LimboAuth icon indicating copy to clipboard operation
LimboAuth copied to clipboard

Exploit!!!

Open SpigotRCE opened this issue 1 year ago • 4 comments

Describe the bug Login bypass.

To Reproduce Steps to reproduce the behavior:

  1. Setup auto reconnect
  2. Afk trying to join thru owner account
  3. When limbo reloads, in that time it would let player log in

Expected behavior Any login plugin should not reload when server is running

Screenshots No screenshots, but a major server named GreenMC was griefed using this exploit

Server Info (please complete the following information):

  • All Limbo plugins versions:

SpigotRCE avatar Jul 15 '24 14:07 SpigotRCE

Are you sure that it is caused by reloads? It seems that i can't reproduce this issue locally with the latest software versions.

UserNugget avatar Jul 15 '24 15:07 UserNugget

Yes

SpigotRCE avatar Jul 19 '24 05:07 SpigotRCE

Oh, is there any additional information like that plugin versions/client version/account type (offline-mode or online-mode) was used?

UserNugget avatar Jul 19 '24 09:07 UserNugget

account type online mode , plugin version latest, client version any

SpigotRCE avatar Aug 10 '24 16:08 SpigotRCE

Actual?

purpurcof avatar Nov 07 '25 13:11 purpurcof

I forgot to test it and never bothered about it cause never happened with me again. The original server where it happened shut down so I wasn't able to log plugin events in time.

SpigotRCE avatar Nov 07 '25 15:11 SpigotRCE