LuckPerms

LuckPerms

41.4k Downloads

If UUID does not match, remove all perms feature

Kainzo opened this issue ยท 6 comments

commented

Greetings!
I recently had a hacker on my server somehow bypass UUID auth, can we have a toggle feature to remove all permissions if the UUID doesnt match with the original UUID the user used to log in?

commented

Is this cracked server? (offline mode)

commented

I mean it's your own fault/risk when the server is in offline/cracked mode.
Because there is virtually no real method to fake a UUID with a cracked account on a online server, since the account will be checked on login, if the UUID is a legit one (and probs even if the name is the same)

commented

get a better Auth plugin, or code one yourself (thats what I did for mine ;p)

commented

Is this cracked server? (offline mode)

obv he does

commented

do they realize thats what can happen in offline mode?

commented

As I mentioned in Discord, I think this would be better handled by an authentication / 2fa plugin.

Thanks for the suggestion, but on this occasion I don't think it's something I'd like to add to the plugin.