Bukkit security issues?!?

Discussion in 'Bukkit Help' started by BigBlueGER, Jan 17, 2011.

Thread Status:
Not open for further replies.
  1. Offline

    BigBlueGER

    Hey,

    I'm running a minecraft server fine since around 2 weeks. I was using the hmod whitelist and just gave the IP to people that are whitelisted. (Including me 5)
    Now - since saturday evening - I run CraftBukkit. Since then already 3 different people tried to join. (I'm using Whitelist plugin).
    2 of them got auto-kicked but 1 produced some error...
    Code:
    2011-01-17 16:12:33 [INFO] codi98 [/84.165.43.221:13637] lost connection
    java.io.IOException: Server returned HTTP response code: 504 for URL: http://www.minecraft.net/game/checkserver.jsp?user=codi98&serverId=90917fb9070cae0d
            at sun.net.www.protocol.http.HttpURLConnection.getInputStream(HttpURLConnection.java:1261)
            at java.net.URL.openStream(URL.java:1027)
            at net.minecraft.server.ThreadLoginVerifier.run(SourceFile:96)
    But even if it seems that they got autokicked, THERE ARE 2 NEW BUILDINGS ON THE MAP.
    I checked it, from the whitelisted people I was the last one to leave yesterday and the first one to come back today.
    So someone must have gotton access to the server and built a floating isle with water sources and a real looking 'Minecraft'-Font out of Cobblestone. Might even be a .schematic, too.
    Now there are 2 questions:
    1.) How the hell did they got the IP?
    and
    2.) How did they come by the whitelist?
    I would be glad if someone could answer me.
    Greetings
     
  2. Offline

    nichiatu

    You need to talk to the creator of the whitelist plugin for this one. It's not a security issue with bukkit itself, the plugin is the issue.
     
Thread Status:
Not open for further replies.

Share This Page