<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Age-of-Empires - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/tags/age-of-empires/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Fri, 09 Oct 2026 21:25:30 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/tags/age-of-empires/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Unbounded JSON Array Allocation in ageLANServer Leads to Remote DoS</title><link>https://feed.craftedsignal.io/briefs/2026-10-agelanserver-dos/</link><pubDate>Fri, 09 Oct 2026 21:25:30 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-10-agelanserver-dos/</guid><description>An unauthenticated remote denial-of-service vulnerability in ageLANServer allows attackers to trigger excessive memory consumption by sending crafted JSON arrays to the getFileURL endpoint.</description><content:encoded><![CDATA[<p>The ageLANServer application, specifically the <code>POST /game/cloud/getFileURL</code> endpoint, contains a critical vulnerability due to unbounded memory allocation based on attacker-supplied input. When the server processes the <code>names</code> JSON array, it performs a slice allocation using <code>make(i.A, len(req.Names.Data))</code> without enforcing any bounds on the array length or the HTTP request body size. By default, the application ships with <code>Authentication = 'disabled'</code>, allowing any network-reachable client to obtain a valid session identifier through the <code>platformlogin</code> flow without credentials.</p>
<p>An attacker can exploit this by sending a specially crafted request containing a large number of elements in the <code>names</code> array, forcing the server to allocate memory proportional to the input. This behavior leads to massive memory amplification, effectively triggering the kernel OOM killer and crashing the server process. The vulnerability affects unmodified installations of the software as shipped in its default configuration.</p>
<h2 id="attack-chain">Attack Chain</h2>
<ol>
<li>The attacker identifies an internet-facing ageLANServer deployment.</li>
<li>The attacker sends a POST request to <code>/game/login/platformlogin</code> with arbitrary <code>accountType</code> and <code>platformUserID</code> parameters to obtain a <code>sessionID</code>.</li>
<li>The attacker constructs a malicious JSON payload with an oversized <code>names</code> array (e.g., millions of elements) encapsulated within a JSON string to bypass initial schema parsers.</li>
<li>The attacker sends the crafted payload in a <code>POST /game/cloud/getFileURL?sessionID=&lt;id&gt;</code> request to the server.</li>
<li>The <code>Bind()</code> function in <code>server/internal/http.go</code> parses the large request body into the <code>getFileURLRequest</code> struct without limiting the size of the input.</li>
<li>The <code>GetFileURL</code> handler in <code>server/internal/routes/game/cloud/getFileURL.go</code> extracts the length of the <code>names</code> array.</li>
<li>The application invokes <code>make()</code> using the attacker-controlled length, leading to immediate massive memory allocation.</li>
<li>The system memory is exhausted, triggering the kernel OOM killer and resulting in a service crash (Denial of Service).</li>
</ol>
<h2 id="impact">Impact</h2>
<p>Successful exploitation results in a full process crash, rendering the game server unavailable to all legitimate players. Because the vulnerability is pre-authentication, no game ownership or valid credentials are required. Dynamic testing confirmed that concurrent requests can force OOM-killer termination of the process, ensuring consistent service disruption. This affects any environment where the server is exposed to untrusted networks.</p>
<h2 id="recommendation">Recommendation</h2>
<p>Prioritize the following remediation and detection actions to mitigate this risk:</p>
<ul>
<li>Apply input validation logic in <code>server/internal/routes/game/cloud/getFileURL.go</code> to enforce a hard cap on <code>len(req.Names.Data)</code> before memory allocation.</li>
<li>Implement middleware using <code>http.MaxBytesReader</code> to limit the size of incoming HTTP request bodies across all endpoints.</li>
<li>Disable the <code>Authentication = 'disabled'</code> setting in <code>server/resources/config/config.toml</code> to enforce mandatory session verification against real platform providers.</li>
<li>Deploy the Sigma rules below to monitor for anomalous POST request sizes or high-frequency login activity indicating automated reconnaissance.</li>
</ul>
]]></content:encoded><category domain="severity">medium</category><category domain="type">advisory</category><category>denial-of-service</category><category>memory-exhaustion</category><category>json-injection</category><category>age-of-empires</category></item></channel></rss>