konsolas / AAC-Issues

AAC Issue Tracker.
32 stars 15 forks source link

Server crash #494

Closed MedicOP closed 7 years ago

MedicOP commented 7 years ago

Edit by staff: Outsourced crash thread dump, pulled up temporary solution

Crash log: https://gist.github.com/Janmm14/aaa5e67cd1134dee37d0dad749a7fb25

Am I vulnerable? Very likely, although no older version of AAC were tested, its likely this crash exploit also crashes all other AAC 3.x versions,

Crash fix plugin: https://cdn.discordapp.com/attachments/248520431986802688/291530017740029952/aacanticrash-1.0-SNAPSHOT.jar (Author: geNAZt from GommeHD.net) The crash fix plugin is not doing any harm to your server, it just blocks some packets normal clients would never send.

Core information

Server version: 1.8.8

AAC version: 3.0.5-b1

ProtocolLib version: 4.2.0

ViaVersion version: 1.0.3

MedicOP commented 7 years ago

Have been told it's caused by the AAC crash exploit currently present.

dnil-io commented 7 years ago

Does this only affect AAC 3.0.5-b1? Having the same issue. Would downgrading to 3.0 help, until there is a fix out?

MedicOP commented 7 years ago

You can use this fix, just install it as a plugin https://cdn.discordapp.com/attachments/248520431986802688/291530017740029952/aacanticrash-1.0-SNAPSHOT.jar

dnil-io commented 7 years ago

OMG THANKS <3 :D

dnil-io commented 7 years ago

Okay, completely saved my day. Thank you really sooo much. Love from the bizziTV server team :)

MedicOP commented 7 years ago

I didn't make it btw, think GommeHD did

Janmm14 commented 7 years ago

Yes the file is form GommeHd.net's lead developer.

Janmm14 commented 7 years ago

Reopened since its not fixed in AAC itself yet.

JamieSinn commented 7 years ago

@konsolas any update on this?

Janmm14 commented 7 years ago

@JamieSinn He is aware of the exploit, but unfortunaly he is moving house atm and has no good internet connection. The temporary (but effective) solution is to use the aacanticrash plugin.