Skip to content
vi395Public

About

🧪 McSecure Lab — security testing platform for Minecraft servers. Plugin backdoor injection + MITM proxy (WIP). Telegram bot + web panel. Dockerized.

Resources

Stars

4 stars

Watchers

0 watching

Forks

Repository files navigation

🧪 McSecure Lab

Python FastAPI Docker Aiogram SQLite

Security testing platform for Minecraft servers
Plugin backdoor injection + (WIP) MITM proxy with traffic sniffing


⚠️ Legal & Ethical Use

This tool is intended for educational and security research purposes only.
Use it exclusively on servers you own or have explicit written permission to test.
The authors are not responsible for any misuse or damage caused by this software.


✨ Features

  • 💉 Plugin Backdoor Injection – injects a remote‑control backdoor into any Bukkit/Spigot/Paper .jar plugin.
    • Console‑level command execution via in‑game chat or web panel.
    • Unique access code for each injected plugin.
  • 🕵️ MITM Sniffer (WIP) – Man‑In‑The‑Middle proxy that intercepts and logs Minecraft traffic.
    • Currently under development – not production‑ready.
  • 🤖 Telegram Bot – interactive bot for injection, balance management, and MITM control.
  • 🌐 Web Control Panel – command history, session management, real‑time logs.
  • 🐳 Fully Containerized – easy deployment with Docker Compose.

🧰 Tech Stack

Area Technologies
Backend API FastAPI, Uvicorn, SQLite, Docker SDK
Bot Aiogram 3.x, aiohttp, Docker SDK
MITM Proxy SniffCraft (binary) + custom Docker wrapper, socat, Gate (MineKube)
Injection Tool OpenBukloit (custom Java patcher)
Orchestration Docker Compose, Makefile
Log Processing Watchdog + aiohttp
Reverse Proxy Caddy

🖼️ Screenshots

Main Menu Deposit Injection Guide
menu deposit injection
MITM (WIP) Promocodes
mitm promocodes

🚀 Quick Start

Prerequisites

  • Docker & Docker Compose
  • Linux server with public IP (for subdomains / Gate)
  • Environment variables (see below)

1. Clone the repository

git clone https://github.com/yourusername/mcsec-lab.git
cd mcsec-lab

2. Prepare configuration

Create a .env file in the project root:

DOMAIN=yourdomain.com
BOT_TOKEN=your_telegram_bot_token
ADMIN_ID=your_telegram_user_id
PRICE_PER_PATCH=100
PRICE_PER_MITM=200
PUBLIC_URL=https://yourdomain.com
REMOTE_URL=https://yourdomain.com
USE_IMAGES=true

3. Build & run

make build   # builds all images (API, bot, sniffcraft-base, openbukloit)
make up      # starts all containers in detached mode

The following services will be available:

  • Web panel & API → http://localhost:8080 (proxied via Caddy on ports 80/443)
  • Telegram bot → polls updates
  • Gate (Minecraft proxy) → 0.0.0.0:25565
  • MITM sniffers → separate containers created on demand

4. Stop / clean

make down   # stops all containers
make clean  # removes containers, volumes, and local data

📱 Usage

Telegram Bot

  1. Start the bot with /start and accept the license.
  2. Deposit credits (payment stubs – extend with real gateways).
  3. Inject a plugin:
    • Send a .jar file → receive patched plugin + unique code.
    • Upload the patched plugin to your Minecraft server.
    • Execute console commands:
      • In‑game chat – type <code> <command> (e.g. a1b2c3 give nothc diamond)
      • Web panel – open https://yourdomain.com/<code> and run commands remotely.
  4. MITM Server (WIP) – not yet functional. The UI and balance deduction work, but actual proxy creation is under construction.

Web Control Panel

  • https://yourdomain.com/<code> – command history and real‑time command submission.
  • https://yourdomain.com/sniffer/<sniffer_id> – WebSocket live log viewer for MITM (once ready).

📁 Project Structure (simplified)

.
├── api/                # FastAPI backend (control panel, sniffer management)
├── bot/                # Telegram bot (aiogram)
├── log_processor/      # watches logs/ and forwards events to API
├── sniffcraft/         # SniffCraft binary + Dockerfile + config template
├── openbukloit/        # OpenBukloit patcher (Java)
├── gate/               # MineKube Gate configuration
├── images/             # screenshots for README & bot
├── data/               # SQLite DB, per‑sniffer configs
├── logs/               # per‑sniffer packet logs
├── docker-compose.yml
├── Makefile
└── Caddyfile

🔧 Current Limitations & TODOs

  • MITM sniffer – backend endpoints, container creation logic, and log processing are implemented, but the SniffCraft integration is not yet fully functional.
    The bot correctly deducts credits and calls the API, but the resulting proxy does not forward traffic.
    Status: WIP – contributions welcome.
  • Payment stubs – only demonstration callbacks; real payment gateways need to be implemented.
  • SniffCraft binaries are not included – you must obtain them separately (sniffcraft-<version> inside sniffcraft/binaries/).

📄 License

AGPL-3.0


🙌 Contributing

Issues and pull requests are welcome.
For major changes, please open an issue first to discuss what you would like to improve.

Keep it real – no refactoring without a reason.

About

🧪 McSecure Lab — security testing platform for Minecraft servers. Plugin backdoor injection + MITM proxy (WIP). Telegram bot + web panel. Dockerized.

Resources

Stars

4 stars

Watchers

0 watching

Forks

Releases

Packages

Contributors

Languages