Crashed and Burned! FG falling over...

12 Jun 2018 15:08 #38897 by Algernon
Thanks, mate... will have a go once I'm sitting at the right computer

Please Log in or Create an account to join the conversation.

13 Jun 2018 18:28 #38924 by StuartC
Terasync IS fatal in 2018.2.1
Ran Terasync because I wanted to spawn on a ship at EGOD.
FG Began stuttering and generally being weird after a few min. It wouldn't let me exit it, screen froze, but I could still here FG running in the background.
Eventually killed it off but on my desktop I found that EDGE had opened up and was continually opening a new tabs, all linked to the IOS and Andriod Download page for Edge. IE was also opening new tabs, each with " page not found errors". I couldn't access anything. Ctrl Alt Del was non functional, and I had to watch as the CPU + RAM usage all maxed out. I had to kill the power.
Tried again tonight, same settings for spawning on a ship. It Ran ok, exited, and I went for dinner. Returned to find the PC completely locked up again.

Please Log in or Create an account to join the conversation.

13 Jun 2018 18:35 #38925 by Algernon
Wow... that does not sound like a minor issue either... I would be pretty freaked if FG was repeatedly trying to open web pages...

Please Log in or Create an account to join the conversation.

13 Jun 2018 19:38 #38927 by enrogue
I wouldn't know what could cause that tbh

I'm currently testing my home terrasync mirror as a terrasync http server for a new linux test machine (Intel Kaby Lake NUC)

I haven't really had issues with terrasync myself, but I don't use windows very often - the issues may be windows specific

Please Log in or Create an account to join the conversation.

13 Jun 2018 19:45 #38929 by StuartC
Just flew again, Without terrasync. Everything was fine until I exited FG, then Edge and IR started opening pages again. Looks like something has come down through terrasync.

Please Log in or Create an account to join the conversation.

13 Jun 2018 21:06 #38935 by Algernon
It definitely sounds malicious. Time to start looking closely at everyone who is contributing to Terrasync, I think...

Please Log in or Create an account to join the conversation.

14 Jun 2018 07:27 #38939 by enrogue
I'm going to run an antivirus scan over my full mirror - it may take a while

Please Log in or Create an account to join the conversation.

14 Jun 2018 07:54 #38941 by StuartC
I have scanned my terrasync folder, it came up clean, so were talking legit code used in a non legit way within terrain tiles.
I removed the tile that was downloaded via terrasync, and FG runs fine again.

Please Log in or Create an account to join the conversation.

14 Jun 2018 07:55 #38942 by Algernon
Good shout. But it's possible it may not show up as recognised malware, as it's possibly just an amateur attempt at using Nasal to create mischief, like we've seen in some of the aircraft produced by the troublesome groups.

I tell you one thing, though - this is disturbing enough that I plan to recommend to the other admins that absolutely no code from any source that isn't considered completely trustworthy by all of us gets into FlightNights. By that I mean to include custom scenery in scenarios, and aircraft associated with problem flying groups. If it means we have to tighten up the operation and not permit certain suspect people or aircraft from taking part, so be it.
The following user(s) said Thank You: StuartC

Please Log in or Create an account to join the conversation.

14 Jun 2018 15:58 #38948 by enrogue
Do we have any examples of what people have tried via Nasal in aircraft & scenery?

I've just been looking at what nasal can do with file io & how it's limited via a whilelist - it would take a while to run but it would be relatively easy to run a grep through the model xml in Terrasync to see if anything odd has crept in

Please Log in or Create an account to join the conversation.

14 Jun 2018 17:18 #38949 by Algernon
I'd like to know this too. As far as I know, it's one of the few things you CAN do without difficulty to make a web page request open in a browser - I experimented with an HTML manual for the Lightning, opening a web page by clicking a menu item, and it was extremely simple if I recall correctly. That's why I'm suspicious - it's an easy way to cause trouble for someone with limited coding/hacking skill.

Please Log in or Create an account to join the conversation.

14 Jun 2018 17:59 #38950 by enrogue
Well an HTTP request in Nasal has to run through fgcommand, which would be easy to find any use of in the model XML

Please Log in or Create an account to join the conversation.

14 Jun 2018 18:16 #38952 by Algernon
Yup. So lets have a look... then the next thing is to find out who was responsible. It won't be a witch hunt, promise.

<starts building a person-sized fire and a ducking stool>

Please Log in or Create an account to join the conversation.

15 Jun 2018 10:10 #38955 by enrogue
So a full antivirus scan came up blank, and a full search of the tree found no instances of io.open, io.write, io.seek, or fgcommand (at least in uncompressed files)

Please Log in or Create an account to join the conversation.

15 Jun 2018 10:14 #38956 by StuartC
Well, All I can verify is, the problem stopped after removing that terrasync downloaded tile. Logic dictates that the tile was causing the issue.

Please Log in or Create an account to join the conversation.

15 Jun 2018 10:33 #38957 by enrogue
Well I have to wonder if one of the terrasync mirrors used had been subverted (DNS? It uses NAPTR records to look up available mirrors)

My mirror (which pulls from flightgear.org) seems ok - thats all I can say for sure

Please Log in or Create an account to join the conversation.

15 Jun 2018 20:28 #38960 by timi
I guess I'll try to sync EGOD from terrasync on a VM and record the session with Wireshark to see where it pulls the stuff from...

Please Log in or Create an account to join the conversation.

15 Jun 2018 22:21 #38963 by timi
Came from 69.30.239.12 which is mpserver16.flightgear.org.

Please Log in or Create an account to join the conversation.

15 Jun 2018 22:37 #38964 by timi
And the DNS servers of flightgear.org seem to agree:

timi@ubuntu1804:~$ nslookup mpserver16.flightgear.org dns1.easydns.com
Server: dns1.easydns.com
Address: 64.68.192.10#53

Name: mpserver16.flightgear.org
Address: 69.30.239.12

timi@ubuntu1804:~$ nslookup mpserver16.flightgear.org dns2.easydns.net
Server: dns2.easydns.net
Address: 198.41.222.254#53

Name: mpserver16.flightgear.org
Address: 69.30.239.12

timi@ubuntu1804:~$ nslookup mpserver16.flightgear.org dns3.easydns.ca
Server: dns3.easydns.ca
Address: 64.68.196.10#53

Name: mpserver16.flightgear.org
Address: 69.30.239.12
The following user(s) said Thank You: Algernon, StuartC

Please Log in or Create an account to join the conversation.

15 Jun 2018 23:05 #38965 by timi
The files with nasal blocks in them after downloading EGOD:

timi@ubuntu1804:~/.fgfs/TerraSync$ grep -ir "nasal" | awk -F: '{ print $1}' | sort | uniq
Models/Airport/ebgb_building_ref_004.xml
Models/Airport/hw-hangar-movable-a.xml
Models/Airport/hw-hangar-movable-b.xml
Models/Airport/hw-hangar-movable-c.xml
Models/Airport/Jetway/EHAM_gate_2.xml
Models/Airport/Jetway/EHAM_gate.xml
Models/Airport/Jetway/generic.xml
Models/Airport/Jetway/glass.xml
Models/Airport/Jetway/jetway-movable-2.xml
Models/Airport/Jetway/jetway-movable-3.xml
Models/Airport/Jetway/jetway-movable.xml
Models/Airport/lfga-refuel.xml
Models/Boundaries/Automatic_Green_Gate_20m.xml
Models/Maritime/Military/CG57.xml
Models/Military/EHVK_shelter.xml
Models/Transport/dc-metro-train.xml
Objects/w010n50/w005n52/superhangar.xml
The following user(s) said Thank You: Algernon, Vodoun da Vinci

Please Log in or Create an account to join the conversation.

Time to create page: 0.159 seconds
Powered by Kunena Forum

PM Mailbox

You are not logged in.

Forum Search

Keyword