Author Topic: PSA: Several servers are being DDoS attacked by a botnet.  (Read 28099 times)


Oh wait you ment ports not BLID's.
****
Disregard what I said previously.

I wish drama let you edit messages
:/

heh, badspot moved this to drama. i made this thread in general discussion because i noticed the drama thread and the other sources and decided to make a topic in general warning about the attacks for people that dont visit the drama thread and that sort of thing (and it is related to blockland as a whole), because this is pretty bad right now. servers like trogs i believe were hit recently, and only servers with ddos protection (glass hosting, theblackparrot's servers) are able to be hosted

noedit: when im talking about how i made this thread for those that didnt visit the drama thread, i mean for people who just generally avoid the drama board as a whole and are wondering what the hell is going on with servers right now.

why is no one doing packet sniffing using wireshark or smth to see who's the primary cause

why is no one doing packet sniffing using wireshark or smth to see who's the primary cause
yeah just smell the packets out maybe you'll eat the IP and their starfishs to the next alien generation and figure out who the man in the mask is

toxicology was one of the people with satire on this forum that was actually funny

toxicology was one of the people with satire on this forum that was actually funny

oh stuff lol sorry for the triple post but i must've been tripping out or something i meant to post this in the toxicology RIP thread

why is no one doing packet sniffing using wireshark or smth to see who's the primary cause
maybe someone thats hosting their server with some players on it can run it, and then when the ddos wave comes we can figure out what exactly is going on

why is no one doing packet sniffing using wireshark or smth to see who's the primary cause
its a proper ddos so even if you did have those prograns they wouldnt tell you anything useful like who the attacker is

its a proper ddos so even if you did have those prograns they wouldnt tell you anything useful like who the attacker is

damn :[

UDP port 111 DDoS attacks are a rudimentary attempt at reflective amplification, since it's the portmapper service port for Linux boxes(in other words, it acts as a 411 for a Linux PC's ports by compiling a list, which takes up CPU).
http://www.securityweek.com/rpc-portmapper-abused-ddos-attack-reflection-amplification


also in relation to passwording your server to attempt to stop DDoS attacks, it's plausible, but unlikely. All anyone has to do to find your IP is to try to connect iirc, so that's how they're getting IPs, but i can't remember if passwording your server hides the actual IP connection dialog behind the password check or not (or if that even matters).

UDP port 111 DDoS attacks are a rudimentary attempt at reflective amplification, since it's the portmapper service port for Linux boxes(in other words, it acts as a 411 for a Linux PC's ports by compiling a list, which takes up CPU).
http://www.securityweek.com/rpc-portmapper-abused-ddos-attack-reflection-amplification


also in relation to passwording your server to attempt to stop DDoS attacks, it's plausible, but unlikely. All anyone has to do to find your IP is to try to connect iirc, so that's how they're getting IPs, but i can't remember if passwording your server hides the actual IP connection dialog behind the password check or not (or if that even matters).
http://master2.blockland.us/
its already public information dude
unfortunately, no it doesn't

unfortunately, no it doesn't
yeah i kind of figured. i think connection attempts are also viewable in console which was why I wasn't sure to begin with. I'm fuzzy when it comes to my knowledge on this stuff anyway since I haven't touched the game in a while

yeah i kind of figured. i think connection attempts are also viewable in console which was why I wasn't sure to begin with. I'm fuzzy when it comes to my knowledge on this stuff anyway since I haven't touched the game in a while
It wouldn't matter either way. To connect to a server you have to know the IP address, so somewhere along the way the game has to find it from a directory or matchmaking service. It's trivial to find server IP's because those servers literally have to advertise their IP in order to enable anyone connecting to them.