EMERGANCY bug/security exploit that could cost some servers pretty big!
Hi, I'm the owner of a medium sized server network (40-60 players), and we have had a pretty good anticheat to catch hackers, until 1.8, where several non-hacking players began to become banned for hacking, which they were not. We use two popular plugins, NoCheatPlus and AntiAura (http://www.spigotmc.org/resources/antiaura-hack-blocker-v5-0.1368/). This is not a flaw of their plugins, but I have contacted them to see if they could help, but I feel as this is a security exploit, which I will explain a bit later. So anyways my server went into emergency maintenance because of this and is still currently down. I gathered my entire staff team to figure this out, and everything was working fine until my staff found this new 1.8 client called "Kryptonaite". Which included a hack called "Fake Hacker". This hack makes it so it apears that the other player is hacking. I didn't believe it until they did it to me (They were hacking and I wasn't) so NoCheatPlus started stating that I was hacking, which I was not. Then AntiAura(Which REQUIRES you to hit mobs behind, and above you to be kicked/banned) went off and banned me for hacks, while the other person was hacking, and I was not. I feel that is not a plugin error and is a security exploit because antiaura requires you to hit fake NPCS and fake mobs that are behind you and above you, so if a client which is installed on another users minecraft is forcing you to hit something then this must be a security exploit. This is an EMERGANCY and my server cannot come back up until this is fixed. This was tested on 1.8.3 but likely could work on other versions. Sincerly, - IHazSugar
2015-04-25, 05:01 AM
2015-05-19, 09:07 AM
2015-04-25, 05:16 AM
0
2
-