Mojira Archive
MC-54970

Exploit during thunder - Hacked clients can retrieve players' coordinates

This exploit only occurs during thunderstorms.

While playing on an anarchy server, someone started to post in chat every players' coordinates he had access to, using a modified client that retrieves global data packets sent by the server.

During thunderstorms, the server sends a sound packet for thunder globally, that contains the coordinates of every thunder impact on active chunks where a player is. This allows to locate a player with a 512 blocks range precision (16x16 on all sides).

Some people are aware of this exploit and made a plug-in: http://www.curse.com/bukkit-plugins/minecraft/localized-thunder

This issue is particularly problematical for raid based servers where the coordinates have to remain secret in order to survive.

Fixed

Jordan

[Mojang] slicedlime

2014-05-10, 02:14 PM

2021-02-21, 03:47 AM

2020-06-04, 01:40 PM

0

4

Plausible

Important

Networking

mojang_internal_1

Minecraft 1.7.9 - 20w15aMinecraft 1.7.9, Minecraft 1.13.2, Minecraft 19w08b, Minecraft 19w09a, 1.14.4, 1.15.2, 20w15a

1.16 Pre-release 1