Elytrium / Elytrium/LimboAuth

LimboAuth Session Exploit Issue — Players Rejoining Without Login Using ExitLag

Open
#227 1 comment 0 reactions 0 assignees View on GitHub
bug
Dominant language
Java
Stars
238
Forks
125
PR merge metrics
No merged PRs in 30d

Description

I'd like to report an issue with the LimboAuth plugin. Currently, there's a significant problem where some players are using software called "exit lag" to rejoin the server even after they've left, without their session expiring. This allows them to transfer items and causes other issues. Could you please adjust the session timeout so that players are forced to log in again whenever they rejoin? This would significantly reduce the risk of this exploit. I believe this is a growing issue, so it would be great if you could look into it as soon as possible.

Thank you!

Contributor guide

No contributing guide indexed for this repository

Research direction

The issue names no files, tests, or entry points. Start by tracing LimboAuth's session handling for players who disconnect and rejoin, then reproduce the reported ExitLag scenario and determine where login state remains valid. Done means a returning player must authenticate again before transferring items or accessing the server.

Written by the indexing model from the issue text.

Assessment

Tech stack
java
Domain
authentication, security
Issue type
Bug
Difficulty
4/5
Estimated time
3-5 days
Activity status
Stale
Clarity
Mostly clear
Newbie friendliness
35/100

Get new issues in your inbox

A short digest of beginner-friendly GitHub issues.