Potential Security Exploit: Minecraft
Posted: Thu Apr 12, 2012 12:22 am
Here's the thread:
http://www.reddit.com/r/Minecraft/comme ... s_you_log/
I haven't read it in detail, but from what I've quickly glanced over (I'm about to go to bed!), it's possible for a malicious operator to snag your session identifier when you log in and use that to masquerade as your player on other servers. Be wary what servers you connect to, if you play Minecraft, at least until this is resolved. If you play on the 'goon server, be aware that this exploit could allow someone to use your privileges on our Minecraft instance if you connect to a malicious host!
http://www.reddit.com/r/Minecraft/comme ... s_you_log/
I haven't read it in detail, but from what I've quickly glanced over (I'm about to go to bed!), it's possible for a malicious operator to snag your session identifier when you log in and use that to masquerade as your player on other servers. Be wary what servers you connect to, if you play Minecraft, at least until this is resolved. If you play on the 'goon server, be aware that this exploit could allow someone to use your privileges on our Minecraft instance if you connect to a malicious host!