View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0000566 | unreal | ircd | public | 2002-12-21 16:37 | 2003-11-20 19:46 |
| Reporter | DJMystic | Assigned To | luke | ||
| Priority | normal | Severity | crash | Reproducibility | always |
| Status | closed | Resolution | no change required | ||
| Summary | 0000566: [stable] Crash with operserv | ||||
| Description | I have a really stupid service root, which made a stupid typo and did: /msg operserv raw : join #weazenet and he was suprised that the servr crashed.. but anyways, should this really crash the server? couldn't anyone make a little protection against this? because if linkers could also do that, they would be able to fuck up my whole network | ||||
| Steps To Reproduce | /msg operserv raw : join #channel | ||||
| Additional Information | its stupid :D | ||||
| 3rd party modules | |||||
|
|
Most service packages clearly state that using raw injection of commands to the uplink server can cause a big mess. That's why some services keep the raw command disabled by default. Using raw commands makes your services uplink to believe it's receiving commands by a server; usually, server-server communications are stable by definition, ie. no server will send you corrupted commands, so there's no need to "check" data coming from a server. If the 'server', being impersonated by a stupid admin, ends up crashing, then you have two choices: 1. choose your admins with more care. 2. disable the raw command completely (why would you need it anyway?) |
|
|
#SNIP# usually, server-server communications are stable by definition, ie. no server will send you corrupted commands #SNIP# That's exactly why Unreal received a nice entry on bugtraq ;-) |
|
|
An issue of which I had mailed to coders list at 2002-03-04 (the bugtraq posting is of 2002-07-19), however I didn't get a response back then. it was patched at 2002-09-06 when I started playing with UnrealIrcd source again. I however don't do Unreal 3.1.x, sorry ;P. I should however repeat that the bugtraq post was stupid because: 1. You need to link a server in order to connect, you can only do that if you know the password or can snif... In both cases I see no reason why one would crash a server instead of abusing. 2. You cannot execute any code by it because it's a null pointer dereference bug IIRC. |
|
|
however however however however however I think I should get some sleep. |
|
|
Bugtraq (imho) is now notorious for 'fake' bugs. For example they reported an exploit in a function in Unreal a while back. So I looked, well the code they were claiming was exploitable wasn't in use since Unreal 3.0 yet the bugtraq said it was reproducable under 3.2 and 3.1.2. Not only that, the code was only used (in 3.0) under windows, yet bugtraq said it was reproducable under any OS. And even further, the code could only be exploitable if it was used incorrectly, and it wasn't. So basically someone wrote in a completely fake bug report and they accepted it. I take everything they post with a grain of salt after that.... |
|
|
Exactly, I guess they didn't even update it after my reply :(. Maybe we can expect a "format string bug in sendto_one" this year, lol ;P. |
|
|
It is assumed that the data received from other servers is valid by Unreal. Granted, this isn't necessarily a sane approach, and 3.2 addresses some of this issue, but this is not a bug. The solution is don't inject invalid data using raw, or more importantly, only give intelligent people access to the raw command. |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2003-04-11 21:48 |
|
Assigned To | => luke |
| 2003-04-11 21:48 |
|
Status | new => assigned |
| 2003-04-11 22:11 | luke | Status | assigned => resolved |
| 2003-04-11 22:11 | luke | Resolution | open => no change required |
| 2003-04-11 22:11 | luke | Note Added: 0002279 | |
| 2003-11-20 19:46 | syzop | Status | resolved => closed |