Skip to content

Comment on Minecraft Migrated Account Session Vulnerability Security Advisoryparent

Comments

The gist is only 4 hours old but it was seen in the wild days ago: http://forums.bukkit.org/threads/a-player-named-notch-logged... http://www.reddit.com/r/admincraft/comments/wc2ey/notch_sess...

A different set of blackhats "Team Nodus Griefing" had it before the gist was up and fell into a honeypot (with packet capture to find the exploit) set by Mojang's Bukkit team and the reddit mods: http://www.reddit.com/r/Minecraft/comments/wl0zy/psa_exploit...

So I don't think this was meant to be responsible disclosure, it was more laying out the facts to get some internet cred ;)

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.