Advertisement
Guest User

Untitled

a guest
Feb 18th, 2020
149
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
text 2.46 KB | None | 0 0
  1. Hey Teddie, it's doodle here!
  2.  
  3. I'm messaging you today on behalf of several players from HelloMiners. I hate to be the one to message you however I felt giving others your contact here would only induce spam and make it harder for normal players to ask.
  4.  
  5. It concerns the new plugin developer that's been hired for the server. They're doing great work and all however a recent security issue has come to light. If you weren't aware, James (magnusfrost) has a girlfriend (bootstoo). He has given bootstoo access to every account of his including discord and every form of account. This means, bootstoo can access all of James' private DM's with other admins or even you which may be only for the admins or higher to know about. Furthermore, this gives them full access to the server's internal files as well as the dynmap server which is currently being hosted on one of James' servers.
  6.  
  7. This is a MASSIVE security risk to the entire server giving someone in the trial mod position access to everything that only the most trusted of people can be given access to. Relationships between people always can go south and that means should sometime happen between the two of them, the server is hostage to whatever they may try and do. To further add to how much of a problem a trial mod having access to the internal files, there is also evidence of bootstoo abusing their powers by using /fly on personal projects. You can see the evidence of this here:
  8.  
  9. Furthermore, I recently found out James has been making custom items and giving them to players for no valid reasons. No event was being run, no reward for a job, nothing to make it an acceptable occurrence. I found the logs of the person showing off the item as well as them clearly stating it was James who gave it to them because they met irl and they also gave him items on their server. Here are the logs: https://pastebin.com/NTymLjYE. This was on the 10th of February, so it's very much recent.
  10.  
  11. Continuing, there was a report made on the forums above bootstoo's behaviour. It included screenshots of bootstoo spamming in caps and using derogatory comments on James' personal discord. If this isn't enough to prove a point, DR_StevenStrange was the first person to jump on the topic, constantly defending everything anyone said before James or Bootstoo had even made their formal reply. To add insult to injury, the topic shortly after was deleted. My question is why would someone delete a valid report topic which highlights a server wide security risk?
Advertisement
Add Comment
Please, Sign In to add comment
Advertisement