I didn't realize that Creative mode players can use a hacked client to create malicious books. I thought this was fixed ages ago. This is a very useful plugin for anyone who allows Creative mode players on their server.
Books are a crucial part of minecraft and when they can be exploited, that's a very big issue. I'm happy theres guys like minoneer who dedicate their time to making plugins in bemeans of keeping minecraft's gameplay secure as a whole!
This plugin definitely does what it claims on the tin! it seems to work well, only reason its 4 stars instead of 5 is because it should have a bypass permission, or a way to add certain books to be ignored
Thanks for your feedback!
You can add a whitelist of commands / urls in the config, and also restrict it to certain worlds (e.g. your creative worlds).
There is intentionally no bypass permission, since those players with the most permissions can do the most damage when accidentally running a command.
Version: 1.1
5 because my prior complaint was addressed and fixed. I love the response and the detail in it, enlightening me on all that was needed for it to be updated.
While this plugin works, updates are slow and servers are left vulnerable to these exploits while waiting. This is frustrating as updating the plugin is trivial. Sadly, it imports the net.minecraft server classes of the specified version instead of using Java reflection to dynamically load the necessary classes. The core of the fix has not changed since 1.8.
Hi, updating the plugin to 1.16 was not trivial, as the underlying code changed significantly. This is also why using reflection is not a good solution - method names and signatures kept changing several times.
I took some time to completely rewrite it against the now extended Spigot API, which will significantly improve the maintainability and compatibility going forward :)
ill give it a 2 sense it doesn't make the server crash with jigaws servercrasher mode set to the tothedumpster but it still lags the crap out of it where it cant be playable
Preventing server crashes due to malicious packages is not the purpose of this plugin. Please do not review plugins on tasks they were never meant to do.
Version: 0.14
Absolutely brilliant. Supposedly the exploit is patched for some versions but why risk it? The included command allows it to be easily tested too which is a nice plus.
Excelent plugin! It worked like a charm. I was wondering if you could do the same for signs with commands too. I have a creative server and users started to create custom signs and for some reason the commands executed in them have op permission. It would be great to have this disabled and I didn't find anything about this on the internet