[Security Bulletin] Do not test/run op gain exploit programs!

Discussion in 'Community News and Announcements' started by EvilSeph, Mar 15, 2012.

     
  1. Offline

    EvilSeph Bukkit Team Member Administrator

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    There is no way for anyone to illegitimately gain op on your server unless you are running your server in offline mode. Any program in existence that claims otherwise is trying to lure you into running it (in an effort to see if your server is at risk) to steal your information.

    You'll notice that in every video you either have to have the program running before you login or need to login, run the program and restart Minecraft. This is because these programs are designed to take the IP you enter into the ForceOP hack for testing, your username and password and send it to the creator. Even if this is not the case, it is fairly simple to put together a fake, convincing video by simply modifying the client to respond to "/op" and print local messages to make it seem like the user has gotten op.

    Regardless, any programs offered for download accompanying these videos or public reports of op force hacking or the like are usually sending the creator an email that says something like:
    "New server to grief: <IP you entered - usually your server, since you want to be sure your server is safe>
    Username: <you username>
    Password: <your password>"

    Every single time someone reports this issue, it turns out to be the same thing. A malicious program designed to fool server admins into thinking their server is at risk, running to try it out and make sure they aren't. Then later finding their server has been attacked by someone with op because they know your username and password, and thus can op anyone they want on your server.

    Until someone brings a real exploit that allows you to gain op to my attention, we'll have to continue stopping the discussion of and advising against the discussion of this 'hack' to slow down it spreading. We take every exploit report we get seriously and investigate each and every one. To this day, we have been unable to find a legitimate exploit to gain op in any server and every reported exploit has turned out to be a malicious program that collects your information in an effort to exploit you and your server.

    If you're looking to report an exploit, we advise people to stop posting exploit discussions publicly and, instead, contact one of my Admins, myself or create a private ticket on http://leaky.bukkit.org.
  2.  
  3. Offline

    Jess_FB

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    Just about everything is "Hack" or 'editable' in some way, that's how we get mods. But its how people today are using them. I mean luring people to steal their info, and then use it against them? I don't see how you get joy or don't feel bad about that, the bad area of the minecraft community really IS bad.
  4. Offline

    Richard Robertson

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    It's not just Minecraft. Phishing (that's the real name for it) exists everywhere. It's like domain names like faceboook.com being registered that pretend to be Facebook so you accidentally log in to it and they have your account. It happens a lot actually.
  5. Offline

    Jess_FB

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    I know, and its sorta sad that people even attempt these things, it reminds me of people being rick-rolled on youtube. Looking for a video by tehnipp1n and see a video similar by tehnippin and get tricked. I dont see why people enjoy doing these things
  6. Offline

    Jacek BukkitDev Staff

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    The best one I ever saw was rnyspace.com. Bit off-topic but it impressed my 12 year old self :)
  7. Offline

    alexistough

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    Sadly sir you are wrong I was hacked.
  8. Online

    TnT Trinitrotoluene Maximus Administrator Bukkit Help

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    We have still not seen a force op hack we could replicate. We're not saying its impossible, just unknown at this time. The ones popularly shown on Youtube are all fake.
  9. Offline

    bbq

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    IP BANNING IS USELESS!
    How many times must I say this?? 99% of the time the person you IP ban will have a dynamic IP address, which means it is simply a matter of unplugging the router and restarting it so that there ISP automatically gives them a new IP. Oh and then there IP maybe allocated to a legit player (but that is very unlikely).
    Whether they have the IQ to do this is a good point thou.

    Also as for MCBans I personally think if your to lazy to manage your own ban list then you shouldn't be running a server.
  10. Offline

    intel5271derpz

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    actually this can happen one of my dumb friends did it he was de-oped and the server is running in online mode and he oped himself so either theres a hidden bug in bukkit or a plugin is screwed up so you tell me that its not true and PROVE it else it is true. nuff said
  11. Offline

    intel5271derpz

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    as for the MCBans i think you sir are correct
  12. Offline

    Jacek BukkitDev Staff

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    He probably knew your password.
  13. Online

    TnT Trinitrotoluene Maximus Administrator Bukkit Help

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    The burden of proof lies with you I am afraid. You must prove, or at least provide evidence proving this is the case.
  14. Offline

    zathrus

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
  15. Offline

    lukegb Bukkit Team Member Administrator

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
  16. Offline

    zathrus

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    ah, I didn't see the original post... the one from MCBans originates a while ago, thus my confusion, sry
  17. Offline

    [qwerty]

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    Yeah, that's true. I like the new account migration though, that's a step in the right direction :)
  18. Offline

    Jacek BukkitDev Staff

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    It's a temporary fix, All they have done it change all of the usernames. The problem of people using alt accounts will come back once the people doing the cracking change their strategy to find emails and crack based on those.
  19. Offline

    MXO10

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    Thanks for the info now i know that it wont work because my friend was trying to do that and he got a virus!
  20. Offline

    fredghostkyle1

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    who reads the adds that come out of that???? i think i am smart to see the hack,

    you can't, it is in the vanilla it is in bukkit AND most people use that, and some don't have plugins w/ permissions so.......... you can't.

    This post has been edited 1 time. It was last edited by fredghostkyle1 Apr 30, 2012.
  21. Offline

    Richard Robertson

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    It's pretty easy to write a Bukkit plugin that removes the /op command.
  22. Offline

    Kainzo

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    Nifty teapot analogy / theory.
  23. Offline

    PandazNWafflez

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    Bukkit can remove it if they want to, and besides, Bukkit technically has permissions built it, just they aren't very good.
  24. Online

    TnT Trinitrotoluene Maximus Administrator Bukkit Help

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    Really? Did you know PEX, bPermissions, PermissionsBukkit all use this API? It may have its quarks, but its far from "not very good".
  25. Offline

    fredghostkyle1

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    kk, i think the people who add the plugin that lets others to be OP, without using console is dum... wether they know it or not. and to TnT, he is right.
  26. Offline

    PandazNWafflez

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    Sorry, that was not worded the best way, I meant that it is impractical for server owners to use the default permissions.yml file without a plugin that allows for groups and other options.

    This post has been edited 1 time. It was last edited by PandazNWafflez May 2, 2012.
  27. Offline

    fredghostkyle1

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    what is the premissions.yml for?
  28. Offline

    Richard Robertson

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    Impractical? My permission plugin doesn't even save runtime changes I've made to permissions. No groups, all files hand edited. That suits some of us just fine.
  29. Offline

    PandazNWafflez

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    Then.. your permissions plugin is terrible? And anyway, how many people are on your server? I mean, look at a server like Super-Earth (thousands of players), if they had to write out all players permissions by hand, how long would it take them? And they use prefixes, which Bukkit doesn't support in permissions.yml by default.
  30. Offline

    PandazNWafflez

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    People that run very small servers that have the time to write out all the permissions separately for each player and don't need prefixes or suffixes.
  31. Offline

    Richard Robertson

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    I wrote the permissions plugin for my personal server which consists of approximately 4 people on at a time max. It's a perfectly practical plugin for MY server. I was arguing your application of "impractical" to all servers.
  32. Offline

    fredghostkyle1

    dev.bukkit.org profile:
    CFUSERNAME
    My Plugins (CFCOUNT)
    Minecraft account:
    MCUSERNAME
    ok, i will have to do that... LOL

Share This Page