11.02.2012, 19:33
(
Последний раз редактировалось HeLiOn_PrImE; 11.02.2012 в 23:02.
)
This is an emergency. My server keeps getting attacked these days with a tool that creates multiple connections. I don't know how, but they got past the host firewall and they are forcing the CPU causing major lag. I banned the person who attacked up until now, and just when the things were getting better, they came back after about an hour, and this time they were more than one.
I don't know what tool they use, but like I said, it got past the firewalls and filters and it forces the CPU up to 100 %.
Once the players connect to the server they stay frozen. They never get to choose the class.
Here is what I found on the log (this is the 1st guy caught):
I banned him on sight but after an hour, big surprise. More came back:
They seem to connect partially to the server, because we can't seem to see them coming and going.
And to be honest, I don't know what to think on the second wave. I can't know if they are actually players or bots, because there are to many IP's.
Is there any script what so ever that can stop these connections? I really need some help here, please!! I know people somehow make connection limits per time to prevent flood. How can I do that?
I don't know what tool they use, but like I said, it got past the firewalls and filters and it forces the CPU up to 100 %.
Once the players connect to the server they stay frozen. They never get to choose the class.
Here is what I found on the log (this is the 1st guy caught):
Код:
[19:10:55] Incoming connection: 78.96.188.35:62119 [19:10:56] Incoming connection: 78.96.188.35:62120 [19:10:56] Incoming connection: 78.96.188.35:62121 [19:10:56] Incoming connection: 78.96.188.35:62122 [19:10:57] Incoming connection: 78.96.188.35:62123 [19:10:57] Incoming connection: 78.96.188.35:62124 [19:10:57] Incoming connection: 78.96.188.35:62125 [19:10:58] Incoming connection: 78.96.188.35:62126 [19:10:58] Incoming connection: 78.96.188.35:62127
Код:
[22:07:33] Incoming connection: 78.97.16.45:1336 [22:07:52] Incoming connection: 79.118.228.243:1262 [22:08:07] Incoming connection: 94.62.248.206:1875 [22:08:13] Incoming connection: 89.123.128.14:3808 [22:08:14] Incoming connection: 188.173.28.230:2904 [22:08:32] Incoming connection: 82.78.92.191:57533 [22:08:41] Incoming connection: 80.96.113.3:62634 [22:08:54] Incoming connection: 89.123.128.14:3825 [22:08:55] Incoming connection: 95.65.59.38:6412 [22:08:56] Incoming connection: 86.126.176.58:4915 [22:09:01] Incoming connection: 188.27.93.248:61331 [22:09:13] Incoming connection: 188.24.166.41:59809 [22:09:31] Incoming connection: 194.102.249.120:65375 [22:09:40] Incoming connection: 89.39.62.156:59739 [22:09:41] Incoming connection: 2.82.134.16:49451 [22:09:42] Incoming connection: 86.104.54.38:56876 [22:09:43] Incoming connection: 188.25.97.3:65192 [22:09:51] Incoming connection: 80.96.113.3:64615 [22:10:18] Incoming connection: 90.230.195.71:61479 [22:10:20] Incoming connection: 92.83.253.223:9771 [22:10:59] Incoming connection: 80.96.113.3:64616 [22:11:11] Incoming connection: 86.122.106.25:4321 [22:11:31] Incoming connection: 2.82.134.16:49455 [22:12:28] Incoming connection: 78.97.221.141:61257 [22:12:43] Incoming connection: 86.122.102.51:4398 [22:12:52] Incoming connection: 78.97.57.92:61629 [22:13:04] Incoming connection: 2.82.134.16:49484
And to be honest, I don't know what to think on the second wave. I can't know if they are actually players or bots, because there are to many IP's.
Is there any script what so ever that can stop these connections? I really need some help here, please!! I know people somehow make connection limits per time to prevent flood. How can I do that?