View Issue Details

IDProjectCategoryView StatusLast Update
0000566unrealircdpublic2003-11-20 19:46
ReporterDJMystic Assigned Toluke  
PrioritynormalSeveritycrashReproducibilityalways
Status closedResolutionno change required 
Summary0000566: [stable] Crash with operserv
DescriptionI have a really stupid service root, which made a stupid typo and did: /msg operserv raw : join #weazenet
and he was suprised that the servr crashed..
but anyways, should this really crash the server? couldn't anyone make a little protection against this? because if linkers could also do that, they would be able to fuck up my whole network
Steps To Reproduce/msg operserv raw : join #channel
Additional Informationits stupid :D
3rd party modules

Activities

jollino

2002-12-25 20:02

reporter   ~0000923

Most service packages clearly state that using raw injection of commands to the uplink server can cause a big mess. That's why some services keep the raw command disabled by default.

Using raw commands makes your services uplink to believe it's receiving commands by a server; usually, server-server communications are stable by definition, ie. no server will send you corrupted commands, so there's no need to "check" data coming from a server. If the 'server', being impersonated by a stupid admin, ends up crashing, then you have two choices:

1. choose your admins with more care.
2. disable the raw command completely (why would you need it anyway?)

thilo

2002-12-26 17:34

reporter   ~0000928

#SNIP#
usually, server-server communications are stable by definition, ie. no server will send you corrupted commands
#SNIP#

That's exactly why Unreal received a nice entry on bugtraq ;-)

syzop

2003-01-15 04:34

administrator   ~0001045

An issue of which I had mailed to coders list at 2002-03-04 (the bugtraq posting is of 2002-07-19), however I didn't get a response back then. it was patched at 2002-09-06 when I started playing with UnrealIrcd source again. I however don't do Unreal 3.1.x, sorry ;P.
I should however repeat that the bugtraq post was stupid because:
1. You need to link a server in order to connect, you can only do that if you know the password or can snif... In both cases I see no reason why one would crash a server instead of abusing.
2. You cannot execute any code by it because it's a null pointer dereference bug IIRC.

syzop

2003-01-15 04:35

administrator   ~0001046

however however however however however I think I should get some sleep.

codemastr

2003-01-15 16:46

reporter   ~0001058

Bugtraq (imho) is now notorious for 'fake' bugs. For example they reported an exploit in a function in Unreal a while back. So I looked, well the code they were claiming was exploitable wasn't in use since Unreal 3.0 yet the bugtraq said it was reproducable under 3.2 and 3.1.2. Not only that, the code was only used (in 3.0) under windows, yet bugtraq said it was reproducable under any OS. And even further, the code could only be exploitable if it was used incorrectly, and it wasn't. So basically someone wrote in a completely fake bug report and they accepted it. I take everything they post with a grain of salt after that....

syzop

2003-01-15 22:32

administrator   ~0001066

Exactly, I guess they didn't even update it after my reply :(. Maybe we can expect a "format string bug in sendto_one" this year, lol ;P.

luke

2003-04-11 22:11

reporter   ~0002279

It is assumed that the data received from other servers is valid by Unreal. Granted, this isn't necessarily a sane approach, and 3.2 addresses some of this issue, but this is not a bug. The solution is don't inject invalid data using raw, or more importantly, only give intelligent people access to the raw command.

Issue History

Date Modified Username Field Change
2003-04-11 21:48 codemastr Assigned To => luke
2003-04-11 21:48 codemastr Status new => assigned
2003-04-11 22:11 luke Status assigned => resolved
2003-04-11 22:11 luke Resolution open => no change required
2003-04-11 22:11 luke Note Added: 0002279
2003-11-20 19:46 syzop Status resolved => closed