MineColonies

MineColonies

59M Downloads

[BUG] Minecolonies Builder allows you to smuggle items into servers (was previously fixed, however in a new iteration).

LinkTheLinker opened this issue ยท 5 comments

commented

Is there an existing issue for this?

  • I have searched the existing issues.

Are you using the latest MineColonies Version?

  • I am running the latest beta/release version of MineColonies for my Minecraft version.
    I am also running the latest versions of other mods that are part of my problem.

Did you check on the Wiki? or ask on Discord?

  • I checked the MineColonies Wiki and made sure my issue is not covered there. Or I was sent from discord to open an issue here.

What were you playing at the time? Were you able to reproduce it in both settings?

  • Single Player
  • Multi Player

Minecraft Version

1.20

MineColonies Version

1.1.653-1.20.1-snapshot-universal

Structurize Version

1.20.1-1.0.755-beta

Related Mods and their Versions

  1. Forge 1.20.1 - 47.2.0
  2. blockui-1.20.1-1.0.186-BETA
  3. donum_ornamentum-1.20-1.0.203-beta-universal
  4. multipiston-1.20-1.2.43-RELEASE
  5. towntalk-1.20.1-1.1.0

Current Behavior

Link to Video: https://drive.google.com/file/d/1-FzQSmRp0suy__M3MGYC60IAB3WQz2D4/view?usp=sharing

The video shows that the items in the Minecart with Hopper bug that I had previously reported has a 2nd iteration, where it doesn't process shulker box inventories correctly. While Bedrock is used in the video, creative items or items with Custom NBT data can be "smuggled" into multiplayer servers. I have tested this on an actual server running an earlier version of Minecolonies with great success. Furthermore, this can also be executed via Minecart with Chest and Boats with Chests.

Expected Behavior

What should happen is when making the scan of the Minecart with Hopper is it should show the resources needed for the items that are contained in the inventory (including the shulker box). Furthermore, the scan should not allow the smuggling of illegal items onto servers.

Reproduction Steps

Boot up a modpack that purely has the Minecolonies mod with the other mods required to boot up Minecolonies or even a modpack with Minecolonies like ATM 9.

Start a new world with Creative mode and Allow Cheats set to ON.

Get a town hall block, builder's hut block, build tool, scan tool, 64 rails, a Minecart with Hopper and the desired item(s) you want to "smuggle" onto a server.

Place the rail, Minecart with Hopper and put the shulker box with the desired item(s) into the Hopper. Then, create a scan with the Scan tool.

Build the town hall with the build tool, and press "assign to builder".

Build the builder's hut with the build tool, and press "assign to builder".

Once a citizen is assigned a builder, build the scan created in step 4 and press "assign to builder".

Give the builder a stack of rails, a Minecart with Hopper, and an empty Shulker Box.

The builder will build the Minecart with Hopper and you will find the shulker with the items you put into into it in the build.

Logs

https://gist.github.com/LinkTheLinker/ca8688ccdb76d234f98ba7f7143bfd3e

Anything else?

Note: This also works in the release versions of Minecolonies as well.

Footer


Viewers

  • Add a thumbs-up to the bug report if you are also affected. This helps the bug report become more visible to the team and doesn't clutter the comments.
  • Add a comment if you have any insights or background information that isn't already part of the conversation.
commented

From the description I'm not entirely sure. Is it necessary to have the items in the shulkerbox in another inventory. Or does any item in an entity inventory work?

commented

It is necessary to have the items in the shulker box to work. The previous iteration of the exploit never required them.

commented

So this is only boats and minecarts with chests (entities essentially) ? Or are shulkerboxes also still a problem?

commented

This is essentially with entities, as with the previous bug I reported, but shulker boxes allow a similar exploit when in inventories scanned in Minecolonies.

commented

This is the older iteration of the bug I am referring to: ldtteam/Structurize#641