Login prompt with other username?

What do you want to see in Armagetron soon? Any new feature ideas? Let's ponder these ground breaking ideas...
User avatar
Jip
Round Winner
Posts: 397
Joined: Sat Sep 26, 2009 5:32 pm

Login prompt with other username?

Post by Jip »

Hi,
I noticed a weird thing and I cant reproduce it. Sometimes (actually it happend only 4-5 times now), when I join a server the armathentication form pops up with a player name (not mine) and disapeares after a few moments. I didnt have time trying to login with this user because it was gone too fast.
I think it always happend when i hit /login and another user hit /logout at the same time, but i am not sure. And always when it happend, I just joined a server with 0.3 running.
I dont know if it could be any weak spot in security?
Have somebody else seen this?
Sry when i posted in the wrong forum, didnt really know where to with it.

EDIT:
12:55:20 <@\u03b5> Jip, google translate ftw? :D
12:56:50 <@Jip> no
12:56:55 <@Jip> my english just sucks :/
User avatar
Z-Man
God & Project Admin
Posts: 11738
Joined: Sun Jan 23, 2005 6:01 pm
Location: Cologne
Contact:

Re: Login prompt with other username?

Post by Z-Man »

That's very odd. I don't think the prompt even can go away on its own. Could you make a debug recording of it? I don't think it's a security risk, you'd probably still have to guess the other guy's password correctly.
User avatar
Jip
Round Winner
Posts: 397
Joined: Sat Sep 26, 2009 5:32 pm

Re: Login prompt with other username?

Post by Jip »

If i can reproduce it i will make a debug recording. But it happens very random and i dont want to record every time i'm playing :D
Could it be, when I enter a server and watching another player who just logs in that i see his prompt?
User avatar
Lackadaisical
Shutout Match Winner
Posts: 823
Joined: Sun Dec 21, 2003 4:58 pm
Location: Amsterdam, Netherlands
Contact:

Re: Login prompt with other username?

Post by Lackadaisical »

I had this happen too, not so long ago.. I entered a server and I got the login prompt with hoax' username filled in. Turned out he timed out right before I entered the server. I have no knowledge whatsoever about the workings behind this, but I assumed I inherited his user ID and the server send the signal to me? Were the people whose username were in the prompt still in the server Jip?
User avatar
Jip
Round Winner
Posts: 397
Joined: Sat Sep 26, 2009 5:32 pm

Re: Login prompt with other username?

Post by Jip »

yeah, they were in the server but just left after this happend.
Word
Reverse Adjust Outside Corner Grinder
Posts: 4327
Joined: Wed Jan 07, 2009 6:13 pm

Re: Login prompt with other username?

Post by Word »

i know the same problem...one time appa logged in and i saw how he typed his password. but i'm unable to reproduce that.
User avatar
Z-Man
God & Project Admin
Posts: 11738
Joined: Sun Jan 23, 2005 6:01 pm
Location: Cologne
Contact:

Re: Login prompt with other username?

Post by Z-Man »

Word: you mean literally, character by character? Or just the prompt disappearing?
Lackadaisical wrote:but I assumed I inherited his user ID and the server send the signal to me?
That could be. Logins are processed in the far background, semi-oblivious to other events on the server.
Word
Reverse Adjust Outside Corner Grinder
Posts: 4327
Joined: Wed Jan 07, 2009 6:13 pm

Re: Login prompt with other username?

Post by Word »

Z-Man wrote:Word: you mean literally, character by character? Or just the prompt disappearing?
i saw these "******"-symbols appearing one after another, then he probably pressed enter and the prompt disappeared. that happened like 3 seconds after i entered a server.
User avatar
Z-Man
God & Project Admin
Posts: 11738
Joined: Sun Jan 23, 2005 6:01 pm
Location: Cologne
Contact:

Re: Login prompt with other username?

Post by Z-Man »

That is genuinely scary. Your PC being possessed by a poltergeist is the easiest explanation. No code path apart from keyboard input should be able to change the password field.
User avatar
Van-hayes
Round Winner
Posts: 398
Joined: Sat Mar 04, 2006 1:15 am
Location: The Maritimes

Re: Login prompt with other username?

Post by Van-hayes »

I got a prompt right after I joined a server that had "joe" as the username, but as soon as the auto login logged me in it went away. Didn't think anything of it until i saw this topic.
You've gone too far, turn back!
Hoax
Shutout Match Winner
Posts: 892
Joined: Sun Jun 18, 2006 5:24 pm
Location: UK

Re: Login prompt with other username?

Post by Hoax »

I thought I timed out or whatever when that happened to lack just before I quit I saw bikes move again but it doesn't look like connection anomalies are a theme here
Concord
Reverse Outside Corner Grinder
Posts: 1661
Joined: Sun Oct 21, 2007 5:24 pm

Re: Login prompt with other username?

Post by Concord »

I've experienced something of Jip's description once, as well.
User avatar
Joe
Core Dumper
Posts: 161
Joined: Fri Aug 27, 2004 6:11 am
Location: C eh N eh D eh
Contact:

Re: Login prompt with other username?

Post by Joe »

van did i just leave that server, or was i timed out?
User avatar
Jip
Round Winner
Posts: 397
Joined: Sat Sep 26, 2009 5:32 pm

Re: Login prompt with other username?

Post by Jip »

I remembered the situation with van-hayes and joe and looked in our server logs. I filtered every login/logout message. Joe timed out as user 14 and van took his id and requested password from joe.
At this time z-thread wasnt installed on the server.
If it helps i can send the complete logs via pm.

Code: Select all

[14 TS=2010/05/19-00:39:46 IP=JOES_IP] Received login from JOES_IP via socket 78.46.117.245:4536, network version: 0.2.8.3.X (ID: 16).
[14 TS=2010/05/19-00:39:46 IP=JOES_IP] New user: 14
[0 TS=2010/05/19-00:39:56] User 14 requests authentication as "Joe@forums".

[0 TS=2010/05/19-00:40:07] received logout from 10.
[10 TS=2010/05/19-00:40:07 IP=] .×] akira left 0 : Twixted Xats.
[10 TS=2010/05/19-00:40:07 IP=] Killing user 10, ping 0.0279962.

[0 TS=2010/05/19-00:41:11] User 14 timed out.
[14 TS=2010/05/19-00:41:11 IP=JOES_IP] Killing user 14, ping 0.345862.
[10 TS=2010/05/19-00:41:16 IP=JOES_IP] Received login from JOES_IP via socket 78.46.117.245:4536, network version: 0.2.8.3.X (ID: 16).
[10 TS=2010/05/19-00:41:16 IP=JOES_IP] New user: 10
[0 TS=2010/05/19-00:41:22] User 10 requests authentication as "Joe@forums".
[0 TS=2010/05/19-00:42:56] Password request sent to user 14, username "Joe", method md5, message "Login with Authority forums".
[0 TS=2010/05/19-00:42:58] Password request sent to user 10, username "Joe", method md5, message "Login with Authority forums".
[10 TS=2010/05/19-00:42:59 IP=JOES_IP] .X] JJ has been logged in as Joe@forums.

[0 TS=2010/05/19-00:45:38] received logout from 13.
[13 TS=2010/05/19-00:45:38 IP=xxxxxx] Killing user 13, ping 0.160213.

[13 TS=2010/05/19-00:50:35 IP=yyyyyy] Received login from yyyyyy via socket 78.46.117.245:4536, network version: 0.2.8.3.X (ID: 16).
[13 TS=2010/05/19-00:50:35 IP=yyyyyy] New user: 13

[14 TS=2010/05/19-00:57:45 IP=VAN_IP] Received login from VAN_IP via socket 78.46.117.245:4536, network version: 0.3.1 (ID: 20).
[14 TS=2010/05/19-00:57:45 IP=VAN_IP] New user: 14
[0 TS=2010/05/19-00:57:53] User 14 requests authentication as "Van-hayes@forums".
[0 TS=2010/05/19-00:58:02] User 14 requests authentication as "Van-hayes@forums".
[0 TS=2010/05/19-00:58:16] Password request sent to user 14, username "Joe", method md5, message "Login with Authority forums".
User avatar
Z-Man
God & Project Admin
Posts: 11738
Joined: Sun Jan 23, 2005 6:01 pm
Location: Cologne
Contact:

Re: Login prompt with other username?

Post by Z-Man »

That looks useful. I don't think clientside recordings can shed any more light on this; if the logs alone aren't enough, they should make it possible to reproduce the problem.
Post Reply