Unbounded JSON Array Allocation in ageLANServer Leads to Remote DoS
An unauthenticated remote denial-of-service vulnerability in ageLANServer allows attackers to trigger excessive memory consumption by sending crafted JSON arrays to the getFileURL endpoint.
The ageLANServer application, specifically the POST /game/cloud/getFileURL endpoint, contains a critical vulnerability due to unbounded memory allocation based on attacker-supplied input. When the server processes the names JSON array, it performs a slice allocation using make(i.A, len(req.Names.Data)) without enforcing any bounds on the array length or the HTTP request body size. By default, the application ships with Authentication = 'disabled', allowing any network-reachable client to obtain a valid session identifier through the platformlogin flow without credentials.
An attacker can exploit this by sending a specially crafted request containing a large number of elements in the names array, forcing the server to allocate memory proportional to the input. This behavior leads to massive memory amplification, effectively triggering the kernel OOM killer and crashing the server process. The vulnerability affects unmodified installations of the software as shipped in its default configuration.
Attack Chain
- The attacker identifies an internet-facing ageLANServer deployment.
- The attacker sends a POST request to
/game/login/platformloginwith arbitraryaccountTypeandplatformUserIDparameters to obtain asessionID. - The attacker constructs a malicious JSON payload with an oversized
namesarray (e.g., millions of elements) encapsulated within a JSON string to bypass initial schema parsers. - The attacker sends the crafted payload in a
POST /game/cloud/getFileURL?sessionID=<id>request to the server. - The
Bind()function inserver/internal/http.goparses the large request body into thegetFileURLRequeststruct without limiting the size of the input. - The
GetFileURLhandler inserver/internal/routes/game/cloud/getFileURL.goextracts the length of thenamesarray. - The application invokes
make()using the attacker-controlled length, leading to immediate massive memory allocation. - The system memory is exhausted, triggering the kernel OOM killer and resulting in a service crash (Denial of Service).
Impact
Successful exploitation results in a full process crash, rendering the game server unavailable to all legitimate players. Because the vulnerability is pre-authentication, no game ownership or valid credentials are required. Dynamic testing confirmed that concurrent requests can force OOM-killer termination of the process, ensuring consistent service disruption. This affects any environment where the server is exposed to untrusted networks.
Recommendation
Prioritize the following remediation and detection actions to mitigate this risk:
- Apply input validation logic in
server/internal/routes/game/cloud/getFileURL.goto enforce a hard cap onlen(req.Names.Data)before memory allocation. - Implement middleware using
http.MaxBytesReaderto limit the size of incoming HTTP request bodies across all endpoints. - Disable the
Authentication = 'disabled'setting inserver/resources/config/config.tomlto enforce mandatory session verification against real platform providers. - Deploy the Sigma rules below to monitor for anomalous POST request sizes or high-frequency login activity indicating automated reconnaissance.
Immediate actions
Update ageLANServer configuration to set Authentication to 'enabled'
Mitigations
Implement request size limiting via reverse proxy or application-level middleware
Uncontrolled resource consumption
Detection coverage 1
Detect ageLANServer Unauthenticated Platform Login Spikes
mediumDetects high-frequency platform login attempts which may indicate session acquisition for DoS attacks.
Detection queries are available on the platform. Get full rules →