1

Two malicious plugins found on BukkitDev

aman207's Avatar aman2079/14/13 5:59 pm
1 emeralds 558 6
9/14/2013 8:07 pm
aman207's Avatar aman207
In case you guys don't know, the dev bukkit staff found two plugins with malicious code.

NanoGuard Anticheat and Infinite Dispenser

http://forums.bukkit.org/threads/psa-ma ... er.174108/

You should remove the plugins if you have them.

From the looks of it, it looks like it auto DDoS'd your server from the inside.
Posted by aman207's Avatar
aman207
Level 40 : Master Cake
50

Create an account or sign in to comment.

6

1
09/14/2013 7:56 pm
Level 47 : Master Button Pusher
Leeberator
Leeberator's Avatar
It's not the server DDoSing itself (that would be a DoS anyway, even if it could clog its own network connection). The malicious code in InfiniteDispensers enabled the plugin to essentially use each server it was installed on to launch a DoS attack on something, thereby making an attack by them a DDoS.
1
09/14/2013 8:07 pm
Level 40 : Master Cake
aman207
aman207's Avatar
Yeah that XD
1
09/14/2013 6:16 pm
Level 1 : New Mage
KingKrafter
KingKrafter's Avatar
Thanks! I was actually going to get NanoGuard Anticheat -_-

Here is the actual post


it has come to our attention that the plugins "NanoGuard Anticheat" and "InfiniteDispenser" have been distributing potentially malicious code hidden within their update process. We urge all server admins running these plugins or who have run these plugins to read this PSA carefully and follow the advice given immediately.

We strongly advise all server admins to cease using these plugins immediately:
NanoGuard Anticheat (Default file name: NanoGuardJAR.jar or similar)
InfiniteDispenser (Default file name: InfiniteDispenser-3.2.jar or similar)
As a general precaution, we strongly recommend that all server admins perform a full examination of their server, keeping an eye out for unknown plugins or suspicious behaviour - as is proper on a periodic basis. We also would like to remind server admins to avoid running anything with root or admin privileges without taking the proper precautions to safeguard against the security risks it poses.
1
09/14/2013 6:13 pm
Level 25 : Expert Network
RiotShielder
RiotShielder's Avatar
Other than the DDoS part, you're correct.
1
09/14/2013 7:05 pm
Level 40 : Master Cake
aman207
aman207's Avatar
If you continue to read on in the thread, some users talk about DDoS
1
09/14/2013 6:04 pm
Level 13 : Journeyman Pokemon
Lax_People
Lax_People's Avatar
Thanks for warning us server owners
Planet Minecraft

Website

© 2010 - 2024
www.planetminecraft.com

Welcome