Mojira Archive
MC-80754

Non-Op players can get op items on servers

Introduction

I am sorry to say but this is only an assumption based on CrushedPixels video and on MC-75630. As far as I understand that it is based on the fact that while you are in creative, you can give yourself items (using mods) which have custom NBT data or aren't available in normal creative mode.

Assumed fix process:

  1. Searge removed feature to place signs with NBT data (for non-operators) and maybe same for command blocks (1.8.5)
  2. Searge removed ability of dispensers to place command blocks as this could exploit 1.8.5 (1.8.6)

The problem

As far as I know spawners were untouched so you can pretty sure still give yourself a spawner which spawns then signs or command blocks with custom NBT data.

And also these are other problems:

  • Player could get bow with negative damage causing (probably) server to crash
  • Player could get player skull without SkullOwner causing clients (and maybe server) to crash
  • Player could get spawner with ItemFrame or Painting causing server to crash
  • Player could get sword with extreme looting enchantment causing server to crash when hitting a mob
  • And probably much more...

Solution

Game Settings

Not everybody had the same experience playing Minecraft under different configurations, so we decided to remove all the graphical settings.

Even though that was the change log of the april fools update, I still believe that you have that opinion in some way, so here my question:

Why should a player with a modded Minecart client should be able to get for example his player head (without being op on a server), while a player with an unmodded client can't get his one?

My suggestion would be preventing non-operator players (in creative mode) from getting items which are not available by default in creative mode and are normally only available for players with operator rights.

This method would also allow the dispenser randomizer again.

Duplicate

Marcono1234

2015-05-27, 04:53 PM

2015-07-28, 07:39 PM

2015-05-27, 07:26 PM

0

1

Unconfirmed

administrator, nbt, operator, server

Minecraft 1.8.6

-