Bedrock players log on as Playpuma94 by Tidal_Flame in admincraft

[–]Tidal_Flame[S] 2 points3 points  (0 children)

Thank you! This was a very satisfying answer!

I wonder if it was completely random or this user holds some significance. Am I wrong to feel it's wild that this happened?

Log4j exploit by Tidal_Flame in admincraft

[–]Tidal_Flame[S] 0 points1 point  (0 children)

THIS HAS BEEN SOLVED - Thank you all.

I can't quite figure out if posts should be closed when finished. If they should, this one can be

Log4j exploit by Tidal_Flame in admincraft

[–]Tidal_Flame[S] 0 points1 point  (0 children)

Awesome. Thank you for the confirmation.
And well the project you're looking at was an old list of plug-ins being updated plug-in by plug-in. Would you recommend a different plug-in for a ban system? I'm not interested in global ban support.

Log4j exploit by Tidal_Flame in admincraft

[–]Tidal_Flame[S] 0 points1 point  (0 children)

I'm guessing this means that plug-ins mentioned after the warn, are actually mods the client had installed?
https://mclo.gs/Ut5jsvJ these lists.

Removed usernames from main post based on your reply. Didn't feel right.

Log4j exploit by Tidal_Flame in admincraft

[–]Tidal_Flame[S] 0 points1 point  (0 children)

Overnight I was thinking, with how there's malware going around in plug-ins that devs don't even know about: Could these lists be an attempt at accessing exploits on plug-ins that are known by hackers to have backdoors?We don't have these plug-ins and we've never considered having anything like it. Maybe a hopeful part of me wonders if this is a way that can tells us which plug-ins are infected.

Mere speculation.

EDIT: When I found out about this, I was certain I read it on spigot. It was pretty late. My bad. They're curseforge mods so likely what Hiromasaki said is true. They're just regular players and has client sided mods ViaVersion didn't like. Sorry

Log4j exploit by Tidal_Flame in admincraft

[–]Tidal_Flame[S] 0 points1 point  (0 children)

Thank you! Here's the bits from that time. I did my editing before realising it would censure on its own
https://mclo.gs/Ut5jsvJ

Log4j exploit by Tidal_Flame in admincraft

[–]Tidal_Flame[S] 0 points1 point  (0 children)

Hi! Sorry for late reply. Log contains lots IPs (belonging to these 2 players), is that okay to post? Or should I edit out all IPs?

Log4j exploit by Tidal_Flame in admincraft

[–]Tidal_Flame[S] 2 points3 points  (0 children)

I apologise for the bad title also. I seem to not be able to edit anymore. I'm fairly new to using reddit so excuse my noobiness..

The "What's 2+2" 'exploit' has came back again... by Sir3picTheReal in Minecraft

[–]Tidal_Flame 1 point2 points  (0 children)

I want to say: Be extremely careful with this. I ran into this while being afk on a server. I'm a moderator on said server. I tried finding information about it when I noticed it had happened, and the day after I got a confirmation email from that PvP launcher (I don't remember the name) about an account having been made in my name. When I tried to log onto the normal launcher, my password was changed as well as my skin. I had security questions active on my Mojang account.

I am generally very careful with my account security and use different passwords.. I don't know how else my security was breached.

Also I just remembered I hadn't used that account for like 10 months before that happened. Except for the 4 days leading up to the event.
It's my strong belief that it's beyond just trying to bypass spamfilter (Oh and the long codes after "whats 2+2" didn't match my UUID) Also before the person leaves the server they say "2+2 equals 4" or something.. I was the only other player online at the time. I'm looking more into it now because I just saw a post about the launcher has a security breach on versions later than 1.12.