Jump to content

Minecraft host exploit


bijan588

Recommended Posts

Guys take a look at this, it could affect all of us

http://www.minecraftforum.net/topic/553214-warning-to-all-shared-minecraft-hosts/

Today DaddyCheese hosting identified a user running a CraftBukkit plugin that enabled a user to traverse and read the systems directory structure outside of their server directory. Thankfully this occurred on a new node and no sensitive information was accessed.

 

I am not sure exactly what setups this will affect, but any system not imposing any kind of access controls will be affected.

 

With the support of Daniel Hofer (Multicraft Author) DaddyCheese hosting has secured its servers from this kind of exploit in the future.

 

I suggest all hosts check their hosting setups to ensure that this is not possible in your environments.

 

We will report more when we have had a chance to investigate the method further.

Link to comment
Share on other sites

Exactly, the problem is server data, maps and such

 

 

Any fix yet for windows users?

 

Fix?

 

Basically just keep a look out and have high security.

 

The OP of that thread mention it is a "bukkit" plugin and ANYONE can just simply rename the .jar to something else.

 

I'm thinking its hard to find if you have tons of users (clients) and if you want to keep track of each plugins every day, every hour.

 

OR unless you disable all .jar uploads but I don't really see the point of providing Minecraft if majority wants to use plugins.

Link to comment
Share on other sites

If all the exploit does is allow the directory to be read all they can do is view what is installed on your server. With out write access what can they do. This could be an issue with EA ranked providers.

 

I dont think any decent gsp will dare to run minecraft next to any other game on a box. Performances would be terrible.

Link to comment
Share on other sites

Why would you have to move servers? Why make assumptions and present them as statements when you don't know?

 

because i know actually. minecraft is resource intensive and certain plugins can cause high cpu usage spikes which can make lag most of other game servers. Small hosts may not be affected by this if running a very low amount of mc servers per machine.

Link to comment
Share on other sites

Any and all games can cause performance hits if allowed to do so. Obviously you have a different circumstance(s) than what I've had experience with.

 

well you are lucky if it did not affect your other games running on the same machine but this will more likely happen.

 

there are certain games that you need to avoid running next to others, minecraft is #1.

Link to comment
Share on other sites

well you are lucky if it did not affect your other games running on the same machine but this will more likely happen.

 

there are certain games that you need to avoid running next to others, minecraft is #1.

 

I was referencing the ranked games as to which you have no knowledge since that is what you originally quoted Sickpuppy about. Anyhow, all of this is useless diatribe at this point.

Link to comment
Share on other sites

  • 3 weeks later...
I was referencing the ranked games as to which you have no knowledge since that is what you originally quoted Sickpuppy about. Anyhow, all of this is useless diatribe at this point.

 

Diatribe dude, had to look that one up.

 

di?a?tribe/ˈdīəˌtrīb/Noun: A forceful and bitter verbal attack against someone or something

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

  • Who's Online   0 Members, 0 Anonymous, 33 Guests (See full list)

    • There are no registered users currently online
×
×
  • Create New...

Important Information

We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue. Terms of Use