Skip to content

Conversation

@bedoflex
Copy link

Player rob exploit fix.

Player rob exploit fix.
Copy link

@Maximus7474 Maximus7474 left a comment

Choose a reason for hiding this comment

The reason will be displayed to describe this comment to others. Learn more.

This does not resolve the exploit, the hacker would just have to pass something else then player or otherplayer as inventory type to bypass the check.

@bedoflex
Copy link
Author

This check fixing the exploit you can try it.

@Maximus7474
Copy link

This check fixing the exploit you can try it.

It doesn't, instead of passing "otherplayer" as invType put something random like your username, you'll see it still bypasses the check.

You didn't even provide a repro or explanation to the fix you've done, how would maintainers know what you're fixing or how the exploit actually occurs ?
Check my PR that resolves the issue entirely to get an idea on what should be done in the PR description #53

Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Labels

None yet

Projects

None yet

Development

Successfully merging this pull request may close these issues.

2 participants