Log in

View Full Version : DoS attacks...


Lark
Apr 14, 2004, 05:33 PM
For two days in a row now my server has been being DoS attacked. Today, Nimrod's server, BlurredD's server, EvilMike's server, and some other server were all DoS attacked at the same time. I suggest everyone puts on ApprehendJJ2.exe while hosting, and if you find the DoS attacker's, IP, show Nimrod a log.

Link
Apr 14, 2004, 05:38 PM
If possible could people also send me the binary log file from ApprehendJJ2? (and tell me what IP the attack was from)

I know there are some things it doesn't detect properly (specifically server-crashing DoS attacks), and I want to fix that.

Violet CLM
Apr 14, 2004, 06:05 PM
I don't know if it was a DoS attack, but someone with the IP of 66.90.77.18 crashed my server a few times recently. Just by joining - no name visible.

Blackraptor
Apr 14, 2004, 06:08 PM
Yeah, I've witnessed it in mikes server, lrk's server and the like. A noname joins, then I got high amounts of baud received and everyone looked like they were timing (I assumed the server crashed, but I was in it for a few min after), I tried to say something but apparently the noname thing kept inserting blank lines of text (no colon) rapidly so my text kept dissapearing with the blink of an eye. Didn't personally crash my server, though, since I cant host =P

Risp_old
Apr 14, 2004, 06:21 PM
The best protection to keep your server from being crashed: not hosting.

Blackraptor
Apr 14, 2004, 07:11 PM
The best protection to keep your server from being crashed: not hosting.

That's also a best way to help jj2 die out.

R3ptile
Apr 15, 2004, 06:17 AM
When AvK hosted my duels then some idiot joined as some kinda weird nickname and his IP wasn't available, when he tried to kick him, the server just crashed. I didn't see him. When this guy also joined my server, it happened again, but this time Newspaz saw him in the server. Well, he is kinda h4x0r or so, I have no idea who he can be, and I couldn't get his IP. Lately, it seems like he is gone, but he always comes back after short time. I hope Nimrod is going to do something with that, and ban the hackers (or so), at last! o.O

~R3ptile

Nimrod
Apr 15, 2004, 10:06 AM
I hope Nimrod is going to do something with that, and ban the hackers (or so), at last! o.O

~R3ptile

A) Its not my job, I have a lot more things to do in life, than spend my time taking notes of IP and taking action.

B) The moment I made a comment about installing some IP Filtering stuff on the List Servers, i had a loads of people screaming out saying that Im abusing my power.. Make up your fricken mind people.

C) Try asking more politely.


Also on the note of those players who join with 'Unknown Network Addresses', if you kick them your JJ2 will Crash. You can remove them using Controller 4, by Overlord.

I had quite a few of them in the After Party Server, all from the same IP. They oberviously thought I wasnt running anyform of packet Monitor and ended up getting caught. I am thinking about speaking to there ISP's Abuse department, providing logs and seeing what action they can take.

Feel free to look at the persons IP:
http://hosting.nimrod-online.com/Caught.JPG

Lark
Apr 15, 2004, 10:15 AM
I had the exact same problem as Violet. That is a DoS attack, Violet. The server crashes so quickly, ApprehendJJ2.exe and JJ2 don't have time to tell you an IP.

Blackraptor
Apr 15, 2004, 12:31 PM
Once some time ago I had 4 hacker bots in my server. If I'd have kicked/banned any of them my jj2 crashed, so I just left them there and they caused no harm whatsoever. But I doubt its one of these types of bots so..=\

Nimrod
Apr 16, 2004, 07:36 AM
I have been collecting 'IPs' of these so call Fake players, They all come from the same Provider.

An ASDL/Dial Up Provider (as there IP changes slightly).

Im collecting as many logs as possible, and sending to the abuse department, If anyone else has any, please share and ill see what I can do.

Link
Apr 16, 2004, 10:06 AM
I know that deliberately crashing servers is technically illegal and you have every right to report it to their ISP, but wouldn't it make more sense to talk to the person first and ask them to stop?

Nimrod
Apr 16, 2004, 10:44 AM
It would, but when they have a dynamic IP, it makes it a lot harder to track them down, it would be easier to speak to there ISP, as they would know who they are.

Black Ninja
Apr 16, 2004, 04:17 PM
just today my server crashed, apparently by another DOS attack. However, I was unsuspecting and didn't get the IP.

Trafton
Apr 16, 2004, 05:04 PM
Blah. There's really no need to get excited about this. I'm aware of who did the DoS'ing, and will contact them as soon as possible.

The crashing is another story, but if you get the IP of another crasher, feel free to PM me it and I will look into it. I can't promise I will get a result, but I oftentimes do.

For future reference, posting IP addresses in public under most circumstances is a very bad idea.

~ Traft

Lark
Apr 16, 2004, 05:46 PM
At times like this, I always have ApprehendJJ2.exe when I'm hosting, even if it doesn't matter if I crash or not that much. If I caught a DoS attacker, I'd have bragging rights. =P

Nimrod
Apr 16, 2004, 05:54 PM
Blah. There's really no need to get excited about this. I'm aware of who did the DoS'ing, and will contact them as soon as possible.

Beat you to it, and they claim there innocent :rolleyes: