Never give authme.admin.* to any group below Owner. Use a separate permission for unregister:
permissions:
authme.admin.unregister:
- rank.senior_admin
Require two admins to verify via Discord before an unregister command is executed.
Go to GitHub. Download the latest 5.6.0-beta2 or higher. The main bypass (#1845) was patched in mid-2023. Minecraft Authme Bypass
Do not run AuthMe 2.x or 4.x. You need AuthMe 5.6+ (or the fork AuthMeReloaded). Check GitHub commits weekly.
Warning: The following is for server administrators to understand attack flows. Do not use this maliciously. Never give authme
Target: A cracked server running AuthMe 5.6.0 with default config.
Attempt 1: NullCipher (Fail)
Attempt 2: Session Stealer (Success)
Attempt 3: BungeeCord Spoof (Success)
