Ok this is the second topic today. I have a problem or bug(or whatever it is). This "bug" allowes the person to access minecraft code modify it and hack the server remotly. Ok here is a explanation on how I found it: Well everyone knows I am a computercraft hacking geek so I decided what if I make a program to remotly access any server and take full control of a program. So I did that I was trying to well do the following:
- Error computercraft code to go to console - FAIL
- Drop out the bios and redirect it to direct console code - FAIL
- Turtle paradox glitch(well known of CCHaxForums) got close crashed server though(alot explaining to do to the owner) - FAIL
- Redirect all code through java into the console - FAIL
- Java auto key presser? - FAIL
Finally though I tried to use the minecraft protocol to connect and handshake with a java program. Then it was a matter of redirecting everything through a packet listener so I can get CC responses and I got this wierd packet wich is actually for the screen. This packet is so if you and your friend are looking on the same screen in the computer you can see what he is typing. That is used by a java bind to Minecraft Server Protocol automaticlly added by forge. Ok so at that point I went awsome I have a binded program, I have captured packet and I have a packet modifier. So I just used the packet modifier to make a packet that will put a auto key presser on there. So after that all I did was automate the process by adding prgramming it into my binded java app. I turned on the CC pc because it needs that to run I turned on the java program and PWNED! Full unlimited access to the console through the CC pc.
Now I am pretty sure you aren't supposed to do that in computercraft. So any mods and admins can please explain? The program used for this exploit will not be released!
Details of what I use:
Java: 7
Computercraft: 1.61
Forge: 9.11.1.965
Server owner status: Wants to kill me.
Chance of working: 80%
Requirements: Same java, forge, computercraft version as the server is using!
My reaction to this: *faceplam*
Estimation time: 2min
Edited by CCGrimHaxor, 17 June 2014 - 02:35 PM.