Jan 21, 2006, 09:14 AM | |
Orbitz?
Dear J2O,
I am letting you know theese crashes occuring are not me for proof take an eye on my ip : 72.139.36.204 So if your gonna blame me prove it cuz its not me.
__________________
<!-- Personal attack edit. Never insult people on these forums -FQuist --> |
Jan 21, 2006, 09:26 AM | |
How can we know you don't have a dynamic IP this time?
__________________
Mystic Legends http://www.mysticlegends.org/ The Price of Admission - Hoarfrost Hollow - Sacrosanct - other - stuff |
Jan 21, 2006, 09:30 AM | |
How can you know he has?
__________________
Interesting Jazz-related links: Thread: Gameplay Theories - Thread: Make Up Your Own Gametype |
Jan 21, 2006, 09:35 AM | |
It's not like you can't change ISPs to get a dynamic IP.
__________________
Mystic Legends http://www.mysticlegends.org/ The Price of Admission - Hoarfrost Hollow - Sacrosanct - other - stuff |
Jan 21, 2006, 09:50 AM | |
This is all speculation. It has no value to build decisions on.
__________________
Interesting Jazz-related links: Thread: Gameplay Theories - Thread: Make Up Your Own Gametype |
Jan 21, 2006, 09:54 AM | ||
Quote:
__________________
Mystic Legends http://www.mysticlegends.org/ The Price of Admission - Hoarfrost Hollow - Sacrosanct - other - stuff |
Jan 21, 2006, 10:37 AM | |
Alright... Orbiyz claims that ThaSpaz is the crasher. That is very likely too. Anyways, here comes some evidence that should get one person banned:
Log from my server's uptime (about 3 minutes, just estimatedly): http://www.freewebs.com/grytolle/jaz...hackernoob.txt 2629 69.72.144.19:51534 192.168.0.100:10052 81 Recv This one sure looks malicious? |
Jan 21, 2006, 10:39 AM | |
Code:
2629 69.72.144.19:51534 192.168.0.100:10052 81 Recv 0000 01 0E 01 03 01 00 00 00 00 41 53 44 41 4F 53 46 .........ASDAOSF 0010 48 4F 49 53 41 46 48 4F 53 41 48 47 4F 4C 41 53 HOISAFHOSAHGOLAS 0020 47 46 48 42 50 53 41 4F 4E 41 53 4F 49 4A 53 4E GFHBPSAONASOIJSN 0030 47 50 4F 53 41 48 4E 4F 49 41 47 53 4F 49 48 53 GPOSAHNOIAGSOIHS 0040 46 4F 50 53 41 49 46 48 4F 49 50 53 41 46 48 53 FOPSAIFHOIPSAFHS 0050 41 A
__________________
I'm sick and tired of this community. So goodbye. PS: Unreal > JJ2. |
Jan 21, 2006, 10:42 AM | |
Not to mention sent spam, probably for flooding. If you follow the log after that, you see that I crash.
Edit: What the (-)? Port 51534? then it sure wasn't sent from a jj2 client?;p Oh, and an admin, please verify that Orbitz didn't lie about his IP. |
Jan 21, 2006, 10:54 AM | ||
Quote:
The address that Orbitz named matches the address from which he posted.
__________________
With our extreme gelatinous apology,
We beg to inform your Imperial Majesty, Unto whom be dominion and power and glory, There still remains that strange precipitate Which has the quality to resist Our oldest and most trusted catalyst. It is a substance we cannot cremate By temperatures known to our Laboratory. ~ E.J. Pratt |
Jan 21, 2006, 10:56 AM | |
Okay, and he didn't post with a known webproxy or so? ;p
2545 69.72.144.19:51534 192.168.0.100:10052 9 Recv Those are all packets from that IP, so it was obviously no one in server that crashed me ;o (And the first one resembles those you get from jforce. Last edited by Grytolle; Jan 21, 2006 at 11:12 AM. |
Jan 21, 2006, 11:51 AM | |
69.72.144.19 resolves to a web server registered in Naperville, Illinois.
Registration contact is: Rags Rajagopalan +1.6305186387 Fax: +1.9999999999 710 E Ogden Ave Suite 540 Naperville, S 60563 US
__________________
And he increases the number of clocks by exactly one. |
Jan 21, 2006, 12:12 PM | |
That's definitely the IP which ApprehendJJ2 logged when I got DoS attacked.
|
Jan 21, 2006, 12:19 PM | ||
Quote:
__________________
I'm sick and tired of this community. So goodbye. PS: Unreal > JJ2. |
Jan 21, 2006, 12:40 PM | ||
Quote:
http://en.wikipedia.org/wiki/Denial_of_service for more stuff |
Jan 21, 2006, 12:46 PM | |
Rags Rajagopalan is apparently the owner of NotionTide, Inc., a wireless evangelism firm. I doubt he's the one responsible.
Should I give him a ring?
__________________
And he increases the number of clocks by exactly one. |
Jan 21, 2006, 01:13 PM | |
OK, I finally found out what the IP was, which was the host of my website. It appears that someone had been accessing my server list thing on my website through a file I had assumed to be deleted and had been using that script to take down servers. It's been fixed now.
__________________
I'm sick and tired of this community. So goodbye. PS: Unreal > JJ2. |
Jan 21, 2006, 01:39 PM | ||
Quote:
__________________
<a href="http://nmap.org/"><img border="0" alt="Nmap Security Scanner" src="http://images.insecure.org/nmap/images/prop/nmap_bnr_matrix_pfos.gif"/></a> |
Jan 21, 2006, 01:43 PM | ||
Quote:
If you have access to the site logs, you should be able to find out who it was, or at least their IP address. Also, how did they find it? Did you have links to this script or tell anyone about it?
__________________
With our extreme gelatinous apology,
We beg to inform your Imperial Majesty, Unto whom be dominion and power and glory, There still remains that strange precipitate Which has the quality to resist Our oldest and most trusted catalyst. It is a substance we cannot cremate By temperatures known to our Laboratory. ~ E.J. Pratt |
Jan 21, 2006, 01:59 PM | |
Overlord, what do you think of:
Detection like this: "0E" to determine it is joining, and then at the first place out of the allowed just make one filter for each possible hexvalue? Then block all such packages. Nvm, I just realized that that is like many combinations -.- Is there any program that can simply filter out too long packets? WPE is great, but it could really use that function. Oh, and for private games, it would be a good idea to just block all packets beginning with XX 0E when all players are in server. Maybe it can be added to the "official filter"? It would suck if jj2wc-games were interrupted by frequent crashes like this... |
Jan 21, 2006, 02:12 PM | ||
Quote:
Orbitz: 72.139.36.204 It indeed is Orbitz' real IP. (I caught this ages ago, at the first crash wave.) ThaSpaz: 83.85.199.209 That is the dutch IP I got from ThaSpaz back af the first crashing wave. I'm fully sure about those being the right ones. |
Jan 21, 2006, 02:16 PM | |||
Quote:
Quote:
|
Jan 21, 2006, 02:28 PM | |
If WPE could somehow block packets that match certain length then I would be most happy. However so far I have not managed to make any filters that check packet length and block those that exceed it. And yes, there are too many combinations to make filters for. A very useful function for WPE would be a check whether a byte is NOT the given value rather than check if it is every possible one, like your idea suggests, Gry. WPE is by no means a perfect packet editor. In fact its far from that.
__________________
<a href="http://nmap.org/"><img border="0" alt="Nmap Security Scanner" src="http://images.insecure.org/nmap/images/prop/nmap_bnr_matrix_pfos.gif"/></a> |
![]() |
CrimiClown |
This message has been deleted by Link.
Reason: [Flame tag edit. I'll tag this as a flame. These things should not be said to users on these forums - FQuist]
|
Jan 21, 2006, 02:58 PM | |
I looked at some more advanced packet scrubbers (I read somewhere that's what shortening packets is called, feel free to correct me), but uh... too advanced, I didn't even get through the install.
|
Jan 21, 2006, 03:23 PM | |
ThaSpaz is best friends with Orbitz, so it doesnt suprise me if Thaspaz is involved.
He was the dude given IP's to Orbitz when he was banned.... until I blocked him. That block needs to be readded soon I'm thinking. |
Jan 21, 2006, 03:44 PM | ||
Quote:
![]() Tha spaz's IP either isn't static or he changed his isp looks like the noname is orbitz too
__________________
![]() |
Jan 21, 2006, 04:26 PM | ||
Quote:
Or I may have forgotten to collect the IPs. ![]()
__________________
NOM
|
Jan 21, 2006, 04:36 PM | ||
Quote:
Orbitz can say that too people as well. ;-P |
Jan 21, 2006, 06:38 PM | ||
Quote:
Anyways, hi Link ![]()
__________________
I'm sick and tired of this community. So goodbye. PS: Unreal > JJ2. |
Jan 21, 2006, 07:30 PM | |
We should have got him at EC2005. Oh wait, I wasn't there.
__________________
I'm sick and tired of this community. So goodbye. PS: Unreal > JJ2. |
Jan 21, 2006, 08:34 PM | ||
Quote:
__________________
With our extreme gelatinous apology,
We beg to inform your Imperial Majesty, Unto whom be dominion and power and glory, There still remains that strange precipitate Which has the quality to resist Our oldest and most trusted catalyst. It is a substance we cannot cremate By temperatures known to our Laboratory. ~ E.J. Pratt |
![]() |
«
Previous Thread
|
Next Thread
»
Thread Tools | |
|
|
All times are GMT -8. The time now is 05:40 PM.
Jazz2Online © 1999-INFINITY (Site Credits). Jazz Jackrabbit, Jazz Jackrabbit 2, Jazz Jackrabbit Advance and all related trademarks and media are ™ and © Epic Games. Lori Jackrabbit is © Dean Dodrill. J2O development powered by Loops of Fury and Chemical Beats. Powered by vBulletin® Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Original site design by Ovi Demetrian. DrJones is the puppet master. Eat your lima beans, Johnny.