[Minecraft] Minecraft 1.3 (+?) Exploit
A malicious attacker can log on using any migrated account to any Minecraft server relying on Mojang Specifications’ official authentication servers to verify user authenticity. This can allow an attacker to gain access to players’ accounts causing losses within the game, or allow an attacker to gain access to a privileged account on the server. Depending on common server modifications, privileged accounts could be used to acquire access to the operating system, or cause serious damage to data on the machine, which includes but is not limited to common software and data found in unison with a Minecraft server such as:

•Server map files
•Operating system files
•Player data
•Database and webserver data
•Proprietary server modifications and source code

This vulnerability seems to be caused by a failure to authenticate usernames with session IDs for migrated accounts. joinServer.jsp will accept any valid session key from a migrated account for another migrated account.

To reproduce this issue an attacker needs to follow the following steps:

1.Log in to Minecraft with a migrated account.
2.Store the session key
3.Connect to a Minecraft server with a different migrated account’s username and the stored session key.

