Uploaded image for project: 'Mojang Web Services'
  1. Mojang Web Services
  2. WEB-1429

Old Authentication servers for legacy versions are offline

    XMLWordPrintable

    Details

    • Type: Bug
    • Status: Open
    • Priority: Normal
    • Resolution: Unresolved
    • Labels:
      None

      Description

      Old versions of Minecraft are unable to use the Mojang authentication system to confirm if users are premium users. This requires servers to run in offline mode allowing for cracked clients to connect to these servers. The issue can be addressed by bringing the previous authentication servers online or redirecting them.

       

      Server Authentication:

      Old URL: https://login.minecraft.net/session?name=

      New URL: http://session.minecraft.net/game/joinserver.jsp?user=

       

      Client Authentication

      Old URL: http://www.minecraft.net/game/joinserver.jsp?user=

      New URL: http://session.minecraft.net/game/joinserver.jsp?user=

       

      Due to these old URLs not working, illegitimate account holders can connect to any Beta/Alpha server.

      Client authentication is the main URL that needs to be fixed, server owners can implement their own fixes to patch authentication server-side although it would be best to fix Server URLs as well.

       

        Attachments

          Activity

            People

            Assignee:
            mojangweb [Mojang] Web Team
            Reporter:
            RhysB Rhys B
            Votes:
            84 Vote for this issue
            Watchers:
            53 Start watching this issue

              Dates

              Created:
              Updated: