Mojira Archive
MC-253889

Servers can tamper with messages through chat reporting in undetectable ways

I am detailing the more serious exploit methods from MC-253888 here out of an abundance of caution.

The other ways servers can trick users into sending modified messages are:

  • Add a feature that lets players show off their items in chat, then modify the embedded item and report players for harassment through item names. Requires hovering over the [item] text to detect. (see item.mp4)
  • Add hover text to one random letter in the chat preview containing a nasty message. The message is visually identical to the typed message, the player must hover and scan the entire preview to detect.
  • Use the insertion style to insert text into the chat preview component. Moderators then see {"insertion":"(something nasty)","text":"test"} as the reported payload and may take action on the nasty message. This is completely undetectable by the player.
  • Use a server resource pack to change what letters look like in the font, so that the chat preview looks like a normal message using the resource pack but is actually offensive in the original letters. The server could abuse similar-looking letters (such as the Cryllic "а" instead of the Latin "a") to ensure that Mojang moderators read an offensive message in what looks like English letters. If moderators treat reports with similar-looking letters as fakes, this enables malicious players to use those same letters to evade punishment.

Works As Intended

Tis_awesomeness

2022-07-04, 02:24 PM

2022-07-10, 02:59 PM

2022-07-06, 08:06 AM

1

3

Plausible

Social Interactions

1.19, 1.19.1 Pre-release 2

-