Minecraft Blogs / Article

Force-Op? A Myth Right? Not Anymore! And Your Server Could Be At Risk!

  • 5,805 views, 2 today
  • 10
  • 2
  • 31
Quaffle82's Avatar Quaffle82
Level 46 : Master Lad
115

Force-OP? It's only a Myth? A Rumor? Right?!



Not Anymore-
And Your Own Server Could Be At Risk

"How?" So many of you are asking yourselves, well, there is a new program out called Session Stealer.

Lets Cut Right to The Chase:

0. Table of Contents of this Blog:

I. What Is It?
  • Goes over What Session Stealer is
  • Goes over how you can be affected
  • Goes over how you "Session Can Be Stolen"

II. How do I defend Myself?
  • Goes over how you can defend yourself from Session Stealer
  • Introduces Plugin, NoCheat+

III. What Happens If You Fell For The Trick?
  • Goes Over how to potentially save your server
  • Goes Through the steps to calmly and easily take care of the mess you made by falling for the trick and not listening to this blog... :D

IV. Known Users
  • Everyone reported to me for attempting to use Session Stealer will be listed in this section

V. Test
  • I test out people's knowledge of the protection of their server and survey what they do


I. What is it?
Session Stealer is a program that creates a fake server. If you are the owner of your server you are a top target. Players have been known to try to lure you into their "server". They will tell you an ip, when you join it, you will get some type of error message, and boom, your session has just been stolen A.K.A Boom Goes The Dynamite

II. How Do I Defend Myself From This?
There are two methods. One, the easier, and safer, is to use a new plugin called NoCheat+, Or NoCheatPlus, not only will this plugin make it so people cannot do many other hacking features on your server, but it includes a feature to make it so players can only be op'ed from the console, thus making it impossible for people to be op'ed on your server through Session Stealer, although, NoCheat+ does not stop people being able to add other commands to their name in the permissions file, it only blocks the ForceOp. There is to block from that though, however it is not very easy. This brings us to our next part. The other way to prevent Session Stealer from attacking your server is to use common sense. If a player on your server says that you should check something out on theirs, don't do it. There are many messages people will use to try to lure you into their server. These can be seen in the later part of this blog "Common Excuses"

III. What Do I Do If I fell For The Trick?
If you join the "server" and get the message "Disconnected From Server" and then "Kicked From Server" or any other type of disconnect message, you must react quickly! Do the following steps to potentially save your server:
1. Go to the server console
2. Ban the player that told you about his "Server"
3. Undo any commands that he did

Common Excuses
Someone Stole Your Map
Can You Check Something On My Server?
(I will add more as I notice more being used)

IV. Known Users (People who tried to use it on you, please add their name in the comments with some sort of proof, then I will add their name here)(Also, just because their name is on here does not mean to completely ban them from every server, just keep in mind that they are lying about their server)

V. Test:
I am going to different servers and trying to see if they will join my "server." I have not set up session stealer and I do not plan to, I am merely seeing if they are educated about it and I am seeing what they will do about it.

I have tested 3 Servers:

1 Server(s) Banned Me For "Session Stealing"
2 Server(s) Tried to Join My Fake Server

33% Acceptance Rate
(Thats Not Good!)

If this helped you please diamond, favorite, like, retweet, and/or share this page so everyone can know how to defnd against this new program.

People to thank:
Mr_Blue_Sky: He told me about the NoCheat+ Features
Tags

5 Update Logs

Update #5 : by Quaffle82 06/09/2012 12:46:34 pmJun 9th, 2012

Updated Test Section
LOAD MORE LOGS

Create an account or sign in to comment.

1
07/15/2014 2:24 pm
Level 15 : Journeyman Engineer
minecraftian2424
minecraftian2424's Avatar
Then just don't have an offline server.
1
07/24/2014 1:59 pm
Level 46 : Master Lad
Quaffle82
Quaffle82's Avatar
Session Stealer, which was patched anyways, would work on online servers.
1
03/16/2014 9:28 am
Level 1 : New Explorer
WolfishFir008
WolfishFir008's Avatar
Dude! Please help! 
A guy named kryso15 is forceop'ing on my server and such,
Me and my friend are trying to make him send us it so we can send it to bukkit!
Please awnser quickly! 
And btw he made it himself.... He's a smart motherfucker
1
03/18/2014 5:40 pm
Level 46 : Master Lad
Quaffle82
Quaffle82's Avatar
It can't be a plugin if you didn't install it on to your server. Give me a list of your plugins, did you get all of them from bukkit?
1
03/26/2014 5:25 pm
Level 1 : New Explorer
WolfishFir008
WolfishFir008's Avatar
It's alright now c: 

I just ip-banned him and added him to the blacklist
1
09/08/2013 6:45 am
Level 1 : New Miner
AeraVII
AeraVII's Avatar
Entire town covered in lava.They claim to be from a website called teamruin.com.

rookytristan47
dck1998

reeszrb
youtuberland101
soxet6
soxey6
yourmomsrighttoe
bacon

These are the names I pulled from my ops list.
1
02/01/2016 8:02 pm
Level 2 : Apprentice Miner
[AoE]Blitz
[AoE]Blitz's Avatar
install worldguard - Go to Config

security:
deop-everyone-on-join: true
block-in-game-op-command: true

make sure those are set to true, enjoy
1
09/08/2013 4:09 pm
Level 46 : Master Lad
Quaffle82
Quaffle82's Avatar
This is the new force op, I see. Thank you.
1
08/30/2013 2:03 pm
Level 2 : Apprentice Crafter
waterlubber
waterlubber's Avatar
Well, although I know about this already, thanks for more info. Will be installing NoCheatPlus ASAP. Also, I think I have been ForceOpped another way on 1.6.2 AND IT WAS NOT SESSION STEALING! Do you know if there is ForceOp for 1.6.2 Bukkit? Please tell me.
1
08/31/2013 1:34 pm
Level 2 : Apprentice Crafter
waterlubber
waterlubber's Avatar
Figured it out. Was doing a rollback and tnt rolled back as well as the blocks, but the tnt was primed (?) and ghasts must have been spawned by the griefer. Is 1.6.2 still at risk by anything other than fake plugins?
Planet Minecraft

Website

© 2010 - 2024
www.planetminecraft.com

Welcome