Uploaded May 2022 | Updated September 2026, 2 weeks ago
This Minecraft:HACKED episode starts with AFK fishing and a potato farm, then applies the scientific method to design a fishing farm for Minecraft 1.19. Because the server is still on 1.18.2, the project turns into an AutoFish mod, a fly hack, and a bypass for server-side flying detection.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-minecraft/server-and-client-modding
Join the Hextree Discord: discord.gg/xgQpCQCpvy
RESOURCES
Simple AFK Treasure Fish Farm Concept for 1.19 Sculk Sensor: youtube.com/watch?v=L-g9ml6wzgM
Easy Carrot & Potato Crop Farm Tutorial | Simply Minecraft (Java Edition 1.17/1.18): youtube.com/watch?v=A8DQYpk5944
MrTroot/autofish: github.com/MrTroot/autofish
Trolling 2b2t Players with a "Magic Carpet": youtube.com/watch?v=Ze9a-I-kFt4
CHAPTERS
00:00 - Intro
01:23 - AFK Fishing Farm Explained
05:30 - Let's Play: Villager Breeder & Potato Farm
07:00 - The Scientific Method
10:27 - Inventing a 1.19 AFK Fish Farm
12:25 - Developing AutoFish Mod
18:14 - Bypassing Server Flying Detection
23:32 - Flying without Elytra!
24:52 - Outro
MUSIC
C418 - Minecraft Soundtrack
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#GameHacking #MinecraftHacked #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.
This Minecraft:HACKED episode starts with AFK fishing and a potato farm, then applies the scientific method to design a fishing farm for Minecraft 1.19. Because the server is still on 1.18.2, the project turns into an AutoFish mod, a fly hack, and a bypass for server-side flying detection.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: hextree.io
Watch this video and more on Hextree: app.hextree.io/courses/yt-minecraft/server-and-client-modding
Join the Hextree Discord: discord.gg/xgQpCQCpvy
RESOURCES
Simple AFK Treasure Fish Farm Concept for 1.19 Sculk Sensor: youtube.com/watch?v=L-g9ml6wzgM
Easy Carrot & Potato Crop Farm Tutorial | Simply Minecraft (Java Edition 1.17/1.18): youtube.com/watch?v=A8DQYpk5944
MrTroot/autofish: github.com/MrTroot/autofish
Trolling 2b2t Players with a "Magic Carpet": youtube.com/watch?v=Ze9a-I-kFt4
CHAPTERS
00:00 - Intro
01:23 - AFK Fishing Farm Explained
05:30 - Let's Play: Villager Breeder & Potato Farm
07:00 - The Scientific Method
10:27 - Inventing a 1.19 AFK Fish Farm
12:25 - Developing AutoFish Mod
18:14 - Bypassing Server Flying Detection
23:32 - Flying without Elytra!
24:52 - Outro
MUSIC
C418 - Minecraft Soundtrack
SUPPORT
Per video: patreon.com/join/liveoverflow
Per month: youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): shop.liveoverflow.com
WATCH, FOLLOW & READ
Second channel: youtube.com/LiveUnderflow
Twitch: twitch.tv/LiveOverflow
Twitter: twitter.com/LiveOverflow
Instagram: instagram.com/LiveOverflow
TikTok: tiktok.com/@liveoverflow_
LiveOverflow blog: liveoverflow.com
Hextree blog (ad): hextree.io/blog
#GameHacking #MinecraftHacked #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement.







![A Vulnerability to Hack The World - CVE-2023-4863
Citizenlab discovered BLASTPASS, a 0day being actively exploited in the image format WebP. Known as CVE-2023-4863 and CVE-2023-41064, an issue in webps build huffman table function can lead to a heap buffer overflow. This vulnerability is very interesting and Im excited to share with you what I learned.
LEARN ON HEXTREE (ad)
Learn hacking on Hextree: https://www.hextree.io/
Join the Hextree Discord: https://discord.gg/xgQpCQCpvy
WebP Fix Commit: https://chromium.googlesource.com/webm/libwebp/+/902bc9190331343b2017211debcec8d2ab87e17a
Citizenlab: https://citizenlab.ca/2023/09/blastpass-nso-group-iphone-zero-click-zero-day-exploit-captured-in-the-wild/
Ben Hawkes: https://blog.isosceles.com/the-webp-0day/
Software Updates
Apple https://support.apple.com/en-gb/106361
Chrome https://chromereleases.googleblog.com/2023/09/stable-channel-update-for-desktop_11.html
Firefox https://www.mozilla.org/en-US/security/advisories/mfsa2023-40/
Android https://source.android.com/docs/security/bulletin/2023-10-01
Whose CVE is it Anyway? https://adamcaudill.com/2023/09/14/whose-cve-is-it-anyway/
References:
2014 bug introduction https://github.com/webmproject/libwebp/commit/f75dfbf23d1df1be52350b1a6fc5cfa6c2194499
https://www.youtube.com/watch?v=JsTptu56GM8
https://www.youtube.com/watch?v=B3y0RsVCyrw
https://www.youtube.com/watch?v=EFUYNoFRHQI
https://www.youtube.com/watch?v=iEm1NRyEe5c
https://stackoverflow.com/questions/13804629/huffman-code-with-lookup-table
https://web.archive.org/web/20230204211844/https://commandlinefanatic.com/cgi-bin/showarticle.cgi?article=art007
enough.c https://github.com/madler/zlib/blob/develop/examples/enough.c
Thanks to:
https://twitter.com/mistymntncop
https://twitter.com/benhawkes
CHAPTERS
00:00 - Intro to CVE-2023-4863
01:32 - Most Valuable Vulnerability?
03:02 - Heap Overflow Related to Huffman Trees
03:58 - Learning about Huffman Codes
06:24 - What are Huffman Tables?
10:24 - Hardcoded Table Sizes (enough.c)
12:21 - Code Walkthrough - BuildHuffmanTable()
13:04 - The code_lengths[] and count[] Arrays
15:14 - Difference Between Compression and Decompression!
17:04 - Outro
SUPPORT
Per video: https://www.patreon.com/join/liveoverflow
Per month: https://www.youtube.com/channel/UClcE-kVhqyiHCcjYwcpfj9w/join
Buy my handwriting font (ad): https://shop.liveoverflow.com/
WATCH, FOLLOW & READ
Second channel: https://www.youtube.com/LiveUnderflow
Twitch: https://twitch.tv/LiveOverflow/
Twitter: https://twitter.com/LiveOverflow/
Instagram: https://instagram.com/LiveOverflow/
TikTok: https://www.tiktok.com/@liveoverflow_
LiveOverflow blog: https://liveoverflow.com/
Hextree blog (ad): https://www.hextree.io/blog
#BufferOverflow #SecurityResearch #LiveOverflow
(ad) LiveOverflow YouTube channel is supported by advertisement and product placement. A Vulnerability to Hack The World - CVE-2023-4863](https://i.ytimg.com/vi/lAyhKaclsPM/mqdefault.jpg)


