Jump to content

Lobby DoS


Stockfish
 Share

Recommended Posts

Today I was trying to login to the 0 A.D. Lobby until a message in red appeared. It said "the stream has been closed by the server"Screenshot_3.thumb.png.80bea95e88cbd90ad7ee56d4b31497ca.png".

I don't know what does that mean, and I'm afraid that I could be banned from there. Can I get some help about it?

Edited by iiLeonn
Missing " in the phrase
Link to comment
Share on other sites

1 hour ago, kizito said:

Oh, ok, I can now relax and maybe do other non essential tasks like preparing dinner, eating, writing reports and sleeping. Thanks for the update

I cant even delete my own posts, this is trash. see you in the game m'lords

Edited by Doonside
Link to comment
Share on other sites

I merged the three topics.

For the non-technical people this means that the lobby server required more security than Windows clients were able to provide and therefore caused a denial of service for all users that had TLS enabled. We are sorry for any inconvenience.

For those that wish to know what happened here is a short summary.

An issue occurred after an Update on the Debian VM hosting the lobby. Debian then required that all clients use TLS 1.2. Currently all users on Windows are limited to TLS 1.0 because of Gloox, which caused them to be denied access to the service.

From the debian mailing list https://lists.debian.org/debian-devel/2017/08/msg00187.html

> I've just uploaded a version of OpenSSL to unstable that disables
> the TLS 1.0 and 1.1 protocol. This currently leaves TLS 1.2 as the
> only supported SSL/TLS protocol version.
> This will likely break certain things that for whatever reason
> still don't support TLS 1.2. I strongly suggest that if it's not
> supported that you add support for it, or get the other side to
> add support for it.

elexis resolved this issue by recompiling the SSL lib without that limitation and changei

17:09 <elexis> have to compile with enable-weak-ssl-ciphers, why even update things
19:11 <elexis> /etc/ssl/openssl.cnf MinProtocol = None CipherString = DEFAULT + ejabberd restart

Another workaround was to disable TLS.

TLS.gif

  • Like 3
Link to comment
Share on other sites

  • 3 weeks later...

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

 Share

×
×
  • Create New...