LuckPerms

LuckPerms

41.4k Downloads

Hackers Giving Themself Perms

Oraxenz opened this issue ยท 1 comments

commented

Description

This Isnt Support But Its To Report. People Are Getting Full Perms To Servers Using Luckperms
https://www.youtube.com/@MultiZen
This Isnt Advertising This Is A Report
Idk how they do it but its happened to me
Somehow they give themselfs a perm called *
Down Below Is What They First Did To get Access
[02:33:48] [luckperms-command-executor/INFO]: [LP] LOG > (Oraxenz) [U] (_cancello)
[02:33:48] [luckperms-command-executor/INFO]: [LP] LOG > permission set * true
The client they use is Aristois

Reproduction Steps

IDK

Expected Behaviour

Fix It

Server Details

Build #93

LuckPerms Version

v5.4.98

Logs and Configs

[02:33:48] [luckperms-command-executor/INFO]: [LP] LOG > (Oraxenz) [U] (_cancello)
[02:33:48] [luckperms-command-executor/INFO]: [LP] LOG > permission set * true

Extra Details

N/A

commented

Having the log file from when that happened is immensely useful, just sharing those two singular lines is next to useless, as there is no information that can be used to diagnose any potential issue.

That being said, every time this has been brought up in our discord server it ends up being an issue with server/network misconfiguration, offline mode, lack of security/proper firewall setting such as leaving ports open or letting the server accept connections outside of the proxy; allowing for UUID spoofing (players being able to log in as other players, incuding those with admin capabilities).

If you have a reason to believe that is not what happened, head over to our discord with the complete server log file to further diagnose the problem.