Forum


Notice to all users

We are migrating towards a new forum system located at community.teamspeak.com, as such this forum will become read-only on January 29, 2020

Results 1 to 3 of 3
  1. #1
    Join Date
    October 2014
    Posts
    10

    Filetransfer exploit?

    I have disabled filetransfer for normal users. At that time I was running server version 3.0.11.4 . Since I got no answers when googleing for this error I thought, might as well post about it here. Maybe it hasn't been fixed in the newer version.
    This was in my logs before the server crashed. Didn't think it was an attack at that time

    Code:
    2016-02-12 20:45:20.618765|ERROR   |FileManager   |   | select() failed Bad file descriptor
    2016-02-12 20:45:20.625791|ERROR   |FileManager   |   | select() failed Bad file descriptor
    2016-02-12 20:45:20.635050|ERROR   |FileManager   |   | select() failed Bad file descriptor
    2016-02-12 20:45:20.711667|ERROR   |FileManager   |   | select() failed Bad file descriptor
    2016-02-12 20:45:20.759764|ERROR   |FileManager   |   | select() failed Bad file descriptor
    2016-02-12 20:45:20.888117|ERROR   |FileManager   |   | select() failed Bad file descriptor
    2016-02-12 20:45:21.309319|ERROR   |FileManager   |   | select() failed Bad file descriptor
    2016-02-12 20:45:21.562294|ERROR   |FileManager   |   | select() failed Bad file descriptor
    2016-02-12 20:45:21.707894|ERROR   |FileManager   |   | select() failed Bad file descriptor
    Since i was SSH-d into my vps I had server running up again almost instantly. Then i saw that the new logfile was abnormally large.
    It had the same error but 12000 lines of it, after the server had been running for only ~2 mins.
    Cause of this attack there were 3.5k+ processes running(I guess every filetransfer makes a new thread). My CPU spiked to 100% usage at times. This is the packet the attacker was sending (removed just in case)
    I have a tcpdump file from the time of attack. If devs want to take a look at it PM me.

  2. #2
    Join Date
    April 2013
    Posts
    43
    Hi. I have version 3.0.12.1 and:

    Code:
    |2016-02-12 16:38:02.866090|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866152|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866177|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866199|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866243|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866278|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866303|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866325|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866348|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866369|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866389|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866409|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866434|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866454|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866587|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866626|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866647|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866670|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866694|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866746|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866787|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866808|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866828|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.866848|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.867506|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.867541|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.867563|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.867598|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.867622|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.867642|ERROR   |FileManager   |   |accept() failed: 24
    2016-02-12 16:38:02.867688|ERROR   |FileManager   |   |accept() failed: 24
    Locked port 30033 helped, but this is not the way ... I think it's a new bug or exploit

  3. #3
    Join Date
    June 2011
    Location
    Germany
    Posts
    4,368
    You can try using a non-default file-transfer port as a quick workaround.

    However, I'm not sure what exactly this is. I just tried connecting to the filetransfer port with telnet and enter an invalid key, but nothing happened. I just got disconnected as the key was invalid. Nothing showed up in the logs.

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. Replies: 1
    Last Post: July 10th, 2015, 06:35 PM
  2. [No Bug] Filetransfer exploit?
    By Roundie in forum General Questions
    Replies: 39
    Last Post: January 28th, 2013, 06:28 PM

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •