1. The forums will be archived and moved to a read only mode in about 2 weeks (mid march).

Not accurate name system

Discussion in 'Help' started by minijaham, Jan 31, 2021.

  1. minijaham

    minijaham Skeleton

    Messages:
    801
    GitHub:
    minijaham
    Yeah, everything logs in strtolower, even ops and bans. People can simply bypass anything if one letter in their username is changed.

    My ign is minijaham, and I had op. If someone with name Minijaham came on, they would have op as well. What the actual fu*k is this? My server was griefed and everyone had access to op. How do you fix this?
     
  2. mmm545

    mmm545 Baby Zombie

    Messages:
    152
    GitHub:
    mmm545
    you've shared this exploit to people on github and now on the forums, now more people will try to grief servers including yours
     
  3. minijaham

    minijaham Skeleton

    Messages:
    801
    GitHub:
    minijaham
    Isn’t it partially on PMMP’s development team as well?
    The issue’s been already known and the team was aware of it. Even simple plugins can solve it but they haven’t done anything even though it seems like “security” is important to them.
     
  4. ethaniccc

    ethaniccc Baby Zombie

    Messages:
    189
    GitHub:
    ethaniccc
    Sharing an exploit on a public forum instead of PMMP's secvun email is an absolutely stupid idea. After someone shared this exploit, it spread like wildfire and now servers are getting shitted on. People are even selling accounts related to this exploit. This is exactly why secvuns should be kept private until fixed.
     
  5. minijaham

    minijaham Skeleton

    Messages:
    801
    GitHub:
    minijaham
    This indeed is as of now I think about it. Too bad though, the issue’s been around for ages, and I blame both Microsoft and PMMP dev team’s incompetence about the situation/issue.
     
  6. ethaniccc

    ethaniccc Baby Zombie

    Messages:
    189
    GitHub:
    ethaniccc
    If you can find a better solution to fix this problem without extending the server's functionallity (etc adding a password system), go ahead. The PMMP dev team (which litteraly almost only Dylan), is not incompetent and is already trying to find a solution while not using those types of solution, so you can duck off with the 'incompetence of the PMMP dev team'
     
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.