PaperMC / Waterfall

BungeeCord fork that aims to improve performance and stability.
https://papermc.io
MIT License
742 stars 297 forks source link

Backdoor issue #784

Closed ghost closed 1 year ago

ghost commented 1 year ago

It's possible to backdoor a server with making your own proxy and then getting one of the backend ports to login as another user if the target server does not have bungeeguard (Add bungeeguard in waterfall?)

electronicboy commented 1 year ago

Not a bug/issue, the expectation is that you resolve it using a firewall or private network; I'd much rather add modern forwarding support to waterfall given the future of interop required between the proxy and the servers, but, given my current love or lack thereof for bungee in general, this is not a priority

Janmm14 commented 1 year ago

This is actively being warned on bungeecord github and https://spigotmc.org/wiki/firewall-guide being linked to prevent this.