“player tracking” vulnerability/exploit

today in my server chat a new user just after logging in said ”lmfao player tracking isn’t fixed”, but i really can’t figure out what he meant, should i be worried?
39 Replies
Admincraft Meta
Thanks for asking your question!
Make sure to provide as much helpful information as possible such as logs/what you tried and what your exact issue is
Make sure to mark solved when issue is solved!!!
/close !close !solved !answered
Requested by filyarduino#0
ProGamingDk
ProGamingDk2y ago
there was a bee coordinate "exploit" if u had bee hives sold on ah but dont think its that
filyarduino
filyarduinoOP2y ago
i don’t have either ah or shop thanks for the suggestion
QarthO
QarthO2y ago
i remember a couple years back, people on hacked clients can attempt to break blocks SUPER far away (thousands of blocks) . and they would get a different response if the chunk was unloaded/or not. so then they can deduce if a player is in the chunk (if its loaded). then when people log on/off can figure out, ok when this player logs on, i can fail to break a block in this chunk... but this was like super heavily engineered and i dont think a random player would be doing this on a random server (not sure if its been patched by minecraft, or if paper does) my guess is maybe you have a plugin on ur server that has an exploit? like map plugin and can see players? idk
filyarduino
filyarduinoOP2y ago
thanks for the tips but i don’t have any map/tracking plugins, only basic stuff
QarthO
QarthO2y ago
map was just an example, what plugins do you have? the player could also just be pulling ur leg, and making u freakout over nothing
filyarduino
filyarduinoOP2y ago
essentialsx, authme, wildrtp, vulcan, skinsrestorer, discordsrv, viewdistancetweaks, viaversions, viabackwards and geyser with floodgate yea it might be that i hope so thanks for your time and tips btw, i’ll wait a bit to see if anyone else has got an idea then i’ll mark as closed
QarthO
QarthO2y ago
just curious, what plugins do you have?
filyarduino
filyarduinoOP2y ago
these ones
QarthO
QarthO2y ago
oh mb, compltely missed that yeah i dont think any of those would be giving up player coords well actually, i think i know what it mite be since ur using authme, my guess is ur in offlinemode, players can just log in as someone else and get their coords
filyarduino
filyarduinoOP2y ago
ah yes
QarthO
QarthO2y ago
!offline
QarthO
QarthO2y ago
turn server to online and no issue will occur
filyarduino
filyarduinoOP2y ago
how didn’t i think of that? do you know if there is a workaround that lets me keep offline mode? like a plugin?
QarthO
QarthO2y ago
ur not gonna get any support here from running an offline server we dont support any piracy
filyarduino
filyarduinoOP2y ago
it’s for the bedrock players
QarthO
QarthO2y ago
u have floodgate bedrock players can log in with online-mode
filyarduino
filyarduinoOP2y ago
but thank you so much anyways ok i’ll look into that have a nice day, bye
ProGamingDk
ProGamingDk2y ago
Why does so many people think Geyser requires offline mode Where do yall read that
filyarduino
filyarduinoOP2y ago
i dunno, but now i’ll try
QarthO
QarthO2y ago
also.. every bedrock player has java now, and every java player has bedrock with floodgate, you can connect the accounts so there never any need for any authentication, just use geysers/mojangs literally tho, im curious why its so common
filyarduino
filyarduinoOP2y ago
ok thanks for the help the thought of having both java and bedrock feels a little hard, so i just tried the easiest solution avoiding linking/authentication steps
QarthO
QarthO2y ago
its not hard at all all u do is flip a config setting and floodgate does it all for you you have to do nothing drop plugin in require linking start server. all ur work is done. u dont even have to require linking, so technically u can do nothing what u have works perfectly already after u turn online-mode on
Discount Milk
Discount Milk2y ago
Authme. Offline mode cringe
1who¡ssus?
1who¡ssus?2y ago
Yeah Kinda weird ngl Geyser works as a proxy iirc
ProGamingDk
ProGamingDk2y ago
Floodgate and Geyser is all ya need
1who¡ssus?
1who¡ssus?2y ago
So people might confuse it with a network setup Because in a network setup I know something else has to be in offline mode A proxy thing And a port allocation
ProGamingDk
ProGamingDk2y ago
No
1who¡ssus?
1who¡ssus?2y ago
No?
ProGamingDk
ProGamingDk2y ago
You don't even need that It can clone ur Java port
1who¡ssus?
1who¡ssus?2y ago
Interesting
QarthO
QarthO2y ago
U will need a port allocation, bedrock uses UDP So even if ur using the same port, you’ll need to also allow udp Java uses TCP
ProGamingDk
ProGamingDk2y ago
Im talking when using a host Port allocation is the word used on pterodactyl
QarthO
QarthO2y ago
well, port allocation is a general term, its not something specific to ptero but i understand what u mean
Deathpacito
Deathpacito2y ago
There are a couple of articles on the internet that says offline mode is required for Bukkit, Waterfall, etc but it actually means to link the main server with the others, I suspect that is why
ProGamingDk
ProGamingDk2y ago
Yes but Geyser isn't any of those also it's not required for bukkit
Deathpacito
Deathpacito2y ago
I meant bungee but yeah fair enough I misread the original item

Did you find this page helpful?