link to FicMC

Fit

Intro:

2b2t the oldest Anarchy server in minecraft has just spent the past four weeks in complete turmoil.

An infamous group of hackers has been using an exploit against the entire server for the past three years in secret and it’s finally been revealed to the public. As someone who has covered1 minecraft exploits for years I can safely say this is the most powerful and destructive one I have ever seen.

The ultimate coordinate exploit capable of tracking the real-time movements of over three hundred thousand players across all three of minecraft’s dimensions. Fifteen thousand bases were found using this exploit. there was nowhere to run or hide. It was used to grief countless builds and steal over 200 million minecraft items from stashes. The group responsible was thought to have quit the server years ago. But they’ve been pulling the strings from behind the scenes the entire time. What’s remarkable is that this exploit shows how fundamentally flawed minecraft as a game actually is. One person even tried to warn the community that this was happening. But they were written off as crazy and no one listened.

Prepare yourselves for today we’ll be discussing NO COM the most powerful exploit in minecraft history explaining who discovered it how it was possible from a technical perspective and the complete and utter destruction it caused.

漏洞的起源:

This video has been three years in the making and has required months of research and gathering testimony. So if you consider hitting that subscribe button you are an absolute legend. With that being said let’s get started.

独立主格

Since the server began in 2010 players have always attempted to use exploits in order to gain an advantage over others. If you haven’t seen my video ”The day 2b2t almost died” I’ll sum it up real quick. In 2016 a group of players that went by the name nerds incorporated attempted to take over the server through the use of hacking and social engineering.

to form into a corporation

ADJ Incorporated is used after a company’s name to show that it is a legally established company. (公司) 股份有限的 [美国英语] [商业] [n ADJ]

…MCA Incorporated.

…MCA股份有限公司。

They actually succeeded at their plan and had access to admin powers. But it was short-lived and they eventually lost them. Many members of the nerds would go inactive and for a couple of years not much was heard from them until two years later in 2018. Two players 0x22 and Babbaj were both server regulars that had an interest in minecraft exploits. They had recently discovered a way to crash the server by loading a massive amount of chunks at the same time. The most simple thing you can do in minecraft is breaking a block and to do this you need to click on it. What the exploit did was click on blocks everywhere across the map even if they were out of render distance. This forced the server to use an incredible amount of resources attempting to load chunks that had never been visited by players.

Thousands upon thousands of chunks were loaded in a matter of seconds causing incredible amounts of lag and eventually the server would crash. Instead of abusing this new exploit right away, 0x and Babbaj started theorizing how it could be used to their advantage. There was a way that they could turn this crash exploit into a coordinate exploit but they needed the proper conditions first. You see the majority of multiplayer servers in the java edition of minecraft run something called Paper mc which fixes bugs and makes the game more stable. Occasionally though a bug fix can lead to a vulnerability that can be exploited to someone’s advantage.

想出方法

Any time there was a server breaking exploit 2b2t’s admin, hause master would have to report the issue to paper mc. If they could crash the server to produce a specific out-of-memory message to Hause, he would report the bug. The most obvious fix to this would be to have chunks only respond to the server if they were loaded by a player, which could reveal someone’s location.

It was genius. The two shared their plan with a close friend named Fr1ckin who was a member of nerds incorporated, the same group that tried to take over the server in 2016.

He confirmed that their plan could work if paper developers were to implement the obvious fix. And so they set their plan into motion. In july of 2018 they would begin crashing the server as fast and hard as they could, making it unplayable. Each crash would notify Hause that players were attempting to click blocks out of render distance and it was causing the server to go haywire. He reportedly issued a paper on July 12th and later the very same day the exact bug fix the group was hoping for was implemented. When attempting to click blocks out of render distance the server would only give a response if a chunk was loaded by a player. They now had the proper conditions for their coordinate exploit and the following day July 13th, they had their first working version, but it was very primitive.

They would keep an afk account in the overworld and it would attempt to click blocks in all chunks leading away from spawn in a spiral pattern. If a chunk responded it would send the coordinates privately in chat. Any chunks that gave a response were then charted on a graph. Bubbaj would begin using the exploit to find and destroy item stashes, which started a panic in the community. Wanting to keep the exploit as low profile as possible, Fricken suggested a name for it, no com, short for no comment. This way if the exploit name was somehow leaked it wouldn’t raise any red flags. As a member of nerds incorporated Fricken told the others in the group about the exploit and they were brought into the circle of trust. In august of 2018 I released a video discussing the crash exploit that had already been patched. But while doing research for that video I asked Bubbaj if he knew anything about the exploit. He replied with no comment. little did I know at the time he was actually telling me the name of the exploit. It was hiding in plain sight and we were all oblivious to it. In the following months the primitive version of the exploit would prove to be tedious. It was slow, resource intensive and there was no easy way to differentiate between actual bases and simple dirt huts. In most cases the charted chunks were just empty wilderness. There was also no easy way to tell which specific player was in the loaded chunks.

Leijurv登场:

They needed some sort of automation. Enter Leijurv a talented programmer and the lead developer of baritone - a program that automated actions in minecraft. Leijurv had legitimate experience with machine learning. So the nerds requested his help in making the exploit more powerful. He accepted the challenge and was brought into the circle of trust. Over the next few months his contributions would change everything. The first order of business was making searches more efficient. A program was taught to follow players once it identified them. They were located by running checks all the way up and down 2b2t’s major highways and then followed them to wherever they were going. Instead of searching in a spiral pattern starting at spawn, an adaptive tracking system would predict where players were headed.

be headed = headed, used mainly NAmE.

The easiest way to describe this exploit is like a game of battleship and the enemy ships are players on the server. You can’t actually see where they are and no matter what spot you choose to fire on, your opponent must tell you whether you hit a ship or you’ve missed. On 2b2t your opponent is the server itself and instead of firing missiles you’re trying to click blocks in chunks that you can’t see. The server has to tell you whether a chunk you clicked on was loaded or not loaded.

After it learned to track players, the program would use probability Association to identify them. It would notice when specific accounts were connecting and disconnecting from the server. If a trail of chunks was suddenly unloaded, at the same time, someone disconnected, it began to associate that username with the chunk trail. So after two or three disconnects it had a clear idea of who was actually in those chunks. This also allowed the program to chart how far a player had gone in a specific session of minecraft.

漏洞的使用

By this point AFK accounts were being used in all three dimensions, so all player movements were being tracked. Leijurv shared with me how the math behind the adaptive tracking system works for this video and as you can see, it’s as easy as one two three. From there the program was taught to search all incoming chunk information for unnatural blocks such as shulkers, stained glass, beacons multiple chests etc. If these blocks were found the program would then recreate the chunks in a separate instance of minecraft. What you are looking at is an actual 2b2t base being reconstructed in real time. The program has identified these chunks as a legitimate base. It’s taking the block information and comparing it to what should be there on 2b2t’s seed which is publicly known.

take 作万金油动词
to collect or gather something for a particular purpose

After running the check it then displays what is different. Once the process is complete the world download is automatically stored on a separate database. This feature effectively gave the nerds a form of spectator mode and allowed them to see what was happening in any loaded chunks on the server.

important
Here, you can see an after the fact2 visualization made from years old data collected on3 the average base4.

This one is named Electric boogaloo. You can see how it starts from nothing, just a few random checks per chunk, then it grabs and explores areas that are likely to be part of the build. It even goes back and rechecks sections periodically to see if any changes have been made. With all of these adaptive programming changes Leijurv would combine them with the nerd’s original exploit. What happened next was nothing short of incredible.

The No Com Exploit was now the most powerful in minecraft history. They were visually tracking every single player movement on the entire server in real time at one second intervals. Every chunk trail, base location and Player Logout Spot was now compromised. Heat maps allowed them to see where the most player activity was happening at all times. They would acquire so much data using this exploit that everything I’ve mentioned so far is just the tip of the iceberg. It was the ultimate power and the nerds had to show an incredible amount of restraint in using it because it was possible due to a paper vulnerability.

gaslighting

This meant that the exploit could work on other servers as well. There was truly nowhere to hide. The exploit had to be kept a secret and to do that the group would have to feed the community false information for years to keep them from finding out the truth. Anytime there was evidence of a coordinate exploit being used on the server, the nerds would brush it off (brush off) as paranoia or make up a different exploit with enough believability that people would buy it. What they were effectively doing was gaslighting. In the english language one way to describe gaslighting is convincing a person that their memories of an event are not accurate. For example let’s say that when you were a young child, your parents took you to an amusement park and while there they gave you a red balloon. If I wanted to gaslight you I would say your balloon wasn’t red it was green, don’t you remember? Now this is an obvious lie, but if I repeat this statement to you enough times, you might start to believe that you were misremembering that your balloon was actually green.

This strategy of making people question their own realities is what the nerds have been doing to the community for years.

Several of my previous videos involving coordinate exploits had explanations such as tracking ender pearl teleportations or triangulating a base by observing a pet teleporting. The reality was that while these methods were actual exploits, they were used as a cover for the no-com exploit which was the true method all along.

Having believable explanations for bases and stashes being found was crucial. In 2019 the nerds would start utilizing their exploit more and more. Their use of it would lead to the leaking or griefing of many prominent bases on the server such as Space Vault3, The Ice Dragon at Niflheim, The Great Tree and many more. Sometimes they would just leak the coordinates out outright and let aspiring griefers take care of the rest5.

The nerds began a campaign called dipper nation and used memes to troll the community about the true nature of the exploit. What’s funny is that in their base leaked screenshots they did not actually visit those places in person. They were using remote viewing to see
what the base looked like. They could doom entire builds without even lifting a finger. It seemed like the group was unstoppable but in the later part of 2019 they would hit a major roadblock. Biblebot, one of the afk accounts that had been used to obtain chunk information was locked by Mojang due to suspicious activity involving the authentication servers. Around this time Hausemaster would also lower the server’s packet limit by a substantial amount.

Hause 的补救:

This meant it was no longer possible to use the exploit by only having a single account logged in. Multiple AFK accounts would have to be used in order to maintain the rate at which data was pulled from the server. Leijurv would also have to retool his machine learning program to overcome these limits. After a few months
of downtime the exploit was back up and running more efficiently than ever. But realizing that more data limits could effectively shut them down, they decided that showing restraint in using the exploit
was no longer an option of the group members. Ox22, Bubbaj and Leijurv were all members of a separate organization called the spawn masons who had become well known on the server for many of their ambitious projects. The three began taking large amounts of stash coordinates from the No Com database and began providing them to the masons with no questions asked.

A subgroup of the masons led by a player named Dectonic would scout out each stash for useful building blocks and decide whether to give it up to the group to steal or destroy it. Over the course of 2020 the group would steal from and then destroy hundreds of stashes around the server.

They did this so that the group would have more resources at its disposal. In total the masons would acquire more than 200 million
minecraft items from these stashes. It was clear that anyone able to use the No Com exploit had a major advantage over everyone else. while the exploit was running flawlessly and Hause was still unaware of the original vulnerability.

0neb noticed:

Someone began to notice that something was not right. A player named 0neb realized that there were at least four accounts logged into the server twenty-four seven, being able to stay online without
getting AFK kicked is very hard. So multiple accounts doing it instantly raised a red flag. 0neb began to suspect that the accounts were being used for an exploit of some kind and he started enquiring about it. His original messages to the nerds had been ignored, but upon mentioning the afk accounts he was surprised to see them respond. They dismissed his claim as paranoia and that he was being ridiculous. 0neb would attempt to bring these findings to the attention of the greater community, but he was either ignored or laughed at.

The nerds would actually program one of their AFK accounts to randomly message nev with random strings of morse code6 from time to time, fueling his paranoia to all-time highs. The nerds would spend the rest of 2020, trolling 0neb, raiding stashes and continuing to expand their database of locations.

A new group found this same vulnerability:

But in 2021 another group of 2b2t players would stumble upon the original paper vulnerability. Enter Steve3 Mahan and Redstoner, three associates of a group called the infinity incursion.

meaning of the (enter sb).

They had developed a brute force version7 of the exploit but far more primitive. At first they used it to observe the highways but after some optimizations they were able to find base and stash coordinates just like the nerds could. But when it came to tracking players real-time movements, they could only follow one person at a time instead of the hundreds that the nerds could. Now with the ability to only follow one person at a time, I want you to take a guess as to who they decided to track. To absolutely no one’s surprise, it was me. in may of 2021, I was base hunting on my Sunday morning live streams, I’d been using an alt account and at the time had not logged into my main account fit for quite a while. I’m usually pretty good at concealing my location. But somehow I was getting found every single week which was highly unusual. While stream snipes have happened in the past, they’re pretty uncommon occurrences and are usually complete accidents.

but to keep getting found every single week despite being hundreds of thousands of blocks away from spawn I knew an exploit was being used. sure enough the stream snipers revealed that they had been tracking me using their exploit. they knew exactly where my account was at all times. I even caught one of them attempting to sell the coordinates of my logout spot for real-world money. At this point I
knew that my main account was not safe to log in with, which is why at the time of me making this video, I haven’t logged into it for over four months. In early June the exploit was starting to go public with more groups starting to gain access to it. Throughout all of June and July bases and stashes began to fall. The server was going into doomsday mode, with players afraid to even log in out of fear of their bases being blown up. But it was too late fifteen thousand locations had already been compromised, regardless of who was online or not.

It was during this chaos that I was finally shown the true power of the exploit. if you saw my previous video you already know that
10 of us joined forces to grief a base belonging to a player named Beardler. After the grief took place, I actually received a message from 0x22. He had tracked my alt and the accounts of everyone else to the staging area a few days before the grief.

Since Beardler had been tracked to that very same location months previously, they already knew why we were there by using remote viewing. The nerds were able to see the TNT being placed on the actual builds without even speaking to any of them. They knew our plan. It was possible to use the exploit to predict events before they actually happened. I was stunned. I knew the exploit was powerful but not that powerful. By this point the community had reached
the breaking point with many emailing house to warn him about the original paper mc vulnerability.

The masons knew that the exploit was going to end so they went on one final killing spree, hunting every new player spawned they could find.

Finally, on july 15 2021, exactly three years after the original exploit was created. Hause implemented a range limit that effectively destroyed it. Accounts were no longer capable of being tracked
and the server would not give information about faraway chunks, but the damage had been done. The exploit had left a trail of destruction spanning multiple years across the entire server. 0neb who had been written off as crazy was actually right all along. He had warned the community, but no one had listened. The total amount of data that the nerds had collected on the entire server was well over two terabytes. The majority of the base and stash locations over fifteen thousand were still located on their private server, just like during the 2016 backdoor drama. They were the ones pulling the strings from behind the scenes all along. They never truly quit.

As someone who has played minecraft for over 11 years. The fallout of this exploit has given me a unique perspective. The reason, the title of this video, is called the fall of minecraft’s 2b2t is because the server that we’ve played on all these years, the one that was compromised by the nerds has finally fallen. With the exploit patched
a new 2b2t can rise from the ashes, while the destruction on the server is going to get a lot worse before it gets better. We can now travel in peace knowing we aren’t being tracked by the all-seeing eye in the sky. Everything that happens here is driven by real players with real motives. For a group of notorious hackers to socially engineer a server admin to open up a vulnerability and using machine learning to create the most powerful exploit in minecraft history, is not a story. You can write it’s as real as it gets and that is why there is no other place in minecraft like 2b2t. We’ve always been
playing a completely different game. The moral of today’s story, no comment. The question now is what happens next. That was a long video so if you enjoyed you better be hitting that like and subscribe button, also make sure to follow my socials. So take it easy fit fam
and you can finally breathe easy.

Description

Today we will discuss how the most powerful exploit in server history caused the fall of Minecraft’s 2b2t, the oldest Anarchy server in the game, and the fallout of the events that took place.

Comments

These people could easily have high paying jobs at the CIA but instead choose to spend years on breaking a block game into it’s absolute limits. I respect that.

Footnotes

  1. to report on an event for television, a newspaper, etc.; to show an event on television ↩

  2. this phrase: after-the-fact, here, used as an adjective. ↩

  3. used to show the basis or reason for sth 根据, 由于: a story based on fact. On their advice I applied for the job. 我听从他们的建议申请了这份工作。 ↩

  4. 后置定语 ↩

  5. the remaining people or things, 指剩余的事情 ↩

  6. 方式状语 ↩

  7. 暴力破解版本,专有名词 ↩