Hi centi (im already in ur Discord and im friends with u on discord)
@sadtruaАй бұрын
Here before the children
@mckayshirouАй бұрын
Interestingly i once saw this as an opportunity to bypass the "login lobbies" of semi-premium servers but at the time (aroun 2018) i wasn't savy enough to know how to breach those defenses, this was a very good documentary...
@niicespiiceАй бұрын
how do semi-premium servers work? i'm interested because i currently have a cracked server and it has security issues
@hashinemiretsien9920Ай бұрын
@@niicespiice Idk if it's these ones, but basically, through cracked clients you could just enter with a name you choose and then make a password if the name's not taken. If you were to be premium, logging in with your name if it's not already taken gives you the option to first make ur password and then "turn" your account into premium status, so once you log in you don't need to use ur password and such, usual premium login.
@ShizkebАй бұрын
@@niicespiice fed
@gobeditsАй бұрын
@@Shizkeb XD
@TheRroganShowАй бұрын
@@niicespiice smei premium auto logs u in to the server without needing the /login command. if you have a premium mc account
@dalton191Ай бұрын
As a server owner, and developer for MC Mods/Plugins you did an amazing job explaining all of the systems talked about in this video! Great video for those who want to learn about the basics of Bungeecord security & networking works as well! I also loved the small jab at Eclipse LMAO 11:28
@_thomasАй бұрын
intellij my beloved ❤️
@X5up0_Ай бұрын
True I am a cyber security student and he explained the Asymmetric authentication part really really well
@Jwolf0Ай бұрын
Yeah I don’t know how anything works and this video honestly helped me understand how all this works, this also explains why once I got a warning by bungee cord and no one explained what the hell it was
@MUmer-g9tАй бұрын
Yea i also known that why bungecord can only connect to different server
@JankoekepannekoekАй бұрын
I can't believe Hypixel made themselves vulnerable to the exploit that normally only occurs on all the 10yo kids first bungee networks.
@adrian-pr4tnАй бұрын
it's because they thought that a firewall is enough, an error on the backend caused for the firewall to reset
@silent4198Ай бұрын
@@adrian-pr4tn in this case it would be enough if it wasn't reset
@TimongcraftАй бұрын
@@adrian-pr4tnThat's why you don't only have 1 layer
@adrian-pr4tnАй бұрын
@@Timongcraft i'm just explaining
@enterprofilname9625Ай бұрын
@@Timongcraft If they have more than one, that would lead to more lag for the server (and you know they are already horrible)
@ItzYotamGamingYTАй бұрын
so basically, every once in a while, a genius comes and somehow hacks Hypixel. they found out they asked about it sometimes they tell, sometimes they don't and at the end they fix all and ban / wipe / punish the hackers. crazy stuff but bro has brains
@ZedacatАй бұрын
this exploit existed since forever, hypixel was only so unlucky for one of their firewalls to die and allow connections
@DreadHalfling9Ай бұрын
@@ItzYotamGamingYT misconfigured ports/machines are very very common and its honestly amazing the internet still functions with how poor the security is on most systems
@ItzYotamGamingYTАй бұрын
@@DreadHalfling9 well yes but my point is someone finds an exploit, abuses it and then tells it, it's a cycle
@DreadHalfling9Ай бұрын
@@ItzYotamGamingYT usually you have to look through logs to figure out what happened when its malicious as people dont really like to share that and make themselves public when theyre bad. But yea in cases like this and in good cases its awesome to have stuff directly from the hacker, glad you found cybersecurity interesting have a good day bro :]
@ItzYotamGamingYTАй бұрын
@@DreadHalfling9 alright, and thanks you too 👍
@mrdragonboiАй бұрын
To be fair, its a good thing he disclosed said method which this guy could be considered a Grey hat hacker, since he didn't do it with permission, but seeing as he helped the admins and devs, well - he technically got away. I would prefer to use a White hat method, but obviously I would only use "burner" accounts (with permission) and tell the admins about such. This is part of cybersecurity, and can be known as other names, especially ethical hacking. Although some countries deem it as a grey area, it is what it is.
@andrewkvk1707Ай бұрын
He also stole discord accounts so I am thinking they only disclosed the exploit to reduce their punishment, more black hat with the hypixel instance itself being grey.
@xblxckxpxny1005Ай бұрын
@@mrdragonboi why are you trying your hardest to sound "cool" and "knowledgable". "gReY hAt" "wHiTe HaT aPpRoAcH" "eTHiCaL hAcKiNg"...? Cringe NPC go back to playing games and doing homework 💀 No one that honestly knows whats up talks like that 🤦♂️
@mrdragonboiАй бұрын
@@andrewkvk1707 Yeah fair point
@MrMauioАй бұрын
man just put the fries in the bag
@mrdragonboiАй бұрын
@@MrMauio Alright then
@das_9677Ай бұрын
As someone with extensive experience in system administration and Spigot plugin development, I think that this was a nice explanation of the exploit. However, I have one correction to make: Velocity is NOT a fork of Bungeecord, but an independent project serving as an alternative to PaperMC's now discontinued "Waterfall" Bungeecord fork that aims for higher performance and security
@KristibekАй бұрын
I thought Velocity is the discontinued fork and Waterfall was the independent one made from scratch
@das_9677Ай бұрын
@@Kristibek Nope, it's the other way around. Velocity is more modern and the only proxy the PaperMC team is maintaining at the moment
@_thomasАй бұрын
this is correct (kinda embarrassing since I was building plugins for both 4 years ago)
@cor3po491Ай бұрын
WHY IS NOBODY TALKING ABOUT HOW ON THE MAP IN THE INTRO NZ IS JUST ROTATED UK 😭
@_thomasАй бұрын
HAHAHAHA CONGRATULATIONS you are the first person to notice
@CeelkerАй бұрын
@@_thomas Why is Africa gone?
@Agent_MightyАй бұрын
what happend to italy…
@teraba1696Ай бұрын
@@_thomasI noticed straight away and was confused, It's where I live aswell 😂😂
@xfsdarkАй бұрын
How da hell im i subscribed I think you hacked me
@aathifshadow6549Ай бұрын
@@xfsdark bro is it me at the thumbnail
@xfsdarkАй бұрын
@@aathifshadow6549 hmm , don't copyright him then
@aathifshadow6549Ай бұрын
@@xfsdark I won't do it
@TheWin9UserАй бұрын
1:51 "Your latest 2 week Minecraft phase?" He knows us good xD
@computeroid6162Ай бұрын
@@TheWin9User Came here to say this too lmao, too accurate
@TheWin9UserАй бұрын
8:28 A needle in a haystack in a field of haystacks.
@TankieBoiАй бұрын
Hypixel's lucky this wasn't a malicious hacker, in this guy's position I'd start Mass-Banning Hypixel moderators on the spot because I find their staff team corrupt as hell
@SnoozzeiАй бұрын
on god. there system sucks too. i've been banned for like 7 years for something i did when i didn't know any better i was like 16 then
@TankieBoiАй бұрын
@@Snoozzei Yes. They will ban based on personal bias, such as flagging a Soviet Flag "Inappropriate" in build battle, despite it, to my knowledge, not being considered an offensive symbol (And making stupid unrelated things to the theme isn't against any rules). I stopped playing Hypixel years ago for various reasons, some unrelated to the server itself, and can't say I'll miss too much about it. I liked build battle and Farm Hunt and maybe sometimes come back to visit it but with the generation of the Skibidi Bedrock children upon us and the Java players outgrowing Minecraft, Hypixel definitely has an unpredictable future
@ProboizzgamerzАй бұрын
Same with fakepixel network
@ookinbaoАй бұрын
Random comment but me and my friend are currently taking a Cyber Security class studying for the SC-900. Your explanation of the encryption system genuinely taught us better than our teacher. Hope to see more of this kind of content, maybe your explanations will help us pass the SC.
@Bilge-ko5qpАй бұрын
I came to watch how one guy hacked Hypixel but learned the whole computer science, wtf! Amazing video dude, immediately liked and subbed!
@teraba1696Ай бұрын
@@Bilge-ko5qp I decided to watch it 3 times cause I didn't expect to learn it either! Gonna be saving it to keep my mind refreshed about it
@Bilge-ko5qpАй бұрын
@@teraba1696 exactly, it's clean as water and teaches this topic very effectively, amazing!
@Clip_It1Ай бұрын
i LOVE how you explained this, its not even hard to understand with your visual examples
@Scriptッ9 күн бұрын
"i would NOT use eclipse" 😭😭
@CherrypizzasquadАй бұрын
5:49 Ithlught that was gonna be a sponsorship lol
@_thomasАй бұрын
man i WISH
@itomato8836Ай бұрын
@@_thomas try to actually dm the marketing representatives of certain companies that are close to the content you offer and offer them a sponsorship, this is a way to get recognized faster and it'll help you get sponsorships easier and have them as your clients.
@TlMEL0RDАй бұрын
15:04 Being a government hacker on you're goverment's side is a job.
@hito198815 күн бұрын
im impressed, never saw this channel and having "minecraft/hypixel" and "hacked" in a video title doesnt sound promising (theres too many fake "i griefed server XY" or "i hacked server XY" on this plattform). but im really surprised, this is a really informative video and im glad i stumbled over it. thanks for taking your time to educate us 👍
@thatfridayfeeling5490Ай бұрын
moyang
@proook3606Ай бұрын
Yangmo
@terrariapro147Ай бұрын
agmnoy
@timebladeАй бұрын
gnaymo
@Nitrogen_DioxideАй бұрын
Who unpinned this man.
@_thomasАй бұрын
moyang!
@MrElectric6096Ай бұрын
ah yes, hack the subscribe button The subscribe button: javascript:void(0)
@mrcavasАй бұрын
15:03 hmm i guess I can start hacking now
@bil0k74Ай бұрын
Я тоже (me too)
@newusername-i4n28 күн бұрын
@@mrcavas and me, конечно же)
@000.J-x1r14 күн бұрын
And meeee my mom going buy me vape v4 ghost client IM going hack and get revenge who people who bully steve andnplayers and me BHAHAHHAHA
@dirtismyolduserАй бұрын
amazing video- great balance of technical detail and accessibility to everyone. Keep up the great work!
@locipro993726 күн бұрын
insane quality and attention to detail from an underrated channel
@scalemeraldАй бұрын
first video i ever watched from you- i put this on for background noise and slight bit of entertainment as i ate a bowl of cereal, praying that you wouldnt be a super quiet content creator that my eating would drown out... just to find out that you are very much not quiet and do your own subtitles.. based as hell, im def coming back here again lmao
@ClazzetteАй бұрын
I've learned more Cybersecurity concepts in this video than my own college course back in the day. I love this video.
@Laggy_boi_Ай бұрын
Not gonna lie, this was such a good documentary. I'm surprised you only have 18.4k subs since your content is peak. Keep it up bro, earned another sub!
@Zilkenian_DavenportАй бұрын
I like the way you explained all of this. I work with servers, and IPs, ports, proxies, firewalls and backend servers are something I deal with on a daily basis, but took me a long time to understand when I started. Would have loved to have your video back then.
@TheElderRealАй бұрын
In just 2 hours There is already someone who archived it In Way back machine This video Is really Great.
@DreadHalfling9Ай бұрын
Techy people like stuff like this and theyre usually the ones who use wayback :)
@TheElderRealАй бұрын
@@DreadHalfling9 Yes sadly The video Is not Registered.
@CrownlessOcto10 күн бұрын
You did a fantastic job at describing all the server security feature then some of my professors lol
@deadshxllАй бұрын
"Cybersecurity professionals need to win every time, attackers need to win only once."
@DeIexo13 күн бұрын
I learned more cybersecurity in this video then my actual class- IN 15 MINUTES.
@user-wb7ot7kt3xАй бұрын
The fact that you have to install a seperate plugin so the backend servers can validate the authenticity of the bungeecord server is insane. Like the whole authentication is handled by bungeecord. Applications like this should be secure by default.
@infinite_bedАй бұрын
Very well done explanations! Just finished a proxy system for my server, and I had to learn everything you explained so will by myself. If only I had these videos a week earlier!
@_thomasАй бұрын
@@infinite_bed damn! if only I had posted this video more than a week ago... 😔
@Rohan.Reddy.Bandi.Ай бұрын
as someone tryna get into cybersecurity and also love minecraft, this was the best video i have ever seen
@SuperNuketown202514 күн бұрын
As per US laws, this almost certainly wouldn’t constitute hacking, because the “hacker” in this case never entered any kind of password or secret, and didn’t abuse known a software bug to bypass such authentication. Misconfiguring a server and giving someone access because you didn’t properly authenticate them is, in fact, not a violation of the computer fraud and abuse act.
@NvroIshereАй бұрын
That's crazy. As someone who has been doing server development and some pentesting myself over at least a decade now, I'm surprised as to how easy of an exploit went unnoticed for so long. I've actually done this before as a test on some smaller servers I worked on as well. Crazy dude. Edit: The fact that they were still using Legacy Bungeecord as well is insane.. but, it makes sense seeing that the server itself is really old and has thousands of players that still play today.
@amynagtegaal6941Ай бұрын
I actually got into hypixel's servers the same way this hacker did a few years ago... Only i truly didn't have any malicious intentions and instead formally informed the hypixel staff. But looking at this video i think that if i hadn't informed the hypixel staff that this hacker could have done way more since back when i did it i had full system access to i believe almost all systems in their internal network. Of course for everyone reading... I do not encourage anyone from actually hacking and stuff.. All i did was simple scans that anyone can do easily, only not everyone knows how to leverage those scans to see the full extend of all the vulnerabilities. If you ever do these things, be responsible and inform the people who the systems belong to, and don't be a shithead and mess with their systems
@aniruddh576Ай бұрын
this is an incredible video man, editing and info wise, loving it! you just gained a new sub
@Jecket22Ай бұрын
Genuinely informative and overall well made video! It's honestly surprising that Hypixel didn't have (an equivalent of) BungeeGuard for their servers. learning something new behind big servers haha
@SentakuuGamingАй бұрын
damn that was well made video insane man also i remember when servers were running 1.8 bungeecord so simple to get to the server bypass authme and grief them i remember i had friend who was very insane in this stuff we griefed one german server like it was fun got bored quickly since nobody was there well anyways keep posting more vids il watch them if its like hypixel history related ;D
@kuba4fulАй бұрын
If you ever get bored of Minecraft videos, please make white hat hacking/computer science explanation videos. I already knew most of the stuff here, but I was surprised at how well it was explained here. I'd love to have such videos back when I was studying this.
@Monkeymario.14 күн бұрын
1:40 It's already 23.3k subs
@TomakinsАй бұрын
It's wild that you kept my attention while describing how logins work
@PR3SVXАй бұрын
i love how you so effortlessly explained asymmetric encryption in 3 minutes better than my computer science teacher did in an hour
@UltraCenterHQ22 күн бұрын
11:48 damn... all the evil hacker wanted was friends all along 😔
@monstersponge9096Ай бұрын
Hypixel having a max player count of 50k with an average of 30k people being on at any given time is really crazy to me. I started playing hypixel in 2015 and haven't been on since 2020. I was online when they hit the maximum connected players (555k at the time) record & sent out a server announcement through chat to thank everyone for playing. Very surprised that the new generation doesn't have much interest in playing multiplayer servers anymore.
@redsox.Ай бұрын
Wow I remember the players with level 5,000+ and had no idea this is what took place. I’m pretty sure hypixel covered it up at the time, claiming they abused some bug
@mrvenzen5719Ай бұрын
Very good vid, story telling and explaining. Enjoyed watching it through, keep it up!
@pontusnyfelt809622 күн бұрын
this is how must stuff work when it comes to securyty that there exist a flaw until someone find that flaw and then that flaw is patch and thats how the securyty gets greater and greater
@DataDerpАй бұрын
Bungeecord in this sense could be also called a load balancer. I guess reverse proxies are all load balancers if configured to do so. Side note: great video, wasnt expecting such s low subscriber count with this quality.
@TimongcraftАй бұрын
Nah, you have load balancing on top, one BungeeCord instance isn't enought and also if that would fail it would be catastrophic
@DataDerpАй бұрын
@@Timongcraft Exactly, there would be load balancing at DNS level (correct me if I'm wrong but I think multiple SRV records) which could point to a different bungeecord instance depending on 'priority' (I think) of the SRV records. I never had to do this, this is based off general system administration knowledge. Then each bungeecord instance works together to route the player across those mini servers.
@TimongcraftАй бұрын
@@DataDerp Ig and they probably either have Bungee in Bungee or some other proxy like HA Proxy too after that.
@lmnkАй бұрын
Great job explaining concepts of server scaning in simple terms!
@luminescentlionАй бұрын
Public Private Key encryption does not work backwards. The server just makes it own private key and sends clients the public key, so they both have each other's public key. ultimately meaning that when you encrypt something with the public key only the designated receiver(Whoever has the private key that matches the public key) can recieve it.
@_thomasАй бұрын
It does, in fact, work backwards. RSA is a trapdoor permutation, works both ways!Typically you would only sign and decrypt with the private key, though, since it's not very good encryption if anyone with your public key can decrypt! The client never generates a keypair. The server never has the client's public key as: 1. the client doesn't have one and 2. it doesn't need it. The server's public key is used to encrypt the shared secret. The client generated the shared secret internally, so it doesn't need to receive any encrypted information. They then use that to talk with AES - symmetrical encryption. Read more about Minecraft's implementation here: wiki.vg/Protocol_Encryption
@ceruleanshepАй бұрын
Some dude finds an exploit to hack the largest MC server in the world. And yet I get banned for accidently using a harmless exploit that no one told me I shouldn't be able to do. I think I'm still salty about it.
@asawskiАй бұрын
what u did
@KastrujeDzieciNozyczkamiАй бұрын
we have to know what dirrr you do
@ceruleanshepАй бұрын
@@KastrujeDzieciNozyczkami So people were flying around in the skywars lobby, and after accidently hitting the space bar twice, I realized I could fly too. After about 5 minutes of flying, I was kicked for "blacklisted mods". I tried to appeal, but was denied, and now I can't appeal again. Literally no one will hear me out. This was back in 2014.
@KastrujeDzieciNozyczkamiАй бұрын
@@ceruleanshep XD thats funny and sad because its their fault
@ceruleanshepАй бұрын
@@KastrujeDzieciNozyczkami After much prying, apparently flying in the lobby was only available for those who donated a certain amount to the server. But NO ONE TOLD ME OR STOPPED ME
@x4damАй бұрын
Bro is so underrated. I learnt more from this than in computing class.
@kemoxАй бұрын
Amazing representation for ports, i've always explained it to my friends as doors to a house but this was a nice well made video for sure. subbed.
@DybannnАй бұрын
i actually love this editing style so fucking much
@rodricbrАй бұрын
well, that's why port plus cidr scanning is so important loved the video, really well explained.
@luckycatzinhoАй бұрын
"security is not a process, it's a state until you got pwned"
@johennes09Ай бұрын
„it wont work with your friends server“ my ass who has a bungeecord server😂
@Ваня12к-щ3кАй бұрын
Instructions unclear, accidentally hacked Minecraft and banned Moyang. -1/-10
@NewRodinАй бұрын
Really well explained. I'm pretty familiar with pentesting and how that stuff works (I work with it and daily drive BlackArch and Qubes) and I love how you ELI5'd it so well so people can understand easily. That hacker was an absolute legend, found the backdoor and responsibly just said what it was so they could patch it, and didn't abuse it for his monetary gains. That's how we do it. Thanks for making this video, it was definitely a good watch. Definitely subscribed!
@NolusWithUsАй бұрын
1:14 wow tysm for this free cats clip
@behasan794917 күн бұрын
Bro the way you explain things is crazy good
@SilentTombMusic19 күн бұрын
here before 25k! Great video bro!
@JJTurtle4everАй бұрын
Well, you've earned a sub! Made me a little more interested in hacks since my microsoft account just got hacked... good job on the explaination!
@cornflakespaghet7661Ай бұрын
It actually used to be possible to steal someone's key just by having them join your fake server. Had some fun with that back in the day O7
@OURPR_Ай бұрын
Crazy good explanations / editing in PERFECT pace 😍✨💅😮💨
@Miiiasm12 күн бұрын
It’s not the first time that Bungeecoord is involved with security flaws on authentication, there were quite few similiar exploits in the past and yet seems nobody even in Hypixel learned their lesson
@talksickcsАй бұрын
Nice informative video on internet security and technology! Well done.
@bigrice303Ай бұрын
That hacker totally deserved keeping the creative mind 🤣
@avivam777Ай бұрын
2:57 = NERD ALERT
@LevemooreАй бұрын
This is a really good video, i love the editing
@Helios1993Ай бұрын
As someone who started working with Minecraft servers almost a decade ago, it's hard to believe Hypixel dev team managed to make such a basic mistake. Using a firewall in this scenario is a bad practice - the backend servers shouldn't even be open to the WAN, and the traffic between them and the proxy server should only go through LAN. The verification key between proxy and backends is also a standard for years and over half the existing server networks use it.
@mbhv-ll9lqАй бұрын
Great video, very good explanation of ports ( towns ).
@beatiok28 күн бұрын
it's crazy how ONE MAN hacked hypixel man.. not an alien or a god, just one man. 👽
@darkmark7366Ай бұрын
If minecraft hackers and war thunder classified documents leakers used their power in anything other than videogames the internet might shut off
@dantheturtle6412Ай бұрын
I love the way you explained things in the video, I actually understood something for once
@epicstar86Ай бұрын
peak content, you're so underrated
@NevvuloАй бұрын
Awesome video, love your explanations and editing :)
@Cyber_ChriisАй бұрын
The port explanation was amazing!
@NiesmiesznyyАй бұрын
my guy could destroy entire hypixel economy but decided to give freebies to himself and his friend and then share with the admins how he did it. What a chad
@jc008titanАй бұрын
why can't teachers explain tokens that well?? you are the best teacher of those things!
@itz_CrihАй бұрын
really good vid and nice explanation. as a java dev myself i have a lot of experience in this and yeah i can say most of the things this guy said is true. There were too many ads tho...
@xanderreadeАй бұрын
There was a 50% chance clicking on the video that it was going to be about you 🤣
@Matthew-we3irАй бұрын
Very very Underrated Video, keep up the good work. Rn the video is at 52,288 view, and I wont be surprised if it hit 2-3 mill.
@hi12167piesАй бұрын
i remember doing this same exploit on some smaller servers, i didn't think hypixel would have ever had this issue considering how large they are.
@edmund0450Ай бұрын
me when million dollar company does "small" oopsie
@LeanPicachuАй бұрын
taught me about asymmetric encryption better than my cybersecurity class 💀
@bill.zhanxgАй бұрын
You explained all concepts very well!
@fruitepic9260Ай бұрын
that's probably the best metaphor for what a proxy is, cheers
@justadude1495Ай бұрын
Small correction: Velocity is NOT a fork or Bungee cord, it's an entirely new reverse proxy from the ground up.
@nathantraverso2713Ай бұрын
Really didn’t think I’d see Thomas on my fyp haven’t seen anything since tfm
@gavinmorrow332823 күн бұрын
As someone trying to get into cyber and tech these were great explanations of all the concepts involved I really loved the port scan metaphor in particular!
@_end3rguy_Ай бұрын
my cousin found an exploit to ban people from entering a chunk and hypixel hired him to use it before it was patched
@BunnySoos12 күн бұрын
plot twist: he asked nicely if he can have admin and hypixel gave him admin
@lucachinouАй бұрын
Good vidéo ! Continue like this !
@desleyv9999Ай бұрын
Hacked the subscribe button just for you. Interesting video, thanks for putting in all the effort to bring it to us!