1. These forums are still being retired! Please use GitHub discussions or Discord. You cannot create new threads or new accounts now. If you need to contact some user of the forums, you should do it sooner, rather than later. This notice was last updated on May 30th, 2021.

Security issue with Null player names

Discussion in 'Help and Support' started by zechnophobe, Feb 18, 2020.

  1. zechnophobe

    zechnophobe Level 0

    Feb 18, 2020
    Hello, I had a character join my server which generated this log entry:

    (dudes.ip.address.ok) from 'guest' group joined. (11/20)

    The start of that line *is* their character name, it's just whitespace characters or something. Showed up in the logs as 'NUL NUL'

    I believe that when this happened it nuked my superadmins ability to send commands to tshock. Command line commands were ignored as well as in game ones, and we had to kill the service.

    Is this a vulnerability of tshock? Is there some way to work around it? (Besides aggressive white-listing)?

    Any help would be appreciated.
  2. TheLastPrism

    TheLastPrism Level 0

    Jul 15, 2019
    Try using player's index.
    You can use /who -i to get players' indexes.