#BCS server issue

1453 messages Β· Page 2 of 2 (latest)

onyx anchor
#

apparently older versions are suspected to crash.. vishal found commit in official ballistica repository which fixed the specdata issue which is suspected to cause the restarting problem.. so it's going all good

warm sigil
#

we thought it was only bcs but then stratex said his servers are crashing too

mild hazel
#

Else we cooked

white arch
warm sigil
#

"servers arent crashing"

reef apex
#

ahh dazz a bummer... n here i was thinkin only my servers survivin dis sheet ASevil

white arch
onyx anchor
#

The guy behind finding this exploit must be a genius

warm sigil
#

but for some reason i am getting 6k ping

jade mountain
mild hazel
#

Btw who is this new Fang guy

slow wave
#

im doing too

white arch
reef apex
warm sigil
#

no body knows u ig

reef apex
#

i literally retired in 2021 okk

slow wave
onyx anchor
white arch
mild hazel
wispy socket
slow wave
#

its Bombsquad that doesnt have proper protection from this simple atttacks..

reef apex
floral wind
#

Hey guys
If u can figure out the ip
Maybe with arp -a on multiple servers and check for common ip
Then u can ip ban that guy with sudo iptables -A INPUT -s [IP_ADDRESS] -j DROP

mild hazel
warm sigil
#

yep

white arch
#

wait lemme check the traffic i didnt checked yet

mild hazel
floral wind
mild hazel
onyx anchor
white arch
reef apex
floral wind
reef apex
#

i just started makin api9 scripts last month

white arch
floral wind
reef apex
#

tho am wonderin if i should keep it opensource since crezy ppl be findin loopholes

onyx anchor
reef apex
warm sigil
#

@reef apex btw your "boxing" still have bombs peeyus

white arch
#

wen will smoothly wake up

reef apex
warm sigil
onyx anchor
#

You guys should go to general.. people trying to find solutions here

flint shale
warm sigil
#

vishu is trying that empty Playerspec

onyx anchor
warm sigil
#

@white arch

white arch
mild hazel
warm sigil
#

are you getting this

floral wind
warm sigil
#

VerifyClientAddr() found mismatch for client 128.

white arch
onyx anchor
#

@floral wind

flint shale
warm sigil
onyx anchor
slow wave
floral wind
slow wave
#

layer 2

#

n 3

wispy socket
#

hmm, the empty playerspec worked a bit because it crashed the server... didn't replicate the repeated crashing

flint shale
#

I once crashed a server just by spamming buttons πŸ˜‚πŸ˜‚

onyx anchor
mild hazel
wispy socket
slow wave
#

but like nothing happens

reef apex
slow wave
#

lemme try again

flint shale
wispy socket
#

it worked on bcs # teams

onyx anchor
# mild hazel Tell / list them

game has v2 accounts, api is rapidly changing, new currency in the game, new chest system.. online mods repository.. asset packages online..

flint shale
#

Me and yoyo raised the issue and gathered info

wispy socket
#

@slow wave which server do you want me to do the empty playerspec attack, tell one of your server

onyx anchor
onyx anchor
#

what to do

slow wave
#

wait

#

we already testing

white arch
#

only yoyo

#

so change bcs to ycs

mild hazel
floral wind
wispy socket
onyx anchor
floral wind
onyx anchor
reef apex
wispy socket
mild hazel
warm sigil
reef apex
wispy socket
warm sigil
#

i was sharing that server's ss only

onyx anchor
floral wind
#

If any of u can run the server with gdb then it will tell you exactly where it broke
So next time this happened try that

heavy fern
#

.

slow wave
#

i mean

floral wind
#

It won't

slow wave
#

depends on what u mean

warm sigil
#

@onyx anchor @wispy socket there is one more weird thing happening with our servers i need help with peeyus

copper pewterBOT
#
indxpiyush has been warned

Reason: Mass mention

flint shale
warm sigil
warm sigil
mild hazel
warm sigil
#

we banned him like 8-10 times

#

still that guy not only joins

#

but spam abuses in the server

floral wind
warm sigil
#

bypassing the chat filter

wispy socket
flint shale
warm sigil
warm sigil
#

same pb id

slow wave
wispy socket
#

id ban him

warm sigil
#

same ip and device id

flint shale
#

Ban device id

slow wave
#

who are u talkin about?

flint shale
#

Demn

warm sigil
slow wave
#

oh

#

ok

strange loomBOT
#
KINGUS

Id: pb-IF4LU04EHw==
Name: KINGUS
Accounts: bs_v2accountIronPilot7
Created: 2 years 2 months 5 days ago
Possible Discord Ids:

flint shale
slow wave
warm sigil
slow wave
#

u use cisco packet tracer?

heavy fern
flint shale
#

We needed ur help

#

Now giv solution

reef apex
flint shale
#

The best modder

heavy fern
#

Try switch off switch on

flint shale
#

πŸ˜‚πŸ€£πŸ€£πŸ€£

heavy fern
floral wind
white arch
onyx anchor
floral wind
reef apex
#

abandon bcs n use feng's scripts...

onyx anchor
#

🀏 πŸ’

reef apex
past coralBOT
#

πŸŽ‰ | Fang leveled up!

reef apex
#

am bored... @onyx anchor coop?

#

we lost multiple yesterday :/

#

its not fun to pley next ones widout completin previous lvls >.<

flint shale
#

Use watermelon script instead of vanilla

warm sigil
flint shale
#

Btw where do u play nowadays haven't played for long with u

warm sigil
#

add bs-dc bridge

#

and ill use it

white arch
#

alr my dear boiz gn tc i have school tomorrow

#

@warm sigil @flint shale @reef apex

copper pewterBOT
#
yoyo2410 has been warned

Reason: Mass mention

white arch
#

@floral wind

warm sigil
#

werent you in college

white arch
#

@wispy socket

flint shale
#

Gn

white arch
warm sigil
white arch
#

jk lol am graduated

reef apex
flint shale
#

Oow

#

Ookk

flint shale
#

πŸ˜©πŸ˜­πŸ’”

#

I don't have another pc or laptop

slow wave
flint shale
#

I called someone let's see if he comes or not

wispy socket
#

damn

slow wave
white arch
#

no issues

slow wave
#

wdym no issues lol

white arch
#

i dont see any kinda of abnormal incoming traffic

flint shale
slow wave
#

u have to see when event happens

reef apex
white arch
floral wind
white arch
reef apex
slow wave
#

i mean

#

mainly yes

#

but not only ofc ☠️

#

tcp is useless for bs

#

except for cycle https reqs

rotund minnow
#

At the end of the day, someone crashed all the bcs servers and vanished

reef apex
#

@flint shale we pleyin atm... join if u would like, cyklons epic ffa nod

flint shale
onyx anchor
#

people are trying the specdata thing

rotund minnow
warm sigil
#

we havent discussed about him yet

onyx anchor
#

no idea but hope so

warm sigil
#

yea

#

need to find a solution about this romanpc first

#

i like how the name patterns are same

#

Aamir Mac

#

Roman Pc

#

lol

heavy fern
#

Guys servers should be back check

warm sigil
#

hail lord hikaru Pray

slate archBOT
white arch
#

@onyx anchor @wispy socket again

copper pewterBOT
#
yoyo2410 has been warned

Reason: Mass mention

rotund minnow
white arch
#

see msg time

#

in tht

rotund minnow
#

need to check server status then

white arch
#

now need to reset again

warm sigil
wispy socket
warm sigil
rotund minnow
warm sigil
#

@rotund minnow you might get that message too

rotund minnow
rotund minnow
white arch
#

alr am sleepy i will go now

#

i have to lead the mrng prayer in my school

reef apex
white arch
#

gn tc

rotund minnow
white arch
#

wait

#

@reef apex

reef apex
rotund minnow
#

@warm sigil strange how BCS id is just before that

rotund minnow
strange loomBOT
#
<:bs_v2account:982402470070341662>BCS

Id: pb-IF4iU0QaEw==
Name: bs_v2accountBCS
Accounts: bs_v2accountBCS
Created: 2 years 4 months 4 days ago
Possible Discord Ids:

warm sigil
#

the crash*

warm sigil
#

according to Vishu

#

which is fixed by eric in recents updates

wispy socket
#

okay now, let me get my dinner and set up some stuff and let's test shit

reef apex
# white arch <@927861412070584391>

their joinin servers is passin some request to api which is not satisfyin the defined headers n conditions... i did encounter few of doz "precondition errors" while dealin wid threadin code but still cant say for certain wot excatly iz causin this thonkk

reef apex
floral wind
#

@white arch i am taking 1 server process down for a moment

white arch
#

use tht smash itself ok

floral wind
#

okk

median gorge
#

did you get it or you want it still?

floral wind
#

bruh did no one send traceback in text

wispy socket
median gorge
#

uh

floral wind
#

0x5e02288a27cd

#

@white arch dont stop the smash tmux session

warm sigil
floral wind
#

no i ran the server in gdb

warm sigil
#

And?

floral wind
#

hopefully if it happens again then we will see some useful info

warm sigil
#

oh

#

ok

#

I wonder if that dude comeback again

#

He clearly stopped because of idk the creator of that tool or what

floral wind
#
FATAL ERROR: Unable to bind to requested udp port 61325 (ipv4)
STACK-TRACE-BEGIN:
./bombsquad_headless(+0x1f37cd) [0x651ddd0257cd]
./bombsquad_headless(+0x11efba) [0x651ddcf50fba]
./bombsquad_headless(+0x11ccc2) [0x651ddcf4ecc2]
./bombsquad_headless(+0x1eacf5) [0x651ddd01ccf5]
./bombsquad_headless(+0x1eb084) [0x651ddd01d084]
./bombsquad_headless(+0x1ee04f) [0x651ddd02004f]
/lib/x86_64-linux-gnu/libstdc++.so.6(+0xdc253) [0x7ae4da2dc253]
/lib/x86_64-linux-gnu/libc.so.6(+0x94ac3) [0x7ae4d9e94ac3]
/lib/x86_64-linux-gnu/libc.so.6(+0x126850) [0x7ae4d9f26850]
STACK-TRACE-END
Server subprocess exited with code 1.

floral wind
#

nothing

#

idk the python wrapper is making it impossible to debug

#
Traceback (most recent call last):
  File "/usr/lib/python3.10/threading.py", line 1016, in _bootstrap_inner
Exception in thread Thread-6 (_populateQueue):
Traceback (most recent call last):
  File "/usr/lib/python3.10/threading.py", line 1016, in _bootstrap_inner
    self.run()
  File "/usr/lib/python3.10/threading.py", line 953, in run
    self.run()
  File "/usr/lib/python3.10/threading.py", line 953, in run
    self._target(*self._args, **self._kwargs)
  File "/home/ubuntu/smash/nbstreamreader.py", line 25, in _populateQueue
    self._target(*self._args, **self._kwargs)
    raise UnexpectedEndOfStream
nbstreamreader.UnexpectedEndOfStream
  File "/home/ubuntu/smash/nbstreamreader.py", line 25, in _populateQueue

floral wind
floral wind
#

also it randomly fails to bind

warm sigil
#

when you ctrl z ./bombsquad_server

#

I usually kill tmux session

#

And launch again

#

And it get fixed

floral wind
#

no i didnt backgraound it

warm sigil
#

then

floral wind
#

idk

warm sigil
#

Did u added the -s?

floral wind
#

do i need to specify port when creating new tmux session?

warm sigil
#

tmux new -s 43210

warm sigil
#

did it worked?

#

earlier it used to work without -s

floral wind
#

guys who are here
can you set ERROR_LOGGING=True in bombsquad_server file

#

well anyways whatever it was i didnt see it

median gorge
#

hey

#

he was just on a min ago

white arch
#

U can use anything in the place of port

#

I use the server name

#

Like fumi

#

Smash

#

Like tht

white arch
#

Ig it works still for single session

#

But i run 3-4 sessions in same instance

white arch
#

U will get tht headless session if u use tht method

#

It stops the session but it won't kill the session if u do in tht way always kill the session and start new one

white arch
#

I will give some session cmds

copper pewterBOT
#
yoyo2410 has been warned

Reason: Duplicated text

white arch
#

@warm sigil

white arch
#

@floral wind @wispy socket

copper pewterBOT
#
yoyo2410 has been warned

Reason: Mass mention

white arch
#

upgrading the package didnt work yesterday ig

#

it was the reboot

warm sigil
flint shale
flint shale
#

Or idk

floral wind
#

So we still in the valid range

#

An unsigned 16 bit integer is used to store it
That's where the limit comes from

reef apex
#

so at the end dat bot was just sending some garbage value(invalid profile name or smtg iirc) for which scripts dint hav proper input validation... n eric fixed it in newer versions? or did i miss smtg peeyus

white arch
reef apex
#

use screen instead of tmux... its much simpler nod

white arch
reef apex
# wispy socket not sure

it seems so... precondition failed in object_input (am assumin invalid profile but can be smtg else)... unhandled exception; lack of dat input validation... erics fix accordin to that commit: person sends garbage value -> yeet him

floral wind
wispy socket
#

hmm

flint shale
#

Oo

jade mountain
#

can anyone tell me what is going on now😭

wispy socket
#

and if the attacker thinks of attacking, then he will

jade mountain
wispy socket
#

bruh

jade mountain
#

wot

slate archBOT
jade mountain
#

so all bs servers are on the mercy of one guy rn? 😭

earnest sand
#

Version ?

rotund minnow
#

Apparantly not in api 9

earnest sand
#

Some other chat group saying this error happening even on Vanilla server

#

And is due to some type of spam

wispy socket
wispy socket
#

but ik that this empty playerspec is a threat for crashing bcs servers

#

because... tested, so yeah

onyx anchor
#

even if it's not relevant I want to share it.. people can just change into my id on the server.

onyx anchor
wispy socket
#

well kinda but not really...

wispy socket
# onyx anchor ?

nothing nvm, just wanted to say you didn't have to mention it but okay

earnest sand
onyx anchor
white arch
earnest sand
#

Anyways back to topic

white arch
#

we already spoke abt this issue 2 years ago

wispy socket
white arch
#

now its not happening idk how it is stopped

wispy socket
#

not really cryptography side

white arch
#

last time also it was stopped after some days

#

like almost it took 2 - 3 days

earnest sand
#

Server get pb-id only from master server.
If some one able to use someone else pb-id then he really have that account credentials

wispy socket
#

need more security with this

earnest sand
white arch
reef apex
earnest sand
#

No, and nothing to discuss on this it slike this form benning and no issue in that

slow wave
#

so stupid exploit...

#

like there is not certificate during initial exchange

#

....

#

i already said this to Eric some weeks ago

#

but i dont think he got time to do something abt it

white arch
#

@wispy socket

#

i got this issue

#

again

#

today

#

@reef apex

earnest sand
#

Is it something with new exploit that's fixe din 1.7.41 ?

#

Error message might be a bit different

reef apex
white arch
#

Oh ok thx

white arch
white arch
#

happening in all servers

onyx anchor
#

Update to latest version

white arch
#

check

#

it is happening in vanilla as well

#

happening when bcs joins

#

@earnest sand

earnest sand
earnest sand
# white arch happening when bcs joins

Bcs iterates public party list,
And that exploit bot also iterate public party list.
That's the only relation between bcs and server crash.

Exploit is about invalid player spec when joining the server , so that player account won't be visible in party window

white arch
#

@earnest sand

#

attack stopped

#

i mean i enabled ufw rule

#

for my port

floral wind
white arch
#

coz ima upgrade my script

floral wind
white arch
#

did someone rm my bs owner role

white arch
floral wind
#

I was jk, ufw is good

floral wind
white arch
#

ikik but i have tested it earlier as well, it can drop ips , but if it is frm more ips it becomes hard for it

white arch