Server hacked!

Status
This thread has been locked.

Keystirras

Supreme
Feedback score
3
Posts
112
Reactions
44
Resources
0
Hello guys, recently a server that i work for was hacked by a person named "Kneesnap" i don't know if you guys have heard of him before, or know his methods he was able to disquise his ip as Localhost so he could log in as anybody including the owner and i.

Command blocks are disabled, we use a Bungeecord and the config seems fine but its only the one server he had access to.

Anyone know the method he uses or how to prevent it from happening again? I had to whitelist the server so an answer would be appreciated soon! Thanks.
 
PebbleHost
High performance, consistent uptime and fast support. Minecraft hosting that just works.

Fire

Always DM me here before dealing via Discord.
Supreme
Feedback score
74
Posts
3,045
Reactions
1,745
Resources
0
Is this a dedicated server or a VPS?
 

Phineas

phineas.io
Premium
Feedback score
8
Posts
281
Reactions
124
Resources
0
Change your server.properties on each server to have the server-ip as 127.0.0.1 - he port scanned your network and since your MC instances are publicly bounded, he is unable to create a fake Bungee and add your servers to connect to.
 

Riv

Hip-Hop / Rap Enthusiast.
Premium
Feedback score
1
Posts
47
Reactions
23
Resources
0
I suggest getting someone to code a plugin where staff are required to setup a password, so they have to enter it everytime they join the server.
 

mattrick

Web Designer & Developer
Premium
Feedback score
0
Posts
105
Reactions
62
Resources
0
I suggest getting someone to code a plugin where staff are required to setup a password, so they have to enter it everytime they join the server.
Plugins like that already exist, except using 2FA which will probably be more secure anyway. There's also a few password plugins, but I'd recommend 2FA still.
 

Derive

Miragon Owner | Developer
Premium
Feedback score
1
Posts
186
Reactions
55
Resources
0
It has to do with your connected servers being offline so he was able to force auth in a alt mc launcher and then logged to the servers not through the bungee.
 

23jd83yhs208d

Deactivated
Feedback score
54
Posts
538
Reactions
701
Resources
0
This happened to me a few times unfortunately. Fortunately, we fixed all our issues. Let me just tell you its a pain to setup and fix. It will cost you some $
 
Status
This thread has been locked.
Top