{"id":20032709,"url":"https://github.com/lucko/bungeeguard","last_synced_at":"2025-04-06T17:13:04.512Z","repository":{"id":26604346,"uuid":"109184914","full_name":"lucko/BungeeGuard","owner":"lucko","description":"A plugin-based security/firewall solution for BungeeCord and Velocity proxies.","archived":false,"fork":false,"pushed_at":"2024-09-03T20:48:55.000Z","size":90,"stargazers_count":215,"open_issues_count":41,"forks_count":50,"subscribers_count":12,"default_branch":"master","last_synced_at":"2025-03-30T15:08:47.034Z","etag":null,"topics":["bungeecord"],"latest_commit_sha":null,"homepage":"","language":"Java","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"mit","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/lucko.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE.txt","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":"SECURITY.md","support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2017-11-01T21:16:37.000Z","updated_at":"2025-03-08T01:17:10.000Z","dependencies_parsed_at":"2024-11-13T09:49:48.858Z","dependency_job_id":null,"html_url":"https://github.com/lucko/BungeeGuard","commit_stats":null,"previous_names":[],"tags_count":9,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lucko%2FBungeeGuard","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lucko%2FBungeeGuard/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lucko%2FBungeeGuard/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/lucko%2FBungeeGuard/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/lucko","download_url":"https://codeload.github.com/lucko/BungeeGuard/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":247517916,"owners_count":20951719,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["bungeecord"],"created_at":"2024-11-13T09:38:58.149Z","updated_at":"2025-04-06T17:13:04.493Z","avatar_url":"https://github.com/lucko.png","language":"Java","funding_links":[],"categories":[],"sub_categories":[],"readme":"# 💂 BungeeGuard\n\nBungeeGuard is a plugin-based security/firewall solution for [BungeeCord](https://www.spigotmc.org/wiki/bungeecord/) (and [Velocity](https://velocitypowered.com/)) proxies.\n\n* [Download](https://github.com/lucko/BungeeGuard/releases)\n* [Development Builds (Jenkins)](https://ci.lucko.me/job/BungeeGuard/)\n* [Install Guide](INSTALLATION.md)\n\n## The problem\n\nBungeeCord installations are **insecure by default**, and require additional firewall rules to be configured (using iptables or otherwise) to prevent malicious users from bypassing the proxy and connecting using any uuid/username they choose.\n\nThis is a **well-known issue**, and over the years many (even large) servers have been successfully targeted using this attack.\n\n### The conventional solution\n\nThe conventional solution recommended by the BungeeCord author is to configure a firewall rule using iptables or ufw to prevent outside connections to the backend servers.\n\nHowever, there are two main problems with this:\n\n1. Configuring these firewall rules is complicated, especially for inexperienced users.\n   1. Even experienced users sometimes make mistakes or overlook things. Unless the setup is absolutely perfect, rules are prone to being broken during later changes, or reset on system reboot.\n2. Users on \"shared hosting\" do not have access to the underlying system and most likely cannot setup their own firewall rules.\n\n### The BungeeGuard solution\n\nServer admins install BungeeGuard (just an ordinary plugin!) on their proxies and backend servers.\n\n* On the **proxy**, BungeeGuard adds a secret \"authentication token\" to the login handshake.\n* On the **backend** (Spigot etc. server), BungeeGuard checks login handshakes to ensure they contain an allowed authentication token. \n\nIt's really that simple.\n\n## Installation\n\nInstallation is very straightforward.\n\nIf you have access to the underlying system and are able to setup firewall rules using iptables (or otherwise), I strongly recommend you do so. Then, install BungeeGuard as well.\n\nSee [INSTALLATION.md](INSTALLATION.md) for a detailed install guide.\n\n## License\n\nBungeeGuard is licensed and made available under the permissive MIT license. Please see [LICENSE.txt](LICENSE.txt) for more information.\n\nDetails about vulnerability reporting \u0026 security disclosures can be found in [SECURITY.md](SECURITY.md).\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Flucko%2Fbungeeguard","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Flucko%2Fbungeeguard","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Flucko%2Fbungeeguard/lists"}