Double Protection Exploit with ACL Protection #33


  • New
  • Defect
Open
Assigned to _ForgeUser298170
  • _ForgeUser7891919 created this issue Sep 1, 2014

    What steps will reproduce the problem?
    1.Make a Mondo Master Chest
    2.Add a Slave Chest of another Player that you dont have access too because of acl and protection setting

    What is the expected output? What do you see instead?
    Expected: Access Denied when not having rights to access chest
    Instead: Chest added as slave and original owner of the slave chest cant access it anymore as it is now double protected.

    What version of the product are you using?
    0.7.2-pre1 on Spigot 1.7.9 Build 1543

    Do you have an error log of what happened?
    there is no log

    Please provide any additional information below.
    This also causes "ghost" protected Slaves. As if the original owner of a slave removes the sign (yes he can, no double protection here) the chest still remains a slave for the other Mondo System and the Owner still cant access it. Also still items can bve shelved by the other master chest.
    This causes all kind of fails that requier admin assistance and the banks file fills up with ghost chests, as when the sign gets destroyed by the original owner, only his Slave gets removed, but not the one from the other master.
    This can be used as form of griefing and to annoy other players and the admins.

  • _ForgeUser7891919 added the tags New Defect Sep 1, 2014

To post a comment, please login or register a new account.