SpigotMC - High Performance Minecraft Software

Want a better Minecraft server?
Read about SpigotMC here!

BungeeGuard 1.4.0

A simple plugin which adds a security token to the BungeeCord handshaking protocol.

  1. Luck
    BungeeGuard

    BungeeGuard is a plugin-based security/firewall solution for BungeeCord (and Velocity) proxies.

    The problem
    BungeeCord installations are insecure by default, and require additional firewall rules to be configured (using iptables or otherwise) to prevent malicious users from bypassing the proxy and connecting using any uuid/username they choose.

    This is a well-known issue, and over the years many (even large) servers have been successfully targeted using this attack.

    The conventional solution
    The conventional solution recommended by the BungeeCord author is to configure a firewall rule using iptables or ufw to prevent outside connections to the backend servers.

    However, there are two main problems with this:

    1. Configuring these firewall rules is complicated, especially for inexperienced users.
      1. Even experienced users sometimes make mistakes or overlook things. Unless the setup is absolutely perfect, rules are prone to being broken during later changes, or reset on system reboot.
    2. Users on "shared hosting" do not have access to the underlying system and most likely cannot setup their own firewall rules.
    The BungeeGuard solution
    Server admins install BungeeGuard (just an ordinary plugin!) on their proxies and backend servers.
    • On the proxy, BungeeGuard adds a secret "authentication token" to the login handshake.
    • On the backend (Spigot etc. server), BungeeGuard checks login handshakes to ensure they contain an allowed authentication token.
    It's really that simple.

    Installation
    Installation is very straightforward.

    If you have access to the underlying system and are able to setup firewall rules using iptables (or otherwise), I strongly recommend you do so. Then, install BungeeGuard as well.

    See here for a detailed install guide.

    License
    BungeeGuard is licensed and made available under the permissive MIT license. Please see here for more information.

Recent Reviews

  1. Maizu
    Maizu
    5/5,
    Version: 1.4.0
    IDK WHAT PEOPLE SAY, THIS WORKS ON 1.20+ USE JAVA 21!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!!

    igonre!
    sdafasfasfasddddwdasdwffwffwwwadasdsa

  2. Ananim353
    Ananim353
    5/5,
    Version: 1.3.3
    FOR PEOPLE WHO ARE WHINING THAT BUNGEEGUARD IS NOT UPDATED
    If you need a fresh version, just go to the GitHub of the project specified in the description and then to Development Builds (Jenkins).
    The build from there was updated in September 2024 and should work with 1.21 and newer versions of the Proxy server.

    HOWEVER!
    I would recommend you to use Velocity proxy which already has BungeeGuard functions built in

  3. DoxyCze
    DoxyCze
    3/5,
    Version: 1.3.3
    The plugin doesn't support newer versions; it seems to be stuck. Hopefully, someone will bring it back to life. :-))
  4. bluepigcz
    bluepigcz
    1/5,
    Version: 1.3.3
    The plugin is not working please fix it

    igonre!
    sdafsdfdsfgasadasfdeswfgrswefgf

  5. Logikoz
    Logikoz
    5/5,
    Version: 1.3.3
    very nice!

    ignore!
    tysdfasdfasdfasdfasdfasdfasdfasdfsadfasdfasdfasdfasdfasdfasdfasdfasdfasdfasdf

  6. Sniper_TVmc
  7. Hugo8348
    Hugo8348
    1/5,
    Version: 1.3.3
    ----------------------------
    Please Update it to 1.20
    ----------------------------
  8. Amp306
    Amp306
    5/5,
    Version: 1.3.3
    Does what it was made for, Won't let you connect to the backend servers from using there IP's exept the Bungeecord's IP
  9. Link_Darck
    Link_Darck
    1/5,
    Version: 1.3.3
    The plugin does not work !
    I was able to connect by creating a bungeecord on my computer
  10. DrNossTV
    DrNossTV
    5/5,
    Version: 1.3.3
    Good plugin but if you can update for 1.20, it's better ;)
    This plugin is a must have !

Read the original on spigotmc.org ↗