My Buddy Erik

Description

My buddy Erik wants to play Minecraft so I set up a server for us to play on. I've commited my configuration to GitHub because it's so convenient! Can you make sure that everything is secure?

https://github.com/VikeSec/vikeCTF-2024-minecraft-serverarrow-up-right

Solution

The github commit historyarrow-up-right is not that interesting, but we do we a reverted commit: Revert "Add RCON password"arrow-up-right.

erik-1

Since the commit has been deleted locally and uploaded to remote cloning wont give satisfactory results. We need to search github for deleted commits.

If we go to branchesarrow-up-right we see update 2 days ago by malcolmseydarrow-up-right. That's weird... because commit history shows update from last week.

erik-2

We can dig further into this Activityarrow-up-right, by going to 3 dot -> Activity.

erik-3

Compare Changes: Disable Mojang telemetryarrow-up-right (3 dots)

Add RCON passwordarrow-up-right

circle-check

Last updated