51

This is from my days of running a rather large (for its time) Minecraft server. A few of our best admins were given access to the server console. For extra security, we also had a second login stage in-game using a command (in case their accounts were compromised). We even had a fairly strict password strength policy.
But all of that was defeated by a slightly too stiff SHIFT key. See, in-game commands were typed in chat, prefixed with a slash -- SHIFT+7 on German-ish keyboards. And so, when logging in, one of our head admins didn't realize his SHIFT key didn't register and proudly broadcast to the server "[Admin] username: 7login hisPasswordHere".
This was immediately noticed by the owner of a 'rival' server who was trying to copy some cool thing that we had. He jumped onto the console that he found in an nmap scan a week prior (a scan that I detected and he denied), promoted himself to admin and proceeded to wreak havoc.
I got a call, 10-ish minutes later, that "everything was literally on fire". I immediately rolled everything back (half-hourly backups ftw) and killed the console just in case.
The best part was the Skype call with that admin that followed. I wasn't too angry, but I did want him to suffer a little, so I didn't immediately tell him that we had good backups. He thought he'd brought the downfall of our server. I'm pretty sure he cried.

Comments
  • 3
    Amazing.
  • 3
    How about the rival server admin? Did you report him to the police?
  • 14
    @brahn No, he was just a kid and I was quite young too.
    It's also sort of a legal grey area - all the damage he did was in a virtual world in-game. We could've probably won in court if we tried, but we couldn't afford a lawyer and didn't really care enough anyways. Everything was rolled back successfully and I "denounced" the owner on our forum and social media. He was preemptively banned from several other large servers and his server lost almost all players when they realized how petty he was.
  • 8
    If you used a login system for an anti compromise account, lock chat messages (for the user) while logging in.
  • 0
    That's a pretty damn good success story on backups. Awesome!
Add Comment