Bukkit Forums

Oct
21
by Jadedcat at 4:50 PM
(32,548 Views / 0 Likes)
87 Comments
Recently a plugin named Magix was uploaded to the site. This plugin had an exploit in it wherein an image file was used to add extra javascript beyond the code in the plugin itself. That could allow for arbitrary opping on a server. Multiple reviews of the project by our staff failed to catch it, and for that mistake we're very sorry.

We have adapted our review process to look for this kind of exploit in the future. Unfortunately no matter how well we review plugins people will try and find new creative ways to add malicious content.

The plugin has been removed and the author banned.

If you downloaded and are using Magix, please remove it from your server.

Again we apologize for missing the exploit when checking the code.
Sep
26
by Jadedcat at 8:35 AM
(40,572 Views / 10 Likes)
66 Comments
There are any number of licenses you can pick for a plugin. GPL amongst others allows other people to copy and redistribute your code under certain conditions. Most noticeably the requirement that any fork also be GPL. Other open source licenses have other requirements.

If you pick the GPL license or any other open source license for your plugin and someone clones your plugin it is not a copyright violation as long as they follow the requirements.

As it pertains to plugins uploaded to BukkitDev or Curse, things are slightly different.

We feel the spirit of open source licenses is to allow for continuing an abandoned project, or forking and creating a new project based on the original. The purpose is not to allow anyone and everyone to create a straight 1-1 clone of actively developed plugins.

On BukkitDev we will decline to host simple clones of existing plugins, regardless of licensing legalities. If you are aware of a straight 1-1 clone of an existing plugin please...
Sep
25
by Kaelten at 2:07 PM
(73,265 Views / 0 Likes)
139 Comments
Hi Everyone, my name is Kaelten.

Not many of you know me. I've been an admin on the Forum for several years, but until recently I've been inactive. I am also a Curse staff member, and the project lead over CurseForge.

Everyone knows there's been a lot of changes and shakeups in the community over the last several weeks. These together have left a feeling of unease with many users.

Let me start by saying that Bukkit.org and Bukkit Dev will stay online for the foreseeable future.

The future of CraftBukkit distribution lies squarely (or with Minecraft is it blockly?) with Wolvereness and Mojang. As things stand right now CraftBukkit will not be available from dl.bukkit.org.

Staffing Changes

With all the changes most of the staff for Bukkit.org have stepped down. Many of the former staff posted farewells. To archive these in perpetuity we've created a forum dedicated to staff member farewells and...
Sep
06
by mbaxter at 2:47 PM
(127,843 Views / 53 Likes)
227 Comments
Over the last two weeks, the Bukkit community has experienced some of the most substantial changes to the project since its inception. Multiple members of the staff, for various reasons, have chosen to resign. These staff are listed below, with links to their goodbye posts. Users on multiple teams are placed into just one by preference.

The Bukkit Administrators
lukegb
EvilSeph - Honorable mention: Removed without chance to say goodbye
mbaxter
TnT [tnt]

The Bukkit Team
Amaranth
evilmidget38
feildmaster

The Bukkit Pull-Request Handlers/Bleeding...