mojira.dev

Riking (Kane York)

Assigned

No issues.

Reported

MC-13441 RCON buffer overflow when more than 128 players are online Duplicate MC-13359 New inventory management adds level bypass to anvils. Duplicate MC-9922 Anvils fail to preserve high level enchants Works As Intended MC-5232 Unnecessary null-check in Item Rendering code Invalid

Comments

Oh look, something that isn't "this affects [insert newest version here]".

@Grum That is not an acceptable response.

In the following situation:

  • Fully vanilla server

  • No server administrators present (gee, maybe they're sleeping?)

An unprivileged client is able to mount a Layer 7 denial of service attack on other players simply by being on a server for a day. Staying on a server for 24 hours is, although uncommon, a perfectly valid action by a player, and should not be arbitrarily prohibited. I highly suggest you come up with a more robust solution than that.

EDIT: This also gives server owners a "<strike>crash command</strike>" "nonstandard kick command" (a pattern Mojang has fixed in the past) - simply copy one of the skin data files to another folder and send it to anyone you don't like. Boom, repeated client <strike>crashes</strike> disconnects.

It appears that this issue has resurfaced in 1.6. I would implore the developers to examine the diff in the sign renderer, as this has been corroberated by multiple server owners - areas with 200+ signs cause FPS drops in 1.6 compared to 1.5 when they were fine.

Gee, I thought I did a good job of searching for dupes. That other issue doesn't say "rcon" or "remote" at all 😞

@Mustek - I'm talking about improving the game for custom maps