• Unfortunately, we have experienced significant hard drive damage that requires urgent maintenance and rebuilding. The forum will be a state of read only until we install our new drives and rebuild all the configurations needed. Please follow our Facebook page for updates, we will be back up shortly! (The forum could go offline at any given time due to the nature of the failed drives whilst awaiting the upgrades.) When you see an Incapsula error, you know we are in the process of migration.

New Agentserver crash exploit? (DoS)

Newbie Spellweaver
Joined
Oct 31, 2011
Messages
66
Reaction score
11
Hello,

i noticed that someone is crashing our servers. He is sending packets to our Server. Maybe we can discuss what can be wrong with the agentserver and how to fix it.

here a part of the logs:
Code:
"...
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! MsgID[0x6101] IP[178.33.225.84]
2012-04-25	15:09:48	[AgentServer]	WARNING!! A SUSPECT DETECTED!!! ..."

/discuss

Edit: I know that the packed 0x6101 is to request the serverstats.
 
Last edited:
Newbie Spellweaver
Joined
Oct 31, 2011
Messages
66
Reaction score
11
v188

These are the 2 OPCodes that got sended to our server:

LoginClientServerListReq = 0x6101
LoginClientAuth = 0x6102

Thank you!
 
Newbie Spellweaver
Joined
Oct 31, 2011
Messages
66
Reaction score
11
This causes an Servercrash if it appear to often. I had it like 500-600 times in an second.

I changed now our firewallsettings to limit the source connections. Now the agendserver isnt crashing anymore. :)
 
Joined
Oct 12, 2011
Messages
554
Reaction score
318
Nice! Can you say what you changed?

Is it tested? :)

Thank you!

1st Thank you
2nd:

PHP:
         old new
00001EA2: E8 90
00001EA3: 59 90
00001EA4: 25 90
00001EA5: 03 90
00001EA6: 00 90
00001ED2: E8 90
00001ED3: 29 90
00001ED4: 25 90
00001ED5: 03 90
00001ED6: 00 90
00001F00: E8 90
00001F01: FB 90
00001F02: 24 90
00001F03: 03 90
00001F04: 00 90
00001F19: E8 90
00001F1A: E2 90
00001F1B: 24 90
00001F1C: 03 90
00001F1D: 00 90
 
Junior Spellweaver
Joined
Aug 3, 2005
Messages
144
Reaction score
3
I got error:

Z:\Server\AgentServer_no_xtrap2.exe is not a valid Win32 application.

How to fix that ?

Thanks !
 
Junior Spellweaver
Joined
Aug 15, 2008
Messages
185
Reaction score
5
If someone has the program can you please re-upload it ?
 
Experienced Elementalist
Joined
Apr 3, 2012
Messages
239
Reaction score
20
trojans? well, i'm working with it
and i'm using rising anti virus so it doesn't say anything but this is the agentserver noxtrap
 
Newbie Spellweaver
Joined
Aug 3, 2012
Messages
41
Reaction score
4
It is no surprise the files were altered prior to release! I requested clean copies of them exactly for that reason. Someone, possibly the uploader or releaser has been fiddling with the files by injecting asm and causing them to malfunction.
 
Back
Top