Exploits: Difference between revisions

Content deleted Content added
Allink (talk | contribs)
m Reword exploit patching clause
Allink (talk | contribs)
Add details about SilentTP exploit
Line 31:
 
It was what prompted the development team to begin work on Scissors which became the foundation for exploit patches as the year progressed and more exploits were discovered.
 
=== SilentTP ===
 
SilentTP, colloquially referred to as the first Nocom exploit, or just Nocom, was a text component that allowed for querying of a target player's position tag when resolved. This was added to [[DeviousMod]] in the form of the stp command, which allowed the user of the mod to teleport to the target player, even if they had TPToggle disabled in the Essentials plugin. Later, this was added to [[Community:SexiestBot|SexiestBot]] in the form of an algorithm which queried the position of every player connected to the server, allowing for teleportation to any player without having to first install DeviousMod.
 
This exploit was initially undiscovered for a few days, until [[Community:fyyv|fyyv]] made a suggestion on the forums, detailing how it deliberately circumvented TPToggle, recommending the server administration patch the exploit<ref>TotalFreedomForum, [https://web.archive.org/web/20230726113259/https://totalfreedom.me/forum/thread/4096-prohibit-the-creative-nocom-exploit/ post 4096].</ref>. SexiestBot was banned when the suggestion was accepted, and was unbanned once the SilentTP functionality had been completely removed.
 
=== Worldcom ===