25.08.2017, 10:49
It is kalcor's obligation to launch a new update the vulnerability is layer 7 and it has been reported for more than 1 year!
I am afraid that it is necessary to change the way of altenticaзгo of the samp is very simple to falsify packages!
It is impossible to block such attacks via firewall, since the packets are identical to those of the clients! Impossible in the right way respecting good practices, and not blocking any legitimate customer!
I spent 5 hours analyzing the traffic of this attack!
The attack is totally spoofed, the ips never repeat !!!!
Do not try to block the ips that flood, adding them to a blacklist, the amount of ips is giant, if you make your memory / cpu will run out quickly,
I am afraid that it is necessary to change the way of altenticaзгo of the samp is very simple to falsify packages!
It is impossible to block such attacks via firewall, since the packets are identical to those of the clients! Impossible in the right way respecting good practices, and not blocking any legitimate customer!
I spent 5 hours analyzing the traffic of this attack!
The attack is totally spoofed, the ips never repeat !!!!
Do not try to block the ips that flood, adding them to a blacklist, the amount of ips is giant, if you make your memory / cpu will run out quickly,