View Issue Details

IDProjectCategoryView StatusLast Update
0000871unrealircdpublic2003-11-20 19:46
Reportershotgun Assigned Tosyzop  
PrioritynormalSeveritycrashReproducibilityalways
Status closedResolutionfixed 
Product Version3.2-beta15 
Summary0000871: Crash when connecting to SSL port
DescriptionWhile attempting to connect to SSL-enabled Unreal-Devel
IRC server using stunnel (with mirc script which
can be found at http://www.mircscripte.de/files/addons/ssl.zip)
the unreal will crash right after the message
"Found your hostname".
Steps To ReproduceInstall the script, connect to unreal-devel ssl server=|.
Additional Information[Metnix:shotgun:~/ircd/Unreal] gdb ./src/ircd core
  [...snap snap...]
(gdb) bt
#0 ssl_get_cipher (ssl=0x823be08) at ssl.c:362
#1 0x080a1c17 in register_user (cptr=0x823ba68, sptr=0x823ba68, nick=0x823ba91 "Shotygun", username=0x823bb51 "Shotgun",
    umode=0x0, virthost=0x0) at s_user.c:1013
#2 0x080a3920 in m_user (cptr=0x823ba68, sptr=0x823ba68, parc=5, parv=0x81c2f80) at s_user.c:1988
#3 0x080806e1 in parse (cptr=0x823ba68, buffer=0x823bb4c "USER", bufend=0x823bb82 "") at parse.c:466
#4 0x0807f247 in dopacket (cptr=0x823ba68,
    buffer=0x81c3920 "USER Shotgun \"shotgun\" \"localhost\" :- Grand Master S -\n", length=55) at packet.c:137
#5 0x08085ac9 in read_packet (cptr=0x823ba68, rfd=0x5a7acaec) at s_bsd.c:1459
#6 0x0808625f in read_message (delay=1, listp=0x81f18e0) at s_bsd.c:1905
#7 0x0807cbe9 in main (argc=1, argv=0x5a7acc44) at ircd.c:1336
0000008 0x2284d571 in __libc_start_main (main=0x807bd10 <main>, argc=1, ubp_av=0x5a7acc44, init=0x806849c <_init>,
    fini=0x8119b90 <_fini>, rtld_fini=0x227c4a24 <_dl_fini>, stack_end=0x5a7acc3c) at ../sysdeps/generic/libc-start.c:129
(gdb)

Stunnel log:
Using 'irc.metnix.com.6601' as tcpwrapper service name
stunnel 3.8p4 on x86-pc-mingw32-gnu WIN32
irc.metnix.com.6601 connected from 127.0.0.1:3941
Connection closed: 69 bytes sent to SSL, 116 bytes sent to socket
irc.metnix.com.6601 connected from 127.0.0.1:3943
remote connect: Unknown error (10061)
irc.metnix.com.6601 connected from 127.0.0.1:3945
remote connect: Unknown error (10061)
Attached Files
871-unrealircd.conf.cen (2,909 bytes)
871-unrealircd.conf.cen (2,909 bytes)
3rd party modules

Activities

syzop

2003-04-06 23:07

administrator   ~0002133

* Can you upload your configfile (with oper and link blocks removed and cloak keys changed) so I can see if I can reproduce it here.
* Oh and what openssl version are you using?

shotgun

2003-04-06 23:15

reporter   ~0002134

OpenSSL 0.9.7a Feb 19 2003

syzop

2003-04-07 01:04

administrator   ~0002137

Ok, it doesn't crash here, BUT I don't use/have your unreal.req.pem, unreal.key.pem (and networks/alteril.network), so one of that could be the problem...
You can mail them to [email protected] / [email protected] if you trust me enough ;).

And, can you open the core file again (gdb src/ircd core) and type:
frame 0
p *ssl

Thanks :P

codemastr

2003-04-08 23:38

reporter   ~0002188

Hmm, well I have seen this before, except the last time I saw this it was caused by an SSL server, not an SSL client. But let me paste the info I got anyway:

$1 = {version = 769, type = 8192, method = 0x81dc340, rbio = 0x821d620, wbio = 0x821d620, bbio = 0x0, rwstate = 1, in_handshake = 0, handshake_func = 0x80bd750 <ssl3_accept>,
server = 1, new_session = 0, quiet_shutdown = 0, shutdown = 0, state = 3, rstate = 240, init_buf = 0x0, init_num = 136435676, init_off = 0, packet = 0x0, packet_length = 136457736,
s2 = 0x0, s3 = 0x0, read_ahead = 136434552, hit = 0, purpose = 0, trust = 0, cipher_list = 0x0, cipher_list_by_id = 0x0, enc_read_ctx = 0x0, read_hash = 0x0, expand = 0x0,
enc_write_ctx = 0x822e250, write_hash = 0x8127460, compress = 0x0, cert = 0x822e2e0, sid_ctx_length = 135427168, sid_ctx = "\000\000\000\000\210Â!\b", '\000' <repeats 23 times>,
session = 0x0, verify_mode = 0, verify_depth = 0, verify_callback = 0x822dfa8, info_callback = 0, error = 5, error_code = -1, ctx = 0x809a3c0, debug = 0, verify_result = 0,
ex_data = {sk = 0x0, dummy = 136404616}, client_CA = 0x0, references = 0, options = 0, mode = 0, first_packet = 0, client_version = 1}

Note how the overall struct is correct, the problem lies in the ssl->session == 0x0, because ssl_get_cipher checks that to get the version of SSL that the user is connecting with, I'll look on the OpenSSL site, maybe there is another way to get this information more reliably, meaning maybe it isn't a problem that it == 0x0, maybe we just aren't supposed to be accessing it.

codemastr

2003-04-08 23:49

reporter   ~0002189

Ok, having just looked through some OpenSSL documentation, I see there is a function SSL_get_version, which does exactly what we wanted to do. I looked at the source code for SSL_get_version, and it checks ssl->version NOT ssl->session->ssl_version, and if you look in that dump I pasted, ssl->version IS valid. So I'm gonna trust the people who wrote OpenSSL and assume they know better than we did. :)

In any case, can you upgrade to the current cvs version and tell me if this still exists?

shotgun

2003-04-10 09:32

reporter   ~0002201

Works, thanks =)

Issue History

Date Modified Username Field Change
2003-04-08 23:38 codemastr Note Added: 0002188
2003-04-08 23:49 codemastr Note Added: 0002189
2003-04-10 09:32 shotgun Note Added: 0002201
2003-04-11 01:05 syzop Status new => resolved
2003-04-11 01:05 syzop Resolution open => fixed
2003-04-11 01:05 syzop Assigned To => syzop
2003-11-20 19:46 syzop Status resolved => closed