Mojira Archive
BDS-16776

The server does not check the size (length) of the nickname

The server does not check the size (length /number of characters in the nickname) when the client connects to the server.

Steps to reproduce:

1.Open the file options.txt,edit the value in mp_username (For example:123456789a123456789b123456789c123456789),save the file.

2.Log in to the server.

Waiting:
The server will check the size of the nickname and if it exceeds a certain value (number of characters) it will reset this "suspicious connection"

Actually:
The server accepts absolutely any size and values from the nickname.

Note:
This can be used to crash the server, you can edit options.txt so that the size of the nickname would be more than 71MB of text.You can do more, it depends on the power and the amount of RAM on the client device.

Upload a special file options.txt the size of 71MB I can't.Uploaded an analog with a smaller nickname.

Linked Issues

Attachments3

32425472.png
32425472.png

Copitoch

453424.png
453424.png

Copitoch

Снимок.PNG
Снимок.PNG

Copitoch

Comments7

MEQS_KEEP_PRIVATE

Hi

Does this issue still occur after updating to 1.19.10?

 

This ticket will automatically reopen when you reply. 

Hi

What file do you need to edit to change nickname lenght?

This ticket will automatically reopen when you reply. 

I don't think you understand what we are talking about.

The server receives a message about the nickname / indificator, does not check what the client tells it, processes and crashes, if the nickname is quite large.Which file, everything is listed above:options.txt . Where it is: at the client in Minecraft...

Thank you for your report!
We're tracking this issue in MCPE-152884, so this ticket is being resolved and linked as a duplicate.

If you would like to add a vote and any extra information to the main ticket it would be appreciated.

If you haven't already, you might like to make use of the search feature to see if the issue has already been mentioned.

Quick Links:
📓 Bug Tracker Guidelines – 📧 Mojang Support
📓 Project Summary – ✍️ Feedback and Suggestions – 📖 BDS Wiki – 📖 FAQs

*If you fix it in the minecraft client and don't fix it on the server software side, the problem won't be solved.

History8

[Mod] OcelotOnesie

Added Security Level: Minecraft - Private

Maciej Piornik
Copitoch

Added attachment:

[Bot] Arisa
Maciej Piornik
[Bot] Arisa
Maciej Piornik
Maciej Piornik

Resolution: UnresolvedDuplicate

Duplicate
Copitoch
0
0
Unconfirmed
1.18.12 Hotfix