#Servers deleting a plugin jar file

25 messages Β· Page 1 of 1 (latest)

polar zephyr
dull nebula
#

We have the same problem they are deleting some of my plugin.

Here is the respone when i contacted them.

There have unfortunately been increased problems recently due to faulty or malicious plugins running on game server services. We have therefore recently developed a new system that automatically checks all uploaded plugins for malware and security aspects during the startup process. The process evaluates the executable code of the JAR files and checks for the following things: possible backdoors, remote code execution, system relevant commands and so on.

These plugins are then marked as dangerous and disabled accordingly. The deactivated plugins are stored in the game server root directory. The path for this looks like this: /gXXX/gamexy/.pluginblacklist/disabledplugins

If you believe that the blacklisting of a certain plugin is a mistake, please let us know. We will then check it in detail as soon as possible and take appropriate action if needed.

We kindly ask for your indulgence and understanding that this is not meant to be a restriction, but rather implemented as a preventive measure to guarantee the best possible security and stability of our systems.

obsidian oriole
polar zephyr
#

What a dumb thing to do. i have just found out 4 plugins have been removed! Funny that all 4 are paid plugins....

dull nebula
#

Same with me. Some of my paid and core plugin are removed. Now my sever is completely broken

obsidian oriole
#

well if they got disabled it means they might have malicious code in them otherwise you can contact the team and get them approved

real sandal
#

So this is what is happening this host is going to crap... Oraxen is one of my core plugins now i have to see if something else was removed aswell jesus...

unreal pecan
#

Oof! Sorry for the inconvenience we caused here.
I'll make sure this gets checked ASAP by the responsible team. 🫑

real sandal
#

Sorry had to vent πŸ˜ͺ just upsetting seeing so much work into something <months> to just have stuff removed without any notice or reason.

polar zephyr
#

I understand why, but it should be all plugins are white-listed but block the ones you know that are causing issues.

nimble rampart
#

Quick addition and clarification on the subject: The plugins are not removed, but deactivated, by moving them to a separate directory. Plugins are allowed to be used freely by default. We don't block plugins (unless already blacklisted) in advance. The plugins are checked during the startup process and deactivated if any conspicuousness is detected.

We have already whitelisted many well-known and popular plugins from the beginning. However, as you probably know, there are quite a lot of plugins available for Minecraft, so we can't include all of them from the beginning. We will continuously expand the system and whitelist plugins again if they triggered a false positive.

dull nebula
#

All my blacklisted plugins are false positive. I hope they will whitelisted them.

nimble rampart
#

Once we have verified and confirmed it, the chances of whitelisting it are quite high. πŸ™‚

real sandal
#

The ticket time is kinda insane especially when it transfers to another person. I'm sure everyone's making tickets now with the update on top of normal ticket time.

dull nebula
#

Update: My plugins are back

"we checked the plugins and verified a false positive.
The plugins has been added to the whitelist and are usable after a server restart again! πŸ™‚
I moved them back to your plugins folder, so everything should be fine as before!"

nimble rampart
#

The ticket time is kinda insane especially when it transfers to another person. I'm sure everyone's making tickets now with the update on top of normal ticket time.

We can fully understand that, but the decision as to whether something is legitimate or not has to be reviewed in detail and takes time. Besides, this has to be done by the colleagues who manage the system and have the corresponding experience with it.

Update: My plugins are back

Glad to hear that! πŸ™‚

real sandal
#

All but 1 plugin restored I can live with that. Sorry for all the complaining

dull nebula
#

i just update my plugin and now its blacklisted again.
Its so very hassle 😞 . So every time i upload the new updated plugin we will wait again 2-3 days to whitelisted them?

#

I hope they will make a plugin list that are whitelisted not just on one game server only but globally, so that every time we upload the latest version, we don't need to wait again for 2-3 days to whitelisted them. This is very time consuming and very hassle.

vestal holly
#

I have the same issue too

#

i got love/hate to this new plugin system

-love, its do protect new minecraft server owners who may not know from a safe plugin

-don't like, you have to get zap to allow it to your paid server

pearl hill
#

The whitelist is global for all servers at ZAP.
New versions will not require a new review and whitelisting of plugins, unless the developer changed the identifier of the plugin.

polar zephyr
#

Thanks Zap for sorting the plugins out. All servers are back online and all plugins checked and globally whitelisted πŸ™‚