View Issue Details
| ID | Project | Category | View Status | Date Submitted | Last Update |
|---|---|---|---|---|---|
| 0000871 | unreal | ircd | public | 2003-04-06 22:58 | 2003-11-20 19:46 |
| Reporter | shotgun | Assigned To | syzop | ||
| Priority | normal | Severity | crash | Reproducibility | always |
| Status | closed | Resolution | fixed | ||
| Product Version | 3.2-beta15 | ||||
| Summary | 0000871: Crash when connecting to SSL port | ||||
| Description | While attempting to connect to SSL-enabled Unreal-Devel IRC server using stunnel (with mirc script which can be found at http://www.mircscripte.de/files/addons/ssl.zip) the unreal will crash right after the message "Found your hostname". | ||||
| Steps To Reproduce | Install the script, connect to unreal-devel ssl server=|. | ||||
| Additional Information | [Metnix:shotgun:~/ircd/Unreal] gdb ./src/ircd core [...snap snap...] (gdb) bt #0 ssl_get_cipher (ssl=0x823be08) at ssl.c:362 #1 0x080a1c17 in register_user (cptr=0x823ba68, sptr=0x823ba68, nick=0x823ba91 "Shotygun", username=0x823bb51 "Shotgun", umode=0x0, virthost=0x0) at s_user.c:1013 #2 0x080a3920 in m_user (cptr=0x823ba68, sptr=0x823ba68, parc=5, parv=0x81c2f80) at s_user.c:1988 #3 0x080806e1 in parse (cptr=0x823ba68, buffer=0x823bb4c "USER", bufend=0x823bb82 "") at parse.c:466 #4 0x0807f247 in dopacket (cptr=0x823ba68, buffer=0x81c3920 "USER Shotgun \"shotgun\" \"localhost\" :- Grand Master S -\n", length=55) at packet.c:137 #5 0x08085ac9 in read_packet (cptr=0x823ba68, rfd=0x5a7acaec) at s_bsd.c:1459 #6 0x0808625f in read_message (delay=1, listp=0x81f18e0) at s_bsd.c:1905 #7 0x0807cbe9 in main (argc=1, argv=0x5a7acc44) at ircd.c:1336 0000008 0x2284d571 in __libc_start_main (main=0x807bd10 <main>, argc=1, ubp_av=0x5a7acc44, init=0x806849c <_init>, fini=0x8119b90 <_fini>, rtld_fini=0x227c4a24 <_dl_fini>, stack_end=0x5a7acc3c) at ../sysdeps/generic/libc-start.c:129 (gdb) Stunnel log: Using 'irc.metnix.com.6601' as tcpwrapper service name stunnel 3.8p4 on x86-pc-mingw32-gnu WIN32 irc.metnix.com.6601 connected from 127.0.0.1:3941 Connection closed: 69 bytes sent to SSL, 116 bytes sent to socket irc.metnix.com.6601 connected from 127.0.0.1:3943 remote connect: Unknown error (10061) irc.metnix.com.6601 connected from 127.0.0.1:3945 remote connect: Unknown error (10061) | ||||
| Attached Files | 871-unrealircd.conf.cen (2,909 bytes) 871-unrealircd.conf.cen (2,909 bytes) | ||||
| 3rd party modules | |||||
|
|
* Can you upload your configfile (with oper and link blocks removed and cloak keys changed) so I can see if I can reproduce it here. * Oh and what openssl version are you using? |
|
|
OpenSSL 0.9.7a Feb 19 2003 |
|
|
Ok, it doesn't crash here, BUT I don't use/have your unreal.req.pem, unreal.key.pem (and networks/alteril.network), so one of that could be the problem... You can mail them to [email protected] / [email protected] if you trust me enough ;). And, can you open the core file again (gdb src/ircd core) and type: frame 0 p *ssl Thanks :P |
|
|
Hmm, well I have seen this before, except the last time I saw this it was caused by an SSL server, not an SSL client. But let me paste the info I got anyway: $1 = {version = 769, type = 8192, method = 0x81dc340, rbio = 0x821d620, wbio = 0x821d620, bbio = 0x0, rwstate = 1, in_handshake = 0, handshake_func = 0x80bd750 <ssl3_accept>, server = 1, new_session = 0, quiet_shutdown = 0, shutdown = 0, state = 3, rstate = 240, init_buf = 0x0, init_num = 136435676, init_off = 0, packet = 0x0, packet_length = 136457736, s2 = 0x0, s3 = 0x0, read_ahead = 136434552, hit = 0, purpose = 0, trust = 0, cipher_list = 0x0, cipher_list_by_id = 0x0, enc_read_ctx = 0x0, read_hash = 0x0, expand = 0x0, enc_write_ctx = 0x822e250, write_hash = 0x8127460, compress = 0x0, cert = 0x822e2e0, sid_ctx_length = 135427168, sid_ctx = "\000\000\000\000\210Â!\b", '\000' <repeats 23 times>, session = 0x0, verify_mode = 0, verify_depth = 0, verify_callback = 0x822dfa8, info_callback = 0, error = 5, error_code = -1, ctx = 0x809a3c0, debug = 0, verify_result = 0, ex_data = {sk = 0x0, dummy = 136404616}, client_CA = 0x0, references = 0, options = 0, mode = 0, first_packet = 0, client_version = 1} Note how the overall struct is correct, the problem lies in the ssl->session == 0x0, because ssl_get_cipher checks that to get the version of SSL that the user is connecting with, I'll look on the OpenSSL site, maybe there is another way to get this information more reliably, meaning maybe it isn't a problem that it == 0x0, maybe we just aren't supposed to be accessing it. |
|
|
Ok, having just looked through some OpenSSL documentation, I see there is a function SSL_get_version, which does exactly what we wanted to do. I looked at the source code for SSL_get_version, and it checks ssl->version NOT ssl->session->ssl_version, and if you look in that dump I pasted, ssl->version IS valid. So I'm gonna trust the people who wrote OpenSSL and assume they know better than we did. :) In any case, can you upgrade to the current cvs version and tell me if this still exists? |
|
|
Works, thanks =) |
| Date Modified | Username | Field | Change |
|---|---|---|---|
| 2003-04-08 23:38 |
|
Note Added: 0002188 | |
| 2003-04-08 23:49 |
|
Note Added: 0002189 | |
| 2003-04-10 09:32 | shotgun | Note Added: 0002201 | |
| 2003-04-11 01:05 | syzop | Status | new => resolved |
| 2003-04-11 01:05 | syzop | Resolution | open => fixed |
| 2003-04-11 01:05 | syzop | Assigned To | => syzop |
| 2003-11-20 19:46 | syzop | Status | resolved => closed |