Pocketmine-mp: Name saving issue

Created on 1 Feb 2021  路  10Comments  路  Source: pmmp/PocketMine-MP

Issue description

Steps will explain.

Steps to reproduce the issue

  1. Generate two accounts with same spelling but different capital usage(i.e. minijaham and mInIjaham).
  2. Log in with the first account and give op.
  3. Log in with second account and you should have op in that account as well.

OS and versions

Plugins

  • If you remove all plugins, does the issue still occur?
    Yes
  • If the issue is not reproducible without plugins:

    • Have you asked for help on our forums before creating an issue?

      I have, but I'm still waiting for an answer

    • Can you provide sample, minimal reproducing code for the issue? If so, paste it in the bottom section

      No reproducing code

Crashdump, backtrace or other files

Client Won't fix

Most helpful comment

well done, you've just advertised a security vulnerability to hundreds of people...

I'm already aware of this issue thanks to people who informed me in a more responsible manner by emailing [email protected] or otherwise contacting us privately.

All 10 comments

This bug cause from gamertag duplicate when creating account Xbox Live, not from server software.

This was tested with other usernames as well.

A lot of servers actually had the same issue.

Even Fallentech, Hyperlands, etc staff account got hacked by this method.

Exactly. Thanks to alvin though, he's told me a solution to this...

Have you report this bug to Microsoft or Xbox?

Have you report this bug to Microsoft or Xbox?

Not yet.

well done, you've just advertised a security vulnerability to hundreds of people...

I'm already aware of this issue thanks to people who informed me in a more responsible manner by emailing [email protected] or otherwise contacting us privately.

How come the issue hasn't been solved yet, if you were already aware of it?

Just wait Microsoft fix this bug. The solution is save real player gamertag without converted to lowercase.

How come the issue hasn't been solved yet, if you were already aware of it?

Because the issue lays with xbox usernames being allowed to have other unicode letters in their names.

Was this page helpful?
0 / 5 - 0 ratings

Related issues

L3ice picture L3ice  路  21Comments

mal0ne-23 picture mal0ne-23  路  17Comments

MisteFr picture MisteFr  路  29Comments

kenygamer picture kenygamer  路  92Comments

KAGsundaram picture KAGsundaram  路  43Comments