly kills npcs and command block in minecarts

    • @caseslayer1157
      @caseslayer1157 Год назад +30

      @@haminice Realized that after looking up what the hack was and quickly added the command blocks

    • @Clip_It1
      @Clip_It1 Год назад

      May I join this realm? If so do you have discord?

    • @caseslayer1157
      @caseslayer1157 Год назад +15

      @@Clip_It1 I would say yes but they have no discord and rely on adding members though that Xbox find group thing so it’s ridiculously annoying to find/join

    • @Clip_It1
      @Clip_It1 Год назад +1

      @Caseslayer115 I don't have xbox tho, I only have Nintendo and phone

  • @zea_64
    @zea_64 Год назад +122

    Even Minecraft Java's default "anticheat" is better than this, you can see that with ghost items: your client says "I have this item" that got desynced and the server responds with "lol no you don't", it seems like Bedrock doesn't even do that kind of check.

    • @LiEnby
      @LiEnby Год назад +16

      yes, though if u go back far enough (i.e alpha something) you actually can spawn in items there, but that was before items could even hold NBT so .

  • @MyNamesLucky
    @MyNamesLucky Год назад +21

    I’m so glad to see larger channels finally looking at the bedrock community because it’s kinda getting horrible at this point. The group that crashed the mob vote servers have done so many awful things it’s insane

  • @whatcouldpossiblygowrong4970
    @whatcouldpossiblygowrong4970 Год назад +51

    I am a realm owner and I have had my realm crash not once, but twice one guy even held it for ransom.

  • @Pirlo926
    @Pirlo926 Год назад +39

    There's also the "4D" skin situation. Most featured servers block these skins, but almost any non-featured server has no restrictions against them. Usually they are just skins with fancy geometry. Although, some people figured out importing real 3D models as skins, and because of this, I have a full model of Young Link from Super Smash Bros. Ultimate as a skin. It lags the hell out of people (sometimes even me) because it's so high poly.

    • @buizelmeme6288
      @buizelmeme6288 Год назад +1

      Video link?

    • @uropig
      @uropig Год назад +2

      there's a way to force these to appear on featured servers, I've seen people use this to force custom capes/pretend to be mojang staff

    • @Pirlo926
      @Pirlo926 Год назад +1

      @@uropig That's interesting. Didn't think it could be bypassed. It would be nice to do that, honestly, just because I have the Mario Mash-Up skin pack on PC (through some means I won't explain) and it'd be funny for people to see the skins that are supposed to be platform locked.

    • @lasercraft32
      @lasercraft32 Год назад +1

      I didn't even know "4D skins" were a thing... :U

  • @QuiteCloth
    @QuiteCloth Год назад +23

    this is insane.... I don't remember it being like this back around 2019 when I was a bedrock player....

    • @Bolt451
      @Bolt451 Год назад +4

      Its basically non existent on the hive Minecraft Galaxie private realms and servers with your friends

  • @LetsGet1MSubsWithoutVidsPlease
    @LetsGet1MSubsWithoutVidsPlease Год назад +114

    Great video! I always enjoy your videos, they're so interesting even if it's a really obscure topic.

  • @MCLVideo
    @MCLVideo Год назад +99

    Wow... And I thought the regular Java-based MC exploits are bad.

    • @tetonis2452
      @tetonis2452 Год назад +17

      yeah somehow microsoft couldn't find devs with any networking experience whatsoever

    • @ES-cf4ph
      @ES-cf4ph Год назад +5

      ​@@atsizbalik I heard that Bedrock is mostly developed by Microsoft. They are even sitting in a different location.

    • @megavirusuchiha5468
      @megavirusuchiha5468 Год назад +4

      ​@@atsizbalik Microsoft developed bedrock, mc Java was made by Mojang

    • @lafunbug
      @lafunbug Год назад +3

      @Abird Pilguy bedrock accounts also get stolen. my friend had an old account (back in like 2019 or something) and it got stolen.

  • @StuffandThings_
    @StuffandThings_ Год назад +129

    Ah, good 'ol Bugrock. I haven't touched it pretty much since Pocket Edition became Bedrock, it just devolved so quickly. At this point I've lost most hope in Minecraft servers, large servers tend to be bland, mid size server struggle with an ungodly amount of issues that Minecraft was never really designed to handle, and small community servers tend to fade away. And of course Bedrock is just a trainwreck. Once again, I think my main hope at this point is just that Hytale (or some other game!) will do it better.

    • @JamesTDG
      @JamesTDG Год назад +4

      Look at mine test

    • @Blavin
      @Blavin Год назад +1

      Pocket edition was always bedrock though, the console versions just merged with pocket edition.

  • @tatecrossette2855
    @tatecrossette2855 Год назад +40

    Let's go! Mr. Epic back with another epic video!

  • @c8ff
    @c8ff Год назад +70

    If in-game items can be modified server-side by the client, I wonder if there is a scarier exploit that allows code execution

    • @ryguy-qh2qk
      @ryguy-qh2qk Год назад +19

      I was thinking the same thing, this could be wayyyyy worse.

    • @ItsUtopia_
      @ItsUtopia_ Год назад +3

      like the Log4Shell exploit?

    • @shadowcomputing
      @shadowcomputing Год назад +16

      @@ItsUtopia_ Yes, but on the server, not the player’s computer.

    • @ES-cf4ph
      @ES-cf4ph Год назад +6

      It's Micro$oft, so probably yes

    • @igameidoresearchtoo6511
      @igameidoresearchtoo6511 Год назад

      @@shadowcomputing Literally exists already for java and (I'm not sure) maybe for bedrock too
      It's not an easy exploit and it needs the ability to obtain specific rare items to use, but it basically shuts down any server in seconds, however, upon restart there is a tiny vulnerability window of time which malicious users can exploit sometimes but it's easily patchable using any non vanilla server.jar (like papermc).

  • @lemonlolxd
    @lemonlolxd Год назад +9

    The reasons for why this stuff works is a bit wrong. The fact that they inject into the game has nothing to do with it, and while an anticheat can prevent them they shouldn't be needed. Java edition clients are able to and do modify packets, but the vanilla game on java edition has checks in place to verify that items should actually exist. On bedrock the server software just accepts whatever its sent. So you can just tell the server you crafted whatever you want and it just goes "yeah sure craft that stack of command blocks". Same thing goes with enchanting etc. Bedrock is just horrible network-wise and allows for much more packet abuse than java edition. Had a lot of fun with this on my old client :)

    • @lemonlolxd
      @lemonlolxd Год назад +3

      I should also mention that bans on servers are literally useless despite bedrock allowing for device bans alongside ip bans, the device id can be spoofed and ip bypassed with a vpn. Alt accounts are free since the ownership of the game is linked to your microsoft store account, but the ingame account can be any xbox account.

    • @lemonlolxd
      @lemonlolxd Год назад +3

      I know im writing a lot here but I'm sure someone would find this stuff interesting so heres one last thing regarding anticheats and kill aura. Kill aura on bedrock is a lot harder to prevent through an anticheat because you have to deal with touchscreen players who can tap on things to hit them regardless of it they are looking at them or not. You can check what platform a player is on but just like with the device id, the platform can be spoofed so that servers think PC players are on mobile.

  • @StuffandThings_
    @StuffandThings_ Год назад +10

    I don't know why but the idea of command block bees just cracks me up

  • @papisop7372
    @papisop7372 Год назад +35

    In the latest 1.19.60 release, Mojang patched all the inventory transaction vulnerabilities and because of this, .cbe, .nbt, .dupe, etc, and the toolbox item changing by changing their nbt are patched. And because of this, both Toolbox and Horion clients are facing a lot of problems, and from 2 weeks Horion client has not supported 1.19.60, but Toolbox did but a lot of things are broken in it. Although, the combat related hacks still work, but server and realm crashing exploits are all patched.

    • @sisilicon14
      @sisilicon14 Год назад +1

      This needs to be pinned or something

    • @Noone-ff4qd
      @Noone-ff4qd Год назад +1

      They aren't patched
      They change the item values again
      They never fully patch it

    • @papisop7372
      @papisop7372 Год назад +1

      @@Noone-ff4qd Actually, you are wrong. In a game, there are some vulnerabilities/faults left in a game and people use those vulnerabilities/faults to exploit the game or hack the game. But, the inventory transaction vulnerability has been fixed by switching the inventory transaction which was done by the client-side to server-side. Let me ask you a question, can you change the code, or values of a world which is hosted by a server and you are a normal member in that server, probably not because it is done in server-side and you can't change server-side stuffs, that's all.

    • @VariableLyon
      @VariableLyon Год назад

      Ever since the Toolbox community realized that the inventory modifiers like NBTs, Give items and Enchant weren't working, they have been talking about it and the developers have found a workaround, which was implemented in Toolbox Beta in 1.19.63. There are even some clients that MODIFY Toolbox so that you don't have to watch a 15 ou 30 seconds ad in order to gain access to some hacks, including NBT, Give and Enchant. It's not even just Toolbox. There are clients that even modify Toolbox so that Toolbox *itself* is hacked.

  • @Justintheminerr
    @Justintheminerr Год назад +8

    This is why I don't even bother with playing on featured servers besides Cubecraft or Hive, Cubecraft literally has a warning every couple hours reminding you of how many players they've banned.
    In my opinion unless your server has a proper anticheat you shouldnt be allowed or elligible to be a featured server at all

  • @_randombmgo1149
    @_randombmgo1149 Год назад +30

    Ive been seeing a lot of NBT videos on my fyp. And honestly they scare me with how badly they can ruin servers and realms.

  • @radwl
    @radwl Год назад +7

    I think it's worth noting that in the latest update (1.19.60) mojang claims to have fixed inventory and nbt hacks. It'll be interesting to see how this change affects hack clients, unless they quickly find workarounds of course.

  • @SemiHypercube
    @SemiHypercube Год назад +14

    Who would win?
    Any Bedrock server, even official ones set up by Mojang themselves
    A beehive

    • @qy9MC
      @qy9MC Год назад +1

      The beehive stands no chance except if he uses steroids like command block minecarts

    • @HungryWarden
      @HungryWarden Год назад

      If this were any other game, I think the server would win.

  • @NegativeIQ000
    @NegativeIQ000 Год назад +10

    This is why I only find myself playing 2 servers, the hive and cubecraft where the anticheat is far better than lifeboat or Mineplex, it's sad to see how far lifeboat has fallen

  • @Z_Z.t
    @Z_Z.t Год назад +5

    You can also go to richard's channel (one of horion devs) and see that there are nickname change exploit, skins with custom and malicious models. Btw if exploit doesnt work on BDS (Realm server software) that doesnt mean that it wont work on other servers, for example on Hive there are no reach limit for blocks, which can lead to funny situations on bedwars when 1 person can break every bed or obstruct bridges (may be patched because I did that 3 years ago). Also there were commands for editing command and structure blocks in paid version, now there no paid version, but I think they are currently mocking mojang and microsoft.

  • @yngsmiley8308
    @yngsmiley8308 Год назад +6

    Bro people out here finding some of the most craziest ways to crash servers its getting insane i wonder what will be next.

  • @arandomguywholikesnumbersl8565
    @arandomguywholikesnumbersl8565 3 месяца назад +1

    As a used to be long time member of one of these groups, i can confirm that alot of these nbts can do this. You can do soo much with nbts that it is insane ranging from simple diamond armor to enchanted grass or smg to illegal items to edited blocks that crash games.

  • @noname-mu6kn
    @noname-mu6kn Год назад +6

    This is why I back up my server every 6-12 hours

  • @LightningfoxxyMC
    @LightningfoxxyMC Год назад +3

    I would say this is the most dangerous bedrock exploit, and for java it would be the chunk and the book ban
    (For those who don’t know, the book ban (or whatever it is actually called) is where a player fills a shulker with written books, each filled with writting. The shulker is filled, then given to another player. This kicks them as it sends to many packets to the server, however they cannot rejoin. The only way they are able to rejoin is by there inventory being manually cleared or inventory accessed by a mod and the shulker being removed

    • @igameidoresearchtoo6511
      @igameidoresearchtoo6511 Год назад

      It's actually easily avoidable.
      Don't pick up weird shulker boxes from anarchy players.
      common sense, literally as common as not typing your passwords in the chat.

  • @MC_CN
    @MC_CN Год назад +5

    Ah yes, BUGROCK Edition

    • @HungryWarden
      @HungryWarden Год назад

      That isn’t even a good pun anymore.

  • @StuffandThings_
    @StuffandThings_ Год назад +17

    Will you ever cover Vintage Story servers? As far as I'm aware it does have a system of privately run, publicly available servers just like Minecraft, but there's virtually no information to sort through them all. Might be worth a look some time, considering its a fun game and Minecraft servers are in a rather sorry state.

  • @JolydieFer
    @JolydieFer Год назад +1

    As someone who used to be a admin on a realm i spent alot of time on, nuke/NBT's are so annoying, there was also a discord server that someone put a bunch of realms on a crash loop by just having its realm code(the owner gave up soon after becuase rerolling hlthe servet did nothing to fix it), crazy what trollers and griefers can do just to mess witj people

  • @ablade254
    @ablade254 Год назад +3

    As a bedrock mod for lifeboat it’s very hard to counter these hacks so for now the only way to combat this is just by doing normal modding and player reports. As time goes on we are figuring how to combat this. The nukers have been pretty much figured out but arua kill and etc. is still a issue

    • @pohodovejrybar5918
      @pohodovejrybar5918 8 месяцев назад

      no wonder why
      lifeboat is p2w so i completely support all hackers

  • @reclusingrecluse4835
    @reclusingrecluse4835 Год назад +1

    This brings me back yo the days of before mobile games started storing important data like paid in-game currency onto servers and it was super easy to modify currency and other stuff

  • @ccsleepy8342
    @ccsleepy8342 Год назад +14

    Cheats are only more powerful on bedrock because the community hasn’t caught up with java’s anti-cheat. And I think java cheats are entering a new era. Clients are constantly testing the limits of anti-cheat so it’s an arms race.

  • @balls_gaming
    @balls_gaming Год назад +1

    i havnt played bedrock in about 2 years, and i used to love these servers. i need to check them out again and see all the hackers

  • @DrNick5hapez
    @DrNick5hapez Год назад +6

    as a bedrock player i must say: the intro gave me "average day on bedrock" vibes

  • @matze7522
    @matze7522 Год назад +2

    Bigger servers do have an anticheat, but the problem is that Minecraft doesn't send packets for things that anticheat developers need
    Right clicking detection isn't possible for example due to the client having a spam bug, which happens when the player is looking on a block, holds right click down and is moving his cursor a bit
    And there are so many other things which bedrock messed up or just didn't implement what leads to the current situation with hackers being around everywhere

  • @GSFigure
    @GSFigure Год назад +4

    There's a reason why most people crap on Bedrock edition, and this is why. You shouldn't be able to do this just by editing your inventory on the client.

  • @mariobrand2257
    @mariobrand2257 Год назад +1

    This moment when a Minecraft 1v1 turns into a DragonBall fight.

  • @smokeys1254
    @smokeys1254 Год назад +2

    This is why I don’t play small servers anymore on bedrock, small servers have worse anticheats (most of the time) and that I only play on the bigger servers.

  • @zenithpurpleunicorn
    @zenithpurpleunicorn Год назад +2

    It happened to my friend's multi-player world. Not server, world. It's on bedrock ofc but he frequently makes backups so he can boot up a backup.

  • @Lopolin_LP
    @Lopolin_LP Год назад +3

    Minecraft Bedrock literally feels like the equivalent of the Ohio Memes at the moment.

  • @NeptuneSXDL
    @NeptuneSXDL Год назад +2

    idk if u know, but these couldve also been used on P2W realms and servers, we in NRIS have been using crash methods that we had linked to an auto crasher to crash the most P2W realms and servers for a month because mojang never took any action to them.

  • @TheFunkiestCat
    @TheFunkiestCat Год назад +3

    If your realm or server gets nuked, turn off command blocks with the settings then make a copy of the world, it worked with the version that happened to me

    • @qy9MC
      @qy9MC Год назад +1

      U have weird people to play with my guy

    • @TheFunkiestCat
      @TheFunkiestCat Год назад

      @qy9 had the world on friends of friends so I didn't know the guy and neither did my friend really lol, definitely put it on invite only when ever you create a world

    • @qy9MC
      @qy9MC Год назад +1

      I didn’t know it was possible to find peoples realm like that

    • @bigeddyspaghetti6681
      @bigeddyspaghetti6681 Год назад

      realm codes has left the chat

  • @AndreasHGK
    @AndreasHGK Год назад +1

    Mojang has often made and often still makes weird decisions regarding servers, also on the development side of things.

  • @slothman_best
    @slothman_best Год назад +4

    Bedrock anarchy was decent but when cbe was discovered it went down hill

  • @r3mix111
    @r3mix111 Год назад +2

    Tbh if this happens to ur realm all u got to do is load a back up from 10-20 minutes ago n it will go back to normal n ban the person that did it I had this happen 20times now and I beat them Everytime

  • @dirtbagpoteddirt8202
    @dirtbagpoteddirt8202 Год назад +3

    once someone invited me to a realm i used tool box but all i did was spawn in some cameras and nether reactors i didnt feel like griefing cuz it was only up for 30 days and hasnt been up since so he never waisted money

  • @Shadows275
    @Shadows275 Год назад +6

    Not even bedrock players know what’s going on in bedrock

    • @SmitePlayz_
      @SmitePlayz_ Год назад +2

      Because it's non existent in any server with more than 1000 players

  • @Proferk
    @Proferk Год назад +1

    Remember in the oldest versions of minecraft java edition where you could give yourself any item on a public server? yeah, this is basically the same thing happening here, but on the latest version of minecraft bedrock. The reason this happens is for the same reason it happened on java, it is because the inventory management code is client sided, meaning the client sends a packet to the server when their inventory changes. The server should be handling this code, but in bedrock, the client handles it. This means a malicious client (by malicious I mean a client which has something injected to it) could just send a fake packet that gives them whatever item they want. This doesn't sound too harmful? Well that would be the case, if only you couldn't manipulate NBT data of the inventory items when sending the packet. They way people get kits is by giving themselves a shulker box, and because they can manipulate the NBT data they can add whatever items they want to the shulker box they gave themselves with the exploit. The reason that people can execute console commands is because beehives, movingblocks and buckets of axolotls, with the proper nbt information supplied, can in-fact execute commands. So, these people just give themselves one of these with the malicious NBT data attached and use it to execute malicious commands on the server.

  • @MetatronsRevenge613
    @MetatronsRevenge613 Год назад +4

    It’s about sending a message (Joker proving how bad bedrock is)

  • @citricmantis_543
    @citricmantis_543 Год назад +1

    The mister epic: I am just showing you guys don’t actually do this.
    The comments: “I know what I am going to do”
    “Time to take out some pay 2 win servers”
    “Wonder if this would work on my friends realm”

    • @qy9MC
      @qy9MC Год назад +1

      Nuking p2w servers is a very common practice it’s not a bad thing.

  • @HazyWrites
    @HazyWrites Год назад +3

    me waiting for horion to update so i can load the kits i made. (i dont mess around with nukers)

    • @SmitePlayz_
      @SmitePlayz_ Год назад

      You're a fucking clown if you need to cheat in a block game made for kids

  • @snudget
    @snudget Год назад +1

    I can't imagine how such a thing like that can happen. When creating a client/server application, you NEVER EVER check the validity of an action on the client. You should never trust the client. Even if the code is not open source, eventually people will find the way to hack it. You should always save the inventory of the player on the server, it should not be possible that the client can modify their inventory. This was fixed in Java right after Multiplayer was released. Imagine you log into a website and it asks "Do you know the password?", you answer yes and it just lets you in, without checking whether you entered the correct password.

  • @ajbb_16
    @ajbb_16 Год назад +3

    gotta say nuking a server in a child's game is the most saddest thing in the world lol

    • @qy9MC
      @qy9MC Год назад +2

      It’s not targeting it’s the simple act of trolling

  • @hanro50
    @hanro50 Год назад +1

    Rule 1....like the first thing you SHOULD learn as a programmer when doing anything network related is the following phrase "NEVER TRUST THE CLIENT".
    If anything, I seriously doubt the quality of Bedrock's internal code if the client is able to change the internal state of a server. This means potentially Bedrock servers don't do any server-side checks to ensure a client behaves as one would expect.

  • @butter0boy573
    @butter0boy573 Год назад +10

    Honestly, this might sound bad but I hope the hackers don't stop so more people go to java addition.
    Edit: I know many people don't have access to java. I thought about that. I was thinking it would get more people to research what java is. The ones who barely even knew about java what it is like. This is a stretch but it could even make Mojang want to make java cross platform. But that probably won't happen because Microsoft is greedy and wants in-game purchases.
    If you think this is wrong LMK.

    • @qy9MC
      @qy9MC Год назад +4

      Fr

    • @mental847
      @mental847 Год назад +2

      That's really shìtty to say tho

    • @lunar07
      @lunar07 Год назад

      not everyone has a pc

    • @qy9MC
      @qy9MC Год назад +1

      @@lunar07 That version is literally a scam. People watch yt which is mostly about java edition, then they get confused why they can’t can’t join hypixel after begging there parents. It doesn’t matter if they don’t have a pc, they didn’t wanted to play that version in the first place.

    • @lunar07
      @lunar07 Год назад +1

      @@qy9MC well not everyone is quite as knowledgeable as we are and so people will not realize they're getting the wrong product as they would assume that it would be the same as they see.
      And how does not having a pc /=/ not wanting to play the version?
      You could very well be aware that there are two versions but you cannot access java since you don't have a pc.

  • @Mathematiqs
    @Mathematiqs Год назад +1

    This is great, the more that new players suffer, the more they'll want to turn to Java
    Also, crashing with 1 block isn't anything new, you can do it on Java if there are no Plugins stopping you and you have creative, the crazy part is the fact that the server just lets you make arbitrary nbt in survival on bedrock

  • @bobydon6000
    @bobydon6000 Год назад +3

    Is it possible to use these bedrock clients on Java servers that are using Geyser? If so do all the same crazy exploits work with it?

    • @zuitsuko2754
      @zuitsuko2754 Год назад

      No. Geyser converts bedrock packets into Java packets. But the server is still fully java

  • @NeverTHOUGHTofIT
    @NeverTHOUGHTofIT Год назад +1

    I remembered when toolbox worked on cubecraft so smoothly like I unlock nether in skyblock in a week, I could have done it in an hour but their admins were so much of tryhards

  • @redpierre
    @redpierre Год назад +3

    solution: play java instead

  • @HungryWarden
    @HungryWarden Год назад +1

    For a game named after the infamous unbreakable block of Bedrock, it sure seems to break easily.

  • @CoffeeSuccubus
    @CoffeeSuccubus Год назад +1

    Most passive aggressive "No pressure" I ever seen...

  • @erikhaag4250
    @erikhaag4250 Год назад

    Biologist: we come across a bee nest and wait for the sun to show itself. as the first buzz of bee... wait what the heck is that? Oh no, is that the fabled command hornet? I've heard rumors about them and...
    Command hornet: /kill @e[type=homo sapien]
    Biologist: I've got a bad felling about this.
    Humanity is now extinct.

  • @SorieMiya
    @SorieMiya Год назад

    Hey, old bedrock hacker here. I've stopped playing now but the situation is worse than you think. I used to play skyways and bedwars and I could pretty much just summon sharpness 32K swords and destroy everyone. Good times, and thanks for bringing attention to this

  •  Год назад +1

    Such a useful video. Thank you so much. Had this happen on an anarchy server I ran and was baffled by the way the beehive was causing this to happen.

  • @EnjoyVoid
    @EnjoyVoid Год назад +1

    We love pople with the Bedrock > java mindset.

  • @gammaboost
    @gammaboost Год назад

    I remember a long time ago before they added commands to PE that there was an app called "PlugPE" or something that would put a fake player in your offline world and would allow you to use commands. I'm surprised that it even worked in the first place, and the fact that it probably still would work now...

  • @lukecreator
    @lukecreator Год назад

    great video, but there's two main points i want to make here:
    1: the reason all of the NBT/item stuff is possible on bedrock is because the server is not "authoritative" of the inventory. the client player can literally say "yeah uhh i got 64 diamond blocks" and the server just agrees. this is actually fixed in newer versions of their server software and i have heard it's on some realms now, which is great.
    2: there is no (moddable) dedicated server software for bedrock edition, so there is a lot of disconnect between the different featured servers and how they work. most server softwares are built entirely from the ground up, and the more janky servers (such as lifeboat) use old, slow community server software that is hard to develop on and immature in its development

    • @mrdiamond64
      @mrdiamond64 Год назад

      point 2 is wrong. BDSX and LiteLoaderBDS are based on the vanilla BDS with modding support

    • @lukecreator
      @lukecreator Год назад

      @@mrdiamond64 you are correct, but they have not taken traction yet really for one reason or another. bdsx is relatively immature if I remember right, but I can't say for LiteLoaderBDS as I don't know

  • @apolloandwarrior_3229
    @apolloandwarrior_3229 Год назад +1

    Oh wow, this is really interesting. Obviously I know this is almost always used for malicious reasons, but it's still pretty cool.

  • @tpkowastaken
    @tpkowastaken Год назад +1

    This video couldn't be timed better as the exploits have now just gone patched. Inventory data (including nbt data) is now managed by the server and not the client. This fixes gamemode exploit, .give command and those nbt loaders. Also They managed to break the client used in this video and now it crashes minecraft. This means that you can no longer just wipe servers (thank god). But the cheaters problem is still present but they at least have the same priviliges as java cheats. In case you wanted to try it out yourself (or even better patch it for your own server) you can use the ambrosial client and insert zypher in minecraft.

  • @firstnameislastname9568
    @firstnameislastname9568 Год назад +1

    I remember when I played pocket edition i used an app called mcpemaster of the play store that basically gave me world edit and the ability to spawn in any item even some that seemingly didn’t exist even on other peoples worlds.

  • @peaktheweak
    @peaktheweak Год назад +2

    When you realize what Crashery is and that you don't even need to join the game let alone open Minecraft to crash a realm 💀

  • @whoooadude4804
    @whoooadude4804 Год назад +1

    I'm so glad Mojang added chat reports instead of patching these, now you dont have to worry about being reported because you can't even play!

    • @LiEnby
      @LiEnby Год назад

      i got banned for making a bot to scrape the marketplace;
      then i went and unbanned myself. very rude mojang

  • @spongebobfan6
    @spongebobfan6 Год назад

    Wow, I don't know what is crazier, the fact that doing this is possible in vanilla servers or the fact that microsoft doesn't care about this and hasn't fixed this crazy exploit..

  • @Designation1118
    @Designation1118 Год назад

    I guess I've technically coded some really annoying nukers, I once made this thing called THE INSURGENCE, and it summons a command block that summons a falling block every time it executes that a falling block exists, and that means every tick it doubles, within like 1 second your whole world has like 1024 entities already spawned lmao.

  • @sfisher923
    @sfisher923 Год назад +1

    I used a Bedrock Client (Onyx) not for the Nuking or anything but to have something like the F3 Screen on my SSP as I tend to do Redstone and Farms and very much of a QoL thing (F3 Screen, On Screen Compass, On Screen Clock, Chunk Borders basically things found on Vanilla or Vanilla+ Java)
    And before you ask I play both Java and Bedrock and I find it hard to go back to Java because I don't know mechanics there

  • @alface935
    @alface935 Год назад +1

    1:18 Ok ok ok i kinda want to see what "DVDLogo" looks like

  • @goredoggy
    @goredoggy Год назад

    this reminds me of, when i was younger, i would play a skyblock server. but someone came over and gave me an item. it wasn't the same as this shit, but it crashed me, and made it unplayable to touch the server ever again

  • @燻
    @燻 Год назад

    I still remember crashing many p2w bedrock servers with servercrasher working on almost everywhere

  • @user-mx5zb6fx1b
    @user-mx5zb6fx1b Год назад

    man i remember having a 32k collection and my own dupe method in mineplex survival on my old xbox, so crazy

  • @breakingaustin
    @breakingaustin 9 месяцев назад +1

    The problem is, it's like criminals and police. The police are always one step behind because they don't know what the criminal is going to invent next. Servers can't patch cheats that they don't know about, and when they do, the hackers invent a work around, meaning there is always going to be cheating... I would go back after a few months and see if they have caught up with hackers or not..

  • @mc_lecraft80
    @mc_lecraft80 Год назад +1

    The funny thing is all those Mineplex hackers are so bad at hacking that I win every game even with 2 hackers at once

  • @JanusZeal11
    @JanusZeal11 Год назад

    Honestly, this really should be on Mojang to fix. They need to implement code in Minecraft that protects the validity of the client code to prevent DLL hijacking attacks like this. Potentially also updating the server code to request a set of hashes for the client libraries to validate against that server's accepted versions.
    It wouldn't even be all that hard...

  • @jimfromdiscord.8904
    @jimfromdiscord.8904 Год назад

    8:13 - (in Demoman's voice): *THERE CAN BE ONLY ONE!*

  • @engieee
    @engieee Год назад

    As a former bedrock realm moderator, I remembered how annoying it was to take ppls 32k, and my freind made a way to clear those certain stuff useing commands. You can see why I don’t play anymore

    • @supergamerstv2615
      @supergamerstv2615 Год назад

      They fixed all the issues mentioned in the video months ago....

  • @4rkain3
    @4rkain3 Год назад

    I guess it’s a good thing I never felt like playing Bedrock multiplayer. I rarely even play Java in multiplayer, but Bedrock just seemed like it’d be tricky with mobile controls.

  • @RngGm
    @RngGm Год назад +1

    I dont have much experience with multiplayer (i made 3 multiplayer games, 2 unfinished) and have 0 experience with Minecraft hacking
    I think the problem is being able to modify your inventory on your client instead of it being changed only by the server

  • @ricedanan
    @ricedanan Год назад

    Imagine playing on a server and then suddenly the real TheMisterEpic starts killing you with hacks

  • @plasmaflippy9376
    @plasmaflippy9376 Год назад +1

    The brainrot is somewhat funny, though, imagine knowing you will completely ruin someone's survival experience, and then expecting them to support your youtube channel and discord server.

  • @TechX1320
    @TechX1320 Год назад

    This reminds me of some old school halo combat evolved hacks. We used to use console commands to spawn modified guns and as soon as someone without the hack picked up the gun, it would crash the server

  • @eimerhegel427
    @eimerhegel427 Год назад

    TheMisterEpic: Bedrock > Java
    TheMisterEpic few years later:

  • @bobnollie
    @bobnollie Год назад

    FINALLY someone spoke up about this! Its such a big problem when some random bozo can just join my casual survival world and destroy it in seconds! This needs to get fixed.