Back to mods
RedHerring project artwork

CurseForge · Minecraft mod

RedHerring

Simple non-invasive coremod to fix the 'exploit' in 1.8.x that allows the server to get yes/no answers.

Choose a version Pick your version below, then grab the matching file.

Quick answer

Which RedHerring release matches 1.8.7?

Updated 7 years ago
Best match for your filters redherring-1.8.9-1.0.0.jar
Game version 1.8.7, 1.8.4, 1.8.8
Loader Not required

redherring-1.8.9-1.0.0.jar targets 1.8.7, 1.8.4, 1.8.8. The project page does not say whether this file belongs on the client, dedicated server, or both. No extra mods listed for this file.

Where it goes

Is RedHerring required on the client, server, or both?

The project page does not say whether this file belongs on the client, dedicated server, or both.

Client Source doesn’t say
Dedicated server Source doesn’t say
Loader for this release No loader listed
Required install it here Optional supported, not mandatory Not supported do not install here Source doesn’t say do not assume

The source does not explicitly classify this release as client-only or server-only.

What else does redherring-1.8.9-1.0.0.jar need?

redherring-1.8.9-1.0.0.jar on 1.8.7. Every mod below is checked against that same setup.

No extra mods listed for this file

This file does not list any required mods. Do not add a library just because a different file uses it.

This file does not list any required or optional mods.

Before you install it

Add RedHerring without breaking your instance.

Built for redherring-1.8.9-1.0.0.jar on 1.8.7. Pick another file and the loader, install side or required mods may change.

  1. 01

    Stick to this file

    Use redherring-1.8.9-1.0.0.jar. It targets 1.8.7, 1.8.4, 1.8.8; another release may have different loader, side or dependency requirements.

  2. 02

    Bring the mods it needs

    This file does not list any required mods. Do not add a library just because a different file uses it.

  3. 03

    Put it on the correct side

    The project page does not say whether this file belongs on the client, dedicated server, or both.

  4. 04

    Pick the file you checked

    Use the “Get this file” button beside redherring-1.8.9-1.0.0.jar. It opens that exact file at the source.

About this project

What does RedHerring add?

Simple, clean server resource pack "Exploit" fix.

No external dependencies besides Forge.
The "Exploit" ONLY allows for the server to check if a file exists on the client or not.
And as a side effect cause the game to try and load the file as a resource pack.
There are currently no know issues with java's zip file management that would allow for any extra malicious activity.
So any claims of people being able to steal your passwords/execute code/etc.. is unfounded. Hence the name RedHerring.

For more info refer to: https://ungeek.eu/minecraft-18-file-access/ Ignore the fear mongering bits like:
"Servers can check if a file exists on the player's computer, enumerate users names but maybe even worse. See PHP's issue with file_exists and phar files."

Logo Found at TvTrops, CC-BY-SA-4.0, https://commons.wikimedia.org/wiki/File:Redherring.gif

Project description from CurseForge.

Pick your setup

RedHerring by Minecraft version and loader

Choose the version and loader you play, then open the matching release.

10 available setups

Check the dependencies, then try the file in a copied instance before changing a world you care about.

Recent files

RedHerring versions and loaders

1 of 1 releases match

Looking for an older file? The official CurseForge project page is in Resources.