Page 1 of 1

Potential Security Exploit: Minecraft

PostPosted: Thu Apr 12, 2012 12:22 am
by Zancarius
Here's the thread:

http://www.reddit.com/r/Minecraft/comme ... s_you_log/

I haven't read it in detail, but from what I've quickly glanced over (I'm about to go to bed!), it's possible for a malicious operator to snag your session identifier when you log in and use that to masquerade as your player on other servers. Be wary what servers you connect to, if you play Minecraft, at least until this is resolved. If you play on the 'goon server, be aware that this exploit could allow someone to use your privileges on our Minecraft instance if you connect to a malicious host!