Security testing platform for Minecraft servers
Plugin backdoor injection + (WIP) MITM proxy with traffic sniffing
This tool is intended for educational and security research purposes only.
Use it exclusively on servers you own or have explicit written permission to test.
The authors are not responsible for any misuse or damage caused by this software.
- 💉 Plugin Backdoor Injection – injects a remote‑control backdoor into any Bukkit/Spigot/Paper
.jarplugin.- Console‑level command execution via in‑game chat or web panel.
- Unique access code for each injected plugin.
- 🕵️ MITM Sniffer (WIP) – Man‑In‑The‑Middle proxy that intercepts and logs Minecraft traffic.
- Currently under development – not production‑ready.
- 🤖 Telegram Bot – interactive bot for injection, balance management, and MITM control.
- 🌐 Web Control Panel – command history, session management, real‑time logs.
- 🐳 Fully Containerized – easy deployment with Docker Compose.
| Area | Technologies |
|---|---|
| Backend API | FastAPI, Uvicorn, SQLite, Docker SDK |
| Bot | Aiogram 3.x, aiohttp, Docker SDK |
| MITM Proxy | SniffCraft (binary) + custom Docker wrapper, socat, Gate (MineKube) |
| Injection Tool | OpenBukloit (custom Java patcher) |
| Orchestration | Docker Compose, Makefile |
| Log Processing | Watchdog + aiohttp |
| Reverse Proxy | Caddy |
| Main Menu | Deposit | Injection Guide |
|---|---|---|
![]() |
![]() |
![]() |
| MITM (WIP) | Promocodes |
|---|---|
![]() |
![]() |
- Docker & Docker Compose
- Linux server with public IP (for subdomains / Gate)
- Environment variables (see below)
git clone https://github.com/yourusername/mcsec-lab.git
cd mcsec-lab
Create a .env file in the project root:
DOMAIN=yourdomain.com
BOT_TOKEN=your_telegram_bot_token
ADMIN_ID=your_telegram_user_id
PRICE_PER_PATCH=100
PRICE_PER_MITM=200
PUBLIC_URL=https://yourdomain.com
REMOTE_URL=https://yourdomain.com
USE_IMAGES=true
make build # builds all images (API, bot, sniffcraft-base, openbukloit)
make up # starts all containers in detached mode
The following services will be available:
- Web panel & API →
http://localhost:8080(proxied via Caddy on ports 80/443) - Telegram bot → polls updates
- Gate (Minecraft proxy) →
0.0.0.0:25565 - MITM sniffers → separate containers created on demand
make down # stops all containers
make clean # removes containers, volumes, and local data
- Start the bot with
/startand accept the license. - Deposit credits (payment stubs – extend with real gateways).
- Inject a plugin:
- Send a
.jarfile → receive patched plugin + unique code. - Upload the patched plugin to your Minecraft server.
- Execute console commands:
- In‑game chat – type
<code> <command>(e.g.a1b2c3 give nothc diamond) - Web panel – open
https://yourdomain.com/<code>and run commands remotely.
- In‑game chat – type
- Send a
- MITM Server (WIP) – not yet functional. The UI and balance deduction work, but actual proxy creation is under construction.
https://yourdomain.com/<code>– command history and real‑time command submission.https://yourdomain.com/sniffer/<sniffer_id>– WebSocket live log viewer for MITM (once ready).
.
├── api/ # FastAPI backend (control panel, sniffer management)
├── bot/ # Telegram bot (aiogram)
├── log_processor/ # watches logs/ and forwards events to API
├── sniffcraft/ # SniffCraft binary + Dockerfile + config template
├── openbukloit/ # OpenBukloit patcher (Java)
├── gate/ # MineKube Gate configuration
├── images/ # screenshots for README & bot
├── data/ # SQLite DB, per‑sniffer configs
├── logs/ # per‑sniffer packet logs
├── docker-compose.yml
├── Makefile
└── Caddyfile
- MITM sniffer – backend endpoints, container creation logic, and log processing are implemented, but the SniffCraft integration is not yet fully functional.
The bot correctly deducts credits and calls the API, but the resulting proxy does not forward traffic.
Status: WIP – contributions welcome. - Payment stubs – only demonstration callbacks; real payment gateways need to be implemented.
- SniffCraft binaries are not included – you must obtain them separately (
sniffcraft-<version>insidesniffcraft/binaries/).
Issues and pull requests are welcome.
For major changes, please open an issue first to discuss what you would like to improve.
Keep it real – no refactoring without a reason.




