Mojira Archive
MC-27335

Malformed nicknames vulnerability

If there's a user "foouser", and someone decides to log in with a nickname of "foouser " (that is, with a 0x20 space at the end, with a cracked launcher most likely), not only that the server will allow connection of such client, but won't disconnect "foouser" either.
Also, what's more severe, "foouser " will get all permissions of "foouser", and no one could kick "foouser " because of how commands are parsed.

Works As Intended

Rafael Ristovski

2013-07-29, 07:30 PM

2015-08-05, 07:16 AM

2013-07-29, 07:55 PM

0

2

Unconfirmed

Minecraft 1.6.2

-