[PSA] Regarding Hacked Clients & Fake Plugins

Discussion in 'Bukkit Discussion' started by Kaikz, Jun 5, 2012.

  1. Offline

    Kaikz

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Yup, my thoughts exactly. More fun for me in ruining their "fun", I suppose.

    This post has been edited 1 time. It was last edited by Kaikz Jun 25, 2012.
    h31ix likes this.
  2. Offline

    JOPHESTUS

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    What is a PSA?
  3. Offline

    zipfe

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
  4. Offline

    TheLimaBeanman

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Found you on HF.
  5. Offline

    Darky1126

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Found that you actually have an account of your own in order to verify it is him.
    np98765, Kaikz and Sushi like this.
  6. Offline

    JOPHESTUS

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    You should sticky this thread
  7. Offline

    Kaikz

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    And? This proves nothing.
  8. Offline

    TheLimaBeanman

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    No, I was just glad to find you there. I use HF to advertise my server.
  9. Offline

    Sushi

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    I have an HF account too, you would be surprised who has one.

    I bet that a large part of the people on HackForums aren't actually hackers per se.
    TheLimaBeanman likes this.
  10. Offline

    Joshuame13

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Another thing you might think about adding is Sketch's "ForceOp" SessionStealer thing. To be clear , IT ISN'T A FORCE OP, but that's what it is commonly called. It allows someone to get op on your server without you oping them, downloading a malicious file, or something of that sort. All you have to do for them to gain op is connect to their (fake) server. SessionStealer makes a fake server on the hacker's computer. If you connect to their IP, it takes your validation info that you use to log into their server and forewords it to your own server. Then, logged in to your own server as you, it sends a chat message, usually in the form of "/op [hacker name here]." All this happens while you are thinking you are connecting to the hacker's home server. After it is done, (you are still waiting on the connecting... screen), it kicks you for a customizable message, usually like "End of Stream" or "Outdated Server." You go away thinking that their server just doesn't work and the hacker goes away with op. Even something as simple as logging into a server can give someone access to your server.

    Thanks for reading,
    Josh

    This post has been edited 1 time. It was last edited by Joshuame13 Jul 8, 2012.
  11. Offline

    Kaikz

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    As far as I know, session stealers have been fixed.
  12. Offline

    md_5

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    * in 1.3, but yeah point remains, no need to worry.
  13. Offline

    Kaikz

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    eh, I heard it was already fixed with something to do with the username. Obviously not.

    But yeah, it's fixed for the most part. sk's new method with WorldGuard, or just block sensitive commands, which NoCheat+ does with /op.

Share This Page