CrackedFlooder
Local load-testing dashboard for Eaglercraft Minecraft servers (WebSocket). For authorized testing only — you must own the target server or have written permission.
What it does
Spawns a configurable number of fake MC 1.12.2 (Protocol 340) clients over WebSocket, routes them through a SOCKS proxy pool, performs the EaglerV2 + MC login handshake, optionally sends /register//login and chat messages, and keeps them alive on keep-alive packets. The dashboard shows live bot state, proxy health, and structured logs.
What's new in v2
- MC protocol fix: proper length-prefixed packet framing,
Set Compressionhandling, and correctPosition and Lookparsing (Little Endian, bitmask, VarInt teleport ID). - Compression-aware: bots negotiate compression when the server enables it (zlib raw).
- Auth state machine: structured matching on
translatekeys (commands.register.success, etc.) instead of brittle substring search. - Proxy registry v2: JSON persistence, scoring (0–100), weighted picking strategies (
best-score,round-robin,least-used,random), per-proxy inflight caps, EMA latency, automatic retest-after-cooldown. - Per-bot inspector: click "Inspect" on any bot to see packets, proxy, last error, and chat from a single bot.
- Rate limits: login, proxy upload, test start, broadcast chat all rate-limited.
- Security:
helmetCSP,httpOnly+sameSite=strictcookies, HMAC-SHA256 session tokens, constant-time password compare, refuses to boot with defaultSESSION_SECRET. - Observability:
/healthz,/metrics(Prometheus),/api/diagnostics, structured JSON daily logs, log throttling. - Frontend: score-colored proxy table, log filter, search, level toggles, per-bot inspector panel.
Quick start
cp .env.example .env # if you don't have one
# Edit .env: set SITE_PASSWORD and SESSION_SECRET
npm install
npm start
Open http://localhost:6070 and enter your SITE_PASSWORD.
Tests
npm run check # syntax check on all source files
npm test # unit tests (packets, codec, compression, auth, registry)
npm run smoke # boot the server, hit endpoints, verify shape
Project layout
src/
config.js config loading + env validation
state.js shared mutable state + event bus
auth.js HMAC tokens, cookie parser, constant-time compare
io.js Socket.IO + throttled broadcaster
validate.js input validation
server.js bootstrap (express, helmet, routes, lifecycle)
proxy/
registry.js ProxyRegistry class (scoring, persistence, picking)
lease.js per-test proxy lease
workerPool.js generic async worker pool
bot/
packets.js VarInt, strings, MC framing helpers
codec.js Eagler + MC 1.12.2 packet parsers/builders
compression.js zlib threshold handling
auth.js AuthStateMachine
bot.js Bot class — state machine
routes/
auth.js /api/auth/*
test.js /api/test/*
proxy.js /api/proxy/*
bots.js /api/bots/*
stats.js /api/stats, /api/logs
health.js /healthz, /metrics, /diagnostics
util/
log.js structured logger (daily rotation)
throttle.js throttle + coalescer
test/ node:test unit tests
scripts/
smoke.js end-to-end smoke test
migrate-proxies.js one-shot proxies.txt → proxies.json
Environment
| Var | Required | Description |
|---|---|---|
SITE_PASSWORD |
yes | Dashboard login password |
SESSION_SECRET |
yes | Random secret for HMAC-signed cookies. Refuse to boot if unset or default. |
PORT |
no | Override config.yaml server.port |
HOST |
no | Override config.yaml server.host |
Configuration
config.yaml is non-sensitive. Top-level keys:
server.{port, host}— defaults to 6070 / 0.0.0.0bots.{max_bots, default_rate, default_spawn_delay, max_spawn_delay, max_packet_rate, password, join_delay_ms, chat_messages, auth_phrases, auth_timeout_ms}— bot limits and defaultsproxy.{test_timeout_ms, concurrency, max_list_size, probe_host, probe_port, score_decay_ms, score_penalty_per_fail, score_recovery_after_ms, alive_latency_max_ms, per_proxy_inflight_cap, default_strategy}— proxy pipeline tuninglogging.{max_log_entries, max_dom_logs, daily_log_dir}— log bufferingauth.session_hours— cookie lifetimerate_limits.*— per-route limitscors.origins— CORS allowlist; empty = same-origin onlyquick_commands— list of/commandstrings available in the dashboard's quick-actions panel
Threat model
This tool is intended for local development and authorized load testing of servers you own or have explicit written permission to test. Use against systems without authorization is illegal.
The dashboard binds to 0.0.0.0 by default; if you're on a multi-tenant host, override HOST in config.yaml to 127.0.0.1. The default rate limits and CORS are tuned for single-user local use; if you expose this beyond localhost, add a reverse proxy with auth and tighten further.
License
MIT