Discussion started by InPaniCsz, May 26, 2015.

    So, recently I've started my server.
    And I had a thing to people suggest things with books and then they dropped a book in the chest and the staff saw it.
    So, one staff guy said me a guy got OP with a book and had a Link in it.
    But he cleared the book, so I'm worry a lot of people now have the OP.
    The worst is that a random guy knows all ours plugins saying he is the owner of them, and he suddenly has OP, i don't know if he is lying, but well that doesn't come in here.
    I need a fix please for this issue

    List your plugins, deop all, and update to the latest version(1.8.6) of craftbukkit or spigot.

    1.8.6 fixed some Force-Op bugs. You could have a malicious plugin, so mind listing your plugins?
    Ok I will post it.

    I removed the list, because I think a found a fix

    I think I found a fix, this one:

    Yes it's working, my friend the hack and it's working :D

    1) Please don't spam, there is an edit button by the date.
    2) Please mark this thread as solved, because it is, right?
    You found a fix for one exploit, but there are others in 1.8 - 1.8.5. They involve signs, command blocks, and apparently dispensers. So you can still have people exploiting security holes.

    Here's an example:

    The only fix is to use 1.8.6 (applies to vanilla, CraftBukkit, or Spigot).
    As I see you need creative to do those with signs, and my server doesn't have creative!
    bwfcwalshy Retired Staff

    @InPaniCsz I believe you could get creative using methods like that, this was a big exploit that Mojang should have tested more for really. Anyhow, it should be fixed in 1.8.6 please update your server. If the issue persists all I can suggest is that you report it to Mojang.
