Mojira Archive
MC-33069

Man in the middle attack in 13w39b

With the new session server the serverID is no longer a sha1 hash with the public key and shared secret allowing an MITM attack to be preformed. See https://gist.github.com/thinkofdeath/d0fa2997886182b6a5ba for an example (in Go)

Fixed

Thinkofdeath

[Mojang] Grum (Erik Broes)

2013-09-28, 05:04 PM

2015-08-05, 07:27 AM

2013-09-29, 12:22 PM

0

2

Unconfirmed

security, session

Minecraft 13w39b

Minecraft 13w41a