feat: dedicated server security hardening
Comprehensive security system to protect against packet-sniffing attacks, XUID harvesting, privilege escalation, bot flooding, and XUID impersonation. - Stream cipher: per-session XOR cipher with 4-message handshake via CustomPayloadPacket (MC|CKey, MC|CAck, MC|COn). Negotiated per-connection, backwards compatible (old clients/servers fall back to plaintext). - Security gate: buffers all game data until cipher handshake completes, preventing unsecured clients from receiving any XUIDs or game state. - Cipher handshake enforcer: kicks clients that don't complete the handshake within 5 seconds (configurable via require-secure-client). - Identity tokens: persistent per-XUID tokens in identity-tokens.json, issued over the encrypted channel, verified on reconnect. Prevents XUID replay attacks. Client stores server-specific tokens. - PROXY protocol v1: parses real client IPs from playit.gg tunnel headers so rate limiting, IP bans, and XUID spoof detection work per-player. - Rate limiting: per-IP sliding window (default 5 connections/30s) with pending connection cap (default 10). - Privilege hardening: OP requires ops.json, live checks on every command and privilege packet. Host-only server settings changes. - XUID stripping: PreLoginPacket response sends INVALID_XUID placeholders. - Packet validation: readUtf global string cap, reduced max packet size, stream desync protection on oversized strings. - OpManager: persistent ops.json with XUID-based OP list. - Whitelist improvements: whitelist add accepts player names with ambiguity detection, XUID cache from login attempts. - revoketoken command: revoke identity tokens for players who lost theirs. - server.log: persistent log file written alongside console output with flush-per-write to survive crashes. - CLI security logging: consolidated per-join security summary with cipher status, token status, XUID, and real IP. Security warnings for kicks, spoofing, and unauthorized commands.
This commit is contained in:
@@ -14,7 +14,16 @@ const wstring CustomPayloadPacket::SET_ADVENTURE_COMMAND_PACKET = L"MC|AdvCdm";
|
||||
const wstring CustomPayloadPacket::SET_BEACON_PACKET = L"MC|Beacon";
|
||||
const wstring CustomPayloadPacket::SET_ITEM_NAME_PACKET = L"MC|ItemName";
|
||||
|
||||
const wstring CustomPayloadPacket::CIPHER_KEY_CHANNEL = L"MC|CKey";
|
||||
const wstring CustomPayloadPacket::CIPHER_ACK_CHANNEL = L"MC|CAck";
|
||||
const wstring CustomPayloadPacket::CIPHER_ON_CHANNEL = L"MC|COn";
|
||||
|
||||
const wstring CustomPayloadPacket::IDENTITY_TOKEN_ISSUE = L"MC|CTIssue";
|
||||
const wstring CustomPayloadPacket::IDENTITY_TOKEN_CHALLENGE = L"MC|CTChallenge";
|
||||
const wstring CustomPayloadPacket::IDENTITY_TOKEN_RESPONSE = L"MC|CTResponse";
|
||||
|
||||
CustomPayloadPacket::CustomPayloadPacket()
|
||||
: length(0)
|
||||
{
|
||||
}
|
||||
|
||||
@@ -22,6 +31,7 @@ CustomPayloadPacket::CustomPayloadPacket(const wstring &identifier, byteArray da
|
||||
{
|
||||
this->identifier = identifier;
|
||||
this->data = data;
|
||||
this->length = 0;
|
||||
|
||||
if (data.data != nullptr)
|
||||
{
|
||||
|
||||
@@ -17,6 +17,16 @@ public:
|
||||
static const wstring SET_BEACON_PACKET;
|
||||
static const wstring SET_ITEM_NAME_PACKET;
|
||||
|
||||
// Security: stream cipher handshake channels
|
||||
static const wstring CIPHER_KEY_CHANNEL; // server->client: carries 16-byte key
|
||||
static const wstring CIPHER_ACK_CHANNEL; // client->server: ack (empty payload)
|
||||
static const wstring CIPHER_ON_CHANNEL; // server->client: activation signal (empty payload)
|
||||
|
||||
// Security: identity token channels
|
||||
static const wstring IDENTITY_TOKEN_ISSUE; // server->client: issue new 32-byte token
|
||||
static const wstring IDENTITY_TOKEN_CHALLENGE; // server->client: request stored token
|
||||
static const wstring IDENTITY_TOKEN_RESPONSE; // client->server: present stored token
|
||||
|
||||
wstring identifier;
|
||||
int length;
|
||||
byteArray data;
|
||||
|
||||
@@ -401,20 +401,32 @@ void Packet::writeUtf(const wstring& value, DataOutputStream *dos) // throws IOE
|
||||
|
||||
wstring Packet::readUtf(DataInputStream *dis, int maxLength) // throws IOException TODO 4J JEV, should this declare a throws?
|
||||
{
|
||||
// Global safety cap to prevent memory exhaustion from malicious string lengths
|
||||
static const int kMaxGlobalStringLength = 8192;
|
||||
if (maxLength > kMaxGlobalStringLength)
|
||||
{
|
||||
maxLength = kMaxGlobalStringLength;
|
||||
}
|
||||
|
||||
short stringLength = dis->readShort();
|
||||
if (stringLength > maxLength || stringLength <= 0)
|
||||
if (stringLength <= 0)
|
||||
{
|
||||
return L"";
|
||||
// throw new IOException( stream.str() );
|
||||
if (stringLength < 0)
|
||||
{
|
||||
app.DebugPrintf("SECURITY: readUtf received negative string length %d\n", stringLength);
|
||||
}
|
||||
return L"";
|
||||
}
|
||||
if (stringLength < 0)
|
||||
if (stringLength > maxLength)
|
||||
{
|
||||
assert(false);
|
||||
// throw new IOException(L"Received string length is less than zero! Weird string!");
|
||||
app.DebugPrintf("SECURITY: readUtf received string length %d exceeding max %d\n", stringLength, maxLength);
|
||||
// Consume the declared bytes to keep the stream synchronized
|
||||
dis->skip(static_cast<int64_t>(stringLength) * 2);
|
||||
return L"";
|
||||
}
|
||||
|
||||
wstring builder = L"";
|
||||
builder.reserve(stringLength);
|
||||
for (int i = 0; i < stringLength; i++)
|
||||
{
|
||||
wchar_t rc = dis->readChar();
|
||||
|
||||
@@ -6,7 +6,7 @@
|
||||
|
||||
|
||||
|
||||
PreLoginPacket::PreLoginPacket()
|
||||
PreLoginPacket::PreLoginPacket()
|
||||
{
|
||||
loginKey = L"";
|
||||
m_playerXuids = nullptr;
|
||||
@@ -20,7 +20,7 @@ PreLoginPacket::PreLoginPacket()
|
||||
m_netcodeVersion = 0;
|
||||
}
|
||||
|
||||
PreLoginPacket::PreLoginPacket(wstring userName)
|
||||
PreLoginPacket::PreLoginPacket(wstring userName)
|
||||
{
|
||||
this->loginKey = userName;
|
||||
m_playerXuids = nullptr;
|
||||
@@ -34,7 +34,7 @@ PreLoginPacket::PreLoginPacket(wstring userName)
|
||||
m_netcodeVersion = 0;
|
||||
}
|
||||
|
||||
PreLoginPacket::PreLoginPacket(wstring userName, PlayerUID *playerXuids, DWORD playerCount, BYTE friendsOnlyBits, DWORD ugcPlayersVersion,char *pszUniqueSaveName, DWORD serverSettings, BYTE hostIndex, DWORD texturePackId)
|
||||
PreLoginPacket::PreLoginPacket(wstring userName, PlayerUID *playerXuids, DWORD playerCount, BYTE friendsOnlyBits, DWORD ugcPlayersVersion,char *pszUniqueSaveName, DWORD serverSettings, BYTE hostIndex, DWORD texturePackId)
|
||||
{
|
||||
this->loginKey = userName;
|
||||
m_playerXuids = playerXuids;
|
||||
|
||||
Reference in New Issue
Block a user