dynmap icon indicating copy to clipboard operation
dynmap copied to clipboard

Harassment Campaign Using dynmap

Open MonkeySaint opened this issue 1 year ago • 46 comments

Dear the dynmap team There is currently a harassment campaign against the group SSI and the people Funtimes909 aka Amy, damcraftde aka Dami.

The group doing this used to be advertising their Discord server by spamming servers using your chat! After their Discord server got terminated, they realized they could enact a personal vendetta. This doesn't just affect your users but also many other people. This would be fixed by enabling require-player-login-ip by default, disabling chat or adding any kind of security to the chat so harassment bots cannot keep spamming servers.

Please look at #4027 which enables require-player-login-ip by default. At least as a temporary fix until there is some security added to the chat of dynmap

Thank you, MonkeySaint

image image

MonkeySaint avatar Nov 26 '24 06:11 MonkeySaint

I can confirm this is an issue, me and dam have been harassed a lot today, maybe more people as well

Funtimes909 avatar Nov 26 '24 06:11 Funtimes909

Can confirm too. This is like the third time this is being done against me, happened multiple months ago already.

lina-x64 avatar Nov 26 '24 06:11 lina-x64

Yeah, can confirm that this currently being used and has been used to harass DAM and the members of Server Scanning Inc.

Paddyk45 avatar Nov 26 '24 06:11 Paddyk45

Question to those who have experience from this. Do they do actually anything or it this just spamming? And is there something I could do to not get those messages? I had been also harassed with this this morning.

MrJuuq avatar Nov 26 '24 07:11 MrJuuq

They use scanning software to find servers with this config option set wrong where they can spam the servers console with messages, and usually spam links to people they do not like, telling the owners to go and harass people from whatever discord server thats completely unreleated, in attempt to get the owners of the discord server and other members harassed for something they never did

Funtimes909 avatar Nov 26 '24 07:11 Funtimes909

@MrJuuq

Question to those who have experience from this. Do they do actually anything or it this just spamming? And is there something I could do to not get those messages? I had been also harassed with this this morning.

open the dynmap config and change the setting

 - class: org.dynmap.SimpleWebChatComponent
    allowchat: true
    # If true, web UI users can supply name for chat using 'playername' URL parameter.  'trustclientname' must also be set true.

allowchat to "false"

lina-x64 avatar Nov 26 '24 07:11 lina-x64

@DAMcraft

Is there any other ways to do that. I mean, I wouldn't necessarily want to disable chat on the dynmap. If I remember correct, was there a some sort of auth system for it? If not Then i guess i have to disable it for now :(

MrJuuq avatar Nov 26 '24 07:11 MrJuuq

Yeah, this is a significant security issue

Hyyeve avatar Nov 26 '24 10:11 Hyyeve

Agreed. This is a pretty big issue.

Atom1cByte avatar Nov 26 '24 11:11 Atom1cByte

Is there any other ways to do that. I mean, I wouldn't necessarily want to disable chat on the dynmap. If I remember correct, was there a some sort of auth system for it? If not Then i guess i have to disable it for now :(

@MrJuuq You can re-enable chat and under org.dynmap.InternalClientUpdateComponent, set require-player-login-ip to true.

Semisol avatar Nov 26 '24 11:11 Semisol

Whoever enabled the chat functionality by default, and allow anonymous people spamming it, was drunk, in my opinion.

0skar2 avatar Nov 26 '24 11:11 0skar2

It shouldnt take place in ANY software. Even if they do not want to disable chat by default, they should at least implement authentication, so only people trusted by the server owner can chat there, and view messages

0skar2 avatar Nov 26 '24 11:11 0skar2

I agree, sending messages without authentication should not have been a default option. I have been a witness of this on both the server owner part and as a moderator of Funtimes' community.

Nucceteere avatar Nov 26 '24 13:11 Nucceteere

This simple misconfiguration has caused several issues in many communities, such as moderator overload, a risk of having the server terminated via mass-report, and spamming welcome messages (and accompanying wave stickers, in some circumstances) in chats of these communities as well.

No level of harassment should be tolerated, and as such, require-player-login-ip should be set to true by default.

imeesa avatar Nov 26 '24 14:11 imeesa

Pretty big issue. More sane and secure defaults should really be in order here to stop this from happening again in the future, when the feature is inevitably targeted once more.

RestartB avatar Nov 26 '24 15:11 RestartB

It should be the responsibility of the developer of a software to provide safe default options.

Nucceteere avatar Nov 26 '24 17:11 Nucceteere

This should be closed as it is the responsibility of the end user to lock down Dynmap appropriately.

most users don't change the defaults (unless instructed/forced to), so keeping the defaults insecure by default is an issue on the developer's side

magmaus3 avatar Nov 26 '24 17:11 magmaus3

i want to confirm this is an issue

kittenvr avatar Nov 26 '24 17:11 kittenvr

It should be the responsibility of the developer of a software to provide safe default options.

Dynmap is indirectly enabling these kinds of smear campaigns by refusing to change the defaults despite the numerous cases of the feature in question being used in a malicious way

crosby-moe avatar Nov 26 '24 18:11 crosby-moe

I also think this should be changed, I've seen many people be a victim of this and it hurts our community

nikolan123 avatar Nov 26 '24 18:11 nikolan123

I also think this should be changed

thepotatolover avatar Nov 26 '24 19:11 thepotatolover

This should be closed as it is the responsibility of the end user to lock down Dynmap appropriately.

Switching to bluemap rn

0skar2 avatar Nov 26 '24 19:11 0skar2

Please do not clutter the issue. A lot of people also get notifications via email. It's not fair that we fill their inboxes.

Nucceteere avatar Nov 26 '24 19:11 Nucceteere

Please do not clutter the issue. A lot of people also get notifications via email. It's not fair that we fill their inboxes.

They can unsubscribe

kittenvr avatar Nov 26 '24 20:11 kittenvr

I'd also like to see it changed.

tufo09 avatar Nov 26 '24 21:11 tufo09

yeah.. seems like the devs behind this arent really listening im switching to bluemap as we speak rn

Northernside avatar Nov 26 '24 22:11 Northernside

Another time I am reminded why Bluemap is so much better

coinflipcoder avatar Nov 26 '24 22:11 coinflipcoder

Please do not clutter the issue. A lot of people also get notifications via email. It's not fair that we fill their inboxes.

Users can unsubscribe if they wish. That doesn't mean users can't state new insights into why this should be disabled.

imeesa avatar Nov 26 '24 22:11 imeesa

Please do not clutter the issue. A lot of people also get notifications via email. It's not fair that we fill their inboxes.

If the maintainers wish to not hear about those affected, they can fix the issue.

And as for cluttering the inboxes of those who are simply replying to this thread, that is unfortunate but I don’t believe the maintainers of dynmap will do anything about this issue unless we make our voices heard.

crosby-moe avatar Nov 26 '24 22:11 crosby-moe

migrated everything to bluemap and my ingame chat is now super clean - no more crypto scam advertisements which appeared when i was using dynmap :D

Northernside avatar Nov 26 '24 22:11 Northernside